Firefox 3.0.9 Released

Tuesday, April 21st, 2009

Firefox 3.0.9 fixes several security issues found in Firefox 3.0.8: Firefox allows Refresh header to redirect to javascript: URIs POST data sent to wrong site when saving web page with embedded frame Malicious search plugins can inject code into arbitrary sites Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString XSS hazard using third-party stylesheets and XBL bindings Same-origin violations ...

SSH server attacks resurface

Saturday, April 18th, 2009

Security researchers are warning administrators to secure their servers in the wake of new Secure Shell (SSH) attacks. Researchers at security firm SANS warned that so-called 'brute force' attacks were occurring on a "daily" basis. The attacks attempt to guess usernames and passwords in an attempt to compromise the server. To help ...

Stealthy Rootkit Slides Further Under the Radar

Wednesday, April 15th, 2009

Thousands of Web sites have been rigged to deliver a powerful piece of malicious software that many security products may be unprepared to handle. The malicious software is a new variant of Mebroot, a program known as a "rootkit" for the stealthy way it hides deep in the Windows operating system, ...

New Attack Sneaks Rootkits Into Linux Kernel

Wednesday, April 15th, 2009

Kernel rootkits are tough enough to detect, but now a researcher has demonstrated an even sneakier method of hacking Linux. The attack attack exploits an oft-forgotten function in Linux versions 2.4 and above in order to quietly insert a rootkit into the operating system kernel as a way to hide malware ...

PIN Crackers Nab Holy Grail of Bank Card Security

Wednesday, April 15th, 2009

Hackers have crossed into new frontiers by devising sophisticated ways to steal large amounts of personal identification numbers, or PINs, protecting credit and debit cards, says an investigator. The attacks involve both unencrypted PINs and encrypted PINs that attackers have found a way to crack, according to the investigator ...