Scriam de Google Chrome , cel mai nou browser web iesit pe piata. Iata ca in scurt timp au inceput sa apara si gaurile de securitate.
Attackers can combine the months-old “carpet bomb” bug with another flaw disclosed last month to trick people running Google’s brand-new Chromebrowser into downloading and launching malicious code, a security researcher has warned.
The attacks are possible because Google used an older version of WebKit, the open-source rendering engine that also powers Apple’s Safari, as the foundation of Chrome, said Israeli researcher Aviv Raff on Wednesday.
Raff posted a proof-of-concept exploit to demonstrate how hackers could create a new “blended threat” - so-named because it relies on multiple vulnerabilities - to attack Chrome.
“This is different from the Safari/IE blended threat,” said Raff in an interview conducted via instant messaging. “It’s a different blend with one similar component. It uses the auto-download vulnerability (aka ‘Carpet Bomb’) in combination with a [user interface] design flaw and an issue with Java that doesn’t display a warning on execution of JAR files downloaded from the Internet.” Raff’s reference to the earlier Safari/IE blended threat was to his May report that said a bug in Apple’s Safari browser could be paired with an unpatched vulnerability in Microsoft’s Internet Explorer (IE) to compromise Windows PCs.
The “carpet bomb” bug, revealed by researcher Nitesh Dhanjani in May and named for the way it could be used to dump files onto the Windows desktop, stemmed from the fact that Safari did not require a user’s permission to download a file. Attackers, Dhanjani said, could populate a malicious site with rogue code that Safari would automatically download to the desktop, where it might tempt a curious user into opening the file.
After first balking - for a time it refused the classify the flaw as a security vulnerability - Apple patched the bug in mid-June by updating Safari to 3.1.2.
Raff combined the still-there carpet bomb bug with another reported by UK-based penetration tester Petko Petkov at the Black Hat security conference last month. At the time, Petkov outlined how a Java flaw allows Windows to automatically execute JAR files without prompting or warning the user. Chrome also contributes to the problem, said Raff, by making downloaded files appear as buttons at the bottom of the browser’s frame. “One click on this button will execute the file,” Raff said. Attackers could place malware on a malicious site, then wait for - or better yet, draw in - users running Chrome. The browser would not warn the user of the JAR file automatically downloaded from the site, and the button-style indicator in Chrome could be easily mistaken for part of the application.
Users can set an option in Chrome that will thwart Raff’s exploit by popping up a warning asking for a filename and location for any downloaded file. To change Chrome, select Options under the “Customize and control Google Chrome” menu; the menu is at the far right, near the top, and although not named, looks like a small wrench. Next, click the “Minor Tweaks” tab in the Options window, then check the box that reads “Ask where to save each file before downloading.”
The blended threat, Raff argued, illustrates a bigger problem for Chrome, which has borrowed components from both Safari - via WebKit - as well as unspecified pieces of Mozilla’s open-source Firefox.
Calling the approach “problematic” from a security standpoint, Raff wondered how quickly Google will be able to patch problems in Chrome.
“They’ll have to track all security vulnerabilities in those [borrowed] features, and fix them in Chrome too,” Raff said in the blog post that spelled out more detail of the Chrome/Java blended threat. “This will probably be only after those vulnerabilities were fixed by the other vendors or were publicly reported. It will put Chrome users at risk for a long time.”
Bac-ul 2008 e in plina desfasurare. Pe langa scandalurile obisnuite ( subiecte gresite, subiecte stupide - unele , subiecte aflate cu ceva timp inainte de inceperea examenului ) anul asta se discuta din ce in ce mai mult de copierea la BAC.
Zilele trecute eram la Piata Timpuri Noi si auzeam discutiile tinerilor care dadusera bac-ul la scoala de langa piata. Unii se laudau in gura mare ca au copiat tot, ca unii profesori chiar le-au spus cum se rezolva subiectele, ca alti profesorii i-au lasat sa copieze din carti sau alte materiale didactice. Alti elevi se plangeau ca n-au putut sa copieze nimic.
Pe de alta parte, din surse sigure am aflat ca multe teze contineau fix aceleasi greseli, in general legate de anumite nume ale unor persoane. De unde concluzia clara ca cineva le-a dictat sau au copiat unii de la altii cu tot cu greseli.
Yahoo, cunoscutul furnizor de servicii de mail si nu numai, a lansat 2 noi domenii: ymail.com si rocketmail.com . Asta inseamna ca acum puteti sa va creeati adrese de mail care sa contina
numele@ymail.com sau @rocketmail.com. Miscarea vine in intampinarea utilizatorilor care nu puteau sa aiba o adresa de mail la yahoo, care sa le contina numele, din cauza numarului urias de conturi deja existente la yahoomail..
Pana acum o saptamana eram un client destul de multumit de serviciile RCS/RDS( cam in proportie de 96 % ). Vinerea trecuta ( 09.05.2008 ) a fost o furtuna, care s-a soldat si cu o intrerupere a curentului electric. Spun asta pentru ca am gasit pc-ul inchis cand m-am intors de la munca. Internetul si cablul tv functionau, doar RDStel era mort. Luni sun la rds sa-i intreb ce si cum.
Primesc raspunsul ca se stie de avarie, se lucreaza si in scurt timp serviciul de telefonie va functiona. Marti sun din nou si mi se spune ca echipamentele sunt configurate ( de parca m-ar fi interesat aceasta informatie ) si ca urmeaza sa fie instalate. Miercuri, o dom’soara foarte intepata, imi spune ca “asa cu mi-au spus si colegii ei mai inainte” termenul de rezolvare al avariei este vineri ( 16.05.2008, am presupus eu ). O intreb foarte inocent daca i se pare normal sa stam o saptamana fara serviciul de telefonie. Primesc un raspuns stupefiant: da, avand in vedere ca este un serviciu gratuit/bonus. Zic, hopa.. asta inseamna ca aia de la vodafone imi dau 30 de minute pe luna gratis dar e posibil sa nu ma lase sa le folosesc :)))). Evident, n-am lamurit nimic cu respectiva.
Ideea e alta. Acum este sambata si nici urma de rdstel. Ma gandesc ca se referea la vinerea viitoare :)).
Ok.. dar ce e PHISHING? Pai este o tentativa de frauda. Cum functioneaza? Se “cloneaza” ( copiaza ) o pagina extrem de populara ( gen yahoomail ) si apoi iti este trimis link-ul paginii copiate via e-mail, messanger sau prin orice alta metoda.
Tu dai click pe un link si te trezesti pe pagina de login a unui anumit serviciu, fie el bancar, fie de e-mail, fie de alta natura. Introduci informatiile tale iar informatiile se transmit catre cei care au pus la punct tentativa de phising si apoi esti redirectionat catre pagina legitima a site-lui respectiv.
Cum te protejezi? Cu multa multa atentie. Trebuie sa stiti ca niciodata bancile nu va vor cere in e-mail-uri sa va actualizati informatiile despre cont. Iar in cazul in care totusi primiti un astfel de e-mail si nu sunteti siguri ca este sau nu legitim nu va logati pe site-ul respectiv de pe link-ul primit pe e-mail. Deschideti un browser ( Iexplorer, Firefox, Opera ) si tastati direct adresa pe care o stiti dvs. WAIT! There is more to read… read on »
So.. finally paypal decided to fully accept Romania in the program. Now, romanian can use the following services of paypal: sending and receiving money and merchant account included.
What can i say? .. Google choose to pay their checks trough Western Union, now paypal in Romania.. a lot of good news for us.
HLShield is a small library, which are injected in Half Life engine, to protect it against exploits, including against CSDOS.
HLShield features:
* block any CSDOS attack, including modified verisions
* block “born to be pig” exploit
* block the scripts which attempt to “fill” the server with fake players
* can to remove some kind of characters from player nickname, like “`” or “~”
* allow sending a funny message to attacker
* logging attacks, including IP-ul and kind of attack
* very easy install/update, based on automatically installing script