Category Archives: Threats, Vulnerabilities, Attacks

Michael Howard from Microsoft Analyzes Recent Symantec and IBM Vulnerabilities

One of main persons behind Microsoft SDL, Michael Howard analyzes recent Symantec and IBM Vulnerabilities in his post on MSDN SDL blog. Michael says: The vulnerabilities are not in Symantec code, yet Symantec customers are still open to attack. The … Continue reading

Share
Posted in Software Security, Threats, Vulnerabilities, Attacks | Tagged , , , , , | Leave a comment

Poll – Hacking Motives

I’ve put poll on this blog to find out what is public opinion on primary motives for hacking.  There are six possible choices and you can choose one according your opinion. Answers are based on Australian government Institute of Criminology i.e. … Continue reading

Share
Posted in Polls, Security, Security Research, Threats, Vulnerabilities, Attacks | Tagged , | 9 Comments

Is Windows Live Messenger Trojan

ZoneAlarm by Check Point, firewall, antivirus and antispyware is tool that I use for quite some time on one of my computers. It offered update to new version 7.0.462.000 today. After installation and starting antispyware scan it detected and considered Windows Live … Continue reading

Share
Posted in Malicious Software, Operating Systems and Application Security, Threats, Vulnerabilities, Attacks | Tagged , , , , , , , , | Leave a comment

Thoughts on Threat Modeling

An excellent series of blog posts by Microsoft’s Larry Osterman about threat modeling with links to all 13 posts is here. Someone who signed comment as Bill Gates (it might be real Bill?) wrote: Larry, keep up the good work, I … Continue reading

Share
Posted in Security Research, Threats, Vulnerabilities, Attacks | Tagged , , , , , | Leave a comment

Does an Expert Need Antivirus Software?

This is a very interesting question that Steve Riley talked about in recent post on his blog (here). And of course, a number of people have asked him if he is recommending such a stance to other individuals or to … Continue reading

Share
Posted in Malicious Software, Threats, Vulnerabilities, Attacks | Tagged , , , , , , | Leave a comment

Malicious Software: Today’s Most Prevalent Threats

Mark Kanok from Symantec put interesting post titled Detection and Remediation on Symantec official blog. It contains updated definitions of some of today’s most prevalent threats: Backdoors — A backdoor is an undocumented way of gaining access privileges to a … Continue reading

Share
Posted in Malicious Software, Threats, Vulnerabilities, Attacks | Leave a comment

Security Developer Center: Threat Modeling

Microsoft Application Threat Modeling is a critical security activity, enabling effective application risk management during the SDLC and beyond. Application Threat Modeling is enforced as part of the Security Development Lifecycle for IT (SDL-IT) at Microsoft. Boeing develops their line … Continue reading

Share
Posted in Operating Systems and Application Security, Secure Programming, Threats, Vulnerabilities, Attacks | Leave a comment

Harry Potter 0day

Someone claims to have hacked the Bloomsbury Publishing network, and has posted what he says is the ending to the last Harry Potter book: The attack strategy was the easiest one. The usual milw0rm downloaded exploit delivered by email/click-on-the-link/open-browser/click-on-this-animated-icon/back-connect to … Continue reading

Share
Posted in Fun, Threats, Vulnerabilities, Attacks | Leave a comment

WordPress AndyBlue Theme URL Cross-Site Scripting

There is new challenge for us who use WordPress as blogging tool. According Secunia, a new vulnerability in the AndyBlue theme for WordPress has been discovered. It can be exploited by malicious people to conduct cross-site scripting attacks. Input passed … Continue reading

Share
Posted in Internet Security, Threats, Vulnerabilities, Attacks | Leave a comment