YAMSIA (Yet Another Massive SQL Injection Attack)

Friday, July 18th, 2008

Clever mnemonics aside, last week we have seen another large scale SQL injection attack (or YAMSIA, if you prefer), this time being orchestrated by a botnet that has become known as Asprox—but first, a history lesson. The code behind the Asprox botnet seems to have been around for quite some time ...

Gmail now blocking fake eBay, PayPal e-mails

Wednesday, July 9th, 2008

Google on Tuesday said it is now using an e-mail authentication technology to keep phishers from luring Gmail users to fake eBay and PayPal Web pages in order to steal usernames and passwords.Source:http://news.cnet.com/8301-10784_3-9985605-7.html?hhTest∂=rss&tag=feed&subj=NewsBlog

Microsoft DNS Security Fix Knocks ZoneAlarm Users Offline

Wednesday, July 9th, 2008

The problem began when Microsoft on Tuesday sent patch number KB951748 to Windows users. The patch is designed to plug a security vulnerability that leaves computers vulnerable to so-called DNS attacks.The vulnerability is widespread and affects products made by numerous networking and software vendors beyond Microsoft. It was discovered by ...

Massive DNS security problem endangers the internet

Wednesday, July 9th, 2008

US-CERT and other security experts have warned of a critical design problem affecting all DNS implementations. The Domain Name Service is responsible for converting readable names like www.heise-online.co.uk into the IP addresses that computers can handle, such as 193.99.144.85. DNS is thus the internet equivalent to a phonebook and without ...

Microsoft Unveils New Internet Explorer Security Features

Wednesday, July 2nd, 2008

Internet Explorer's getting a little bit safer. Microsoft Wednesday unveiled significant new security features that will be in the next version of the company's Web browser, Internet Explorer 8, currently in public beta testing. From Microsoft's standpoint, any improvement in security is a plus, and the company seems to be taking ...