Archive for the ‘security’ Category

14 March 2008 @ 10:38Fingerprint protected USB sticks not all that secure

Numerous fingerprint “protected” USB sticks on the market purport to allow access to a protected portion of the flash memory only when the proper fingerprint is detected. It turns out that bypassing this “protection” is fairly simple. All you need to do is use the PLscsi tool to send a single USB command – Command Descriptor [...]

by Jon | Add a comment | Posted in accessories, security

6 March 2008 @ 8:12FireWire exploit available for Mac and Win

The latest exploit affects both Macs and Windows machines. The vulnerability lies in the way FireWire handles Direct Memory Access (DMA). Theoretically, this exploit could be extended to other I/O that use DMA. This exploit is apparently not new, but is receiving more attention due to the recent memory attacks demoed by a few Princeton students. If [...]

by Jon | Add a comment | Posted in exploits, firewire, security

4 March 2008 @ 8:36PayPal advises to avoid Safari

PayPal has advised its customers to avoid using Apple’s Safari browser, because it lacks some anti-phishing features that some of the other browsers have. Safari also lacks Extended Validation (EV) certificates. While these anti-phishing measures make users feel warm and safe, they are not the “end-all” of web exploitation. The only person who can fully insure [...]

by Jon | Add a comment | Posted in apple, safari, security

22 February 2008 @ 10:49Cold Boot Attacks on Encryption Keys

A group of Princeton computer scientists has published a paper(pdf) demonstrating a method for accessing a computer’s memory to gain access to encryption keys. Contrary to popular belief, RAM contents are not immediately erased once a computer is shut down. It can take 2.5 to 35 seconds for the data to fade away. This time [...]

by Jon | Add a comment | Posted in exploits, security

18 February 2008 @ 10:28Satellite spotters don’t make good government bedfellows

There is a community of geeks that track the orbit of satellites across the night sky despite the fact that many of these satellites are supposed to be government secrets.(#) “If Ted can track all these satellites,” Pike said, “so can the Chinese.”

by Jon | Add a comment | Posted in security

22 January 2008 @ 9:30Bigger is Better?

Anyone who travels often will drool over the 3-pound computer that’s so thin that it fits into a manila envelope. (Though your IT security department is probably worrying about that capability, right about now.)(#) So, Apple should make their notebooks thicker and heavier to please security professionals?

by Jon | Add a comment | Posted in apple, macbook air, security

21 December 2007 @ 8:15When Is a Brick Not a Brick?

When Computerworld says it’s a “brick”. Computerworld is reporting that an exploit has been found that affects HP and Compaq computers and results in the computer being “bricked”. According to the article, “the Software Update bugs let an attacker corrupt Windows’ kernel files, making the laptop unbootable, or with a little more effort, allow hacks [...]

by Jon | Add a comment | Posted in exploits, security

17 December 2007 @ 19:40Security Update 2007-009

Security Update 2007-009 • Address Book CVE-ID: CVE-2007-4708 Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11 Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: A format string vulnerability exists in Address Book’s URL handler. By enticing a user to visit a maliciously crafted website, a remote attacker [...]

by Jon | Add a comment | Posted in apple, security

28 November 2007 @ 17:20A Sick Feeling in My Gut

Over the past week some Mac sites (four that I know of) were defaced by someone calling himself “malcor”. This, in turn, brought about some panic in the security and Wordpress communities. A couple security firms blogged about the incident (Avert Labs, Blogvis.com) which only served to increase the awareness/panic. The so-called hacker named “malcor” [...]

by Jon | 6 comments | Posted in exploits, security, stupid

26 November 2007 @ 11:28QuickTime 7.3 Buffer Overflow Exploit

Secunia has issued a security advisory (SA27755) for a buffer overflow exploit in QuickTime and has labeled it as “extremely critical”. The vulnerability is caused due to a boundary error when processing RTSP replies and can be exploited to cause a stack-based buffer overflow via a specially crafted RTSP reply containing an overly long “Content-Type” header.

by Jon | Add a comment | Posted in apple, exploits, security

Sign up for PayPal and start accepting credit card payments instantly.

Get fed!

rss icon subscribe to Geek stuff

rss icon Geek stuff in your inbox

Add the "Geek stuff" Google Gadget to your homepage

Add the "Daily Deals" Google Gadget to your homepage

Featured Tee

UneeTee.com

One Day, One Artist, One cool T-shirt

$3000 Kick Off by Uneetee
Guys - $13
Girls - $13

Apparel

Search Amazon

Search Amazon.com
Search Amazon.co.uk

Advert

Web hosting by ICDSoft