Malaysian Kaspersky website and shop hacked. Users at risk?

20/07/2008 Written by Roberto Preatoni

kasperskyThe offi­cial Malaysian Kasper­sky Antivirus’s web­site has been hacked yes­ter­day by a Turk­ish cracker going by the han­dle of “m0sted”.

Along with it, the same cracker hacked also the offi­cial Kasper­sky S.E.S. online shop and its sev­eral other subdomains.

The attacker reported “patri­o­tism” as the rea­son behind the attack and “SQL Injec­tion” as the tech­ni­cal way the intru­sion was performed.

Both web­sites has been home page defaced as well as sev­eral other sec­ondary pages. The inci­dent, though appear­ing a sim­ple web­site deface­ment, might carry along big risks for end-​users because from both the web­sites, eval­u­a­tion copies of the Kasper­sky Antivirus are dis­trib­uted to the pub­lic. In the­ory, the attacker could have uploaded tro­janized ver­sions of the antivirus, infect­ing in this way the unaware users attempt­ing a down­load from a trusted Kaspersky’s file repos­i­tory (remem­ber the tro­jan in the Debian file repository?).

Read more

Blogless blogs, Olympic blogs the Chinese way

15/07/2008 Written by SyS64738 (Roberto Preatoni)

beijing_olympic_08For all you folks, fan of the civil lib­er­ties as well as the Olympic games, here’s the inte­gral text of the Inter­na­tional Olympic Com­mit­tee Blog­ging Guide­lines for the accred­ited per­sons. It’s the per­fect com­pan­ion of the recent deci­sion from the Olympic Chi­nese Com­mit­tee to ban the flags from the stadiums.

As you will read, blogs are admit­ted but:

– should not con­tain infor­ma­tion not related to strictly per­sonal experience
– should not con­tain sound or mov­ing images from the Olympic Games
– should not con­tain still images con­tain­ing any sport­ing action of the
Games or the Open­ing, Clos­ing or Medal Cer­e­monies of the Games.
– should not con­tain the Olympic symbol
– should not con­tain com­mer­cial ref­er­ences (Blogspot, bye bye!)
– should not con­tain the word “Olympic” within the blog URL

But you are lucky, still you can use your plain white Olympic blog home­page to test the bright­ness of your screen.

… enjoy and please com­ment the offi­cial text

Read more

250 thousands emails at risk? It is a feature!

10/07/2008 Written by minor

 “It is not a bug, it is a fea­ture. You invented the wheel.”

If you get this kind of answer from a web­site oper­a­tor in rela­tion to a secu­rity bug found in his appli­ca­tion, then you have only two choices: either you’re para­noid or the oper­a­tor doesn’t care much about secu­rity. What are talk­ing about? About leak­age of 250.000 email addresses.

One of the most vis­ited web­sites in Slo­va­kia, the com­mu­nity web­site Azet​.sk known thanks to his freemail and chat ser­vices has sev­eral sec­tions, among which is also a dat­ing sec­tion . The web­site is vis­ited by surfers of var­i­ous age that would like to find a part­ner for any­thing: chat­ing, meet­ing, sex etc. You just put an announce and every­body can respond you through a web form. But few days ago, on one of the most vis­ited secu­rity blogs in Slo­va­kia blog​.syn​opsi​.com appeared the detailed descrip­tion of how to get email addresses from the Azet dat­ing ser­vice with a PoC script.

Read more

The weakest link of the chain

09/07/2008 Written by Roberto Preatoni

flying_me_658_07-07Warn­ing: this arti­cle is not for the fainted of heart!

A chain is only as strong as its weak­est link”, this sen­tence applies to any process that will fail if some step in it goes wrong. The guys at Tech­ni­cal Park and ABB, the indus­trial colos­sus that built the new Fly­ing Fury amuse­ment park attrac­tion, should have taken it into consideration.

Here’s the story…

Read more

Darpa's "trust in IC": a smart article and our comments

07/07/2008 Written by SyS64738 (Roberto Preatoni)

microchip2 With­out any doubt, the best arti­cle pub­lished about the Darpa’s Turst in IC pro­gram has appeared on IEEE Spectrum’s web­site. We wel­come you to read that arti­cle, then to come back here as we posted our com­ments (oh boy, we have so much to say…)

Read more

3 4 5 6 7 8 9 10 11 12
ZONE-H In Numbers
  • News: 4.735
  • Admins: 7
  • Registered Users: 83.648
  • Early Warning subscriptions: 9396
  • Digital Attacks: 8.393.747
  • Attacks On Hold: 38.281
  • Online Users: 409
Login




 Lost password ?

Events
  • M
  • T
  • W
  • T
  • F
  • S
  • S
  •  
  •  
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  •  
  •