Tuesday, December 16, 2008

Firefox: most vulnerable Windows application


A firm Bit9, who listed 12 most vulnerable applications on windows,has taken Firefox on top of the list.

The browser has earned the reputation from Mozilla patching 10 vulnerabilities which could be used to gain control, access, or execute miscellaneous code via buffer overflow, malformed URI links, javascript, documents and third party tools.

The browser is well respected throughout its open source community. Users can download add-ons, themes and many other tweaks that users can be used to adjust, modify and tweak their browser for maximum performance and appearance.

List of the top 12 vulnerable applications:
  1. Mozilla Firefox
  2. Adobe Flash and Adobe Acrobat
  3. EMC VMware Player,Workstation and other products
  4. Sun Java JDK and JRE, Sun Java Runtime Environment (JRE)
  5. Apple QuickTime, Safari and iTunes
  6. Symantec Norton products (all flavors 2006 to 2008)
  7. Trend Micro OfficeScan
  8. Citrix Products
  9. Aurigma Image Uploader, Lycos FileUploader
  10. Skype
  11. Yahoo Assistant
  12. Microsoft Windows Live (MSN) Messenger

ZoneAlarm 8.0.065.0


ZoneAlarm is an easy-to-use firewall that blocks hackers and other unknown threats.
  • Intrusion Blocking systematically identifies hackers and blocks access attempts.
  • Stealth Mode automatically makes your computer invisible to anyone on the Internet.
  • Automatic Program Configuration provides safety and simplicity by automatically configuring programs. Automatically decides whether to allow or deny Internet access to individual programs.
  • Expert Controls give savvy users precise control over security settings.
This free version is for non-commercial use only.

ZoneAlarm

Saturday, September 13, 2008

Privacy/security breach?IPhone Snaps Everything You Do


What is apple upto? I mean... this is totally a privacy breach for any user who just uses a iPhone because he likes it.

wired.com says
While demonstrating how to break the iPhone's passcode lock in a webcast, iPhone hacker and data-forensics expert Jonathan Zdziarski explained that the popular handset snaps a screenshot of your most recent action -- regardless of whether it's sending a text message, e-mailing or browsing a web page -- in order to cache it. This is purely for aesthetic purposes: When an iPhone user taps the Home button, the window of the application you have open shrinks and disappears. In order to create that shrinking effect, the iPhone snaps a screenshot, Zdziarski said.

The phone presumably deletes the image after you close the application. But anyone who understands data is aware that in most cases, deletion does not permanently remove files from a storage device. Therefore, forensics experts have used this security flaw to gather evidence against criminals convicted of rape, murder or drug deals, Zdziarski said.

"There's no way to prevent it," Zdziarski said during the webcast. "I'm kind of divided on it. I hope Apple fixes it because it's a significant privacy leak, but at the same time it's been useful for investigating criminals."

Now what is that means?It means.. to catch such people,everyone is a suspect?And every user who buys an iPhone will have to suffer such things? This is not the right feature if its breaching your security and privacy.I hope wpple will do something in this regard.

Wednesday, September 3, 2008

Google Chrome - reasons to avoid

This is something really we should consider.I read this on neowin. Google chrome is a big thing these days.Everyone is talking about this small piece. But here users have submitted the flaws and vulnerability in this browser. It talks about what the users must keep in mind before use it because just the name of google. Google has released the thing without the patch for the problems.

Neowin said,
"The first, is the popular "carpet bomb" vulnerability that still exists within Chrome, as pointed out on our forums by our member matessim. This vulnerability allows malicious websites to drive by download and execute programs on your machine. Our visitors may remember the uproar that this same vulnerability caused for Safari users, and that Apple patched the carpet-bombing issue with Safari v3.1.2. Chrome is vulnerable to this exploit because it is based on the same engine, WebKit 525.13, and Google did not patch or update the engine before releasing the software.

The other, and less technical, problem with Chrome exists in its EULA. More specifically, the point that would seem to give Google rights to anything you post on the Internet while using their browser, mostly in conjunction with the promotion of its services."
As the google EULA says,
"By submitting, posting or displaying the content you give Google a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive license to reproduce, adapt, modify, translate, publish, publicly perform, publicly display and distribute any content which you submit, post or display on or through, the services. This license is for the sole purpose of enabling Google to display, distribute and promote the services and may be revoked for certain services as defined in the additional terms of those services."
Which should not be in some browser which is an Open Source piece and expected to be a good software from a reputed company. I mean what google wants to prove?

So please think before you use it without the patch released and about your information sharing with google :).

Wednesday, July 9, 2008

More Security on Gmail now


This is what is expected since long.May be Gmail is safe as we think but excessive usage of Ajax and java script can be injurious to privacy and security!

I read this on gmailblog.They have added support for remote log off now.If you had logged in from another PC last time and forgot to log off,next time it will show you the IP address with a link for more details. On details, you will get more details regarding concurrent access to the account and recent activities.Which will show account type, access type and IP addresses with time of access.

More @ GmailBlog

Saturday, June 7, 2008

Throw it away: Virgin and BPI oposite to illegal downloaders


Virgin Media and the British Phonographic Institute (BPI) are to send warning letters to customers they believe are downloading or distributing music illegally. The announcement represents the first such public deal between the BPI and an ISP.

The pair hope that the new campaign will avoid users risking disconnection and possible legal action.
"Virgin Media's fibre optic broadband is a great platform for people who want to download lots of music,"
said Virgin Media in a statement.
"But we want them to do so without infringing the rights of musicians and music companies."
Customers whose accounts appear to have been used to distribute music in breach of copyright will receive "informative letters" from Virgin Media and the BPI.

What's this? I mean no one is free? This is too much. I mean all the artists and makers of movies and music are already getting much more then they need. They are 'they' because of people like them. People like them because maximum people watch or here them, out of them many are using pirated copies but it makes them more fans. They say they loss money, but i think they got popular with piracy. What you think? If Virgin media is doing this, then what you could download you can understand ;). So better don't use it, throw away it and take some another connection if possible which is not having such crappy rules about how your should use the network after paying much money to keep their mouth shut!

I think all media must be free to public once its out of theaters or published. If they don't like piracy, don't buy bulk pricey expensive DVDs,CDs etc. They made by us, can be fallen by us!

Wha do you think?

More on virgin @ vnunet

Thursday, May 15, 2008

Spammers - new front is social networking sites

Social networking sites have become the new front in the war against spam, according to security watchers.

In the six months leading up to March 2008, social networking sites saw a four-fold growth in the amount of spam on their network. At several major social networking sites, 30 per cent of new accounts created are automated fraudulent 'zombie' accounts, designed to be used for spam and other malicious attacks, according to anti-spam firm Cloudmark.

JF Sullivan, VP of marketing at Cloudmark, said the type of spam advertised through social networks is the same type as that advertised by email spam and punted by much the same people. "There's an implicit trust in social networking. People don't think they're going to be attacked with spam," Sullivan told El Reg. "People don't trust email anymore. Spammers are following peoples' online habits."

Mobile spam, by contrast, is sent by different group of individuals.

Social networking spam can be messages between users or posts to walls or other similar applications. Social network spammers most often hijack accounts using fake log-in pages. Phishing-like tactics, password guessing and the use of Trojans to capture keystrokes are also in play.

Full story @ theRegister

Wednesday, May 14, 2008

Debian and Ubuntu flaw - private SSL/SSH keys guessable


The Debian Security Advisory posted up DSA-1571-1 openssl -- predictable random number generator issue today and strongly advised its users to take steps to avoid possible compromising of any systems running on Debian, such as Ubuntu.

The researcher Luciano Bello discovered a security flaw in Debian's random number generator that allows to predict a random generated number. This is caused by an incorrect Debian change to the openssl package. As a result, cryptographic key material may be guessable.

This problem not only affects Debian, but also all its derivatives, such as Ubuntu.

It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on affected systems is recreated from scratch. Furthermore, all DSA keys ever used on affected systems for signing or authentication purposes should be considered compromised.

Via: debian.org

Thursday, May 8, 2008

Bluetooth: A risk for privacy!


Worried about your civil liberties and privacy? Then it may come as a shock to discover that you have unwittingly been allowing your phone to signal your every move.

Bluetooth, a wireless link built into many cellphones, makes our movements trackable by anyone equipped with a PC and an appropriate receiver. Vassilis Kostakos at the University of Bath in the UK placed four Bluetooth receivers in the city's centre. Over four months, his team tracked 10,000 Bluetooth phones and was able to "capture and analyse people's encounters" in pubs, streets and shops.

Bluetooth is now more of a privacy threat than the more frequently publicised RFID chips, Kostakos says.
"If people are worried, they should turn off the Bluetooth function on their mobile phones."
via NewScientistTech

Tuesday, April 29, 2008

Microsoft Web Servers Hacked

Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government -- have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors' machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft's Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn't aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they'd heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn't offer much more information.

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

Washington Post

Saturday, April 19, 2008

MPAA sues website linking to pirated media

The Motion Picture Association of America (MPAA) has sued Pullmylink.com, a website featuring links to free - and allegedly pirated - movies and TV shows, claiming the site promotes and profits from copyright infringement. The lawsuit is the seventh action filed by the MPAA against content aggregators in the US since late last year and is part of a larger anti-piracy campaign that included a criminal raid on the UK headquarters of the website TV Links. The campaign against sites that link to, but do not host, illegal content has raised some eyebrows with critics asking why the association doesn’t go after the host sites or search engines such as Google, which owns video sharing site YouTube.
“...Is the message that it’s less criminal to host illegal content on YouTube than it is to link to it from a site such as TV Links?...”
Guardian technology columnist Jack Schofield wrote in the wake of the MPAA-directed raid on TV Links in October.


rlsLog.net

Tuesday, April 1, 2008

Sony BMG Sued for Software Piracy!

Sony BMG, a company known for enforcing its intellectual property rights, is now facing the other end of an Intellectual Property related lawsuit. A report (French) says the complaining company, PointDev, seized some of Sonys assets which revealed that the pirated software appeared on four of their servers.

PointDev, a small software company, mandated a bailiff to raid one of Sony BMGs owned building in January this year. The raid revealed that four of the Sony BMGs owned servers contained the pirated software.

It appears as though the company discovered this when an IT department employee requested assistance for the use of a product called Ideal Migration. When technical support looked into the case, they discovered that the key used to activate the software was a pirated version.

Essentially, the PointDev CEO says that the BSA has said that French Corporations have a software piracy rate of 47%. The CEO also says that piracy may even be a part of Sony's business policy - if you can't afford it, pirate it. It is said that Sony was in the process of merging with BMG when the pirating incident occurred.

An additional report (French) (Google Translation) says that the CEO of PointDev wants to make this piracy case an example.

Sony told La Province to not report on the ongoing investigation. Clearly, Sony is not happy that this case was made public at all.

via zeropaid.com

Saturday, March 29, 2008

Apple Mac hacked!

The fastest $10,000 Charlie Miller ever earned!

He took the first of three laptop computers -- and a $10,000 cash prize -- Thursday after breaking into a MacBook Air at the CanSecWest security conference's PWN 2 OWN hacking contest.

Show organizers offered a Sony Vaio, Fujitsu U810, and the MacBook as prizes, saying that they could be won by anybody at the show who could find a way to hack into each of them and read the contents of a file on the system using a previously undisclosed "0day" attack.

Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on. He was the first contestant to attempt an attack on any of the systems.

Miller was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug until the contest's sponsor, TippingPoint, can notify the vendor. Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.

yahoo news

Thursday, March 27, 2008

Flaws in Safari browser for Windows


We had just a discussion on this that its not as good and FF3 and stick to FF3 is better, this is what i found today.

An Argentinian security researcher has discovered two flaws in Apple's Safari for Windows browser. Juan Pablo Lopez Yacubian said the vulnerabilities could allow hackers to remotely take control of a victim's computer.

He described the most serious flaw as a vulnerability in the Safari 3.1 browser for Windows which allows a hacker to “falsify the web address and enter another page or content".

This essentially means that even though you see a trusted URL in the browser address bar, the web page could be displaying unauthorized content that could put your PC at risk.

webUser.co.uk

Wednesday, March 12, 2008

TrueCrypt 5.1


What's New in version 5.1:

New features:

  • Support for hibernation on computers where the system partition is encrypted (previous versions of TrueCrypt prevented the system from hibernating when the system partition was encrypted). (Windows Vista/XP/2008/2003)
  • Ability to mount a partition that is within the key scope of system encryption without pre-boot authentication (for example, a partition located on the encrypted system drive of another operating system that is not running). (Windows Vista/XP/2008/2003)

    Note: This can be useful e.g. when there is a need to back up or repair an operating system encrypted by TrueCrypt (from within another operating system).
  • Command line options for creating new volumes. (Linux and Mac OS X)
Improvements:
  • Increased speed of AES encryption/decryption (depending on the hardware platform, by 30-90%). (Windows)
  • Faster booting when the system partition is encrypted. (Windows Vista/XP/2008/2003)
  • When the system partition/drive is encrypted, the TrueCrypt Boot Loader is now stored in a compressed form and is, therefore, smaller. If a non-cascade encryption algorithm is used (i.e., AES, Serpent, or Twofish), the TrueCrypt Boot Loader is now small enough so that a backup of the TrueCrypt Boot Loader can be (and is) stored in first drive cylinder. Whenever the TrueCrypt Boot Loader is damaged, its backup copy is run automatically instead.

    As a result of this improvement, the following problem will no longer occur: Certain inappropriately designed activation software (used for activation of some third-party software) writes data to the first drive cylinder, thus damaging the TrueCrypt Boot Loader. The affected users had to use the TrueCrypt Rescue Disk to repair the TrueCrypt Boot Loader. This will no longer be necessary after upgrading to this version of TrueCrypt (provided that the system partition/drive is encrypted using a non-cascade encryption algorithm, i.e., AES, Serpent, or Twofish).

    Note: If your system partition/drive is currently encrypted using a non-cascade encryption algorithm (i.e., AES, Serpent, or Twofish), a backup copy of the TrueCrypt Boot Loader will be automatically stored in the first drive cylinder when you upgrade to this version of TrueCrypt.
  • The minimum memory requirements for the TrueCrypt Boot Loader have been reduced from 42 KB to 27 KB (twenty-seven kilobytes). This allows users to encrypt system partitions/drives on computers where the BIOS reserves a large amount of memory. (Windows Vista/XP/2008/2003)
  • Many other minor improvements. (Windows, Mac OS X, and Linux)
Resolved incompatibilities:
  • On some computers, when performing the system encryption pretest, Windows failed to display the log-on screen. This will no longer occur. (Windows Vista/XP/2008/2003)
Bug fixes:
  • On some systems, drive letters were not correctly assigned to newly mounted non-system volumes. This will no longer occur. (Windows)
  • Many other minor bug fixes. (Windows, Mac OS X, and Linux)
TrueCrypt.org

Security hack: Developer's Backdoor Hack in G-Archiver for GMail


A serious Gmail account hacking backdoor, has been found in the popular Gmail archiving software G-Archiver. This application, in all its innocence, allows you to download and backup all emails from your GMail account. But apparently the developer included the code to send an email to his email ID with all usernames and passwords!

G-Archiver has posted this explanation of what happened: "It is urgent that you remove the current version of G-Archiver from your computer, and change your Gmail account password right away. What happened was that a member of our development team had inserted coding used for testing G-Archiver in the debug version and forgot to delete it in the final release version."

winVistaClub

Monday, March 10, 2008

New Camera Can See Through Clothes

British company ThruVision has developed a new camera, the T5000, that can detect weapons, drugs or explosives hidden under people's clothes from up to 25 meters away in what could be a breakthrough for the security industry. The camera uses "passive imaging technology" to identify objects by the natural electromagnetic rays -- known as Terahertz or T-rays -- that they emit. The technology works on the basis that all people and objects emit low levels of electromagnetic radiation. Terahertz rays lie somewhere between infrared and microwaves on the electromagnetic spectrum and travel through clouds and walls.

The high-powered camera can detect hidden objects from up to 80 feet away and is effective even when people are moving. It does not reveal physical body details and the screening is harmless, the company says. "Acts of terrorism have shaken the world in recent years and security precautions have been tightened globally," said Clive Beattie, the chief executive of ThruVision. "The ability to see both metallic and non-metallic items on people out to 25 meters is certainly a key capability that will enhance any comprehensive security system."

Reuters.com

Thursday, February 21, 2008

News: Pirate Bay to buy country 'seaLand'

Notorious file-sharing site The Pirate Bay is planning to buy its own country and turn it into a copyright-free piracy paradise.

Currently based in Sweden, The Pirate Bay uses BitTorrent technology to let visitors share videos, games, software and music - mostly without each work's copyright holder's permission.

This week it launched Buy Sealand, a campaign to buy the former World War 2 gun platform now known as the Principality of Sealand, located six miles from the UK coast.

The island is reportedly for sale after its infrastructure was badly damaged by fire in summer 2006.

The Pirate Bay plans to fund the £100 million sale through donations from users who will automatically become citizens of the principality.

"It should be a great place for everybody, with high-speed Internets [sic] access, no copyright laws and VIP accounts to The Pirate Bay," the group said in a statement on the buysealand.com website.

If the bid for Sealand fails, The Pirate Bay plans to look elsewhere. "We will try to buy another small island somwhere [sic] and claim it as our own country," it stated.

Wednesday, February 20, 2008

Reviews: LockCrypt 1.18

LockCrypt is a free account management program written in Java. It uses high strength AES encryption to encrypt your data, so only you can access it. 1.18 adds different views and a menu option to reset all settings (incase you forget the password).

Changes in LockCrypt 1.18
  • Added wizard which loads on first run to configure database and passwords.
  • Added different views: Large icons, Small icons, List or Tiles.
  • Added Split Pane to main window to allow resizing.(Thanks Mercury52)
  • Added created and last modified fields for accounts (Thanks Mercury52)
  • Added menu option to clear all preferences.
  • Changed: Scrolling behaviour when showing a group.

LockCrypt Mobile, a J2ME version is also available. It allows you to carry your account database with you on any Java enabled mobile device.

LockCrypt.com

Bugged by Virus??

So lately you suffered a computer crash and a headache of course due to a virus intrusion or a spyware. So people ask me what are the ways to avoid that. Here are some of the basic steps that everyone should follow to prevent such an intrusion.

1) Install a reputed antivirus software.

2) Upgrade your Internet Explorer to version 7

3) Use Firfox browser for increased security.

4) Regularly install windows update and keep it on.

5) Run liveupdate on your antivirus and put it on automatic update mode.

Read the complete article here: TechJunkies

(Sam is a Certified Ethical Hacker who blogs at TechJunkies)