Android flaw executed typed text

Monday, November 10th, 2008

With the news that Google's Android shipped with an embarrassing security hole being followed by a simple two-step method to 'jailbreak' the OS, you'd think that the company had ironed out most of the remaining bugs – but you'd be wrong. According to ZDnet's Ed Burnette, the open-source Linux-based smartphone platform ...

Hackers exploit PDF security flaws

Monday, November 10th, 2008

Attackers have been using the recently announced vulnerability in Adobe Reader 8 to attack Windows users, warn security experts from ISC (Internet Storm Center). The attackers are exploiting the util.printf JavaScript function to trigger a buffer overload. A PDF containing the malicious code was recognised by over 30 virus scanners ...

Fake WordPress steals data

Thursday, November 6th, 2008

Yesterday evening amid the researching the Barack related malware our friends at The Register pointed out an interesting article on Craig Murphy’s blog. Craig talks about how when he logged in to his admin account in WordPress he received a “High Risk Vulnerability Warning” from a spoofed WordPress domain. (The last ...

Private Browsing in Firefox

Wednesday, November 5th, 2008

Today, a major feature was added to the pre-release versions of Firefox 3.1, called Private Browsing. I've been working for quite some time on this, so I thought it may be a good time to write about what this feature is and how to use it. As you may know, while ...

Ruby On Rails Security Guide published as free ebook

Tuesday, November 4th, 2008

The Ruby on Rails Security Project have published a Ruby on Rails Security Guide as a free e-book and also made it available as HTML. The guide covers how to secure Ruby on Rails applications, looking at, sessions and how to manage them securely, cross site forgery, redirection and other ...