Robert Lemos

…articles and musings of a technology and science journalist

Robert Lemos header image 1

Retro attack gets new life, worries browser makers

August 6th, 2007 · No Comments

Researchers find that browsers and plug-ins could be exploited to turn a victim’s computer into a door to the internal network. One study finds an attack could claim 100,000 IP addresses in three days.
SecurityFocus

→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus · Software

Teaching hacking helps students, professors say

August 5th, 2007 · No Comments

Universities and colleges could find more students interested in computer-science courses, if the teachers taught practical hacking, educators say.
SecurityFocus

→ No CommentsTags: Open Source · Research · Security · SecurityFocus

Will the iPhone be iPwned?

August 1st, 2007 · No Comments

Security experts’ predictions for the sleek high-end device vary, but they agree that Apple’s first phone will be scrutinized closely.
SecurityFocus

→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus

Firm finds new danger in dangling pointers

July 25th, 2007 · No Comments

The common software flaw should be considered a security threat, not a quality control issue, researchers say.
SecurityFocus

→ No CommentsTags: Flaws and vulnerabilities · Research · Security · SecurityFocus

MPack interview chat sessions posted

July 23rd, 2007 · No Comments

A Russian site has somehow gotten the transcript of my interview with the Dream Coders Team, the developers of MPack, and posted them. In fact, they scooped my own posting at SecurityFocus, posting apparently the day of the first interview I had on June 20 (June 21, Russian time) and then updating the following day. The two later chat sessions, on June 26 and July 2, were not posted.

I just learned that they published the transcripts today, after someone posted the link to the comment section of OffensiveComputing’s post on the interview. The Russian information in the chat log, the local time, and the fact that
the chat included blank responses apparently from me, all point to the logs being from the interviewee’s computer.

The posting of the chat sessions poses some interesting questions, among the most salient being: Why would DCT post the interviews, and if it wasn’t DCT, does that call into question the identity of the interviewee?

[Read more →]

→ No CommentsTags: Blog · Journalism · Security · Viruses and worms

Newsmaker: DCT, MPack developer

July 20th, 2007 · No Comments

One of the three Russian developers behind the MPack infection kit virtually sits down with SecurityFocus to discuss the program and making a business out of cybercrime.
SecurityFocus

→ No CommentsTags: Cybercrime · Flaws and vulnerabilities · Interview · Security · SecurityFocus · Software · Viruses and worms

Updated GPG key

July 19th, 2007 · No Comments

I let my key lapse last month, so I apologize to anyone that has been trying to contact me. Feel free to use the new one, which can be found here.

→ No CommentsTags: Blog · Security

Spammers dump images, switch to PDF files

July 18th, 2007 · No Comments

A wave of spam e-mail messages carrying attachments in the Portable Document Format gathers speed, hitting companies and consumers worldwide.
SecurityFocus

→ No CommentsTags: Cybercrime · Flaws and vulnerabilities · Research · Security · SecurityFocus

Got Interference? Data-Crowding Problems Loom for Wi-Fi

July 17th, 2007 · No Comments

Interference on wireless networks will likely get worse before it gets better. Sometimes, the most egregious offenders aren’t nearby residential networks or municipal Wi-Fi grids, but the myriad electronic devices in people’s homes. Poorly shielded microwave ovens leak radio waves tuned to 2.45 GHz, the resonant frequency of water. Many cordless phones operate in the 2.4-GHz band as well. Wireless keyboards, Bluetooth devices, wireless security cameras and baby monitors can all interfere with a Wi-Fi network.
Wired News

→ No CommentsTags: Consumer Tech · Flaws and vulnerabilities · Software · Wired News

Flaw auction site highlights disclosure issues

July 13th, 2007 · No Comments

WabiSabiLabi gets mixed reviews, but security pros agree that interesting times are ahead.
SecurityFocus

→ No CommentsTags: Flaws and vulnerabilities · Research · Security · SecurityFocus