TechBlog

An update on attempted man-in-the-middle attacks

Published: August 31, 2011 Reading time: 1 min

Google: Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it). Google Chrome users were protected from this attack because Chrome was able to detect the fraudulent certificate. ...

Continue Reading

Panda Cloud Antivirus makes firewall social

Published: August 31, 2011 Reading time: 2 min

BetaNews.com: Panda Security has released Panda Cloud Antivirus 1.9.1 Beta, a preview of its forthcoming 2.0 release. The beta sees Panda’s lightweight free cloud-based antivirus tool add firewall protection for the first time. The new firewall is community based, which means it’s capable of detecting known processes and settings appropriate levels of protection for them without bothering the end user with a pop-up alert. The new firewall is visible from a new tab on the Panda Cloud Antivirus interface. ...

Continue Reading

Blogger’s fresh new look

Published: August 31, 2011 Reading time: 2 min

Blogger Buzz: As you may have heard, things are starting to look a little different across many Google products—and today, Blogger is the next product to get a makeover. It’s been a few years since we made major updates to Blogger’s look and feel, and there’s a lot more to these changes than just shiny new graphics. We’ve rewritten the entire editing and management experience from scratch so it’s faster and more efficient for you—and easier for us to update and improve over time. ...

Continue Reading

Using Gmail, Calendar and Docs without an Internet connection

Published: August 31, 2011 Reading time: 2 min

Gmail Blog: The great thing about web apps is that you can access all of your information on the go, and we’ve introduced ways to use Google Apps on a variety of devices like mobile phones and tablets. But it’s inevitable that you’ll occasionally find yourself in situations when you don’t have an Internet connection, like planes, trains and carpools. When we announced Chromebooks at Google I/O 2011, we talked about bringing offline access to our web apps, and now we’re taking our first steps in that direction. Gmail offline will be available today, and offline for Google Calendar and Google Docs will be rolling out over the next week, starting today. ...

Continue Reading

Firefox, Thunderbird and SeaMoney blacklist bad DigiNotar SSL certificates

Published: August 31, 2011 Reading time: 2 min

Mozilla Security Blog: Mozilla just released an update to Firefox for Desktop, Thunderbird and SeaMonkey. Updates are now available for: Firefox for Windows, Mac and Linux (final release) Firefox for Windows, Mac and Linux (3.6.21 final release) Firefox Aurora for Windows, Mac and Linux Firefox Nightly for Windows, Mac and Linux SeaMonkey (2.3.2) Thunderbird (6.0.1) We strongly recommend that all users upgrade to these releases. If you already have Firefox, you will receive an automated update notification within 24 to 48 hours. Users can also manually check for updates if they do not want to wait for the automatic update. ...

Continue Reading

Create PDF files on your iPhone and iPad now

Published: August 30, 2011 Reading time: 2 min

Acrobat Blog: We are excited to announce that Adobe CreatePDF application is now available on iOS. With this, Adobe brings rich, high-fidelity and Acrobat-like PDF creation to the iOS devices. You can now convert all your documents on iPad, iPhone & iPod touch devices to PDF for reliable, secure sharing and viewing across PCs, tablets & Smartphones. The application uses Adobe’s online PDF Creation service for conversion of files to PDF thereby ensuring no compromise on quality and performance. ...

Continue Reading

Hacker steals user data from Nokia developer forum

Published: August 29, 2011 Reading time: 1 min

H-Online: A vulnerability in its forum software has been exploited by a hacker to compromise mobile phone maker Nokia‘s developer forum. The attacker used SQL injection to access the forum database at developer.nokia.com and, according to Nokia, obtained email addresses of registered users. Where configured to be publicly available, the table also includes details such as the user’s date of birth, web site URL and Skype, ICQ or other IM username; this is reported to be the case for around 7 per cent of users. The database did not contain passwords or credit card information. The issue does not, according to Nokia, affect any other Nokia accounts. ...

Continue Reading

Screenshots of Chinese hacking tool

Published: August 29, 2011 Reading time: 2 min

Schneier on Security: It’s hard to know how serious this really is: The screenshots appear as B-roll footage in the documentary for six seconds­between 11:04 and 11:10 minutes — showing custom built Chinese software apparently launching a cyber-attack against the main website of the Falun Gong spiritual practice, by using a compromised IP address belonging to a United States university. As of Aug. 22 at 1:30pm EDT, in addition to Youtube, the whole documentary is available on the CCTV website. ...

Continue Reading

New worm targeting weak passwords on Remote Desktop connections (port 3389)

Published: August 29, 2011 Reading time: 2 min

Microsoft Malware Protection Center: We’ve had reports of a new worm in the wild and that generates increased RDP traffic for our users on port 3389. Although the overall numbers of computers reporting detections are low in comparison to more established malware families, the traffic it generates is noticeable. The worm is detected as Worm:Win32/Morto.A and you can see a detailed description of at http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fMorto.A. Morto attempts to compromise Remote Desktop connections in order to penetrate remote systems, by exploiting weak administrator passwords. Once a new system is compromised, it connects to a remote server in order to download additional information and update its components. It also terminates processes for locally running security applications in order to ensure its activity continues uninterrupted. Affected users should note that a reboot may be required in order to complete the cleaning process. ...

Continue Reading

Start of Avira 12 Betatest!

Published: August 26, 2011 Reading time: 1 min

Start of AV 12 Betatest! It starts from today and ends on 29th of September 2011. Finally after a long time Avira started Betatest of Avira AntiVir 12. If you would like to test this build and feature beta releases, you can register in Avira BetaCenter: http://betacenter.avira.com More Info: http://techblog.avira.com/2011/09/08/avira-products-version-2012-for-windows-now-available-for-beta-testing/en/

Continue Reading