Researchers find that browsers and plug-ins could be exploited to turn a victim’s computer into a door to the internal network. One study finds an attack could claim 100,000 IP addresses in three days.
SecurityFocus
Retro attack gets new life, worries browser makers
August 6th, 2007 · No Comments
→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus · Software
Teaching hacking helps students, professors say
August 5th, 2007 · No Comments
Universities and colleges could find more students interested in computer-science courses, if the teachers taught practical hacking, educators say.
SecurityFocus
→ No CommentsTags: Open Source · Research · Security · SecurityFocus
Will the iPhone be iPwned?
August 1st, 2007 · No Comments
Security experts’ predictions for the sleek high-end device vary, but they agree that Apple’s first phone will be scrutinized closely.
SecurityFocus
→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus
Firm finds new danger in dangling pointers
July 25th, 2007 · No Comments
The common software flaw should be considered a security threat, not a quality control issue, researchers say.
SecurityFocus
→ No CommentsTags: Flaws and vulnerabilities · Research · Security · SecurityFocus
MPack interview chat sessions posted
July 23rd, 2007 · No Comments
A Russian site has somehow gotten the transcript of my interview with the Dream Coders Team, the developers of MPack, and posted them. In fact, they scooped my own posting at SecurityFocus, posting apparently the day of the first interview I had on June 20 (June 21, Russian time) and then updating the following day. The two later chat sessions, on June 26 and July 2, were not posted.
I just learned that they published the transcripts today, after someone posted the link to the comment section of OffensiveComputing’s post on the interview. The Russian information in the chat log, the local time, and the fact that
the chat included blank responses apparently from me, all point to the logs being from the interviewee’s computer.
The posting of the chat sessions poses some interesting questions, among the most salient being: Why would DCT post the interviews, and if it wasn’t DCT, does that call into question the identity of the interviewee?
→ No CommentsTags: Blog · Journalism · Security · Viruses and worms
Newsmaker: DCT, MPack developer
July 20th, 2007 · No Comments
One of the three Russian developers behind the MPack infection kit virtually sits down with SecurityFocus to discuss the program and making a business out of cybercrime.
SecurityFocus
→ No CommentsTags: Cybercrime · Flaws and vulnerabilities · Interview · Security · SecurityFocus · Software · Viruses and worms
Updated GPG key
July 19th, 2007 · No Comments
I let my key lapse last month, so I apologize to anyone that has been trying to contact me. Feel free to use the new one, which can be found here.
→ No CommentsTags: Blog · Security
Spammers dump images, switch to PDF files
July 18th, 2007 · No Comments
A wave of spam e-mail messages carrying attachments in the Portable Document Format gathers speed, hitting companies and consumers worldwide.
SecurityFocus
→ No CommentsTags: Cybercrime · Flaws and vulnerabilities · Research · Security · SecurityFocus
Got Interference? Data-Crowding Problems Loom for Wi-Fi
July 17th, 2007 · No Comments
Interference on wireless networks will likely get worse before it gets better. Sometimes, the most egregious offenders aren’t nearby residential networks or municipal Wi-Fi grids, but the myriad electronic devices in people’s homes. Poorly shielded microwave ovens leak radio waves tuned to 2.45 GHz, the resonant frequency of water. Many cordless phones operate in the 2.4-GHz band as well. Wireless keyboards, Bluetooth devices, wireless security cameras and baby monitors can all interfere with a Wi-Fi network.
Wired News
→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Software · Wired News
Flaw auction site highlights disclosure issues
July 13th, 2007 · No Comments
WabiSabiLabi gets mixed reviews, but security pros agree that interesting times are ahead.
SecurityFocus
→ No CommentsTags: Flaws and vulnerabilities · Research · Security · SecurityFocus