After the FBI arrested Cosmo, the alleged leader of the UGNazi hacking group, the hackers attacked CloudFlare via a flaw in Google's two-factor authentication system. The CloudFlare hack allowed UGNazi to change the DNS for 4chan, so visitors to the site were redirected to a UGNazis Twitter account. The attack on the Wounded Warrior Project site was allegedly done for no reason but to spite The Jester. . The link for this article located at Network World is no longer available. . A new wave of cyber resistance features the UGNazi collective, exploiting security gaps to execute strikes on CloudFlare and other selected entities.. UGNazi Hacktivists, CloudFlare Attack, Cybersecurity Breach, 4chan Hijacking, Hacktivism. . LinuxSecurity.com Team
Twitter officially disabled Basic authentication this week, the final step in the company's transition to mandatory OAuth authentication. Sadly, Twitter's extremely poor implementation of the OAuth standard offers a textbook example of how to do it wrong. . This article will explore some of the problems with Twitter's OAuth implementation and some potential pitfalls inherent to the standard. I will also show you how I managed to compromise the secret OAuth key in Twitter's very own official client application for Android. OAuth is an emerging authentication standard that is being adopted by a growing number of social networking services. It defines a key exchange mechanism that allows users to grant a third-party application access to their account without having to provide that application with their credentials. It also allows users to selectively revoke an application's access to their account. Some of the more technical aspects of this article will be easier to understand if you have a basic familiarity with the standard and the problems that it is trying to solve. We published a primer earlier this year that you can refer to if you are looking for additional background information. The article located at arsTechnica is no longer available. . This article will explore some of the problems with Twitter's OAuth implementation and some potentia. twitter, officially, disabled, basic, authentication, final, company's, transiti. . Alex
"... With a bit of ingenuity, anyone can skirt basic password authentication and go straight to the goodies on those sites where administrators are foolish enough to post them. If the desired information is contained in a Web page, anyone . . .. "... With a bit of ingenuity, anyone can skirt basic password authentication and go straight to the goodies on those sites where administrators are foolish enough to post them. If the desired information is contained in a Web page, anyone can find it." The link for this article located at TheRegister is no longer available. . Uncover the methods utilized by cybercriminals to exploit inadequate online security and simplistic login vulnerabilities through search engines, highlighting major threats.. web exploits, site security issues, online authentication flaws. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.