Next Generation War-Dialing Tool On Tap

Friday, March 6th, 2009

War-dialing is back, and it's not limited to finding modems anymore. Renowned researcher HD Moore is putting the final touches on his latest project -- a telephone auditing tool that also finds PBXes, dial tones, voicemail, faxes, and other phone line connections for security assessment, research, or inventory. This is not ...

Tigger Trojan Keeps Security Researchers Hopping

Thursday, March 5th, 2009

It's malware that actually removes other malware from its victims' PCs. And so far, nobody is exactly sure how it's being distributed. Security experts this week are buzzing about a new Trojan called Tigger.A, also known as Syzor. The data-stealing malware has quietly claimed about 250,000 victims since it was first ...

GMail Service CSRF Vulnerability

Tuesday, March 3rd, 2009

Gmail is Google's "free webmail service. It comes with built-in Google search technology and over 2,600 megabytes of storage (and growing every day). You can keep all your important messages, files and pictures forever, use search to quickly and easily find anything you're looking for, and make sense of it ...

Excel 0-Day Exploited

Tuesday, February 24th, 2009

Symantec is reporting that Trojan.Mdropper.AC is exploiting an unpatched vulnerability in Excel 2007. Earlier versions of Excel may also be vulnerable. The vulnerability is described as a "Boundary Condition Error" and can result in remote code execution, but that's it for details for now. The research is obviously in its early ...

Researcher Shows New SSL Website Hack

Saturday, February 21st, 2009

A researcher has found a convincing way to hack the SSL protocol used to secure logins to a range of Web sites, including e-commerce and banking sites. Using a specially-created app, 'SSLstrip', a researcher calling himself Moxie Marlinspike demonstrated to Black Hat Arlington, Va attendees, how vulnerable many SSL connections were ...