Contact Me By Email

Showing posts with label E-mail address. Show all posts
Showing posts with label E-mail address. Show all posts

Friday, September 24, 2010

Safari vulnerable to AutoFill security bug (again) | Browsers & Add-Ons | MacUser | Macworld

Safari vulnerable to AutoFill security bug (again) | Browsers & Add-Ons | MacUser | Macworld
You might remember that Apple’s Safari browser got hit by a nasty security bug involving its text AutoFill feature in late July. Apple squashed this bug with the Safari 5.0.1 update, but according to the researcher who discovered the AutoFill flaw in the first place, the bug is back.
According to Jeremiah Grossman, the founder of WhiteHat Security, this flaw is a slight variation on the original AutoFill flaw that allowed malicious Websites to harvest your personal information—such as your name, address, workplace, and e-mail address—without you knowing, even if you’ve never visited the site before.
The new version of this hack is less “automatic” than the initial one, according to Grossman, but a hacker just needs to perform a little social engineering to get a hapless Web user to give up their personal details.
As before, Grossman suggests that, if you use Safari, you should disable form auto-fill to avoid getting taken by this bug. To do so, select Preferences under the Safari menu, and click AutoFill in the toolbar; uncheck all three boxes.

Monday, September 13, 2010

Anti-US Hacker Takes Credit for 'Here You Have' Worm - PCWorld

Anti-US Hacker Takes Credit for 'Here You Have' Worm - PCWorld
A hacker who claims he was behind a fast-spreading e-mail worm that crippled corporate networks last week said that the worm was designed, in part, as a propaganda tool.
The hacker, known as Iraq Resistance, responded to inquiries sent to an e-mail address associated with the "Here you have" worm, which during a brief period early Thursday accounted for about 10 percent of the spam on the Internet. He (or she) revealed no details about his identity, but said, "The creation of this is just a tool to reach my voice to people maybe... or maybe other things."
He said he had not expected the worm to spread as broadly as it had, and noted that he could have done much more damage to victims. "I could smash all those infected but I wouldn't," said the hacker. "I hope all people understand that I am not negative person!" In other parts of the message, he was critical of the U.S. war in Iraq.
On Sunday, Iraq Resistance posted a video echoing these sentiments and complaining, through a computer-generated voice, that his actions were not as bad as those of Terry Jones. Jones is the pastor at a small Florida church who received worldwide attention this week for threatening to burn copies of the Koran.
Security experts agree that the worm could have caused more damage. However, it did include some very malicious components, such as password logging software and a backdoor program that could have been used to allow its creator to control infected machines. But because the software was not terribly sophisticated, it was quickly shut down as Web servers that it used to infect machines and issue new commands were taken offline last week.
__________________________________
This is a fortaste of our future. This is scary.
John H. Armwood