On September 9th, Patch Tuesday fixes 42 security flaws
covering Windows, Internet Explorer, .NET Framework, and Lync Server.
This month Patch Tuesday contains a total of FOUR different bulletins,
one of which was rated as CRITICAL. Internet Explorer (IE) has clinched
the limelight by addressing 37 vulnerabilities under MS14-052 bulletin. Where as MS14-053 and MS14-055 fix Denial of Service (DoS) issues in the .Net framework and Lync Server respectively. MS14-054
security update addresses a vulnerability in Microsoft Windows Task
Scheduler that allows attackers to gain elevated privileges via a
crafted application. <more>
Friday, September 19, 2014
Google Glass susceptible to hacker profiling
According to Kaspersky Lab, a wearable technology Google Glass is prone to hacker profiling through network vendors attacks.
Kaspersky researchers, Roberto Martinez and Juan Andres Guerrero have
done in-depth analysis of Google Glass and Samsung Galaxy Gear 2 in
search of privacy issues that could be faced by users. Bluetooth or
Wi-Fi can be used to browse the web through Google Glass. Wi-Fi doesn’t
need a separate mobile device to access the Internet. According to security
researcher, as the data transmission is not fully encrypted giving an
opportunity for intruders to intercept sensitive information via
Man-in-The-Middle (MiTM) attacks. <more>
Monday, September 15, 2014
NO MORE!! Man-In-The-Middle attacks in Firefox
Latest Firefox implements support for public-key pinning feature. This newly added feature validates the authorization of a server based on an internal list of trusted certificates. Secure communication can be accomplished by encrypting the data, based on a digital certificate issued by any Certificate Authority (CA) and then verify the service identity. Earlier forged certificates had been obtained by cybercriminals and get valid SSL certificate for a domain by deceiving Certificate Authority (CA). Another way of getting the certificate through hacking into their systems and issued on their behalf. The latest firefox wiped out these risks through public-key pinning where digital certificate of the website compares with the certificate present in the browser and it must be matched for communication. <more>
Subscribe to:
Posts (Atom)

