Friday, September 19, 2014

September’s PATCH TUESDAY fixes 42 flaws

On September 9th, Patch Tuesday fixes 42 security flaws covering Windows, Internet Explorer, .NET Framework, and Lync Server. This month Patch Tuesday contains a total of FOUR different bulletins, one of which was rated as CRITICAL. Internet Explorer (IE) has clinched the limelight by addressing 37 vulnerabilities under MS14-052 bulletin. Where as MS14-053 and MS14-055 fix Denial of Service (DoS) issues in the .Net framework and Lync Server respectively. MS14-054 security update addresses a vulnerability in Microsoft Windows Task Scheduler that allows attackers to gain elevated privileges via a crafted application. <more>

Google Glass susceptible to hacker profiling

According to Kaspersky Lab, a wearable technology Google Glass is prone to hacker profiling through network vendors attacks. Kaspersky researchers, Roberto Martinez and Juan Andres Guerrero have done in-depth analysis of Google Glass and Samsung Galaxy Gear 2 in search of privacy issues that could be faced by users. Bluetooth or Wi-Fi can be used to browse the web through Google Glass. Wi-Fi doesn’t need a separate mobile device to access the Internet. According to security researcher, as the data transmission is not fully encrypted giving an opportunity for intruders to intercept sensitive information via Man-in-The-Middle (MiTM) attacks. <more>

Monday, September 15, 2014

NO MORE!! Man-In-The-Middle attacks in Firefox

Latest Firefox implements support for public-key pinning feature. This newly added feature validates the authorization of a server based on an internal list of trusted certificates. Secure communication can be accomplished by encrypting the data, based on a digital certificate issued by any Certificate Authority (CA) and then verify the service identity. Earlier forged certificates had been obtained by cybercriminals and get valid SSL certificate for a domain by deceiving Certificate Authority (CA). Another way of getting the certificate through hacking into their systems and issued on their behalf. The latest firefox wiped out these risks through public-key pinning where digital certificate of the website compares with the certificate present in the browser and it must be matched for communication. <more>