More Trojan horse for Apple Mac! Is Mac more insecure than windows?
One more malware have been spotted for the Apple Mac machine. This time Trojan.iServices.B which gets into the system, open the backdoor in Mac machines and connect them to a zombie network. This malware is distributed through pirated copies Adobe Photoshop CS4 available at warez channel.
Few days back another malware of the same type was [...]
Detecting New Rootkits
A new rootkit can either be one that has never been seen before, or one that uses new technologies or previously unused methods of attack. Or both. Andthat is where our rootkit detection problems start.
How can we detect rootkits? There are simple and complex pseudo-solutions. I say “pseudo” because of the number of false [...]
What is a rootkit?
For me, it is the evolution of the Trojan Horse concept. It is, in these days, a complete package of trojanized system utilities, with some interesting add-on programs, like specially designed sniffers and, maybe the most dangerous or frightening, kernel modules whose primary objective is to hide certain processes, directories and/or files. Being at the [...]
Cyber attacks are real but is there any foolproof defense yet?
Tulip Systems Inc., the world renowned high bandwidth and broadcast stream hosting service US corporation was under repeated cyber attacks aimed at disrupting web services during the Georgia-Russia standoff few months ago. The promoters of Tulip are Georgian expatriates and this has enabled Tulip to work on many internet initiatives in Georgia. Tulip revealed [...]
Hack Tools, Utilities and Exploits
Packetstorm Last 10 Files
glsa-200901-13.txt – Gentoo Linux Security Advisory GLSA 200901-13 – Multiple vulnerabilities have been discovered in Pidgin, allowing for remote arbitrary code execution, denial of service and service spoofing. Versions less than 2.5.1 are affected.
moinmoin-xss.txt – The MoinMoin Wiki engine suffers from a cross site scripting vulnerability.
What Damage Can Hackers Do?
Hackers like to subvert computer security without permission. They are cyber criminals. This can mean gaining access to a computer across the Internet for illicit purposes. They might engage in any of the following activities:
* Vandalism—Destruction or digital defacement of a computer or its data for destruction’s sake. Sometimes this is [...]
Detecting and Preventing Social Engineering and other Hacking Processes
Social engineering attacks are growing fast, and today majority of attackers use social engineering techniques to infiltrate into a victim’s network. It is very difficult for a technician to identify social engineering attacks, as these attacks do not involve any technical tools or any software-coding program. A social engineering hacker attempts to persuade users to [...]
SQL injection Basic Tutorial
One of the major problems with SQL is its poor security issues surrounding is the login and url strings.this tutorial is not going to go into detail on why these string work as am not a coder i just know what i know and it works
SEARCH:
admin\login.asplogin.asp
with these two search string you will have plenty of [...]
[Paper XSS] Vulnerabilities in Common Shockwave Flash Files
SummaryCritical vulnerabilities exist in a large number of widely used web authoring tools that automatically generate Shockwave Flash (SWF) files, such as Adobe (r) Dreamweaver (r), Abobe Contribute (r), Adobe Acrobat (r) Connect ™ (formerly Macromedia Breeze), InfoSoft FusionCharts, and Techsmith Camtasia. The flaws render websites that host these generated SWF files vulnerable to Cross-Site [...]
DNS disaster: first attacks reported
The first attacks that are likely to have stemmed from a serious Domain Name System flaw have been reported.
Dan Kaminsky
(Credit: Kaminsky’s blog)
The existence of the Domain Name System (DNS) flaw, which could be used to redirect browsers to malicious sites, was revealed at the start of July by security researcher Dan Kaminsky. Multiple vendors, including [...]