<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Hacking-News.com</title>
	<link>http://www.hacking-news.com</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Mon, 01 Feb 2010 21:48:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.3</generator>
	<language>en</language>
			<item>
		<title>Google to drop IE6 support in cloud apps</title>
		<link>http://www.hacking-news.com/2010/02/01/google-to-drop-ie6-support-in-cloud-apps/</link>
		<comments>http://www.hacking-news.com/2010/02/01/google-to-drop-ie6-support-in-cloud-apps/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 21:48:21 +0000</pubDate>
		<dc:creator>zdnet.co.uk</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2010/02/01/google-to-drop-ie6-support-in-cloud-apps/</guid>
		<description><![CDATA[Search and advertising giant Google is phasing out support for Internet Explorer 6 in its cloud services, starting with Google Docs and Google Sites, from 1 March.
Google announced in a blog post on Friday that from the beginning of March, certain key functionality in Google Docs and Google Sites &#8220;would not work properly&#8221; with IE6 and older versions of other browsers.
&#8220;Please take the time to switch your organisation to the most... <a href="http://www.hacking-news.com/2010/02/01/google-to-drop-ie6-support-in-cloud-apps/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Search and advertising giant Google is phasing out support for Internet Explorer 6 in its cloud services, starting with Google Docs and Google Sites, from 1 March.</p>
<p>Google announced in a blog post on Friday that from the beginning of March, certain key functionality in Google Docs and Google Sites &#8220;would not work properly&#8221; with IE6 and older versions of other browsers.</p>
<p>&#8220;Please take the time to switch your organisation to the most up-to-date browsers available,&#8221; said Rajen Sheth, Google Apps senior product manager, in the blog post.</p>
<p>The company is urging Google Apps users to move to IE7, Firefox 3.0, Chrome 4.0 or Safari 3.0, or more recent versions of those browsers. Net Applications put IE6&#8217;s share of the general browser market in January at about 20 percent, bettered only by IE8 at 22 percent. In April, Forrester Research found that 60 percent of enterprises used IE6 as their default browser.</p>
<p>Google has not specified precisely which Apps functionalities in older browsers will be affected. However, the company said it wants to support HTML 5, the latest version of markup language HTML, which is not supported by older browsers.</p>
<p>&#8220;Older browsers were not designed to handle new web-based applications, which means they don&#8217;t support modern web technologies like HTML 5 and advanced JavaScript processing,&#8221; a Google spokesperson said. &#8220;For example, IE6 doesn&#8217;t support HTML 5, and IE6 and [Firefox 2] do not process JavaScript nearly as efficiently as newer versions of IE and FF.&#8221;</p>
<p>The dropping of support means Google will not fix issues specific to older browsers and will not develop new features for them. However, users will still be able to access Google Docs and Sites using the software.</p>
<p>&#8220;With Google Docs, we plan on continuing to support view-only mode in IE6, and we will still support viewing of Google Sites in IE6,&#8221; the company&#8217;s spokesperson said.</p>
<p>Goggle&#8217;s phasing out of support for IE6 has nothing to do with the recent security problems Google encountered through IE6 use, according to the spokesperson.</p>
<p>&#8220;No, this was already planned and is being done so we can continue using the latest web technologies to bring new, innovative features to our users,&#8221; the spokesperson said. &#8220;We&#8217;re following other companies that have done the same, like Twitter, Facebook and Microsoft for Office Web Apps.&#8221;</p>
<p>Earlier this month, Microsoft admitted that Chinese attacks on Google and other companies had exploited a hole in IE6, which was also present in IE7 and IE8.</p>
<p>At the time, the flaw did not have a patch, leading the French and German governments to recommend that users update to the later versions of IE, or switch browsers.</p>
<p>The UK government urged users to update their browsers, but said that switching browsers was unnecessary. Various government departments, including the Department for Work and Pensions (DWP), the Department of Health (DoH) and the Department for Business, Innovation and Skills (BIS) use IE6 on all desktop and laptop computers.</p>
<p>The DoH issued advice to its users on 21 January saying they should upgrade to IE7. &#8220;It is recommended that organisations still using Internet Explorer 6 on the affected platforms upgrade to Internet Explorer 7,&#8221; it said, in email advice seen by ZDNet UK. Internet Explorer 7 has gone through an internal accreditation process, said the DoH, and as a result has been verified to work correctly within the central NHS system, known as the NHS Spine.</p>
<p>Microsoft released an out-of-band patch for the IE zero-day on 21 January.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2010/02/01/google-to-drop-ie6-support-in-cloud-apps/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google aims to speed up DNS requests</title>
		<link>http://www.hacking-news.com/2010/02/01/google-aims-to-speed-up-dns-requests/</link>
		<comments>http://www.hacking-news.com/2010/02/01/google-aims-to-speed-up-dns-requests/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 21:47:33 +0000</pubDate>
		<dc:creator>zdnet.co.uk</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2010/02/01/google-aims-to-speed-up-dns-requests/</guid>
		<description><![CDATA[Google and Neustar UltraDNS have proposed a extension to try to build some geographic awareness into the Domain Name System.
The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user&#8217;s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google sai... <a href="http://www.hacking-news.com/2010/02/01/google-aims-to-speed-up-dns-requests/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Google and Neustar UltraDNS have proposed a extension to try to build some geographic awareness into the Domain Name System.</p>
<p>The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user&#8217;s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google said in a blog post on Wednesday.</p>
<p>As designed, it would, for example, return the address for Google&#8217;s Dutch server, not Google&#8217;s California server, to a user in the Netherlands who needs to reach it.</p>
<p>For more on this story, see Google proposes geo-smart Internet speedup on CNET News.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2010/02/01/google-aims-to-speed-up-dns-requests/feed/</wfw:commentRss>
		</item>
		<item>
		<title>4G handset to be demonstrated this month</title>
		<link>http://www.hacking-news.com/2010/02/01/4g-handset-to-be-demonstrated-this-month/</link>
		<comments>http://www.hacking-news.com/2010/02/01/4g-handset-to-be-demonstrated-this-month/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 21:46:53 +0000</pubDate>
		<dc:creator>zdnet.co.uk</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2010/02/01/4g-handset-to-be-demonstrated-this-month/</guid>
		<description><![CDATA[NTT DoCoMo is to demonstrate a prototype handset based on the high-speed wireless data technology LTE later this month, according to the Japanese mobile operator&#8217;s handset partner, NEC.
NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was develop... <a href="http://www.hacking-news.com/2010/02/01/4g-handset-to-be-demonstrated-this-month/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>NTT DoCoMo is to demonstrate a prototype handset based on the high-speed wireless data technology LTE later this month, according to the Japanese mobile operator&#8217;s handset partner, NEC.</p>
<p>NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was developed by Fujitsu, NEC, NTT DoCoMo and Panasonic, and first sampled in October.</p>
<p>LTE, the &#8216;long-term evolution of 3G&#8217;, is the successor to HSDPA and is roughly 10 times faster, providing theoretical downlink speeds of at least 100Mbps and a theoretical uplink of at least 50Mbps. The technology was designed to reduce latency in data transmission and improve the efficiency of frequency usage, making it more suitable than 3G for services such as streaming HD video, video conferencing and online gaming.</p>
<p>The world&#8217;s first commercial LTE mobile broadband services went live in Oslo and Stockholm in December through the Scandinavian operator TeliaSonera, which is initially offering LTE access via a mobile dongle.</p>
<p>Huawei announced in December that it had completed its first UK-based LTE trials, held in conjunction with O2, that reached maximum downlink throughput of 150Mbps. The trial took place in the Slough area, where O2&#8217;s headquarters are located.</p>
<p>NTT has said it plans to spend between ?300bn-?400bn (?2bn-?3bn) on LTE rollouts over the next five years.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2010/02/01/4g-handset-to-be-demonstrated-this-month/feed/</wfw:commentRss>
		</item>
		<item>
		<title>40,000 More Extensions!</title>
		<link>http://www.hacking-news.com/2010/02/01/40000-more-extensions/</link>
		<comments>http://www.hacking-news.com/2010/02/01/40000-more-extensions/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 21:45:57 +0000</pubDate>
		<dc:creator>computerworld.com</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2010/02/01/40000-more-extensions/</guid>
		<description><![CDATA[One thing that got lost in the commotion of the extensions launch is a feature that is near and dear to my heart: Google Chrome 4 now natively supports Greasemonkey user scripts. Greasemonkey is a Firefox extension I wrote in 2004 that allows developers to customize web pages using simple JavaScript and it was the inspiration for some important parts of our extension system.
Ever since the beginning of the Chromium project, friends and coworkers ... <a href="http://www.hacking-news.com/2010/02/01/40000-more-extensions/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>One thing that got lost in the commotion of the extensions launch is a feature that is near and dear to my heart: Google Chrome 4 now natively supports Greasemonkey user scripts. Greasemonkey is a Firefox extension I wrote in 2004 that allows developers to customize web pages using simple JavaScript and it was the inspiration for some important parts of our extension system.</p>
<p>Ever since the beginning of the Chromium project, friends and coworkers have been asking me to add support for user scripts in Google Chrome. I&#8217;m happy to report that as of the last Google Chrome release, you can install any user script with a single click. So, now you can use emoticons on blogger. Or, you can browse Google Image Search with a fancy lightbox. In fact, there&#8217;s over 40,000 scripts on userscripts.org alone.</p>
<p>Installation is quick and easy, just like installing an extension. That&#8217;s because under the covers, the user script is actually converted into an extension. This means that management tasks like disabling and uninstalling work just like they do with extensions.</p>
<p>Note that user scripts are powerful software and have full access to your private data on any web site. So, for example, they could read all your web mail or access your online bank. Be sure to read the comments on any user scripts in order to decide whether you trust the author with this power.</p>
<p>Also keep in mind that some user scripts won&#8217;t work in Google Chrome yet, because of differences between it and Firefox. Based on some analysis that the current maintainers of Greasemonkey did, I expect between 15%-25% of scripts to not work in Google Chrome. If you find such a script, you should consider letting the author know. There may be something he or she can do to easily fix the problem. In the meantime, we&#8217;ll keep working on bugs on our side to bring our implementation closer to Greasemonkey.</p>
<p>Have fun trying out the thousands of available scripts. And don&#8217;t worry - If you get bored, there&#8217;s lots more extensions at Google Chrome&#8217;s extension gallery.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2010/02/01/40000-more-extensions/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Internet Users Continue to Amaze with Foolish Passwords</title>
		<link>http://www.hacking-news.com/2009/01/16/internet-users-continue-to-amaze-with-foolish-passwords/</link>
		<comments>http://www.hacking-news.com/2009/01/16/internet-users-continue-to-amaze-with-foolish-passwords/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 12:01:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/internet-users-continue-to-amaze-with-foolish-passwords/</guid>
		<description><![CDATA[It is a disgrace that humans havenât still got the hang of setting passwords. It seems as though that most internet users have inextricably tethered themselves to a promise of not setting strong-enough passwords, which may force hackers to reconsider their choice of profession for its grueling nature. As you devour more of this story, you will begin to envy hackers for having it stroll-in-the-park easy.
A new study has revealed â rather... <a href="http://www.hacking-news.com/2009/01/16/internet-users-continue-to-amaze-with-foolish-passwords/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>It is a disgrace that humans havenât still got the hang of setting passwords. It seems as though that most internet users have inextricably tethered themselves to a promise of not setting strong-enough passwords, which may force hackers to reconsider their choice of profession for its grueling nature. As you devour more of this story, you will begin to envy hackers for having it stroll-in-the-park easy.</p>
<p>A new study has revealed â rather reiterated - that internet users nonchalantly continue to set unimaginative, fatuous passwords. The study appraised 28,000 passwords that were recently stolen from a U.S website.</p>
<p>Sixteen percent of the users had set their first name as their password. Around fourteen percent chose easiest to recall key combinations, including â1234â and â12345678â. Other users, who apparently donât rate their mathematical ability highly, chose to steer clear of numbers and settled for passwords such as âAZERTYâ and âQWERTYâ.</p>
<p>Five percent of the passwords were found to be inspired by popular things and celebrities, including names of movies, TV shows and actors. The strongest password in this category was found to be âIronmanâ as it sounds impenetrable.</p>
<p>Three percent of the people reckon passwords are another medium of expression. How else would you explain passwords like âIloveyouâ and âIhateyou?â</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/internet-users-continue-to-amaze-with-foolish-passwords/feed/</wfw:commentRss>
		</item>
		<item>
		<title>This month&#8217;s Microsoft patches could lead to a hectic week for IT managers</title>
		<link>http://www.hacking-news.com/2009/01/16/this-months-microsoft-patches-could-lead-to-a-hectic-week-for-it-managers/</link>
		<comments>http://www.hacking-news.com/2009/01/16/this-months-microsoft-patches-could-lead-to-a-hectic-week-for-it-managers/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 12:01:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/this-months-microsoft-patches-could-lead-to-a-hectic-week-for-it-managers/</guid>
		<description><![CDATA[This week could be âhectic&#8217; with Microsoft offering a critical patch for Internet Explorer.
Alan Bentley, regional VP EMEA of Lumension, said even though there are only two critical patches being issued tomorrow, it could still be a hectic week as the most critical patch this month is the IE bulletin requiring a reboot of all XP and Vista machines in the organisation running IE 7. 
Bentley said: âLarge-scale reboots of all desktop... <a href="http://www.hacking-news.com/2009/01/16/this-months-microsoft-patches-could-lead-to-a-hectic-week-for-it-managers/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>This week could be âhectic&#8217; with Microsoft offering a critical patch for Internet Explorer.</p>
<p>Alan Bentley, regional VP EMEA of Lumension, said even though there are only two critical patches being issued tomorrow, it could still be a hectic week as the most critical patch this month is the IE bulletin requiring a reboot of all XP and Vista machines in the organisation running IE 7. </p>
<p>Bentley said: âLarge-scale reboots of all desktops can lead to disruption and productivity hits if not planned and coordinated appropriately. As organisations are looking at the IE 7 update, they should also look at the recently released critical update for the Firefox browser, more stealthy malware is being introduced to endpoints via browser exploits; therefore, critical browser updates need to be made a higher priority than ever before.â</p>
<p>Regarding the critical patch that will cover the vulnerability in the Exchange mail server software, he claimed that this has proven to be the easiest target for hackers to infiltrate, as if they are able to compromise an organisation&#8217;s Exchange Server, then they will be able to intercept every email coming and going, essentially making it open to every corporation across the globe.</p>
<p>Bentley said: âGiven the proximity of the Exchange Server to external data entering the network, organisations will want to deploy this update immediately. However, critical email services are often subject to change control processes that could make an urgent deployment a complex matter.</p>
<p>âIf this ends up being a web-facing vulnerability, then it will be highly critical to patch as IT professionals constantly have to make sure these types of systems are patched and secure while running efficiently at the same time. Although the Exchange vulnerability is critical, organisations will want to read the details carefully when the full patch comes out to see if there are any mitigating controls.â</p>
<p>He also claimed that organisations should consider the update for the SQL Server as critical, despite it only being named as âimportant&#8217;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/this-months-microsoft-patches-could-lead-to-a-hectic-week-for-it-managers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The websites of two major providers of security products have been hit by hackers.</title>
		<link>http://www.hacking-news.com/2009/01/16/the-websites-of-two-major-providers-of-security-products-have-been-hit-by-hackers-the-website-of-russian-it-security-provider-kaspersky-lab-was-hit-at-the-weekend-by-a-romanian-%e2%80%98white-hat/</link>
		<comments>http://www.hacking-news.com/2009/01/16/the-websites-of-two-major-providers-of-security-products-have-been-hit-by-hackers-the-website-of-russian-it-security-provider-kaspersky-lab-was-hit-at-the-weekend-by-a-romanian-%e2%80%98white-hat/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 12:00:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/the-websites-of-two-major-providers-of-security-products-have-been-hit-by-hackers-the-website-of-russian-it-security-provider-kaspersky-lab-was-hit-at-the-weekend-by-a-romanian-%e2%80%98white-hat/</guid>
		<description><![CDATA[A new Valentine&#8217;s Day spam email has been detected by Websense as containing a Waledac variant. Websense Security Labs has reported to have seen several fake Valentine&#8217;s Day sites serving up malware recently, with an increase in adult dating and âhealthcare&#8217; related email spam released to mark the occasion. Carl Leonard, Websense threat research manager, claimed that it works by the user opening the URL in the spammed messa... <a href="http://www.hacking-news.com/2009/01/16/the-websites-of-two-major-providers-of-security-products-have-been-hit-by-hackers-the-website-of-russian-it-security-provider-kaspersky-lab-was-hit-at-the-weekend-by-a-romanian-%e2%80%98white-hat/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>A new Valentine&#8217;s Day spam email has been detected by Websense as containing a Waledac variant. Websense Security Labs has reported to have seen several fake Valentine&#8217;s Day sites serving up malware recently, with an increase in adult dating and âhealthcare&#8217; related email spam released to mark the occasion. Carl Leonard, Websense threat research manager, claimed that it works by the user opening the URL in the spammed message and being redirected to a site with two puppies and a love heart to give a Valentine&#8217;s theme. The user is then enticed to download a Valentine&#8217;s kit to prepare a present for a loved one, which is a new Waledac variant.  </p>
<p>Leonard said: âThe usual suspects have emerged as expected, with Valentine spam emails and Trojans. The public are becoming more aware of these and it is getting harder to trick people this way. Cybercriminals are also taking their efforts to social networks, given its rising popularity and potential to manipulate the user through âfriend&#8217; messages.</p>
<p>âOrganised criminal units have a long history of timing their attacks to coincide with popular occasions in order to achieve maximum success. Valentine&#8217;s Day 2009 is a day that is similarly marked on the criminals&#8217; calendar for targeted attacks.â</p>
<p>Websense has warned of three key signs of fake sites: âBroken Hearts&#8217; sites show colourful images such as puppy dogs or a picture of 12 pretty hearts and ask âGuess, which one is for you?&#8217;. The web page however is one big image and a single click from a tricked user commences the download of Trojans named âonlyyou.exeâ or âyouandme.exeâ, which can connect to remote websites to receive commands and send information about the compromised system.</p>
<p>âI am your friend&#8217; uses social networking tricks to get users to visit fake sites, with Websense claiming that a popular technique at the moment is spam email pretending to originate from social networking sites â complete with love hearts and cartoon characters. Clicking through to the link would download a Trojan designed to steal log in credentials for banking sites.</p>
<p>Seventy per cent of the top 100 most popular websites either hosted malicious content or contained a masked redirect to lure unsuspecting victims from legitimate sites to malicious sites. Specially created malicious sites are in decline as cybercriminals switch to compromising âtrusted&#8217; websites. Websense claimed that as there is increased confidence in shopping and researching online - a lot of which happens whilst in the office â people are turning to the internet to order flowers, chocolates and other gifts and cybercriminals are compromising these sites and stealing data.</p>
<p>Leonard said: âThe underground economy is positively flourishing as companies fail to keep up with security technology. Criminals are taking advantage of the growing number of Web 2.0 properties, which allows user generated content. More than ever we&#8217;re seeing websites injected with links to direct users to malicious and compromised sites.</p>
<p>âSince many email security systems lack web intelligence, spammers have also stepped up email campaigns which contain links to malicious web pages. It&#8217;s clear that businesses need security with real-time protection, but until this becomes the norm â cybercriminals will continue stealing data and breaking hearts.â</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/the-websites-of-two-major-providers-of-security-products-have-been-hit-by-hackers-the-website-of-russian-it-security-provider-kaspersky-lab-was-hit-at-the-weekend-by-a-romanian-%e2%80%98white-hat/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Kaspersky Lab and BitDefender websites hit by hackers</title>
		<link>http://www.hacking-news.com/2009/01/16/kaspersky-lab-and-bitdefender-websites-hit-by-hackers/</link>
		<comments>http://www.hacking-news.com/2009/01/16/kaspersky-lab-and-bitdefender-websites-hit-by-hackers/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 11:59:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/kaspersky-lab-and-bitdefender-websites-hit-by-hackers/</guid>
		<description><![CDATA[The websites of two major providers of security products have been hit by hackers.
The website of Russian IT security provider Kaspersky Lab was hit at the weekend by a Romanian âwhite-hat&#8217; hacker.
A group calling itself âthe Romanian Security Team&#8217; claimed that the hackers achieved full access to the database supporting the websites â which includes customer data â by simply altering a parameter in the URLs. They ... <a href="http://www.hacking-news.com/2009/01/16/kaspersky-lab-and-bitdefender-websites-hit-by-hackers/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>The websites of two major providers of security products have been hit by hackers.</p>
<p>The website of Russian IT security provider Kaspersky Lab was hit at the weekend by a Romanian âwhite-hat&#8217; hacker.</p>
<p>A group calling itself âthe Romanian Security Team&#8217; claimed that the hackers achieved full access to the database supporting the websites â which includes customer data â by simply altering a parameter in the URLs. They could also perform SQL injections to remotely introduce harmful code into the database.</p>
<p>The group also claimed to have hit the Portuguese site of US anti-virus provider BitDefender, with the personal details of thousands of users viewed. The hackers said that they alerted the two companies of the security flaw and did not expose any of the data they found.</p>
<p>Kaspersky Lab said in a statement: âOn Saturday February 7 2009, a vulnerability was detected on a subsection of the usa.kaspersky.com domain when a hacker attempted an attack on the site.</p>
<p>âThe site was only vulnerable for a very brief period, and upon detection of the vulnerability we immediately took action to roll back the subsection of the site and the vulnerability was eliminated within 30 minutes of detection. The vulnerability wasn&#8217;t critical and no data was compromised from the site.&#8221;</p>
<p>Gunter Ollmann, chief security strategist at IBM&#8217;s Internet Security Systems, said: âI hope that Kaspersky administrators fix this vulnerability rather quickly as they no doubt have a large customer base, and it would appear that all those customers are now exposed</p>
<p>âOn top of that, this type of critical flaw can probably be used to usurp legitimate purchases and renewals of their products - which could include the linking to malicious and backdoored versions of their software - thereby infecting those very same customers that were seeking protection from malware in the first place.â</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/kaspersky-lab-and-bitdefender-websites-hit-by-hackers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hackers attack antivirus firm&#8217;s tech-support site</title>
		<link>http://www.hacking-news.com/2009/01/16/hackers-attack-antivirus-firms-tech-support-site/</link>
		<comments>http://www.hacking-news.com/2009/01/16/hackers-attack-antivirus-firms-tech-support-site/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 11:58:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Anti-Virus]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/hackers-attack-antivirus-firms-tech-support-site/</guid>
		<description><![CDATA[February 16, 2009 (Computerworld) A Kaspersky Lab technical support site was hacked late last month, exposing private customer information for 11 days, the Moscow-based security company admitted last week. The company learned of and closed the breach on Feb. 7 after it was notified by the Romanian hackers.
&#8220;This is not good for any company, especially for a company dealing with security,&#8221; acknowledged Roel Schouwenberg, a senior antiv... <a href="http://www.hacking-news.com/2009/01/16/hackers-attack-antivirus-firms-tech-support-site/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>February 16, 2009 (Computerworld) A Kaspersky Lab technical support site was hacked late last month, exposing private customer information for 11 days, the Moscow-based security company admitted last week. The company learned of and closed the breach on Feb. 7 after it was notified by the Romanian hackers.</p>
<p>&#8220;This is not good for any company, especially for a company dealing with security,&#8221; acknowledged Roel Schouwenberg, a senior antivirus researcher at Kaspersky, in a conference call last week. &#8220;This should not have happened.&#8221;</p>
<p>The company had revamped the U.S. support site and relaunched it on Jan. 28. From that point until Feb. 7, the support database was open to attack, Schouwenberg said. The revamped site has now been replaced by the old version.</p>
<p>In a blog post, the hackers claimed that they were able to access a customer database that held e-mail addresses and software-activation codes by launching a SQL injection attack.</p>
<p>Schouwenberg confirmed that the database was hacked via SQL injection, but he contended that only the database&#8217;s table labels were accessed, not the customer data. However, the e-mail addresses of about 2,500 customers and some 25,000 activation codes were at risk, he noted.</p>
<p>Schouwenberg said the hack was made possible by a combination of vulnerable code crafted by an unnamed third-party vendor and poor code review by Kaspersky.</p>
<p>Kaspersky hired Next Generation Security Software Ltd.&#8217;s David Litchfield, an expert on SQL injection attacks, to audit the systems. His report, delivered Feb. 12, confirmed Kaspersky&#8217;s findings.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/hackers-attack-antivirus-firms-tech-support-site/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security and authentication added to pay TV services from TC TrustCenter</title>
		<link>http://www.hacking-news.com/2009/01/16/security-and-authentication-added-to-pay-tv-services-from-tc-trustcenter/</link>
		<comments>http://www.hacking-news.com/2009/01/16/security-and-authentication-added-to-pay-tv-services-from-tc-trustcenter/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 11:56:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.hacking-news.com/2009/02/16/security-and-authentication-added-to-pay-tv-services-from-tc-trustcenter/</guid>
		<description><![CDATA[TC TrustCenter has been mandated to implement certification for the CI Plus standard in Europe.
It is to provide certification to protect premium digital TV content against piracy with the new CI Plus Common Interface Standard. TC TrustCenter will provide certificate issuance and management services and the necessary registration for all manufacturers of TV devices, digital recorders and conditional access modules that want to license the CI Plus... <a href="http://www.hacking-news.com/2009/01/16/security-and-authentication-added-to-pay-tv-services-from-tc-trustcenter/">read more &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>TC TrustCenter has been mandated to implement certification for the CI Plus standard in Europe.</p>
<p>It is to provide certification to protect premium digital TV content against piracy with the new CI Plus Common Interface Standard. TC TrustCenter will provide certificate issuance and management services and the necessary registration for all manufacturers of TV devices, digital recorders and conditional access modules that want to license the CI Plus standard.<br />
The CI Plus standard is an enhancement of the existing CI specification that eliminates vulnerabilities in content protection for Pay-TV content.</p>
<p>To ensure optimum security between the CA Module and the digital receiver, the new CI Plus standard uses a collection of established, industry accepted and validated techniques, including key management, device and message authentication and encryption.</p>
<p>The founder members of CI Plus - Sony, SmarDTV, Samsung, Philips and Neotion â have appointed TC TrustCenter to cover everything from vetting to verification of subscription requirements to contract management.</p>
<p>Michelle Lewis, account executive at TC TrustCenter, explained that before, people could hack in and download the films, which leads to piracy and forced the manufacturers to plug the hole and offer security.</p>
<p>Lewis said: âWe offer digital certification for authentication and scrambling when they are being downloaded to the set top box or TV set. CI Plus injects the certificates into the TV that are created by TC TrustCenter. This is going to enable more business to be done as the providers want to enable secure downloading for consumer services.â</p>
<p>Mark Londero of CI Plus, said: âWe chose TC TrustCenter because they demonstrated excellent technical expertise and an impressive responsiveness in adjusting to and acting on our specific requirements throughout the selection process.â</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacking-news.com/2009/01/16/security-and-authentication-added-to-pay-tv-services-from-tc-trustcenter/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
