Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2


Around The Web

CHANNEL 4 NEWS
Millions Of Barclays Card Users Exposed To Fraud
In an expos? by the UK's BBC Channel 4, investigators were able to use card-reader-enabled mobile phones to lift the details from RFID-equipped bankcards simply by tapping the victim?s wallet. Information was then used to make a variety of purchases online, the easiest being Amazon.com

ITWORLD
Mozilla At Work On Mobile Do Not Track
Spurred by the success of its Web-based Do Not Track software that hides users from the eyes of third parties, Mozilla is working hard to create a mobile version. The Open Web Devices Platform, codenamed Boot to Gecko, will serve as an alternate OS to Android. So far, to try it out, users must root their phones and tinker around a bit

PCWORLD
Mobile Malware: Beware Drive-by Downloads On Your Smartphone
Drive-by downloads, or the sneaky installation of malware on a computer without the user?s knowledge, are well-known by security-savvy users. But even pros can get caught by malware that mimics ordinary functions of the phone, such as messaging or incoming call notifications

MSNBC
Cracks Appear In Face Of Apple's iOS Security
Android gets all the notoriety for its exploitable loopholes, but iOS might not be quite as secure as people think. So far, some say, iOS has been spared because Android is the low-hanging fruit. Many predict that successful attacks will increase, worsened by Apple?s unofficial policy of scapegoating individual developers or employees

ITWEB
Scope, Not Technology, The Game-Changer For Mobile Security
Charl van der Walt, co-founder and managing director of SensePost believes that, in the mobile world, it is less an issue of technology that affects security and more an issue of the staggering variety of connectivity and platforms. In a decentralized heterogeneous environment, responsibility for patching and security updates is blurred.

PCWORLD
Symantec Details Mobile Device Management Plans
Symantec has acquired Nukona, a software provider for mobile device management. While Symantec already has a MDM solution, the company claims that the purchase will make it stronger in a BYOD environment

PCMAG
Lost Phone Survey Makes No Sense
The much-vaunted Lookout Mobile Security report detailing the high incidence of loss of personal cellphones might not be quite the objective study as it seems, critics say

CIO
Android Security Threats Overhyped? Not So Fast...
Quite a few pundits have claimed that the near-endless talk of Android vulnerabilities is just a ploy to sell less-than-useful security products. But the threat, while probably overstated, still deserves attention

THE GLOBE AND MAIL
Flash Of An iPad Gets Man Past Border Security
A Canadian man who had left his passport at home was able to enter the United States by handing over his iPad?with a scanned copy of his identification. The U.S. Border Patrol is not authorized to accept photocopies or scans of passports. Although there has been some push to accept digital documents, the current state of technology makes vital documents all too easy to manipulate

GoMoNews
Fully-Featured Android Security App Comes Out Of Beta
avast! Free Mobile Security has left the beta stage, gone gold, and is being distributed freely for the Android platform--along with GPS location, it offers a remotely-triggered siren, remote wipe, and audio monitoring so you can listen to the crook as he negotiates a better price for your phone at the local swap meet

ITBUSINESSEDGE
Android Struggles To Secure Itself
Like the PC/Mac debate, the easier attack vector on the Android seems to improve the security of the iPhone just by acting as a lightning rod. Despite the early opinions that facial recognition is a bit dodgy, Ice Cream Sandwich offers some help, but will it be enough to make a difference?

CNET
Apple Patent Application Details Password-Protecting Power Adapters
Apple appears to be patenting a new application of password technology not completely different from the good old dongle. Password information would be stored in the power adapter for each individual device and a password reset would involve nothing more than plugging your iPhone or iPad into its charger and going from there

PC ADVISOR UK
Norton Plans iPhone, iPad Security Software
Symantec?s EMEA regional product director Con Mallon has suggested that the company hoped to expand beyond its Android mobile security product into the iPhone and iPad market

EWEEK
Latest Apple iOS Jailbreak Tool Exploits Two Security Flaws
A new jailbreak tool dubbed Corona is able to exploit vulnerabilities in iOS 5 in order to execute unsigned binaries within the platform. One of the exploits takes advantage of a format string bug, leaving some to wonder if Apple even bothers with a static analysis tool

ZDNET
iPhone Date Glitch Exposes Photo Albums
Apple?s reliance on a simple timestamp to secure photo albums in iOS has proven to be a vulnerability, says tech consultant Ade Barkah. He discovered that changing the clock setting on iPhone should give anyone access to the phone?s camera roll, even if the phone is locked.

GCN.COM
DISA OKs Secure Android Mobile System For DoD
Government CIOs have been handed a new tool with the Defense Information Systems Agency?s certification of a new Android-based mobile system as secure enough for Department of Defense use. The special secure mobile os, developed by Good Technology for use with the Dell Streak 5 smartphone provides adequate authentication and encryption for use even in combat areas

HELP NET SECURITY
SonicWALL Launches Mobile Connect App For iOS
App enables secure remote access from Apple devices such as iPad and iPhone

OFFICE OF INADEQUATE SECURITY
UK: Council Lost Memory Stick Containing 18,000 Residents' Details
Unencrypted memory stick threatens compromise of citizens' personal data

AMERICAN NEWS REPORT
More Americans Falling Victim To Identity Thieves
Department of Justice study shows that 8.6 million households were affected in 2010, up from 6.4 million in 2005

COMPUTER WEEKLY
Most UK Workers Unaware Of Security Issues, Study Reveals
Enterprises need to do more training on mobile and other threats, according to report


Best Of Web Archive:
Most Recent | 1| 2








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)