Tuesday, July 15, 2008

Facebook and Privacy Issues

Facebook can use your personal information for marketing...

Lately there's been a lot of news about Facebook using personal details for profit and now Canada's federal privacy commissioner has launched an investigation into Facebook. Apparently four students complained that the popular Web site violates Canadian law by disclosing personal information to advertisers without proper consent.

This in turn reminded me of a wonderful
YouTube video - definitely worth watching and passing on to your less security-aware friends and family! - source Pete Wood.

Anti-Virus softwares are vulnerable itself...

Approximately 800 vulnerabilities discovered in antivirus products
A recent
ZDnet blog discusses a large number of vulnerabilities German research team N.Runs says it found in anti malware products from nearly every vendor. The ZDNet posting includes scary graphs to frighten users of security products.

If anti-virus softwares are vulnerable to security exploits then how someone can rely on anti-virus products? I guess, we soon need to look for anti-vulnerable software and then we might need anti-virus software.

Anti-virus companies should focus on overall security of their software rather then just increasing the prices for updating virus definitions and marketing of their products.

Please refer here for much more detail response on the subject by McAfee.

Monday, July 14, 2008

Mobile Malware next thing to watch out!!

Mobile malware not yet a risk but companies told to prepare

Security risks to mobile devices such as mobile phones, smartphones and personal digital assistants (PDA) are not yet a major issue these days compared to the 1980s when computer networks were once vulnerable to such threats.

However, a security expert said companies should nonetheless be prepared just in case criminal elements, such as hackers, may beat them to it and steal valuable company information usually made available to corporate mobile workers.

The security expert said malware and viruses currently attacking mobile devices are usually simple nuisance viruses, such as those which can freeze the operating system (OS) or change the user’s preferences.

Refer to here for further details.

Thursday, July 10, 2008

XP SP3 will be rolled out soon!

Microsoft to push XP SP3 via Auto Update on July 10

Microsoft is going to release Windows XP Service Pack (SP) 3 via its Automatic Update (AU) service on Thursday July 10, company officials confirmed this week.

The client team has been vague about when it planned to push the latest version of XP to users. “Early summer” and “sometime soon” were favorite comebacks when officials were asked for an AU timeframe for SP3.

Customers who have automatic updates turned on but who don’t want XP SP3 to be downloaded to user desktops this week — for whatever reasons — need to deploy the Microsoft Service Pack blocker toolkit to delay pushed-delivery of SP3. While Microsoft will begin pushing SP3 tomorrow, not all users will receive it immediatly, as the company will be staggering the rollout.

Spammers prefer Gmail Accounts

Gmail: The Choice of Spammers?

An examination of spam originating from the major free e-mail providers shows that like consumers, spammers prefer Google.

In a three-week period from mid-June to this month, e-mail filtering firm Roaring Penguin said it saw an explosion of spam originating from Gmail, while Microsoft Hotmail and Yahoo Mail remained flat.

The company attributes this meteoric rise in Gmail spam to the cracking of Google's CAPTCHA. A CAPTCHA (define) is a test, typically used in Web site registration, that is designed to tell humans apart from programs designed to hack or automate registrations. It consists of a word displayed in such a way that it's difficult for a computer to read, but not a human. A user would be able to successfully enter the word into an input box to gain entry.

Tuesday, July 8, 2008

Universal Forensic Extraction Device (UFED)

Forensics on cell phones

Inside and outside government, professionals increasingly carry data on their cell phones, including e-mail messages, documents, videos and instant messages. And there are those — such as law enforcement officers, some employers and, yes, hackers — who want to get at that data without the owner’s permission.

Until recently, however, the tools to do that weren’t available. A handful of PC-based programs have been able to extract data from selected cell phone models, but special challenges face those who deliver powerful forensic tools.

The biggest one is that there are hundreds of models of cell phones, with manufacturers adding dozens of new ones each year. And all those models employ a wide array of BIOS versions, operating systems and software. The other nut to crack is portability. Cell phones are, of course, extremely portable. But if you need to plug one into a computer equipped with forensic software, extracting data in the field or without the owner’s knowledge can be problematic.

Please refer here for more details.

Protect your Gmail Account

Your Gmail is now a lot more secure

Your email account can contain a lot of personal information, from bank alerts to love letters. Email that, I'm sure, you don't always want other people to see. We understand how important your Gmail accounts are to you, so we're adding a new layer of information and control. With this new feature, you can now track your recent sessions and you can also sign yourself out remotely.

If you are anything like me, you probably sign in to Gmail from multiple computers. I, for example, occasionally sign into my Gmail account from a friend's house when I need to check an important email. Usually I remember to sign out, but every once in a while I wonder if I really did. Now I no longer have to wonder.

At the bottom of your inbox, you'll see information about the time of the last activity on your account and whether it's still open in another location.

Please refer to gmail's blog for more information.

Sunday, July 6, 2008

Wireshark and TShark network tools

Several bugs fixed

The new version 1.0.1 of the Wireshark network analysis tool and its command line variant TShark, remedy a number of security problems. Bugs in previous versions in the analysis modules for GSM messages, PANA, KISMET, and RTMPT packets as well as syslog messages, made it possible for attackers to crash the program. According to the developer advisory, the RMI module would even reveal some contents of the RAM to attackers.

The advisory states that the vulnerabilities are also present in Ethereal. Up to version 0.99, Ethereal was the original name of the Wireshark project. For users that cannot update to the newest version, the developers recommend deactivating the affected module.

I.E 8 with much better security features

Microsoft addresses XSS in Internet Explorer

Microsoft is planning to add a series of new security features to the next version of its Internet Explorer browser, including protection against cross-site scripting attacks.

A beta version of IE 8 is due out in August, and along with the XSS filter, it will include a filter designed to provide better protection against phishing attacks, features that make it easier for developers to request resources and share information across domains, and some changes to the way that ActiveX controls are handled by the browser. Specifically, developers will be able to write controls that are only available for the individual user who downloads them.

The announcement of the new security features in IE 8 came just a week after the release of Firefox 3, the latest version of IE's main competition in the browser world. Firefox 3 also includes updated antimalware and antiphishing capabilities and several other security updates. Microsoft has been fighting to repair the security reputation of IE for several years, since the initial release of Firefox, which the Mozilla Foundation has positioned as a more secure alternative to IE.

Thursday, July 3, 2008

PINS can leak while in transit....

ATM breach reveals PIN problems

Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.

Please refer here to read full details.

SSL Blacklist Service - Free of charge

DNS blacklist for weak SSL keys

Working closely with the German hosting company – manitu, heise is making available with immediate effect a realtime DNS-based blacklist service for identifying weak SSL keys. The provider already runs the Realtime Blacklist for the iX spam filter NiX Spam, which enables mail servers to identify and filter spam.

The principle of a DNS realtime blacklist is as simple as it is elegant. An application makes a DNS enquiry for .weakSSLkeys.dnsbl.manitu.net, which arrives at the name server responsible for the weakSSLkeys.dnsbl.manitu.net domain. It checks in its lists to see whether the string – host name is there. If it is, the DNS server responds with the IP address 127.0.0.2; if it cannot find the string, it responds with 127.0.0.3. DNS blacklists normally use NXDOMAIN for a negative result. It makes little sense to do so here, however, as under certain circumstances, certificate tests cannot determine the exact error code of the DNS lookup.

The SHA1 hash value from the certificate's modulus of the RSA key is used as the host name. All tests for weak SSL certificates use a similar fingerprinting, including the Debian Tools openssl-vulnkey and the heise networks SSL tests. The lists log keys with 512, 1024, 2048 and 4096-bits, both for 32- and 64-bit systems and little- or big-endian architectures.

Full article can be read from here.

Tuesday, July 1, 2008

Coffee Machine is hackable, Amazing things in amazing world...

My classmate finds vulnerability in his coffee maker.

Craig Wright, my classmate and a risk advisory services manager at professional services firm BDO, has discovered security holes in his internet-connected coffee maker that could allow a remote attacker to not only take over his Windows XP-based PC but also make his coffee too weak.

He found several security holes, including a buffer overflow in the internet connection software that links his Jura F90 coffee maker to his PC.

Once connected to the internet, the high-end coffee maker, which retails for nearly US$2,000 on Amazon, lets you do things like set the strength of your coffee and get remote diagnostic help over the internet without having to send the appliance in for service.

Wright posted the information on the vulnerabilities, and the fact that there is no patch available yet, to the BugTraq security e-mail list on Tuesday.

"I don't know if many people would target this particular vulnerability because there probably are not a lot of coffee makers at the moment that are internet-connected, and in my case it's behind a firewall," he said.


However, internet-connected appliances are the wave of the future. There is already an internet-connected refrigerator, at least one prototype of a Web-enabled oven, and pilot tests for dryers and water heaters.

Eventually "you'll be able to turn on your oven with your mobile phone" and a malicious hacker could wind up burning the house down, Wright said.

Further article can be read from here.

VOIP Calls are tappable....

Compression lets attackers tap VoIP calls

A common compression technique can make internet telephone calls significantly more susceptible to bugging, according to recent research from Johns Hopkins University.

Internet telephony has become widely used through consumer-centric applications such as Skype, and is becoming more common in enterprises.

The new research suggests, however, that standard encryption and compression methods, when used together, are not sufficiently secure. VoIP calls are commonly encrypted using a technique that preserves the lengths of voice patterns in the original, unencrypted conversation, the researchers said.

Please click here to read full article.

Identity Theft and Financial Fraud

Unisys Security Index Reveals Identity Theft and Financial Fraud Remain Top Global Concerns for Consumers

Fears about identity theft and financial fraud are top global concerns for consumers, according to the latest results of the Unisys Security Index.

Identity theft is the primary security concern cited among respondents in nine out of 14 countries, while misuse of credit or debit card information ranks as the first or second greatest fear in 12 out of the 14 countries.

Source - Earth Times , press release

As i always say, we really need to be careful about our Identity. We need to make sure who we are giving our details are legitimate people. I would prefer giving out less details on social networking websites if you use one and make sure you only add those users who are really your friends.

iSpring - Cool Utility

Converts PowerPoint Presentations to Flash Video

Windows only: Freeware PowerPoint plug-in iSpring converts your PowerPoint presentation to an interactive Flash video with the click of a button. Not only is iSpring a great way to make your PowerPoint presentation more portable (not everyone has PowerPoint, after all), but as Digital Inspiration points out, an exported movie even preserves all of your slide transitions, animations, and hyperlinks.

iSpring is freeware, Windows only, works with PowerPoint 2000 through 2007.

Alternately, you can upload any presentation directly to the SlideBoom web site (which appears to convert and host Flash movies made with iSpring) if you don't want to host the presentation yourself.

***This post is not security related***