Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat

Published: October 29, 2010 Reading time: 1 min

Adobe have published details of a critical vulnerability the following applications. Adobe Flash Player 10.1.85.3 and earlier versions Adobe Reader 9.4 and earlier 9.x versions Adobe Acrobat 9.4 and earlier 9.x versions The vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Flash Player. ...

Continue Reading

New Trojan Virus Attacks Mac Computers Via Social Networking Sites

Published: October 28, 2010 Reading time: 3 min

**Mac: Hi PC, I’m not feeling so hot today… ** PC: Oh, I know ALL about that. I think you have a virus! Security experts by and large agree that security via obscurity is not a wise model for protecting customers over the long term. That’s exactly the model Apple has employed successfully for some time now. However, its luck finally appears to be running short. ...

Continue Reading

Firesheep: who is eating my cookies?

Published: October 26, 2010 Reading time: 3 min

Internet is great, and everyday millions of people spend their day surfing it, using Google, Gmail, Youtube, Twitter, Facebook, etc. Some people buy at ebay, or Amazon. Even some people use it to work, though these cases maybe not that common😉 As a reader of this blog, you are concerned about security and therefore you already know that connecting through public WiFi is a risky sport. But it is also really convenient, how many of you have done it in McDonalds,Starbucks, etc.? Yeah, me too😮 ...

Continue Reading

Spam from the Advocate

Published: October 25, 2010 Reading time: 1 min

Currently cyber criminals try to make fast money by spamming out emails in masses in Germany which allegedly stem from an Advocate specialized in copyright. According to the spam mails, the user was downloading copyrighted material. An IP address is in the email to proof that. To not call the attorney to action, the recipient of the mail is offered to send 100 Euros via a payment system called Ukash. Don’t fall for that social engineering, don’t pay! ...

Continue Reading

Google's Spam Report Extension

Published: October 24, 2010 Reading time: 1 min

If you want to improve Google’s results and report spammy web pages, there’s a Chrome extension for you.Google Webspam Report adds a link next to each Google search result and automatically fills the spam report form with information like the URL of the page and your query. You can also use the button from Chrome’s toolbar to report pages. The most interesting feature is the integration with Chrome’s browsing history that lets you select recently visited pages and recent Google searches. ...

Continue Reading

12Seconds.com shutdown :-(

Published: October 22, 2010 Reading time: 1 min

Last mail I got from 12Seconds.com: Dear 12ers, Tonight at 8:15PM PST we will shut down 12seconds.tv. No videos can be recorded after 5PM PST. If you have not yet downloaded your videos, go to 12seconds.tv and use the awesome 12seconds video export tool and save your memories. The tool will be available until 5:15 PM PST, so be sure to export your videos before then. Is this the last time you will hear from us? ...

Continue Reading

Panda: Mac is less secure than Windows, here's an antivirus

Published: October 22, 2010 Reading time: 2 min

Follow up from: Panda security launches Panda Antivirus The number of Mac OS vulnerabilities has quintupled in less than a year. In 2009, 34 vulnerabilities were detected for Mac OS. So far in 2010, this number has risen to 175 vulnerabilities. Furthermore, the platform can also be affected by 170,000 macro viruses for Windows and there are 5,000 classified strains of malware that specifically target Apple systems, according to Panda Security. ...

Continue Reading

Zynga sued in privacy breach controversy

Published: October 22, 2010 Reading time: 2 min

218 million “class members” probably won’t settle for Farmville dollar A suit has been filed in U.S. District Court in San Francisco on behalf of a Minnesota woman charging game maker Zynga with leaking the personal information of 218 million Facebook members in violation of federal law. The suit seeks class action status. The action follows by three days an investigative story by The Wall Street Journal that found a large number of Facebook’s apps – including Zynga games such as Farmville and Mafia Wars – leaked the user IDs of Facebook players and their friends to outside companies. ...

Continue Reading

PCWorld links to scareware

Published: October 21, 2010 Reading time: 2 min

I was reading an article on PCWorld’s website about the upcoming Google Chrome OS: So far so good. Except that I inadvertently clicked on one of their sponsored links: which ironically states “Here is all about spyware removal and even more.” After a few redirects, my browser is hijacked by one of those FakeAV scanners: Here is the HTTP traffic capture screenshot and log: ...

Continue Reading

Man cops to botnet-fueled pump-and-dump scheme

Published: October 21, 2010 Reading time: 2 min

An Arizona computer specialist has admitted taking part in a conspiracy that used large networks of compromised computers to inflate the value of stocks so they could later be sold at a profit. James Bragg, 41, of Chandler, Arizona, pleaded guilty on Wednesday to conspiracy to commit securities fraud and fraud, prosecutors said. He faces a maximum sentence of five years in prison and a $250,000 fine. It wasn’t immediately clear when sentencing is to take place. ...

Continue Reading