Bot breaks Hotmail’s CAPTCHA in 6 seconds

Monday, April 14th, 2008

A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday. Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test ...

Vulnerability in Google spreadsheets allows cookie stealing

Monday, April 14th, 2008

Security researcher Billy Rios has discovered a vulnerability in Google Spreadsheets which attackers can exploit using links to crafted tables to steal a user's cookie. According to Rios, the victim has to follow such a link in Internet Explorer. The stolen cookie can be used to access all Google services ...

Password theft via vulnerability in Google code

Monday, April 7th, 2008

Billy Rios has discovered a vulnerability in the Google Code service which could be exploited to steal passwords from developers who have registered on the site. The Google Security Team has since fixed the vulnerability. Rios succeeded in gaining cross-domain access by uploading a crafted Java applet to a project on ...

Google Maps diminishing value of homes, causing “mental suffering”?

Saturday, April 5th, 2008

A couple is accusing Google of diminishing the value of their property and causing them "mental" suffering" for including their recluse home in the Google Maps Street View project. The road leading up to their house is apparently labeled "private", something the Street View operator must've missed. We checked the ...

Analysis of a Win32.Delf Variant

Friday, April 4th, 2008

We have been noticing quite a few malware samples having references to or communicating with Google's SMTP servers. This post dissects one of these samples and in the process attempts to illustrate to the reader some reversing techniques and information gathering techniques, while explaining the behavior and impact of this ...