Report

Anonymous Hacks Syrian President’s Email. The Password: 12345

Published: February 8, 2012 Reading time: 3 min

Mashable: Syrian President Bashar al-Assad has been under fire from world leaders to step down this week. He’s also under fire from hacktivist group Anonymous, who leaked hundreds of his office’s emails on Monday. While Anonymous is infamous for its hacking know-how, it doesn’t take a genius computer programmer to guess one of the passwords commonly used by Assad’s office accounts: 12345. The string of consecutive numbers is the second-weakest password according to a 2011 study. ...

Continue Reading

Satellite phone encryption cracked

Published: February 8, 2012 Reading time: 1 min

H-Online: Researchers at Ruhr-Universität Bochum in Germany have announced that they have cracked the A5-GMR-1 and A5-GMR-2 encryption algorithms used in satellite phones. Satellite phones are mainly used in areas with insufficient mobile network coverage and in the maritime sector. The researchers obtained the proprietary, and previously undocumented, algorithms by reverse engineering phone firmware updates. Ideally this, in itself, should not compromise the security of the transmitted data. Data security should not depend on the secrecy of the encryption methods, it should only depend on the non-disclosure of the secret key that is being used. ...

Continue Reading

Malware automatically uploading stolen data to the File sharing sites

Published: February 6, 2012 Reading time: 1 min

The Hacker News: Roland Dela Paz, a threat response engineer with Trend Micro have discovered a piece of malicious software that automatically uploads its stolen data cache to the SendSpace file-sharing service for retrieval. File-storage services offer several advantages for cybercriminals. SendSpace accepts files and then generates a link that can be shared with other people to download the content in the files. The malware has been configured to send files, copy the download link and send it to a command-and-control server along with the password needed to access the archive, Dela Paz wrote. ...

Continue Reading

Joomla! updates close information disclosure holes

Published: February 6, 2012 Reading time: 1 min

The H-Online: Versions 1.7.5 and 2.5.1 of the open source Joomla! content management system (CMS) have been released to address two information disclosure vulnerabilities. These include one medium severity problem in Joomla! 1.7.x that could allow an unauthorized user to gain access to the error log stored on a victim’s server, and, in both versions, an inadequate validation problem that could be exploited to gain access to private data. The update to Joomla! 2.5, which arrived last month, also fixes 30 bugs, including one that caused batch processing to break. ...

Continue Reading

Google Launches ‘Solve for X,’ Think Tank for Fixing Global Problems

Published: February 6, 2012 Reading time: 2 min

Mashable: Google just debuted a project dedicated to attacking some of the biggest problems facing civilization, such as global warming, and proposing “radical” ideas for solving them. Solve for X Called “Solve for X,” the idea resembles TED (Technology Entertainment and Design), the series of conferences that feature industry leaders exploring big-picture ideas and how they can improve society. Solve for X, however, appears to be more focused on global problems, using them as opportunities to encourage “moonshot” thinking. ...

Continue Reading

German government makes recommendations for secure Windows PCs

Published: February 6, 2012 Reading time: 2 min

The H-Online: The German Federal Office of Information Security (BSI (German), BSI English) has compiled security recommendations for Windows PCs that will probably sound familiar to regular readers of The H: Anti-virus software – including free solutions –, backups, security updates, an alternative browser such as Google Chrome and “a healthy level of mistrust” are the main components of its proposal for a secure Windows PC. As the UK lacks a governmental organization that makes such recommendations, as usually such organizations recommend policy for public projects, it is worth seeing what Germany’s BSI suggests. ...

Continue Reading

Critical PHP vulnerability being fixed

Published: February 2, 2012 Reading time: 2 min

The H-Security: The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions. The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web. ...

Continue Reading

Facebook Scam: See who views your profile!

Published: January 24, 2012 Reading time: 1 min

Earlier today we have seen a new Facebook clickjacking scam which spreads quite fast. I KNOW WHEN YOU LOOK AT MY PROFILE USING THIS: http://bit.ly/ NEW! See who views your profile! www..com Do you want to know who is looking at your photos right now? Find out who looks at your profile the most and what they look at! or other variant even more provocative: CLICK HERE TO SEE WHO IS STALKING YOU: http://bit.ly NEW! See who views your profile! www..com Do you want to know who is looking at your photos right now? Find out who looks at your profile the most and what they look at! ...

Continue Reading

LA Time: Dropbox inventor determined to build the next Apple or Google

Published: January 17, 2012 Reading time: 1 min

Drew Houston’s wildly popular service allows people to access the latest version of all their digital stuff on any device no matter where they are. Every day 325 million files are saved on Dropbox. Drew Houston, 28, chief executive and co-founder of Dropbox, last fall pocketed $250 million from seven of Silicon Valley’s top venture capital firms. That eye-popping sum pegged the value of his company at $4 billion and his own net worth — at least on paper — at an estimated $600 million. (Matt Staver, Bloomberg / July 6, 2011) ...

Continue Reading

Adobe closes Acrobat and Reader security holes

Published: December 17, 2011 Reading time: 2 min

The H-Online: The first patches for the zero-day flaw in Adobe’s Acrobat and Reader applications, which the company confirmed was being exploited in the wild, have been released. The initial problem was caused by a memory corruption when processing Universal 3D (U3D) files, which could allow attackers to potentially take control of an affected system. The patches released also address a newly revealed critical flaw (CVE-2011-4369) which can cause memory corruption when processing Product Representation Compact (PRC) 3D files. ...

Continue Reading

Duqu exploits previously unknown vulnerability in Windows kernel

Published: November 3, 2011 Reading time: 2 min

The H-Online Security: Microsoft has confirmed a report from Budapest-based Laboratory of Cryptography and System Security (CrySyS), which claimed that the Duqu bot spreads by exploiting a zero day vulnerability in the Windows kernel. How it spreads had previously been unknown. CrySyS discovered the Windows vulnerability whilst analysing the installer. The bot, which anti-virus software firm Symantec believes is related to Stuxnet, infects target systems using a specially crafted Word file which injects the malware into the system using a kernel exploit. Microsoft is already working on a patch. ...

Continue Reading

MyBB downloads were infected

Published: October 25, 2011 Reading time: 2 min

The H-Security: In a blog posting, the MyBB development team has confirmed that the download package for version 1.6.4 of MyBB had been modified to include malicious code. Unknown attackers were able to exploit a vulnerability in the MyBB web site’s CMS (content management system) to inject and execute PHP code. The attackers placed a contaminated version of MyBB, containing a backdoor, on the server. It is unclear exactly when the hack took place, meaning that all downloads of 1.6.4 prior to 6 October could be affected. Users with MyBB systems are advised to check their installations and apply a patch. For rapid disinfection, the developers are advising users to replace the /index.php file with a clean version and to delete the /install/ directory. ...

Continue Reading

Hacker Rattles Security Circles: 21 Years Old Iranian

Published: September 19, 2011 Reading time: 1 min

The building housing the Dutch company DigiNotar, which issues digital Web site certificates and was hacked last month. The New York Times: He claims to be 21 years old, a student of software engineering in Tehran who reveres Ayatollah Ali Khamenei and despises dissidents in his country. _“I’m totally independent,” he said in an e-mail exchange with The New York Times. “I just share my findings with some people in Iran. They are free to do anything they want with my findings and things I share with them, but I’m not responsible.” _He Said. ...

Continue Reading

GlobalSign gives itself clean bill of health after Iranian hacker's braggadocio

Published: September 12, 2011 Reading time: 2 min

SophosLabs: Following the widely-publicised disgrace of Dutch digital certificate issuer DigiNotar, a person calling himself ComodoHacker claimed that he’d breached four other Certificate Authorities (CAs), too. Only one of these CAs was named: GlobalSign, the world’s fifth-biggest issuer of digital certificates. In my opinion, GlobalSign would have been justified in ignoring this claim altogether. It comes across as a stream of made-up, self-serving puffery, including bluster like this: You see? I’m so smart, sharp, dangerous, powerful, etc. huh? ...

Continue Reading

Yes, Microsoft Did Change The World More Than Apple

Published: September 8, 2011 Reading time: 1 min

Business Insider: A new poll in France says 7 out of 10 people think Microsoft did more to change the world than Apple. We think we would have similar results in other countries, if only because a lot more people (still!) use Microsoft products than Apple products, at least for personal computing which is (still!) the most important part of computing. It’s hard to see a mention of Steve Jobs without the worlds “change the world” or “changing an industry.” And let’s give him his due. Let’s give him his due as one of the greatest entrepreneurs in history, as an amazing entrepreneur and visionary who left many “dents” in the universe. And he did change many industries, like music, film, and yes, personal computing. ...

Continue Reading