Tuesday, March 16, 2010
Big Brother 2.0
"The Feds are on Facebook. And MySpace, LinkedIn and Twitter, too.
"U.S. law enforcement agents are following the rest of the Internet world into popular social-networking services, going undercover with false online profiles to communicate with suspects and gather private information, according to an internal Justice Department document that offers a tantalizing glimpse of issues related to privacy and crime-fighting.
"Think you know who's behind that `friend` request? Think again. Your new `friend` just might be the FBI..."
More at laramieboomerang.com...
Thursday, March 11, 2010
IE Users PWN3D By 0day... Again
"Hackers are exploiting the just-disclosed unpatched bug in Internet Explorer (IE) to launch drive-by attacks from malicious Web sites, security researchers said today.
"`This attack appears to be rather targeted at the moment, but as with other unpatched vulnerabilities in the past, this has the potential to explode now that the word is getting out,` said Craig Schmugar, a threat researcher at McAfee, in a blog post today.
"Attacks are launched from Web sites in a classic drive-by fashion, said Schmugar and others. `Visiting the page is enough to get infected,` Schmugar said."
From ComputerWorld...
The First Rule Of Govt. Info Security...
"Last week, Pennsylvania’s chief information security officer Robert Maley was at an information security conference in San Francisco talking about a hacking incident involving PennDOT’s computers. This week, Maley is gone.
"Gary Tuma, Gov. Ed Rendell’s press secretary, confirmed that Maley is no longer employed by the state, but he declined to comment further, saying it is a personnel matter.
"Attempts to contact Maley yesterday were unsuccessful.
"Danielle Klinger, a spokeswoman for the state Department of Transportation, said the agency is not aware of any hacking or breach that occurred involving scheduling system for its driving test. However, she said that a few weeks ago, `we did discover an anomaly and we have actually turned that over to [the state police] for further investigation. We’re not sure what that anomaly is, but it is being investigated. Unfortunately, I can’t provide any more details on it.`"
More at PennLive.com...
Monday, March 8, 2010
Energizer Bunny Arrested, Charged With Battery
"A USB charger from Energizer uses software that contains a Trojan, according to US-CERT. The software was apparently developed outside the U.S. and may have been giving hackers access to PCs since 2007. An analyst said trust in the Energizer bunny may have led many consumers to install the DUO USB charger malware even with a warning.
"US-CERT researchers said Friday that the software that installs with the Energizer charger contains a Trojan horse that gives malicious hackers a back door into Windows machines.
"`An attacker is able to remotely control a system Relevant Products/Services, including the ability to list directories, send and receive files, and execute programs. The backdoor operates with the privileges of the logged-on user,` US-CERT said. `Removing the Energizer USB charger software will also remove the registry value that causes the backdoor to execute automatically when Windows starts.`"
More at NewsFactor.com...
Trust No One 2.0
"Facebook founder Mark Zuckerberg has been accused of hacking into the email accounts of rivals and journalists.
"The CEO of the world's most successful social networking website was accused of at least two breaches of privacy in a series of articles run by BusinessInsider.com.
As part of a two-year investigation detailing the founding of Facebook, the magazine uncovered what it claimed was evidence of the hackings in 2004.
"In the first instance, it said that, when Zuckerberg discovered that Harvard's student newspaper The Crimson was planning on running an article on him in 2004, he used reporters' Facebook logins to hack into their accounts.
"In the second instance, the magazine claimed Zuckerberg hacked into the accounts of rivals at Harvard who accused him of stealing their idea for a social network. He then allegedly tried to sabotage the rival network they had set up..."
Read thw whole story here...
Thursday, March 4, 2010
Insurance Companies Leverage Facebook To Raise Your Rates
"Any town U.S.A. You walk into a store and notice someone you recognize, from Facebook. But you really don’t know the individual; only online have you “met” that person. You have shared a note, or played a game on Facebook, Myspace, or other media website. You can choose to say hello or ignore them. That choice is up to you.
"Sometime in the future, you wind up in a car accident and suffer physical injuries that you decide can be claimed in a lawsuit against the insurance company. Now your friends on Facebook may not have any choice of getting to know you up close and in person. You may not even be aware that they are being questioned.
"Insurance companies are beginning to demand access to information about you and they do not want your explicit consent. In a Globe and Mail report, the insurance industry wants to use sites such as Facebook to collect and use background information collected to contradict any evidence you have used in your claim for damages.
"The first thing the insurance lawyers will do in court is to ask plaintiffs if they have Facebook accounts and demand a court order to review those account — even if you have always had your privacy settings configured to be not searchable by Google or other services. And if somehow they find out that you are on Facebook and you said no, chances are your lawsuit against the insurance company may fail. And so the game begins. The lawyers will have access to everything about you; your friends are also now exposed and may be questioned about your online habits what you are doing online, personal messages are read and now your friend’s privacy is also vulnerable - even if you have never met them in person..."
Morre at ZDNet...
XP Users Helpless Against New Web Hack
"Microsoft told Windows XP users today not to press the F1 key when prompted by a Web site, as part of its reaction to an unpatched vulnerability that hackers could exploit to hijack PCs running Internet Explorer (IE).
"In a security advisory issued late Monday, Microsoft confirmed the unpatched bug in VBScript that Polish researcher Maurycy Prodeus had revealed Friday, offered more information on the flaw and provided some advice on how to protect PCs until a patch shipped.
"`The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer,` read the advisory. `If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user.`"
From ComputerWorld...
Subscribe to:
Posts (Atom)