Gmail security vulnerability may allow an attacker to set up filters on users' e-mail accounts without their knowledge, according to a proof of concept posted Sunday at GeekCondition.com.
In his post, Brandon writes that the vulnerability has caused some people to lose their domain names registered through GoDaddy.com
Read More
Monday, November 24, 2008
Wednesday, November 19, 2008
Microsoft announces free Morro antivirus software
Microsoft is getting serious about global security, offering a free anti-malware package code-named Morro that has been specially designed for low cost PCs in developing nations.
The software will be available in the second half of 2009 and will provide 'comprehensive protection' from 'the majority of online threats', including viruses, spyware, rootkits and trojans.
Read More
The software will be available in the second half of 2009 and will provide 'comprehensive protection' from 'the majority of online threats', including viruses, spyware, rootkits and trojans.
Read More
Thursday, November 06, 2008
Microsoft: Flaws down but malware on the rise
The number of flaws impacting Microsoft products dropped 33.6 percent in the first half of 2008 compared to the last half of 2007, as hackers ramp up their focus on third-party applications, the latest Microsoft Security Intelligence Report found.This trend was particularly noticeable in the browser, said the report, released Monday. Browser-based exploits occurring on Windows XP machines were attributable to Microsoft bugs 42 percent of the time and third-party software 58 percent of the time.
Read More
Read More
Wednesday, October 29, 2008
Antivirus Defense-in-Depth Guide
The information presented in the Antivirus Defense-in-Depth guide has been updated to reflect the security improvements provided as part of Windows XP Service Pack 2. A number of the features in Windows XP Service Pack 2 have made it more difficult for malware to attack a Windows XP-based computer. The updates to this guide are designed to ensure that these enhancements are identified and explained.
http://www.microsoft.com/technet/security/guidance/serversecurity/avdind_0.mspx
http://www.microsoft.com/technet/security/guidance/serversecurity/avdind_0.mspx
Malware Removal Starter Kit
Many small- and medium-sized organizations use antivirus software, and yet new viruses, worms, and other forms of malicious software (malware) continue to infect large numbers of computers in these organizations. Malware proliferates at alarming speed and in many different ways, which makes it particularly widespread today.
This guide is intended for IT Generalists who want information and recommendations that they can use to effectively address and limit malware that infects computers in small- and medium-sized organizations. This guidance provides a set of tasks that licensed Windows® users can perform at no cost to create the Malware Removal Starter Kit. Recommendations for free malware-scanning tools are included. You can use these tools in combination with the kit to conduct scans, detect problems, and remove malware from your computer
http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx#EHD
This guide is intended for IT Generalists who want information and recommendations that they can use to effectively address and limit malware that infects computers in small- and medium-sized organizations. This guidance provides a set of tasks that licensed Windows® users can perform at no cost to create the Malware Removal Starter Kit. Recommendations for free malware-scanning tools are included. You can use these tools in combination with the kit to conduct scans, detect problems, and remove malware from your computer
http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx#EHD
Sunday, October 12, 2008
Fake Microsoft email contains "backdoor" virus
I personally received this email,
fake phishing email making the rounds seemingly comes from Microsoft, but actually contains a “backdoor” trojan.
The email has a subject line that reads, “Security Update for OS Microsoft Windows” and supposedly came from the "Microsoft Official Update Center" at a domain named securityassurance[at]microsof[dot]com.
The message urges users to run an attached file to install an update that the email said will protect from the recipient from security threats and performance problems.
Read More
fake phishing email making the rounds seemingly comes from Microsoft, but actually contains a “backdoor” trojan.
The email has a subject line that reads, “Security Update for OS Microsoft Windows” and supposedly came from the "Microsoft Official Update Center" at a domain named securityassurance[at]microsof[dot]com.
The message urges users to run an attached file to install an update that the email said will protect from the recipient from security threats and performance problems.
Read More
Tuesday, October 07, 2008
How thieves can steal your card info without you knowing it
Nice article to Read and secure you Credit Card Transactions
Taking just 5 seconds to inspect any credit/debit card readers before you swipe could end up saving you from identity and credit card theft.
Read More
Taking just 5 seconds to inspect any credit/debit card readers before you swipe could end up saving you from identity and credit card theft.
Read More
Tuesday, September 23, 2008
Yahoo, Hotmail, Gmail all vulnerable to password reset hack
Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail earlier this week.
Google Inc.'s Gmail, Microsoft Corp.'s Windows Live Hotmail and Yahoo Inc.'s Mail all rely on automated password reset mechanisms that can be abused by knowing a username associated with an account and an answer to a single security question, according to quick tests run by Computerworld .
Read More
Google Inc.'s Gmail, Microsoft Corp.'s Windows Live Hotmail and Yahoo Inc.'s Mail all rely on automated password reset mechanisms that can be abused by knowing a username associated with an account and an answer to a single security question, according to quick tests run by Computerworld .
Read More
Wednesday, September 17, 2008
How to configure NAP for Windows Server 2008
Really Nice Article in how to configure Microsoft NAP
http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1327034,00.html?track=NL-422&ad=659042&asrc=EM_NLT_4467618&uid=7917188
http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1327034,00.html?track=NL-422&ad=659042&asrc=EM_NLT_4467618&uid=7917188
Microsoft's NAC comes out on top
Microsoft comes out on top of the NAC heap in an evaluation of 10 vendors that was published recently by Forrester Research.
The result is interesting because it’s not based on how many units were sold or performance tests but rather on evaluation of how well the products would meet the challenges of a set of real-world deployment situations
Read More
The result is interesting because it’s not based on how many units were sold or performance tests but rather on evaluation of how well the products would meet the challenges of a set of real-world deployment situations
Read More
Monday, September 08, 2008
Will Microsoft Take a Sip of 'Midori'?
After some 23 years of Windows development, Microsoft appears to be more seriously considering the delivery of a non-Windows operating system. "Midori," the code name for a componentized operating system being built from scratch, has been kicking around the Redmond labs for four or five years. Recently, however, sources familiar with the project say Midori is now in "incubation," meaning the product is likely meandering its way closer to commercial availability. Midori is just one of a number of incubations under Craig Mundie, Microsoft's chief research and strategy officer.
However, another indication that the company is beginning to take Midori more seriously is that Eric Rudder, a longtime Microsoft veteran and senior vice president for technical strategy, is now supervising the project.
Read More
However, another indication that the company is beginning to take Midori more seriously is that Eric Rudder, a longtime Microsoft veteran and senior vice president for technical strategy, is now supervising the project.
Read More
Sunday, September 07, 2008
Cisco warns of flaws in Cisco ASA 5500, PIX, Cisco Secure ACS
Cisco is warning of multiple security holes in its security appliances that if exploited, could result in a reload of the devices or disclosure of confidential information. The company has also issued a fix to a vulnerability in its Cisco Secure Access Control Server, that was discovered by external security researchers.
Read More
Read More
Thursday, September 04, 2008
Early security issues tarnish Google's Chrome
Security researchers have already uncovered vulnerabilities in Google's Chrome browser, including one that could allow a user to download malicious code
Read More
Read More
Wednesday, August 27, 2008
Intrusions hit Fedora, Red Hat Enterprise Linux servers; some OpenSSH packages compromised
The maker of Red Hat Enterprise Linux and Fedora said that hackers have gained access to key servers in what appear to be two separate incidents. Red Hat Inc. found last week that someone had compromised several Fedora servers, including one that is used to sign Fedora packages. The company said that although the server was accessed illegally, they don’t believe that the passphrase used to get to the key used to actually sign the packages was compromised.
Read More
Read More
Monday, August 18, 2008
Microsoft BlueHat Security Briefings: Fall 2008
The eighth edition of BlueHat will be held on October 16-17, 2008, at the Microsoft corporate headquarters. The Microsoft BlueHat conference is a twice-a-year event aimed at bringing internal Microsoft security professionals and external security researchers together in a relaxed environment to promote the sharing of ideas and social networking. The event highlights important emergent technologies, techniques, and industry best practices.
Sessions
BlueHat v8 will consist of two full days of great content from both internal and external security experts presented in a lecture theater environment. These presentations will offer speakers the opportunity to showcase ongoing research and collaborate with peers while educating and highlighting advancements in security products and techniques.
Day 1: Sessions will be a hybrid of content from deep-dive technical security issues to innovative techniques and best practices in the information security realm.
Day 2: Microsoft’s Security Development Lifecycle (SDL) team will host sessions emphasizing secure development and testing practices and how to develop with security in mind from the beginning of the software development lifecycle. The BlueHat SDL sessions will focus more on appropriate defense strategies and less on attack techniques. Sessions might include demonstrations of secure coding techniques or correct and incorrect methods of using various security tools.
http://technet.microsoft.com/en-us/security/cc748656.aspx
Sessions
BlueHat v8 will consist of two full days of great content from both internal and external security experts presented in a lecture theater environment. These presentations will offer speakers the opportunity to showcase ongoing research and collaborate with peers while educating and highlighting advancements in security products and techniques.
Day 1: Sessions will be a hybrid of content from deep-dive technical security issues to innovative techniques and best practices in the information security realm.
Day 2: Microsoft’s Security Development Lifecycle (SDL) team will host sessions emphasizing secure development and testing practices and how to develop with security in mind from the beginning of the software development lifecycle. The BlueHat SDL sessions will focus more on appropriate defense strategies and less on attack techniques. Sessions might include demonstrations of secure coding techniques or correct and incorrect methods of using various security tools.
http://technet.microsoft.com/en-us/security/cc748656.aspx
Thursday, August 14, 2008
Hackers spoof MSNBC alerts in new twist on malware ruse
Hackers trying to plant malware on PCs have switched from touting CNN news in come-on messages to pushing breaking stories said to be from rival network MSNBC, security experts said today.
The fake messages pose with subject headings that include the phrase "Breaking News," along with phony news story headlines, such as " Jerry Yang relinquishes control over Yahoo," "Mary-Kate Olsen responsible for Heath Ledger's death," and "Plane crashes into prep school, hundreds of kids killed," said researchers at F-Secure Corp. and Sophos Plc
Read More
The fake messages pose with subject headings that include the phrase "Breaking News," along with phony news story headlines, such as " Jerry Yang relinquishes control over Yahoo," "Mary-Kate Olsen responsible for Heath Ledger's death," and "Plane crashes into prep school, hundreds of kids killed," said researchers at F-Secure Corp. and Sophos Plc
Read More
Thursday, August 07, 2008
From BLACK HAT 2008: Google gadget flaws
Google gadgets are small applications, such as a currency converter, calendar or weather forecast, that can be added to the iGoogle homepage or a computer's desktop. The problem lies in the fact that the mini-modules are created by third-party developers, who can embed malicious JavaScript to redirect users to hacker websites, security researcher Robert “RSnake” Hansen told several hundred people in attendance
Read More
Read More
Tuesday, August 05, 2008
Microsoft to give partners heads-up on security vulnerabilities
Microsoft will be giving companies that sell security software and services to its customers a sneak peek at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly "Patch Tuesday" updates.
The new Microsoft Active Protection Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a change to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.
"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."
Read More
The new Microsoft Active Protection Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a change to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.
"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."
Read More
Switches are Supported by MS NAP 802.1x Enforcement
very Important article for implementing MS NAP 802.1x Enforcement
http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx
http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx
Sunday, August 03, 2008
MySpace and Facebook targeted by worm
Facebook users take care of this !!!
The worm variants are spread through the popular social networking sites, turning infected machines into zombies - PCs illicitly controlled by hackers to carry out tasks like denial of service attacks.The Net-Worm.Win32.Koobface.a is activated when a user accesses their MySpace account, and is spread when it automatically comments on linked friend's sites. Facebook is targeted by Net-Worm.Win32.Koobface.b, which sends messages to the infected user's contacts through the Facebook site.
Read More
The worm variants are spread through the popular social networking sites, turning infected machines into zombies - PCs illicitly controlled by hackers to carry out tasks like denial of service attacks.The Net-Worm.Win32.Koobface.a is activated when a user accesses their MySpace account, and is spread when it automatically comments on linked friend's sites. Facebook is targeted by Net-Worm.Win32.Koobface.b, which sends messages to the infected user's contacts through the Facebook site.
Read More
Subscribe to:
Posts (Atom)