browserrecon – Passive Browser Fingerprinting

Wednesday, May 14th, 2008

Most of todays tools for fingerprinting are focusing on server-side services. Well-known and widely-accepted implementations of such utilities are available for http web services, smtp mail server, ftp servers and even telnet daemons. Of course, many attack scenarios are focusing on server-side attacks. Client-based attacks, especially targeting web clients, are becoming ...

ZoneAlarm ForceField – Virtualized Browser Security

Monday, May 12th, 2008

ZoneAlarm ForceField provides a protective layer around your browser, shielding you from drive-by downloads, browser exploits, phishing attempts, spyware and keyloggers. So your passwords, your confidential information, and your financial data remain protected. While traditional security, such as firewalls, antivirus, and security suites, protects your PC, ZoneAlarm ForceField protects your browser ...

Two Factor Authentication is Dead

Thursday, May 1st, 2008

The fundamental problem with two factor (2FA) session authentication is that the approach is vulnerable to Man in the Middle and Man in the Browser attacks. 2FA requires that customers present not only a password (something they know) when they log into online banking, but also demonstrate that they possess ...

Between black and white: the state of grayware on the PC

Friday, April 25th, 2008

In the old days, as our parents frequently love to remind us, life was much simpler. You bought a computer, and when you finally figured out what you wanted to do with it, you assembled a list and went down to your local Egghead for some software. It was straightforward, ...

PayPal Plans to Ban Unsafe Browsers

Thursday, April 17th, 2008

PayPal says allowing customers to make financial transactions on unsafe browsers "is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts." PayPal, one of the brands most spoofed in phishing attacks, is working on a plan to block its users from making transactions from ...