Stories
Slash Boxes
Comments
typodupeerror delete not in

Slashdot is powered by your submissions, so send in your scoop

Comments: 34 +-   First Malicious iPhone Worm In the Wild on Saturday November 21, @03:37PM

Posted by timothy on Saturday November 21, @03:37PM
from the because-some-jerks-are-clever dept.
security
An anonymous reader writes "After the ikee worm that displayed a picture of Rick Astley on jailbroken iPhones, the first malicious iPhone worm (Google translation; original, in Dutch) has now been discovered in the wild. Internet provider XS4ALL in the Netherlands encountered several of such devices (link in Dutch) on the wireless networks of their customers and put out a warning. After obtaining a copy of the malware it was discovered that the jailbroken phones, which are exploited through openSSH with a default password, scan IP ranges of mobile internet providers for other vulnerable iPhones, phone home to a C&C botnet server, are able to update themselves with additional malware and have the ability to dump the SMS database as well. Owners of a jailbroken iPhone with a default root password are advised to flash to the latest Apple firmware in order to ensure no malware is present."
Read More... 34 comments story

Comments: 67 +-   Cyber Attacks On US Military Jump Sharply In 2009 on Saturday November 21, @02:02AM

Posted by Soulskill on Saturday November 21, @02:02AM
from the proportional-with-gold-farming dept.
security
angry tapir writes "Cyber attacks on the US Department of Defense — many of them coming from China — have jumped sharply in 2009, a US congressional committee has reported. Citing data provided by the US Strategic Command, the US-China Economic and Security Review Commission said that there were 43,785 malicious cyber incidents targeting Defense systems in the first half of the year. That's a big jump. In all of 2008, there were 54,640 such incidents. If cyber attacks maintain this pace, the yearly increase will be around 60 percent. The full report (PDF) is available online."
Read More... 67 comments story

Comments: 55 +-   RFID Fingerprints To Fight Tag Cloning on Saturday November 21, @12:00AM

Posted by Soulskill on Saturday November 21, @12:00AM
from the cloning-is-bad-haven't-you-seen-scifi dept.
privacy
Bourdain writes with news out of the University of Arkansas, where researchers are looking for ways to combat counterfeit RFID tags. Passive tags typically wait for a reader to transmit a signal of the appropriate strength and frequency before sending their own transmission. The scientists found that the amount of power required to trigger this varies quite a bit from one tag to the next, especially when many different frequencies are sampled. This and other physical characteristics give the tag its own "fingerprint" that is independent of the signal information stored in its memory, which the researchers say will facilitate the detection of cloned tags.
Read More... 55 comments story

Comments: 205 +-   Zero-Day Vulnerabilities In Firefox Extensions on Friday November 20, @10:14AM

Posted by kdawson on Friday November 20, @10:14AM
from the wild-in-the-playground dept.
bug
An anonymous reader writes "Researchers have found several security holes in popular Firefox extensions that have an estimated total of 30 million downloads from AMO (the Addons Mozilla community site). Three 0-days were also released. Mozilla doesn't have a security model for extensions and Firefox fully trusts the code of the extensions. There are no security boundaries between extensions and, to make things even worse, an extension can silently modify another extension." The affected extensions are Sage version 1.4.3, InfoRSS 1.1.4.2, and Yoono 6.1.1 (and earlier versions). Clearly the problem is larger than just these three extensions.
Read More... 205 comments story

Comments: 169 +-   Fedora 12 Package Installation Policy Tightened on Friday November 20, @08:52AM

Posted by kdawson on Friday November 20, @08:52AM
from the tougher-by-default dept.
redhat
AdamWill writes "After the controversy over Fedora 12's controversial package installation authentication policy, including our discussion this week, the package maintainers have agreed that the controversial policy will be tightened to require root authentication for trusted package installation. Please see the official announcement and the development mailing list post for more details."
Read More... 169 comments story

Comments: 209 +-   MS Finds Security Flaw In Google Chrome Frame on Friday November 20, @05:40AM

Posted by timothy on Friday November 20, @05:40AM
from the they're-the-experts dept.
msie
Christmas Shopping writes with this excerpt from Kaspersky Labs' threatpost: "Back in September, when Google launched the Google Chome Frame plug-in for Internet Explorer users, Microsoft immediately warned that the move would increase the attack surface and make IE users less secure. Now comes word that a security researcher in the Microsoft Vulnerability Research (MSVR) has discovered a 'high risk' security vulnerability that could allow an attacker to bypass cross-origin protections." "Google has hurried out a patch," he adds.
Read More... 209 comments story

Comments: 441 +-   Microsoft Denies It Built Backdoor Into Windows 7 on Thursday November 19, @05:16PM

Posted by timothy on Thursday November 19, @05:16PM
from the how-are-your-wife's-bruises? dept.
security
CWmike writes "Microsoft has denied that it has built a backdoor into Windows 7, a concern that surfaced yesterday after a senior National Security Agency (NSA) official testified before Congress that the agency had worked on the operating system. 'Microsoft has not and will not put "backdoors" into Windows,' a company spokeswoman said, reacting to a Computerworld story Wednesday. On Monday, Richard Schaeffer, the NSA's information assurance director, told the Senate's Subcommittee on Terrorism and Homeland Security that the agency had partnered with the developer during the creation of Windows 7 'to enhance Microsoft's operating system security guide.' Thursday's categorical denial by Microsoft was accompanied by further explanation of exactly how the NSA participated in the making of Windows 7. 'The work being discussed here is purely in conjunction with our Security Compliance Management Toolkit,' said the spokeswoman. The company rolled out the Windows 7 version of the toolkit late last month, shortly after it officially launched the operating system."
Read More... 441 comments story

Comments: 95 +-   Two Arrested For Zbot Trojan on Wednesday November 18, @10:23PM

Posted by samzenpus on Wednesday November 18, @10:23PM
from the sorry-about-that dept.
security
An anonymous reader writes "Officers from the Metropolitan Police's Central e-Crime Unit have made Europe's first arrests in the battle against the ZeuS or Zbot Trojan which threatened to compromise thousands of computers. Officers arrested a man and woman, both aged 20 years, in Manchester for offenses under the 1990 Computer Misuse Act and the 2006 Fraud Act. Both suspects were interviewed by PCeU detectives and have been bailed for further in-depth inquiries to be completed. The arrests in connection with the malware represent some of the first in the world, and the first in Europe to combat the distribution and control of ZeuS."
Read More... 95 comments story

Comments: 498 +-   Fedora 12 Lets Users Install Signed Packages, Sans Root Privileges on Wednesday November 18, @04:30PM

Posted by timothy on Wednesday November 18, @04:30PM
from the try-it-you-might-like-it dept.
redhat
eqisow writes "The new default policy for Fedora 12 allows local, unprivileged users to install signed packages without root access. This change apparently went mostly unnoticed until after the Fedora 12 GA release, at which point it sparked a mailing list thread that is, as of this writing, over 100 posts long."
Read More... 498 comments story

Comments: 262 +-   Firefox 3.6 Locks Out Rogue Add-ons on Wednesday November 18, @10:13AM

Posted by CmdrTaco on Wednesday November 18, @10:13AM
from the and-stay-out dept.
mozilla
CWmike writes "Mozilla will add a new lockdown feature to Firefox 3.6 that will prevent developers from sneaking add-ons into the program, the company said. Dubbed 'component directory lockdown,' the feature will bar access to Firefox's 'components' directory, where most of the browser's own code is stored. Mozilla has billed the move as a way to boost the stability of its browser. 'We're doing this for stability and user control [reasons],' said Johnathan Nightingale, manager of the Firefox front-end development team. 'Dropping raw components in this way was never an officially supported way of doing things, which means it lacks things like a way to specify compatibility. When a new version of Firefox comes out that these components aren't compatible with, the result can be a real pain for our shared users ... Now that those components will be packaged like regular add-ons, they will specify the versions they are compatible with, and Firefox can disable any that it knows are likely to cause problems.'"
Read More... 262 comments story

Comments: 85 +-   Hackers Broke Into Brazil Power Grid Operator's Website Last Thursday on Tuesday November 17, @06:41PM

Posted by kdawson on Tuesday November 17, @06:41PM
from the wolf-no-really-this-time-i-mean-it dept.
security
An anonymous reader writes "A week ago, 60 Minutes had a story (we picked it up too) claiming that hackers had caused power outages in Brazil. While this assertion is now believed to be in error, hackers were inspired by the story actually to do what was claimed. Last Thursday, they broke into ONS, the operator of the grid (Google translation; Portuguese original). DarkReading has specific details on the SQL injection vulnerabilities the hackers probably used."
Read More... 85 comments story

Comments: 97 +-   SSL Renegotiation Attack Becomes Real on Monday November 16, @06:30PM

Posted by kdawson on Monday November 16, @06:30PM
from the laugh-a-while-you-can dept.
security
rastos1 and several other readers noted that the SSL vulnerability we discussed a couple of weeks back, which some researchers had claimed was too theoretical to worry about, has now been demonstrated by exploit. The attack description is available on securegoose.org. "A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, a man in the middle is able to steal the credentials of a user authenticating himself through HTTPS to a trusted website."
Read More... 97 comments story

Comments: 57 +-   DNSSEC Implementation Held Up By Tech Delays on Monday November 16, @02:40PM

Posted by timothy on Monday November 16, @02:40PM
from the not-just-those-dogs-in-the-hallway dept.
internet
Jack Spine writes "VeriSign has said that the main obstacle to DNSSEC implementation has been technical delays. The large size of the .com and .net domains would have made it impractical to deploy earlier versions of DNSSEC, according to VeriSign vice president of naming services Pat Kane. Deployment of DNSSEC will close a major security flaw in the DNS, the internet's equivalent to a telephone directory. The problem of DNS cache poisoning was thrown into sharp relief by researcher Dan Kaminsky last year."
Read More... 57 comments story

Comments: 99 +-   Most Security Products Fail To Perform on Monday November 16, @08:45AM

Posted by CmdrTaco on Monday November 16, @08:45AM
from the ninety-percent-of-everything-is-crap dept.
security
An anonymous reader writes "Nearly 80 percent of security products fail to perform as intended when first tested and generally require two or more cycles of testing before achieving certification, according to a new ICSA Labs report that details lessons gleaned from testing thousands of security products over 20 years. Across seven product categories core product functionality accounted for 78 percent of initial test failures. For example, an anti-virus product failing to prevent infection and for firewalls or an IPS product not filtering malicious traffic. Rounding out the top three is the startling finding that 44 percent of security products had inherent security problems. Security testing issues range from vulnerabilities that compromise the confidentiality or integrity of the system to random behavior that affects product availability."
Read More... 99 comments story

Comments: 288 +-   The First Windows 7 Zero-Day Exploit on Monday November 16, @04:54AM

Posted by kdawson on Monday November 16, @04:54AM
from the think-global-print-local dept.
security
xploraiswakco writes with the first Microsoft-confirmed Windows 7 zero-day vulnerability, with a demonstration exploit publicly available. The problem is in SMBv2 and SMBv1 and affects Windows 7 and Windows Server 2008 R2, but not Vista, XP, or Windows Server 2003. A maliciously crafted URI could hard-crash affected machines beyond any remedy besides pushing the white button. "Microsoft said it may patch the problem, but didn't spell out a timetable or commit to an out-of-cycle update before the next regularly-scheduled Patch Tuesday of December 8. Instead, the company suggested users block TCP ports 139 and 445 at the firewall." Reader xploraiswakco adds, "As important as this the mentioned article is, it should also be pointed out that any IT staff worth their pay packet should already have port 139 blocked at the firewall, and probably port 445, too."
Read More... 288 comments story

Comments: 409 +-   UN Officials Remove Poster Mentioning Chinese Firewall on Sunday November 15, @06:04PM

Posted by kdawson on Sunday November 15, @06:04PM
from the can-you-spell-hypocricy dept.
censorship
At a UN-sponsored Internet Governance Forum in Egypt, anti-censorship group Open Net Initiative was startled by a demand from UN officials to remove a poster mentioning Chinese Net censorship. When ONI refused the request, security personnel arrived and took away the poster. The group was promoting a new book, Access Controlled, a survey of Internet censorship, filtering, and online surveillance. A witness said, "The poster was thrown on the floor and we were told to remove it because of the reference to China and Tibet. We refused, and security guards came and removed it. The incident was witnessed by many." Here is a video of the removal.
Read More... 409 comments story

Comments: 102 +-   The "Hail Mary Cloud" Is Growing on Sunday November 15, @12:23PM

Posted by Soulskill on Sunday November 15, @12:23PM
from the like-a-zombie-chia-pet dept.
security
badger.foo writes "The Australian rickrolling of jailbroken iPhones only goes to prove that bad passwords are bad for you, Peter Hansteen points out, as he reports on the further exploits of the password-guessing Hail Mary Cloud (which we've discussed in the past). The article contains log data that could indicate that the cloud of distributed, password-guessing hosts is growing. 'With 1767 hosts in the current sample it is likely that we have a cloud of at least several thousand, and most likely no single guessing host in the cloud ever gets around to contacting every host in the target list. The busier your SSH deamon is with normal traffic, the harder it will be to detect the footprint of Hail Mary activity, and likely a lot of this goes undetected.'"
Read More... 102 comments story

Comments: 69 +-   DNS Problem Linked To DDoS Attacks Gets Worse on Sunday November 15, @09:13AM

Posted by Soulskill on Sunday November 15, @09:13AM
from the i-blame-the-schools dept.
security
itwbennett writes "The percentage of devices on the Internet that are configured to accept DNS queries from anywhere — what networking experts call an 'open recursive' or 'open resolver' system — has jumped from around 50 percent in 2007 to nearly 80 percent this year, according to research sponsored by DNS appliance company Infoblox. As more consumers demand broadband Internet, service providers are rolling out modems configured this way to their customers, said Cricket Liu, vice president of architecture with Infoblox. Georgia Tech researcher David Dagon agreed that open recursive systems are on the rise, in part because of 'the increase in home network appliances that allow multiple computers on the Internet. ... Almost all ISPs distribute a home DSL/cable device. Many of the devices have built-in DNS servers. These can sometimes ship in "open by default" states.' What's worse, says Dagon, is that many of these devices do not include patches for a widely publicized DNS flaw discovered by researcher Dan Kaminsky last year."
Read More... 69 comments story

Comments: 141 +-   Hackers Fail To Crack Brazilian Voting Machines on Sunday November 15, @01:55AM

Posted by kdawson on Sunday November 15, @01:55AM
from the voting-envy dept.
government
blueser writes "From Nov 10th to Nov 13th the Brazilian Government hosted a public hacking contest to test the robustness of its voting machines. 38 participants from private and public IT companies (including the Brazilian Federal Police) were divided into 9 teams, which tried several different approaches to try to tamper with the software installed on the machines, and even to physically interfere in other stages of the process. All attempts (aside from a minor one which would not compromise the overall results) failed, and observations from the participants and neutral observers will be taken into account to improve the process even further. Here is the official announcement for the contest (Google translation; Portuguese original). A summary of the results is available in the Brazilian press (original). Brazilian voting machines use Linux." US voting officials ought to be envious of their Brazilian counterparts, or ashamed, or both. Perhaps this MIT-developed cryptographic voting system offers a way forward.
Read More... 141 comments story

Comments: 101 +-   US Cybersecurity Plan Includes Offense on Saturday November 14, @10:16AM

Posted by Soulskill on Saturday November 14, @10:16AM
from the take-aim-at-their-internets,-soldier dept.
security
z4ns4stu writes "Shane Harris of the National Journal describes how the US government plans to use, and has successfully used, cyber-warfare to disrupt the communications of insurgents in Iraq. 'In a 2008 article in Armed Forces Journal, Col. Charles Williamson III, a legal adviser for the Air Force Intelligence, Surveillance, and Reconnaissance Agency, proposed building a military "botnet," an army of centrally controlled computers to launch coordinated attacks on other machines. Williamson echoed a widely held concern among military officials that other nations are building up their cyber-forces more quickly. "America has no credible deterrent, and our adversaries prove it every day by attacking everywhere," he wrote. ... Responding to critics who say that by building up its own offensive power, the United States risks starting a new arms race, Williamson said, "We are in one, and we are losing."'"
Read More... 101 comments story

It may or may not be worthwhile, but it still has to be done.