Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Microsoft urges users to stop using safari on windows

Sunday, June 1, 2008 |

Microsoft security advisory: Blended Threat from Combined Attack Using Apple’s Safari on the Windows Platform
Microsoft

Microsoft on
May 30, 2008 issued an advisory that warned windows users to not use apple's safari web browser until a patch is available that could stop the attackers to hack computers.
Microsoft Security Response Center (MSRC) issued a security advisory, which it called a "blended threat".
It is caused by a combination of a bug in Apple's Safari Web browser and the vulnerability in the way the Windows XP and Vista handle executable (exe) files on the desktop. This allows the remote execution of malicious code on all supported Windows XP and Vista when the Safari web browser for Windows is installed. This bug was disclosed 2 weeks ago by a researcher Nitesh Dhanjani.

Safari lacks an option to require a user's permission to download a file. Attackers, could populate a malicious site with a code that Safari that would automatically download to the desktop, which is the default location.

Nitesh Dhanjani


A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed. Safari is available as a stand-alone install or through the Apple Software Update application.

An attacker could trick users into visiting a specially crafted Web site that could download content to a user’s machine and execute the content locally using the same permissions as the logged-on user.

Microsoft

High bandwidth : The evil side

|

Scientists across the world are devising new techniques and are exploring other protocols to serve one purpose, a high bandwidth. Internet service providers are competing with each other to provide higher bandwidths to customers at competitive prices. The world is on the internet highway, where the speed limit is continuously increasing. We live, talk and socialize on the internet. Some of us met their life partners on the internet. Wow! what a life changing experience. Amidst all this positivity and development, there have been many people who have been affected. Some positively and a few negatively. The most affected people have been the movie producers. Their movies have been stolen, ripped and are available for download on forums across the world. For the internet user with a high bandwidth and a less price, it would take a few minutes to download the DVD rip of a movie. A movie once downloaded, will surely be circulated across and once his friends see the movie, they wouldn't actually spend money to go to the theater to watch them. If you are more patient, a week or two (maximum) after the movies release, pirated copies are available for less than $1. With high bandwidth comes the risk of huge file transfers (illegal). Recently some chinese suckers (hackers), hacked Indian defense websites, stealing vital information. I feel hacking is an achievement (of evil) in itself and hackers being the lord voldermort (the evil guy) of harry potter. Some times this evil is used by us, when we use and watch pirated stuff. It will take some hard work and smart effort by the antivirus and web security companies to curb the ill effect of high bandwidth

Gmail was on the verge of collapse

Sunday, February 24, 2008 |

If a genie granted you a wish, would "The ability to access other people's Gmail accounts" be it? Abdulaziz Al-Shalabi from Kuwait wasn't visited by a genie, but he was granted access to Gmail accounts that were not his -- for a considerable period of time at that!

The goof-up began last weekend and only stopped on Wednesday. As it happened, Al-Shalabi was incessantly trying to access his Gmail, and he just wasn't able to. It's not clear whether entering his own username and password -- or random ones -- allowed him access to other Gmail accounts. But as he reported to News.com, he got a peek into the private information of over 30 Gmail users.
The problem apparently occurred only over Al-Shalabi's ISP and with Gmail accounts; it didn't work with Hotmail accounts, for example. Having heard the news, a Gmail user in Sri Lanka reported a similar experience.

Acknowledging the problem, a Google spokesman said the goof-up had occurred in Kuwait because of a server caching problem the ISP was facing. He said Google was in contact with the ISP in question in order to find a solution. It's not known whether other Google sites were also affected by the ISP's problem, and if so, to what extent.

This is certainly a one-off incident, and we're certainly not trying to say you should switch away from Gmail. What's to be learnt is that the system isn't foolproof, and that it's possible for your mail to become accessible to others -- which, we bet, most of you would have thought impossible (unless your password is "abc123" and someone guessed it, in which case you deserve it).

If you're the really paranoid kind, and this bit of news has shaken you more than a bit, you might consider encrypting sensitive mails (such as those in which you call your boss an unfortunate accident of evolution) using a free service such as Hushmail.

Source:techtree.com

Microsoft reveals hole in Excel

Sunday, January 20, 2008 |

Microsoft has revealed that hackers have found a way to infiltrate older versions of its Excel program to take control of infected computer systems.

Earlier in the week, the software major said it's investigating reports of such attacks though hasn't yet determined whether it will go ahead and patch the bug, and if so, when.

Q) How will it infiltrate the anti-virus cordon and how can you protect your PC from it ?
Ans) The modus operandi is: you may either get a specially crafted Excel file as an email attachment or may end up visiting a compromised Web site -- either ways, you could be inviting hackers to arbitrarily take control of your PCs for furthering their malicious cause, be it stealing passwords and other personal information or sending out spam.

Microsoft Office Excel 2003 Service Pack 2, Excel Viewer 2003, Excel 2002, Excel 2000, and Excel 2004 for Mac, are all vulnerable to this form of attack, Microsoft said.

The way to go for users, as advised by Redmond, is to use a tool named 'Microsoft Office Isolated Conversion Environment', which scans files for bad code before opening them.

Meanwhile, more recent versions of Excel such as Excel 2007, Excel 2007 SP 1, and Excel 2008 for Mac are believed not to be vulnerable.