« May 2005 | Main | July 2005 »

Thursday, June 30, 2005

Microsoft & RSS security

It seems I'm not the only one concerned about the implications of integrating RSS into every application via the OS. Check the earlier post here: Longhorn RSS Support

Posted by Matthew Carrick at 10:32.17 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:10.56 PM EDT

| Categories: RSS Applications

Wednesday, June 29, 2005

Newest Windows AntiSpyware (Beta)

This is indeed good news. The original version of this application was due to die on June 31, 2005. This newest version will live until Dec 30, 2005. It is, of course, new and improved with Vitamin B, B12 and Riboflavin. Yes, we know Windows is a security nightmare but this application is a further step in the right direction for Microsoft.Get it. Use it.

Posted by Matthew Carrick at 2:30.43 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:12.38 PM EDT

| Categories: Adware/Spyware

Tuesday, June 28, 2005

Longhorn RSS Support

While browsing the web, users will be able to easily discover RSS feeds through an illuminated icon, as well as read the feed while still in the web browser. Additionally, users will be able to subscribe to an RSS feed as easily as adding a web page as a favorite. Once a user chooses to subscribe to a feed, the fact that the user has subscribed is available to any interested application.

Uh-huh. How long will it take until some nasty script automatically and in the background subscribes me to ad-driven crap that proceedes to infiltrate to my other interested applications?

Unless the security of Internet Explorer + Longhorn is substantially improved there is no way in hell I'm letting this loose on my system.

Posted by Matthew Carrick at 3:47.52 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:14.47 PM EDT

| Categories: Best Practices, RSS Applications

Mac Adobe Reader/Acrobat Vulnerabilities

Mac OS X users of Adobe Reader and Adobe Acrobat should upgrade to version 7.0.2 from 7.0 or 7.0.1 or they risk having arbitrary code launched on their beloved coloured box.

See: http://www.adobe.com/support/downloads/

Posted by Matthew Carrick at 10:19.42 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:14.31 PM EDT

| Categories: Security Alerts

Sunday, June 26, 2005

Customer Support - Real Security Updates

Poor old RealPlayer has been affected by a potential security flaw.

Check the link and determine if your installed version needs a patch or a newer version.

According to the Website my install needed the patch only but during the install process I was informed that I really needed to get the full install - this may simply be a way to get the newest version installed and so inflict the latest sponsored junk on me.



Posted by Matthew Carrick at 8:24.59 AM EDT | Permanent Link

| Categories: Security Alerts

Friday, June 24, 2005

Multiple Browsers Fail Spoof Test

These phishing attacks could be successfully carried out on the following browsers:

1) Firefox 1.0.4
2) Internet Explorewr 6.0

But NOT on these browsers:

1) K-Meleon 0.9
2) Opera 8.1

The trick here is never key information into a browser window if you can't easily identify the source of the window.

Posted by Matthew Carrick at 9:48.52 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:22.32 PM EDT

| Categories:

Sunday, June 19, 2005

40,000,000 VISA Cards Compromised?

A security breach affecting some 40 million credit cards was announced today.
It appears that little personal information was accessed indicating future identity theft is unlikely, merely a little disappearing cash. Whoa, dodged a bullet there.

Better Safe Than Sorry, eh?

Posted by Matthew Carrick at 8:38.52 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:23.39 PM EDT

| Categories:

Thursday, June 16, 2005

Hackers Access Canadian Credit Bureau

Hackers have accessed some 600 credit records located in a British Columbia credit bureau. The affected people are mostly located in BC as well. The Globe and Mail reports Equifax and the R.C.M.P are conducting an investigation and Equifax has contacted the affected consumers.

The report goes on to say that affected customers will be given a year's subscription to a service that monitors credit activity and warns customers of possible irregularities possibly leading to identity theft.

Posted by Matthew Carrick at 1:16.15 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:24.40 PM EDT

| Categories:

Hackers Access Canadian Credit Bureau

Posted by Matthew Carrick at 1:16.15 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 2:58.19 PM EDT

| Categories: Security Alerts

Upgrade Your Opera to Version 8.01

A flaw in Opera 8.0 has been discovered. The easiest solution is to upgrade to Opera 8.01. DO IT NOW.

Posted by Matthew Carrick at 12:59.48 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:25.30 PM EDT

| Categories:

Upgrade Your Opera to Version 8.01

Posted by Matthew Carrick at 12:59.48 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 2:55.53 PM EDT

| Categories: Opera

Saturday, June 11, 2005

Jacko Suicide Email is Trojan

Don't be fooled by this email message. The linked site will attempt to download a trojan to your PC. If you use an unpatched version of Internet Exploder you may then be unwittingly enlisted into a bot network - oooh, scary.

So, don't clck on links in email from people you don't know, don't use Internet Exploder or if you must make sure you have the latest security hotfixes applied and always have a recently updated Anti-virus application running in case you manage to infect yourself.

Posted by Matthew Carrick at 8:47.42 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 6:24.50 PM EDT

| Categories: Security Alerts, Viruses-Trojans-Worms

Tuesday, June 07, 2005

Browser Frame Injection Phish

This exploit is very old (1998) so why it has reappeared should be interesting! This vulnerability allows web sites to project their content into a frame hosted my another site. Very nasty. Even using SpoofStick (you are using SpoofStick, right?) won't help protect you here.

The work around here is to always visit your banking or other sensitive sites using ONE BROWSER WINDOW ONLY. Close all other Browser Windows and when you are finished close your Browser completely.

Or do not open new windows at all - use tabs only as this exploit does not work from tab to tab only from window to window.

Posted by Matthew Carrick at 12:57.08 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:26.23 PM EDT

| Categories:

Browser Frame Injection Phish

Posted by Matthew Carrick at 12:57.08 PM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 2:59.12 PM EDT

| Categories: Security Alerts

Friday, June 03, 2005

Cracking 'secure' Bluetooth devices

Uh-oh. Bluetooth appears to be the WIN95 of wireless communication - a giant open security hole. Two chaps have found that virtually any Bluetooth device can be cracked in as little as a few seconds. Best to turn off Bluetooth for now me thinks!

Posted by Matthew Carrick at 10:55.25 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 4:27.17 PM EDT

| Categories:

Cracking 'secure' Bluetooth devices

Posted by Matthew Carrick at 10:55.25 AM EDT | Permanent Link
Edited on: Wednesday, July 20, 2005 2:58.33 PM EDT

| Categories: Security Alerts
Archives

Archive Index
Categories
Adobe
Adware/Spyware
All Things Mac
Alternative Apps
Best Practices
Bluetooth
Concepts
Eudora Email
Firefox Extensions
Google Chrome
Hardware Innovations
Hardware Recalls
Headlines
Instant Messaging
Internet Explorer
Mac Safari Browser
Mobile
Mozilla Firefox
Mozilla Thunderbird
Online Apps
Openoffice.org
Open Source
Opera
Penelope Email
Physical Security
Privacy Issues
RSS Applications
Security Alerts
Software Tools
Technology
TPDBP
Viruses-Trojans-Worms