Tuesday, July 15, 2008
Facebook and Privacy Issues
Lately there's been a lot of news about Facebook using personal details for profit and now Canada's federal privacy commissioner has launched an investigation into Facebook. Apparently four students complained that the popular Web site violates Canadian law by disclosing personal information to advertisers without proper consent.
This in turn reminded me of a wonderful YouTube video - definitely worth watching and passing on to your less security-aware friends and family! - source Pete Wood.
Anti-Virus softwares are vulnerable itself...
A recent ZDnet blog discusses a large number of vulnerabilities German research team N.Runs says it found in anti malware products from nearly every vendor. The ZDNet posting includes scary graphs to frighten users of security products.
If anti-virus softwares are vulnerable to security exploits then how someone can rely on anti-virus products? I guess, we soon need to look for anti-vulnerable software and then we might need anti-virus software.
Anti-virus companies should focus on overall security of their software rather then just increasing the prices for updating virus definitions and marketing of their products.
Please refer here for much more detail response on the subject by McAfee.
Monday, July 14, 2008
Mobile Malware next thing to watch out!!
Mobile malware not yet a risk but companies told to prepare
Security risks to mobile devices such as mobile phones, smartphones and personal digital assistants (PDA) are not yet a major issue these days compared to the 1980s when computer networks were once vulnerable to such threats.
However, a security expert said companies should nonetheless be prepared just in case criminal elements, such as hackers, may beat them to it and steal valuable company information usually made available to corporate mobile workers.
The security expert said malware and viruses currently attacking mobile devices are usually simple nuisance viruses, such as those which can freeze the operating system (OS) or change the user’s preferences.
Refer to here for further details.
Thursday, July 10, 2008
XP SP3 will be rolled out soon!
Microsoft is going to release Windows XP Service Pack (SP) 3 via its Automatic Update (AU) service on Thursday July 10, company officials confirmed this week.
The client team has been vague about when it planned to push the latest version of XP to users. “Early summer” and “sometime soon” were favorite comebacks when officials were asked for an AU timeframe for SP3.
Customers who have automatic updates turned on but who don’t want XP SP3 to be downloaded to user desktops this week — for whatever reasons — need to deploy the Microsoft Service Pack blocker toolkit to delay pushed-delivery of SP3. While Microsoft will begin pushing SP3 tomorrow, not all users will receive it immediatly, as the company will be staggering the rollout.
Spammers prefer Gmail Accounts
An examination of spam originating from the major free e-mail providers shows that like consumers, spammers prefer Google.
In a three-week period from mid-June to this month, e-mail filtering firm Roaring Penguin said it saw an explosion of spam originating from Gmail, while Microsoft Hotmail and Yahoo Mail remained flat.
The company attributes this meteoric rise in Gmail spam to the cracking of Google's CAPTCHA. A CAPTCHA (define) is a test, typically used in Web site registration, that is designed to tell humans apart from programs designed to hack or automate registrations. It consists of a word displayed in such a way that it's difficult for a computer to read, but not a human. A user would be able to successfully enter the word into an input box to gain entry.
Tuesday, July 8, 2008
Universal Forensic Extraction Device (UFED)
Inside and outside government, professionals increasingly carry data on their cell phones, including e-mail messages, documents, videos and instant messages. And there are those — such as law enforcement officers, some employers and, yes, hackers — who want to get at that data without the owner’s permission.
Until recently, however, the tools to do that weren’t available. A handful of PC-based programs have been able to extract data from selected cell phone models, but special challenges face those who deliver powerful forensic tools.
The biggest one is that there are hundreds of models of cell phones, with manufacturers adding dozens of new ones each year. And all those models employ a wide array of BIOS versions, operating systems and software. The other nut to crack is portability. Cell phones are, of course, extremely portable. But if you need to plug one into a computer equipped with forensic software, extracting data in the field or without the owner’s knowledge can be problematic.
Please refer here for more details.
Protect your Gmail Account
Your email account can contain a lot of personal information, from bank alerts to love letters. Email that, I'm sure, you don't always want other people to see. We understand how important your Gmail accounts are to you, so we're adding a new layer of information and control. With this new feature, you can now track your recent sessions and you can also sign yourself out remotely.
If you are anything like me, you probably sign in to Gmail from multiple computers. I, for example, occasionally sign into my Gmail account from a friend's house when I need to check an important email. Usually I remember to sign out, but every once in a while I wonder if I really did. Now I no longer have to wonder.
At the bottom of your inbox, you'll see information about the time of the last activity on your account and whether it's still open in another location.
Please refer to gmail's blog for more information.
Sunday, July 6, 2008
Wireshark and TShark network tools
The new version 1.0.1 of the Wireshark network analysis tool and its command line variant TShark, remedy a number of security problems. Bugs in previous versions in the analysis modules for GSM messages, PANA, KISMET, and RTMPT packets as well as syslog messages, made it possible for attackers to crash the program. According to the developer advisory, the RMI module would even reveal some contents of the RAM to attackers.
The advisory states that the vulnerabilities are also present in Ethereal. Up to version 0.99, Ethereal was the original name of the Wireshark project. For users that cannot update to the newest version, the developers recommend deactivating the affected module.
I.E 8 with much better security features
Microsoft is planning to add a series of new security features to the next version of its Internet Explorer browser, including protection against cross-site scripting attacks.
A beta version of IE 8 is due out in August, and along with the XSS filter, it will include a filter designed to provide better protection against phishing attacks, features that make it easier for developers to request resources and share information across domains, and some changes to the way that ActiveX controls are handled by the browser. Specifically, developers will be able to write controls that are only available for the individual user who downloads them.
The announcement of the new security features in IE 8 came just a week after the release of Firefox 3, the latest version of IE's main competition in the browser world. Firefox 3 also includes updated antimalware and antiphishing capabilities and several other security updates. Microsoft has been fighting to repair the security reputation of IE for several years, since the initial release of Firefox, which the Mozilla Foundation has positioned as a more secure alternative to IE.
Thursday, July 3, 2008
PINS can leak while in transit....
ATM breach reveals PIN problems
Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.
The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.
The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.
Please refer here to read full details.
SSL Blacklist Service - Free of charge
Working closely with the German hosting company – manitu, heise is making available with immediate effect a realtime DNS-based blacklist service for identifying weak SSL keys. The provider already runs the Realtime Blacklist for the iX spam filter NiX Spam, which enables mail servers to identify and filter spam.
The principle of a DNS realtime blacklist is as simple as it is elegant. An application makes a DNS enquiry for
The SHA1 hash value from the certificate's modulus of the RSA key is used as the host name. All tests for weak SSL certificates use a similar fingerprinting, including the Debian Tools openssl-vulnkey and the heise networks SSL tests. The lists log keys with 512, 1024, 2048 and 4096-bits, both for 32- and 64-bit systems and little- or big-endian architectures.
Full article can be read from here.
Tuesday, July 1, 2008
Coffee Machine is hackable, Amazing things in amazing world...
Craig Wright, my classmate and a risk advisory services manager at professional services firm BDO, has discovered security holes in his internet-connected coffee maker that could allow a remote attacker to not only take over his Windows XP-based PC but also make his coffee too weak.
He found several security holes, including a buffer overflow in the internet connection software that links his Jura F90 coffee maker to his PC.
Once connected to the internet, the high-end coffee maker, which retails for nearly US$2,000 on Amazon, lets you do things like set the strength of your coffee and get remote diagnostic help over the internet without having to send the appliance in for service.
Wright posted the information on the vulnerabilities, and the fact that there is no patch available yet, to the BugTraq security e-mail list on Tuesday.
"I don't know if many people would target this particular vulnerability because there probably are not a lot of coffee makers at the moment that are internet-connected, and in my case it's behind a firewall," he said.
However, internet-connected appliances are the wave of the future. There is already an internet-connected refrigerator, at least one prototype of a Web-enabled oven, and pilot tests for dryers and water heaters.
Eventually "you'll be able to turn on your oven with your mobile phone" and a malicious hacker could wind up burning the house down, Wright said.
Further article can be read from here.
VOIP Calls are tappable....
A common compression technique can make internet telephone calls significantly more susceptible to bugging, according to recent research from Johns Hopkins University.
Internet telephony has become widely used through consumer-centric applications such as Skype, and is becoming more common in enterprises.
The new research suggests, however, that standard encryption and compression methods, when used together, are not sufficiently secure. VoIP calls are commonly encrypted using a technique that preserves the lengths of voice patterns in the original, unencrypted conversation, the researchers said.
Please click here to read full article.
Identity Theft and Financial Fraud
Unisys Security Index Reveals Identity Theft and Financial Fraud Remain Top Global Concerns for Consumers
Fears about identity theft and financial fraud are top global concerns for consumers, according to the latest results of the Unisys Security Index.
Identity theft is the primary security concern cited among respondents in nine out of 14 countries, while misuse of credit or debit card information ranks as the first or second greatest fear in 12 out of the 14 countries.
Source - Earth Times , press release
As i always say, we really need to be careful about our Identity. We need to make sure who we are giving our details are legitimate people. I would prefer giving out less details on social networking websites if you use one and make sure you only add those users who are really your friends.
iSpring - Cool Utility
Windows only: Freeware PowerPoint plug-in iSpring converts your PowerPoint presentation to an interactive Flash video with the click of a button. Not only is iSpring a great way to make your PowerPoint presentation more portable (not everyone has PowerPoint, after all), but as Digital Inspiration points out, an exported movie even preserves all of your slide transitions, animations, and hyperlinks.
iSpring is freeware, Windows only, works with PowerPoint 2000 through 2007.
Alternately, you can upload any presentation directly to the SlideBoom web site (which appears to convert and host Flash movies made with iSpring) if you don't want to host the presentation yourself.
***This post is not security related***