PINs stolen from Citibank ATMs

Tuesday, July 1st, 2008

We all worry about keeping our online passwords safe from prying eyes. But now our faith in ATM PIN codes is being shaken. Three people face charges in federal court in New York for allegedly breaking into Citibank's ATM network inside 7-Eleven stores and stealing PIN codes, according to court filings ...

Searchable SWFs

Tuesday, July 1st, 2008

I got forwarded this link today from businesswire about how Google and Yahoo are now going to be armed with the information necessary to look at and extract information out of SWF files. Ho-boy, here we go. The link was sent to me with the “bad juju” caveat, and I’m ...

Kaspersky adds anti-keylogger keyboard

Tuesday, July 1st, 2008

The new version of Kaspersky's security suite, Internet Security 2009, features a novel but simple defense against keylogging malware -- a virtual keyboard. Full details have yet to be confirmed, but it is understood that the program will let users bring up the keyboard from which to enter login details for ...

Xpath Injection

Tuesday, July 1st, 2008

Yesterday I wrote a quick proposal for the Synapse project. Since not everyone has access to the Synapse project, I will share some ideas here from time to time. I started with a proposal on how to detect Xpath vulnerabilities. Since Xpath can be used in combination with every server-side ...

DNS blacklist for weak SSL keys

Tuesday, July 1st, 2008

Working closely with the German hosting company – manitu, heise is making available with immediate effect a realtime DNS-based blacklist service for identifying weak SSL keys. The provider already runs the Realtime Blacklist for the iX spam filter NiX Spam, which enables mail servers to identify and filter spam.The principle ...