Core Security released details on three iCal bugs last week. What’s suspicious is that Apple hasn’t fixed them yet, despite being told in January. The bugs are relatively harmless if you have iCal configured correctly – ie. to not automatically parse invitations from Mail. Unfortunately, that’s not the default on Leopard. I’ve run into the same problem before, and I turned the “feature” off for other reasons. There’s a bug in the ics parser that could potentially allow for remote code execution. Not good. Any program that automatically opens up attachments from your mail reader -Mail, Outlook, Thunderbird, etc. SHOULD BE RECONFIGURED! The same goes for remote images. Any attachment should be suspect unless you know who it came from,[…]
Category: hacking
Hackers pulled off an attack that had a physical effect when they found a way to post flashing images on an epilepsy forum. Some users of the site experienced migraines and “near-seizure reactions.” The attack happened when hackers exploited a security hole in the foundation’s publishing software that allowed them to quickly make numerous posts and overwhelm the site’s support forums. I remember learning in my computer ethics class about bad programming practices that led to physical injuries and even death. Lax security can have all sorts of effects, and when you see someone intentionally trying to bring physical harm to a group of people, you get an idea of the type of person we’re working against.
At the ToorCon conference in Seattle this past Saturday, Microsoft announced it would allow ethical hackers to test and probe it’s services. In a first for a major company, Microsoft has publicly pledged not to sue or press charges against ethical hackers who responsibly find security flaws in its online services. I personally think this is great news, and wish more larger companies would do the same. Far too often are valid security holes being found, and not reported in fear of repercussions, and those same holes are then exploited by real hackers for their own personal gain. We need a community more open to the fact that there are good guys out here who are trying to help. Luckily[…]
Just when you thought implementing that new biometric fingerprint reader was enough to circumvent those pesky keyloggers or pin readers, something like this comes along: A British researcher has developed a biometric keylogger of sorts that can capture fingerprints required to unlock building doors or gain access to computer networks or other restricted systems. I was honestly curious as to what took so long. Let’s face it, the idea of security now days is pretty much just that, an “idea”. Password can become stronger, keycards or tokens can be used, all electronic communication can be encrypted. But unless ever feasible measure is taken to ensure protect something, it’s always going to fall to the old proverb – “a chain is[…]
Security engineers at Indiana University were stumped by a misbehaving printer, but lead engineer Nate Johnson solved the problem when he found a networking vulnerability. While investigating the printer problem, Nate Johnson, IU lead security engineer, took a chance and tested the printer for vulnerability to an FTP Bounce Attack, a method used by malicious computer hackers to relay a network scan through another device, essentially covering their tracks online. The FTP bounce attack has been around for over a decade, but Canon’s imageRUNNER printers were not configured by default to disallow misuse of the PORT command. A security engineer needs to be aware that new attacks are born every day, but the old ones don’t necessarily go away.
An opinion piece worth reading from Bruce Schneier in Wired: Security requires a particular mindset. Security professionals — at least the good ones — see the world differently. They can’t walk into a store without noticing how they might shoplift. They can’t use a computer without wondering about the security vulnerabilities. They can’t vote without trying to figure out how to vote twice. They just can’t help it. When we hire people at Gemini Security Solutions, this mentality is something we explicitly look for. I do think this can be taught, but people with the innate hacker tendencies tend to come up with 5 vulnerabilities where an “ordinary” person might only see one or two. via /.