A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser's password storage, rather than logging a user's keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser's memory. . A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically and without requesting the user's consent. The malware will, for instance, simply comment out Firefox's confirmation request in the nsLoginManagerPrompter.js file and add a line with automatic storage instructions. The H's associates at heise Security were able to reproduce the effect of the manipulations The link for this article located at H Security is no longer available. . A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically an. trojan, recently, analysed, webroot, retrieving, passwords, browse. . LinuxSecurity.com Team
Cyber-Ark revealed the results of their annual survey which illuminates the industry-wide struggle to safely and easily share and manage administrative passwords. The survey shows that the majority of IT professionals mismanage the storage of passwords by keeping them in inaccessible or unsecured locations. . A quarter admit that their IT staff can access the administrative passwords without permission, which is a serious oversight considering it is these very passwords that are the most powerful and critical of all passwords, over-riding all the others and enabling the "administrator" to access the network, systems and the very applications which provide the backbone of enterprises worldwide. The link for this article located at Help Net Security is no longer available. . One in four acknowledge that IT personnel can obtain admin passwords without authorization, revealing significant vulnerabilities in security protocols.. Password Management, IT Security, Safe Password Storage. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.