Trend Micro session token insufficiently random

Monday, August 25th, 2008

Secunia, the security services provider, has issued a security advisory about a vulnerability in Trend Micro's OfficeScan 8.0 and Worry-Free Business Security 5.0 that makes it easier for attackers to take control of the web management of those products. According to Secunia, the web-based configuration interface uses a pseudo-random token ...

How to Use Honeypots to Improve Your Network Security

Monday, August 25th, 2008

Traditionally, the area of information security has been purely defensive. Classic examples of the defensive mechanisms used in order to protect communication networks include firewalls, encryption and IDS (Intrusion Detection Systems). The strategy follows the classical security paradigm of "Protect, Detect and React.” In other words, try to protect the ...

New attack against multiple encryption functions

Saturday, August 23rd, 2008

Unless you're a dyed in the wool cryptographic geek you probably didn't know that there was a Crypto conference, or even a chain of worldwide crypto conferences that take place each year. Fortunately, for the most of us that aren't crypto geeks there are a handful of very highly skilled ...

Cool new snoop tool for HR people

Friday, August 22nd, 2008

Dutch Valleywag reader Dirk Dijksma has come up with a clever twist on the old metasearch engine: He's collected all the sites that HR people use to suss out job applicants, and put them into one page called CVGadget with expanding/collapsing widgets that only show the top few of each ...

Bogus FedEx Notifications: New Malware Courier of Choice

Friday, August 22nd, 2008

Remember the UPS spam runs that were popular last month (see previous blog posts here and here)? Spammers have chosen a different courier this time, but the message was basically the same.Posing as FedEx notifications, these email messages have the same format as their earlier UPS counterparts: tracking number (perhaps ...