Showing posts sorted by relevance for query open-source. Sort by date Show all posts
Showing posts sorted by relevance for query open-source. Sort by date Show all posts

Black Hat 2012- Key-Card of Hotel Door Can Be Bypassed With An Open-Source Tool "Arduino"


Black Hat 2012- Key-Card of Hotel Door Can Be Bypassed With An Open-Source Tool "Arduino"

For millions of travelers the ubiquitous hotel key card is the primary and essentially the only way to access their rooms at the end of day. But when you will heard that the key card, you use to access your private room is no longer safe then its very much possible that you will shock. And trust me this happened in Black Hat 2012. A security researcher, Cody Brocious believes the current systems used to secure hotel doors throughout the United States and elsewhere are severely flawed. Speaking at the Black Hat security conference here, Brocious demonstrated how locks from Onity a company that sells security products to hotels and other businesses can easily be bypassed. At the show, Brocious detailed the primary security flaws that allowed him to bypass Onity locks and gain access to rooms.
According to eWEEk -Brocious used an open-source tool known as Arduino, a portable programming platform. Arduino was used as a substitute for the commercial portable programmer that an Onity lock would typically require. Brocious explained that the Onity locks have a serial hardware connection that is easily accessible, as well. In addition to the Arduino tool, Brocious used an oscilloscope that allowed him to see what was happening in the lock whenever a key card was put in and the door opened or closed. He was able to determine through his research that the underlying firmware on the lock does not require any form of authentication to arbitrarily access the memory of the lock. This means it is possible to read out every bit of information that is on the lock, which makes it possible for anyone to gain access or make a key.
In theory, programming for the lock should go over a secure channel, rather than doing direct unencrypted memory access, said Brocious. The problem, according to his research, is that the existing Onity lock design does not easily allow for that, and there is no easy way to update the firmware. Another potential option is to actually provide physical security on the door lock. For example, the company could make the serial port harder to access. However, with 5 million of these locks in use today, Brocious said this would be an expensive and challenging way to add additional security. The actual door locks are only half the problem exposed by Brocious. The card keys are also at risk. Typical card keys in the Onity system use only 32-bit key encryption making them easy to decrypt, according to Brocious. "The system is broken at every layer," said Brocious.
The severity of the issue and its high impact is what led Brocious to choose to release his research at Black Hat. In addition to his research, he is also releasing a software tool so that others can continue or expand on his efforts. "Something needs to be done about this problem, and I didn't want to put it out there in a way that could be defeated by process," said Brocious. "No doubt, this vulnerability has been found before, and it has been in the locks for years."
Brocious added: “I'd be surprised if this hasn't been used by malicious actors in the past.” What Brocious is hoping to achieve from this disclosure is not a mass string of hackers getting unauthorized access to hotel rooms, but rather some kind of fix and industry response. "I'm saying that this is what you're vulnerable [to], so come up with a way to solve the problem," said Brocious.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

National Security Agency (NSA) Released Security Enhanced (SE) Android


US National Security Agency (NSA) released the first public release of the Security Enhanced (SE) Android Project, a program designed to find and plug security holes and risks in the Android flavor of Linux. SE Android is based on the NSA’s SELinux, first released in 2000.
SEAndroid is the name of both a project to identify, and find solutions for, critical gaps in Android security and of a reference implementation of a security enhanced Android. The project is currently focusing its efforts on enabling SELinux functionality in the hope that it can limit the damage done by malicious apps, but hopes to widen its scope in the future.
SE Android was first publicly described at Linux Security Summit 2011. In essence, the NSA is attempting to bring the same access control and damage mitigation measures found in SELinux to the Android Open Source Project. In the Security Summit presentation, a number of known security vulnerabilities were demonstrated and tested against a version of Android running SE Android controls. All exploits failed unless specifically tailored to the particular system, and even in those cases the exploit’s effectiveness was much reduced.
SEAndroid is only available as source and is built by cloning the Android Open Source Project (AOSP) git repository, and then applying the SE Android modifications from the project’s git repository. Currently the project is builds on Fedora 16, and has built on Fedora 14 and 15. Instructions how to build for emulators and devices (specifically the Nexus S) and how to get started developing policies are available from the project’s wiki.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

TCHunt: Detect Encrypted TrueCrypt Volumes!


ccf6d14dee5ae28a638fbbbbb0a009a2 TCHunt: Detect Encrypted TrueCrypt Volumes!
As we know, TrueCrypt is a free and open-source disk encryption software for Windows 7/Vista/XP, Mac OS X, and Linux. It does so by creating a virtual encrypted disk within a file and mounts it as a real disk. The reason we are mentioning aboutTrueCrypt is because of TCHunt – an open source application to detect most encrypted TrueCryptvolumes.
Since TrueCrypt is very stable and does it’s job as it says, it is used by almost everyone who wants to deny unauthorized access to their data. It allows you to use keyfiles that stop basic keyloggers, supports automatic unmounting after timeouts, etc. However, this also brings in the “bad guys” who hide behind such legitimate software to protect themselves. It does become really difficult while forensically investigating a TC encrypted drive. This is where TCHunt comes in handy. TCHunt allows you to search for file  with the following attributes :
  1. The suspect file size modulo 512 must equal zero.
  2. The suspect file size is at least 19 KB in size (although in practice this is set to 5 MB).
  3. The suspect file contents pass a chi-square distribution test.
  4. The suspect file must not contain a common file header.
TCHunt also seems very robust. Only, if a volume happen to be created with a common file header, then TCHunt would not find that volume. Even if someone were to rename your encrypted TrueCryptvolumes and hide them among millions of files of similar size, file extension, modification time, etc., TCHunt would quickly and accurately find the actual encrypted volumes! That’s not all! TCHunt completely ignores file names and file extensions. Owing to this, TCHunt can still find encrypted volumes that lack file extensions or have fictitious file extensions! You can employ TCHunt to locate encrypted sparse volumes and encrypted hidden volumes too!
TCHunt can run on Windows XP or newer Windows operating systems. Best of all, it is a self-contained, standalone program, that does not need any additional dependencies and can be used from a floppy disk, USB drive or CD/DVD! Just take care while compiling from the source code that you link the source with boost and FLTK libraries.
Download TCHunt v1.5 (TCHunt-1.5-en.exe/TCHunt-1.5-en.linhere.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Willysy Malware Infects More than 6 Million WeSites

 
In less than two weeks, a malware injection that targets e-commerce Web pages has ballooned from 90,000 infected pages to more than 6 million. Malware willysy The malware, called willysy, exploits a vulnerability in a popular online merchant platform, osCommerce, according to Web application security provider Armorize, of San Francisco.
When the company initially reported the injection on July 24, it found 90,000 infected pages. When it took another look at the malware on August 3, it found the injection had spread to some 6.3 million pages.

Although the identity of the perpetrators of the attacks by the malware could not be identified by Armorize, the company did trace the forays to eight IP addresses, all located in the Ukraine.
Armorize explainedthat the attacks exploit three known vulnerabilities in version 2.2 of osCommerce. The exploits allow the attackers to place an invisible frame (iFrame) on the page and then inject malicious code (JavaScript) into the page, where it will infect visitors to the online store.
Once the infection makes it to shopper's computer, it targets vulnerabilities in Java, Adobe Reader, Windows Help Center and Internet Explorer. Although the flaws in those programs targeted by the infection are known and have been patched, the attackers are betting that the user hasn't patched all the programs.
Even the exploitation of osCommerce itself depends on lax patch management by the shopping site, since the holes in the program used by the attackers were patched in version 2.3 of the software released in November of last year. Since that time, two versions of the offering have been released, 2.3.1 and 3.0.1.

According to osCommerce, the open source software is used by some 249,000 store owners, developers, service providers and enthusiasts.
Attacks like the one discovered by Armorize can be especially harmful to small and medium-size businesses (SMB), asserts Frank Kenney, a former Gartner analyst and vice president of Global Strategy at Ipswitch, a file transfer security company in Lexington. Malware willysyWillysy's progress Those companies typically don't have the financial resources of larger firms so they're attracted to open source programs like osCommerce and use off-the-shelf software in their operations. "Whenever you use off-the-shelf software, you have to understand there are data issues and all types of security vulnerabilities that exist," he told
While the makers of off-the-shelf software patch their programs often, he continued, the business still has to invest in the resources to insure that proper patch work is done. "That requires an outlay of capital that SMBs are not willing to deal with or don't have within their margins," he says.
Such lack of diligence can hurt a business in the long run, because security breaches can invite scrutiny from credit card companies, he explained. A credit card company may refuse to allow the business to use its services until it shows a certain level of security compliance that is out of the reach of the business from a financial or time and resource point of view.
That would have dire consequences for an SMB, he maintains. "The ability to process cards is the difference between a small business or a chain of mom-and-pop stores being open today and being closed tomorrow," he says.
 
-News Source (PC World)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Twitter Joins The Linux Foundation as A Silver Member

Twitter Joins The Linux Foundation as A Silver Member

Social networking giant Twitter joined The Linux Foundation, the nonprofit organization while dedicated to accelerate the growth of Linux & open-source. In addition to Twitter, the Linux Foundation also announced that Inktank and Servergy have also become members. Twitter joined as a silver member, paying $15,000 for the privilege. The Linux Foundation announced Twitter’s membership today as it gears up for next week’s annual LinuxCon conference in San Diego. “Linux and its ability to be heavily tweaked is fundamental to our technology infrastructure,” said Chris Aniszczyk, manager of open source at Twitter, in a statement. “By joining The Linux Foundation, we can support an organization that is important to us and collaborate with a community that is advancing Linux as fast as we are improving Twitter.”
Twitter is a real-time information service on which people post ideas, comments and news in 140 characters or less. Twitter brings users closer to the topics, events and people they care most about around the world. Based in San Francisco, Twitter is available worldwide in 30 languages, with 140 million active users and 400 million Tweets per day. This volume of data puts high demands on real-time data processing and the pace of innovation at the company. Twitter is supported by tens of thousands of Linux machines, which allow the company to customize for its unique needs. Twitter is joining The Linux Foundation to support the mission of promoting, protecting and advancing Linux, the company said. Twitter’s Chris Aniszczyk will deliver a keynote at LinuxCon on Aug. 30 entitled “The OSS Behind a Tweet.” 
Google, Yahoo is another big Web company that is part of the foundation. One missing name is Facebook, but Zemlin hopes to get Mark Zuckerberg and team on board as well. "We would love to have them as a member," Zemlin said. "They do participate in our events around the Open Compute Project so that’s a good thing. Their business runs on Linux as well."


-Source (eWeek & ars technica)






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Joomla! 1.6 update Fixes security holes

The Joomla! developers have released version 1.6.4 of their open source content management system (CMS), a maintenance and security update to the 1.6 branch. The latest version addresses a total of four security vulnerabilities.The vulnerabilities include two medium priority cross-site scripting (XSS) issues, a medium priority problem related to inadequate permission checking that could allow for unauthorised access, and a low priority information disclosure hole caused by inadequate filtering. Versions up to and including 1.6.3 are reportedly affected. All users are advised to update as soon as possible.Joomla! is a widely used and easily deployed PHP-based CMS, which can be used to create anything from small web sites to corporate sites and large online applications. Examples of how it is being used can be found in the Community Showcase.Further details about the update can be found in the official release announcement. Joomla! 1.6.4 is available to download from the project's web site and is released under the GNU General Public License. The Joomla! Project is sponsored by Open Source Matters, Inc., a non-profit organization.
You May Also like:-

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

IBM Unveils Breakthrough Software and New Services to Exploit Big Data




As companies seek to gain real-time insight from diverse types of data, IBM (NYSE: IBM) today unveiled new software and services to help clients more effectively gain competitive insight, optimize infrastructure and better manage resources to address Internet-scale data. For the first time, organizations can integrate and analyze tens-of-petabytes of data in its native format and gain critical intelligence in sub-second response times.
(Logo: http://photos.prnewswire.com/prnh/20090416/IBMLOGO)
IBM also announced a $100 million investment for continued research on technologies and services that will enable clients to manage and exploit data as it continues to grow in diversity, speed and volume. The initiative will focus on research to drive the future of massive scale analytics, through advancing software, systems and services capabilities.
The news comes on the heels of the 2011 IBM Global CIO Study where 83 percent of 3,000 CIOs surveyed said applying analytics and business intelligence to their IT operations is the most important element of their strategic growth plans over the next three to five years.
Today's news further enables Smarter Computing innovations realized by designing systems that incorporate Big Data for better decision making, and optimized systems tuned to the task and managed in a cloud.
According to recent IT industry analyst reports, enterprise data growth over the next five years is estimated to increase by more than 650 percent. Eighty percent of this data is expected to be unstructured.  
The new analytics capabilities pioneered by IBM Research will enable chief information officers (CIOs) to construct specific, fact-based financial and business models for their IT operations. Traditionally, CIOs have had to make decisions about their IT operations without the benefit of tools that can help interpret and model data.
With today's news, IBM is expanding its portfolio and furthering its investments in analytics with:
  • New, patented software capabilities to analyze massive volumes of streaming data with sub-millisecond response times and Hadoop-based analytics software to offer scalable storage to handle tens-of-petabytes level data.  These capabilities complement and leverage existing IT infrastructure to support a variety of both structured and unstructured data types.
  • 20 new services offerings, featuring patented analytical tools for business and IT professionals to infuse predictive analytics throughout their IT operations. The services enable IT organizations to assess, design and configure their operations to address and take advantage of petabytes of data.

"The volume and velocity of information is generated at a record pace. This is magnified by new forms of data coming from social networking and the explosion of mobile devices," said Steve Mills, Senior Vice President and Group Executive, IBM Software & Systems.  "Through our extensive capabilities in business and technology expertise, IBM is best positioned to help clients not only extract meaningful insight, but enable them respond at the same rate at which the data arrives."


New Services Address Analytics for IT Infrastructure
Leveraging years of intellectual capital in managing data centers and IT departments, as well as over 30 patented technologies from IBM Research, the new IT services feature dozens of analytical tools to help IT professionals use server, storage and networking technologies more efficiently, improving security and insight into planning major IT investments.  Examples of services that help clients with analytics include:
  • Cloud Workload Analysis -- The new analysis tool maps your IT workload characteristics and current capabilities to prioritize cloud deployment and migrations plans. This allows IT managers to identify cloud opportunities 90 percent faster to reduce costs.  
  • Server and Storage -- New server optimization and analysis tools achieve up to 50 percent reduced transformation costs and up to 80 percent faster implementation time.  New storage services help create self-service to provision explosive growth while reducing architects time by 50 percent.
  • Data Center Lifecycle Cost Analysis Tool -- Identifies how to reduce total data center costs by up to 30 percent by assessing total cost plus including environmental impact over a 10 to 20 year life.
  • Security Analytic services -- Analytic systems identify known events and automatically handle them; This results in handling of more than 99 percent of critical events without human intervention.

IBM Big Data Software Taps into Hadoop
IBM is making available new InfoSphere BigInsights and Streams software that allows clients to gain fast insight into information flowing in and around their businesses.  The software, which incorporates more than 50 patents, analyzes traditional structured data found in databases along with unstructured data -- such as text, video, audio, images, social media, click streams -- allowing decision makers to act on it at unprecedented speeds.  
BigInsights software is the result of a four-year effort of more than 200 IBM Research scientists and is powered by the open source technology, Apache Hadoop. The software provides a framework for large scale parallel processing and scalable storage for terabyte to petabytes-level data. It incorporates Watson-like technologies, including unstructured text analytics and indexing that allows users to analyze rapidly changing data formats and types on the fly.  
Additional new features include data governance and security, developer tools, and enterprise integration to make it easier for clients to build a new class of Big Data analytics applications. IBM also offers a free downloadable BigInsights Basic Edition for clients to help them explore Big Data integration capabilities.  
Also born at IBM Research, InfoSphere Streams software analyzes data coming into an organization and monitors it for any changes that may signify a new pattern or trend in real time. This capability helps organizations to capture insights and make decisions with more precision, providing an opportunity to respond to events as they happen.
New advancements to Streams software makes it possible to analyze Big Data such as Tweets, blog posts, video frames, EKGs, GPS, and sensor and stock market data up to 350 percent faster than before.  BigInsights complements Streams by applying analytics to the organization's historical data as well as data flowing through Streams. This is an ongoing analytics cycle that becomes increasingly powerful as more data and real-time analytic results are available to be modeled for improvement.
As a long time proponent of open source technology, IBM has chosen the Hadoop project as the cornerstone of its Big Data Strategy. With a continued focus on building advanced analytics solutions for the enterprise, IBM is building upon the power of these open source technologies while adding improved management and security functions, and reliability that businesses demand. Hadoop's ability to process a broad set of information across multiple computing platforms, combined with IBM's analytics capabilities, now makes it possible for clients to tackle today's growing Big Data challenges. IBM's portfolio of Hadoop-based offerings also include IBM Cognos Consumer Insight which integrates social media content with traditional business analytics, and IBM Coremetrics Explore which segments consumer buying patterns and drills down into mobile data. Additionally, Hadoop is the software framework the IBM Watson computing system uses for distributing the workload for processing information, which supports the systems breakthrough ability to understand natural language and provide specific answers to questions at rapid speeds.
University of Ontario Institute of Technology Expands Neo-Natal Research to China
Dr. Carolyn McGregor, Research Chair in Health Informatics at the University of Ontario Institute of Technology has been exploring new approaches for the last 12 years to provide specialists in neonatal intensive care units better ways to spot potentially fatal infections in premature babies.  
Changes in streams of real-time data such as respiration, heart rate and blood pressure are closely monitored in her work and now she is expanding her research to China. "Building upon our work in Canada and Australia, we will apply our research to premature babies at hospitals in China.  With this new additional data, we can compare the differences and similarities of diverse populations of premature babies across continents," said Dr. McGregor. "In comparing populations, we can set the rules to optimize the system to alert us when symptoms occur in real time, which is why having the streaming capability that the IBM platform offers is critical. The types of complexities that we're looking for in patient populations would not be accessible with traditional relational database or analytical approaches."
IBM's Big Data software and services reinforces IBM's analytics initiatives to deliver Watson-like technologies that help clients address industry specific issues. On the heels of The IBM Jeopardy! Challenge, in which the IBM Watson system demonstrated a breakthrough capability to understand natural language, advanced analytical capabilities can now be applied on real client challenges ranging from identifying fraud in tax or healthcare systems, to predicting consumer buying behaviors for retail clients.
Over the past five years, IBM has invested more than $14 billion in 24 analytics acquisitions. Today, more than 8,000 IBM business consultants are dedicated to analytics and over 200 mathematicians are developing breakthrough algorithms inside IBM Research. IBM holds more than 22,000 active U.S. patents related to data and information management.
To hear how IBM clients are using analytics to transform their business visit: http://www.youtube.com/user/ibmbusinessanalytics.
For more information on IBM Big Data initiatives, visit: www.ibm.com/bigdata.
For more information on IBM's full set of new analytics services, visit: www.ibm.com/services/it-insight.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Red Hat Inc Announced The General Availability Red Hat Enterprise Linux (RHEL) 6.5

Red Hat Inc Announced The General Availability Red Hat Enterprise Linux (RHEL) 6.5 

The RHEL 6x series get another important update as Red Hat Inc, the world's leading provider of open source solutions announced the general availability of Red Hat Enterprise Linux 6.5, the latest version of Red Hat Enterprise Linux 6. According to the official press release of Red Hat -RHEL 6.5 expands Red Hat’s vision of providing an enterprise platform that has the stability to free IT to take on major infrastructure challenges and the flexibility to handle future requirements, with an extensive partner and support ecosystem. 
Red Hat Enterprise Linux 6.5 is mainly designed for those who build and manage large, complex IT projects, especially enterprises that require an open hybrid cloud. From security and networking to virtualization, Red Hat Enterprise Linux 6.5 provides the capabilities needed to manage these environments, such as tools that aid in quickly tuning the system to run SAP applications based on published best practices from SAP.“Red Hat Enterprise Linux 6.5 provides the innovation expected from the industry’s leading enterprise Linux operating system while also delivering a mature platform for business operations, be it standardizing operating environments or supporting critical applications. The newest version of Red Hat Enterprise Linux 6 forms the building blocks of the entire Red Hat portfolio, including OpenShift and OpenStack, making it a perfect foundation for enterprises looking to explore the open hybrid cloud.”-said Jim Totton, vice president and general manager of Red Hat Inc. Now lets take a closer look to the main highlights of RHEL 6.5 : 

Securing the Next-Generation Enterprise
Red Hat Enterprise Linux 6.5 continues the push for integrated security functionality that combines ease-of-use and up-to-date security standards into the platform. The addition of a centralized certificate trust store enables standardized certificate access for security services. Also included are tools that meet leading security standards, including OpenSCAP 2.1, which implements the National Institute of Standards and Technology’s (NIST’s) Security Content Automation Protocol (SCAP) 1.2 standard. With these additions, Red Hat Enterprise Linux 6 provides a secure platform upon which to build mission-critical services and applications.

Networking – When Every (Micro)Second Matters
In the financial services and trading-related industries, application latency is measured in microseconds, not seconds. Now, the latest version of Red Hat Enterprise Linux 6 fully supports sub-microsecond clock accuracy over the local area network (LAN) using the Precision Time Protocol (PTP). Precision time synchronization is a key enabler for delivering better performance for high-speed, low latency applications. Red Hat Enterprise Linux 6.5 can now be used to track time on trading transactions, improving time stamp accuracy on archived data or precisely synchronizing time locally or globally. Thanks to other networking enhancements in Red Hat Enterprise Linux 6.5, system administrators now have a more comprehensive view of network activity. These new capabilities enable sysadmins to inspect IGMP (Internet Group Management Protocol) data to list multicast router ports, multicast groups with active subscribers and their associated interfaces, all of which are important to many modern networking scenarios, including streaming media.

Virtualization Enhancements
Red Hat Enterprise Linux 6.5 continues Red Hat’s commitment to improving the overall virtualization experience and includes several improvements that make it a compelling choice for running in virtualized environments. Sysadmins can now dynamically enable or disable virtual processors (vCPUs) in active guests, making it an ideal choice for elastic workloads. The handling of memory intensive applications as Red Hat Enterprise Linux guests has also been improved, with configurations supported for up to 4TB of memory on the Kernel-based Virtual Machine (KVM) hypervisor. The KVM hypervisor also integrates with GlusterFS volumes to provide direct access to the distributed storage platform, improving performance when accessing Red Hat Storage or GlusterFS volumes. Finally, guest drivers have been updated to improve performance of Red Hat Enterprise Linux 6.5 running as a guest on supported third-party hypervisors.

Evolving Ease-of-Use, Storage, and More
As application deployment options grow, portability becomes increasingly important. Red Hat Enterprise Linux 6.5 enables customers to deploy application images in containers created using Docker in their environment of choice: physical, virtual, or cloud. Docker is an open source project to package and run lightweight, self-sufficient containers; containers save developers time by eliminating integration and infrastructure design tasks. Red Hat Enterprise Linux 6.5 stays current with the advancements in Solid-State Drive (SSD) controller interface, introducing support for NVM Express (NVMe)-based SSDs. The NVMe specification aims to standardize the interface for PCIe-based SSDs and its inclusion in Red Hat Enterprise Linux 6.5 positions the platform to support an expanding range of future NVMe-based devices.

Improvements have also been added to improve enterprise storage scalability within Red Hat Enterprise Linux 6.5. It is now possible to configure more than 255 LUNs connected to a single iSCSI target. In addition, control and recovery from SAN for iSCSI and Fibre Channel has been enhanced, and updates to the kexec/kdump mechanism now make it possible to create debug (dump) files on systems configured with very large memory (e.g. 6TB).

Red Hat Enterprise Linux 6.5 makes it easier to track and manage subscription consumption across the enterprise, integrating subscription tracking into existing business workflow. Usability enhancements include support for remote access to Windows clients and servers that use a newer version of the RDP protocol, including Windows 7 and 8 desktops and Windows Server 2012

To Download Red Hat Enterprise Linux 6.5 Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Chrome-based Web security scrutinizer by Google



Google today released an open-source tool called DOM Snitch that tries to flag Web site software that would be dangerous to run in a browser.
The software is an experimental Chrome extension that examines how Web site code executes to see if commands could lead to cross-site scripting or other attacks used to deliver malware to computers via a Web browser.
DOM Snitch (download) "enables developers and testers to identify insecure practices commonly found in client-side code," said Google security test engineer Radoslav Vasilev in a blog post. He elaborated:
To do this, we have adopted several approaches to intercepting JavaScript calls to key and potentially dangerous browser infrastructure such as document.write or HTMLElement.innerHTML (among others). Once a JavaScript call has been intercepted, DOM Snitch records the document URL and a complete stack trace that will help assess if the intercepted call can lead to cross-site scripting, mixed content, insecure modifications to the same-origin policy for DOM access, or other client-side issues.
The move is one of many Google has made of late to improve security on the Web--a medium the company believes is the programming platform of the future and that holds a dominant role in its own business. The company also is working hard to improve Chrome's own security.
Other open-source Google security products include Skipfish and Ratproxy, which let people test the security of Web applications.
-NEWS  SOURCE (Cnet)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Graphics Firm NVIDIA Joins The Linux Foundation

Graphics Firm NVIDIA Joins The Linux Foundation

The Linux Foundation has announced that amongst its latest addition of new members is graphics firm, NVIDIA, a move which is expected to strengthen the company's relationship within the Linux community. It has been hoped that from this membership, NVIDIA may partake in open-source driver projects, as currently NVIDIA only offers closed-source drivers for Linux, which typically adds complexity to integration and prevents the open-source community from efficiently contributing enhancements and bug-fixes.
On the other-hand, at the most basic level, NVIDIA may simply wish to reap the benefits of membership to support its increasing involvement in Linux-based operating systems such as Google Android, with the firm no doubt interested in the multimedia direction that Ubuntu appears to be heading in. In a brief statement, Nvidia said that its membership in the Linux Foundation will enable it to collaborate better with "the organizations and individuals instrumental in shaping the future of Linux, enabling a great experience for users and developers of Linux."



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ubertooth r434 A Passive Bluetooth Monitoring Tool


Earlier we have talked a lot about Ubertooth. Recently the author has released the last version. Ubertooth is an open source 2.4 GHz wireless development platform suitable for passive bluetooth monitoring. It aims to be the world’s first open source and affordable bluetooth monitoring and development platform. It contains both – hardware and software.


Official Change Log:-
  • ToorCon 13 Badge: This is a special Ubertooth design made for ToorCon 13. Hardware design files and firmware source code are part of Project Ubertooth. For more information, see: http://greatscottgadgets.com/tc13badge/
  • Pogoprog update: The hardware design has been updated. It now uses Micro USB, has a secondary pin header, a more ergonomic PCB shape, and other small changes. Pogoprog can be used to write firmware to the LPC175x on all Ubertooth designs as well as the R8C microcontroller on the ToorCon 13 Badge.
  • ubertooth-dump -f: The -f option tells ubertooth-dump to output the full USB data stream, not just the baseband symbol data. The -i option on ubertooth-lap, ubertooth-uap, etc. support file input of this type and can take advantage of timestamp information. Mostly this is useful for test and development.
  • ubertooth-hop: So far this new command line tool only does hop reversal, an intermediate step toward frequency hopping.

To Download Ubertooth r434 Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Metasploit Pro (Community Edition of Metasploit)


US security company Rapid7 has announced the launch of a Community Edition of the popular Metasploit exploit framework. According to Rapid7 Chief Security Officer and Metasploit Creator HD Moore, "The best way to tackle the increasing information security challenge is to share knowledge between practitioners, open source projects and commercial vendors."
The Community Edition is free for personal and professional use, combining the open source version of the framework with several of the features found in Metasploit Pro, to provide "an entry-level response to the evolving threat landscape". It includes "a basic version" of the commercial graphical user interface which is aimed at making it easier for users to get started with vulnerability verification and security assessments.
According to Rapid 7:-
Metasploit Pro helps enterprise defenders prevent data breaches by efficiently prioritizing vulnerabilities, verifying controls and mitigation strategies, and conducting real-world, collaborative, broad-scope penetration tests to improve your security risk intelligence.
Prevent data breaches:-
Metasploit Pro helps you improve your enterprise vulnerability management program and test how well your perimeter holds up against real world attacks:

  • Identify critical vulnerabilities that could lead to a data breach so you know what to patch first
  • Reduce the effort required for penetration testing, enabling you to test more systems more frequently
  • Discover weak trust models caused by shared credentials that are vulnerable to brute forcing and harvesting
  • Locate exposed, sensitive information with automated post-exploitation file system searches

Prioritize Vulnerabilities:-
Metasploit Pro makes your security and operations team more efficient because it helps you prioritize the vulnerabilities reported by your vulnerability scanner:

  • Import vulnerability management reports from more than a dozen third-party applications and verify their findings to eliminate false positives
  • Integrate with your in-house Nexpose infrastructure to kick off new scans and access real-time vulnerability findings (requires Nexpose)
  • Focus on remediating critical vulnerabilities to reduce exposure and reduce mitigation costs
  • Prove exploitability to application owners to expedite remediation

Verify controls and mitigation efforts:-
Metasploit Pro helps you verify that your remediation effort, such as a patch, new firewall rule or IPS configuration, actually stops the vulnerability from being exploited.

  • Re-run exploits after mitigation to verify its effectiveness in preventing a data breach
  • Enable the IT operations team or your client to verify whether controls and mitigations were successful by handing them a replay script that re-traces the steps you took to exploit the vulnerability
  • Draw on the Nexpose vulnerability database to read up on ways to remediate vulnerabilities (requires Nexpose)
For more information about Metasploit Pro Click Here

To Download Metasploit Click Here

-News Source (Rapid 7)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

AnDevCon 2 (The Android Developer Conference)


The technical conference for software developers building or selling Android apps, arrives after a smashing debut in March, 2011 (nearly 1,000 attendees and 20 major sponsors).  It will offer one day of intensive workshops, followed by three days of technical classes.  More than 1,000 software developers, engineers and entrepreneurs from 35 nations are projected to attend Android DevCon and choose from 70 classes to bring Android open source development to a high level.
Android handsets are taking the world by storm.  And because it’s an open platform, Android is finding its way into tablets, set-top boxes and just about everything you can imagine.
You can receive a $100 discount off the Full Event Passport and/or gain free admission to the exhibits

According to The AnDevCon-2 Chairman:- 

"Android’s success is incredible. Driven by the energy of the open-source movement, backed by many of the biggest names in software, hardware and carrier services, Android is taking off like a rocket. Between handsets and the emerging world of Honeycomb-based tablets, there are superlatives everywhere. Astounding. Amazing. Astonishing. And that’s just the letter “A.”
Come to AnDevCon II: The Android Developer Conference to learn how to succeed with your mobile apps development, deployment and marketing.
AnDevCon is focused 100% on your need to thrive in the hot and exciting world of Android apps. Produced by BZ Media – publishers of SD Times, the newspaper for the software development industry – this is the most info-packed, most practical Android conference in the world. At AnDevCon, you'll be able to choose from dozens of workshops and technical classes at all levels, from overview to intermediate, from advanced to expert. Come and learn what fits your needs, as our sessions are organized into five subject areas suitable for you and everyone on your team:
Developer Essentials: These technical classes and workshops are for all Android developers and cover all programming topics.
Android Enterprise: These technical sessions cover topics specific to building and managing apps for employees, business customers and partners, such as back-end integration corporate data center communications, ERP or CRM systems.
Android Business: These classes and workshops are for entrepreneurial developers who want to learn the most effective ways of distributing and selling Android apps, including how to maximize profit through the Android Market.
Android Tablets: These classes and workshops are specific to Android Honeycomb and the world of Android tablets.
Embedded Android: These classes and workshops are for developers working close to the hardware, such as on custom devices, or diving deep into the internals of this flavor of embedded Linux.
But wait – there’s more, lots more. In the AnDevCon exhibit hall, you'll learn about the best tools, services and resources for Android developers and marketers. Mingle and network during breaks and at our big evening reception. There's more, much more… this is the conference you won't want to miss.
Join us for three days and learn from the brightest minds in the Android universe."

For registration and more information visit 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Mantra v0.61




Mantra is a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers,security professionals etc. It is portable, ready-to-run, compact and follows the true spirit of free and open source software. Mantra is lite, flexible, portable and user friendly with a nice graphical user interface. You can carry it in memory cards, flash drives, CD/DVDs, etc. It can be run natively on Linux, Windows and Mac platforms. It can also be installed on to your system within minutes. Mantra is absolutely free of cost and takes no time for you to set up.


These are the new features at a glance:


Base: Upgraded to Firefox 4
Ayudha: Introducing Ayudha aka Tools
Menu: Integrated FireCAT for better navigation
Hackery: Integrated The Open Penetration Testing Bookmarks Collection
Welcome screen: A new welcome screen with integrated Google Search
New look and feel: Less cluttered and simple


Download OWASP Manra v0.61 (Mantra Security Toolkit – Gandiva x86_64.tar.bz2) here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ice Cream Sandwich (Android 4.0) Source Code Released


Google officially released the source code of long waited Android 4.0 also known as Ice Cream Sandwich (ICS). Although the repositories will also contain the source code of Android 3.x, Honeycomb, it will be scattered through the history of the various files. Honeycomb was not released as open source because, according to Google, the company took numerous shortcuts in the development of the tablet version of Android. The Google developers are not globally tagging (marking in the history) the 3.x releases of Android in the repository. Queru said: "since Honeycomb was a little incomplete, we want everyone to focus on Ice Cream Sandwich", though he later backed off on this position slightly saying he was considering tagging some of the 3.2.x release in the frameworks to help developers. 
The release comes with ICS 4.0.1, the one Galaxy Nexus will ship with, so it’s the latest version. Unfortunately the device build target, full_maguro, can be used for building a system image for the Samsung Galaxy Nexus, though we will get builds for more devices soon, according to Queru. Hopefully developers will be able to port it to other devices pretty soon, because I would really like to see how ICS runs on my Galaxy S II.
There were many rumors that Google will release the Galaxy Nexus at the November 16th event and once with this release we can be nearly sure that’s what the event will be about. All we have to see next is if Google will have more luck with their new device in comparison with the other Nexus-branded smartphones. They will probably be able to take advantage of the fact it will be only ICS smartphone, though I am pretty sure Samsung, HTC, Motorola and all the others will do their best and move fast to release ICS smartphones and updates for the ones currently on the market. Ice Cream Sandwich is the latest and probably the biggest Android update, which unites all devices into one OS and promises a lot of improvements, like speed and battery life. It also comes with exciting new features and an all-new design. It will probably boost Android’s sales even more.

To download the ICS Source Code Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

VLC is Giving Malware Alert While Downloading


VLC Player by VideoLAN is no doubt one of the best and most popular media player available on Windows, Mac & Linux systems. Being open source software, the source code of VLC player is available to everyone. It’s however being reported that few fraud companies are abusing the source code and distributing the software infected with malware. These fraud companies tweak the source code and inject their own malware in the player and then make it available for download through various sources. User thinks that it’s the legit version of the software, however, receives the infected version which either does not work or spreads malware on their computer system. 
What’s causing more trouble is that these fraud companies have enough money to have Google Adwards accounts so that they can buy advertisements on the Internet and expand their reach. Many such companies have even registered ‘official sounding’ domains which trick users to believe that they’re actually downloading from the official website. Ludovic Fauvet, the developer of VLC player says that his organization, being a non-profit, does not have enough money to sue these companies which are discrediting his work and also abusing the GPL license.
It’s being highly recommended that users looking to download VLC player should download it ONLY from the official website (link below) to be 100% sure that they’ve downloaded the authentic version of the software that just works fine and does not contain any malware.

                                                                                                                                                                     -News Source (Crazy Engineers)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Z-Admin (New GUI Admin For Zarafa)

                                    
Zarafa has released version 1.0 of Z-Admin, the company's next generation, its an open source administration interface for the Zarafa Collaboration Platform (ZCP). With the Z-Admin web application, system administrators can set up, configure, monitor and maintain a Zarafa mail server using any modern browser. To develop Z-Admin, Zarafa worked with German firm bitbone to integrate the open source Yaffas (Yet another framework for administering servers) administration framework into the groupware server.As can be expected, the tool's main administrative focus is on the mail server area. From basic mail server settings to spam filter rules, system administrators can now do their work using the Z-Admin GUI. Admins can also check memory consumption and cache settings at runtime, and optimise them if required. For editing and managing users and groups, Z-Admin can – depending on the requirements – either use the ZCP server's data or access an external OpenLDAP or Active Directory server.
Licensed under the AGPLv3, Z-Admin 1.0 is available to download from the company's site, and is compatible with Red Hat Enterprise Linux (RHEL) and Ubuntu Server.

To Download Z-Admin Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Critical vulnerability in open source Eucalyptus clouds


Researchers at the Ruhr-University Bochum have discovered a critical vulnerability in Eucalyptus, an open source implementation of the Amazon EC2 cloud APIs. An attacker can, with access to the network traffic, intercept Eucalyptus SOAP commands and either modify them or issue their own arbitrary commands. To achieve this, the attacker needs only to copy the signature from one of the XML packets sent by Eucalyptus to the user. As Eucalyptus did not properly validate SOAP requests, the attacker could use the copy in their own commands sent to the SOAP interface and have them executed as the authenticated user.
All versions up to and including 2.0.2 are vulnerable; a fixed version, 2.0.3, is available to download. Ubuntu's Eucalyptus-based Ubuntu Enterprise Cloud (UEC) is also vulnerable; updates for Ubuntu 10.04 LTS, 10.10 and 11.04 are already available in Canonical's repositories. Eucalyptus does note that the changes made to close the holes may lead to some existing tools failing to work as the system will interpret them as a replay attack if they issue commands too rapidly.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Metasploit 3.7 Takes Aim at Apple iOS


The open source Metasploit vulnerability testing framework got a major overhaul this week with the release of Metasploit 3.7.
The Metasploit 3.7 release provides an enhanced session tracking backend that is intended to improve performance. Metasploit 3.7 also provides over 35 new exploit modules for security researchers to test, including new ones designed to test Apple's iOS mobile operating system security.
The Apple iOS Backup File Extraction module however is not an attack vector for directly exploiting iOS. Rather it is what is known as a post-exploitation module.
"The post-exploitation modules (post for short) are designed to run on systems that were compromised through another vector, whether its social engineering, a guessed password, or an unpatched vulnerability," HD Moore, Rapid7 chief security officer and Metasploit chief architect told InternetNews.com. "This module requires iTunes to be installed and for a backend to be accessible that has not been encrypted."
Apple's iOS was specifically targeted during this year's pw2own hacking challenge in which security researcher Charlie Miller was able to exploit the system. Apple has since patched the pw2own flaw.
"In large corporate environments, a single domain administrator login can yield access to hundreds of desktop systems, and the Metasploit Pro product makes it easy to scavenge these iTunes backup files from the entire network at once," Moore said.
Metasploit is a popular vulnerability testing frame and is available in Express, Pro and Open Source editions. The Metasploit 3.7 release follows the Metasploit 3.6 release, which came out in March and had a focus on compliance related issues.
With Metasploit 3.7, in addition to new exploit module, there is a focus on improving performance. The improvements to the session tracking system and the associated database in Metasploit 3.7, means that Metasploit is now faster.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

sqlsus v0.7 (SQL Injection and Takeover Tool)


sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the databases, and much more. sqlsus is an open source (My)SQL injection tool, written in perl. It focuses on speed and efficiency, optimising the available injection space. It provides an easy to use interface with lots of neat features.

Features of Sqlsus v0.7:-
  • Added time-based blind injection support (added option “blind_sleep”, and renamed “string_to_match” to “blind_string”).
  • It is now possible to force sqlsus to exit when it’s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.
  • Rewrite of “autoconf max_sendable”, so that sqlsus will properly detect which length restriction applies (WEB server / layer underneath). (removed option “max_sendable”, added options “max_url_length” and “max_inj_length”)
  • Uploading a file now sends it into chunks under the length restriction.
  • sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.
  • Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.
  • get db (tables/columns) in inband mode now uses multithreading (like everything else).
  • clone now uses count(*) if available (set by “get count” / “get db”), instead of using fetch-ahead.
  • In blind mode, “start” will now test if things work the way they should, by injecting 2 queries : one true and one false.
  • sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).
To Download sqlsus (My SQL Injection Tool) 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...