Google Gadgets an open door for attack - Network World
Gadget lovers were dealt a blow on Wednesday when two researchers outlined what they called a "hole" during a Black Hat presentation.
"The attacker can forcibly install Google Gadgets; they can read the victim's search history once a malicious gadget has been installed in some specific circumstances; they can attack other Google Gadgets; they can phish usernames and passwords from victims, and so on," said Robert Hansen, also known as RSnake, a founder of security consultancy SecTheory. "Really, the sky is the limit, once the browser is under the control of an attacker. And that point is exacerbated by the fact that people trust Google be a trustworthy domain, making the attacks even easier."
Sphere: Related Content
Friday, August 8, 2008
Thursday, August 7, 2008
Kaminsky: Many ways to attack with DNS - Network World
Kaminsky: Many ways to attack with DNS - Network World
There were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community, even an accidentally leaked Black Hat presentation, but after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he'd do it all over again. Sphere: Related Content
There were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community, even an accidentally leaked Black Hat presentation, but after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he'd do it all over again. Sphere: Related Content
Wednesday, August 6, 2008
Video Demonstration: Aurora Concept Video Proposes the Future of the Web
Video Demonstration: Aurora Concept Video Proposes the Future of the Web:
"What will browsing the web be like a decade from now? Leading design and UI company Adaptive Path offers one possible answer in a new concept video series called Aurora. Jesse James Garrett (the guy who coined the term AJAX) designed and narrated part one of a video series demonstrating what the future of the web might look like. There's some gorgeous, imaginative, and high-tech stuff going on here—hit the play button below to watch." Sphere: Related Content
"What will browsing the web be like a decade from now? Leading design and UI company Adaptive Path offers one possible answer in a new concept video series called Aurora. Jesse James Garrett (the guy who coined the term AJAX) designed and narrated part one of a video series demonstrating what the future of the web might look like. There's some gorgeous, imaginative, and high-tech stuff going on here—hit the play button below to watch." Sphere: Related Content
Tuesday, August 5, 2008
Computerworld > Firewall vendors scramble to fix DNS problem
Computerworld > Firewall vendors scramble to fix DNS problem
When I sit down at my computer and type Bank of America's Web site into my browser's address bar, I expect to be taken to Bank of America. When I send an e-mail to my parents from my G-mail account, I expect that e-mail to go to my family in Memphis. But now, because of a first-of-its-kind flaw in the Internet's infrastructure, hackers can easily divert you to fake Web sites where your personal information – from your banking passwords to your e-mails – are ripe for the picking. Sphere: Related Content
When I sit down at my computer and type Bank of America's Web site into my browser's address bar, I expect to be taken to Bank of America. When I send an e-mail to my parents from my G-mail account, I expect that e-mail to go to my family in Memphis. But now, because of a first-of-its-kind flaw in the Internet's infrastructure, hackers can easily divert you to fake Web sites where your personal information – from your banking passwords to your e-mails – are ripe for the picking. Sphere: Related Content
ABC News: Major Web Flaw Puts Personal Info At Risk
ABC News: Major Web Flaw Puts Personal Info At Risk
When I sit down at my computer and type Bank of America's Web site into my browser's address bar, I expect to be taken to Bank of America. When I send an e-mail to my parents from my G-mail account, I expect that e-mail to go to my family in Memphis. But now, because of a first-of-its-kind flaw in the Internet's infrastructure, hackers can easily divert you to fake Web sites where your personal information – from your banking passwords to your e-mails – are ripe for the picking. Sphere: Related Content
When I sit down at my computer and type Bank of America's Web site into my browser's address bar, I expect to be taken to Bank of America. When I send an e-mail to my parents from my G-mail account, I expect that e-mail to go to my family in Memphis. But now, because of a first-of-its-kind flaw in the Internet's infrastructure, hackers can easily divert you to fake Web sites where your personal information – from your banking passwords to your e-mails – are ripe for the picking. Sphere: Related Content
ABC News: Meet A-Z: Hacker Behind Cybercrime Wave
ABC News: Meet A-Z: Hacker Behind Cybercrime Wave
He goes by the nickname A-Z and is one of Russia's bright young tech stars. He's a crack programmer, successful entrepreneur and creator of sophisticated software tools that help his customers make millions. Sphere: Related Content
He goes by the nickname A-Z and is one of Russia's bright young tech stars. He's a crack programmer, successful entrepreneur and creator of sophisticated software tools that help his customers make millions. Sphere: Related Content
Children's internet activity could create security problems - SC Magazine UK
Children's internet activity could create security problems - SC Magazine UK
The provider claims that 84 per cent of parents rely on a verbal agreement to ensure that their children ‘surf safely', with 48 per cent regularly using downloads. Although there are reports on personal safety while using chatrooms and social networking, there could also be a danger of technology security. Sphere: Related Content
The provider claims that 84 per cent of parents rely on a verbal agreement to ensure that their children ‘surf safely', with 48 per cent regularly using downloads. Although there are reports on personal safety while using chatrooms and social networking, there could also be a danger of technology security. Sphere: Related Content
Update: Eleven indicted in massive ID theft scheme
Update: Eleven indicted in massive ID theft scheme
Eleven people have been charged or indicted in a massive identity theft and computer fraud scheme involving some of the largest data breaches in recent U.S. history, the Department of Justice announced Tuesday Sphere: Related Content
Eleven people have been charged or indicted in a massive identity theft and computer fraud scheme involving some of the largest data breaches in recent U.S. history, the Department of Justice announced Tuesday Sphere: Related Content
Computerworld > DNS patches slow servers, but fast action is advised
Computerworld : DNS patches slow servers, but fast action is advised
Software patches released in early July to protect against a critical flaw in the Domain Name System protocol have slowed servers running the internet's most popular DNS implementation and crippled some Windows Server systems. Sphere: Related Content
Software patches released in early July to protect against a critical flaw in the Domain Name System protocol have slowed servers running the internet's most popular DNS implementation and crippled some Windows Server systems. Sphere: Related Content
WEIS 2008: Escalation and incentives for better security - Network World
WEIS 2008: Escalation and incentives for better security - Network World
Xia Zhao is a research fellow at the Glassmeyer/McNamee Center for Digital Strategies of the Tuck School of Business at Dartmouth. In collaboration with M. Eric Johnson, professor of operations management and director of the Center for Digital Strategies, she presented a paper entitled "Information Governance: Flexibility and Control through Escalation and Incentives." Sphere: Related Content
Xia Zhao is a research fellow at the Glassmeyer/McNamee Center for Digital Strategies of the Tuck School of Business at Dartmouth. In collaboration with M. Eric Johnson, professor of operations management and director of the Center for Digital Strategies, she presented a paper entitled "Information Governance: Flexibility and Control through Escalation and Incentives." Sphere: Related Content
Monday, August 4, 2008
SecurityProPortal.com - Expect Government to be interested in your IT security.
SecurityProPortal.com - Expect Government to be interested in your IT security.
Disaster has struck and all big organisations should be preparing to pay the price. In the aftermath of the HM Revenue & Customs (HMRC) loss -of personal information and a subsequent flood of data security breaches, large organisations should be ready to prove that they can take care of personal information. Sphere: Related Content
Disaster has struck and all big organisations should be preparing to pay the price. In the aftermath of the HM Revenue & Customs (HMRC) loss -of personal information and a subsequent flood of data security breaches, large organisations should be ready to prove that they can take care of personal information. Sphere: Related Content
UK Hacker is doing all he can not to get extradited to the US
UK Hacker is doing all he can not to get extradited to the US
In a last ditch effort Gary McKinnon, the UK hacker who allegedly hacked in to the Pentagon, is now taking his case to the European Court on Human Rights. McKinnon feels that his human rights were violated when the U.S. offered him a plea-bargain (something the UK courts to not do) to get a lighter sentence. He felt that by accepting this he would be opting himself out of a fair trial. Of course, he’s already admitted he did the crimes, having left a melodramatic note on the system saying among other things: Sphere: Related Content
In a last ditch effort Gary McKinnon, the UK hacker who allegedly hacked in to the Pentagon, is now taking his case to the European Court on Human Rights. McKinnon feels that his human rights were violated when the U.S. offered him a plea-bargain (something the UK courts to not do) to get a lighter sentence. He felt that by accepting this he would be opting himself out of a fair trial. Of course, he’s already admitted he did the crimes, having left a melodramatic note on the system saying among other things: Sphere: Related Content
FBI warns of new Storm Worm attacks - Network World
FBI warns of new Storm Worm attacks - Network World
A rash of complaints prompted the FBI to issue a warning of a new round of spam e-mails bombarding the Internet to spread the malicious Storm Worm.
In an announcement today, the FBI and its partner organization, the Internet Crime Complaint Center (IC3), said they've received reports of recent spam e-mails spreading the Storm Worm. The e-mails contain the phrase "F.B.I. vs. facebook," according to the warnings, and ask recipients to click on a link to view an article about the FBI and Facebook that then downloads malicious software. Sphere: Related Content
A rash of complaints prompted the FBI to issue a warning of a new round of spam e-mails bombarding the Internet to spread the malicious Storm Worm.
In an announcement today, the FBI and its partner organization, the Internet Crime Complaint Center (IC3), said they've received reports of recent spam e-mails spreading the Storm Worm. The e-mails contain the phrase "F.B.I. vs. facebook," according to the warnings, and ask recipients to click on a link to view an article about the FBI and Facebook that then downloads malicious software. Sphere: Related Content
Sunday, August 3, 2008
Telecommuting poses security, privacy risks - Network World
Telecommuting poses security, privacy risks - Network World
Allowing employees to work from home and telecommute poses security and privacy risks that are not being addressed adequately by business or government, according to a study released today by consulting firm Ernst & Young in partnership with the Washington-based advocacy group Center for Democracy and Technology. Sphere: Related Content
Allowing employees to work from home and telecommute poses security and privacy risks that are not being addressed adequately by business or government, according to a study released today by consulting firm Ernst & Young in partnership with the Washington-based advocacy group Center for Democracy and Technology. Sphere: Related Content
Subscribe to:
Posts (Atom)