Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

FaceTime for Mac OS X Has a Serious Security Flaw

Published: October 21, 2010 Reading time: 2 min

A German source is signaling that those who haven’t downloaded FaceTime for Mac just yet may want to hold back on the desire to video chat with their iPhone-wielding friends, as there may be some serious security risks involved. During yesterday’s Back to the Mac special event held in Cupertino, California, Apple’s CEO confirmed the availability of FaceTime for Mac. The application effectively enables anyone with a mac running Snow Leopard to use their computer’s iSight camera and mic to talk to their iPhone, iPod touch-equipped friends. ...

Continue Reading

Panda Security Launches Panda Antivirus for Mac

Published: October 21, 2010 Reading time: 3 min

Panda Security has announced the launch of Panda Antivirus for Mac. This new solution delivers comprehensive protection against malware affecting Mac OS and Mac OS X; it also prevents Mac users from transmitting malware to other users of Windows and Linux operating systems. Panda Antivirus for Mac scans files and email, detecting and eliminating or blocking many types of threats, including viruses, Trojans, spyware, keyloggers, adware, hacking tools, botnets, dialers, scareware and other threats that have traditionally targeted Windows users. ...

Continue Reading

Are You Smarter Than John?

Published: October 21, 2010 Reading time: 1 min

How not to manage your passwords… John, and his unique approach to security is part of an F-Secure Internet Security 2011 campaign. You can find more at besmarterthanjohn.com.

Continue Reading

Predator Software Pirated?

Published: October 21, 2010 Reading time: 1 min

This isn’t good: Intelligent Integration Systems (IISi), a small Boston-based software development firm, alleges that their Geospatial Toolkit and Extended SQL Toolkit were pirated by Massachusetts-based Netezza for use by a government client. Subsequent evidence and court proceedings revealed that the “government client” seeking assistance with Predator drones was none other than the Central Intelligence Agency. IISi is seeking an injunction that would halt the use of their two toolkits by Netezza for three years. Most importantly, IISi alleges in court papers that Netezza used a “hack” version of their software with incomplete targeting functionality in response to rushed CIA deadlines. As a result, Predator drones could be missing their targets by as much as 40 feet. ...

Continue Reading

Malware Pushers Abuse Firefox Warning Page

Published: October 21, 2010 Reading time: 3 min

This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user – which in all honestly is a safe bet most of the time! You could consider it a Social Engineering attack as it’s taking something that’s familiar and changing it to deliver malware. I’m sure all the Firefox users reading have at some point or another been faced with the warning screen that tells you a site is not safe to visit, the red page which states in big white letters “Reported Attack Page!”. ...

Continue Reading

Hacked Kaspersky Download Site Directs Users to Fake Antivirus

Published: October 20, 2010 Reading time: 4 min

Kaspersky Lab now admits that people attempting to buy Kaspersky’s security products on Oct. 17 were redirected by hackers to a scareware site with links to fake antivirus software called Security Tool. Hackers have caused serious embarrassment for a major security technology company. Kaspersky Lab’s Website was hacked over the weekend, sending customers looking for security software to an external download page pushing counterfeit software. When users tried to download software from Kaspersky on Oct. 17, they were redirected to a malware site that tricked users into downloading fake antivirus software called Security Tool. Once executed, Security Tool displays pop-ups reporting a number of vulnerabilities and threats “found” to scare users into buying what it says is a full version in order to fix these problems. ...

Continue Reading

Operation Payback takes down UK IP office

Published: October 20, 2010 Reading time: 2 min

HAVOC CAUSING hacker activist group Operation Payback has extended its reach and strangled the life out of the UK Intellectual Property Office’s website. Yesterday they apparently took down the MPAA’s website in the US, and today, though already busy, they have widened their focus and laid a smackdown on the UK IPO, knocking its website offline. According to a blog post on the Panda security blog Anonymous is 4Chan, and yesterday a forum on that website published its list of targets and its timeline for attacks. ...

Continue Reading

Turkish hackers attack CDU websites

Published: October 20, 2010 Reading time: 2 min

Two regional websites for Chancellor Angela Merkel’s Christian Democrats (CDU) were hacked on Tuesday by unknown perpetrators claiming to be Turkish following controversial comments by her conservatives on immigration. Police and domestic intelligence agencies are now investigating in both the city-state of Hamburg and the northern state of Mecklenburg-Western Pomerania after CDU officials said their party sites were paralysed overnight when hackers replaced their homepages with a black background featuring a Turkish crest and critical comments. ...

Continue Reading

Microsoft sees "unprecedented wave" of Java malware exploits

Published: October 19, 2010 Reading time: 2 min

There has been an “unprecedented wave” of exploits against vulnerabilities in Oracle’s Java during the third quarter of this year, according to data from the Microsoft Malware Protection Center. The software giant provided the following data to back its claims, outlining three specific vulnerabilities (all of which have patches available) that are being exploited en masse: CVE Attacks Computers Description 2008-5353 3,560,669 1,196,480 A deserialization issue in vulnerable versions of JRE (Java Runtime Environment) allows remote code execution through Java-enabled browsers on multiple platforms, such as Microsoft Windows, Linux, and Apple Mac OS X. 2009-3867 2,638,311 1,119,191 Another remote code execution, multi-platform issue caused by improper parsing of long file:// URL arguments. 2010-0094 213,502 173,123 Another deserialization issue, very similar to CVE-2008-5353. As you can see, the first two are particularly worrying: they’ve gone from hundreds of thousands per quarter to millions. The third one is the newest, so it’s possible that it will also do the same. ...

Continue Reading

Fake Twitter homepage kit serves up naked ladies and infection files

Published: October 18, 2010 Reading time: 2 min

You might be wondering why the frontpage of Twitter has a big “Edit” line running through it in the screenshot below: The answer, of course, is that this is not the real Twitter page at all. It’s part of an increasingly popular kit used for shenanigans: The scammer downloads the zip, edits the links in the .htm file and places something likely to catch the attention of an end-user underneath the “Edit” line. The fact that the fake content is sitting directly underneath the “New Twitter” promotional text is not a coincidence. ...

Continue Reading