This POODLE bites: exploiting the SSL 3.0 fallback

Tuesday, October 14th, 2014

Today we are publishing details of a vulnerability in the design of SSL version 3.0. This vulnerability allows the plaintext of secure connections to be calculated by a network attacker. I discovered this issue in collaboration with Thai Duong and Krzysztof Kotowicz (also Googlers). SSL 3.0 is nearly 15 years old, ...

Dropbox has been hacked, change your password immediately

Monday, October 13th, 2014

If you use Dropbox, you need to change your password immediately as it looks like there has been a breach in the security. In a posting on Pastebin, which will not link to as it contains account data, the user claims to have nearly 7 million account user names and ...

The malware of the future may come bearing real gifts

Sunday, October 12th, 2014

“What,” asked the speaker. “if Notepad behaved just like you would expect it to, but only for the first hour or so that you used it? What if it began to do different things after that?” According to Giovanni Vigna, a professor at the University of California, Santa Barbara, and the ...

Test Your Anti-Malware Solution

Sunday, October 12th, 2014

The wicar.org website was designed to test the correct operation your anti-virus / anti-malware software. The following table contains static HTML pages with known malicious content, based on the Metasploit Framework. The exploits contain a non-malicious payload which under Windows will execute 'calc.exe', the in-built calculator (if your browser is ...

Malware Based Credit Card Breach at Kmart

Friday, October 10th, 2014

Sears Holding Co. late Friday said it recently discovered that point-of-sale registers at its Kmart stores were compromised by malicious software that stole customer credit and debit card information. The company says it has removed the malware from store registers and contained the breach, but that the investigation is ongoing. “Yesterday ...