Alerts This Week
Warning Icon 1 825
Alerts This Week
Warning Icon 1 825

Linux Hacks & Cracks - Page 89

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Hacks/Cracks News

Google Personalization RSS Feed XSS Advisory: Security Risk Identified

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Google is vulnerable to cross site scripting. While surfing around the personalization section of Google I ran accross the RSS feed addition tool which is vulnerable to XSS. The employees at Google were aware of XSS as they protected against it as an error condition, however if you input a valid URL (like my RSS feed) it will return with a JavaScript function containing the URL.

Freenode Network Breach: User Passwords Exposed in Security Incident

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

"The world's largest FOSS IRC network, FreeNode, was hijacked (for lack of a better term) by someone who somehow got a hold of the privileges of Robert Levin, AKA lilo, the head honcho of FreeNode and its parent organization, PDPC. To make matters worse, the passwords of many users may have been compromised by someone posing as NickServ, the service that most clients are configured to send a password to upon connecting, while they reconnected to the servers that hadn't been killed.

Abertay University: Launching Ethical Hacking Degree Program

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A Scottish university has become the first in the UK to offer a degree course in what it describes as "ethical hacking". The University of Abertay, based in Dundee, will offer the 3-year course from this September with the aim of turning out "white hat" experts to help companies protect themselves from computer security risks. The course will be thoroughly vetted, with the background of each applicant being studied by The UK Home Office to stop the possibility of criminals signing up.

VoIP Reselling Insights: US DoJ Complaints And Hacker Details

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The two hackers who were reselling VoIP service have been all over the news this week. Details have been scarce, but after looking at VoIPSA, I saw that someone had posted the link to the US DoJ site where the criminal complaints can be found. Both PDFs have interesting details, such as the email addresses and handles used by both individuals. One thing I was interested in finding out, was the name of the company Pena had set up. Apparently, Pena used "Fortes Telecom, Inc." and "Miami Tech & Consulting, Inc." for his operations.

Enhancing U3 Smart USB Drives Security Through Autorun Changes

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

U3 is a platform for developing applications that install to and execute from USB flash drives. It provides these applications a means to execute, read, write and clean up after themselves once the drive is removed. I haven't actually used any U3 apps yet, but having bought a "U3 Smart" drive at OfficeMax (the SanDisk Cruzer Micro 512M), I became interested in the unique way these U3 drives present themselves as two separate disks, so that the U3 software is write-protect and can auto-run on Windows machines. This page documents my attempts at changing the U3 drive to modify the write-protected partition and control the autorun feature.

Examining Youth Career Choices in Technology and Cybercrime

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

I'm not apologizing for hackers who break the law, get caught and get punished. But I do wonder why some obviously smart young men disdain the idea of college, and even quit high school, and apply their skills to computer crime. Teachers and corporate technology managers should connect with these kids before they connect to computers to commit crimes.

Australia Air Traffic Control: ASD-B Hacking Risks Exposed

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Hackers armed with little more than a laptop computer could conjure up phantom planes on the screens of Australia's air traffic controllers using new radar technology, Dick Smith haswarned. The prominent businessman and aviator claims to have found another security flaw in the new software being introduced in the air traffic control system. He has challenged Transport Minister Warren Truss to allow him to set up a demonstration of the problem at a test of the technology in Queensland to show how hackers could exploit the automatic dependent surveillance broadcasting (ASD-B) system to create false readings on an air traffic controller's screen.

Unlocking Restricted Content Using Google Bot Techniques

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

For more and more websites you need to register or pay to have full access. The odd thing is that Google has the complete and full index of the website. So what's going on here? Why must regular users pay or register to have access when the google search engine bot has full access?. The reason is simple; every site wants to use the benefits of the wonderful world of Google, for webmasters free advertising is always welcome. But there is a simple way to be the Google (search)Bot. In this little article i will try to explain it.

UAT Network Security Program: Degree for Aspiring Hackers

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The University of Advancing Technology (UAT) in Phoenix, Ariz., is marketing its new Network Security program as a way to get a degree in hacking. The school is drawing the interest of geeks who use Windows, Linux, and Macintosh, according to UAT's IT manager Raymond Todd Blackwood, and even a few who want to go to the dark side of network security. Hackerdegree.com's Web page looks like a non-Windows desktop with a few terminals open, inviting the curious to learn more about fighting "cybercrime," "cybertheft," and even "cyberterrorism."

Nurse from Greater Manchester Faces Ransomware Attack and Blackmail

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A woman from Greater Manchester has become a victim of an internet scam in which hackers hijack computer files and blackmail owners to get them back. Helen Barrow, a 40-year-old nurse from Rochdale, is believed to be one of the first victims of the con in the UK. Criminals encrypt files with complex passwords, leaving a ransom note telling victims not to contact police.

Key Security Insights From SQL Injection Tutorial Video

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Joel over at appiant.net has posted a great video of how he used SQL injection to bypass security controls on a college website. While his methods may seem 1-2-3 to web application security testers, they are a great example of just how simple this type of attack is, and a reminder that you MUST perform this same type of testing on EVERY web application you deploy, period.

Your message here