Showing posts sorted by date for query Skype. Sort by relevance Show all posts
Showing posts sorted by date for query Skype. Sort by relevance Show all posts

Skype Vulnerability Reveals User IP Addresses

Skype Vulnerability Reveals User IP Addresses

If you are a Skype user then both your IP address and location can be determined or in other word can easily be revealed. According to a blog post, a modified version of the Skype VoIP software can be used to easily find out the IP address of any valid Skype user. No contact has to be made with the user in order to get the information. This IP could then be used to find out other personal details about the user, such as their location or even their employer. The process only works if the other user is online. The only method of protecting against this is to log off of Skype when you're not using it, or ot use a virtual private network to hide the IP address. The IP address doesn't give up a person's name or other specific information, but it does provide information on the country, and in some cases city, of origin. Last week, someone posted a an exploit of that vulnerability within the Skype network on Pastebin, providing details of how to download a modified or patched version of Skype 5.5 that would allow the exploit to be run.  "Claudius," a community manager on the Skype forums, said that Microsoft was aware of the issue. "Hello, yes, our security experts are aware of it and looking into it already," he posted Monday morning.
Microsoft said - "We are investigating reports of a new tool that allegedly captures a Skype user's last known IP address, a Skype representative said in an emailed statement. "This is an ongoing, industry-wide issue faced by all peer-to-peer software companies. We are committed to the safety and security of our customers and we are takings measures to help protect them." 



 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Planned To Release Skype Application For Windows Mobile

Microsoft Planned To Release Skype Application For Windows Mobile
Microsoft Corporation has planned to release Skype video-calling application for its Windows Phone. The application will be avalable on April this year. Terry Myerson, head of the Redmond, Washington-based company’s mobile business, said in an interview last week. It will unveil the software today at the Mobile World Congress in Barcelona, Spain, and release a version for beta testers. Terry Myerson, head of the Redmond, Washington-based company’s mobile business, said in an interview last week. It will unveil the software today at the Mobile World Congress in Barcelona, Spain, and release a version for beta testers.
Microsoft bought Skype to gain customers and enhance its existing products -- such as Windows phones and Xbox game consoles, along with Internet-calling and videoconferencing software. Skype customers made more than 300 billion minutes of calls last year, Microsoft Chief Executive Officer Steve Ballmer said in January. The service, which handles both voice and video calls, is the top provider of international calling. Windows Phone has just 2 percent of the mobile operating- system market, and lags behind Apple Inc. and Google Inc. in providing apps. Both those rivals already have Skype apps.
Microsoft bought Skype to gain customers and enhance its existing products -- such as Windows phones and Xbox game consoles, along with Internet-calling and videoconferencing software. Skype customers made more than 300 billion minutes of calls last year, Microsoft Chief Executive Officer Steve Ballmer said in January. The service, which handles both voice and video calls, is the top provider of international calling.
Windows Phone has just 2 percent of the mobile operating- system market, and lags behind Apple Inc. and Google Inc. in providing apps. Both those rivals already have Skype apps.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI Is Paying Attention To The US-China Commission Data Breach Issue



US-China Commission Data Breach issue is again on high node. Now Federal Bureau of Investigation (FBI) is investigating claims made by an Indian computer hacking group that India’s intelligence services intercepted the communications of the US-China Economic and Security Review Commission.

The documents posted on the Internet about a month ago and allege to be from the Indian government’s Directorate General of Military Intelligence and include about 10 emails from the Congressionally mandated Commission from September and October 2011. The commission reports to Congress annually on national security, trade and economic issue with China.

The Commission released their annual report to Congress in November 2011 this year. One federal law enforcement official indicated that the Indian government may have been snooping for early details on the assessments of the Commission if the documents are genuine.
While the emails do appear to be genuine the document has not been authenticated. Emails and phone calls made to the Indian embassy in Washington were not returned on Wednesday.
The alleged Indian military intelligence memo can be found Here
Though An FBI spokeswoman declined to comment on the investigation. The documents include an e-mail received by Michael Danis, the Commission’s executive director concerned General Electric’s business and joint ventures in China. The documents posted on the Internet were allegedly obtained by a group called the Lords of Dharamraja which has also compromised the source code on Symantec’s popular Norton antivirus software.
The document that is allegedly from the Indian intelligence service claims that the emails were obtained by using backdoors from mobile device manufacturers Apple, Research in Motion and Nokia. In the United States the Communications Assistance for Law Enforcement Act mandates that the FBI and police must have “backdoor” access to phone and internet communications with a lawful court order. The Bureau has been pushing for expanded surveillance powers with new technology such as Skype and Twitter in what they have termed their “Going Dark” program.
The inquiry into the data breach at the Commission follows the disclosure last month that China had infiltrated the US Chamber of Commerce computer system targeting the work by the Chamber’s Asia policy analysts.


-Source (ABC News)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

XSS Vulnerability In Google Earth, Said Kyle Osborn At TakeDownCon Security Conference



Security researchers have shown that relying on browser technology in mobile apps—and even some desktop apps—can result in hidden vulnerabilities in those applications that can give an attacker access to local data and device features through cross-site scripting. At TakeDownCon security conference in Las Vegas, researcher Kyle Osborn presented some examples of cross-site scripting attacks that he and colleagues have discovered on mobile devices. "XSS is generally considered to be a browser attack,"  But many applications, he said, such as those built with cross-platform mobile-development tools like PhoneGap, use HTML rendering to handle display of data. If applications aren't properly coded, it's possible for JavaScript or other web-based attacks to be injected into them through externally-provided data. "Often, there are times when you can just make a JavaScript request and pull files from the local filesystem," he said.
The most recent example Osborn found is a vulnerability in the Google Earth app that allows execution of arbitrary JavaScript code on the device by embedding script in location data. He says that the flaw has been reported to Google.
Osborn said other vulnerabilities that have been discovered, and that in most cases have now been patched, include Skype on Apple's iOS and Gmail on Android and iOS. The vulnerabilities aren't limited to mobile platforms—many desktop applications that use Webkit or another web rendering engine have also had issues, Osborn said. The Skype vulnerability was originally discovered on Mac OS X, and similar bugs have been discovered and patched in the Adium instant messaging client on OS X and Empathy social networking client on Ubuntu.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype Security Flaws Caller Location Can Easily Be Exposed


Recently Researchers at the Polytechnic Institute of New York University found a serious security hole in Skype which may expose a user’s location by revealing their Internet Protocol address. Researchers initiated video calls to 10,000 randomly selected Skype users and discovered that even when a recipient does not accept the incoming call, the user’s Internet Protocol, or IP, address can still be vulnerable to theft.
Armed with an IP address, hackers can uncover specific information about victims, including who they chat with, what they download while online, and in many cases, their zip-code specific location. 
For example, the researchers were able to track one Skype user through three different cities during the experiment. The ability to keep tabs on a user may be an immediate nuisance, but the larger implications are alarming. Criminals, terrorists, and hackers may use the security flaw to glean locations of government officials, corporate leaders, politicians, and celebrities.
Computer science professor and study researcher Keith Ross told that, “Any sophisticated high school or college hacker could easily do this,” and emphasized that “the findings have real security implications for the hundreds of millions of people around the world who use VoIP or P2P file-sharing services.”
Skype, recently owned by Microsoft, boasts 171 million registered users around the world, who may wonder how such a major security flaw escaped notice. Previously lost of vulnerability has been found on Skype related with androidFacebook and also there was XSS flaws many more
Skype Tuesday said it will address the issue. “We value the privacy of our users and are committed to making our products as secure as possible,” said Adrian Asher, chief information security officer for Skype. “Just as with typical Internet communications software, Skype users who are connected may be able to determine each other’s IP address. Through research and development, we will continue to make advances in this area and improvements to our software.”




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Spyware, Trojans Exploits iTunes & Gaining Access To Computers


A remote monitoring software" developed in Germany is designed to exploit a vulnerability in iTunes in order to infect target computers. An IT monitoring company advertises its ability to distribute spyware software for government agencies using fake iTunes updates. Apple iTunes has been rectified and closed a security hole. The exploit in question relies on the fact that, assuming Apple Software Updater is not active, iTunes uses an unencrypted HTTP request to query for the URL for the latest version of the program from the Apple server. Because the query is unencrypted, this URL could be modified. If a user were to respond to an iTunes update message, they could then be taken to a crafted web page intended to install the "remote monitoring tool" onto their computer. For the redirection to work, however, a Gamma customer would need to be able to actively interfere with the network, limiting its use to entities such as ISPs acting under government orders.

iTunes update to play Trojans :-

Unlike their Italian rivals of the company hacking team, which campaigned in Berlin also to new customers, the gamma-people even ensures that journalists had to leave before the presentation of their "Managing Directors" the hall. The fear has obviously good reasons: Gamma seems to operate at FinFisher dubious methods - that suggests marketing material SPIEGEL has obtained. After that, the authorities offered and government software works similarly to that of computer criminals who should be fought with it.
Apparently, it is clear from FinFisher promotional videos, for example, the software uses Apple's popular iTunes media supermarket to load with a fake software updates FinFisher-sniffing software on the computers of suspects.

The demand for surveillance technology for the Internet, such as the Gamma International Ltd. and hacking demonstration team in Berlin and they peddled, has risen significantly in recent years internationally. Security agencies worldwide are faced with the problem that increasingly suspicious encrypted communication over the Internet. Agreements, the suspects met earlier on relatively simple to intercept landline telephones or mobile phones to run, now increasingly encrypted Internet telephony services like Skype or encrypted computer chat. Authorities often get only with how to arrange suspects via cell phone to the next encrypted chat.
This issue promises companies like Gamma International Ltd. and hacking team to solve. However, this kind targeted surveillance measures are not easy to implement: Listening encrypted communication is only possible if it occurs before encryption. This software must be installed, the conversations, emails or chats ausleitet unnoticed on the computers of suspects - unencrypted to the security authorities. In plain English: the authorities have to hack into the computers of suspects. 


-News Source (Spiegel Online)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Mozilla Firefox 8 Released With More Add-on Control Features


Mozilla announced today the official release of Firefox 8, a new version of the popular open source Web browser. The modest update introduces a few new features and brings a number of minor improvements to the browser’s underlying HTML renderer. From version 8, when Firefox launches and detects that a new third-party add-on has been installed, the add-on will be disabled by default until approved by the user. When users upgrade to Firefox 8, they will be presented with a one-time dialog for approving previously installed add-ons. Another noteworthy user-facing feature in Firefox 8 is stricter control over side-loaded add-ons. Mozilla is cracking down on third-party applications that install add-ons in Firefox without the user’s knowledge or permission. Such add-ons have caused serious problems for users in the past—like the notoriously buggy Skype toolbar which Mozilla had to remotely disable earlier this year when it caused 33,000 Firefox crashes in one week.


To Download Firefox 8 Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Finally Completed The Skype Deal For $8.5 Billion

Microsoft said late on Thursday that it has completed its deal to acquire Internet calling leader Skype for $8.5 billion. With the closing of the deal, which was announced back in May, Skype will become a new business unit within Microsoft, with Skype CEO Tony Bates becoming the president of the newly created Skype division. Over time, Microsoft said, it will integrate Skype into a variety of its products.
“By bringing together the best of Microsoft and the best of Skype, we are committed to empowering consumers and businesses around the globe to connect in new ways,” Bates said in a statement. “Together, we will be able to accelerate Skype’s goal to reach 1 billion users daily.”


-News Source (Microsoft, AllthingsD, Skype)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

"0zapftis" or "R2D2"(Backdoor Trojan Horse) Discovered By Chaos Computer Club (CCC)

The famous Chaos Computer Club (CCC) has announced the discovery of a backdoor Trojan horse capable of spying on online activity and recording Skype internet calls which, it says, is used by the German police force. The malware - which has been variously dubbed "0zapftis", "Bundestrojaner" or "R2D2" - is likely to kick up a political storm, if the allegations are true.

For some years, German courts have allowed the police to deploy a Trojan known colloquially as "Bundestrojaner" ("Federal Trojan") to record Skype conversations, if they have legal permission for a wiretap.
A CCC spokesperson expressed the group's concern at the discovery:-
"This refutes the claim that an effective separation of just wiretapping internet telephony and a full-blown trojan is possible in practice – or even desired. Our analysis revealed once again that law enforcement agencies will overstep their authority if not watched carefully. In this case functions clearly intended for breaking the law were implemented in this malware: they were meant for uploading and executing arbitrary code on the targeted system."
But the CCC's claim is controversial, as the Trojan they have uncovered has more snooping capabilities than that. For instance, it includes functionality to download updates from the internet, to run code remotely and even to allow remote access to the computer - something specifically in violation of Germany's laws.

Functionality:-
  • The Trojan can eavesdrop on several communication applications - including Skype, MSN Messenger and Yahoo Messenger.
  • The Trojan can log keystrokes in Firefox, Opera, Internet Explorer and SeaMonkey.
  • The Trojan can take JPEG screenshots of what appears on users' screens and record Skype audio calls.
  • The Trojan attempts to communicate with a remote website.


-News Source (NS & CCC)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

XSS Vulnerability on Skype Allowing Attacker To Steal Address Book


A Cross-Site Scripting vulnerability exists in the "Chat Message" window in Skype 3.0.1 and earlier versions for iPhone and iPod Touch devices. Skype uses a locally stored HTML file to display chat messages from other Skype users, but it fails to properly encode the incoming users "Full Name", allowing an attacker to craft malicious JavaScript code that runs when the victim views the message. Executing arbitrary Javascript code is one thing, but I found that Skype also improperly defines the URI scheme used by the built-in webkit browser for Skype. Usually you will see the scheme set to something like, "about:blank" or "skype-randomtoken", but in this case it is actually set to "file://". This gives an attacker access to the users file system, and an attacker can access any file that the application itself would be able to access.
File system access is partially mitigated by the iOS Application sandbox that Apple has implemented, preventing an attacker from accessing certain sensitive files. However, every iOS application has access to the users AddressBook, and Skype is no exception. I created a proof of concept injection and attack that shows that a users AddressBook can indeed be stolen from an iPhone or iPod touch with this vulnerability.

Here is a Video Which Will Guide you about the Vulnerability:-




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Nokia developer Forum Hacked By pr0twctor & Later Nokia Decided To Shut Down Their Developer Forum Temporally


Nokia developer site  hacked and defaced by pr0twctor AKA mrNRG. After this phenomena Nokia decided to shut down their  developer forum temporally. 
Developers of apps for Nokia phones have been warned that their personal information may have been stolen by hackers, after a security breach on the official developer.nokia.com/community discussion forum.
The first warning that many Nokia developers would have had that something was amiss would have been when they visited the forum and instead of the usual chit-chat about technical issues, been taken to a third-party webpage containing an image of Homer Simpson

The web-page contained a message seemingly from those responsible for the hack:-
Owned by pr0tect0r AKA mrNRG
LOL. Worlds number 1 mobile company but not spending a dime for server security! FFS patch you security holes otherwise you will be just another antisec victim. No Dumping, No Leaking!
According to the Finnish telecoms giant, hackers exploited a SQL injection vulnerability in the forum software used on the Nokia Developers site to access databases containing members' email addresses and (in some cases) birth dates, and usernames for AIM, ICQ, MSN, Skype or Yahoo.
Passwords and credit card information is not believed to have been exposed - which is a relief for affected members and must be causing a sigh of relief inside Nokia.


-News Source (Naked Security)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype 5.3 Client Released for Apple Mac OS X Lion



(VoIP) outfit Skype has updated its client software for Apple Mac users to version 5.3, which brings support for Mac OS X 10.7 Lion. The latest version of the internet chat software provides a number of fixes and improvements to the interface according to Skype. It also includes support for high definition (HD) video calls, provided you have an HD webcam.
"On the heels of our recent update to Skype 5.2 for Mac OS X, we are pleased to announce that we are making even more improvements to our Mac client with the release of Skype 5.3 for Mac OS X."

It's been just over a month since Skype launched version 5.2. If you haven't got Mac OS X Lion, the latest version of Apple's operating system, then Skype 5.3 is compatible with older versions going back to Leopard.
Other features of the software include group video calling and group screen sharing, for an extra cost. Skype recently made a deal with Microsoft and Facebook has integrated Skype into its social networking web site for video chat. Meanwhile, Windows users are up to Skype client version 5.5, which includes instant messaging to Facebook friends.


To see the Skype blog statement click here
To download Skype for MAC click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype & Facebook Integration=Critical Security Vulnerability Can Compromise Your System

 
Skype’s integration with Facebook is being touted as “the best of both worlds” but the new Skype 5.5 for Windows update contains a highly-critical security flaw that allows Skype session hijacks or even full system compromise.
The vulnerability surfaced after David Vieira-Kurz posted the proof of concept video above to the Secalert website. Apparently, he had "found a few security issues which makes it possible to hijack a Skype Session and compromise a user's system due to a lack output sanitization."  According to an advisory posted at secalert.net, an attacker can exploit a system even if the victim is not a Facebook friend or a Skype contact.
The Skype security blog has not yet acknowledged the flaw.
 
The Following Video Will Clarify the Entire Matter:-  
 

 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype 5.5 (With Deeper Facebook Integration)


Skype has released the latest update to its online calling software for Windows, offering more options for Facebook users.
Officially out of beta since Wednesday, the latest Skype 5.5 for Windows lets you check which of your Facebook friends are online and available to chat, all without having to leave Skype. Simply clicking on the View menu in the Skype software and then choosing Facebook Friends shows you the list.
By clicking on and then closing the Skype Home screen, you can also update your Facebook status and scroll down to view your entire Facebook wall.
Beyond the Facebook integration, Skype says that its latest version offers improved controls for video and group calls for Windows, better call reliability, and various design changes in the interface.
Once it was installed, you will be able to use Skype 5.5 to view online Facebook friends, access wall, and post status updates just as easily as one could in Facebook.

To Download Skype 5.5 click Here
For More information about Skype 5.5 click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec Spokesman Busted By Scotland Yard


Scotland Yard's cybercrime unit has arrested a teenager it suspects of working as the spokesman for the Lulz Security hacking collective, officials said Wednesday.
The Metropolitan Police's Central e-Crime Unit arrested a 18-year-old at an address in Scotland's remote Shetland Islands, the force said in a statement. His name wasn't released, but police said he was believed to be "Topiary," one of LulzSec's most prominent members.
Police originally gave his age as 19 but later issued a correction. 
LulzSec shot to prominence in May with attacks on the US Public Broadcasting Service - whose website it defaced by posting a bogus story claiming that the late rapper Tupac Shakur had been discovered alive in New Zealand.
The group is a spin-off of Anonymous, an amorphous collection of Internet enthusiasts, pranksters and activists whose targets have included the Church of Scientology, the music industry, and financial companies including Visa and MasterCard.
Topiary was linked to both groups, serving as the on-again, off-again media liaison for the publicity-hungry hackers.
In his only known television interview, on the "David Pakman Show" earlier this year, Topiary phoned in via Skype to feud with Shirley Phelps-Roper of the Westboro Baptist Church, a Kansas-based group notorious for picketing the funerals of slain American soldiers.
Anonymous vandalised the church's website live over the course of the interview.
In conversations with The Associated Press, Topiary said he controlled LulzSec's Twitter feed, which garnered some 300,000 followers over the course of its six-week-long Internet rampage.
LulzSec has claimed responsibility for breaches at pornography websites, gaming companies, and law enforcement organisations. It's also claimed credit for harassing seemingly random targets including an obscure New Jersey-based magnet manufacturer.
One its most spectacular hacks was against Sony Pictures Entertainment. The group posted the usernames, passwords, email addresses and phone numbers of tens of thousands of people, many of whom had given Sony their information for sweepstakes draws. Another stinging series of breaches last month targeted Arizona's police force in protest against its contentious immigration law. Officers had to scramble to change their numbers because their phones were being jammed with calls.
Shortly thereafter the group abruptly announced it was disbanding, although Topiary said at the time that the group wasn't bowing to police pressure.
"We're not quitting because we're afraid of law enforcement," he said in a Skype call. "The press are getting bored of us, and we're getting bored of us."
Attempts to reach Topiary since then have been unsuccessful, although his group recently re-emerged from retirement, defacing The Sun newspaper's website with a fake story claiming that media tycoon Rupert Murdoch had died. In one of its last messages, LulzSec said it was working with unnamed media outlets on a WikiLeaks-style release of emails it claimed to have stolen from the tabloid.
Topiary's once-plentiful Twitter feed was practically wiped clean Wednesday. The only remaining post, from nearly a week ago, read: "You cannot arrest an idea."
The latest arrest is one of an increasing number claimed by law enforcement in Britain and the United States in connection to their investigations into Anonymous and its offshoots. Last week, the FBI, British and Dutch officials carried out 21 arrests, many of them related to the group's attacks on Internet payment provider PayPal Inc., which has been targeted over its refusal to process donations to WikiLeaks.
Last month another 19-year-old, Ryan Cleary, was charged with attacks on Britain's Serious Organized Crime Agency and various UK-based music sites. Although at least one of the attacks he was charged with seemed linked to LulzSec, Topiary claimed at the time that Cleary was at most only tangentially involved with the group.
Scotland Yard said Wednesday it was also searching a residential address in Lincolnshire, in central England, and interviewing an unnamed 17-year-old in connection with the investigation. The second teen has not been arrested.

-News Source (IBN)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Linvo Linux 2010.12.6.


A new distribution flew onto my radar today and it might be interesting to take a quick look. Linvo is a Bulgarian hailed distribution based on Slackware featuring the GNOME 2.32 desktop. Yesterday, developers released Linvo 2010.12.6.
According to the Official Website of Linvo:-

Why Linvo?

● Out-of-the-box experience
● Functionality
● Software support and installation
● Easy to configure
● Live CD
● Full multimedia support
● Compatibility
● Security and stability
● Easy to use, fast and beautiful desktop!
● Only platform-independent and function-rich applications
● Innovations that improve security, practicability and speed
● Absolutely free and open source

For new distributions especially it's an advantage to ship as a live CD/DVD and Linvo does just that. Most Slackware-based distros come as install images, so Linvo got bonus points before I even booted into the desktop. But it lost one because of being available just for 32-bit architectures.
Linvo ships with Linux 2.6.36, Xorg X Server 1.9.5, and GCC 4.5.2. A starter set of applications includes Biniax, GIMP, OpenOffice.org 3.2, Shotwell, Empathy, Gwibber, Skype, Chromium, Evolution, Brasero, Cheese, VLC, Rhythmbox, and lots of utilities such as a firewall configuration. Updates and additonal software can be installed using Gslapt with Linvo and Slackware repos. Even more applications can be installed from what some might call Linvo one-click installers on the Website. From the Website:
LinvoApp

This is the most distinctive feature of Linvo: the application management system. It allows you to:
● Multi-user, every system user can use different applications for himself
● Using applications from different kinds of media without needing installation
● Compared to other systems of that kind (for example, portableapps.org), LinvoApp does not require any special repackaging for the application to be converted into the required format
● Compared to systems like Slax's modules, LinvoApp works on an installed system rather than only on LiveCD and provides automatic dependency handling
● Synchronization with the website, an ability to restore your applications if any data loss occurs or if you install a different instance of Linvo; this is also usable if you need to synchronize a group of computers with the same selection of software (for example, in schools)
● An ability to personalize the Live CD
● Unbreakable upgrades between versions - applications and settings are (optionally) kept after reinstall, so it works as well as upgrade, only much more stable

The installer is quick and easy with just a few configuration questions. It worked well with no damage to my other partitions. The only complaint I have is that it didn't give me a choice about installing a bootloader. It installed GRUB seamlessly. I had a pretty bootloader that I liked, but Linvo's did pick up all my other installs and added them to the list. It's not very pretty though. But the Linvo desktop is quite pretty. It uses an attractive but unobtrusive window decoration and theme as well as a really pretty wallpaper. I haven't tested all the applications or spent lengthy time stress-testing Linvo, but what I've seen I like. I'm impressed. For a relative newcomer, it seems to be holding its own against any other 1-CD distribution.

 To Download Linvo click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype is Still Vulnerable

 
An Armenian hacker is claiming that Skype has failed to learn from prior security lessons, falling victim to a cross-site scripting (XSS) vulnerability similar to one it patched in May, which would allow users to redirect victims to unwanted websites or run arbitrary code.  The May vulnerability allowed users to fool the Mac client of Skype into running arbitrary code as the client didn't check, or sanitise, instant messages to ensure they were free of malicious code.

While Skype issued a low-priority patch at the time, a 28-year-old Armenian-based security engineer, Levent "noptrix" Kayan, claimed on Wednesday night that a similar XSS vulnerability existed elsewhere in Skype's software. He said that the failure to sanitise certain user information or the output rendered in Skype clients could still allow code to be executed.

In particular, Kayan claimed that he could see remote users' session information, which he said a malicious user could utilise to masquerade as the remote user and make calls on their account. He also said it could be used to take advantage of other holes, possibly allowing full control over the PC. Both of the latest versions of Windows and Mac clients are affected.
HE told that "An attacker would need to [submit] malicious code. The victim doesn't have to do anything. He will be attacked, when he just logs into his account."
Skype said the vulnerability was considered a minor issue and that it had developed a fix for it which would be deployed next week.
Skype's head of information security, Adrian Asher, said that in order to exploit this, a person would have to be a validated contact of yours and one of the most frequent people you are in contact with and was therefore very unlikely to cause any issues in the real world. Nevertheless, he said the vulnerability shouldn't have existed and it would be fixed.
Additionally, Skype said that the session information that Kayan had been able to access was in relation to the web session IDs and not Skype IDs, suggesting that the attacker couldn't make calls using the exploit. It did, however, concede that it was possible for a victim's contacts to redirect them to any website using the web browser built into the Skype client, but stressed that only validated contacts would be able to do so. In the meantime, it said users should not authorise people they do not know and/or do not want to talk to.
HackLabs director, Chris Gatford, said that it was common to come across these sorts of vulnerabilities in the work penetration testing of client systems his company does.
"I would suggest that 80 per cent, perhaps even 90 per cent of the time, cross-site scripting vulnerabilities are present," he said.
Gatford mentioned the previous XSS vulnerability in the Skype client and thought that it was surprising that Skype had not patched all of its input validation problems when it was previously brought to its attention. "This would be a simple fix for them. To be honest, I'm kind of surprised they didn't learn their lesson the first time and extend the fix system-wide then."

-News Source (ZDNet)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Skype 2.0 for Android Released and Also Hacked


It was only yesterday when Skype 2.0 for Android was released, but the latest version of the popular instant messenger has already been hacked to allow video calls to be made over Wi-Fi or 3G/4G using non-supported devices as well. Thanks to that, it is not only Google Nexus S, HTC Desire S, Sony Ericsson Xperia neo and Xperia pro owners who can enjoy Skype's newly-added and long-anticipated feature.
The hacked Skype 2.0 version has been intended to run on the Samsung Galaxy S II, and our test showed that it works without a hitch. However, the program has been successfully tried out on a number of other smartphones and tablets. So far, the list of devices that reportedly run the unofficial Skype

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Security Essentials is on the first place in North America



Microsoft (17.07 percent), AVG (15.63 percent), and Symantec (14.47 percent) were found to be the top three antivirus vendors in North America, according to the latest quarterly antivirus market share report released by OPSWAT. Microsoft increased its market share from OPSWAT's previous antivirus report to surpass Symantec and become the North American leader. AVG held steady in the second position, and Symantec fell to third.
Worldwide, the top three antivirus vendors detected were Avast (12.37 percent), AVG (12.37 percent), and Avira (12.29 percent). Microsoft was fourth (11.24 percent), followed by ESET Software (9.98 percent).
The software company analyzed more than 43,000 opt-in reports from endpoints worldwide. The reports, generated by OPSWAT's AppRemover and Am I OESIS OK? tools, utilize the detection capabilities of the OESIS Framework to list the applications installed on the endpoint computer. The full 8-page document, titled Q2 2011 Antivirus and Instant Messenger Market Share Report, includes data on the leading antivirus vendors and products in North America and worldwide, Windows OS usage in North America and worldwide, instant messaging market share worldwide, and instant messaging usage in North America and Europe.
The rest of the data wasn't too surprising: Windows 7 usage continues to increase in North America and worldwide, showing a steady trend away from Windows Vista. In both North America and worldwide, Windows XP remains the dominant Windows operating system. The top three worldwide IM applications are Windows Live Messenger, Skype, and Yahoo! Messenger. The report does not, however, account for Web-based instant messaging services such as Google Chat or Facebook. This is because it only looks at installed applications, and those services run in the browser.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Cybercrime can ruin the entire economies



Russian anti-virus guru Eugene Kaspersky does a quick calculation in his head as he blinks at the ceiling.Satisfied, he announces: "About 200000."

That's the number of virus-infected computers in a targeted attack on SA's internet infrastructure that would shut it off from the rest of the world. No e-mail. No electronic transactions. No web searches. No e-government. No Skype, Twitter or Facebook. Nothing.

He's not being alarmist - it happened in Estonia in 2007.
And 200000 rogue computers is not a huge number. Organised syndicates or loners with modest technical know-how and resources can harness millions of virus-infected machines they effectively control to add muscle to their efforts - from stealing money and identities to managing online corporate espionage or collapsing the infrastructure and function of a country's economy and government.
Kaspersky is CEO and founder of Kaspersky Lab, one of the world's top four anti-virus software companies and Europe's biggest. Worldwide, the software anti-virus industry is worth about $7-billion a year in profit for firms in the sector. His fortune is estimated at $800-million and Forbes rates him as Russia's 125th-richest person. He was in SA to talk to business executives and security experts about the rising cybercrime threat to business, governments and organisations of all types.
"There are literally millions of computer viruses in the wild," he says. "Last year alone we collected 20million of them. Most are variations on a theme and can be dealt with automatically in our labs. However, there are teams of experts at anti-virus organisations around the world that work against new threats round the clock. Once a virus is discovered, it can be reverse-engineered and countered with an antidote pretty quickly," says Kaspersky.
He worries about the ability of viruses, or malware (malicious software) to perform increasingly sophisticated and sinister attacks. Typically, these are denial of service (DOS) assaults using networks of computers infected by malware to bring down websites or online services by bombarding them with data. People who control these botnets can trigger a destructive payload at will.
The 2007 Estonian attack showed a botnet with enough resources could shut down banks, government departments, education networks, the media - just about any organisation with an online presence.
DOS attacks are just one aspect of the destructiveness of modern malware. Malware can also help with identity theft and data theft. The damage can be devastating.
"Estimates put the cost to business of cybercrime at anything between $100-billion to $1-trillion," he says . "One of the reasons it's so hard to put a figure on it is organisations that have been compromised are reluctant to talk about it."
Another is they don't know about it. Data theft is big business but differs from other forms of pilfering in that the original data stays where it is while a copy is spirited away, often undetected, via the ether.
"Some businesses are aware and active in countering virus attacks. Banks, for example, now build losses from cybercrime into the cost of doing business - they have a budget for it which includes defending against it and compensating for it when breaches occur. Computer viruses have permeated every part of society," he says.
In August 2008, a Spanair airliner crashed just after taking off from Madrid. It was that year's deadliest aviation accident and 154 people died.
Kaspersky says the airline found the computer system used to monitor aircraft technical problems was infected with malware that probably prevented detection of a system failure.
Last year marked the appearance of the Stuxnet virus, a virus so complicated to produce and dispatch it was probably at least partly the work of, or funded by, a nation state. Speculation is Stuxnet's purpose was to sabotage an Iranian nuclear reactor, although it can damage a variety of industrial systems.
Computer viruses have come a long way since the first, written in 1982 by US schoolboy Rich Skrenta, 15. Called Elk Cloner and written for early Apple II systems, it replicated itself on floppy disks and displayed a poem, sometimes corrupting disks it infected.
Brain was the first virus to infect IBM PCs and was released in 1986. It was written by two Pakistani brothers and distributed with their medical software to prevent piracy. It replicated itself and slowed systems.
The advent of the commercial internet in the early 1990s provided the ideal vehicle to spread viruses.
More advanced techniques used by virus writers meant they could be used to do anything from data theft and identity fraud to corporate espionage, blackmail and extortion.
Kaspersky says a Swedish bank was attacked in February and the remote access Trojan fooled operators into thinking that the screens they were monitoring had been frozen by a Windows blue screen computer error.
"The first rule when this happens is don't touch anything. They didn't. But the machine wasn't frozen, the virus had generated the blue screen and was diverting funds in the background from a perfectly functioning system that the operators thought wasn't working.
"Now malware writers are using social networks like Facebook and Twitter to spread their work." Organisations were threatened from within by disgruntled staff or criminals as shown by malware found on organisations' computers not connected to the internet.
Kaspersky says the computer virus threat is on the rise and inadequately protected businesses are vulnerable.
"Cybercrime is an industry now. Governments are finding it difficult to fight it because any laws they make regarding cybercrime are difficult if not impossible to enforce in the online world where attacks may come from networks made up of computers in different countries.
"Even on home soil, laws are difficult to keep relevant as the nature of attacks change. And in Japan, for example, there's simply no law against writing computer viruses.
"Lack of understanding the real threat of viruses is a dangerous game for businesses and organisations of all sizes to play," he says.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...