RSS Feed     Twitter     Facebook

Posts Tagged ‘researchers’

Windows Security Software Bypassed with New Technique, Researchers Find

Researchers with Matousec.com, a project of Different Internet Experience, found a way to circumvent some of the most popular security software for Windows desktops, including products from Symantec, McAfee, Sophos and others.
– Security researchers have developed an attack technique they say can circumvent dozens of anti-virus products used to protect Windows desktops, including McAfee, Sophos and Symantecs Norton anti-virus.
Researchers at Matousec.com call the technique an “argument-switch” attack.
Many security vendor…


Researchers to Demonstrate Database Man-in-the-Middle Attacks at Black Hat

Two researchers from Trustwave will demonstrate how to use man-in-the-middle attacks against Oracle databases to steal user credentials and take over sessions at Black Hat Europe next week.
– Two researchers from Trustwave will demonstrate how a
man-in-the-middle attack on Oracle databases can be leveraged to swipe
user credentials and hijack sessions at the upcoming Black Hat Europe security conference.
Armed with a new proof-of-concept tool, Trustwave Director of
Security Research …


Facebook Soaring in Search, Popularity, Researchers Say

Facebook saw search queries grow 10 percent in February 2010 and surpassed Google in the U.S. to become the most visited Website for the week ending March 13. Facebook.com reached the No. 1 ranking on Christmas Eve, Christmas Day and New Year’s Day as well as the weekend of March 6th and 7th, said HitWise. Meanwhile, comScore said search queries on Facebook grew from 395 million in January 2010 to 436 million in February 2010, a growth of 10 percent. Facebook is becoming a fine referrer to other Web services, which could end up helping Microsoft Bing.
– Facebook saw search queries grow 10 percent in February 2010 and surpassed
Google in the United States
to become the most visited Website for the week ending March 13, according to
studies from leading market researchers.
Facebook.com recently reached the No. 1 ranking on Christmas Eve, Christm…


Researchers Present Web Application Attack Targeting Database Connection

At Black Hat DC, security researchers present a way to hack the connection between Web applications and the database, a method they call connection string parameter pollution.
– Two security researchers unveiled a new attack at Black Hat DC that
targets the connection between Web applications and databases.
Independent researcher Jose Palazon and Chema Alonso of security vendor
Informatica64 presented their finding, which they called a CSPP (connection string
paramete…


Microsoft, NSF Offering Free Cloud Computing to Researchers

Microsoft and the National Science Foundation (NSF) announced a collaboration to provide NSF-supported researchers with free access to the Windows Azure cloud platform and its development tools for three years. The evident hope is that those researchers will leverage the cloud-computing capabilities of the platform to analyze massive amounts of data inherent in large projects. Microsoft made the Windows Azure platform generally available on Feb. 1 in 21 countries, requiring users to pay for the service.
– An agreement between Microsoft and the National Science
Foundation will see the software giant providing NSF-supported researchers with
access to the Windows Azure cloud platform and its various development tools.
According to a press release issued by the NSF, following a joint press
conference…


Researchers Uncover Security Vulnerabilities in Femtocell Technology

Two Trustwave security consultants report they have uncovered hardware and software vulnerabilities in femtocell devices that can be used to take over the device. The duo will present their findings at the ShmooCon conference in Washington.
– Researchers with Trustwave have discovered flaws in the hardware and
software of femtocell devices that can allow an attacker to take full control
of the miniature cell towers without the user’s knowledge.
Zack Fasel and Matthew Jakubowski, security consultants with Trustwave’s
SpiderLabs, will…


China Domain Name Registration Changes Could Reduce Malicious Sites, Researchers Say

China has changed its domain name registration process as part of what its government says is a crackdown on Internet porn. Security researchers believe the changes could help limit the number of malicious sites using the .cn top-level domain.
– When McAfee published its list of the most dangerous Web domains,

Chinas .cn domain was among the lists familiar faces.

However, some security researchers say that may change as a side effect of China tightening its control over the Internet. Chinese authorities recently changed their…


Australian koalas face possible extinction, researchers say

Australia’s koalas have suffered a sharp population decline because of development, bushfires and global warming, and could vanish within decades, researchers said on Tuesday. Mainland Australia’s wild koala population was between 43,000 and 80,000, well under previous estimates of

IBM Researchers Simplify Mobile Web Browsing

IBM has announced that a team of IBM researchers has created technology that makes it simpler for Webmasters to make their Web sites more readable on mobile devices.
– IBM has announced that a team of IBM researchers has created technology that makes it simpler for Webmasters to make their Web sites more readable on mobile devices.
The technology initially developed as an accessibility feature aimed at visually-impaired users, helps to reduce the burdensome scrol…


Researchers Expose Sophisticated Banking Trojan Linked to Thefts

Security researchers at Finjan track a cyber-gang that pilfered German bank accounts in summer 2009. The gang uses a Trojan dubbed URLZone that represents the next generation of banking malware.
– Researchers at Finjan are shining a light on a sneaky banking Trojan
behind the theft of roughly $439,000 (300,000 euros) from German bank accounts
over a 22-day period.
Dubbed URLZone, the Trojan served as a digital lock pick for a sophisticated
cyber-gang Finjan tracked from Aug. 11 to Sept. 1…


Security Researchers Find Alleged Facebook Hacking Service

PandaLabs discovers a service offering to hack any Facebook account for $100. But security researchers say the site is likely a scam.
– PandaLabs has uncovered an
online
service offering to hack Facebook accounts for a fee. But would-be
customers may find out the joke is on them.
According to PandaLabs,
the service which was discovered this week offers to break
into Facebook accounts in exchange for $100. But researchers at Pa…


Apple iPhone OS 3.1 Phishing Protection Falling Short, Researchers Say

Security pros say the Apple iPhone OS 3.1′s anti-phishing feature falls short, failing to block sites blocked by the desktop version of the Safari browser.
– The anti-phishing feature for the iPhone OS 3.1 isn’t all it’s cracked
up to be, according to security researchers.
For whatever reason, some researchers have found, phishing sites blocked by
the desktop version of Apple Safari are not consistently blocked by
the mobile version. Since Apple r…


Researchers Boot Million Linux Kernels to Help Botnet Research

Scientists at Sandia National Laboratories have demonstrated the ability to run more than 1 million Linux kernels as virtual machines, an effort they say will ultimately help researchers analyzing massive botnets.
– Scientists at Sandia National Laboratories are harnessing more than a
million Linux kernels as virtual machines as part of an effort to aid researchers
to better analyze botnet behavior.
According to Sandia, which serves as an R amp;D arm for the Department of
Energy, the project will allow s…



Researchers to Unveil Browser-Based Darknet at Black Hat

HP security researchers are presenting Veiled, a darknet or private file-sharing and communications network, at Black Hat. Veiled can be accessed by any device with a browser, from a PC to an iPhone.
– Two researchers from Hewlett-Packard have developed a browser-based darknet
that allows users to share files and communicate anonymously.
Traditionally, darknets are defined as closed, private networks used for
secure communications and file sharing. Popular examples of darknets include
Freenet…


Security Researchers Exploit Vulnerability in Handling of EV SSL Certificates

Two researchers will demonstrate a man-in-the-middle attack at the Black Hat security conference this month that allows them to silently sniff traffic on EV SSL protected Websites. The vulnerability in the way browsers treat EV SSL certificates makes them no more valuable than the cheapest SSL certificate, the researchers say.
– Two researchers have discovered a design flaw in Web browsers that can
be exploited to launch man-in-the-middle attacks on extended
validation
SSLcertificates.
Mike Zusman, principal consultant at Intrepidus Group, and independent
security researcher Alex Sotirov plan to reveal the details of…