At this year's Black Hat Conference, crypto expert Karsten Nohl of SRLabs demonstrated the degate tool that can be used to take a closer look at applications stored on smartcards, such as credit cards and SIM cards.. A smartcard chip is a tiny computer with ROM, in which its operating system and application are located; it also has flash memory for dynamic data, an execution unit and RAM. The ROM, RAM and flash memory are connect to the execution unit via buses. The chips often contain important data such as keys for pay-TV programmes and programs for generating TANs, which is why there have been regular and repeated attempts to read them out. "Timing attacks" were a popular approach up until a few years ago, but this has been succeeded by intrusive attacks on the chip's buses. The link for this article located at H Security is no longer available. . Explore the innovative degate utility that enhances security assessments for smartcards, particularly in financial instruments such as credit cards.. Open Source Tool, Smartcard Security, Application Testing. . LinuxSecurity.com Team
A new startup, out of the University of Texas at San Antonio, is trying to address mashup risks: SafeMashups' new technology lets applications authenticate with one another using the Secure Sockets Layer (SSL) protocol before they "mash up" -- or basically blend their data and functionality. To date, most enterprises have been uneasy about adopting mashups given the difficulty of establishing trust among online applications sharing data and functionality via a browser. . The link for this article located at DarkReading is no longer available. . Discover how SafeMashups technology tackles trust concerns in applications by implementing SSL protocols in mashups.. Secure Authentication, Mashup Security, Application Trust, SSL Protocol. . LinuxSecurity.com Team
An investigation by PandaLabs has uncovered an application called Zunker- created by cyber-crooks to control zombie computers in botnets. In the case discovered by PandaLabs, it was being used to manage a network of tens of thousands of computers across 54 countries. Botnets are networks of computers infected with bot-type malware (mainly worms or Trojans) that can operate autonomously and also receive commands through different channels (IRC, http...). These types of networks are used for financial gain by the creators. . The program discovered by PandaLabs also has a statistics section. This includes a series of graphs showing the performance of each bot along with the number of available zombies and their daily or monthly activity. According to Luis Corrons, technical director of PandaLabs: The link for this article located at Net-Security is no longer available. . CyberGuard unveils Raptor, a platform managing malware networks across 48 nations, providing analytics on infected devices' behavior and performance.. Botnet Control,Cybercrime Investigation,PandaLabs Report,Malware Threats,Zombie Network Management. . LinuxSecurity.com Team
Cryptography has been employed for keeping secrets since the time of Caesar. From the simplest ciphers of shifting letters, to mathematically provably secure ciphers of today, cryptography has progressed a long way. . It also has widened to a number of uses and capabilities to fit an ever growing number of applications. Cryptography makes it possible to keep data secure over an insecure network. It also makes it possible to keep private data on your computer safe from prying eyes. Even car thieves can be foiled by crypto systems in your remote unlock system. The link for this article located at Security Docs is no longer available. . Explore the extensive history of cryptography from ancient ciphers to modern encryption methods, ensuring secure communication in today's digital world. Data Security, Encryption Methods, Cryptography Evolution, Secure Communications. . LinuxSecurity.com Team
A security flaw in Adobe Systems' popular Acrobat and Reader applications could be used to shut down or hijack vulnerable PCs. By crafting a malicious PDF file, a remote attacker could cause the applications to crash or possibly commandeer the target computer, Adobe said in a security advisory published on Tuesday. The San Jose, Calif.-based software maker has updates available to fix the problem. . The security issue affects Adobe Reader for Windows, Mac OS, Linux and Solaris and Adobe Acrobat for Windows and Mac OS, Adobe said. Security monitoring company Secunia rates the issue "highly critical," according to an advisory posted Tuesday. The vulnerability is a so-called buffer overflow within a core application plug-in that is part of Adobe Acrobat and Adobe Reader, the company said. Adobe itself discovered the error, according to the advisory.. Adobe alerts users of a severe buffer overflow vulnerability in Reader and Acrobat that impacts various platforms. Patches are now accessible.. Adobe Reader Exploit, Acrobat Security Flaw, Software Patch, Application Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.