Showing posts with label General Security. Show all posts
Showing posts with label General Security. Show all posts

Saturday, September 29, 2007

Banking Trojans

F-secure recently released a paper on Banking Trojans. The paper talks about various methods used by Trojans targeting online money transactions. It also talks about a tool called “Mstrings” which helps in identifying Banking Trojans.

The paper is available at F-secure's website.

Wednesday, September 12, 2007

Codename 1234 !!!

Recently a list of around 100 email ids and passwords were posted by a hacker on his website (Deranged).All these accounts belonged to various government organizations around the globe and contained classified information. Some passwords in the list were too simple that even a small kid could have broken into those accounts. Most Indian embassies had one of the easiest passwords somebody could think of (1234).Indian DRDO seems to be much better in choosing passwords ,They seems to have added 1 to their password and made it more secure !!!! (password+1).

Tuesday, September 11, 2007

Phishing in 30 Seconds

These days even Phishing software comes with video tutorials.
The following video demonstrates how to use a phishing software called Auto Phisher.

Auto Phisher Tutorial

Thursday, August 30, 2007

Another Yahoo Security Fix

Within a week after its previous security update, Yahoo has now come up with another security fix. This update patches a stack overflow in one of the activex controls related to Yahoo Messenger. According to analysis by iDefense.


It is important to note that functions within this class can only be called if the control believes it is being run from the yahoo.com domain. In order for this exploit to be triggered an attacker would either have to leverage a Cross-Site Scripting vulnerability in the yahoo.com domain, or be able to control the targeted user's DNS resolution


Yahoo's advisory related to this vulnerability could be found at http://messenger.yahoo.com/security_update.php?id=082907

Patched version of Yahoo Messenger is available at http://messenger.yahoo.com/download.php.

Monday, August 27, 2007

Yahoo Fixes Security Flaw

Yahoo recently released an updated version of Yahoo Messenger which fixes a heap based overflow in one of its webcam related functions. Details about the update could be found at http://messenger.yahoo.com/security_update.php?id=082107.

A proof of concept for the above mentioned vulnerability was posted last month on a Chinese security forum. Later this was found and reported by a researcher of Mcafee Avertlabs. The vulnerability was fixed within one week after it was reported by Avertlabs but more than one month after it first appeared in a public forum.