Reptilians were the earliest North American pioneers

|
The oldest reptile prints ever found suggest that reptiles were the first creatures to venture into continental interiors


Adobe vulnerability management: Arkin on the new threat landscape

|
Adobe's Brad Arkin discusses the company's struggle to protect Reader, Acrobat and Flash, including its new partnership with the Microsoft Active Protections Program.

Add to digg Add to StumbleUpon Add to del.icio.us Add to Google

Adobe Systems - Microsoft - Adobe Acrobat - Adobe Flash - Adobe

Are cloned steak and milk on European menus?

|
Reports suggest that meat and dairy products from the offspring of cloned cattle are already on sale in Europe, says Jessica Griggs


Dog brains rotated by selective breeding

|
Thanks to thousands of years of skull morphing, the brains of some domestic dogs have shifted and a key component relocated


Intercepting Mobile Traffic

|
Hi guys,

I wanted to see what I'm allowed to post before I get myself flammed and banned!! ... I'm intercepting the network traffic from my phone which connects to my wireless network, I poison the ARP table to route traffic through my PC. The aim of this is to attempt to intercept the response when trying to activate a product, so that I can fake a positive response .... Though I'm stuck on a couple of points.

Am I allowed to post the specifics on here to request a few pointers, or is this a no no??

Cheers

Hacking ATMs

|

Hacking ATMs to spit out money, demonstrated at the Black Hat conference:

The two systems he hacked on stage were made by Triton and Tranax. The Tranax hack was conducted using an authentication bypass vulnerability that Jack found in the system's remote monitoring feature, which can be accessed over the Internet or dial-up, depending on how the owner configured the machine.

Tranax's remote monitoring system is turned on by default, but Jack said the company has since begun advising customers to protect themselves from the attack by disabling the remote system.

To conduct the remote hack, an attacker would need to know an ATM's Internet IP address or phone number. Jack said he believes about 95 percent of retail ATMs are on dial-up; a hacker could war dial for ATMs connected to telephone modems, and identify them by the cash machine's proprietary protocol.

The Triton attack was made possible by a security flaw that allowed unauthorized programs to execute on the system. The company distributed a patch last November so that only digitally signed code can run on them.

Both the Triton and Tranax ATMs run on Windows CE.

Using a remote attack tool, dubbed Dillinger, Jack was able to exploit the authentication bypass vulnerability in Tranax's remote monitoring feature and upload software or overwrite the entire firmware on the system. With that capability, he installed a malicious program he wrote, called Scrooge.

EDITED TO ADD (7/30): Another two articles.

Smartphones tempting new targets for hackers (AFP)

|

A shopper looks at a smartphone at a shop in Taipei on July 19. Software security experts warn that mobile phones are tempting targets for hackers in a world where people eagerly invite strange applications onto handsets packed with personal data.(AFP/File/Patrick Lin)AFP - Software security experts warn that mobile phones are tempting targets for hackers in a world where people eagerly invite strange applications onto handsets packed with personal data.


Graphene bubbles mimic explosive magnetic field

|
Electrons trapped inside strain bubbles in graphene act as if they were in an incredibly powerful magnetic field – good news for future electronics


Cisco Internet Streamer: Web Server Directory Traversal Vulnerability http://www.cisco.com/warp/public/707/cisco-sa-20100721-spcdn.shtml, (Fri, Jul 30th)

|
----------- Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot org (c) SANS Internet Storm Center. http://isc.sans.org Creative Commons Attribution-Noncommercial 3.0 United States License.

WAF fail

|

Posted by Henri Salo on Jul 30

WAF fail;

http://www.1filesharing.com/search_rapidshare/index.php?q=%22%27%3E%3Cscript%3Ealert%281%29;%3C/script%3Ei&fl=all&source=

1filesharing.com does not reply to abuse-emails and won't delete files
even I have requested it. I have four different malware-links still
spreading using that service.

Best regards,
Henri Salo