Forgot your password?

typodupeerror

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

Facebook

Ask Slashdot: How To Best Setup a School Internet Filter? 454

Posted by samzenpus
from the watch-how-you-play dept.
An anonymous reader writes "I was recently volunteered to be the network/computer admin for a small non-profit school. One of the items asked of me had to do with filtering inappropriate content (i.e. stuff you wouldn't want your mother to see). Essentially we want to protect people who aren't able to protect themselves, at least while on campus. Basic site filtering is fairly easy — setup squid with one of the many filtering engines and click to filter the categories your interested. Additionally, making the computer lab highly visible uses public shame and humiliation to limit additional activity. The real question — How do you filter Facebook? There is a lot of great content and features on Facebook, and its a great way to stay in contact with friends, but there is also a potentially dark side. Along with inappropriate content, there is a tendency to share more information than should be shared, and not everyone follows proper security and privacy guidelines. What's the best way to setup campus-wide security/privacy policies for Facebook?"
Bug

ICS-CERT Warns of Serious Flaws In Tridium SCADA Software 34

Posted by timothy
from the their-security-problems-are-scadalous dept.
Trailrunner7 writes "The DHS and ICS-CERT are warning users of some popular Tridium Niagara AX industrial control system software about a series of major vulnerabilities in the applications that are remotely exploitable and could be used to take over vulnerable systems. The bugs, discovered by researchers Billy Rios and Terry McCorkle, are just the latest in a series of vulnerabilities found in the esoteric ICS software packages that control utilities and other critical systems. The string of bugs reported by Rios and McCorkle include a directory traversal issue that gives an attacker the ability to access files that should be restricted. The researchers also discovered that the Niagara software stores user credentials in an insecure manner. There are publicly available exploits for some of the vulnerabilities."
Cellphones

First Pictures of Apple's New Mini Connector 303

Posted by timothy
from the ok-now-complain-about-it dept.
tad001 writes "The Daily Mail has pictures of Apple's new mini connector. The photograph, shared by French tech website nowhereelse.fr, shows two components, one of which is said to be similar to another apparently leaked picture of a part of the new iPhone. As well as the new dock connector, the part also seems to take in the headphone jack and the home button connector for the hotly awaited devices."
Data Storage

Ask Slashdot: Protecting Data From a Carrington Event? 386

Posted by timothy
from the managed-to-save-the-kids-and-the-games dept.
kactusotp writes "I run a small indie game company, and since source code is kind of our lifeblood, I'm pretty paranoid about backups. Every system has a local copy, servers run from a RAID 5 NAS, we have complete offsite backups, backup to keyrings/mobile phones, and cloud backups in other countries as well. With all the talk about solar flares and other such near-extinction events lately, I've been wondering: is it actually possible to store or protect data in such a way that if such an event occurred, data survives and is recoverable in a useful form? Optical and magnetic media would probably be rendered useless by a large enough solar flare, and storing source code/graphics in paper format would be impractical to recover, so Slashdot, short of building a Faraday cage 100 km below the surface of the Moon, how could you protect data to survive a modern day Carrington event?"
Government

Cyber Attack Knocks Offline Saudi Aramco 67

Posted by timothy
from the just-communicate-with-oil dept.
wiredmikey writes "Saudi Aramco, Saudi Arabia's national oil company and the largest oil company in the world, confirmed that is has been hit by a cyber attack that resulted in malware infecting user workstations and forcing IT to kill the company's connection to the outside world. '..An official at Saudi Aramco confirmed that the company has isolated all its electronic systems from outside access as an early precautionary measure that was taken following a sudden disruption that affected some of the sectors of its electronic network,' the company wrote in a statement. This incident follows an attack on systems at the National Iranian Oil Company back in April, when a virus was detected inside the control systems of Kharg Island oil terminal, which also resulted in the company taking its systems offline. In response to continued cyber attacks against its networks and facilities, Iran earlier this month said it plans to move key ministries and state bodies off the public Internet to protect them from such attacks."
Security

Anonymous Claims To Have Hacked Sony PSN Again 239

Posted by samzenpus
from the we're-back dept.
hypnosec writes "Anonymous has claimed a new attack on Sony's PlayStation Network, and this time around it seems they have information from nearly 10 million user accounts. As a proof of the hack they dumped more than 3000 credentials online in the form of a pastebin post. The notorious hacktivist group is claiming that the entire set of hacked credentials contains over 10 million PSN accounts and that the file is of around 50GB." Update: 08/16 13:12 GMT by S : Sony has denied this claim.
Botnet

Botnet Flaw Lets Researchers Disrupt Attacks 26

Posted by Soulskill
from the perhaps-should-have-hidden-the-on/off-switch dept.
Trailrunner7 writes "A team of researchers has discovered a weakness in the command-and-control infrastructure of one of the major DDoS toolkits, Dirt Jumper, that enables them to stop attacks that are in progress. The discovery gives the researchers the ability to access the back-end servers that control the attack tool, as well as the configuration server, and key insights into the way that the tool works and how attackers are using it. Dirt Jumper is not among the more well-known of the DDoS attack toolkits, but it's been in use for some time now and has a number of separate iterations. The bot evolved from the older RussKill bot over time, and various versions of the tool's binary code and back end configuration files have been made public. Researchers have watched as the bot has been used in attacks around the world against a variety of targets, and now they've been able to find a crack in the malware's control infrastructure."
Privacy

Gaining Info On Tech Execs With Just Their Email 75

Posted by Unknown Lamer
from the mark-zuckerburg-revealed-as-closet-myspace-fan dept.
jfruh writes "Did you know that Craigslist founder Craig Newmark has a loyalty points account with the Starwood hotel chain? Did you know that both Tim Cook and Steve Ballmer have Dropbox accounts? All this information — and much more — can be found out because so many prominent executives use their corporate email address for their account logins, and most sites make it possible to see if an email address is associated with an account even if you don't have the account password. Just knowing that such an account exists can lead to technical and social engineering attempts to crack it, as happened in the case of Wired's Mat Honan."
Crime

Inside a Ransomware Money Machine 158

Posted by Unknown Lamer
from the spam-this-time-it-breaks-your-legs dept.
tsu doh nimh writes "The FBI is warning that it's getting inundated with complaints from people taken in by ransomware scams that spoof the FBI and try to scare people into paying 'fines' in lieu of going to jail for having downloaded kiddie porn or pirated content. KrebsOnSecurity.com looks inside a few of the scams in the FBI alert, and it turns out it only takes 1-3 percent of victims to pay up to make it seriously worth the fraudsters' while."
Security

WikiLeaks Back Online After Massive DDoS Attack 56

Posted by Soulskill
from the of-barn-doors-and-horses dept.
Trailrunner7 writes "Controversial document-sharing site WikiLeaks was back online Monday evening after sustaining a week-long distributed denial-of-service attack. The organization apparently received some extra capacity and assistance from Web performance and security firm Cloudfare to counter the 10 gigabits per second of bogus traffic that overwhelmed servers for numerous WikiLeaks domains and several supporters' sites. Targets included WikiLeaks' news aggregation site and its donations infrastructure, which it calls the Fund for Network Neutrality. A few days ago the organization posted a statement describing what it surmised was a DNS amplification attack. 'Broadly speaking, this attack makes use of open DNS servers where attackers send a small request to, the fast DNS servers then amplify the request, the request has now increased somewhat in size and is sent to the server of wikileaks-press.org. If an attacker then exploits hundreds of thousands of open DNS resolvers and sends millions of requests to each of them, the attack becomes quite powerful. We only have a small uplink to our server, the size of all these requests was 100,000 times the size of our uplink.'"
Encryption

Researchers Seek Help Cracking Gauss Mystery Payload 229

Posted by timothy
from the fabulous-prizes-await dept.
An anonymous reader writes "Researchers at Kaspersky Lab are asking the public for help in cracking an encrypted warhead that gets delivered to infected machines by the recently discovered Gauss malware toolkit. They're publishing encrypted sections and hashes in the hope that cryptographers will be able to help them out." Adds reader DavidGilbert99: "The so-called Godel module is targeting a specific machine with specific system configurations, and Kaspersky believes the victim is likely a high-profile target. The decryption key, Kaspersky believes, will be derived from these specific system configurations, and so far it has been unable to find out what they are."
Education

Ask Slashdot: Open Source Software To Manage Student Grades? 120

Posted by timothy
from the vi-is-all-you-need dept.
An anonymous reader writes "I have been assigned the task of finding a software package to automate the management of grades in a high school. It does not need to be a complete system, but rather just manage grading calculations and printing of report cards. The management of grades is currently done using spreadsheets. What are some open source options to handle this situation?"
Security

Companies Advise Tighter Security After Honan Hack 99

Posted by samzenpus
from the add-another-security-question dept.
In the wake of the hacking of Mat Honan's accounts, Google, Facebook, Amazon, and Apple are just a few of the companies making their security policies tougher, and they are advising people to do the same. From the article: "Even as those companies’ teams moved to patch the holes, others moved to offer security tips. Matt Cutts, head of Google’s Webspam team, used his personal Website to urge Gmail users to embrace two-factor authentication. 'Much of the story is about Amazon or Apple’s security practices, but I would still advise everyone to turn on Google’s two-factor authentication to make your Gmail account safer and less likely to get hacked,' he wrote in the August 6 posting."
Cellphones

DOJ Says iPhone Is So Secure They Can't Crack It 454

Posted by samzenpus
from the too-hard dept.
zacharye writes "In the five years since Apple launched the iPhone, the popular device has gone from a malicious hacker's dream to law enforcement's worst nightmare. As recounted by the Massachusetts Institute of Technology's Technology Review blog, a Justice Department official recently took the stage at the DFRWS computer forensics conference in Washington, D.C. and told attendees that the beefed up security in iOS is now so good that it has become a nightmare for law enforcement."

VMS must die!

Working...