Students crack Microsoft CardSpace

Friday, May 30th, 2008

Students at the Ruhr University of Bochum, Germany, say they have found a way to steal security tokens in Microsoft's new CardSpace authentication framework. Attackers can apparently get access to protected, encrypted user data – such as passwords, credit card numbers, and delivery addresses – when they are transmitted. ...

PstPassword Recovers Lost Outlook Passwords

Friday, May 30th, 2008

Windows only: When you dig up that old Outlook PST (Personal Folders) file from years ago you cleverly secured with a hard-to-guess password—and now you can't guess it—you want PstPassword. Turns out that Outlook passwords aren't that difficult to figure out, because this handy utility detects the PST's on your ...

fgdump 2.1.0 and pwdump 1.7.1 Released – Dump LanMan & NTLM Hashes

Wednesday, May 28th, 2008

The major change is both tools now support 64-bit targets! Good news for us. pwdump6 is a password hash dumper for Windows 2000 and later systems. It is capable of dumping LanMan and NTLM hashes as well as password hash histories. It is based on pwdump3e, and should be stable on ...

Facebook security snafu could compromise accounts

Friday, May 23rd, 2008

A researcher has spotted a security problem in Facebook that could lead to hackers taking control of user accounts. The flaw allows a hacker to execute scripts on Facebook that could potentially be used to create a fake log-in page and capture people's passwords, according to the XSSED security blog. The ...

Researchers find new ways of snooping

Monday, May 19th, 2008

Researchers have developed techniques for stealing computer data from a computer using some unlikely hacking tools: cameras and telescopes. In two separate pieces of research, teams at the University of California, Santa Barbara, and at Saarland University in Saarbrucken, Germany, describe attacks that seem ripped from the pages of spy novels. ...