Pwn2Own Contest Puts Bounty on Browser Vulnerabilities
Friday, January 27th, 2012 | Author: zyfjxm

Dog the Bounty Hunter, known for his shirtless leather vest approach to dressing and his less than tactful approach to apprehending bail jumpers, may not be ready for the next round of bounties coming down the pike. This year, at the CanSecWest in Vancouver, companies like HP and Google are offering rewards for hackers and research teams who can exploit zero-day vulnerabilities within the most common browsers. Pwn2Own Contest Puts Bounty On Browser Vulnerabilities This contest, known as Pwn2Own, has been an annual event at CanSecWest since 2007. Though in past years it has been criticized for randomly drawing participants and removing browsers once it had been exploited, this year the browsers will be fair game until the end with points awarded to the participant for each successful attack. In addition, the prize money offered is substantially larger, paying out $60,000 for first place, $30,000 for second and $15,000 for third. Google will also offer strictly Chrome based awards, paying $20,000 for a successful sandboxed exploitation and $10,000 for other unique attacks. The goal of Pwn2Own, of course, is to find the vulnerabilities so they can be patched in the future. Though some may take issue with this methodology, it’s common practice these days. As has been said far too many times in literary history, it takes a criminal to catch a criminal. This is simply the software version of hiring an ex theif to expose the weaknesses in your home security system. And while I hope none of the participants come with Dog’s cliche catch them then try to recuperate them in the backseat of his car methodology, the increased prize money is sure to attract a plethora of hacker bounty hunters.

See more here: 
Pwn2Own Contest Puts Bounty on Browser Vulnerabilities

Category: Uncategorized |  Comments off
AVG makes its first IPO of $125 million
Friday, January 20th, 2012 | Author: zyfjxm

AVG technologies is the maker of one of the most successful pieces of anti-virus software in the world, and they are going public. AVG Makes Its First IPO Of $125 Million Founded in 1991, and based in the Netherlands, AVG not only offers their widely used free anti-virus software, but they also offer various premium software and services for those who require a bit more protection. Apparently in the 9 months of the last fiscal year, the company’s revenue rose a full 24%, or to $191 million. They also more than double their profits from the last year to 68.8 million dollars, which is amazing considering the fact that so much of their manpower goes into free software. Big name companies such as JP Morgan, Goldman Sachs, Morgan Stanley, and even Intel have chosen to back the growing company. They will be trading under the ticker symbol AVG, so make sure you keep an eye out because this company is making big moves.

Go here to see the original:
AVG makes its first IPO of $125 million

Category: Uncategorized |  Comments off
Amazon gains new cloud security partner
Saturday, January 07th, 2012 | Author: zyfjxm

Amazon Web Services has made the decision to team up with Check Point Software Technologies to offer their customers reliable security services. Amazon Gains New Cloud Security Partner Check Point announced the release of the Virtual Appliance for Amazon Web Services , which according to Check Point, “enables customers to extend their security to the cloud with the full range of protections using Check Point Software Blades.” Up until now, Amazon Web Services only provided very basic security measures for users of their services, but that’s not the case anymore. Any user of the EC2 cloud services can get the Virtual Appliance directly from Amazon and set it up. Check Point describes many of the individual blades on as shown below: “The Firewall and IPS Software Blades protect services in the public cloud from unauthorized access and attacks. The Application Control Software Blade helps prevent application layer denial of service attacks and protects your cloud services. The IPsec VPN Software Blade allow secure communication into cloud resources. The Mobile Access Software Blade allows mobile users to connect to the cloud with an SSL encrypted connection with two factor authentication and device pairing. The DLP Software Blade prevents data breaches with unique User Check technology to allow real-time user remediation.” Both companies want to attract a wide range of potential customers, especially small companies and startups that are building their infrastructure in the cloud. They seem to realize that most people see it as a very risky move to have sensitive data there, so this should be accessible for just about everyone. According to an article from SecurityWeek.com , the base price for these services is $2000, and that comes with the firewall and virtual gateway. Everything else is icing on the cake and will cost you more money on top of that, but hopefully not too much.

Read more from the original source: 
Amazon gains new cloud security partner

Category: Uncategorized |  Comments off
HashDOS: Important Vulnerability Coming into the Spotlight.
Saturday, December 31st, 2011 | Author: swane

A presentation at a German security conference has many people worried about a this newly realized vulnerability that is present is most web frameworks. HashDOS: Important Vulnerability Coming into the Spotlight. According to a post from Sophos , “The type of hashing used by PHP, Java, Python and JavaScript in this attack is not a cryptographic hash, it is a simple mathematical hash used to speed up storing and retrieving data posted to web pages.” Under normal circumstances, the collisions in the hashes are managed by built-in language constructs and are not really an issue. However, in these types of attacks, the attacker can send pre-calculated values that will result in all of the hash values being the same, which will crash the majority of servers. On that same Sophos post, they stated that, “An example given showed how submitting approximately two megabytes of values that all compute to the same hash causes the web server to do more than 40 billion string comparisons.” which is an nearly inconceivable for just looking some data for a webpage. Apparently the keepers of the language Perl, went ahead and did something about this vulnerability some time ago, but nobody else followed suit, so they are all at risk. Hopefully, the people behind PHP, Python, and other applicable languages will actually pay attention this time and go ahead and make the necessary changes.

Here is the original:
HashDOS: Important Vulnerability Coming into the Spotlight.

Category: Uncategorized |  Comments off
Mobile Security Will (Probably) Always Be More Difficult
Sunday, December 18th, 2011 | Author: ostap

When is comes to security for mobile platforms, there is a very serious learning curve to getting it right and keeping it strong. Mobile Security Will (Probably) Always Be More Difficult Every day that goes by, mobile devices are getting smaller, sleeker, and more powerful, and to some people out there, that just means the they are new and vulnerable. This is a huge problem considering the rate at which people are acquiring smart phones for personal and business use, which also tend to hold sensitive data. Large corporations are steadily gaining the power to do something about the situation, and most are taking advantage. Many products have come out lately that allow these corporations to monitor the mobile devices given to their employees for business use. Most also allow administrators to delete/block unwanted applications, block malicious incoming data, and disable the device completely. This is fantastic for new phones and ones that haven’t been compromised yet, but what about the ones that aren’t so lucky? According to Lookout, a leading mobile security firm, mobile botnets are going to be one of the biggest problems for mobile platforms in the coming year. In fact, some of these have already been created, like the DroidDream scam that was removed from the marketplace not too long ago. One issue that I always like to bring up when talking about mobile security is the universal fragmentation of the world of Android, which is a huge part of the reason attacks like DroidDream can occur. The vast majority of the Android enabled devices out in the market right now are 2-3 OS releases behind, which poses a huge security threat whether your phone is actively tracked by a company admin or not. There will always be third-party solutions for fighting off attacks, but the issue will not be resolved until the Android (and is some ways, Apple) actually does something about it.

Originally posted here:
Mobile Security Will (Probably) Always Be More Difficult

Category: Uncategorized |  Comments off
Widespread Xbox Live phishing scams plague gamers
Monday, December 05th, 2011 | Author: zyfjxm

Users of the popular online gaming service have been getting phony emails from sites claiming to give away Microsoft points (the online currency for Xbox Live). Widespread Xbox Live Phishing Scams Plague Gamers These emails are made to look very official and many unwary consumers have been getting dragged in to the scam. These emails redirect to these sites where people are asked to enter sensitive information that can be used to purchase more points. Many users have been making reports of checking their bank statements and finding many charges on these cards that they did not make. The transactions are generally very small and they victims don’t actually notice until it has already been going on for some time. This is apparently not the first time something like this has happened with the service, as hackers have shown in the past to have multiple methods of getting customer information . While it is clearly wrong on the part of the cyber-criminals to participate in these activities in the first place, it is also the victims fault in this case. Unlike other, more direct methods of stealing customer information, such as directly from a database, this method requires the customer to give away their info. So, what that means is that any savvy user can avoid such situations by simply paying attention to what they are doing. DO NOT GIVE YOUR INFORMATION AWAY TO STRANGE WEBSITES. This is something every company offering web services should remind their customers just to make sure that they are safe. As these customers have trusted the companies to protect their information, their should actually be a little effort on both sides. However, if you or anybody you know has already been affected by these scams, go here to the Xbox site to report the incident.

Excerpt from:
Widespread Xbox Live phishing scams plague gamers

Category: Uncategorized |  Comments off
  • cables
  • bright
  • dis 0 0.9
  • beamerbea france
  • chicago bears tattoos
  • la ink members
  • doble
  • connecticut lakes
  • chad ochocinco vs skip bayless
  • search in vi
  • chad ochocinco quickstep
  • assignment
  • hplc
  • randy moss yahoo stats
  • connecticut natural gas
  • vince young rumors
  • chad ochocinco and cheryl burke
  • search vim
  • paths
  • deerfield
  • cspan facebook
  • gifting
  • search engines internet
  • others
  • connecticut state parks
  • zara phillips queen elizabeth
  • cspan michelle bachmann
  • hp support driver downloads
  • breaking
  • dis tester
  • dis systems
  • chad ochocinco nascar
  • lebaron
  • cspan ap government review
  • zara phillips yachtzara phillips zimbio
  • litre
  • new england patriots 65
  • hp support quick test pro
  • battleship yamato wreck
  • tea party for kids
  • new england patriots store
  • beagle
  • bengals 09 record
  • relocation
  • gregg olsen books
  • collar
  • new england patriots underwear
  • hp support contact number
  • hp support greece
  • jars
  • search 78search 800 numbers
  • eaton
  • loveseat
  • dis poem
  • vince young uncle rico
  • chicago bears 08 record
  • burnt
  • greg olsen twitter
  • connecticut food bank
  • la ink youtube pixie
  • batter
  • vince young yahoo stats
  • search engines images
  • randy moss college
  • hp support monitors
  • greg olsen dustin keller
  • bea oracle
  • battleship vittorio veneto
  • search engines watch
  • search engines for jobs
  • la ink phone number
  • search 5500
  • discjuggler
  • zara phillips youtube 2009
  • battleship egg hunt
  • zara phillips and the queen
  • hp support error 1005
  • new england patriots 80
  • battleship ipad
  • vince young 6
  • lancer
  • bengals games
  • gathering
  • coated
  • hp support hard drive replacement
  • cubby
  • header
  • bengals arrests
  • dilemma
  • search engines for jobs
  • hp support number united states
  • battleship lexington
  • maja
  • crab
  • c span video contest
  • la ink bob tyrrell
  • c span youtube obama
  • new england patriots jake locker
  • surfboard
  • search xml file
  • azerbaijan
  • di's hallmark
  • lenscrafters
  • tea party zombies download
  • salsa
  • search engines usage statistics 2010
  • greg olsen puzzles
  • bengals record 2010
  • freida pinto miral
  • greg olsen website
  • connecticut airports
  • tea party agenda
  • soffit
  • mtv 25 lame
  • greg olsen no greater love
  • curtis
  • search 990 finder
  • search optics
  • new england patriots 98.5
  • pore
  • connecticut lottery
  • hp support center
  • creation
  • greg olsen boulder
  • connecticut post
  • removing
  • search engines non tracking
  • dis boards cruise
  • bengals new uniforms 2012
  • c span ii
  • chicago bears posters
  • bea per capita income
  • bea test
  • hp support englandhp support forum
  • chad ochocinco bears
  • bengals football
  • hp support 6500a plus
  • connecticut department of labor
  • chicago bears 09 draft
  • new england patriots 07
  • chicago bears pictures
  • battleship 1967
  • greg olsen mormon
  • connecticut 7 day weather forecast
  • cemetery
  • battleship galactica
  • treat
  • zara phillips guest list
  • wagons
  • chad ochocinco sisterchad ochocinco twitter
  • spire
  • chad ochocinco traded
  • chicago bears 17 lisa lampanelli
  • expedition
  • tea party young people
  • la ink season 5
  • zara phillips engagement ring
  • scrub
  • la ink upcoming episodes
  • rash
  • damascus
  • la ink ink
  • battleship layout
  • holly
  • volusia
  • bengals qb situation
  • lite
  • bengals andy dalton
  • bea zuberbühler
  • bea binene
  • pursuit
  • tea party obama
  • battleship excel
  • tea party birthday
  • bengals undraftedbengals vs steelers
  • search jail inmates
  • freida pinto can't act
  • elder
  • chad ochocinco wedding date
  • rearend
  • search domains
  • mtv cartoons
  • garlic
  • la ink price list
  • straw
  • disks
  • freida pinto 1995
  • tea party medicare
  • connecticut law tribune