Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Embarrassing security failure at PayPal

Published: March 22, 2012 Reading time: 2 min

The H-Security: Until just a few days ago, web sites belonging to the world’s largest online payment service contained a security vulnerability in a key component that could have been exploited by fraudsters to steal information from customers. PayPal fixed the vulnerability shortly after being notified of its presence by The H’s associates at heise Security. The eBay subsidiary was, however, unable to give any information on how such a serious security problem could have remained undetected. ...

Continue Reading

Chrome 17 update fixes high-risk vulnerabilities

Published: March 22, 2012 Reading time: 2 min

The H-Security: Google has released version 17.0.963.83 of its Chrome web browser, a maintenance update that fixes issues with Flash games and closes several security holes. The Stable channel update addresses a total of nine vulnerabilities, six of which are rated as “high severity“. These include an integer issue in libpng (the official PNG reference library), a memory corruption problem in WebGL canvas handling and a cross-origin violation related to “magic iframe”, as well as use-after-free errors in first-letter handling, CSS cross-fade handling and block splitting. One medium-risk invalid read in the V8 JavaScript engine and two low-risk problems related to WebUI privileges and unpacked extension installation have also been fixed. ...

Continue Reading

New Dr Who girl Jenna-Louise Coleman's name exploited by Twitter sex video scammers

Published: March 22, 2012 Reading time: 2 min

SophosLabs: Jenna-Louise Coleman has been unveiled as the new “Doctor Who” companion, joining the BBC TV time traveller in his TARDIS later this year. “Doctor Who” is one of Britain’s biggest television shows, and is popular elsewhere around the world, so it was no surprise to find 25-year-old actress Jenna Louise-Coleman’s name was a trending topic on Twitter today. Unfortunately, there are frequently mischief-makers, scammers and cybercriminals waiting to exploit a popular search term or hashtag. ...

Continue Reading

‘Fileless' malware installs into RAM

Published: March 20, 2012 Reading time: 2 min

Exploit found in Russian adware invades process, doesn’t install files The Register: Researchers at Kaspersky Labs have found malware which, unusually, does not install any files on its victims PCs. The researchers aren’t quite sure how unusual it is, describing it as both “unique” and “very rare”, but no matter how scarce this type of malware is it does sound rather nasty as it “… uses its payload to inject an encrypted dll from the web directly into the memory of the javaw.exe process.” That mode of operation means Windows and MacOS are both affected by the exploit, which is hard for many antivirus programs to spot given it runs within a trusted process. ...

Continue Reading

Apple's new iPad is great, but it's not free, nor called iPad 3

Published: March 19, 2012 Reading time: 2 min

SophosLabs: Only hours after the launch of Apple’s newest iPad we are beginning to see spammers trying to use the excitement over its release to ensnare innocent people into their scams. The scammers are sending out emails with the subject “Where do we send your Free iPad 3, just Test & Keep! See details”. The email contains an image with the text “TEST & KEEP an iPad 3 FREE – Click here”. ...

Continue Reading

Pidgin IM client 2.10.2 closes DoS holes

Published: March 15, 2012 Reading time: 1 min

The H-Online: Version 2.10.2 of the open source Pidgin instant messaging program has been released. According to its developers, the maintenance and security update brings a number of changes and addresses two denial-of-service (DoS) vulnerabilities that could be exploited by an attacker to cause the application to be terminated. These remote crashes are caused when the MSN server sends messages that are not UTF-8 encoded and also when some types of nickname changes occur in chat rooms using the XMPP protocol. Versions up to and including 2.10.1 are affected. Pidgin 2.10.2 fixes these issues and all users are advised to upgrade. ...

Continue Reading

Digital Playground porn passwords exposed by hackers

Published: March 13, 2012 Reading time: 3 min

SophosLabs: A group of hackers are claiming to have stolen the details of more than 70,000 users of the Digital Playground porn website. The group, calling itself “The Consortium”, appears to have scooped up some 40,000 financial details (including credit card numbers, names, CCV numbers, and expiration dates) as well as the email addresses and passwords of 72,000 users. According to the hackers, who appear to be affiliated with the Anonymous movement, the sensitive information was not encrypted. ...

Continue Reading

Nude Heather Morris pictures – hacker blamed

Published: March 13, 2012 Reading time: 2 min

SophosLabs: Heather Morris, famous for playing cheerleader Brittany in the popular “Glee” TV show, is said to be the latest celebrity to have had nude photos leak onto the web. The naked pictures are alleged to have been stolen by hackers from the 25-year-old actress’s mobile phone. Of course, Heather Morris isn’t the first celebrity to have fallen victim to a nude photo hacker. Nude photos and videos of Vanessa Hudgens, the star of “High School Musical”, surfaced on the net in 2011, after it was claimed the actress’s Gmail account was hacked. ...

Continue Reading

Scam for FC Barcelona Fans

Published: March 13, 2012 Reading time: 2 min

Symantec Connect: Phishers often choose baits with the motive of targeting a large audience. Using popular celebrities as bait is a good example. Phishers understand that choosing celebrities with a large fan base would target the largest audience and supply more duped users. This month phishers are using the same strategy but, instead of targeting a popular celebrity, they associated their phishing site with the popular FC Barcelona football club. FC Barcelona is the world’s second richest football club and has a large fan following. The phishing site, hosted on a free web hosting site, has since been removed and is no longer active. However, though phishing sites are frequently short-lived, internet users should be aware that other phishing sites using this or a similar template could easily be encountered in future. ...

Continue Reading

Firefox 11 release postponed due to security issues [Updated]

Published: March 13, 2012 Reading time: 2 min

H-Online: The Firefox team has announced that they are postponing the release of Firefox 11, originally planned for today, because of a security report which the team wants to evaluate to make sure the issue will not impact on their code. Jonathan Nightingale, Mozilla’s Senior Director of Firefox Engineering, also Microsoft’s monthly Patch Tuesday security update, also scheduled for today, as a reason to hold back on releasing the new Firefox version. ...

Continue Reading