Archive for October, 2007

Russian PDF attacks surge; Microsoft takes blame

Microsoft updated a security advisory that addressed a broad flaw in Windows and said it is working around the clock to fix the bug. But it may be too late for many. Security researchers said hackers had amped up attacks using malicious PDF files that exploit the vulnerability.. Finland-based F-Secure called the surge in spam carrying the rigged PDF documents “massive” and said the run is ongoing. Ken Dunham, director of response at i… read more »

Leopard hacked to run on PCs

The cat and mouse game between hackers and Apple takes another move, with news that Apple’s new Leopard operating system has already been succesfully installed on Windows PCs. The OSx86 Scene forum has released details of how Windows users can migrate to Apple’s new OS, without investing in new hardware - even though installing Leopard on an PC may be counter to Apple’s terms and conditions.
The forum is offering full instructio… read more »

Tool opens iPhone, iPod Touch via web

iPhone hackers have released a tool that allows owners of firmware 1.1.1 iPhones and iPod Touches to open up their devices to third-party apps - all without the need for a host Mac or PC. The utility’s called AppSnapp, and it’s launched via the devices’ Safari web browser. The code uses a known vulnerability with firmware 1.1.1, which it subsequently patches. Before doing so, it activates iPhones, jalbreaks both types of device … read more »

London police hunting online account hackers

Police in London are hunting a gang of online thieves that hacked into bank accounts and stole hundreds of thousands of pounds. According to a report by UK newspaper The Times, the gang hacked into private bank accounts and used confidential customer details to order new debit and credit cards which were used to buy expensive jewellery, electronic goods and euros.
Detective constable Keith Harrington from the Dedicated Cheque and Plastic Crime Un… read more »

F-Secure warning over PDF malware threat

Emails containing malicious PDF files have been putting computers at risk since Friday, Finnish security software firm F-Secure said on Saturday. “The emails, sent in bulk, looked like credit-card statements, and contained an attachment called ‘report.pdf’,” chief research officer Mikko Hypponen said in a statement.
When such PDF files are viewed on vulnerable machines, they start downloading software from servers in Malay… read more »

Storm Worm now just a squall

The Storm Worm’s days may be numbered, according to a University of California researcher. A network security analyst at UC San Diego, Brandon Enright, has been tracking Storm since July and said that, despite the intense publicity that the network of infected computers has received, it’s actually been shrinking steadily and is presently a shadow of its former self. On Saturday, he presented his findings at the Toorcon hacker conferen… read more »

Exploit code found serving from popular advertising site

RealNetworks Inc. said it would publish a patch later Friday for its RealPlayer media program to protect users from ongoing attacks. Less than 24 hours before, Symantec Corp. had issued a high-level alert that warned of a critical vulnerability in RealPlayer that could be used against anyone browsing the Web with Internet Explorer.
The bug came to light after the NASA space agency warned employees of a spike in attacks that it said originated fro… read more »

Hacker uses public APIs to breach eBay

eBay has begun an audit of its IT systems after a hacker managed to access and disable user accounts. The company said last week that the hacker exploited public application programming interfaces (APIs) that enable merchants to build e-commerce sites on top of eBay. “This fraudster found very old administrative interfaces into the eBay system that had not been deactivated when we changed the security of our internal systems several years a… read more »

Cracker sales target pegged at Rs.1 crore

TIRUCHI: The Chinthamani Cooperative Supermarket at Puthur here has fixed a cracker sales target of Rs. 1 crore for Deepavali festival. The authorities have planned to establish 10 special sales outlets in the Chinthamani branches at Puthur and Teppakulam in the city and Manapparai and Kulithalai towns to sell popular brands of fireworks.
Transport Minister K.N. Nehru inaugurated the sale at a function held at the Chinthamani supermarket on Sunda… read more »

Storm: The malware that won’t die

We like to imagine that hackers are smart, but it is their collective incompetence that has allowed the IT industry to survive their attacks as long as they have. Viruses may be unleashed, worms may spread, but usually the McAfees and Symantecs of the world are quick enough to help isolate and deal with such malware in a manner of weeks, if not days. This was the case with Sasser, Nimda, and even Code Red. Rare is the malware that acts with the c… read more »

RSS