http://conference.hitb.org/hitbsecconf2008kl/



hackinthebox
 ::  hitb portal  ::  hitb portal (SSL)  ::  hitb forum (SSL)  ::  hitb security conference  ::  hitb training ::  hitb irc  ::  hitb photos  ::  hitb videos :: 

HITB Search:
Who's Online
There are 230 unregistered users and 0 registered users on-line.

You can log-in or register for a user account here.



Security White Papers:

Main Menu

Top Stories for Today
[370] The new rules for buying a Mac
[204] Teenage hacking gang busted in Bavaria
[201] Fedora 9 - an OS that even the Linux challenged can love
[168] Hacker Posts Data of 6 Million Chileans
[154] BlackBerry challenge to iPhone
[154] Microsoft software gives free tours of space
[152] Check your rootkits at the door with rkhunter
[138] The future of security
[128] Windows XP SP3 Adds 10% Performance Boost, Tests Show
[126] Chile government probes major data hack
[124] Google launches local hosted security service
[122] Facebook asks for $100 million
[119] Is it OK to hack if you are a good guy?
[113] Kaspersky says mobile malware very active in first quarter of 2008
[111] HP has eye on IBM as it discusses EDS acquisition
[111] Don't Get Duped by Myanmar Scams
[110] PC World Editor to Step Down, Start Own Venture
[108] Virgin Media to raise fibre-network capacity fourfold
[105] April Sees Thirty-Five Percent Increase in Web Threats
[100] Hackers hijack a half-million sites in latest attack
[97] 3 charged in LI with hacking into national restaurant chain
[94] Interview: Shlomo Kramer, CEO of Check Point
[93] Anti-Botnet Security Vendor FireEye Gets $14.5 Million Funding
[87] Dublin businesses vulnerable to IT attacks
[87] Apple To Launch iPhone In Four Asian Regions
[62] Purdue IT Staff Builds Supercomputer In A Half Day

View the Top 50 articles

Top 20 of the Last 2 Weeks

E-Zine Archive

Past Articles
Tuesday, May 13
·Anti-Botnet Security Vendor FireEye Gets $14.5 Million Funding (0)
·Hacker Posts Data of 6 Million Chileans (0)
·The future of security (0)
·Apple To Launch iPhone In Four Asian Regions  (0)
·Windows XP SP3 Adds 10% Performance Boost, Tests Show (0)
·Purdue IT Staff Builds Supercomputer In A Half Day (0)
Monday, May 12
·Hackers attack Mexican Congress website, opposing oil privatization (0)
·Tax refund spam circulating on Internet (0)
·Websites provide crucial links in Myanmar cyclone crisis (0)
·What can cash buy? Not an iPhone (0)
·Hackers target Herald website (0)
·Anatomy of Security-Enhanced Linux (SELinux) (0)
·Games Convention Asia Conference calls for papers (0)
·UK.gov torpedoes personal carbon credit plans (0)
·The 25 Year Old BSD Bug (0)
·UK Government Uses CCTV and Anti-Terror Laws to Prosecute Petty Crimes (0)
Saturday, May 10
·Pirate Bay: MPAA damage claim is a fabrication (0)
·Women in IT thank mums for encouragement (0)
·Former Siemens chief faces admin probe (0)
·Use Hydra to Remotely Test Password Security (0)
·Sync Your iPhone Wirelessly in Linux (0)
·Hackers Find a New Place to Hide Rootkits - SMM (0)
·Apple has Wii-like Apple TV controller under development (0)
·FBI probes counterfeit China computer parts (0)
·NASA's new supercomputer aims for 10 PFLOPS by 2012 (0)
·EA receives $1 billion loan commitment (0)
·TorrentSpy Won't Pay $111 Million Court Order, Lawyer Says (0)
·Facebook 'Connect' To Let Users Share Profiles (0)
·ID Theft Monitoring Services: What You Need To Know (0)
Friday, May 09
·Microsoft shares more IE8 security details (0)
 Older articles

HITB Links

Teenage hacking gang busted in Bavaria
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:41 AM (Reads: 204)
Source: Manufacturing and Logistics IT



German authorities crack down on illegal online activities

Hackers can make money by stealing identities and personal information. Experts at SophosLabs™, Sophos's global network of virus, spyware and spam analysis centers, have welcomed the news that German authorities have apprehended 11 people suspected of running a hacking ring.

According to media reports, police arrested suspects aged between 15 and 22 years old in Baden-Württemberg, Hamburg, Lower Saxony North Rhine-Westphalia and Rhineland-Palatinate and confiscated computers for forensic examination.

[ Printer-friendly page Send this story to someone ]

PC World Editor to Step Down, Start Own Venture
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:39 AM (Reads: 110)
Source: Wired (Blog)



PC World editor in chief Harry McCracken has announced his retirement from the venerable computer magazine he heads.

McCracken, who has been with PC World for 14 years, will step down June 2, he wrote in a blog post.

He told Epicenter that his departure has nothing to do with any disagreement with the executives of PC World parent company IDG, unlike last year, when McCracken quit -- and was later rehired -- in a dispute over editorial independence from the magazine's advertising staff.

[ Printer-friendly page Send this story to someone ]

Chile government probes major data hack
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:38 AM (Reads: 126)
Source: USA Today



A prosecutor was appointed Monday to investigate how a computer hacker accessed government data for 6 million Chileans and posted it to the Internet.

Prosecutor Jose Ignacio Escobar, a specialist in high-tech crime, opened the probe as the government announced plans to step up data protection.

Police chief Jaime Jara said the weekend data leak did not include financial records and was less serious than first thought.

The information accessed by a hacker included identity card numbers, addresses, telephone numbers, e-mails and academic records.

[ Printer-friendly page Send this story to someone ]

BlackBerry challenge to iPhone
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:37 AM (Reads: 154)
Source: The Independent (UK)



A summer sales war is about to break out between Apple’s iPhone and the BlackBerry, as the two wildly popular mobile phone brands do battle with new, upgraded versions of their internet-enabled devices.

Research in Motion, the company behind the BlackBerry, unveiled the BlackBerry Bold yesterday morning, hoping that a host of new video and music features will snare consumers who previously associated the device only with business users.

Wall Street traders sent Research in Motion shares to an all-time high on news of the launch, which showed the company had resolved technical issues earlier than expected, and puts it on course to challenge Apple’s iPhone for consumers’ hearts.

[ Printer-friendly page Send this story to someone ]

Virgin Media to raise fibre-network capacity fourfold
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:36 AM (Reads: 108)
Source: ZDNet (UK)



As web users' thirst for bandwidth soars, cable broadband purveyor Virgin Media is looking to squeeze four times the capacity out of its optical network, but without the expense of ripping out and upgrading its fibre.

The trend for online video content and popular bandwidth-heavy applications, such as the BBC's iPlayer, has led to concerns among ISPs that their infrastructure will soon be creaking under the strain.

But now Virgin Media — which, with its 20Mbps service, already offers the fastest broadband speeds in the UK and has a 50Mbps rollout planned for this year — has completed a trial of bandwidth-boosting kit which increased capacity on its long-haul 10G network fourfold.

[ Printer-friendly page Send this story to someone ]

Microsoft software gives free tours of space
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:35 AM (Reads: 154)
Source: Reuters



Any Star Trek fan knows that space travel is not always easy, but Microsoft Corp wants to make traveling the "final frontier" as simple as turning on your computer.

The world's largest software maker launched a free software application called WorldWide Telescope on Monday that allows everyone from space novices to astronomy professors to easily explore galaxies, star systems and distant planets.

The WorldWide Telescope stitches together 12 terabytes -- the data equivalent of 2.6 billion pages of text -- of pictures from sources including the Hubble Space Telescope, the Chandra X-Ray Observatory Center and the Spitzer Space Telescope.

[ Printer-friendly page Send this story to someone ]

The new rules for buying a Mac
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:34 AM (Reads: 370)
Source: Computer World



The world has a lot of unwritten rules -- in social etiquette. In baseball. And in buying computers. For years, we have unquestioningly followed numerous unwritten rules when buying a Mac.

Like many customs, these rules were once based on a foundation of facts and reason. But in the past few years, many long-standing Mac truths have been upended. All Macs run on multiple-core Intel processors now. IMacs are no longer hobbled by crippling feature limitations. And speedy external peripherals have drastically lessened the need for add-on cards.

In other words, the old rules no longer apply. If you're planning on buying a new Mac, you need facts about the modern lineup so you can choose the computer that's right for you.

[ Printer-friendly page Send this story to someone ]

Facebook asks for $100 million
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:32 AM (Reads: 122)
Source: Tech Radar



In the space of four years, Facebook has grown from being a Harvard University web project to one of the biggest social-networks in the world. An explosive growth such as this is enough to give any CEO a nosebleed, especially when the cash coming in doesn’t quite cover the amount of servers needed to accommodate so much information.

That’s why, according to Business Week, Facebook has gone cap in hand to venture lenders and asked to borrow a hefty $100 million. That’s not counting the $370 million that the company has already raised in the last year.

[ Printer-friendly page Send this story to someone ]

HP has eye on IBM as it discusses EDS acquisition
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:31 AM (Reads: 111)
Source: Yahoo! News



Having seized the lead in personal computer sales worldwide, Hewlett-Packard Co. is stalking the technology services market for its next conquest.

In what could turn into its biggest deal in six years, HP hopes to buy Electronic Data Systems Corp., which pioneered the concept of running data centers and providing other high-tech help for large companies and government agencies.

Palo Alto-based HP and Plano, Texas-based EDS confirmed Monday that they are in "advanced discussions" about a possible combination without providing additional details.

[ Printer-friendly page Send this story to someone ]

Google launches local hosted security service
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:30 AM (Reads: 124)
Source: ZDNet (Australia)



Google has launched a hosted security service for enterprise customers in Australia, a re-branded version of the Postini service it acquired last year.

The hosted service, now called "Google Web Security for Enterprise", protects corporate Web and e-mail users from viruses, spyware, malicious Web sites, and offers hosted e-mail archiving services.

The service offers a choice of cheap security features. The option of Google Message Filtering (e-mail filtering) is billed at AU$3.65 per user per year, while Google Message Security (scanning of inbound and outbound e-mail plus messaging controls) is charged at AU$14.63 per user per year.

[ Printer-friendly page Send this story to someone ]

Fedora 9 - an OS that even the Linux challenged can love
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:13 AM (Reads: 201)
Source: The Register



Fedora 9, the latest release from the Fedora Project, goes up for download on Tuesday. The ninth release of Fedora ushers in a number of changes aimed at making the venerable distribution a more newbie-friendly desktop, but longtime users needn't fear a great dumbing down; version 9 packs plenty of power user punch as well.

Fedora is a community-driven distribution sponsored by Red Hat and, while Fedora may be best known as a popular server OS, most of the changes in Fedora 9 are aimed at making the system friendlier for desktop users.

[ Printer-friendly page Send this story to someone ]

Kaspersky says mobile malware very active in first quarter of 2008
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:12 AM (Reads: 113)
Source: Secure Computing



Kaspersky’s senior virus analyst has warned of ‘unpleasant news’ from the world of mobile malware in its latest quarterly security trend report.

Alexander Gostev, senior virus analyst at Kaspersky Lab and author of Malware Evolution: January – March 2008, has revealed that in the first three months of 2008, innovation and quantity of new malicious programs targeting mobile phones have increased.

Most operating systems were targeted; namely Symbian, Windows Mobile, J2ME (Java platform) and the popular iPhone.

[ Printer-friendly page Send this story to someone ]

Interview: Shlomo Kramer, CEO of Check Point
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:10 AM (Reads: 94)
Source: Secure Computing



The serial company founder and SC's CEO of the Year tells Paul Fisher why he knew all along that data-centric security was the future.

We are on the top floor of the Mandarin Oriental hotel in Knightsbridge, [London]. Shlomo Kramer's imposing frame is supported by a sofa in the middle of the living area of the suite, which seemingly meets his approval. He likes the view.

Looking through the windows and out over Hyde Park, Kramer asks if there is much fun to be had there - he is bringing his family over for Passover, he says, and is looking for activities for the kids.

[ Printer-friendly page Send this story to someone ]

Dublin businesses vulnerable to IT attacks
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:10 AM (Reads: 87)
Source: Tech Central (Ireland)



Security improvements have not kept pace with the increase in the number of wireless connections in Dublin's business districts. While the number of wireless connections has risen by 25% since 2006, there has only been a two percentage point increase in the number of secure wireless connections.

This situation came to light in the latest wireless vulnerability assessment by professional services firm Deloitte. The firm pinpointed 1,107 wireless connections in 2008, compared with 884 found in 2006. Of these 594 (54%) were found to be insecure. In 2006, 497 (56%) networks were found to be insecure.

[ Printer-friendly page Send this story to someone ]

Is it OK to hack if you are a good guy?
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:08 AM (Reads: 119)
Source: Network World



I have a problem with hackers. I don’t think they are heroes. I don’t think they should be rewarded for their illegal activities. It bugs me that ex-hackers make big bucks trading on their notoriety with book deals and public speaking engagements.

Mind you I know lots of people that were hackers at an early age and got caught. They were usually scared onto the straight and narrow by a knock on the door by the FBI, or a call from the site administrators of one of their targets. No big deal. Sometimes the experience is the first time they have had to figure out the difference between right and wrong. Usually they were hacking for fun, not profit. Long time readers know that I criticize the victims of these forays as much as the purps. NASA servers vulnerable? Fix ‘em. Website vulnerable to SQL insertion? Do something about it! These guys are skilled and inquisitive and I don’t condemn them, especially if they experience remorse and mend their ways.

[ Printer-friendly page Send this story to someone ]

Check your rootkits at the door with rkhunter
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:06 AM (Reads: 152)
Source: Tech Republic



So it’s usually op ed here but I ran across a story the other day about a new proof of concept rootkit (Hackers Find a New Place to Hide Rootkits) and thought maybe I’d highlight an application I generally use to inspect systems for rootkits. The application is rkhunter. This tool claims to keep you 99.9% free from rootkits. By running such tests as:

* MD5 hash compare
* Rootkit default file search
* Inconsistent binary file permissions
* LKM and KLD suspected string search
* Hidden file search
* Optional scan within plaintext and binary files

And even thought it’s .1 % inaccurate (as the developers claim) it’s still a smart move to install this application on any machine that lives on line, especially production-level machines.

[ Printer-friendly page Send this story to someone ]

April Sees Thirty-Five Percent Increase in Web Threats
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:05 AM (Reads: 105)
Source: Govtech



In its Global Threat Report issued today, ScanSafe reported a 35 percent increase in Web-based malware in April. The increase was driven by two separate series of attacks -- an expanding iframe injection on middle tier sites that comprise the so-called "Long Tail" of the Web -- as well as a much higher profile SQL injection attack that affected thousands of Web sites -- including many well known sites such as the United Nations.

"What we saw in April was a one-two punch," says Mary Landesman, senior security researcher, ScanSafe. "In addition to the much publicized SQL injection attack, Web surfers were impacted by the mushrooming of an attack on mid-tier websites. While individually these mid-tier sites may not pack in the visitors, collectively they make up what's often referred to as the Long Tail of the Web. Ongoing investigation by our Security Threat Alert Team indicates this is a large scale attack that is growing exponentially and is not being detected by the majority of Web crawlers."

[ Printer-friendly page Send this story to someone ]

Hackers hijack a half-million sites in latest attack
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:04 AM (Reads: 100)
Source: Computer World



More than half a million Web sites have been compromised in a new round of attacks that hacked domains in order to infect unsuspecting users' PCs with a variety of malware, a security researcher said today.

"This is an ongoing campaign, with new domains [hosting the malware] popping up even this morning," said Paul Ferguson, a network architect at antivirus vendor Trend Micro Inc. "The domains are changing constantly."

According to Ferguson, over half a million legitimate Web sites have been hacked by today's mass-scale attack, only the latest in a string that goes back to at least January. All of the sites, he confirmed, are running "phpBB," an open-source message forum manager.

[ Printer-friendly page Send this story to someone ]

3 charged in LI with hacking into national restaurant chain
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:03 AM (Reads: 97)
Source: KVIA.com



Three men were charged today with hacking into a national restaurant chain's computerized cash registers and stealing credit card information from customers.

Federal prosecutors say that eleven Dave & Buster's restaurants at various locations around the United States were hit in the scheme.

The indictment was unsealed in U.S. District Court in New York.

[ Printer-friendly page Send this story to someone ]

Don't Get Duped by Myanmar Scams
Posted by l33tdawg on Tuesday, May 13, 2008 - 04:02 AM (Reads: 111)
Source: Eye Witness News



The Better Business Bureau is warning people about scams that target your generosity.

Fake charities are pretending to collect donations for the victims of the cyclone that hit Myanmar last week. Almost 32,000 people were killed and nearly 30,000 are still missing.

BBB officials say they usually see scam such as this anytime after a major disaster. Mid-South BBB President Randy Hutchison says after Hurricane Katrina, the FBI identified 4,000 websites asking for donations and about 60% of the sites were from people overseas. Hutchison says the overseas sites were probably bogus.

[ Printer-friendly page Send this story to someone ]

Login
 



 


 Log in Problems?
 New User? Sign Up!


Last 15 Postings to HITB Forum

Packet Storm Security Latest
· e107zogo-sql.txt
The e107 zogo-shop plugin version 1.16 Beta 13 suffers from a SQL injection vulnerability.
· aih-sql.txt
Advanced Image Hosting version 2.1 remote SQL injection exploit.
· e107blog-blindsql.txt
The e107 BLOG engine plugin version 2.2 suffers from a blind SQL injection vulnerability.
· ajhyip-sql.txt
AJ HYIP ACME suffers from a remote SQL injection vulnerability in topic_detail.php.
· eqdkp-bypass.txt
EQDKP version 1.3.2f authentication bypass proof of concept exploit.
· USN-612-2.txt
Ubuntu Security Notice 612-2 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems.
· dsa-1571-1.txt
Debian Security Advisory 1571-1 - Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package. As a result, cryptographic key material may be guessable. This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.
· articlelive-xss.txt
Interspire ArticleLive NX is vulnerable to a cross site scripting vulnerability.


Topics
· All topics
· AMD News (May 07, 2008)
· Apple News (May 13, 2008)
· Articles (Feb 13, 2006)
· Ask Us (Feb 01, 2003)
· Audio/Video (May 07, 2008)
· Encryption (May 08, 2008)
· Games (May 12, 2008)
· Hardware (May 10, 2008)
· HITB News (Dec 03, 2007)
· Industry News (May 13, 2008)
· Intel News (Apr 29, 2008)
· Law and Order (May 13, 2008)
· Linux (May 12, 2008)
· Microsoft (May 13, 2008)
· Networking (May 13, 2008)
· PDAs (Feb 09, 2007)
· Privacy (May 13, 2008)
· Red Hat (May 13, 2008)
· Science (Apr 28, 2008)
· Security (May 13, 2008)
· Software & Programming (May 12, 2008)
· Spam (May 12, 2008)
· Technology (May 13, 2008)
· Transmeta (Jul 07, 2007)
· Viruses & Malware (May 13, 2008)
· Wireless (May 01, 2008)

HITB Affiliates

Latest Advisories from Xatrix