Passa ai contenuti principali

Post

Security Incidents of This Week (weekly)

VoIP hacker sentenced to 10 years A Venezuelan citizen on Friday was sentenced to 10 years in US federal prison for hacking into the networks of telecommunications companies and then routing millions of minutes of voice over IP calls over their systems. Edwin Andres Pena, 27, admitted in February that he pocketed more than $1m in the scam, in which he posed as a legitimate reseller of long-distance calling services. By scanning networks of AT&T and other companies, Pena was able to identify unprotected ports through which he could transmit more than 10 million minutes of unauthorized calls. tags : SecurityIncident Phones Un cannone orbitale contro i siti delle major è tuttora reperibile in rete il software LOIC (Low Orbit Ion Cannon) che permette facilmente di saturare di richieste i siti oggetto dell'attacco sino a renderli irraggiungibili. t...

Security Incidents of This Week (weekly)

Under attack: 4,300 Indian websites defaced in H1 2010 - More and more Indian websites are coming under threat from attackers and face the fear of getting defaced. In the first half of 2010, around 4,300 websites were reported to have been defaced in India. This threat has assumed significance in light of the fact that Indian companies are now increasing their online presence and tapping consumers through social networking sites tags : SecurityIncident Defacement Pentagon computers attacked with flash drive - A foreign spy agency pulled off the most serious breach of Pentagon computer networks ever by inserting a flash drive into a U.S. military laptop, a top defense official said Wednesday. The previously classified incident, which took place in 2008 in the Middle East, was disclosed in a magazine article by Deputy Defense Secretary William J. Lynn and released by t...

Security Incidents of This Week (weekly)

Adobe PDF Vulnerability: Stack overflow in Font File parsing - Niels Provos tags : SecurityIncident Vulnerable Adobe Reader 0day under active attack tags : SecurityIncident Vulnerable Malware Used to Steal South Korean Military Secrets tags : SecurityIncident Military malware MS probes mystery IE bug "A nasty vulnerability exists in the latest Internet Explorer 8," Evans wrote. "I have been unsuccessful in persuading the vendor to issue a fix." tags : SecurityIncident Vulnerable Microsoft investigating long-known vulnerability in IE tags : ...

Certificato self-signed (falso) e malware

Un malware nascosto in una falsa update di Flash Player è associato ad una firma digitale. Installa un nelle trusted authorities un certificato self-signed per “VeriSign Class 3 Code Signing 2009 CA”. Ovviamente falso. http://www.sophos.com/blogs/sophoslabs/?p=10078

Phishing

Tratto da un articolo che descrive il funzionamento della tecnologia di rilevazione dei phishing websites sviluppata ed utilizzata quotidianamente da Google: Gartner estimates that phishers stole $1.7 billion in 2008, and the Anti-Phishing Working Group identified roughly twenty thousand unique new phishing sites each month between July and December of 2008 Articolo: Large-Scale Automatic Classification of Phishing Pages . NDSS 17-th Annual Network and Distributed System Security Symposium (2010).

Routing dinamico

Un articolo leggero ma ben fatto: In 1998, a hacker told Congress that he could bring down the Internet in 30 minutes by exploiting a certain flaw that sometimes caused online outages by misdirecting data. In 2003, the Bush administration concluded that fixing this flaw was in the nation's "vital interest." Fast forward to 2010, and very little has happened to improve the situation. The flaw still causes outages every year. Molto interessante perché la faccenda è una conseguenza diretta di alcuni aspetti fondamentali di Internet: routing dinamico, sistema aperto, assenza di autorità centrale unica, assenza di meccanismi di autenticazione. Just how fragile is the internet? http://skunkpost.com/news.sp?newsId=2327