Hackers trying to plant malware on PCs have switched from touting CNN news in come-on messages to pushing breaking stories said to be from rival network MSNBC, security experts said today.
The fake messages pose with subject headings that include the phrase "Breaking News," along with phony news story headlines, such as " Jerry Yang relinquishes control over Yahoo," "Mary-Kate Olsen responsible for Heath Ledger's death," and "Plane crashes into prep school, hundreds of kids killed," said researchers at F-Secure Corp. and Sophos Plc
Read More
Thursday, August 14, 2008
Thursday, August 07, 2008
From BLACK HAT 2008: Google gadget flaws
Google gadgets are small applications, such as a currency converter, calendar or weather forecast, that can be added to the iGoogle homepage or a computer's desktop. The problem lies in the fact that the mini-modules are created by third-party developers, who can embed malicious JavaScript to redirect users to hacker websites, security researcher Robert “RSnake” Hansen told several hundred people in attendance
Read More
Read More
Tuesday, August 05, 2008
Microsoft to give partners heads-up on security vulnerabilities
Microsoft will be giving companies that sell security software and services to its customers a sneak peek at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly "Patch Tuesday" updates.
The new Microsoft Active Protection Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a change to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.
"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."
Read More
The new Microsoft Active Protection Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a change to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.
"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."
Read More
Switches are Supported by MS NAP 802.1x Enforcement
very Important article for implementing MS NAP 802.1x Enforcement
http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx
http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx
Sunday, August 03, 2008
MySpace and Facebook targeted by worm
Facebook users take care of this !!!
The worm variants are spread through the popular social networking sites, turning infected machines into zombies - PCs illicitly controlled by hackers to carry out tasks like denial of service attacks.The Net-Worm.Win32.Koobface.a is activated when a user accesses their MySpace account, and is spread when it automatically comments on linked friend's sites. Facebook is targeted by Net-Worm.Win32.Koobface.b, which sends messages to the infected user's contacts through the Facebook site.
Read More
The worm variants are spread through the popular social networking sites, turning infected machines into zombies - PCs illicitly controlled by hackers to carry out tasks like denial of service attacks.The Net-Worm.Win32.Koobface.a is activated when a user accesses their MySpace account, and is spread when it automatically comments on linked friend's sites. Facebook is targeted by Net-Worm.Win32.Koobface.b, which sends messages to the infected user's contacts through the Facebook site.
Read More
Wednesday, July 23, 2008
Details of major Internet flaw posted by accident
The flaw was discovered several months ago by IOActive researcher Dan Kaminsky, who worked through the early part of this year with Internet software vendors such as Microsoft, Cisco and the Internet Systems Consortium to patch the issue.
The companies released a fix for the bug two weeks ago and encouraged corporate users and ISPs to patch their DNS systems as soon as possible. Although the problem could affect some home users, it is not considered to be a major issue for consumers, according to Kaminsky.
Read More
The companies released a fix for the bug two weeks ago and encouraged corporate users and ISPs to patch their DNS systems as soon as possible. Although the problem could affect some home users, it is not considered to be a major issue for consumers, according to Kaminsky.
Read More
Tuesday, July 22, 2008
New risks in 802.11n
Along with the potential performance and coverage benefits of 802.11n come a few new security risks, says industry security guru Joshua Wright. Wright presented a Webinar last week that outlined several new vulnerabilities that high-speed 802.11n networks introduce
Read More
Read More
Monday, July 21, 2008
Facebook best Security practice
If you are Facebook user , really you need to read this
Sophos recommended privacy settings for Facebook
ID fraudsters target Facebook and other social networking sites to harvest information about you. Sophos experts recommend you set the following Facebook privacy options to protect against online identity theft.
Read More
Sophos recommended privacy settings for Facebook
ID fraudsters target Facebook and other social networking sites to harvest information about you. Sophos experts recommend you set the following Facebook privacy options to protect against online identity theft.
Read More
Sunday, July 20, 2008
Anything But Microsoft
Really nice Article to read
Microsoft is a security nightmare, Macs and Linux are a godsend.
Just because you're a Linux or Mac person sipping coffee in your server room on Patch Tuesdays doesn't mean you're immune from exploits. Nothing is bulletproof these days.
http://www.darkreading.com/document.asp?doc_id=99291&page_number=3
Microsoft is a security nightmare, Macs and Linux are a godsend.
Just because you're a Linux or Mac person sipping coffee in your server room on Patch Tuesdays doesn't mean you're immune from exploits. Nothing is bulletproof these days.
http://www.darkreading.com/document.asp?doc_id=99291&page_number=3
Tuesday, July 15, 2008
Intel Chips under Attack
Waaw!!!!!!!!
Security researcher and author Kris Kaspersky plans to demonstrate how an attacker can target flaws in Intel's microprocessors to remotely attack a computer using JavaScript or TCP/IP packets, regardless of what operating system the computer is running.
Read More
Security researcher and author Kris Kaspersky plans to demonstrate how an attacker can target flaws in Intel's microprocessors to remotely attack a computer using JavaScript or TCP/IP packets, regardless of what operating system the computer is running.
Read More
Thursday, July 03, 2008
IE8.0 new security features
Microsoft has outlined new security features it will add to Internet Explorer (IE) next month, including anti-malware protection to block most cross-site scripting attacks.
Read More
Read More
ISA Server 2006 Service Pack 1 - Released
Finally Microsoft has released ISA 2006 SP1 ,and you can downlaoded from the following link
http://www.microsoft.com/downloads/details.aspx?FamilyId=D2FECA6D-81D7-430A-9B2D-B070A5F6AE50&displaylang=en
http://www.microsoft.com/downloads/details.aspx?FamilyId=D2FECA6D-81D7-430A-9B2D-B070A5F6AE50&displaylang=en
Monday, June 30, 2008
Yahoo Mail flaw found and fixed
If you have Yahoo desktop messenger , you need to read this one
Researchers at Cenzic discovered a vulnerability in Yahoo Mail they said could allow attackers to steal Yahoo identities and potentially access users’ sensitive information.
The company, a Web application security provider based in Santa Clara, Calif., notified Yahoo of the cross-site scripting flaw in its popular Web mail program on May 23 and Yahoo fixed it June 13.
The vulnerability requires the attacker use Yahoo Messenger desktop application version 8.1.0.209 to chat with someone using the Messenger support in the latest version of Yahoo Mail. An attacker can make their chat status “invisible” and craft a malicious message; when he returns to the chat and the user clicks on the message, the malicious scripting is executed, said Mandeep Khera, Cenzic vice president of marketing.
Read More
Researchers at Cenzic discovered a vulnerability in Yahoo Mail they said could allow attackers to steal Yahoo identities and potentially access users’ sensitive information.
The company, a Web application security provider based in Santa Clara, Calif., notified Yahoo of the cross-site scripting flaw in its popular Web mail program on May 23 and Yahoo fixed it June 13.
The vulnerability requires the attacker use Yahoo Messenger desktop application version 8.1.0.209 to chat with someone using the Messenger support in the latest version of Yahoo Mail. An attacker can make their chat status “invisible” and craft a malicious message; when he returns to the chat and the user clicks on the message, the malicious scripting is executed, said Mandeep Khera, Cenzic vice president of marketing.
Read More
Saturday, May 24, 2008
ISA Server 2006 Service Pack 1 Features
Microsoft® Internet Security and Acceleration (ISA) Server 2006 Service Pack (SP) 1 will be available for your installation pleasure this summer!
really enjoy the new features
read More
really enjoy the new features
read More
Thursday, May 22, 2008
Microsoft Offers Cash To Use Its Search Engine
Microsoft plans to entice advertisers and users of its search engine with savings on online purchases on a site called Live Search cashback
Read More
Read More
Thursday, May 15, 2008
Facebook applications exposed as security risk
Take care while you are using Facebook , security report shows Facebook applications exposed as security risk
Speculation on the security of social networking has increased amid reports that applications on Facebook are capable of collecting personal information.
Read The Report
Speculation on the security of social networking has increased amid reports that applications on Facebook are capable of collecting personal information.
Read The Report
Tuesday, May 13, 2008
The Award for “outstanding Individual contributor FY08”

I was very delightful when I received a call from Symantec inviting me to attend the “Symantec Partner Awards Dinner 08” held in Dubai.
At the beginning they insisted to have me there without giving me a reason, I did my best to get the Visa and it did not work , So I wasn’t able to attend.
One of my colleges attended on my behalf and the surprise that I have been awarded as the “outstanding Individual contributor FY08”, Best Pre -Sales in the ME.
Monday, May 12, 2008
Flaw turns Gmail into spamming machine
A "serious security flaw" in Gmail turns Google's e-mail service into a spamming machine, according to a recent security report.
INSERT, the Information Security Research Team, has created a proof of concept that exploits the "trust hierarchy" that exists between mail service providers. By exploiting a flaw in the way Google forwards messages, a spammer can send thousands of bulk e-mails through Google's SMTP service, bypassing Google's 500-address bulk e-mail limit and identity fraud protections.
Read More
INSERT, the Information Security Research Team, has created a proof of concept that exploits the "trust hierarchy" that exists between mail service providers. By exploiting a flaw in the way Google forwards messages, a spammer can send thousands of bulk e-mails through Google's SMTP service, bypassing Google's 500-address bulk e-mail limit and identity fraud protections.
Read More
Wednesday, May 07, 2008
Microsoft is winning the NAC war, expert says
Why Microsoft is doing it right, ACLs are better than VLANs and the dirty dark corner of NAC (management).
By Julie Bort , Network World , 05/06/2008
Security guru Joel Snyder from Opus One recently starred as the guest of a live Network World chat where he discussed the state of network access control. Snyder says that Microsoft is emerging as one of the clear winners of NAC, but that Microsoft's technology is a foundation from which to build, not an end-all. He also says that those who are anti-NAC simply don't understand the technology. He answered a slew of technical questions from attendees including why ACLs are better than VLANs, the dirty dark corner of NAC (management) and the how and why of 802.1X. What follows is a full transcript
Read More
By Julie Bort , Network World , 05/06/2008
Security guru Joel Snyder from Opus One recently starred as the guest of a live Network World chat where he discussed the state of network access control. Snyder says that Microsoft is emerging as one of the clear winners of NAC, but that Microsoft's technology is a foundation from which to build, not an end-all. He also says that those who are anti-NAC simply don't understand the technology. He answered a slew of technical questions from attendees including why ACLs are better than VLANs, the dirty dark corner of NAC (management) and the how and why of 802.1X. What follows is a full transcript
Read More
Wednesday, April 30, 2008
MS gaining fast in AV-Comparatives tests
Detection rates up 7% in six months, more improvement predicted.
AV-Comparatives have released the results of their latest test of detection rates, pitting 17 scanners already known to perform well against their huge collection of malware. The most improvement over the previous run, which took place in February, was shown by Microsoft, whose score shot up by 7%.
The tests take the form of an on-demand scan over a testset of over 800,000 verified samples, including file and macro viruses, worms, trojans, backdoors and other malware, using 'best possible' settings. Multi-engine product AEC Trustport (which combines detection technologies from Norman, BitDefender and AVG) topped the tables with over 99.64%, with Avira's AntiVir in second place and another multi-engine scanner, GDATA's AVK, in third - both scored over 99%. Symantec and Kaspersky round out the top five, both spotting over 98% of all samples.
Read More
AV-Comparatives have released the results of their latest test of detection rates, pitting 17 scanners already known to perform well against their huge collection of malware. The most improvement over the previous run, which took place in February, was shown by Microsoft, whose score shot up by 7%.
The tests take the form of an on-demand scan over a testset of over 800,000 verified samples, including file and macro viruses, worms, trojans, backdoors and other malware, using 'best possible' settings. Multi-engine product AEC Trustport (which combines detection technologies from Norman, BitDefender and AVG) topped the tables with over 99.64%, with Avira's AntiVir in second place and another multi-engine scanner, GDATA's AVK, in third - both scored over 99%. Symantec and Kaspersky round out the top five, both spotting over 98% of all samples.
Read More
Subscribe to:
Posts (Atom)