SEARCH RESULTS
 
Showing 1-10 of 18 records
 
Expand article

GMail Flaw Opens Floodgates for Spammers

2008-05-13 12:58:36 by Editor in Cheap Hack
 
...INSERT claims that any message header contents can be forged using it. The real problem here is not that you can send spam, but that it comes through Google's SMTP servers. Server-based reputation is one of the principal methods by which e-mail is filtered. Known bad servers are blacklisted and known good servers are whitelisted. Google's...
 
 
 
 
 
Expand article

Why PCI DSS is doomed.

The Article has images
2008-05-12 10:50:00 by Russ McRee in HolisticInfoSec.org
...insert code into your Web site to get a copy of their certificate. Since you are inserting code into your Web page for a GIF, it is anyones guess as to whether or not they are hacking your site at the same time they are supposedly protecting it Oh, scary. Common, guys. I think you should insert this picture on your website. Then your...
 
 
 
 
 
Expand article

More on Autorun

2007-10-30 22:12:27 by Steve Riley in Steve Riley on Security
 
...insert a USB drive that your computer has already seen. I received an email from Susan Bradley that links to an article on Nick Brown's blog, " Memory sitck worms ." Nick mentions the MountPoints2 registry key, which keeps track of all USB drives your computer has ever seen. I'll admit, I didn't know this existed! I'm glad Nick wrote about...
 
 
 
 
 
Expand article

Autorun: good for you?

2007-09-23 05:29:48 by Steve Riley in Steve Riley on Security
 
...inserting a CD-ROM or USB drive will bypass the autorun.inf file -- but do you really want to rely on individual users remembering this? Nope. Group policy is your security friend: put it to good use here and disable autorun right now BTW, Sony is up to their dirty old tricks again Updated, 22 September 2007. Turns out there's a registry key...
 
 
 
 
 
Expand article

Paul, Wheres the Beef (The CEP Jobs)?

2008-01-14 13:55:33 by Tim Bass in The Complex Event Processing Blog
 
...insert CEP vendor name here) professionals Curious, Ifollowed Pauls link and foundno references, or job openings,at TIBCO for CEP or BusinessEventsrelated positions Paul, where are theTIBCO CEP related jobs(the beef Inquiring minds want to know
 
 
 
 
 
Expand article

Central Bank of the UAE reports ATM fraud to lenders

The Article has images
2008-03-03 11:41:37 by Evan Francen in The Breach Blog
...insert an electronic reader into the card reader of one of its ATMs, which enabled them to copy the data of all the cards used in the said ATM during the period 19-25 February 2008 Evan] Obviously I don't use ATM machines in UAE much, but aren't there controls in place to prevent most tampering? The ATMs around here in Minnesota (US) would be...
 
 
 
 
 
Expand article

Disinfecting a virus-laden PC

2008-04-14 00:00:00 by HASH0x8472f5c in Network World on Security
 
When I insert a floppy into the A: drive and the floppy is used on another computer, that computer either then gets the virus or the anti-virus software on that computer reports that there is a virus trying to get access/control of the computer. How can I get rid of the virus
 
 
 
 
 
Expand article

Web Email Exploitation Kit in the Wild

The Article has images
2008-04-16 13:42:23 by HASH0x8ab1c88 in Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
...insert malicious code with iframe) 2) code, driving the victim to a page feykovuyu authorization. In the first case, the victim is in the browser's just a matter of your own scripte but in the second case, the victim is redirected to a page with false authorization, there enters its data, which logiruyutsya you, and sent back to his box. For...
 
 
 
 
 
Expand article

Hacking ISP Error Pages

2008-04-24 06:43:52 by schneier in Schneier on Security
 
...insert a YouTube video from 80s pop star Rick Astley into Facebook and PayPal domains. But a black hat hacker could instead embed a password-stealing Trojan. The attack might also allow hackers to pretend to be a logged-in user, or to send e-mails and add friends to a Facebook account Earthlink isn't alone in substituting ad pages for error...
 
 
 
 
 
Expand article

2FA is dead

The Article has images
2008-04-29 09:19:31 by Editor in Security x.0
...insert their bank card into a stand-alone reader. Unfortunately, there is nothing to stop an attacker using a 2FA authentication code to commit fraud In the classic Man in the Middle attack, the customer is coerced to visit the attacker's website, normally by a phishing email. The website will look identical to the legitimate bank site, but...