IE8 beta installs with search bar ‘keylogger’

Thursday, September 11th, 2008

Microsoft's IE8 browser includes a keystroke-logging search suggestion tool similar to the one that Google modified on Monday after coming under fire from consumers. Unlike Chrome, IE8 Beta 2 does not enable the feature - which some have compared to a keylogger - by default. One privacy expert said that was ...

Facebook botnet risk revealed

Saturday, September 6th, 2008

Researchers have created a proof-of-concept application for Facebook that turned the machines of people who added the app to their Facebook page into a botnet that launched denial-of-service attacks on a victim server in a demonstration. "Social Network Web sites have the ideal properties to become attack platforms," according to a ...

Wells Fargo Passwords Are Not Case-Sensitive!

Friday, September 5th, 2008

I just heard on the Security Now podcast a listener mention that his Wells Fargo password was not case-sensitive.  I'm not a Wells Fargo user but several users who are that I asked this morning actually confirmed this.  You will be logged in no matter what case you enter into ...

Using Nessus to call Nikto

Friday, September 5th, 2008

Earlier this year, Michel Arboi wrote a blog post explaining how to use Nessus to call Nikto and incorporate the results into Nessus output. Most newcomers to Nessus have enabled the nikto.nasl wrapper only to find it produced no output. Some Nessus users have found various ways to ensure Nikto ...

Twitter targeted by malware attacks

Friday, September 5th, 2008

Twitter's time has finally come.The microblogging service, once the playground of the Web 2.0 digerati, is now mainstream enough to be targeted by online criminals.Kaspersky Lab has uncovered a fake Twitter profile created solely for the purpose of infecting people's computers.The profile, with an alias that means "pretty rabbit" in ...