Web Gives Hackers More Territory, Tools

Sunday, September 28th, 2008

As more people become accustomed to Web surfing and downloading software and multimedia, legitimate Web sites have become the favorite targets of hackers. "The hacking of legitimate Web sites is the biggest threat today," said David Freer, Symantec's vice president for consumer business in Asia-Pacific and Japan. Freer revealed that based on ...

Trojan can grab extra personal banking data

Saturday, September 27th, 2008

A Trojan horse program now available to a growing number of fraudsters can add data entry fields to legitimate online banking sites and entice consumers to give up sensitive information such as bank card numbers and PINs (personal identification numbers). The Limbo malware integrates itself into a Web browser using a ...

NoScript mitigates HTTPS cookie hijacking attacks

Thursday, September 11th, 2008

The invaluable NoScript for Firefox plug-in just got a tad better. According to Giorgio Maone, the developer behind the popular browser extension, a new experimental feature called “Forced Secure Cookies” has been added to NoScript v1.8.0.5 to mitigate the HTTPS cookie hijacking attack vector discussed at DEFCON 16 last month. Source: http://blogs.zdnet.com/security/?p=1882

CSRF vulnerability allows Twitter ‘follow’ abuse

Thursday, September 11th, 2008

Last week, TechCrunch’s Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called “johng77536″ to game the popular micro-blogging service to add thousands of followers (subscribers) in a short period of time. The “johng77536″ account has since been disabled but a security researcher tracking Twitter security flaws and ...

NMap 4.75 now maps the network graphically

Thursday, September 11th, 2008

Nmap, the popular network scanner and mapper, has been updated to version 4.75 and gained the ability to graphically display the network topology it scans and maps. The update also includes hundreds of new OS signatures and new scripting engine modules.The mapping facility is incorporated in the Zenmap GUI for ...