New DOS Attack Is a Killer

Friday, October 3rd, 2008

Things are a-brewin’ in Sweden. Sweden is not just home of the infamous bikini team, it is also the home of Outpost 24, an equally sexy software-as-a-service network scanning service, and the employer of my friend Robert E. Lee and his colleague Jack C. Louis. These guys are the inventors ...

Researchers uncover major IP flaw

Wednesday, October 1st, 2008

Researchers at Finnish security firm Outpost 24 claim to have discovered a flaw in the Internet Protocol that can disrupt any computer or server. After keeping the flaw quiet for years, the researchers hope that going public will help accelerate the creation of a solution. The flaw allows attackers to cripple computers ...

All Major Browsers Vulnerable To Clickjacking

Monday, September 29th, 2008

Security research sites are buzzing about a new attack description called "clickjacking." The descriptions are still pretty vague, but they are scary enough that US Cert has weighed in and browser vendors are reported to have patches in the works. The basic description of the attack is that it allows the ...

Web Gives Hackers More Territory, Tools

Sunday, September 28th, 2008

As more people become accustomed to Web surfing and downloading software and multimedia, legitimate Web sites have become the favorite targets of hackers. "The hacking of legitimate Web sites is the biggest threat today," said David Freer, Symantec's vice president for consumer business in Asia-Pacific and Japan. Freer revealed that based on ...

CSRF vulnerability allows Twitter ‘follow’ abuse

Thursday, September 11th, 2008

Last week, TechCrunch’s Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called “johng77536″ to game the popular micro-blogging service to add thousands of followers (subscribers) in a short period of time. The “johng77536″ account has since been disabled but a security researcher tracking Twitter security flaws and ...