Posts Tagged ‘News’

Infragistics Acquires SharePoint Mobile App Developer SouthLabs

|
Comments Off
The SharePlus suite, which includes a free version of the app, is available for iPhone, Android and BlackBerry devices. - Infragistics, a user experience software company and a specialist in user interface development tools, announced the acquisition of SouthLabs, developers of SharePlus, the mobile SharePoint app. Through the acquisition, Infragistics said it intends to expand its business solutions further into the e...

Level Platforms Offers Mobile Device Management for MSPs

|
Comments Off
Managed Workplace allows MSPs to collect asset information, remotely configure devices, track location and restrict user access. - Remote monitoring and management (RMM) solutions provider Level Platforms, which markets its products toward managed service providers, introduced Mobile Device Management (MDM) as a new feature in the imminent release of Managed Workplace 2012. With MDM, service providers can manage and monitor...

Facebook malware scam takes hold

|
Comments Off
A "worrying number" of Facebook users are sharing a link to a malware-laden fake CNN news page reporting the U.S. has attacked Iran and Saudi Arabia, security firm Sophos said Friday.

Hungarian hacker gets 30 months for extortion plot on Marriott

|
Comments Off
A Hungarian hacker who attempted to extort money from Marriott International Inc. by stealing confidential data from its computers and threatening to expose it was sentenced to 30 months in prison.

Microsoft wraps up ads aimed at Google with IE9 pitch

|
Comments Off
Microsoft on Friday wrapped up a three-day campaign against rival Google by claiming its newest browser, Internet Explorer 9, is superior in stopping users from being tracked by online advertisers.

Anonymous grabs email from firm that defended Marine in Haditha case

|
Comments Off
In what's turning out to be quite a busy Friday for the hacking collective, Anonymous today said it has broken into the website of a law firm that represented a U.S. Marine accused of killing civilians in Haditha, Iraq.

ISC StormCast for Friday, February 3rd 2012 http://isc.sans.edu/podcastdetail.html?id=2302, (Fri, Feb 3rd)

|
Comments Off
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Critical PHP bug patched, (Fri, Feb 3rd)

|
Comments Off
Just about a month ago, PHP 5.3.9 was released, which included a patch for the hash collision problem. The basic hash collision problem affected various languages, including php and .Net (Microsoft fixed the issue in an out of band patch 2011-100 in late December).
PHP fixed the issue not by introducing a new hash function, but instead it limited the number of input parameters. Just like the php hardening patch suhosin did all along, PHP now supported a max_input_var parameter to limit the number of input parameters a request may send. The default limit was set to 1,000, plenty for most web applications.
Sadly, the fix was implemented incorrectly, and introduced a more severe vulnerability, a remote code execution vulnerability. Thats right: An attacker could craft a request, that will execute code on a web server running PHP 5.3.9.
Today, the PHP team released PHP 5.3.10 to address the issue.
If you are running PHP 5.3.9: PATCH NOW! This is a very critical bug
If you are running PHP 5.3.8: DO NOT UPGRADE TO 5.3.9. I would actually recommend that you wait.
Additionally, try to enable Suhosin if at all possible. There is a slight performance hit, but it is unlikely to break your web application unless you are already tight in resources. Many Linux distributions include Suhosin, so it may be pretty easy to set up.
------

Johannes B. Ullrich, Ph.D.

SANS Technology Institute

Twitter (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

German gov’t endorses Chrome as most secure browser

|
Comments Off
Germany's cyber security agency today recommended that Windows 7 users run Google's Chrome browser, citing the application's sandbox and auto-update features.

VeriSign Management Was ‘Out of the Loop’ About 2010 Data Breaches

|
Comments Off
VeriSign didn't disclose that it had been successfully attacked several times in 2010 because the security team didn't tell management about the incidents until recently. - VeriSign, the company responsible for the .com, .net and .gov domain spaces, acknowledged in a recent filing with the Securities and Exchange Commission that it was hacked several times in 2010. The company had not disclosed the incidents at the time they occurred. While VeriSign admitted to t...