Syber Group
Toll Free : 855-568-TSTG(8784)
Subscribe To : Envelop Twitter Facebook Feed linkedin

Microsoft’s IE Latest Flaw: ‘Cookiejacking’

May 31, 2011 by  
Filed under Internet

Comments Off on Microsoft’s IE Latest Flaw: ‘Cookiejacking’

A technology security researcher has discovered a flaw in Microsoft Corp’s widely used Internet Explorer browser that he said may allow hackers to steal credentials to access FaceBook, Twitter and other websites.

He coined the technique as ”cookiejacking.”

“Any website. Any cookie. Limit is just your imagination,” said Rosario Valotta, an independent Internet security researcher based in Italy.

Hackers can exploit the flaw to access a data file stored inside the browser known as a “cookie,” which holds the login name and password to a web account, Valotta wrote.

Once a hacker has that cookie, he or she can use it to access the same site, said Valotta, who calls the technique “cookiejacking.”

The vulnerability affects all versions of Internet Explorer, including IE 9, on every version of the Windows operating system.

To take advantage of this flaw, the hacker must first persuade the victim to drag and drop an object across the PC’s screen before the cookie can be hijacked.

That sounds like a difficult task, but Valotta said he was able to do it fairly easily. He built a puzzle that he put up on Facebook in which users are challenged to “undress” a photo of an attractive woman.

“I published this game online on FaceBook and in less than three days, more than 80 cookies were sent to my server,” he said. “And I’ve only got 150 friends.”

Microsoft said there is little risk a hacker could succeed in a real-world cookiejacking scam.

“Given the level of required user interaction, this issue is not one we consider high risk,” said Microsoft spokesman Jerry Bryant.

Read More….

Sony Hacked Again

May 29, 2011 by  
Filed under Around The Net

Comments Off on Sony Hacked Again

More than 2000 users of Sony Ericsson’s Canadian Website are impacted by the latest hack attack to hit a battle worn Sony. Sony Ericsson is joint mobile phone venture between Sony and Ericsson. According to Sony hackers made off with e-mail addresses, passwords and phone numbers–but no credit card details. Sony has now shut down the affected site. Around 1000 of the stolen records from the Sony Canadian Website are already online, posted by Idahc, a “Lebanese grey-hat hacker”.

“Sony Ericsson’s Website in Canada, which advertises its products, has been hacked, affecting 2000 people,” a Sony spokesperson told AFP. “Their personal information was posted on a Website called The Hacker News. The information includes registered names, email addresses and encrypted passwords. But it does not include credit card information.”

“Sony Ericsson has disabled this e-commerce Website,” Sony detailed to IDG News. “We can confirm that this is a standalone website and it is not connected to Sony Ericsson servers.” For security, Sony has shut down the Canadian Sony Ericsson eShop page, which currently reads: “D’oh! The page you’re looking for has gone walkabout. Sorry.”

Read More…..

Skype Gives Asterisk The Boot

May 29, 2011 by  
Filed under Internet

Comments Off on Skype Gives Asterisk The Boot

The Internet is buzzing with news that Skype is in the process of giving Asterisk the boot by no longer offering Skype for Asterisk starting in July.  Skype for Asterisk is proprietary software that was developed by Digium with Skype’s approval. The software was unique in that it allowed Asterisk based systems to join Skype’s VoIP Network. We assume this will not negatively impact current users for the next couple of years.

We wonder if Microsoft had a hand in killing this deal with Asterisk since they have a competing product.  One could also assume that Skype wanted to develop a native application and not use Asterisk for SIP implementations. I guess we will need the executives at Skype to fill us in on the details one day.

Read More….

Apple Admits To Security Issues

May 28, 2011 by  
Filed under Computing

Comments Off on Apple Admits To Security Issues

Apple has finally acknowledge and has promised an update for Mac OS X that will find and remove the MacDefender fake security software, and warn uninfected users when they download the infectious program.

The announcement — part of a new support document that the company posted late Tuesday — was the company’s first public recognition of the threat posed by what security experts call “scareware” or “rogueware.”

Apple has taken criticism for not publicly responding to the MacDefender threat.

“In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants,” Apple said in the document. “The update will also help protect users by providing an explicit warning if they download this malware.”

Apple also outlined steps that users with infected Macs can take to remove the scareware.

Andrew Storms, director of security operations with nCircle Security, was surprised that Apple said it would embed a malware cleaning tool in Mac OS X.

Read More……

Verizon To End Unlimited Mobile Data Plan

May 24, 2011 by  
Filed under Smartphones

Comments Off on Verizon To End Unlimited Mobile Data Plan

If you have a smartphone with an unlimited data plan on the Verizon Wireless network, get ready to mourn the end of those good times.

Verizon will put the kabash on its unlimited smartphone data plan some time this summer, according to comments made by the carrier’s chief financial officer. Speaking at the Reuters Global Technology Summit on Thursday, Verizon CFO Fran Shammo stated the company will soon roll out new tiered pricing plans and altogether eliminate the current $30-a-month unlimited option.

According to Reuters, which reported the news, the move is designed to “force heavy data users to pay more for mobile data.”

Read More….

Google Moves Quickly To Plug Data Leaks

May 24, 2011 by  
Filed under Smartphones

Comments Off on Google Moves Quickly To Plug Data Leaks

Google confirmed that it’s starting to roll out a server-side patch for a security vulnerability in most Android phones that could allow hackers to access important credentials at public Wi-Fi hotspots.

“Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in Calendar and Contacts,” said a Google spokesman in an emailed statement. “This fix requires no action from users and will roll out globally over the next few days.”

Google will apparently apply the fix to its servers since it does not need to push out an over-the-air update to Android phones.

Experts applauded Google’s fast reaction.

“It’s impressive how quickly Google fixed this,” said Kevin Mahaffey, chief technology officer and a co-founder of San Francisco-based mobile security firm Lookout. “Google’s security team, especially on Android, is very, very quick to deal with issues.”

Whatever Google is implementing will shut the security hole that three German researchers publicized last week.

According to the University of Ulm researchers, who tested another researcher’s contention last February that Android phones sent authentication data in the clear, hackers could easily spoof a Wi-Fi hotspot — in a public setting such as an airport or coffee shop — then snatch information that users’ phones transmitted during synchronization.

In Android 2.3.3 and earlier, the phone’s Calendar and Contacts apps transmit information via unencrypted HTTP, then retrieve an authentication token from Google. Hackers could eavesdrop on the HTTP traffic at a public hotspot, lift authentication tokens and use them for up to two weeks to access users’ Web-based calendars, their contacts and also the Picasa photo storage and sharing service.

Read More…

Google SEARCH Goes SSL

May 22, 2011 by  
Filed under Internet

Comments Off on Google SEARCH Goes SSL

Google is finally taking privacy seriously to a degree by offering its users a secure form of searching while using Google Search. Moving forward users will have the opportunity to enable SSL (Secure Socket Layer) for added security.  Be advised, the service will only cover the Google search and clicks made through Google to other non-secured sites will be visible.

Read More……

HTC To Have Many Tablets

May 21, 2011 by  
Filed under Around The Net

Comments Off on HTC To Have Many Tablets

Smartphone maker HTC plans to introduce a range of different tablet computers to gain a its share in the fast-growing market, a company executive said on Tuesday.

The global market for tablets, started only last year with Apple’s iPad, will likely grow to 108 million devices next year, compared with just 17.6 million in 2010, according to research firm Gartner.

“I really believe that the tablet market is really going to be a big market in the future and this is just the start,” HTC Europe head Florian Seiche told the Reuters Global Technology Summit.

“In five years’ time, schools will have tablets probably instead of physical notebooks. I think that’s going to be such a massive wave of additional penetration in society… I think we can’t even guess the potential.”

Read More…

Bill Had A Hand In Microsoft Buying Skype

May 20, 2011 by  
Filed under Telecom

Comments Off on Bill Had A Hand In Microsoft Buying Skype

One of the world’s richest people, Bill Gates had given his blessing for Microsoft to buy Skype for $8.5 billion dollars.  Actually, Bill Gates pressed other executives on the board of directors to support or back the idea of gobbling Sky which has yet to turn a profit.

Word on the street is that Bill told the Gates BBC in an interview which will be televised this weekend that he played an instrumental role in getting this deal approved by the board of directors. So this really squashes any rumors that Steve Ballmer was the force behind the deal getting approved by the executive team.

Read More…..

AOL Launches Professional Division

May 19, 2011 by  
Filed under Around The Net

Comments Off on AOL Launches Professional Division

AOL Inc is launching a professional division called AOL Industry on Monday geared towards capturing the  government, energy and defense executives attention.

The idea is to bring the use of social media, video and design from consumer-oriented sites and apply it to media for business professionals.

“(Trade media) hasn’t done as good a job at innovating as consumer media,” said Jay Kirsch, vice president and general manager of AOL Industry, who pitched the idea to AOL at the end of last summer.

“If you look at most of the innovations that have really changed media most of them have been consumer facing and not business-to-business.”

AOL Energy rolled out first and will be followed by AOL Government and AOL Defense in June. AOL Industry is not charging a subscription for access and will not have a print component.

Read More…

« Previous PageNext Page »