On Tuesday, hacker Samy Kamkar demonstrated a way to identify a browser's geographical location by exploiting weaknesses in many WiFi routers. Now, he's back with a simple method to penetrate hardware firewalls using little more than some javascript embedded in a webpage.. By luring victims to a malicious link, the attacker can access virtually any service on their machine, even when it's behind certain routers that automatically block it to the outside world. The method has been tested on a Belkin N1 Vision Wireless router, and Kamkar says he suspects other devices are also vulnerable. "What this means is I can penetrate their firewall/router and connect to the port that I specified, even though the firewall should never forward that port," Kamkar told El Reg. "This defeats that security by visiting a simple web page. No authentication, XSS, user input, etc. is required." The link for this article located at The Register is no longer available. . Cybercriminal exploits Python scripts to circumvent software barriers, unveiling applications concealed by proxies through deceptive URLs.. JavaScript Exploit, Hardware Firewall, Network Breach, Router Weaknesses. . Anthony Pell
supposed to be securely stored on ZKey's award-winning information storage portal. All he needed was a little JavaScript. A new security hole, discovered Aug. 14 by a hacker who calls himself "Blue Adept," allows ZKey users on Internet Explorer 5.5 . . . . supposed to be securely stored on ZKey's award-winning information storage portal. All he needed was a little JavaScript. A new security hole, discovered Aug. 14 by a hacker who calls himself "Blue Adept," allows ZKey users on Internet Explorer 5.5 with a ZKey account to easily steal the user names and passwords of other ZKey users simply by sending an email that includes a specific JavaScript code embedded in the body of the message. The link for this article located at Wired is no longer available. . A recent vulnerability found in ZKey demonstrates that user passwords can be swiftly compromised through a malicious JavaScript embedded in emails.. ZKey Security, Data Protection, JavaScript Exploit. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.