Archive for 2010

Faceparty password sites really want you to click on things

April 14, 2010 - “Faceparty is a UK based social networking site allowing users to create online profiles and interact with each other using forums and messaging facilities similar to email” - Wikipedia Faceparty does things a little differently to other social (continue reading...) Read more

From XSS to root: Lessons Learned From a Security Breach

April 14, 2010 - In an excellent blog, the people from Apache did a very good job analyzing and documenting how a security breach happened–going through all the stages of the attack and drawing conclusions. Should you (continue reading...) Read more

The road to glory, from XSS to Root on apache.org

April 14, 2010 - On the 9th of April 2010, Apache.org infrastructure suffered a direct and targeted attack on the server hosting the Apache issue-tracking software, Atlassian JIRA.  This is the second major compromise (continue reading...) Read more

Online Backup Beta 2.2.0

April 14, 2010 - Looking for something to do at home this weekend? You are? Excellent, then try out our latest Online Backup beta.I have to admit, I (continue reading...) Read more

Zipping Images and Documents – Did That Really Help?

April 14, 2010 - Does anyone really care about opening a zip file to examine an RTF or JPEG file? This task—combined with a dull, unexciting, unstimulating subject line—competes with the content of the email to win a race of worthlessness. This is how (continue reading...) Read more

Phishers Send Out Standard Chartered Spam

April 14, 2010 - TrendLabsSM recently encountered a phishing email specifically targeting Standard Chartered Bank clients. The spammed message instructs recipients to log in to their online accounts and to visit the Secure Messages section to read a specific message. The email body includes an embedded (continue reading...) Read more

Malicious Web Site / Malicious Code: New Zbot campaign comes in a PDF

April 13, 2010 - Websense Security Labs™ has received several reports of a Zbot trojan campaign spreading via email. We have seen over 2200 messages so far. Zbot (also known as Zeus) is an information stealing trojan (infostealer) collecting confidential data from each infected (continue reading...) Read more

Tenable Network Security Podcast – Episode 30

April 13, 2010 - Welcome to the Tenable Network Security Podcast - Episode 30 Announcements Several new blog posts have been published this week, including: Plugin Spotlight: SMB Insecurely Configured Service Vulnerability Metrics Webinar - April 28, 2:00 PM EST New Nessus training is now being (continue reading...) Read more

VB’s RAP on VIPRE

April 13, 2010 - Virus Bulletin Reactive and Proactive (RAP) testingSunbelt Software’s VIPRE engine was among the top AV products for reactive and proactive detection in April in Virus Bulletin testing.Virus Bulletin’s (continue reading...) Read more

Microsoft Patch Tuesday – April 2010

April 13, 2010 - Hello and welcome to this month’s blog on the Microsoft patch releases. This is a fairly busy month—the vendor is releasing 11 bulletins covering a total of 25 vulnerabilities. Nine of the issues are rated “Critical” and affect SMB client, (continue reading...) Read more

Symantec Hosted Services Cyber Threat Gallery Brings Cyber Threats to Life

April 13, 2010 - For the past three years, the Symantec Hosted Services (formerly MessageLabs) Cyber Threat Gallery has traveled far and wide displaying at events from London to San Francisco. This week, the collection is on display at Symantec’s Vision 2010 Conference. Attendees (continue reading...) Read more

Twitter Spammers get creative with rearranged spelling

April 13, 2010 - It seems spammers on Twitter are using some curious methods to get their message across (thanks to David Cawley for pointing me in the right direction).Check this out: (continue reading...) Read more

April 2010 – Patch Tuesday’s Vulnerability Analysis

April 13, 2010 - April thus far has been a busy month for administrators tasked with applying updates. As announced, Microsoft released 11 bulletins today. 8 RCEs, 1 DoS, 1 spoofing and 1 privilege escalation. Microsoft’s breakdown went along the lines of: 5 critical, 5 (continue reading...) Read more

Patch Tuesday is today

April 13, 2010 - Microsoft has issued Security Bulletins MS10-109 through 029 -- eleven bulletins addressing 25 vulnerabilities in Windows, Exchange and Office.For further information:http://www.microsoft.com/technet/security/current.aspxTom Kelchner (continue reading...) Read more

Sex and the (not so) Great Firewall of China

April 13, 2010 - Scale the wall, comrade. View the peaks of JapanSometimes the collective behavior of a lot of people discloses information that isn’t apparent any other way. There’s a big word for it (continue reading...) Read more

April 2010 Security Bulletin Release

April 13, 2010 - Hi everyone, Today, as part of our monthly security update cycle, we are releasing 11 security bulletins to address 25 vulnerabilities: five rated Critical, five rated Important and one rated Moderate. This month’s release affects Windows, Microsoft Office, and (continue reading...) Read more

Persistent Meterpreter over Reverse HTTPS

April 13, 2010 - Botnet agents and malware go through inordinate lengths to hide their command and control traffic. From a penetration testing perspective, emulating these types of communication channels is possible, but often requires a custom toolkit to be deployed to the target. (continue reading...) Read more

Twitter will advertise. Will mal-tweets follow?

April 13, 2010 - Twitter cofounder Biz Stone has announced on the Twitter blog that the microblogging service will begin tweeting advertising.“We are launching the first phase of our Promoted Tweets platform with a handful of innovative advertising partners that (continue reading...) Read more

Sex, lies & spam

April 13, 2010 - I have to admit that even though spam is a waste of time, sometimes it's really funny to see all those messages in my inbox recommending to enlarge my penis or to buy cheap viagra, and so on -how the (continue reading...) Read more

Adobe and Microsoft Simultaneously Release Patches

April 13, 2010 - Regular Release for Microsoft This April April 13 is here and for Windows users, this means it is Patch Tuesday. According to the advance notification from Microsoft almost a week ago, the company will be releasing (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.