| 

German government makes recommendations for secure Windows PCs

  • Post author: Omid Farhang
  • Post published: February 6, 2012
  • Reading Time: 2 min
  • Word Count: 289 words

The H-Online: The German Federal Office of Information Security (BSIĀ (German), BSI English) has compiled security recommendations for Windows PCs that will probably sound familiar to regular readers of The H: Anti-virus software ā€“ including free solutions ā€“, backups, security updates, an alternative browser such as Google Chrome and ā€œa healthy level of mistrustā€ are the main components of its proposal for a secure Windows PC. As the UK lacks a governmental organization that makes such recommendations, as usually such organizations recommend policy for public projects, it is worth seeing what Germanyā€™s BSI suggests. ...

Continue Reading German government makes recommendations for secure Windows PCs

Critical PHP vulnerability being fixed

  • Post author: Omid Farhang
  • Post published: February 2, 2012
  • Reading Time: 2 min
  • Word Count: 237 words

The H-Security: The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions. The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web. ...

Continue Reading Critical PHP vulnerability being fixed

Facebook Scam: See who views your profile!

  • Post author: Omid Farhang
  • Post published: January 24, 2012
  • Reading Time: 1 min
  • Word Count: 162 words

Earlier today we have seen a new Facebook clickjacking scam which spreads quite fast. I KNOW WHEN YOU LOOK AT MY PROFILE USING THIS: http://bit.ly/ NEW! See who views your profile! www..com Do you want to know who is looking at your photos right now? Find out who looks at your profile the most and what they look at! or other variant even more provocative: CLICK HERE TO SEE WHO IS STALKING YOU: http://bit.ly NEW! See who views your profile! www..com Do you want to know who is looking at your photos right now? Find out who looks at your profile the most and what they look at! ...

Continue Reading Facebook Scam: See who views your profile!

LA Time: Dropbox inventor determined to build the next Apple or Google

  • Post author: Omid Farhang
  • Post published: January 17, 2012
  • Reading Time: 1 min
  • Word Count: 101 words

Drew Houstonā€™s wildly popular service allows people to access the latest version of all their digital stuff on any device no matter where they are. Every day 325 million files are saved on Dropbox. Drew Houston, 28, chief executive and co-founder of Dropbox, last fall pocketed $250 million from seven of Silicon Valleyā€™s top venture capital firms. That eye-popping sum pegged the value of his company at $4 billion and his own net worth ā€” at least on paper ā€” at an estimated $600 million. (Matt Staver, Bloomberg / July 6, 2011) ...

Continue Reading LA Time: Dropbox inventor determined to build the next Apple or Google

Adobe closes Acrobat and Reader security holes

  • Post author: Omid Farhang
  • Post published: December 17, 2011
  • Reading Time: 2 min
  • Word Count: 253 words

The H-Online: The first patches for the zero-day flaw in Adobeā€™s Acrobat and Reader applications, which the company confirmed was being exploited in the wild, have been released. The initial problem was caused by a memory corruption when processing Universal 3D (U3D) files, which could allow attackers to potentially take control of an affected system. The patches released also address a newly revealed critical flaw (CVE-2011-4369) which can cause memory corruption when processing Product Representation Compact (PRC) 3D files. ...

Continue Reading Adobe closes Acrobat and Reader security holes

Duqu exploits previously unknown vulnerability in Windows kernel

  • Post author: Omid Farhang
  • Post published: November 3, 2011
  • Reading Time: 2 min
  • Word Count: 393 words

The H-Online Security: Microsoft has confirmed a report from Budapest-based Laboratory of Cryptography and System Security (CrySyS), which claimed that the Duqu bot spreads by exploiting a zero day vulnerability in the Windows kernel. How it spreads had previously been unknown. CrySyS discovered the Windows vulnerability whilst analysing the installer. The bot, which anti-virus software firm Symantec believes is related to Stuxnet, infects target systems using a specially crafted Word file which injects the malware into the system using a kernel exploit. Microsoft is already working on a patch. ...

Continue Reading Duqu exploits previously unknown vulnerability in Windows kernel

MyBB downloads were infected

  • Post author: Omid Farhang
  • Post published: October 25, 2011
  • Reading Time: 2 min
  • Word Count: 219 words

The H-Security: In a blog posting, the MyBB development team has confirmed that the download package for version 1.6.4 of MyBB had been modified to include malicious code. Unknown attackers were able to exploit a vulnerability in the MyBB web siteā€™s CMS (content management system) to inject and execute PHP code. The attackers placed a contaminated version of MyBB, containing a backdoor, on the server. It is unclear exactly when the hack took place, meaning that all downloads of 1.6.4 prior to 6 October could be affected. Users with MyBB systems are advised to check their installations and apply a patch. For rapid disinfection, the developers are advising users to replace the /index.php file with a clean version and to delete the /install/ directory. ...

Continue Reading MyBB downloads were infected

Hacker Rattles Security Circles: 21 Years Old Iranian

  • Post author: Omid Farhang
  • Post published: September 19, 2011
  • Reading Time: 1 min
  • Word Count: 133 words

The building housing the Dutch company DigiNotar, which issues digital Web site certificates and was hacked last month. The New York Times: He claims to be 21 years old, a student of software engineering in Tehran who reveres Ayatollah Ali Khamenei and despises dissidents in his country. _ā€œIā€™m totally independent,ā€ he said in an e-mail exchange with The New York Times. ā€œI just share my findings with some people in Iran. They are free to do anything they want with my findings and things I share with them, but Iā€™m not responsible.ā€Ā _He Said. ...

Continue Reading Hacker Rattles Security Circles: 21 Years Old Iranian

GlobalSign gives itself clean bill of health after Iranian hacker's braggadocio

  • Post author: Omid Farhang
  • Post published: September 12, 2011
  • Reading Time: 2 min
  • Word Count: 367 words

SophosLabs:Ā Following the widely-publicised disgrace of Dutch digital certificate issuer DigiNotar, a person calling himself ComodoHacker claimed that heā€™d breached four other Certificate Authorities (CAs), too. Only one of these CAs was named: GlobalSign, the worldā€™s fifth-biggest issuer of digital certificates. In my opinion, GlobalSign would have been justified in ignoring this claim altogether. It comes across as a stream of made-up, self-serving puffery, including bluster like this: You see? Iā€™m so smart, sharp, dangerous, powerful, etc. huh? ...

Continue Reading GlobalSign gives itself clean bill of health after Iranian hacker's braggadocio

Yes, Microsoft Did Change The World More Than Apple

  • Post author: Omid Farhang
  • Post published: September 8, 2011
  • Reading Time: 1 min
  • Word Count: 143 words

Business Insider: A new poll in France says 7 out of 10 people think Microsoft did more to change the world than Apple. We think we would have similar results in other countries, if only because a lot more people (still!) use Microsoft products than Apple products, at least for personal computing which is (still!) the most important part of computing. Itā€™s hard to see a mention of Steve Jobs without the worlds ā€œchange the worldā€ or ā€œchanging an industry.ā€ And letā€™s give him his due. Letā€™s give him his due as one of the greatest entrepreneurs in history, as an amazing entrepreneur and visionary who left many ā€œdentsā€ in the universe. And he did change many industries, like music, film, and yes, personal computing. ...

Continue Reading Yes, Microsoft Did Change The World More Than Apple