April 2010

Denial-of-Service (DoS) attack

You may have heard of denial-of-service attacks launched against websites, but you can also be a victim of these attacks.Denial-of-service attacks can be difficult to distinguish from common network activity,but there are some indications that an attack is in progress.
 
What is a denial-of-service (DoS) attack?

Understanding Firewalls

When anyone or anything can access your computer at any time,your computer is more susceptible to being attacked.You can restrict outside access to your computer and the information on it with a firewall.

What do firewalls do?
 

Adobe Reader and Acrobat JavaScript Blacklist Framework

The Adobe Reader and Acrobat JavaScript Blacklist Framework introduced in versions 9.2 and 8.1.7 provides granular control over the execution of specific JavaScript APIs. This mechanism allows selective blocking of vulnerable APIs so that you do not have to resort to disabling JavaScript altogether.

The blacklist is maintained in the Windows registry and the Macintosh OS X FeatureLockdown file.On Windows, there are two blacklists, one for enterprise administrators,and one for Adobe patches and updates.

 

 

Adobe Reader and Acrobat Vulnerabilities

Original release date: April 13, 2010
Last revised: --
Source: US-CERT
 

Systems Affected

  • Adobe Reader 9.3.1 and earlier 9.x versions
  • Adobe Reader 8.2.1 and earlier versions
  • Adobe Acrobat 9.3.1 and earlier 9.x versions
  • Adobe Acrobat 8.2.1 and earlier versions

 

Kaminsky bug

DNS Cache Poisoning Issue ("Kaminsky bug")
A weakness in the DNS protocol may enable the poisoning of caching recurive resolvers with spoofed data. DNSSEC is the only full solution. New versions of BIND provide increased resilience to the attack.
 

CVE: CVE-2008-1447
CERT: VU#800113
Program Impacted: BIND

Cyber Espionage

Cyber Espionage is the Real Problem
Dr. Jim Lewis sees the issue of economic cyber espionage as the greatest threat the United States currently faces in cyberspace.“The real problem is economic espionage,”
Lewis said today at an event hosted by the Potomac Officers Club.
Lewis is one of the premier experts in cybersecurity.He led the CSIS Commission on Securing Cyberspace for the 44th Presidency and has given testimony before Congress.

Military Asserts Right to Return Cyber Attacks

WASHINGTON -- The U.S. must fire back against cyber attacks swiftly and strongly and should act to counter or disable a threat even when the identity of the attacker is unknown, the director of the National Security Agency has told Congress.

Lt. Gen. Keith Alexander, who is the Obama administration's nominee to take on additional duties as head of the new Cyber Command, also said the U.S. should not be deterred from taking action against countries such as Iran and North Korea just because they might launch a cyber attack.

"Even with the clear understanding that we could experience damage to our infrastructure, we must be prepared to fight through in the worst case scenario," Alexander said in a Senate document obtained by The Associated Press.

 

Cyber Defence Centreand of Excellence and Symantec Experts

Symantec Corp. (Nasdaq: SYMC) and the NATO-accredited Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Estonia announced they have signed a memorandum of understanding  to promote cooperation on the research of online threats.This joint research project will be based in Tallinn, Estonia, overseen by experts from both organisations.

Open Source Intelligence

All political and military conflicts now have a cyber dimension,whose size and impact are difficult to predict.National security experts must now acknowledge that real political and military objectives can be won or lost in cyberspace,even if only on the propaganda front.Globalisation and the Internet have aided foreign intelligence services and terrorists as much as any other part of society.

Scam Artists

Old computers and mobile phones that people have thrown away to be re-used or recycled are often not thought of again by their owners, but in fact they still may have very sensitive personal data on them that can often be worth a lot more to criminals than the recyclable materials contained in the device.

Pages

Hacking

Post date: 05/23/2013 - 08:16
Post date: 05/22/2013 - 09:23
Post date: 05/18/2013 - 11:38

Infosec

Post date: 05/23/2013 - 17:08
Post date: 05/23/2013 - 12:16
Post date: 05/23/2013 - 11:05
Post date: 05/23/2013 - 10:54