Archive for May, 2008

Registrar Impersonation Phishing Attacks

Thursday, May 29th, 2008

ICANN SSAC (Security and Stability Advisory Committee) has published an advisory SAC 028 “Registrar Impersonation Phishing Attacks”.

Built-in Windows command line tools

Thursday, May 29th, 2008

Ed Skoudis describes some of built-in Windows commands. They can be useful to determine if a system has been hacked.

Five free pen-testing tools

Wednesday, May 28th, 2008

Nmap, Nessus, Metasploit Framework, Wireshark and KisMAC are featured in yesterday’s Computerworld article.

Vulnerability in Adobe Flash Player SWF File

Wednesday, May 28th, 2008

Adobe Flash Player is prone to an unspecified remote code-execution vulnerability.

Facebook XSS

Friday, May 23rd, 2008

New critical cross-site scripting vulnerability is found on Facebook.com.

SCPcert

Thursday, May 22nd, 2008

Microsoft announced the extension of the Microsoft Security Cooperation Program (SCP) to include computer emergency response teams (CERTs), computer security incident response teams (CSIRTS), and other response and guidance organizations that represent a nation, region or population. The primary goal of the third version of Microsoft SCP, called SCPcert, is to provide customers with the best protection possible by making necessary information available for CERTs to respond to computer security incidents.

Guardian Angel

Thursday, May 15th, 2008

A new U.S. Patent Application 20080082465 has been published in April. The assignee is Microsoft Corporation and Bill Gates is listed as one of the inventors. This Patent Application describes an intelligent personalized agent which monitors, regulates, and advises a user in decision-making processes for efficiency or safety concerns.

Botnets

Tuesday, May 13th, 2008

There are two interesting articles about botnets I have noticed in today’s headlines: “The botnet business” by Vitaly Kamluk (Viruslist) and “U.S. military to build botnet?” by Robert Lemos (SecurityFocus).

Vista security credentials tarnished in malware survey

Saturday, May 10th, 2008

“Windows Vista is better at protecting against malware than XP but more easily infected than Windows 2000, according to a study by Australian anti-virus firm PC Tools. [...] Recent research based on malware scans of more than 1.4m PCs running PC Tools’ ThreatFire security technology over a period of six months turned up 639 threats [...]

Malware evolution in Q1 2008

Friday, May 9th, 2008

Alexander Gostev, Senior Virus Analyst at Kaspersky Lab, has released the report “Malware evolution: January – March 2008″. What is interesting, in brief.