Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Purdue University security researchers recently discovered a vulnerability affecting IoT devices running Bluetooth which could lead to spoofing attacks. The vulnerability has a broad impact on mainstream platforms that support BLE communications, including Linux, Android and iOS. . Bluetooth Low Energy (BLE) is the most widely utilized low-energy communication protocol for mobile and IoT devices. Sales of Bluetooth Low Energy (BLE) devices are forecasted to triple by 2023 to 1.6 billion annual shipments, according to market advisory firm ABI. BLE devices rely on pairing, a critical procedure, to build trust between two devices when they connect for the first time. Once paired, the reconnections between BLE devices are often transparent to the user. The vulnerability lies in the reconnection procedures for previously paired BLE devices. And reconnections happen frequently in typical usage scenarios, said Jianliang Wu, a PhD student from the PurSec Lab at Purdue University and one of the lead researchers on the project. . Unveil the vulnerability within Bluetooth Low Energy that permits malicious spoofing across IoT gadgets and the potential ramifications.. Bluetooth Spoofing, IoT Security, BLE Vulnerability. . Brittany Day
A serious flaw in how Firefox handles log-ons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday. Aviv Raff, an Israeli researcher best known for ferreting out browser flaws, revealed the Firefox spoofing vulnerability on his personal blog, and posted a demonstration video there. He did not go public with any proof-of-concept code or working exploit, however. Have you heard about the latest FireFox vulnerability? When do you think the developers will release a patch fixing the bug?. The link for this article located at PC World is no longer available. . A critical vulnerability in Firefox has emerged, potentially enabling cybercriminals to trick individuals into disclosing their login credentials. Investigate the implications.. Firefox spoofing threat, identity theft risk, browser flaw discovery. . Bill Locke
A new flaw in how some developers implement RSA cryptography has left OpenSSL and other applications vulnerable to attackers forging digital signatures and spoofing Websites as well as SSL clients. . OpenSSL, one of the most popular open cryptography toolkits, was the first to report the flaw in its RSA cryptography implementation, along with Fedora, which uses OpenSSL in Fedora Core 5 Linux, but security researchers say there will likely be more disclosures soon from other open source as well as commercial software vendors. The flaw was originally discovered by Bell Labs researcher Daniel Bleichenbacher. "It's particularly worrisome to think that some hardware-accelerated appliances may be hardwired into being vulnerable to the attack" as well, says Thomas Ptacek, a researcher with Matasano Security. The link for this article located at DarkReading is no longer available. . OpenSSL has disclosed a significant vulnerability in its RSA encryption method, presenting risks of impersonation attacks on numerous software platforms.. OpenSSL, RSA Flaw, Spoofing Security, Cryptography Issues. . LinuxSecurity.com Team
Sweaty hands might make you unpopular as a dance partner but they could someday prevent hackers from getting into your bank account. Researchers at Clarkson University have found that fingerprint readers can be spoofed by fingerprint images lifted with Play-Doh or gelatine or a model of a finger moulded out of dental plaster. The group even assembled a collection of fingers cut from the hands of cadavers. . In a systematic test of more than 60 of the carefully crafted samples, the researchers found that 90 per cent of the fakes could be passed off as the real thing. The link for this article located at Silicon.com is no longer available. . In a systematic test of more than 60 of the carefully crafted samples, the researchers found that 90. sweaty, hands, might, unpopular, dance, partner, someday, prevent, hackers. . LinuxSecurity.com Team
Microsoft has denied that a spoofing technique available on its Internet Explorer browser is a security vulnerability. The software giant accepted the possibility that spoofing could occur on version six of IE, but rejected claims that this was a security flaw.< . . .. Microsoft has denied that a spoofing technique available on its Internet Explorer browser is a security vulnerability. The software giant accepted the possibility that spoofing could occur on version six of IE, but rejected claims that this was a security flaw. In a prepared email statement from the company, a spokesperson said: "Microsoft is aware of a security issue reported last week that could allow spoofing the URL a user sees in Internet Explorer's status bar. Users could see a URL in the status bar when the mouse hovers over the link on a webpage, but clicking the link would take the user to a different URL. Our investigation has indicated that this is not a security vulnerability." Last week, a researcher in Germany, Benjamin Tobias Franz, posted warnings on bulletin board Web site Bugtraq, stating that Internet Explorer could spoof links if users put two URLs and a table inside an HTML href tag. The result, Franz claimed, was that malformed links to URLs, could take users to an entirely different Web site without their knowledge. The link for this article located at zdnet.co.uk is no longer available. . Apple refutes claims that a vulnerability in Safari poses a risk, outlining its position regarding the matter.. Internet Explorer Spoofing, Microsoft Response, URL Spoofing Techniques. . LinuxSecurity.com Team
What is ANI / Caller ID spoofing? ANI / Caller ID spoofing is setting the ANI / Caller ID on the outgoing call you are making to a 10 digit number of your own choosing. Traditionally it has been a complicated process either requiring the assistance of a cooperative phone company operator or an expensive company PBX system. . . .. What is Caller ID? Caller ID is a service provided by most telephone companies (for a monthly cost) which will tell you the number / name of an incoming call. [Definition: Hack FAQ ] What is ANI? Automatic Number Identification is a system used by the telephone company to determine the number of the calling party. There are believed to be two types, "FLEX ANI" (used for e.g. verification services such as voicemail) which is relatively easy to spoof, and "Real Time ANI" (used only for billing purposes on e.g. 800 numbers) which is harder to spoof. [Definition: Hack FAQ ] What is ANI / Caller ID spoofing? ANI / Caller ID spoofing is setting the ANI / Caller ID on the outgoing call you are making to a 10 digit number of your own choosing. Traditionally it has been a complicated process either requiring the assistance of a cooperative phone company operator or an expensive company PBX system. What is Automated ANI / Caller ID spoofing? Automated ANI / Caller ID spoofing is setting the number you are calling from without the use of an operator / company PBX system. By far the easiest method thanks to the increasing take-up of internet telephony services are VoIP (Voice over Internet Protocol) service providers who allow you when using their service to set whatever caller ID you like (which is also used as ANI). The link for this article located at rootsecure.net is no longer available. . Explore the complexities of Automatic Number Identification (ANI) and Caller ID spoofing, revealing key secure calling practices used in Voice over Internet Protocol (VoIP) systems. Telephony Spoofing, ANI Spoofing, VoIP Security. . LinuxSecurity.com Team
The Pentagon said today that an attempt to send a virus through its systems last week was thwarted before damage could be caused. On the morning of Feb. 14, someone "spoofed" the Defense Technology Information Center (DTIC) header, camouflaging the . . . . The Pentagon said today that an attempt to send a virus through its systems last week was thwarted before damage could be caused. On the morning of Feb. 14, someone "spoofed" the Defense Technology Information Center (DTIC) header, camouflaging the sender's real address to make recipients think the message had come from the Defense Department. The message had a virus attached and was sent through Pentagon computers to two mailing lists. "Our computers caught the virus and stripped it out," said Terry Davis, manager of the Public Web Program in the Office of the Secretary of Defense. "So what went out was the original text message that was sent in the e-mail, but the virus and the attachment were both stripped." The link for this article located at FCW is no longer available. . The Pentagon said today that an attempt to send a virus through its systems last week was thwarted b. pentagon, today, attempt, virus, through, systems, thwarted. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.