Microsoft Plugs Internet Explorer Security Hole (Which was Exposed in A Contest)


Microsoft last week patched the last vulnerability in Internet Explorer (IE) used by a researcher in March to win $15,000 at the
The company had patched IE twice before to quash bugs exploited by Stephen Fewer of Harmony Security to bring down IE8 on Windows 7 at Pwn2Own. For his efforts, Fewer was awarded a cash prize of $15,000 and a Sony notebook.

Microsoft internet explorer Fewer chained three exploits , each for a different vulnerability, to bypass IE's sandbox, called "Protected Mode," and compromise IE8. Pwn2Own sponsor HP Tipping Point called the feat "impressive" at the time.
Microsoft patched the third IE bug in a multiple-flaw update to its browser, part of a 13-bulletin collection .
Although Microsoft credited Fewer in the MS11-057 bulletin for reporting the third vulnerability, it said the bug wasn't a security flaw. "Yes, this update addresses a Protected Mode bypass issue, publicly referenced as CVE-2011-1347," Microsoft said in response to an FAQ query, "Does this update contain any non-security related changes to functionality?"
At Pwn2Own, Fewer used the bypass bug to escape Protected Mode so he could circumvent the browser's sandbox, which allowed him to add a file to the machine, a task that mimicked a hacker's insertion of malware.

Fewer confirmed that last week's IE update fixed the final flaw he used at Pwn2Own.
"Yes MS11-057 patches the final bug, the protected mode bypass, that I used in my Pwn2Own exploit, the other two being a use-after-free which was patched in MS11-018 and an information leak patched in MS11-050," Fewer said today in an email reply to questions.

Earlier Flaws Addressed

MS11-018 and MS11-050 were the designations of the April and June bulletins, respectively, that patched the two other vulnerabilities he reported to Microsoft via Tipping Point's bug bounty program.
According to Aaron Portnoy, manager of TippingPoint security research team and the company's Pwn2Own organizer, Tuesday's IE update wraps up patching for the 2011 contest.
During Pwn2Own, Microsoft said that IE9, the browser that launched shortly after Fewer's hack, did not contain the bugs he exploited.
Including Tuesday's update, IE9 has been patched twice since its March launch. Of the August bugs Microsoft acknowledged as security issues, one was reported by Fewer.
"Yes, I have been doing some research into IE9 and actually my first IE9 vulnerability was also patched this Tuesday as part of MS11-057," Fewer said, referring to a separate bug he was credited with this week.
That flaw, dubbed "CVE-2011-1964," was reported via TippingPoint to Microsoft in May, and was ranked critical for IE9 when run on Vista or Windows 7.
Fewer wouldn't commit to taking on IE9 at next year's Pwn2Own, but he left the door open to a repeat performance. "I don't have any plans as of yet for next year's competition, but if I have a few new bugs handy closer to the time, who knows?"
August's security updates, including MS11-057 for IE, can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

-News Source (PC-World)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Mac OS X Lion Said Good-Bye to Analog Communications (Modem)


Mac OS X Lion has killed off a number of things including, but not limited to Rosetta, visible scrolls bars, Quicken (see Rosetta), and unnatural scrolling. Now another casualty is the venerable analog modem.
According to users on MacRumors Forums it is true that Apple has killed off support for the analog Apple USB Modem in Mac OS X Lion since the device is no longer working after they upgraded from Mac OS X Snow Leopard.
When you will try to plug your Apple USB Modem into an available USB port on your iMac and MacBook Air (both running Mac OS X Lion) we will receive the following error message.
"You can not use Apple usb Modem withn this computer"
The problem is being blamed on two issues: the required modem drivers are missing and the drivers only work when your Mac kernel is running in 32-bit mode. Since Lion generally runs in 64-bit kernel mode by default the drivers will not work unless you boot your machine into 32-bit mode. A lively discussion about 32 vs. 64-bit mode can be found here.
The forum discussion included a work around that required modification of your system files and instructions on starting your Mac in 32-bit kernel mode. Unfortunately at press time I wasn’t able to get the suggested work around to work on either of my Macs.
One person, HellDiverUK, on the forum made a comment that I can agree with when they asked, “Modem?” followed by “Last millennium is calling, it wants its outdated technology back. ”  We think Apple agrees and that they are telling you that it looks like it is time to say good-bye to the analog modem and look to alternatives like encrypted email, zip files, PDFs, or secure FTP.

For more information and help to resolve this click Here

-News Source (Culture Of Mac)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Cyber Army India Facebook Page Hacked Albanian Hacker


Cyber Army India, official Facebook Page Hacked by Albanian Hacker. They also gave message to Indian Hackers...

"Albanian Hackers Are Here !
India Cyber Army Respect Brothers !
But Next Time Be More Careful !
Peace From Albania !

Writed By : !.. Toni AHG ..!..DriLoN Alla .. !"


Hacked FB Page:-
http://www.facebook.com/www.cyberarmy.in



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Punjab University of Agriculture Website Hacked By ZHC


Punjab University of Agriculture official website Hacked and defaced by ZCompany Hacking Crew (ZHC)

Hacked Site:-

Mirror  Link:-

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Cybertek Web-Server Rooted, More Than 50 Domains Hacked By TGH


The Web-server of Cybertek rooted, more than 50 domains defaced by ErroR of Team Greyhat (TGH)

Hacked Sites:-


Mirror Links:-


Fore More Information and to See the Official Press Release of TGH Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook CEO Mark Zuckerberg's Sister Said 'No more anonymous on Internet'

The sister of Facebook CEO Mark Zuckerberg wants to put an end to online anonymity. She wants to force people to use their real names at all times on the Internet.
Randi Zuckerberg, who is Facebook's marketing director, believes users would act much more responsibly on the Internet if real names at all times were compulsory. Her remarks recall  the tangle that Google+, Facebook's fledging rival, got into the other week as it enforced its own real names policy.
Randi Zuckerberg was speaking during a presentation hosted on Tuesday by Marie Claire magazine on cyberbullying and social media. She said the use of real names online could help curb bullying and harassment on the web.

"I think anonymity on the Internet has to go away... People behave a lot better when they have their real names down. ... I think people hide behind anonymity and they feel like they can say whatever they want behind closed doors."
She added, "There's so much more we can do...We're actively tying to work with partners like Common Sense Media and our safety advisory committee."
Five months ago, Facebook, which requires all members to use their real names, announced new safety resources and tools for reporting issues, in conjunction with a White House summit for preventing bullying. Four months ago, the company rolled them out.
Christopher Poole, founder of 4chan, is however a defender of anonymity on the Internet , as ZDNet reports.
With anonymity, users can employ what Poole calls “fluid identity." He explains,  "Where there's no risk of failure, experimentation flourishes. On websites that require you to login via Facebook, the cost of failure is really high because you’re contributing as yourself. As a result, mistakes are attributed to who you are.

"I believe real names should only be required in scenarios where your actions can hurt others; in other cases, anonymity is just fine."

-News Source (The Drum & Social-network UK)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

50 More Indian Websites Hacked BanneD™ And <=Shak=> (PCA)


15th August id over but still the Cyber-War is on. 50 More Indian Websites Hacked By BanneD™ And <=Shak=> of PCA (Pakistan Cyber Army). The attacker shows Pakistani Flag, as a big birthday Gift to All Pakistani Hackers at The End Of 15 August.

List of Hacked Sites:-
http://pastebin.com/W54zsV14

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...