subscribe to the RSS Feed

Saturday, November 22, 2008

Gauri de securitate in Google Chrome

Posted on 7 September 2008 at 8:30

Scriam de Google Chrome , cel mai nou web iesit pe piata. Iata ca in scurt timp au inceput sa apara si gaurile de securitate.

Attackers can combine the months-old “carpet bomb” bug with another flaw disclosed last month to trick people running Google’s brand-new into downloading and launching malicious code, a researcher has warned.
The attacks are possible because Google used an older version of WebKit, the open-source rendering engine that also powers Apple’s Safari, as the foundation of , said Israeli researcher Aviv Raff on Wednesday.
Raff posted a proof-of-concept exploit to demonstrate how hackers could create a new “blended threat” - so-named because it relies on multiple vulnerabilities - to attack .
“This is different from the Safari/IE blended threat,” said Raff in an interview conducted via instant messaging. “It’s a different blend with one similar component. It uses the -download vulnerability (aka ‘Carpet Bomb’) in combination with a [user interface] design flaw and an issue with Java that doesn’t display a warning on execution of JAR files downloaded from the .” Raff’s reference to the earlier Safari/IE blended threat was to his May report that said a bug in Apple’s Safari could be paired with an unpatched vulnerability in Microsoft’s Explorer (IE) to compromise Windows PCs.

The “carpet bomb” bug, revealed by researcher Nitesh Dhanjani in May and named for the way it could be used to dump files onto the Windows desktop, stemmed from the fact that Safari did not require a user’s permission to download a file. Attackers, Dhanjani said, could populate a malicious site with rogue code that Safari would automatically download to the desktop, where it might tempt a curious user into opening the file.
After first balking - for a time it refused the classify the flaw as a vulnerability - Apple patched the bug in mid-June by updating Safari to 3.1.2.
Raff combined the still-there carpet bomb bug with another reported by UK-based penetration tester Petko Petkov at the Black Hat conference last month. At the time, Petkov outlined how a Java flaw allows Windows to automatically execute JAR files without prompting or warning the user.
also contributes to the problem, said Raff, by making downloaded files appear as buttons at the bottom of the ’s frame. “One click on this button will execute the file,” Raff said. Attackers could place malware on a malicious site, then wait for - or better yet, draw in - users running . The would not warn the user of the JAR file automatically downloaded from the site, and the button-style indicator in could be easily mistaken for part of the application.
Users can set an option in that will thwart Raff’s exploit by popping up a warning asking for a filename and location for any downloaded file. To change , select Options under the “Customize and control Google ” menu; the menu is at the far right, near the top, and although not named, looks like a small wrench. Next, click the “Minor Tweaks” tab in the Options window, then check the box that reads “Ask where to save each file before downloading.”
The blended threat, Raff argued, illustrates a bigger problem for , which has borrowed components from both Safari - via WebKit - as well as unspecified pieces of Mozilla’s open-source Firefox.
Calling the approach “problematic” from a standpoint, Raff wondered how quickly Google will be able to patch problems in .
“They’ll have to track all vulnerabilities in those [borrowed] features, and fix them in too,” Raff said in the blog post that spelled out more detail of the /Java blended threat. “This will probably be only after those vulnerabilities were fixed by the other vendors or were publicly reported. It will put users at risk for a long time.”

By Gregg Keizer, Computerworld (US)

Sursa: google chrome vulnerable

BAC-ul

Posted on 28 June 2008 at 10:12

-ul 2008 e in plina desfasurare. Pe langa scandalurile obisnuite ( subiecte gresite, subiecte stupide - unele , subiecte aflate cu ceva timp inainte de inceperea examenului ) anul asta se discuta din ce in ce mai mult de copierea la .
Zilele trecute eram la Piata Timpuri Noi si auzeam discutiile tinerilor care dadusera -ul la de langa piata. Unii se laudau in gura mare ca au copiat tot, ca unii profesori chiar le-au spus cum se rezolva subiectele, ca alti profesorii i-au lasat sa copieze din carti sau alte materiale didactice. Alti elevi se plangeau ca n-au putut sa copieze nimic.

Pe de alta parte, din surse sigure am aflat ca multe teze contineau fix aceleasi greseli, in general legate de anumite nume ale unor persoane. De unde concluzia clara ca cineva le-a dictat sau au copiat unii de la altii cu tot cu greseli.

Noi domenii de la yahoo

Posted on 21 June 2008 at 20:57

, cunoscutul furnizor de de si nu numai, a lansat 2 noi domenii: ymail.com si rocketmail.com . Asta inseamna ca acum puteti sa va creeati adrese de care sa contina
numele@ymail.com sau @rocketmail.com. Miscarea vine in intampinarea utilizatorilor care nu puteau sa aiba o adresa de la , care sa le contina numele, din cauza numarului urias de conturi deja existente la ..

RCS & RDS, servicii de tot rahatul

Posted on 17 May 2008 at 13:38

Pana acum o saptamana eram un client destul de multumit de serviciile RCS/( cam in proportie de 96 % ). Vinerea trecuta ( 09.05.2008 ) a fost o furtuna, care s-a soldat si cu o intrerupere a curentului electric. Spun asta pentru ca am gasit pc-ul inchis cand m-am intors de la munca. Internetul si cablul tv functionau, doar era mort. Luni sun la sa-i intreb ce si cum.

Primesc raspunsul ca se stie de avarie, se lucreaza si in scurt timp serviciul de telefonie va functiona. Marti sun din nou si mi se spune ca echipamentele sunt configurate ( de parca m-ar fi interesat aceasta informatie ) si ca urmeaza sa fie instalate. Miercuri, o dom’soara foarte intepata, imi spune ca “asa cu mi-au spus si colegii ei mai inainte” termenul de rezolvare al avariei este vineri ( 16.05.2008, am presupus eu :D ). O intreb foarte inocent daca i se pare normal sa stam o saptamana fara serviciul de telefonie. Primesc un raspuns stupefiant: da, avand in vedere ca este un serviciu gratuit/bonus. Zic, hopa.. asta inseamna ca aia de la vodafone imi dau 30 de minute pe luna gratis dar e posibil sa nu ma lase sa le folosesc :)))). Evident, n-am lamurit nimic cu respectiva.

Ideea e alta. Acum este sambata si nici urma de . Ma gandesc ca se referea la vinerea viitoare :)).

PHISHING

Posted on 17 May 2008 at 7:34

Ok.. dar ce e PHISHING? Pai este o tentativa de . Cum functioneaza? Se “cloneaza” ( copiaza ) o pagina extrem de populara ( gen ) si apoi iti este trimis link-ul paginii copiate via e-, messanger sau prin orice alta metoda.

Tu dai click pe un link si te trezesti pe pagina de login a unui anumit serviciu, fie el bancar, fie de e-, fie de alta natura. Introduci informatiile tale iar informatiile se transmit catre cei care au pus la punct tentativa de si apoi esti redirectionat catre pagina legitima a site-lui respectiv.
Cum te protejezi? Cu multa multa atentie. Trebuie sa stiti ca niciodata bancile nu va vor cere in e--uri sa va actualizati informatiile despre cont. Iar in cazul in care totusi primiti un astfel de e- si nu sunteti siguri ca este sau nu legitim nu va logati pe site-ul respectiv de pe link-ul primit pe e-. Deschideti un ( Iexplorer, Firefox, Opera ) si tastati direct adresa pe care o stiti dvs.
WAIT! There is more to read… read on »

Unhappy Adsense publisher

Posted on 2 October 2007 at 19:57

Some crazy kid destroyed a google adsense check, and he says that is original …right, :))

Paypal in Romania

Posted on 2 October 2007 at 16:47

So.. finally paypal decided to fully accept Romania in the program. Now, romanian can use the following services of paypal: sending and receiving and merchant account included.

What can i say? .. Google choose to pay their checks trough Western Union, now paypal in Romania.. a lot of good for us.

HLDShield Anti - CSDOS (Linux)

Posted on 1 October 2007 at 19:49

What is HLShield

HLShield is a small library, which are injected in Half Life engine, to protect it against exploits, including against CSDOS.

HLShield features:

* block any CSDOS attack, including modified verisions
* block “born to be pig” exploit
* block the scripts which attempt to “fill” the server with fake players
* can to remove some kind of characters from player nickname, like “`” or “~”
* allow sending a message to attacker
* logging attacks, including IP-ul and kind of attack
* very easy install/update, based on automatically installing script

WAIT! There is more to read… read on »

Page 1 of 3123»