You are currently browsing the Security Tutorial : Archive weblog archives for December, 2008.

Breaking News

A tour of Google’s new Experimental Search. Verdict: awesome

admin @ January 30, 2008 # No Comment Yet

At Google’s new experimental search features page, a total of five projects are available for users to try: Alternate view for search results, Keyword suggestions, Keyboard shortcuts, Left-hand search navigation, and Right-hand contextual search navigation. Users can only elect to use one experimental feature at a time, and the only reason that explains this […]

More on page 113

2007 A Hacking Odyssey – Reconnaissance

admin @ January 29, 2008 # No Comment Yet

2007 A Hacking Odyssey – Reconnaissance
a tutorial by nokia
The aim of this series of papers that will take an in-depth look at how someone may target and electronically break into an organisation, is to educate people who may be tasked with looking after and securing a corporate network to do so in an effective manner.
My […]

More on page 112

Jihadists get world-class encryption kit

admin @ January 28, 2008 # No Comment Yet

The Global Islamic Media Front has released a new set of encryption tools to help militants conduct clandestine communications, according to a security firm.
Through its alleged contacts within the militant jihadist community, VeriSign staff have acquired a pre-release version of the group’s latest encryption tools called “Asrar Al-Mujahidin” or “Mujahedeen Secrets”, according to Rick Howard, […]

More on page 110

Employee’s silent rampage wipes out $2.5m worth of data

admin @ January 24, 2008 # No Comment Yet

A Florida woman who believed she was about to get fired has been accused of deleting $2.5m worth of computer files to seek revenge on her employer.
Jacksonville Sheriff’s officials say Marie Lupe Cooley, 41, used her own account credentials to access the server of Steven E. Hutchins Architects and delete seven years’ worth of drawings. […]

More on page 106

French bank SocGen says hit by $7.1 billion fraud

admin @ January 24, 2008 # No Comment Yet

French bank Societe Generale said fraud by a single trader had caused it a 4.9 billion euro ($7.1 billion) loss and that it would seek emergency funds as a result, shocking battered markets.If fraud is proved, the loss will be the biggest caused by a rogue trader, ahead of the $2.6 billion hit to Sumitomo […]

More on page 105

Compatibility and IE8

admin @ January 23, 2008 # No Comment Yet

But wait, a lot of people say at this point, why isn’t this a problem for Firefox, or Safari, or any other browser? The answer is that developers of many sites had worked around many of the shortcomings or outright errors in IE6, and now expected IE7 to work just like IE6. Web developers expected […]

More on page 104

Memo to Internet nutjobs: Please, think before you post

admin @ January 23, 2008 # No Comment Yet

Threats against others on the Internet are just about as surprising as the sky being blue every morning. But some threats are more serious than others, and the list of victims seems to be expanding as more of the unwashed masses general public gets online. Online marketers are one of the newest groups to join […]

More on page 103

RIAA Website Wiped Clean by Hackers

admin @ January 21, 2008 # One Comment

Someone has used SQL injection to wipe their entire database. There is no content left on that site at all.SQL injection works when a sloppy programmer passes a URL variable straight into a query without validating it. So if you have something like this:
SELECT article_title FROM table WHERE year = [URL variable]
And you pass “2007″ […]

More on page 102

Can Intelligence Agencies Read Overwritten Data?

admin @ January 20, 2008 # No Comment Yet

Of course, modern operating systems can leave copies of ” deleted” files scattered in unallocated sectors, temporary directories, swap files,remapped bad blocks, etc, but Gutmann believes that an overwritten sector can be recovered under examination by a sophisticated microscope and this claim has been accepted uncritically by numerous observers. I don’t think these observers have […]

More on page 99

CIA Says Hackers Have Cut Power Grid

admin @ January 19, 2008 # No Comment Yet

Speaking at a conference of security professionals on Wednesday, CIA analyst Tom Donahue disclosed the recently declassified attacks while offering few specifics on what actually went wrong.
Criminals have launched online attacks that disrupted power equipment in several regions outside of the U.S., he said, without identifying the countries affected. The goal of the attacks was […]

More on page 98

Vulnerability Turns MS Excel Into Open Door for Hackers

admin @ January 16, 2008 # No Comment Yet

The vulnerability is in Microsoft Office Excel 2003 Service Pack 2, along with Microsoft Office Excel Viewer 2003, Microsoft Office Excel 2002, Microsoft Office Excel 2000 and Microsoft Excel 2004 for Mac, Microsoft said. If successfully exploited on a vulnerable computer, it could enable remote code execution, the company added.
Microsoft is now investigating public reports […]

More on page 46

Sun Microsystems Announces Agreement to Acquire MySQL

admin @ January 16, 2008 # No Comment Yet

January 16, 2008 Sun Microsystems, Inc. (NASDAQ: JAVA) today announced it has entered into a definitive agreement to acquire MySQL AB, an open source icon and developer of one of the world’s fastest growing open source databases for approximately $1 billion in total consideration. The acquisition accelerates Sun’s position in enterprise IT to now include […]

More on page 94

Five-Year-Old Boy Detained by the TSA

admin @ January 12, 2008 # No Comment Yet

A less extreme example again is that of the US Transportation Security Administration (TSA), the authority charged with protecting US transportation systems, and supposedly those using them, recently detaining a five-year-old boy on the suspicion of being a terrorist. His name was similar to someone on the US “no-fly” list, which contains the names of […]

More on page 45

Teenager hacks Polish tram system

admin @ January 12, 2008 # No Comment Yet

A 14 year-old schoolboy hacked into a Polish tram system and used a remote control to change the direction of a number of vehicles.
Transport employees in Lodz immediately suspected outside interference when a driver who was trying to turn right found his tram veering to the left.
The tram’s back wagon was derailed and hit a […]

More on page 93

Anatomy of a hack attack

admin @ January 8, 2008 # No Comment Yet

With the help of security experts, we reconstruct a typical hack attack on two large organisations and walk through the steps that the head of IT should follow in such a case.
Monday, 9am
Blackjack, a hacker working from an internet cafe in London, is about to launch an attack on a major government agency. His aim […]

More on page 44