A “hacker” broke into a Homeland Security Department telephone system over the weekend and racked up about $12,000 in calls to the Middle East and Asia

WASHINGTON - A hacker broke into a Homeland Security Department telephone system over the weekend and racked up about $12,000 in calls to the Middle East and Asia.
The hacker made more than 400 calls on a Federal Emergency Management Agency voicemail system in Emmitsburg, Md., on Saturday and Sunday, according to FEMA spokesman Tom Olshanski.
FEMA [...]

DEFCON 16 – The Tools

DEFCON, the 9000+ attendee hacker conference in Vegas has become a sort of hydra conference. It has become more like a global fair than what most people think of conferences; even the badge is highly unique. I say this because there are so many things to do at DEFCON, other than going to talks, that [...]

Attacks Continue on Retail Stores and Restaurants

Criminals exploit wireless vulnerabilities, social engineering to collect large volumes of customer data.

Mozilla Releases Firefox 3.0.1

Mozilla has released Firefox 3.0.1 to address three vulnerabilities. Exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. One of these vulnerabilities may also affect Thunderbird and SeaMonkey. Two of these vulnerabilities were previously fixed in Firefox 2.0.0.16 as well; please see the US-CERT Current Activity [...]

Denial-of-coffee attacks affect networked coffee maker

Now this is just funny… If you own a Jura F90 Coffee Maker, you can also buy a Jura Internet Connection Kit, which lets you program and set your coffee prefs via the network: however, its got a bunch of vulnerabilities that allow for remote denial-of-coffee attacks:
Guess what - it can not be patched as [...]

Scan for SQL/XSS Injection Vulnerabilities Using “Exploit-Me” Firefox Add-on Suite

So you have been coding a new CMS for your site… making every effort to make sure any/all user inputted data is escaped properly, but you still would like to remain paranoid and scan for vulnerabilities. We don’t blame you. sqlmap has been around for awhile, but now there are other choices.
Take a look at [...]

Macbook Air Hacked in 2 mintues

San Francisco - It may be the quickest $10,000 Charlie Miller ever earned.
He took the first of three laptop computers — and a $10,000 cash prize — Thursday after breaking into a MacBook Air at the CanSecWest security conference’s PWN 2 OWN hacking contest.
Show organizers offered a Sony Vaio, Fujitsu U810, and the MacBook as [...]

VLC Player Vulnerable to Remote Hijack

VLC is a popular media player among BitTorrent users. Not just for the fact that it is free, also because it includes a huge number of the video codecs, so it can play virtually every video file available.Unfortunately, the latest versions of VLC have a security flaw according to a report from Luigi Auriemma. The [...]

Local root exploit in kernels 2.6.17 to 2.6.24.1

There is a new local root exploit found in linux kernels 2.6.17 to 2.6.24.1. Here’s a proof-of-concept, which basically works as a “passwordless su”.
I have tested the exploit on a few systems I manage, and it just plain works on a number of them. The distros I have around that are vulnerable are:

Fedora 8
CentOS [...]

ICANN Moves To Disable Domain Tasting

“Following Google’s crackdown on ‘domain tasters’, ICANN has voted unanimously to eliminate the free period that many domain buyers have been taking advantage of. At the same meeting they also discussed Network Solutions’ front running but took no action on it.”
Source
ICANN’s Release

500,000 private Myspace pictures leaked and available for download

Sorry for the typical and tredy “myspace pic” above. This is an article from Wired Magazine. It might be the largest “security breach” in awhile but what on earth would anyone do with 17gb of random Myspace teenagers?
A 17-gigabyte file purporting to contain more than half a million images lifted from private MySpace profiles has [...]

The Meanest Thing Gizmodo Did at CES

Long story shorts now banned from attending CES. They walked around and turned off people’s tvs during presentations. Sucks to be a gadget blog banned from CES.
Click the link below to view the video Gizmodo made of their mischief.
CES has no shortage of displays. And when MAKE offered us some TV-B-Gone clickers to bring [...]

Attackers target unpatched QuickTime flaw that affects Windows & Macs

The vulnerability, called the Apple QuickTime RTSP Response Header Stack-Based Buffer Overflow Vulnerability, was first disclosed on Nov. 23rd and still remains unpatched. The vulnerability can be exploited through Internet Explorer, Firefox, Opera, and Safari and effects both Windows and Mac users.
First observed on Saturday, the attacks appear to be aimed at Windows users, but [...]

© 2008 twinturbo.org. All Rights Reserved.
24 queries. 1.607 seconds. | ¯\(°_o)/¯
Word to our gui, os, http server, database, and scripting language. lamp-for-life.