Browser Bug Could Allow Phishing Without Email

Monday, January 12th, 2009

A bug found in all major browsers could make it easier for criminals to steal online banking credentials using a new type of attack called "in-session phishing," according to researchers at security vendor Trusteer. In-session phishing (pdf) gives the bad guys a solution to the biggest problem facing phishers these days: ...

Hacker Leaves Message for Microsoft in Trojan Code

Monday, January 12th, 2009

Here's a new way to get Microsoft to pay attention to you: Slip a brief message into the malicious Trojan horse program you just wrote. That's what an unnamed Russian hacker did recently with a variation of Win32/Zlob, a Trojan program victims are being tricked into installing on their computers. The message ...

Obfuscation: The Art of Creating Undetectable Malware

Monday, January 5th, 2009

Do not expect that your system would start misbehaving once it is infected by a malware. Malwares can perform their functions without showing any symptoms for days, months or years. New malwares are capable of hiding themselves even from powerful Antivirus scan engines. They can also perform their jobs without affecting ...

FBI issues code cracking challenge

Monday, December 29th, 2008

The FBI today challenged anyone in the online community to break a cipher code on its site.  The code was created by FBI cryptanalysts. The bureau invited hackers to a similar code-cracking challenge last year and got tens of thousands of responses it said. A number of sites host such cipher ...

Ruby On Rails Security Guide published as free ebook

Tuesday, November 4th, 2008

The Ruby on Rails Security Project have published a Ruby on Rails Security Guide as a free e-book and also made it available as HTML. The guide covers how to secure Ruby on Rails applications, looking at, sessions and how to manage them securely, cross site forgery, redirection and other ...