Custom Search

WordPress SPAM Causing Headaches

It seems that SPAM is all the rave these days, wonder why, could it be because it’s a multi-million business?

In any event, detecting is always a challenge as is remediating. This is what it might look like if you use our free scanner to scan the website:

Besides some of the obvious things we have …

Beware of a new Windows security vulnerability (MS12-024)

As a part of the April’s “Patch Tuesday”, Microsoft released a fix for the MS12-024 / CVE-2012-0151 vulnerability.

This issue was discovered and researched by us; we have been in contact with Microsoft engineers for the past few months to fix this problem. The aim of this blog post is to explain the problem, the …

SOPA bytes GoDaddy’s business, and it will hurt you too.

SOPA as currently constructed can never work as intended. I'm not going to get into the reasons we don't like it because of its oppressive implications or because it is against our first amendment rights nor for any other reason (there's been so much other commentary on those issues that it would be superfluous). I …

Using DLLCHARACTERISTICS’ FORCE_INTEGRITY Flag

I discovered the flag FORCE_INTEGRITY last year when I released my tool setdllcharacteristics. This flag will force a check of the executable’s digital signature (on Windows Vista and Windows 7) and will prevent the program from running if the signature is invalid (or missing).

But it’s only now that I hold all the pieces to test …

Ascio Registrar Compromised – Brings Down UPS.com, Theregister and Others

If you tried to visit today the sites for UPS.com, theregister.co.uk, Vodafone, The Daily Telegraph and some other high profile sites, you would have received a scary message saying that they’ve been hacked (by turkguvenligi):

And they were indeed hacked, but not in the way most people think. Their servers were not …

Hong Kong stock exchange (HKEx) website hacked, impacts trades

The Hong Kong stock exchange (HKEx) halted trading this afternoon for seven stocks after its website was hacked during the morning trading session.

The seven stocks in question were all due to release sensitive results to the website that could impact the price of their stocks.

Although the Hong Kong stock exchange also operates an …

Phishers get greedy

Phishing scams are rapidly becoming one of the most dangerous online threats. They target all platforms equally and use a technique that technology cannot combat efficiently: social engineering.

Here is a Phish from JP Morgan Chase (online banking):

The scam consists of scaring the person by saying big words like “safety and integrity of …

Privacy and security in the cloud – is there any?

This evening (Monday 30 May 2011), I’ll be lecturing at the New South Wales branch forum of the Australian Computer Society (ACS).

The topic is Privacy and security in the cloud – is there any?

The Cloud – whatever that is – isn’t new, whatever the marketing material may imply. But the scale of …

Exploring Old Computing Integrity Strategies

Encapsulating computing operations has been encouraged to maintain integrity by separating and hiding functionality for years. Meanwhile, personal computing technologies have intertwined our daily functions onto one computing platform. Banking, gambling, mailing, and other daily activities are all performed on one machine over a single line of communications.

Manufacturing, for example, has many cases where …