Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

Monday, May 14, 2012

Microsoft Causes OSX Vulnerability, Then Gloats

Microsoft discovered a vulnerability in Word that could allow an attacker to execute code on any system using Microsoft Word to read a specially malformed document, then spins it to say it is proof that Macs are just as vulnerable as Windows to document-based attacks.

Friday, October 15, 2010

Microsoft Hopelessly Battles with an Angry Dragon Inside Its Own Network

Ok, the headline is exaggerated, but only a bit.

Microsoft's squeaky-tight security was bypassed by hackers who subsequently used their uber-hardened servers to send spam about cheap viagra, penis enlargement, and other services that don't come with a dubious EULA. Oh, and they even launched an attack against an information security blogger.

I can't wait to hear the spin on this one.

Tuesday, October 5, 2010

Antivirus Companies Finally Do Something About Their Own Website Security

In an industry where security companies have gotten rich enough to practice what they preach, you'd expect them to be setting the example when it comes to secure coding practices. It's the age old story about the cobbler's kids wearing crappy shoes.

You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.

Some of the companies that should know better: Symantec, Eset, and Panda.

Friday, September 24, 2010

First Worm To Deliberately Attack SCADA Systems Found

In June, Belarus antivirus company VirusBlokAda reported a new bug with some interesting features. The Stuxnet worm they discovered was programmed to specifically attack industrial control systems, and reprogram the controllers to hide the changes from view using a methods almost identical to those used in 1980's - 90's stealth viruses.

The last time someone hacked up a SCADA system like this, it caused a 3 kiloton explosion that was reported as having been the most monumental non-nuclear explosion and fire ever seen from space.

Thursday, September 9, 2010

Twittering Too Much?

The Register posted an article about a bug that could cause Internet Explorer to post tweets just by visiting a website like this one.  Of course, since the exploit works by stealing the credentials of other active sessions in your browser, Chris' concept can be tweaked to access just about any site where people tend to stay logged in, such as facebook or gmail.

Of course, just about every other browser in existence has already fixed this bug.

Tuesday, July 27, 2010

Dell Blames Their Own Staff for Spybot Infected Motherboards

Instead of admitting it was a huge corporate blunder, Dell blames a handful of its workforce instead of its own processes and governance, for a recent spat of infected server-class motherboards.

Dell claims all infected motherboards have been replaced.

Technician Aboard the BP Oil Rig that Exploded Shut Alarms Off To Avoid Waking Up The Crew

Apparently the system that monitors and controls drilling operations was running Windows, and kept crashing with the famed Blue Screen of Death (BSoD). An alarm that goes off to alert the crew to dangerous levels of combustible gases was shut off to avoid waking anyone up. Aren't BSoD's and alarms meant to wake people up and alert them to problems?

Wednesday, July 7, 2010

Microsoft Officially Out of the Vulnerabilities Loop

Companies have finally started to realize that giving Microsoft free security consulting is losing them money overall.

VUPEN, who used to be known as FrCIRT, who used to be a 0-day vulnerability disclosure site, have ceased sending free vulnerability reports to Microsoft to help them fix their security woes. Instead the reports, exploit code, patches, and whatever else they produce goes straight to their paying customers - none of whom are Microsoft.