In the space of one hour, my entire digital life was destroyed. First my Google account was taken over, then deleted. Next my Twitter account was compromised, and used as a platform to broadcast racist and homophobic messages. And worst of all, my AppleID account was broken into, and my hackers used it to remotely erase all of the data on my iPhone, iPad, and MacBook.. In many ways, this was all my fault. My accounts were daisy-chained together. Getting into Amazon let my hackers get into my Apple ID account, which helped them get into Gmail, which gave them access to Twitter. Had I used two-factor authentication for my Google account, it The link for this article located at Wired is no longer available. . In many ways, this was all my fault. My accounts were daisy-chained together. Getting into Amazon le. space, entire, digital, destroyed, first, google, account, taken. . LinuxSecurity.com Team
A newly exposed cross-site scripting (XSS) vulnerability in Twitter lets an attacker wrest control of a victim's account merely by sending him or her a tweet. U.K. researcher James Slater reported the serious flaw earlier this week, and now says Twitter's fix in response to his disclosure doesn't actually fix the problem. . "It seems they've made a pretty amateurish attempt to fix the issue, completely missing the massive problem staring them in the face," Slater said in his blog. The attack basically exploits an input validation weakness in a field of the form used for adding third-party Twitter clients, such as TweetDeck and Twitterific. The form doesn't fully vet what can go in that box, Slater said, so an attacker can put JavaScript tags there as well as raw HTML code, for instance. "Whatever I type in that box will appear at the end of my tweets," he blogged in a follow-up post. "Anyone who sees that tweet will then be viewing that code." The link for this article located at Dark Reading is no longer available. . A critical XSS vulnerability on Twitter permits cybercriminals to hijack user accounts through malicious tweets. Learn further about this security issue.. Twitter Exploit,XSS Attack,Account Security Risk. . LinuxSecurity.com Team
A security hole in Google's Gmail service, which reportedly made it easy for hackers to access users' e-mail, has been corrected, Google says. The security breach made it easy for hackers to obtain and exploit users' cookie files. . . .. A major security hole was discovered in Google's Gmail service, according to several news reports that surfaced over the weekend, but the problem reportedly was corrected as of Saturday. "Google was recently alerted to a potential security vulnerability affecting the Gmail service. We have since fixed this vulnerability, and all current and future Gmail users are protected," Google says in a statement. Simple Hack An Israeli hacker named Nir Goldshlagger told an Israeli publication about the flaw. The vulnerability allowed hackers access into Gmail accounts by obtaining the Gmail user's cookie file, which allowed the user to log onto Gmail without retyping his or her password, according to Goldshlagger. Using the cookie, the hacker could then obtain authentication as the Gmail user. . A major security hole was discovered in Google's Gmail service, according to several news reports th. security, google's, gmail, service, which, reportedly, hackers, users. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.