January 30, 2009 4:23 AM
Posted by: Ken Harthun
Anti-malware,
Cybercrime,
Malware,
TrojanTalk about irony. You get infected by a cybercriminal's illegal bot (Ozdok/Mega-D in this case) which takes a screen shot that shows you searching for illegal underage porn; then, security researchers get hold of some screen shots from the bot's command and control (C&C) server; while going...
January 23, 2009 2:15 AM
Posted by: Ken Harthun
Malware,
Opinion,
Patch management,
Security,
Security bulletin,
Zero-day vulnerabilityThe latest mass infection to hit the Internet is the Win32/Conficker/Downadup Worm, estimated to have already infected between 500,000 and 8.9 million PCs, depending on whose numbers you believe. This is astounding, considering that the worm exploits a vulnerability in Windows that Microsoft
January 18, 2009 1:34 AM
Posted by: Ken Harthun
Data destruction,
Data sanitization,
Secure Computing,
Secure drive wipe,
SecurityHow many times do you have to overwrite a hard drive in order to securely wipe it? This question has been at the center of an ongoing controversy for a long time. On the one hand, we've had Peter Gutmann saying it takes 35 passes (Gutmann, P. (1996) “
January 17, 2009 3:27 AM
Posted by: Ken Harthun
Anti-malware,
Cybercrime,
Exploits,
Malware,
Secure Computing,
Security,
VulnerabilitiesWith cybercriminals now actively poisoning search results and legitimate websites--unbeknownst to the webmasters--you can't be too careful when clicking on links. Take a look at this video library presented by
January 7, 2009 3:35 AM
Posted by: Ken Harthun
Cryptography,
hashing algorithm,
MD5,
Security,
SHA1,
VulnerabilitiesJust last week, two German security researchers, Alex Sotirov and Jacob Appelbaum, made a surprising announcement at the Chaos Communication Conference in Berlin: they had created a fraudulent Certificate Authority (CA) that had a valid signature from a root CA, Equifax, one of the oldest. The...
December 30, 2008 8:33 PM
Posted by: Ken Harthun
Malware,
Phishing,
SecurityCastleCops, the largest and most effective volunteer security community on the Internet, has shut down operations. Their website has this announcement posted:
You have arrived at the CastleCops website, which is currently offline. It has...
December 24, 2008 4:43 PM
Posted by: Ken Harthun
Database,
Remote Code Execution,
Security,
SQL Server,
VulnerabilitiesMicrosoft's latest Security Advisory (961040) covers a vulnerability in SQL Server that could allow remote code execution:
Microsoft is investigating new public reports of a vulnerability that could allow...
December 21, 2008 11:19 PM
Posted by: Ken Harthun
Anti-malware,
Browsers,
Firefox,
Internet Explorer,
Opinion,
Phishing,
Security,
VulnerabilitiesSecurity Fix reports that on December 16, Mozilla released its final update to Firefox 2, and plans no...