on :
Monday, 12 Dec, 2011
Yahoo! adds 2-step verification for account security
Yahoo! have now joined Google in adding 2-step verification for account security although it is only ‘beta’ right now. This means, after you login to your account with your password, you will have to verify the code sent to your mobile device or will have to answer a security question. It’s about time too. I personally believe the 2-step verification should be set as default for any cloud-based account. Yahoo! users will have to enable the second sign-in verification feature from their Yahoo! account information page. You will be asked to enter
on :
Thursday, 8 Dec, 2011
Fake Verizon email with malicious ZIP in circulation
Microsoft is warning users about a fake Verizon notification which is carrying a Trojan. The email appears to come from Verizon and attempts to make the customer feel a sense of urgency by claiming it contains crucial account information from verizon Wireless. The fake email has a ZIP file attached named 'Verizon-Wireless-Account-StatusNotification_#######.zip' (random numbers are used in the name). This same malware attack vector is being used in fake critical updates for Adobe Acrobat Reader and Adobe X
on :
Thursday, 8 Dec, 2011
Google Code Playground XSS vulnerability
Two security researchers have identified an XSS in Google Code. Proof Of Concept: Just go to http://code.google.com/apis/ajax/playground/ and then click on edit HTML after that remove all the codes and type this script : "<img src="<img src=search"/onerror=alert("XSS")//">"
on :
Thursday, 8 Dec, 2011
Brazilian banking Trojan disguised as Microsoft anti-virus software
A Trojan (identified as Trojan-Downloader.Win32.VB.aoff) is targeting Windows-based systems by removing built-in AV software and clearing a path for cybercriminals to silently steal online banking credentials. The Trojan affects 'ntldr' the default boot loader in Windows.The Trojan
on :
Thursday, 8 Dec, 2011
Facebook fixes photo privacy security flaw
Facebook has this week (w/c 5th Dec) patched a vulnerability that allowed any user to view any other user’s private photos. Mark Zuckerberg’s Facebook account was compromised and a total of thirteen photos were downloaded and posted
on :
Wednesday, 7 Dec, 2011
Hakin9 Mobile 1/11 (1)
Android Insecurities by Joey Peloquin The article will begin with a focus on what the author calls Offensive Mobile Forensics, an analysis technique that mimics the approach an attacker would take in the event they acquired a lost or stolen
on :
Wednesday, 7 Dec, 2011
Ready to Break Some Code? Raytheon Recruiting!
Ready to break some code? Visit our enhanced gaming site, and take the new cyber warrior challenge! View our website HERE At Raytheon, our cyber warriors play offense and defense. They know how the adversary thinks and can adopt
on :
Tuesday, 6 Dec, 2011
Carrier IQ tracking mobile behaviour – spyware?
Carrier IQ isn't spyware as such. It does indeed collect and map geo-location and device (T-Mobile and other carriers in the US have confirmed the app is resident on some of their devices) specific data which includes
on :
Tuesday, 6 Dec, 2011
On-line Hakin9Lab Trainings Enquiry
Dear friends! We are entering with new initiative devoted to on-line trainigs. This innovative project is based on case studies and laboratories. We would like to ask you to answer a few questions related to trainings topic. Thank you in
on :
Monday, 5 Dec, 2011
Get 20 % discount NOW!
Huge discounts on security books from Feisty Duck! Feisty Duck is providing all readers of Hakin9 with a special discount for additional 20% off our current prices. Use
on :
Monday, 5 Dec, 2011
Reverse proxy flaw in Apache patch CVE-2011-3368
A security researcher has found that an old patch CVE-2011-3368 can still be exploited by a crafted request that could exploit a fully pateched Apache Web Server (even if Apache 2.2.21 with CVE-2011-3368 patch is applied) which
on :
Monday, 5 Dec, 2011
















