Some news, views and musing about things going on in the Information Security World.
Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts
Monday, May 14, 2012
Microsoft Causes OSX Vulnerability, Then Gloats
Microsoft discovered a vulnerability in Word that could allow an attacker to execute code on any system using Microsoft Word to read a specially malformed document, then spins it to say it is proof that Macs are just as vulnerable as Windows to document-based attacks.
Key Words:
0-day,
computer viruses,
hacking,
microsoft,
security controls,
trojan
Friday, October 15, 2010
Microsoft Hopelessly Battles with an Angry Dragon Inside Its Own Network
Ok, the headline is exaggerated, but only a bit.
Microsoft's squeaky-tight security was bypassed by hackers who subsequently used their uber-hardened servers to send spam about cheap viagra, penis enlargement, and other services that don't come with a dubious EULA. Oh, and they even launched an attack against an information security blogger.
I can't wait to hear the spin on this one.
Microsoft's squeaky-tight security was bypassed by hackers who subsequently used their uber-hardened servers to send spam about cheap viagra, penis enlargement, and other services that don't come with a dubious EULA. Oh, and they even launched an attack against an information security blogger.
I can't wait to hear the spin on this one.
Tuesday, October 5, 2010
Antivirus Companies Finally Do Something About Their Own Website Security
In an industry where security companies have gotten rich enough to practice what they preach, you'd expect them to be setting the example when it comes to secure coding practices. It's the age old story about the cobbler's kids wearing crappy shoes.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
Key Words:
0-day,
computer viruses,
hacking,
microsoft,
security controls,
trojan
Friday, September 24, 2010
First Worm To Deliberately Attack SCADA Systems Found
In June, Belarus antivirus company VirusBlokAda reported a new bug with some interesting features. The Stuxnet worm they discovered was programmed to specifically attack industrial control systems, and reprogram the controllers to hide the changes from view using a methods almost identical to those used in 1980's - 90's stealth viruses.
The last time someone hacked up a SCADA system like this, it caused a 3 kiloton explosion that was reported as having been the most monumental non-nuclear explosion and fire ever seen from space.
The last time someone hacked up a SCADA system like this, it caused a 3 kiloton explosion that was reported as having been the most monumental non-nuclear explosion and fire ever seen from space.
Key Words:
0-day,
computer viruses,
data destruction,
hacking,
microsoft,
physical security,
security controls,
spying,
terrorism,
trojan
Thursday, September 9, 2010
Twittering Too Much?
The Register posted an article about a bug that could cause Internet Explorer to post tweets just by visiting a website like this one. Of course, since the exploit works by stealing the credentials of other active sessions in your browser, Chris' concept can be tweaked to access just about any site where people tend to stay logged in, such as facebook or gmail.
Of course, just about every other browser in existence has already fixed this bug.
Of course, just about every other browser in existence has already fixed this bug.
Key Words:
0-day,
hacking,
microsoft,
security controls,
trojan
Tuesday, July 27, 2010
Dell Blames Their Own Staff for Spybot Infected Motherboards
Instead of admitting it was a huge corporate blunder, Dell blames a handful of its workforce instead of its own processes and governance, for a recent spat of infected server-class motherboards.
Dell claims all infected motherboards have been replaced.
Dell claims all infected motherboards have been replaced.
Technician Aboard the BP Oil Rig that Exploded Shut Alarms Off To Avoid Waking Up The Crew
Apparently the system that monitors and controls drilling operations was running Windows, and kept crashing with the famed Blue Screen of Death (BSoD). An alarm that goes off to alert the crew to dangerous levels of combustible gases was shut off to avoid waking anyone up. Aren't BSoD's and alarms meant to wake people up and alert them to problems?
Wednesday, July 7, 2010
Microsoft Officially Out of the Vulnerabilities Loop
Companies have finally started to realize that giving Microsoft free security consulting is losing them money overall.
VUPEN, who used to be known as FrCIRT, who used to be a 0-day vulnerability disclosure site, have ceased sending free vulnerability reports to Microsoft to help them fix their security woes. Instead the reports, exploit code, patches, and whatever else they produce goes straight to their paying customers - none of whom are Microsoft.
VUPEN, who used to be known as FrCIRT, who used to be a 0-day vulnerability disclosure site, have ceased sending free vulnerability reports to Microsoft to help them fix their security woes. Instead the reports, exploit code, patches, and whatever else they produce goes straight to their paying customers - none of whom are Microsoft.
Subscribe to:
Posts (Atom)