The autocomplete feature can be pretty handy at times. It helps you log in on your favorite website faster or load a website in your browser without having to enter the full web address. Researchers from Minded Security Labs have released a proof of concept that demonstrates how a third party website can get access [...]
- Author: Mike Halsey MVP
- Comments: 8
Windows 7 Enterprise Security is better than OS X
Researchers at Black Hat have said that they’ve found Windows 7′s Enterprise security to be better than that of Apple’s OS X operating system. The problems for OS X seem to stem from user privileges. While Windows 7 isn’t perfect, OS X seems to have more “soft spots” according to a report by Network World. [...]
- Author: Mike Halsey MVP
- Comments: 1
Adobe / Microsoft to team up on Vulnerability Sharing
Microsoft has announced that it’s to extend it’s Microsoft Active Protections Program (MAPP) to include vulnerability sharing information from Adobe. The programme, launched in October 2008 allows sharing of information about security vulnerabilities with security software vendors. So far 65 companies have signed up to the scheme.
- Author: Mike Halsey MVP
- Comments: 2
Microsoft warn of Windows Shell Critical Vulnerability
Microsoft have warned of a critical vulnerability in Windows Shell, caused when parsing .lnk shortcuts that can automatically launch a malicious program through use of a specially crafted shortcut. The vulnerability afcects all versions of Windows including XP and Windows 7. On Windows 7 the exploit can bypass the operating system’s security as it does not [...]
- Author: Mike Halsey MVP
- Comments: 4
Adobe release ‘critical’ Flash patch
Adobe have today released a patch to sort out the critical vulnerability in Flash that was discovered last week, which is a quick turnaround. The patch, released through version 10.1 of the Flash player is available now from www.adobe.com and there is also a new version of Adobe Air as well.
- Author: Martin Brinkmann
- Comments: 12
Adobe Fixes Critical Shockwave Vulnerability
Adobe has issues a security patch for the Adobe Shockwave software program that fixes one vulnerability that has been rated critical by Adobe Software. The vulnerability gives attackers, who can attack systems remotely, control over affected computer systems. The interesting aspect of the issued patch is that Adobe recommends to completely uninstall Adobe Shockwave 11.5.0.596 [...]
- Author: Martin Brinkmann
- Comments: 4
New Attack: Combine Files With Jar Scripts
A new attack, dubbed Gifar by their creators named after the two file types that they mixed to create the attack (Gif and Jar), was mentioned in a Black Hat Sneak Preview article over at ZDnet. While not everything was revealed in that preview article it mentioned that the developers were able to combine two [...]
- Author: Martin Brinkmann
- Comments: 4
Are you running the latest browser version?
In a recently released research paper Stefan Frei, Thomas Dübendorfer, Gunter Ollmann and Martin May analyzed Google Search Engine logs between January 2007 and June 2008 to understand the web browser threat. The research paper brought up some interesting figures including worldwide browser usage, number of users with the latest version of the browser and [...]
- Author: Martin Brinkmann
- Comments: 19
You better stop using Internet Explorer for now
A security vulnerability came to light recently that affects Internet Explorer 6, Internet Explorer 7 and even Internet Explorer 8 that can be used to record keystrokes of a user even if he is switching domains. That means that a specifically prepared website can launch some Javascript that records everything the user does afterwards including [...]
