It's been known for some time that there are security issues associated with the increasing use of RFID tags in credit cards, but this past weekend afforded a fresh demonstration of just how easy it is for hackers to take advantage of them. . Onstage at the Shmoocon hacker conference in Washington, D.C., Recursion Ventures security researcher Kristin Paget used about $350 in equipment to wirelessly read a volunteer's RFID-enabled credit card and then encode its key data onto a blank card, as described Monday by Forbes. The link for this article located at Network World is no longer available. . Uncover the alarming simplicity with which cybercriminals can manipulate RFID-enabled payment cards using basic tools, as demonstrated at Shmoocon.. RFID Technology, Credit Card Exploits, Wireless Hacking Techniques. . LinuxSecurity.com Team
At the ShmooCon hacker conference, security expert Jon Larimer from IBM's X-Force team demonstrated that Linux is far from immune from attacks via USB storage devices: during his presentation, the expert obtained access to a locked Linux system using a specially crafted USB flash drive, .... taking advantage of a mechanism that allows many desktop distributions to automatically recognise and mount newly connected USB storage devices and display the contents of the device, in this case, in the Nautilus file explorer. The desktop will do this even if the screensaver is already active. When trying to create thumbnails for the files on the device, Nautilus was tricked by a specially crafted DVI file which then activated the exploit. While the relevant hole in the evince thumbnailer was closed in January, the system used in the presentation was kept vulnerable for demonstration purposes. Larimer also disabled the Address Space Layout Randomisation (ASLR) and AppArmor security mechanisms. However, the expert presented measures that would allow potential attackers to bypass these obstacles. The link for this article located at H Security is no longer available. . Discover the methods by which USB worms can target Linux platforms and observe the demonstration at ShmooCon highlighting critical cybersecurity protocols.. Linux Exploits, USB Security, ShmooCon Insights, X-Force Presentation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.