Saturday, June 8, 2013

Tool Time: Secunia Online Software Inspector (OSI) | hakin9.org






Mervyn Heng, CISSP – May 2013

The beauty of running Ubuntu Linux is the ease of maintaining your Operating System (OS) and software using the apt command or Update Manager. Both tools offer a single mechanism of keeping your system patched and up to date. The same cannot be said of Windows because the built-in update program only caters to Microsoft proprietary software such as the OS and Microsoft Office for examples.

Microsoft has enterprise tools like System Center Configuration Manager (SCCM) to install patches and upgrades to servers as well as endpoints but there are still standalone systems that require manual patching.

Besides Microsoft components, there are a host of other software (eg. Reader, Flash, Java) that are require to support business operations but highly susceptible to compromise. Maintaining them can be tedious, time consuming and insecure as an administrator may not apply a patch or upgrade in a timely manner.

There is a simple solution to this predicament. Secunia hosts a free tool called Online Software Inspector (OSI). Click Start Scanner to initiate a check on your system.

Black Hat security conference to include 110 talks | scmagazine.com

by Dan Kaplan, Executive Editor

When Black Hat's annual security conference rolls into Las Vegas at the end of July, event organizers promise one of the most "content-heavy" installments yet.

Last week, the conference, now in its 16th year, announced some of the planned presentations, most of which are known as "briefings" and which will span 11 tracks. In total, there will be 110 talks.

"Normally Black Hat accepts in the 80-90 range, but they expanded the number this year because there was so much incredible content – it was hard to fit it all in," a Black Hat spokeswoman told SCMagazine.com. "Not all of these talks have been announced on the website yet."

Wednesday, May 8, 2013

Scammers Impersonate Bank Exec on LinkedIn to Target Corporate Bank Accounts | HOTforSecurity

Imagine you receive an e-mail from an unknown prince / political refugee – the classic Nigerian scam of the past 10 years. You wouldn’t fall for that, would you?
Imagine now a legit business proposal from a bank manager with all the credentials, work experience and peers. It’s not even disguised as a Nigerian operation – it’s a business proposition. And it’s on LinkedIn.

We got such a message from an individual impersonating Aziz Mohammad, a manager at a highly popular bank in Malaysia. A brief look at his profile revealed it was built using the visual identity and profile information of the real Aziz Mohammad, a third-degree connection.



The scam message is crafted generically, as it lays the ground for the con: a business proposal for people who have full control of the company, including the possibility to initiate money transfers. The contact information is, of course, an e-mail address that does not belong to the banking institution the impersonator claims to be affiliated with, but rather a disposable account set up with Yahoo.

Hackers gain access to all .edu domains | H-Online



The hacker collective "Hack the Planet" (HTP) has claimed responsibility for an attack on MIT (Massachusetts Institute of Technology) computer systems in late January, in which it claims to have briefly taken control of the university's domain, redirected email traffic, and obtained administrator access to all .edu domains. HTP also claims to have compromised web servers for other sites, including security tool Nmap, network security service Sucuri, IT security company Trend Micro, and network analysis tool Wireshark.

Some of the hacks made use of a zero-day exploit, which the group has now taken the opportunity to disclose, against a vulnerability in the MoinMoin wiki system. Hack the Planet has also released information about an exploit against web servers running ColdFusion 9 or 10. The group claims to have used a variant of this exploit for their April attack on hosting company Linode.

Kali Linux Tutorial - Websploit Framework | eHacking.net



Websploit is an automatic vulnerability assessment, web crawler and exploiter tool. It is an open source command line utility that composed on modular structure. At the time of writing, there are 16 modules are available on Websploit, it can be downloaded from sourceforge project website but it is available on Kali Linux by default.

Websploit can be synchronize with Metasploit WMAP project for web vulnerability scanning, there are four categories of modular are available and they are:

Web Modules
Network Modules
Exploit Modules
Wireless Modules

Phishers target eBay customers via live chat support | Help Net Security

U.K.-based ISP Netcraft is warning users about phishers impersonating eBay's live chat support feature in the hopes of getting their hands on eBay users' login, personal and financial information.


The ISP blocked the bogus site offering the fraudulent service, but says that others might easily pop up.

In this particular case, the phishers were using a third-party live chat service provided by Volusion, and the fraudulent chat window was, at first, showing the eBay logo.

The eBay branding later disappeared from the site, and was replaced by a place-holder company logo, which means that the phishers can easily impersonate any of the other companies that outsource their live chat support. The fact that Volusion's services have a valid SSL certificate could also make many victims believe that they are dealing with a legitimate service.