StrongWebmail CEO's mail account hacked via XSS
Ryan Naraine: A Webmail service that touts itself as hack-proof and offered $10,000 to anyone who could break into the CEO’s e-mail has lost the challenge. A trio of hackers successfully compromised the e-mail using persistent cross-site scripting (XSS) vulnerability and are now claiming the bounty. [ SEE: Email service provider: 'Hack into our CEO's email, win $10k' ] The [...]


Thu Jun 04 14:16:32 PDT 2009
FTC shuts down notorious botnet ISP
Ryan Naraine: The Federal Trade Commission (FTC) has shut down a U.S.-based Internet Service Provider for recruiting, hosting and actively participating in the distribution of spam, child pornography, and other harmful electronic content. Pricewert LLC (also known as 3FN and APS Telecom) was shut down by a district court judge at the FTC’s. The ISP?s upstream providers and [...]


Thu Jun 04 13:58:40 PDT 2009
Patch Tuesday heads-up: Critical Windows, IE fixes coming
Ryan Naraine: Microsoft plans to ship 10 security bulletins next Tuesday (June 9, 2009) with fixes for a wide range of code execution vulnerabilities affecting Windows, Microsoft Office and Internet Explorer. Six of the ten bulletins will be rated “critical,” Microsoft’s highest severity rating. [ SEE: Dangerous Microsoft DirectX vulnerability under attack ] This month’s batch of patches will [...]


Thu Jun 04 10:58:11 PDT 2009
Typo'd Google domains in Top 10 malware exploit sites
Ryan Naraine: Misspelled versions of two popular Google services are among the Top 10 sites hosting exploits for use in drive-by malware download attacks. On the heels of two massive drive-by attacks — ten of thousands of hijacked sites launching attacks via the browser — Google released a list showing that malicious hackers are typo-squatting on its domains [...]


Thu Jun 04 08:55:15 PDT 2009
419 scammers using NYTimes.com 'email this feature'
Dancho Danchev: What do Burkina Faso and the New York Times have in common? As of recently, a peak of 419 scams promising you the Moon and asking you for advance-fees via emails sent through the NYTimes.com’s ‘email this feature’ in order to successfully bypass anti-spam filters. The tactic applied by 419 con artists aiming to abuse the [...]


Wed Jun 03 12:10:40 PDT 2009
Email service provider: 'Hack into our CEO's email, win $10k'
Dancho Danchev: A newly launched startup called StrongWebMail is aiming to add a new layer of secure authentication for its customers - phone verification prior to logging in and alert services for potential email compromises. The company is in fact so confident in its approach that it’s currently offering $10,000 reward to the person who breaks into the [...]


Tue Jun 02 12:54:50 PDT 2009
No comments:
Post a Comment