According to a latest EFF research, it . In the past, U.S. Secret Service has admitted that the hidden printer code was a part of a deal with laser printer manufacturers. These secret codes in printers help the government to identify the counterfeited documents. The new revelations have uncovered the private information that was encoded in each document printed on these printers. . In the past, U.S. Secret Service has admitted that the hidden printer code was a part of a deal with. according, latest, research, secret, service, admitted, hidden. . LinuxSecurity.com Team
We all know how annoying fingerprints on touchscreens can be, but now researchers believe they can actually leave your mobile phone susceptible to hacking.. University of Pennsylvania researchers tested the Google Nexus One and HTC G1, both of which use a graphical password system to unlock the phone that works by swiping a set pattern on the touchscreen. Unlocking your phone in this way leaves oily residues on the screen that can remain even if you wipe it. "Latent smudges may be usable to infer recently and frequently touched areas of the screen -- a form of information leakage," warns the article. Using standard cameras and lights, researchers took pictures of the touchscreens and analysed the images with simple photo-editing software available on most home computers. The link for this article located at CNET Crave is no longer available. . Experts caution that fingerprints on iOS displays may uncover passcodes and jeopardize safety.. Android Security, Touchscreen Vulnerabilities, Password Protection. . LinuxSecurity.com Team
Sec Partners has detailed half a dozen ways to hack into VoIP phone systems that use the H.323 and Inter Asterisk eXchange protocols. Himanshu Dwivedi, principal partner at iSec, and Zane Lackey, security analyst there, also released exploit tools to back up their claims about the weaknesses in H.323 and IAX. Does this prove that we need to start thinking about VoIP security more seriously? I know I don't think about it much. Maybe the VoIP software will have to starting using security technologies like encryption or authentication. What do you think will help improve VoIP security? . "There are many ways software can leak information, and often programmers are clueless about how to prevent it," said V.N. Venkatakrishnan, assistant professor of computer science and co-director of University of Illinois at Chicago's Center for Research and Instruction in Technologies for Electronic Security. Internet users might be reassured by web pages telling them their transactions are secure along the network, but Venkatakrishnan The link for this article located at TechWorld is no longer available. . Uncover potential security flaws within Voice over IP (VoIP) infrastructures and assess proposed measures to enhance defense against attacks.. VoIP Security,H.323 Security,IAX Exploits,Secure Communication,VoIP Exploit Mitigation. . LinuxSecurity.com Team
Security researchers at the firm @stake say they've found a flaw in how network device drivers send information that could create an "information leakage vulnerability" that may let hackers collect sensitive information sent from vulnerable devices. If successful, @stake says, hackers . . . . Security researchers at the firm @stake say they've found a flaw in how network device drivers send information that could create an "information leakage vulnerability" that may let hackers collect sensitive information sent from vulnerable devices. If successful, @stake says, hackers potentially could view "slices of previously transmitted packets or portions of kernel memory" over certain networks. The CERT Coordination Center has posted a long list (http://www.kb.cert.org/vuls/id/412115) of network vendors' products that could be vulnerable to the flaw. However, as of now, the majority of vendors haven't disclosed whether their device drivers are at risk. So far, Cisco Systems, F5 Networks, Hitachi, Microsoft, and NEC have reported that they're not vulnerable. According to @stake's advisory, the software and hardware vendors were notified of the potential flaw in June 2002. According to CERT, no statement concerning this vulnerability is yet available from more than 40 of the vendors notified more than six months ago. The link for this article located at CommWeb is no longer available. . Investigators have uncovered a vulnerability in network interface software that could expose confidential data, increasing the threat of unauthorized access to private details.. Information Leakage, Network Vulnerability, Device Driver Flaws, Data Exposure, Cybersecurity Advisory. . Anthony Pell
Security researchers have discovered a serious vulnerability that may be present in many Ethernet device drivers that is causing the devices to broadcast sensitive information over networks. . .. Security researchers have discovered a serious vulnerability that may be present in many Ethernet device drivers that is causing the devices to broadcast sensitive information over networks . According to the IEEE's Ethernet standard, packets transmitted on an Ethernet network should be a minimum of 46 bytes. If, as sometimes happens with protocols such as IP, a higher layer protocol requires less than 46 bytes, the Ethernet frames are supposed to be padded with null data. However, researchers at @stake Inc., in Cambridge, Mass., have discovered that many drivers instead pad packets with data from previously transmitted Ethernet frames. This results in the device sending out sensitive information to other machines on the same Ethernet network. The type of data sent depends upon the device driver implementation, but it can range from data housed in the dynamic kernel memory, to static system memory allocated to the driver, to a hardware buffer located on the network interface card. The link for this article located at eWeek is no longer available. . Security researchers have discovered a serious vulnerability that may be present in many Ethernet de. security, researchers, serious, vulnerability, present, ethernet. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.