Posts by author:

spinman

Government To Issue Terror Alerts On Facebook

by spinman on April 8, 2011

in SBN


The U.S. Department of Homeland Security will begin issuing terror alerts via Facebook and Twitter starting the end of this month. Color-coded alerts will be a thing of the past, and instead of five different warning levels, only two will remain — elevated and imminent — and the public will only hear about them some [...]

Microsoft Security Patches for April

by spinman on April 8, 2011

in SBN


Patch Tuesday a staggering 17 security bulletins (nine of which have been given Microsoft’s highest severity rating of “critical”), addressing 64 security vulnerabilities. Software including bugs which are said to be fixed by the patches include Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio and .NET Framework. One of the vulnerabilities reportedly fixed will be the MHTML redering [...]


There is yet another viral scam being spread across Facebook by a rogue application, tricking users into believing that Facebook is closing all accounts today. Many Facebook users have found that their profiles have been updated with a message which reads:       Facebook is closing all accounts today. They can’t handle so many [...]

UAE Man-in-the-Middle Attack Against SSL

by spinman on September 4, 2010

in SBN

Who are these certificate authorities? At the beginning of Web history, there were only a handful of companies, like Verisign, Equifax, and Thawte, that made near-monopoly profits from being the only providers trusted by Internet Explorer or Netscape Navigator. But over time, browsers have trusted more and more organizations to verify Web sites. Safari and Firefox now trust more than 60 separate certificate authorities by default. Microsoft’s software trusts more than 100 private and government institutions.

Read the full article –  [Schneier on Security]

Share/Bookmark

Automated vs. Manual Security

by spinman on September 4, 2010

in SBN

In this video from OWASP AppSec Research 2010, David Byrne and Charles Henderson from Trustwave talk about automated vs. manual security.

Share/Bookmark

Facebook is Adding More Security

by spinman on September 3, 2010

in SBN

Facebook has announced another security feature which will allow you to logout of your account remotely.  So now if you use someone else’s computer or phone to access your facebook account and forget to logoff of when your done, you will be able to login from another device and end that session.  This feature will more than likely be rolled out gradually and below is an image of what you will see when it is.

facebook-remote-logout

To check to see if you have it already, simply go to your Account Settings page and choose to change you Account Security.  The information provided for each active session will consist of the login time, device name (if you have named it), a ballpark location derived from the IP address, and the browser and operating system on the used device. This way, even if someone accesses you account after you or your account credentials get phished and used, you can lock out those users by terminating the session remotely and changing the password for the account.

In case you forgot Facebook also rolled out a security feature in May that when enabled will notify you when your account has been accessed from an unapproved device. Below is what that screen will look like.

fb-account-security

Share/Bookmark

The Pub Poll

by spinman on September 3, 2010

in SBN


Take the Pub Poll!


Share/Bookmark

IPv6 Will Bring New Threats

by spinman on September 3, 2010

in SBN

ipv6 The countdown to the saturation of the IPv4 address supply is now down to a matter of months: and along with the vast address space of the next-generation IPv6 architecture comes more built-in network security as well as some new potential security threats.

Check out the rest of the article – [Dark Reading]

Share/Bookmark

Apple’s Ping Social Network is being Exploited

by spinman on September 3, 2010

in SBN

ping I bet Apple didn’t expect this when they released iTunes 10 and the new iTunes Ping a social network for music.  Spammers and scammers have quickly exploited this new feature that launched on Wednesday.  Ping is a cross between Facebook and Twitter, giving over 160 million iTunes users the ability to have networks of friends.

Sophos researchers have found that Ping is being over-run by scams and spam messages, some of which try and direct users into believing they will receive a free iPhone if they complete online surveys.

Most of the security industry has been pointing out the migration of spam from an email-only venture to blog/forum comments, Facebook, Twitter and other Web 2.0 platforms,” writes Chester Wisniewski of Sophos. “But apparently Apple didn’t consider this when designing Ping, as the service implements no spam or URL filtering. It is no big shock that less than 24 hours after launch, Ping is drowning in scams and spams.

More information about the Ping spam attacks, including screenshots, can be found in Chester Wisniewski’s Blog from Sophos.

Share/Bookmark

Microsoft has released a new version of a software tool that developers and administrators can use to harden older applications against common vulnerabilities. Short for Enhanced Mitigation Experience Toolkit, EMET version 2.0 brings several new protections to operating systems and applications such as Windows XP or Internet Explorer 6, which remain widely used even though they are not as secure as more recent releases.

Check out the rest of the article –  The Register

Share/Bookmark