Dig Security together —— 阅读、挖掘、评论,安全共进步。




Tag Cloud
Emerging Threat


1
digs
Open DNS Significant Loop Hole
submitted by wanghongyang 353 days ago (via usawarez.org)
Open DNS is a great service I personally love it and use it ,about four and a half months back I discovered an interesting feature Open DNS offers known as shortcuts ,it lets you configure your network so that if a user types in a phrase on any PC on your Open DNS network ,you can direct the traffic on to a URL of your choice
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
Smartphones a greater security risk than laptops
submitted by wanghongyang 643 days ago (via techcrunch.com)
According to survey of 300 senior IT staff, smart phones pose more of a threat to business security than laptops, largely due to user mentality; for one reason or another, many smart phones just don’t seem to be getting the protection their lap dwelling counterparts might.
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
USB malware increases
submitted by wanghongyang 643 days ago (via watchyourend.com)
According to new research, around ten percent of all malware is designed to use portable storage media, such as removable USB drives, to attack and propagate. The research found that the most common type of malware on USB sticks was INF/Autorun, a generic identification for malware that tries to use the autorun.
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
Hacking Second Life
submitted by wanghongyang 700 days ago (via net-security.org)
At Black Hat in Amsterdam we caught up with Michael Thumann, CSO of ERNW. In this video he discusses Second Life hacking. Beyond being an online game Second Life is a growing marketplace for big companies where lot of money is made. Living and acting in a virtual world gives the people the opportunity to do things they would never do in real life.
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
XSS Introduction by Steve
submitted by wanghongyang 696 days ago (via steve.org.uk)
1. Introduction: Setup the cookie 2. Simple cookie stealing 3. Basic filtered input 4. Evading simple filtering 5. I can run script, what now? 6. Protecting against these attacks
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
安全专家:Web页面就可以轻松搞定你的路由器
submitted by wanghongyang 696 days ago (via cnbeta.com)
在周二旧金山举行的RSA安全会议上,安全专家Dan Kaminsky演示了如何通过网页入侵用户的路由器. Kaminsky花费了数年时间注意有关Internet DNS系统的设计缺陷,这一问题设计可导致被攻击者滥用,以用来攻击防火墙背后的用户.目前已知D-Link和Linksys的多种无线或有线路由器包含此问题.受害人只需要访问到一个恶意
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
《纳税富翁》惊现漏洞,一步不走也赚五千万
submitted by wanghongyang 696 days ago (via cnbeta.com)
之前玩了在CB上发现的深圳地税局自主开发的税收网游 -纳税富翁,发现了一个大漏洞,该漏洞可以做到一步也不走,都可以用原有的五十万变成五千万。
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
Mikko delivered a presentation on Espionage Trojans
submitted by wanghongyang 695 days ago (via youtube.com)
Espionage Trojans(间谍木马)。
 
0 Comments - More Info - Bury   Topic: Emerging Threat
Watch Video
1
digs
Espionage Against Pro-Tibet Groups, Others, Spurred Microsoft Patches
submitted by wanghongyang 695 days ago (via wired.com)
Computer intruders targeting pro-Tibetan groups, U.S. defense contractors and government agencies slipped in through previously unknown security holes in Microsoft Office, prompting Microsoft to issue a flurry of patches to the popular software suite in 2006 and 2007, according to computer security experts. These attacks, which appeared to have originated in China, began in early 2006 ...
 
0 Comments - More Info - Bury   Topic: Emerging Threat
1
digs
警惕民生银行1元充值缴费优惠活动
submitted by wanghongyang 695 days ago (via cisrt.org)
随着新春佳节来临,各式各样的优惠活动也随之产生。但是这时恶意网站也随之而来,CISRT今天截获一个钓鱼网站,该钓鱼网站伪装成“民生银行1元充值缴费优惠活动”,通过诱骗用户输入民生银行借记卡和信用卡卡号等一系列私密资料,来盗取用户的借记卡、信用卡卡号和密码等重要资料。CISRT提
 
0 Comments - More Info - Bury   Topic: Emerging Threat