Crafted EXE files can inject code in ClamAV

Monday, April 14th, 2008

Security service provider Secunia has discovered a vulnerability in the ClamAV open source virus scanner. Attackers can foist code on the appliction using manipulated EXE files. According a Secunia advisory, a boundary error in the cli_scanpe() function in libclamav/pe.c can cause a heap-based buffer overflow. Manipulated PE executables (Windows .exe files) ...

Bot breaks Hotmail’s CAPTCHA in 6 seconds

Monday, April 14th, 2008

A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday. Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test ...

BT Home Hub Wi-Fi Security Easy to Crack

Monday, April 14th, 2008

A security researcher claims to have found a significant weakness in the wireless encryption of a DSL home gateway made by Thomson and distributed to broadband subscribers in the U.K. by network operator BT. Exploiting the weakness could enable someone to connect to a victim's Wi-Fi router for malicious purposes such ...

Add File types to the Microsoft Outlook Attachment Manager

Monday, April 14th, 2008

Microsoft Outlook categorizes mail attachments into three risk types which are high, medium and low. Outlook uses the default Microsoft configuration to determine if a file poses a high, medium or low risk when the user tries to open the attachment. The file extension .exe for instance poses a high ...

Hackers exploit poor website code

Monday, April 14th, 2008

Many of the loopholes left in the code created for websites have been known about for almost a decade say the security researchers. The poor practices are proving very attractive to hi-tech criminals looking for a ready source of victims. According to Symantec the number of sites vulnerable in this way almost ...