Hacking - Infoworld http://www.infoworld.com/t/2106 en Got remote access? Lock it down http://www.infoworld.com/t/application-security/got-remote-access-lock-it-down-186194?source=rss_hacking <div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="https://www.infoworld.com/sites/infoworld.com/files/media/image/Security_lock_2_hp.jpg" alt="Got remote access? Security Access Control Application Security Hacking Security Management Fri, 10 Feb 2012 17:25:26 +0000 InfoWorld Tech Watch 186194 at http://www.infoworld.com Data breach? Blame your third party's remote access systems http://www.infoworld.com/d/security/data-breach-blame-your-third-partys-remote-access-systems-185842?source=rss_hacking <!--paging_filter--><p>An in-depth study of <a href="http://www.networkworld.com/news/2012/011712-zappos-data-breach-254971.html" target="_blank">data-breach</a> problems last year where hackers infiltrated 312 businesses to grab gobs of mainly customer payment-card information found the primary way they got in was through third-party vendor remote-access <a href="http://www.networkworld.com/topics/applications.html" target="_blank">applications</a> or VPN for systems maintenance.</p> Security Cyber Crime Data Loss Prevention Data Security Hacking VPN Tue, 07 Feb 2012 13:28:46 +0000 admin 185842 at http://www.infoworld.com Anonymous claims to have released source code of Symantec's pcAnywhere http://www.infoworld.com/d/security/anonymous-claims-have-released-source-code-of-symantecs-pcanywhere-185839?source=rss_hacking <!--paging_filter--><p>Hacker group Anonymous <a href="https://twitter.com/anonymousirc/status/166744502315388930" target="_blank">claimed late Monday</a> that the source code of Symantec's pcAnywhere had been <a href="https://thepiratebay.se/torrent/7014253" target="_blank">uploaded</a> on The Pirate Bay site.</p> <p>Symantec could not immediately comment on whether the hackers had indeed released the source code of its product. "It happened so recently that we're still in the process of analyzing and won't be able to confirm until the morning," a spokesman said via email.</p> Security Symantec Cyber Crime Hacking Tue, 07 Feb 2012 12:09:34 +0000 admin 185839 at http://www.infoworld.com The point after: Apple's China problem, U.S. copyright conundrums, and more http://www.infoworld.com/t/cringely/the-point-after-apples-china-problem-us-copyright-conundrums-and-more-185795?source=rss_hacking <!--paging_filter--><p>It's been a while since I dipped into the reader mailbag and pulled out a few choice nuggets. Today, the unofficial federal holiday known as "Super Bowl Monday Hangover," seems as good a time as any to look back with amusement and ibuprofen at what riles up the residents of Cringeville.</p> Axis of Apple Cringely Intellectual Property Hacking Windows Phone Mon, 06 Feb 2012 19:35:04 +0000 Robert X. Cringely 185795 at http://www.infoworld.com Tinker tailor coder spy? Anonymous strikes again http://www.infoworld.com/t/cringely/tinker-tailor-coder-spy-anonymous-strikes-again-185696?source=rss_hacking <!--paging_filter--><p>Memo to the G-men on both sides of the pond: If you're hoping to catch the bad guys, it's generally a good idea to not let them listen in on your private conversations -- especially when the conversations are about them.</p> <p>International law enforcers just learned this the hard way after members of Anonymous managed to record a phone conversation between the FBI and Scotland Yard about -- yes -- Anonymous.</p> Cringely Hacking Fri, 03 Feb 2012 20:35:44 +0000 Robert X. Cringely 185696 at http://www.infoworld.com VeriSign hacked several times, won't reveal the details http://www.infoworld.com/t/cyber-crime/verisign-hacked-several-times-wont-reveal-the-details-185617?source=rss_hacking <div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/Security_lock_2_hp.jpg" alt="VeriSign hacked several times, won't reveal the details" width="243" height="182" align="right" /></div> <p>In October 2011, Internet infrastructure firm VeriSign released its usual quarterly report. Buried in the 50-page filing to the SEC was the revelation that the company had been breached multiple times the previous year.</p> Security Verisign Cyber Crime Data Security Hacking Security Management Web Security Thu, 02 Feb 2012 20:24:50 +0000 InfoWorld Tech Watch 185617 at http://www.infoworld.com Hackers infect WordPress 3.2.1 blogs to distribute TDSS rootkit http://www.infoworld.com/d/security/hackers-infect-wordpress-321-blogs-distribute-tdss-rootkit-185370?source=rss_hacking <!--paging_filter--><p>Hackers are compromising WordPress 3.2.1 blogs in order to infect their visitors with the notorious TDSS rootkit, according to researchers from Web security firm Websense.</p> <p>It's not clear how the websites are being compromised, but there are publicly known exploits for vulnerabilities that affect WordPress 3.2.1, which is an older version of the popular blog publishing platform.</p> Security Internet Hacking Malware Tue, 31 Jan 2012 15:30:40 +0000 admin 185370 at http://www.infoworld.com Many pcAnywhere systems still sitting ducks http://www.infoworld.com/d/security/many-pcanywhere-systems-still-sitting-ducks-185358?source=rss_hacking <!--paging_filter--><div style="position: relative; width: 243px; background: #ffffff no-repeat center top; float: right; height: 182px; padding: 8px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/IFW_Hacking3.jpg" alt="Many pcAnywhere systems still sitting ducks" width="243" height="182" align="right" /></div><p>Despite warnings from security software maker Symantec not to connect its pcAnywhere remote-access software to the Internet, more than 140,000 computers appear to remain configured to allow direct connections from the Internet, thereby putting them at risk.</p> Security Symantec Endpoint Protection Hacking Network Security Vulnerability Assessment Security Tue, 31 Jan 2012 11:00:00 +0000 Eric Knorr 185358 at http://www.infoworld.com 15 worst Internet privacy scandals of all time http://www.infoworld.com/d/security/15-worst-internet-privacy-scandals-of-all-time-185105?source=rss_hacking <!--paging_filter--><p>In honor of National Data Privacy Day this Saturday, Jan. 28, we've put together a list of the 15 worst Internet privacy scandals of all time.</p> <p>These high-profile privacy scandals involve many underlying technologies, from search to social media, email to voice mail, mobile phones to Webcams to GPS. But at the heart of all of these privacy scandals are companies collecting personal data without the user's knowledge or consent and then either sharing it with third parties or simply failing to keep it safe.</p> Security Apple Google Microsoft Consumer Electronics iPhone Data Security Hacking Internet Privacy Fri, 27 Jan 2012 13:36:01 +0000 admin 185105 at http://www.infoworld.com Threatened by Anonymous, Symantec tells users to pull pcAnywhere's plug http://www.infoworld.com/d/security/threatened-anonymous-symantec-tells-users-pull-pcanywheres-plug-185065?source=rss_hacking <!--paging_filter--><p>Symantec this week took the highly unusual step of telling users of its pcAnywhere remote access software to disable or uninstall the software while it fixes an unknown number of bugs.</p> <p>Security experts said the move was unprecedented for a company of Symantec's size.</p> <p><strong>[ Find out how to block the viruses, worms, and other malware that threaten your business, with hands-on advice from InfoWorld's expert contributors in InfoWorld's "<a href="http://www.infoworld.com/browser-security-deep-dive?source=ifwelg_fssr">Malware Deep Dive</a>" PDF guide. ]</strong></p> Security Symantec Access Control Hacking Patch Management Thu, 26 Jan 2012 13:54:13 +0000 ccraig 185065 at http://www.infoworld.com Linux vendors rush to patch privilege escalation flaw after root exploits emerge http://www.infoworld.com/d/security/linux-vendors-rush-patch-privilege-escalation-flaw-after-root-exploits-emerge-184889?source=rss_hacking <!--paging_filter--><p>Linux vendors are rushing to patch a privilege escalation vulnerability in the Linux kernel that can be exploited by local attackers to gain root access on the system.</p> <p>The vulnerability, which is identified as CVE-2012-0056, was discovered by Jüri Aedla and is caused by a failure of the Linux kernel to properly restrict access to the "/proc/&lt;pid&gt;/mem" file.</p> Security Linux Hacking Patch Management Tue, 24 Jan 2012 18:31:52 +0000 ccraig 184889 at http://www.infoworld.com Hacker releases 100,000 Facebook log-in credentials http://www.infoworld.com/d/security/hacker-releases-100000-facebook-log-in-credentials-184791?source=rss_hacking <!--paging_filter--><p>A hacker who claims to act in defense of Israel has released 100,000 credentials of allegedly Arab users of Facebook in an ongoing row between Israeli and Arab hackers.</p> <p>The hacker, who goes by the name Hannibal, <a href="http://pastebin.com/CWWRgD1t" target="_blank">posted the credentials</a> in four parts on Pastebin on Saturday as well as making the details available on 14 file-sharing sites.</p> Security Facebook Data Security Hacking Social Networking Mon, 23 Jan 2012 17:22:46 +0000 admin 184791 at http://www.infoworld.com Researchers expose flaws in popular industrial control systems http://www.infoworld.com/d/security/researchers-expose-flaws-in-popular-industrial-control-systems-184629?source=rss_hacking <!--paging_filter--><p>Researchers showcased unpatched security flaws in software used to control critical industrial systems by oil, gas, water, and electrical distribution plants at the 2012 SCADA Security Scientific Symposium (S4) on Thursday.</p> <p>The vulnerabilities ranged from information disclosure and privilege escalation bugs to remote denial-of-service (DoS) and arbitrary code execution flaws.</p> Security Hacking Malware Vulnerability Assessment Fri, 20 Jan 2012 16:13:07 +0000 admin 184629 at http://www.infoworld.com Symantec backtracks, admits own network hacked http://www.infoworld.com/d/security/symantec-backtracks-admits-own-network-hacked-184334?source=rss_hacking <!--paging_filter--><p>Symantec today backed away from earlier statements regarding the theft of source code of some of its flagship security products, now admitting that its own network was compromised.</p> <p>In a statement provided to the <a href="http://www.reuters.com/article/2012/01/17/us-symantec-hackers-idUSTRE80G1DX20120117" target="_blank">Reuters</a> news service, the security software giant acknowledged that hackers had broken into its network when they stole source code of some of the company's software.</p> Security Symantec Hacking Tue, 17 Jan 2012 21:38:06 +0000 admin 184334 at http://www.infoworld.com Oracle's latest Java moves frustrate users and vendors http://www.infoworld.com/d/application-development/oracles-latest-java-moves-frustrate-users-and-vendors-183452?source=rss_hacking <!--paging_filter--><p>Oracle, which officially took on the big job of <a href="http://www.infoworld.com/d/applications/oracles-ambitious-plans-integrating-suns-technology-891">shepherding Java two years ago this month</a>, is traveling bumpy roads lately, with its modularization and licensing plans for Java raising eyebrows and security concerns coming to the fore as well.</p> Application Development Applications Open Source Software Security Oracle Ubuntu Linux Java Programming Hacking Tue, 10 Jan 2012 11:00:00 +0000 Galen Gruman 183452 at http://www.infoworld.com Bow down to your new hacker overlords http://www.infoworld.com/t/cringely/bow-down-your-new-hacker-overlords-183574?source=rss_hacking <!--paging_filter--><p>Anonymous, move over. WikiLeaks, take a hike. There's a new uber hacking/whistleblowing group in town with some serious game and a wicked cool name that's putting you both to shame.</p> Cringely Mobile Security Hacking Mon, 09 Jan 2012 19:55:42 +0000 Robert X. Cringely 183574 at http://www.infoworld.com Symantec leak: Minor security threat but questions remain http://www.infoworld.com/t/cyber-crime/symantec-leak-minor-security-threat-questions-remain-183410?source=rss_hacking <div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/IFW_Hacking3.jpg" alt="Symantec leak: Minor security threat but questions remain" width="243" height="182" align="right" /></div><p>A group of purported Indian hackers claimed this week to have <a href="http://www.infoworld.com/d/the-industry-standard/symantec-investigates-possible-leak-norton-antivirus-source-code-183345">stolen the source code to Symantec's Norton AntiVirus soft Symantec Anti-virus Cyber Crime Data Loss Prevention Hacking Fri, 06 Jan 2012 17:54:54 +0000 InfoWorld Tech Watch 183410 at http://www.infoworld.com Symantec confirms source code leak in two enterprise security products http://www.infoworld.com/d/security/symantec-confirms-source-code-leak-in-two-enterprise-security-products-183368?source=rss_hacking <!--paging_filter--><p>Symantec late Thursday confirmed that source code used in two of its older enterprise security products was <a href="http://www.computerworld.com/s/article/9223190/Hacker_group_threatens_to_release_Symantec_AV_source_code" target="_blank">publicly exposed</a> by hackers this week.</p> <p>In a statement, the company said that the compromised code is between four and five years old and does not affect Symantec's consumer-oriented Norton products as had been previously speculated.</p> Security Symantec Anti-virus Data Security Endpoint Protection Hacking Fri, 06 Jan 2012 12:42:46 +0000 admin 183368 at http://www.infoworld.com AJAX-based Web exploitation attacks detected in the wild http://www.infoworld.com/d/security/ajax-based-web-exploitation-attacks-detected-in-the-wild-183308?source=rss_hacking <!--paging_filter--><p>Security researchers from Web filtering vendor M86 Security have detected Web exploitation attacks that use <a href="http://www.infoworld.com/category/tags/ajax">AJAX</a> (Asynchronous JavaScript and XML) to fragment the payload into small pieces of code that are harder to detect by antivirus programs and intrusion prevention systems.</p> Security AJAX Anti-virus JavaScript Hacking Intrusion Detection Vulnerability Assessment Thu, 05 Jan 2012 17:34:05 +0000 admin 183308 at http://www.infoworld.com Researcher devises hard-to-detect DoS attack against HTTP servers http://www.infoworld.com/d/security/researcher-devises-hard-detect-dos-attack-against-http-servers-183279?source=rss_hacking <!--paging_filter--><p>Qualys senior software engineer Sergey Shekyan has devised a new HTTP denial-of-service (DoS) attack method which relies on prolonging the time clients need to read Web server responses.</p> <p>Shekyan's method is dubbed Slow Read DoS and is based on previous research by Robert Hansen, the creator of the Slowloris HTTP DoS tool and the late Jack C. Louis, who developed Sockstress, a proof-of-concept application that applies the slow read attack concept to TCP stacks.</p> Security Hacking Vulnerability Assessment Thu, 05 Jan 2012 16:28:21 +0000 admin 183279 at http://www.infoworld.com