Saturday, September 13, 2008

Privacy/security breach?IPhone Snaps Everything You Do


What is apple upto? I mean... this is totally a privacy breach for any user who just uses a iPhone because he likes it.

wired.com says
While demonstrating how to break the iPhone's passcode lock in a webcast, iPhone hacker and data-forensics expert Jonathan Zdziarski explained that the popular handset snaps a screenshot of your most recent action -- regardless of whether it's sending a text message, e-mailing or browsing a web page -- in order to cache it. This is purely for aesthetic purposes: When an iPhone user taps the Home button, the window of the application you have open shrinks and disappears. In order to create that shrinking effect, the iPhone snaps a screenshot, Zdziarski said.

The phone presumably deletes the image after you close the application. But anyone who understands data is aware that in most cases, deletion does not permanently remove files from a storage device. Therefore, forensics experts have used this security flaw to gather evidence against criminals convicted of rape, murder or drug deals, Zdziarski said.

"There's no way to prevent it," Zdziarski said during the webcast. "I'm kind of divided on it. I hope Apple fixes it because it's a significant privacy leak, but at the same time it's been useful for investigating criminals."

Now what is that means?It means.. to catch such people,everyone is a suspect?And every user who buys an iPhone will have to suffer such things? This is not the right feature if its breaching your security and privacy.I hope wpple will do something in this regard.

Wednesday, June 11, 2008

Don't use safari on windows: Research says

We all know about safari on windows since the last release of it. Many articles has been written on that and apple has done patches also. But still something remains :). Read this, and you will surely not use safari on windows.

A researcher has created a proof-of-concept site that graphically demonstrates the risk Windows users face when using Apple's Safari browser. Microsoft's security team already warned that a "blended threat" was so serious that Windows users should curtail their use of Safari until a security patch is available. Blog post from researcher Liu Die Yu makes it clear the warning was by no means overstated.

Clicking on this link with Safari using default settings automatically downloads a booby-trapped file onto a Windows user's desktop with no prompting. The next time the user opens Internet Explorer, the force-fed file automatically causes the notepad.exe application to launch and open a non-existent file. Of course, miscreants could choose far more nefarious code.

When informed that its browser downloads files with no prompting, Apple said it may get around to changing this behavior at some point. In other words, this is no big deal from a security perspective, so let's all move on.

The Register

Saturday, June 7, 2008

Throw it away: Virgin and BPI oposite to illegal downloaders


Virgin Media and the British Phonographic Institute (BPI) are to send warning letters to customers they believe are downloading or distributing music illegally. The announcement represents the first such public deal between the BPI and an ISP.

The pair hope that the new campaign will avoid users risking disconnection and possible legal action.
"Virgin Media's fibre optic broadband is a great platform for people who want to download lots of music,"
said Virgin Media in a statement.
"But we want them to do so without infringing the rights of musicians and music companies."
Customers whose accounts appear to have been used to distribute music in breach of copyright will receive "informative letters" from Virgin Media and the BPI.

What's this? I mean no one is free? This is too much. I mean all the artists and makers of movies and music are already getting much more then they need. They are 'they' because of people like them. People like them because maximum people watch or here them, out of them many are using pirated copies but it makes them more fans. They say they loss money, but i think they got popular with piracy. What you think? If Virgin media is doing this, then what you could download you can understand ;). So better don't use it, throw away it and take some another connection if possible which is not having such crappy rules about how your should use the network after paying much money to keep their mouth shut!

I think all media must be free to public once its out of theaters or published. If they don't like piracy, don't buy bulk pricey expensive DVDs,CDs etc. They made by us, can be fallen by us!

Wha do you think?

More on virgin @ vnunet

Thursday, June 5, 2008

Firefox tweaking for Broadband

By default, Firefox is optimized for dial up connection. You can change the browser settings so that it can be used to browse with DSL or cable or other broadband links. In order to change the settings, first you need to edit config file. Type about:config in the address bar and press enter. Then enter network.http in the filter field and enter the following changes.


  1. Double click on ‘network.http.pipelining’ and set the value to true.
  2. Double click on 'network.http.pipelining.maxrequests’ and in the dialog box enter a higher value than the default value 4. 15 is an ideal value.
  3. Double click on ‘network.http.proxy.pipelining’ and set the value to true.
  4. Right click on the page and select New->Integer. Enter nglayout.initialpaint.delay and then click ok. Set the integer value of this to 0 and click ok.

Thursday, May 15, 2008

Spammers - new front is social networking sites

Social networking sites have become the new front in the war against spam, according to security watchers.

In the six months leading up to March 2008, social networking sites saw a four-fold growth in the amount of spam on their network. At several major social networking sites, 30 per cent of new accounts created are automated fraudulent 'zombie' accounts, designed to be used for spam and other malicious attacks, according to anti-spam firm Cloudmark.

JF Sullivan, VP of marketing at Cloudmark, said the type of spam advertised through social networks is the same type as that advertised by email spam and punted by much the same people. "There's an implicit trust in social networking. People don't think they're going to be attacked with spam," Sullivan told El Reg. "People don't trust email anymore. Spammers are following peoples' online habits."

Mobile spam, by contrast, is sent by different group of individuals.

Social networking spam can be messages between users or posts to walls or other similar applications. Social network spammers most often hijack accounts using fake log-in pages. Phishing-like tactics, password guessing and the use of Trojans to capture keystrokes are also in play.

Full story @ theRegister

Wednesday, May 14, 2008

Blogger: Most visited posts widget script...

This script finds your most visited posts and gives you back theresult in html.I found this from bloggerbuster and it uses pipes.yahoo.com to get the ratings.
So now you don't need to put your features post links.Just put the script in new widget,change the url,change the number of posts you want to show, and done!
<script type="text/javascript">
function pipeCallback(obj) {
document.write('<font ><ol style="text-transform: capitalize;">');
var i;
for (i = 0; i < obj.count ; i++)
{
var href = "'" + obj.value.items[i].link + "'";
var item = "<li>" + "<a href=" + href + ">" + obj.value.items[i].title + "</a> </li>";
document.write(item);
}
document.write('</ol></font>');
}
</script>
<script src="http://pipes.yahoo.com/pipes/pipe.run?_render=json&_callback=pipeCallback
&_id=1cf38ae68efbe859c4ba1ee239cec099&url=http%3A%2F%2Fwww.techlads.com&num=10" type="text/javascript"></script>

In the url, only below part is important. Change the url to your one and change the num param to what you want.I made it only top 10 posts.
url=http://www.techlads.com&num=10

Debian and Ubuntu flaw - private SSL/SSH keys guessable


The Debian Security Advisory posted up DSA-1571-1 openssl -- predictable random number generator issue today and strongly advised its users to take steps to avoid possible compromising of any systems running on Debian, such as Ubuntu.

The researcher Luciano Bello discovered a security flaw in Debian's random number generator that allows to predict a random generated number. This is caused by an incorrect Debian change to the openssl package. As a result, cryptographic key material may be guessable.

This problem not only affects Debian, but also all its derivatives, such as Ubuntu.

It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on affected systems is recreated from scratch. Furthermore, all DSA keys ever used on affected systems for signing or authentication purposes should be considered compromised.

Via: debian.org

Thursday, May 8, 2008

TorrentSpy must pay $110 million to MPAA

A clear message to all torrent websites hosted on the US soil was sent all over the world today: A federal judge is hitting the shuttered TorrentSpy service with a $111 million penalty for facilitating the infringement of thousands of copyrighted works. U.S. District Judge Florence -Marie Cooper in Los Angeles, ruling in a case brought by the Motion Picture Association of America, said site operator Justin Bunnell and associates must pay the maximum $30,000 for "each of the 3,699 infringements shown." The case, producing what is among the largest fines in copyright history, was bolstered after the MPAA allegedly paid a hacker $15,000 for internal TorrentSpy e-mails and correspondence.

via rlsLog

Bluetooth: A risk for privacy!


Worried about your civil liberties and privacy? Then it may come as a shock to discover that you have unwittingly been allowing your phone to signal your every move.

Bluetooth, a wireless link built into many cellphones, makes our movements trackable by anyone equipped with a PC and an appropriate receiver. Vassilis Kostakos at the University of Bath in the UK placed four Bluetooth receivers in the city's centre. Over four months, his team tracked 10,000 Bluetooth phones and was able to "capture and analyse people's encounters" in pubs, streets and shops.

Bluetooth is now more of a privacy threat than the more frequently publicised RFID chips, Kostakos says.
"If people are worried, they should turn off the Bluetooth function on their mobile phones."
via NewScientistTech

Tuesday, April 29, 2008

Microsoft Web Servers Hacked

Hundreds of thousands of Web sites - including several at the United Nations and in the U.K. government -- have been hacked recently and seeded with code that tries to exploit security flaws in Microsoft Windows to install malicious software on visitors' machines.

The attackers appear to be breaking into the sites with the help of a security vulnerability in Microsoft's Internet Information Services (IIS) Web servers. In an alert issued last week, Microsoft said it was investigating reports of an unpatched flaw in IIS servers, but at the time it noted that it wasn't aware of anyone trying to exploit that particular weakness.

On Thursday, Spanish anti-virus vendor Panda Security said that it had alerted Microsoft that a flaw IIS was the cause of all the break-ins. When I asked Microsoft whether they'd heard from Panda or if the hundreds of thousands of sites were hacked from a patched or unpatched flaw in IIS, a spokesman for the company didn't offer much more information.

According to Finnish anti-virus maker F-Secure, the number of hacked Web pages serving up malicious software from this attack may be closer to half a million.

Washington Post

Tuesday, April 1, 2008

Sony BMG Sued for Software Piracy!

Sony BMG, a company known for enforcing its intellectual property rights, is now facing the other end of an Intellectual Property related lawsuit. A report (French) says the complaining company, PointDev, seized some of Sonys assets which revealed that the pirated software appeared on four of their servers.

PointDev, a small software company, mandated a bailiff to raid one of Sony BMGs owned building in January this year. The raid revealed that four of the Sony BMGs owned servers contained the pirated software.

It appears as though the company discovered this when an IT department employee requested assistance for the use of a product called Ideal Migration. When technical support looked into the case, they discovered that the key used to activate the software was a pirated version.

Essentially, the PointDev CEO says that the BSA has said that French Corporations have a software piracy rate of 47%. The CEO also says that piracy may even be a part of Sony's business policy - if you can't afford it, pirate it. It is said that Sony was in the process of merging with BMG when the pirating incident occurred.

An additional report (French) (Google Translation) says that the CEO of PointDev wants to make this piracy case an example.

Sony told La Province to not report on the ongoing investigation. Clearly, Sony is not happy that this case was made public at all.

via zeropaid.com

Saturday, March 29, 2008

Apple Mac hacked!

The fastest $10,000 Charlie Miller ever earned!

He took the first of three laptop computers -- and a $10,000 cash prize -- Thursday after breaking into a MacBook Air at the CanSecWest security conference's PWN 2 OWN hacking contest.

Show organizers offered a Sony Vaio, Fujitsu U810, and the MacBook as prizes, saying that they could be won by anybody at the show who could find a way to hack into each of them and read the contents of a file on the system using a previously undisclosed "0day" attack.

Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on. He was the first contestant to attempt an attack on any of the systems.

Miller was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug until the contest's sponsor, TippingPoint, can notify the vendor. Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.

yahoo news

Thursday, March 27, 2008

Flaws in Safari browser for Windows


We had just a discussion on this that its not as good and FF3 and stick to FF3 is better, this is what i found today.

An Argentinian security researcher has discovered two flaws in Apple's Safari for Windows browser. Juan Pablo Lopez Yacubian said the vulnerabilities could allow hackers to remotely take control of a victim's computer.

He described the most serious flaw as a vulnerability in the Safari 3.1 browser for Windows which allows a hacker to “falsify the web address and enter another page or content".

This essentially means that even though you see a trusted URL in the browser address bar, the web page could be displaying unauthorized content that could put your PC at risk.

webUser.co.uk

Monday, March 24, 2008

Advanced WindowsCare 3 Beta 1

This comprehensive PC-care utility has a one-click approach to helping protect, repair and optimize your PC. Advanced WindowsCare Personal Edition helps protect, optimize, and repair your PC –– with daily use.

Features:

* Ending slow downs, freezes, crashes, and security threats.
* Scanning and finding what other utilities miss on your PC.
* Keeping your PC error-free and running more smoothly than ever.
* Designed for Windows Vista, XP, and 2000.
* Over 10,000,000 downloads since 2006.
* Availability is free of charge for private use.
* Plus, Advanced WindowsCare Personal is 100% safe and clean with no adware, spyware, or viruses.

What's New:
* New Features, New Interface, New Functions
* Improved Scanning, Cleaning, Repairing, and Optimizing
* Triple Backup Mechanism
* Faster Loading

Home Page

Wednesday, March 12, 2008

Security hack: Developer's Backdoor Hack in G-Archiver for GMail


A serious Gmail account hacking backdoor, has been found in the popular Gmail archiving software G-Archiver. This application, in all its innocence, allows you to download and backup all emails from your GMail account. But apparently the developer included the code to send an email to his email ID with all usernames and passwords!

G-Archiver has posted this explanation of what happened: "It is urgent that you remove the current version of G-Archiver from your computer, and change your Gmail account password right away. What happened was that a member of our development team had inserted coding used for testing G-Archiver in the debug version and forgot to delete it in the final release version."

winVistaClub

Thursday, February 21, 2008

News: Pirate Bay to buy country 'seaLand'

Notorious file-sharing site The Pirate Bay is planning to buy its own country and turn it into a copyright-free piracy paradise.

Currently based in Sweden, The Pirate Bay uses BitTorrent technology to let visitors share videos, games, software and music - mostly without each work's copyright holder's permission.

This week it launched Buy Sealand, a campaign to buy the former World War 2 gun platform now known as the Principality of Sealand, located six miles from the UK coast.

The island is reportedly for sale after its infrastructure was badly damaged by fire in summer 2006.

The Pirate Bay plans to fund the £100 million sale through donations from users who will automatically become citizens of the principality.

"It should be a great place for everybody, with high-speed Internets [sic] access, no copyright laws and VIP accounts to The Pirate Bay," the group said in a statement on the buysealand.com website.

If the bid for Sealand fails, The Pirate Bay plans to look elsewhere. "We will try to buy another small island somwhere [sic] and claim it as our own country," it stated.

Wednesday, February 20, 2008

Bugged by Virus??

So lately you suffered a computer crash and a headache of course due to a virus intrusion or a spyware. So people ask me what are the ways to avoid that. Here are some of the basic steps that everyone should follow to prevent such an intrusion.

1) Install a reputed antivirus software.

2) Upgrade your Internet Explorer to version 7

3) Use Firfox browser for increased security.

4) Regularly install windows update and keep it on.

5) Run liveupdate on your antivirus and put it on automatic update mode.

Read the complete article here: TechJunkies

(Sam is a Certified Ethical Hacker who blogs at TechJunkies)

Monday, February 18, 2008

News: Linux kernel bugs discovered

Security researchers have uncovered "critical" security flaws in a version of the Linux kernel used by a large number of popular distributions. The three bugs allow unauthorized users to read or write to kernel memory locations or to access certain resources in certain servers, according to a SecurityFocus advisory.

They could be exploited by malicious, local users to cause denial of service attacks, disclose potentially sensitive information, or gain "root" privileges, according to security experts. The bug affects all versions of the Linux kernel up to version 2.6.24.1, which contains a patch. Distributions such as Ubuntu, Turbolinux, SuSE, Red Hat, Mandriva, Debian and others are affected. The problems are within three functions in the system call fs/splice.c, according to an advisory from Secunia.

Saturday, February 16, 2008

What is svchost.exe And Why Is It Running?

You are no doubt reading this article because you are wondering why on earth there are nearly a dozen processes running with the name svchost.exe. You can't kill them, and you don't remember starting them… so what are they?

So What Is It?

According to Microsoft: "svchost.exe is a generic host process name for services that run from dynamic-link libraries". Could we have that in english please?

Some time ago, Microsoft started moving all of the functionality from internal Windows services into .dll files instead of .exe files. From a programming perspective this makes more sense for reusability… but the problem is that you can't launch a .dll file directly from Windows, it has to be loaded up from a running executable (.exe). Thus the svchost.exe process was born.

Why Are There So Many svchost.exes Running?

If you've ever taken a look at the Services section in control panel you might notice that there are a Lot of services required by Windows. If every single service ran under a single svchost.exe instance, a failure in one might bring down all of Windows… so they are separated out.

Those services are organized into logical groups, and then a single svchost.exe instance is created for each group. For instance, one svchost.exe instance runs the 3 services related to the firewall. Another svchost.exe instance might run all the services related to the user interface, and so on.

So What Can I Do About It?

You can trim down unneeded services by disabling or stopping the services that don't absolutely need to be running. Additionally, if you are noticing very heavy CPU usage on a single svchost.exe instance you can restart the services running under that instance.

The biggest problem is identifying what services are being run on a particular svchost.exe instance…

More @ howToGeek.com

Thursday, February 14, 2008

year 2038 problem: Y2K38 Bug has started...!

On January 19, 2038, UNIX-based programs and UNIX-like operating systems will run out of time. To be more precise, at 3:14:07 GMT, UNIX will be exactly 1 billion seconds old. Many see this as a milestone, but from a technical point of view, this can mean disaster for computer programs and systems around the world.

UNIX keeps track of time in a 4-byte integer that represents the number of seconds after January 1, 1970 12:00:00.
For example, a time of 60 represents the date January 1, 1970 12:01:00. A 4-byte integer has a maximum value of 2,146,483,547. This time (known as maximum time) corresponds exactly to January 19, 2038 3:14:07. This explains why UNIX programs in large, were pretty much unaffected by the Y2K bug - since it kept track of time in units of seconds. However, its own version of Y2K will occur a second past the maximum time.

At exactly January 19, 2038 3:14:08 (one second past the maximum UNIX time), one of two things can happen to programs that keep track of time with this format. It will either crash and stop functioning altogether, or it will rollback time to the beginning of UNIX time: the first minute of 1970.

What this means for computer programs and systems that haven't been fixed depends on the program itself. The consequences can be similar those predicted with the Y2K bug.

Many pieces of software that involve future dates (i.e. Calendars, Investment calculators etc.) are already experiencing problems with the 2038 bug, being unable to involve any dates past 2038.

Also, some calculations that involve averaging dates have begun to fail as well. For example, if an algorithm adds two dates together and then divides by 2 to find the middle date, it would fail.

y2k38.info