Security

Sun issues patches for ‘highly critical’ Java flaws

Oct 4, 2007   5 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

sun_java_logo Sun Microsystems has shipped patches to fix a batch of “highly critical” vulnerabilities in Sun Java JRE (Java Runtime Environment), affecting Windows, Solaris and Linux users.

According to researchers, the flaws can be exploited to bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system.

Click for more on Sun issues patches for ‘highly critical’ Java flaws »

New Software Security

Apple Finally Patches Year-old QuickTime Flaw

Oct 4, 2007   1 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock The flaw, which affects Windows XP and Windows Vista machines, opens up a backdoor that could enable a hacker to break into Firefox.

The company released an update for the Windows version of QuickTime media player on Wednesday afternoon to patch what Apple calls a “command injection issue” in the way the media player handles URLs. The flaw, which affects Windows XP and Windows Vista, was first disclosed in September of 2006 by Petko D. Petkov, a penetration tester.

Click for more on Apple Finally Patches Year-old QuickTime Flaw »

Cell Phone Security

iPhone Turned into Pocket-Sized Hacking Platform

Oct 2, 2007   4 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock It turns out all iPhone applications run as root and any application vulnerability means winner takes all.

The iPhone has been turned into a “pocket-sized … network-enabled root shell,” said H.D. Moore, thanks to the well-known security researcher having published shell code and instructions for the smart phone on how to use it as a portable hacking platform.

Click for more on iPhone Turned into Pocket-Sized Hacking Platform »

Security

Virtual rootkits not a problem, say researchers

Oct 2, 2007   1 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock Rootkits that use virtualization techniques should not present detection problems, according to researchers from Carnegie Mellon and Stanford universities.

Working with virtualization technology vendors VMware and XenSource, the researchers produced a study recently called “Compatibility is Not Transparency: VMM Detection Myths and Realities.” (PDF) In the study, the researchers said that rootkits could not use hypervisor technology to remain undetected on a system.

Click for more on Virtual rootkits not a problem, say researchers »

Security

AOL Working On Patch For Instant Messenger Vulnerability

Sep 27, 2007   2 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock Security researchers disclosed a bug in AIM that could enable a hacker to remotely execute malicious code, affecting all AIM versions under Windows.

America Online is working on a patch for what security researchers are calling a “major vulnerability” in the company’s highly popular Instant Messenger application.

Click for more on AOL Working On Patch For Instant Messenger Vulnerability »

Security

Gmail cookie vulnerability exposes user’s privacy

Sep 27, 2007   1 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

gmail-logo Can be used to steal contacts and incoming e-mails from Google Gmail users.

A proof-of-concept program, by a hacker group “GNUCitizen”, demonstrate the vulnerability, which can be used for malicious purposes.

Click for more on Gmail cookie vulnerability exposes user’s privacy »

Security

Hackers expose holes in GMail, Blogspot, Search Appliance

Sep 25, 2007   5 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock Multi security issues are affecting the widely used GMail, Blogspot and Picasa services.

In the past few days, there have been multiple disclosures of security vulnerabilities in a wide range of Google products.

Click for more on Hackers expose holes in GMail, Blogspot, Search Appliance »

Security

Critical vulnerability found in Ask.com toolbar for IE

Sep 25, 2007   3 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock A vulnerability in Ask.com’s toolbar for Internet Explorer could allow an attacker to take control of a person’s computer, according to security advisories.

The problem concerns a buffer overflow flaw in the toolbar and involves an ActiveX control, according to an advisory posted by security vendor Secunia APS, which rated the problem as “highly critical,” its second most severe rating. It affects version 4.0.2 of the toolbar and possibly others.

Click for more on Critical vulnerability found in Ask.com toolbar for IE »

Security

OpenOffice bug hits multiple operating systems

Sep 25, 2007   3 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

ooo_writer Vulnerabilities in OpenOffice.org could allow attackers to remotely execute code on Linux, Windows or Apple Mac-based computers.

OpenOffice version 2.0.4 and earlier versions are vulnerable to maliciously crafted TIFF files, which can be delivered in an e-mail attachment, published on a Web site or shared using peer-to-peer software.

Click for more on OpenOffice bug hits multiple operating systems »

Security

Multi Google Security Holes Revealed

Sep 24, 2007   2 pm
These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Technorati
  • Furl

security-lock Multiple Google-targeted exploits disclosed in the past 3 days could compromise your GMail account, steal your pictures from Picasa or impersonate you on almost 200,000 big sites.

In the past 3 days, 4 interesting disclosures have been published:

Click for more on Multi Google Security Holes Revealed »