Help2Go
Free Computer Help.
Powered by Volunteers.




Home

These forums have moved!

Click here to view the new, updated Help2Go

COMPUTER NEWS Apr.23/08


   Help2Go Forum Index -> Community Discussion
View previous topic :: View next topic  
Author Message
Canuck
Help2Go Administrator


Joined: 22 May 2003
Posts: 6945
Points: 1425
Location: Edmonton, Alberta, Canada

canada.gif
Posted: Wed 04/23/2008 1:33pm [Post #1]

SANS Solves Mystery of Mass Web Site Infections

http://www2.csoonline.com/article/337615/SANS_Solves_My stery_of_Mass_Web_Site_Infections

The SANS Institute has uncovered what they've termed a "rare gem" as far as computer security investigations go that sheds new light on how up to 20,000 Web sites have been hacked since January. They found a sneaky software tool that uses Google's search engine to hunt for Web sites running certain kinds of vulnerable applications, wrote Bojan Zdrnja, on the institute's blog. When the tool finds a site that is vulnerable, it kicks into action. "The exploit just consisted of an SQL statement that tried to inject a script tag into every HTML page on the web site," Zdrnja wrote. That SQL statement was crafted to target Web sites running Microsoft's Internet Information Server and SQL Server. Once compromised, the Web sites were then rigged to serve malicious software to visitors using JavaScript, which tried various exploits based on known software vulnerabilities. Among the malicious programs served up was a password-stealing program for the game "Lord of the Rings Online," security vendor McAfee said last month.

EarthLink Redirect Service Poses Security Risk, Expert Says

http://www.computerworld.com/action/article.do?command= viewArticleBasic&articleId=9079099&source=rss_topic17

A vulnerability in servers used by EarthLink Inc. to handle mistyped Web page requests may have allowed attackers to launch undetectable phishing attacks against any Internet site, according to a noted Internet security researcher. The bug, which was patched earlier this week, underscores a fundamental security risk in the way that some Internet service providers are attempting to generate advertising revenue from mistyped Web addresses, said Dan Kaminsky, director of penetration testing at IOActive Inc., a security consulting firm. Because of a bug in the software used to redirect users to these advertising and search pages, Kaminsky was able to get the pages to run his own JavaScript code. With the browser treating this code as if it were from a legitimate domain, Kaminsky was able to steal users' cookies, create fake Web sites that appeared to be hosted on legitimate domains, and even log into certain Web sites without authorization.

British Police Use Facebook to Gather Evidence

http://www2.csoonline.com/article/337667/British_Police _Use_Facebook_to_Gather_Evidence

UK - The Greater Manchester Police force is looking for friends - on Facebook. It has created a Facebook application to collect leads for investigations, marking the first use of the social networking site by U.K. law enforcement. The application delivers a real-time feed of police news and appeals for information. Next to that content is a feature to share a particular story with other friends in a person's network, as well as post comments. One of the recent updates is an appeal asking for information about four men, one of whom was armed with an axe, who robbed a betting shop. A "Submit Intelligence" link takes a Facebook user to the police Web site where they can anonymously submit tips.
 
This post has: 0 recommendations

Back to top
Display posts from previous:   
   Help2Go Forum Index -> Community Discussion All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


phpBB component by Adam van Dongen. Based on phpBB © 2001, 2002 phpBB Group
Creative Commons License

(C) 2008 Help2Go      Contact Us      Joomla! is Free Software released under the GNU/GPL License.