TechBlog

Stuxnet in the news

Published: September 30, 2010 Reading time: 1 min

The Stuxnet Trojan is very well covered in the media as more and more details about its sophisticated code become public. It abuses four previously unknown security vulnerabilities in Windows to enter the system and is specialized on attacking Siemens processing systems. An interesting information which didn’t get much attention yet comes from heise Security: The nuclear plant in Busheer isn’t really the target of the worm as rumours say, as the attacked systems aren’t approved for usage in nuclear plants.

Continue Reading

Google offers to turn off threading in Gmail

Published: September 30, 2010 Reading time: 1 min

Google has finally decided to allow users to turn off the controversial ‘conversation view’ threading functionality in Gmail. Conversation view has been a characteristic of Gmail ever since it launched, but Google software engineer Dong Chen admitted in a blog post yesterday that it is the webmail service’s “most hotly debated feature “. “Threading enthusiasts say they spend less mental energy drawing connections between related messages, and that their inboxes are much less cluttered,” he wrote. ...

Continue Reading

Nokia N8 Shipments Begin

Published: September 30, 2010 Reading time: 1 min

Nokia would like the world to know that its upcoming smartphone, the N8, is finished. The first batch of devices has left the factories in Finland and China, and these N8s will soon end in the hands of customers all over the world. Many Nokia fans have wondered will there be further delays for the N8, and this is probably the best answer to that question. Recently, Nokia informed some of the customers who have pre-ordered the device they will be receiving it “during October,” as Nokia decided to “hold the shipments for a few weeks to do some final amends.” However, Nokia immediately clarified that the N8 is not being delayed, and now it proved it with the pictures of N8s leaving the factory. ...

Continue Reading

Xmarks service ends January 2011

Published: September 30, 2010 Reading time: 1 min

Xmarks will be shutting down free browser synchronization services on January 10, 2011. For details on how to transition to recommended alternatives, consult this page. For the full story behind the Xmarks shutdown, please read their blog post. It’s a sad story to me! 😢 Here I found a good article to read: http://www.zdnet.com/blog/networking/no-more-xmarks-no/192

Continue Reading

Microsoft Kills Live Space blogs

Published: September 29, 2010 Reading time: 2 min

Microsoft announced that it has collaborated with WordPress and now onwards it will be the default blogging platform for Windows Live users. This means Microsoft is killing it’s own blogging platform and suggesting users to go for better platform called ‘WordPress’. In TechCrunch Disrupt conference, Windows Live Director ‘Dharmesh Mehta’ announced that all existing Windows Live Spaces users will be migrated over to an account at WordPress.com. So now onwards users who sign up for a Windows Live account get free Hotmail , the Xbox Live site , a free blog from WordPress.com and other services. ...

Continue Reading

Browser cookies are becoming an issue

Published: September 23, 2010 Reading time: 3 min

The New York Times is reporting a rising number of law suits against some major players because of their use of persistent web tracking: — Fox Entertainment Group — NBC Universal — Specific Media — Quantcast The Times said the suits are claiming that the companies used Flash cookies to collect data on browsing activities in spite of the fact that users had privacy settings on to block them. Those Local Shared Objects (LSOs) are persistent cookies that are stored in several ways and in some cases will restore themselves when deleted. One is available, with a detailed description here. ...

Continue Reading

Twitter XSS vulnerability fixed

Published: September 23, 2010 Reading time: 1 min

Twitterers are still clogging the micro-blogging service with little messages about the cross-site-scripting problem earlier today. Twitter has announced that the problem has been fixed. A cross-site scripting vulnerability using “onmouseover” was being widely exploited to spread worms and redirect viewers to malicious sites. Story here from The Register.

Continue Reading

More Spam with JavaScript redirectors

Published: September 23, 2010 Reading time: 1 min

We received new spam emails which contain a JavaScript redirector in form of a HTML attachment. The emails we received have the subject “Consultation Appointment”. The decrypted JavaScript consists of new JavaScript code. This JavaScript redirector loads yet another JavaScript from the internet. The domain which is hosting the malicious .js is registered to someone from Malaga. Domain tools show that this person has registered about 2.400 other domains. ...

Continue Reading

Twitter XSS getting abused

Published: September 21, 2010 Reading time: 1 min

On Twitter a new security flaw gets currently exploited. Hackers found a way to inject malicious JavaScript code into tweets with the onMouseOver event. This can lead to pop-ups appearing, redirecting to websites, re-tweeting spam, or even worse things like cookie stealing (compromising the user accounts). The problem is that Twitter doesn’t properly filter out some tags in tweets. Users should be very cautious when seeing colored text blocks (background and text colors are the same, called “rainbow tweets”) – these are currently mostly used to exploit the security vulnerability. Hopefully, Twitter closes the security hole soon! Until then, using the NoScript web browser extension or disabling JavaScript on Twitter helps against the attack. Also, using twitter applications which rely upon the Twitter API aren’t affected.

Continue Reading

Flash Player Updates fix 0-day-vulnerability

Published: September 21, 2010 Reading time: 1 min

Adobe fixed the vulnerability in Flash Player in a record time again. Just one week after the 0-day became public and started to get exploited, an update is available to close the security hole. Even though Adobe Reader and Acrobat are affected (which are supposed to get an update in 2 weeks), until now we’ve only seen exploits against the Windows Flash Player. Users and administrators should update their Flash Player as soon as possible! The version 10.1.85.3 fixes the issue for Windows, Unix, Solaris and is available through Adobe’s download center. Android users can get the update to 10.1.95.1 on the Android Market Place.

Continue Reading