In association with heise online

Top News

Update for Apache 2.2 web server closes various security holes

Apache Feather Version 2.2.15 fixes numerous bugs and closes three security holes. One of the holes is rated critical but only affects the Windows version of Apache more »

Top Feature

Shortened-breaks

Network Teaser Logo When people click on short URLs from services like bit.ly or tr.im, they don't always know where they'll land until they've actually arrived. The next generation of short URLs even go one step further more »

IT security news and features

News & Features

10 March 2010
Vodafone sold an Android smartphone infected with Mariposa

Android Logo Vodafone Spain sold a HTC Magic Android smartphone which had the Mariposa bot installed on its memory card more »

10 March 2010
Twitter to detect, intercept and prevent bad links

Twitter Logo Twitter has announced that it is launching a new service to protect its users against phishing and other attacks by attempting to detect, intercept and prevent "bad links" before a user has a chance to click on them more »

10 March 2010
Alert!Attacks on newly discovered vulnerability in IE 6 and 7

Microsoft Logo Microsoft warns of an unpatched vulnerability in Internet Explorer 6 and 7, which is already being actively exploited in targeted attacks to infect Windows PCs with a Trojan more »

10 March 2010
Password cracker 100 times faster with an SSD

Padlock Broken Teaser The security specialist Objectif Sécurité has optimised its rainbow tables - a common tool used to crack password hashes - to make use of SSDs more »

10 March 2010
Alert!Microsoft closes seven holes in Excel

Microsoft Logo Microsoft has released two security updates to close one hole in Windows Movie Maker and seven holes in Excel more »

9 March 2010
Researchers show infecting smartphones with malware is relatively easy

Mobile At the RSA conference, two security specialists presented the results of an investigation into how easy it is to inject a malicious program into thousands of Android smartphones and jail-broken iPhones more »

9 March 2010
OpenSSH 5.4 couples standard local input with server ports

OpenSSH Logo As well as a range of bug fixes, OpenSSH 5.4 includes a netcat mode which couples a local system's standard input to another computer's network port. There are also enhancements to the SFTP subsystem more »

8 March 2010
ZigBee: attack of the killer bees

ZigBee logo KillerBee is a collection of open source Linux tools for testing the security of ZigBee wireless networks more »

8 March 2010
Windows tool to eliminate update hassle

Every five days, the average Windows user must install an update to close a potential security hole in a Windows application. A new version of the Personal Software Inspector is to automate this procedure more »

8 March 2010
Alert!Dangerous security hole in Opera

Opera logo Secunia and others say the problem can be exploited to execute arbitrary code on a vulnerable system. Opera remain unconvinced. more »

6 March 2010
The H Week - CeBIT, a bid on Novell, Ubuntu's new look and botnet arrests

The H Week logo Highlights for The H in this past week include CeBIT, a bid on Novell, the IIPA attacked countries over their open source policies and Ubuntu announcing a new look. A scrap developed over a defective patch for a PHP extension and Spanish police closed a major botnet operation more »

5 March 2010
Hardware attack on RSA implementation

Crypto icon Researchers have shown how, in one specific case, it is possible to calculate the private key from specific erroneous RSA signatures. Whether the attack has practical utility is questionable more »

5 March 2010
Cisco patches vulnerabilities in voice solutions

Cisco logo Vulnerabilities in Cisco's Unified Communications Manager and Digital Media Manager can be exploited to eavesdrop on and to disrupt, voice networks more »

5 March 2010
Second maintenance release for PHP 5.3

PHP logo PHP 5.3.2 fixes more than 60 bugs, offers various updates and closes security holes more »

5 March 2010
Several known vulnerabilities to remain unpatched on forthcoming Microsoft patch day

Microsoft logo Microsoft plans to release just two security updates to fix eight vulnerabilities in Windows and Office on its forthcoming patch day. Vulnerabilities in Internet Explorer will, however, remain unpatched more »

4 March 2010
US government publishes parts of its cyber security directive

Closed Padlock icon The US government has published a document which allows some insight into the cyber security directive issued by George W. Bush in 2008 although parts of the directive remain under cover more »

4 March 2010
Worth reading: Security on BlackBerry devices

BlackBerry logo Security firm SMobile has examined the effectiveness of BlackBerry security functions and questions whether the information conveyed by BlackBerry warning messages allows users to make the right decisions more »

4 March 2010
CeBIT 2010: Generating keys from radio echoes

CeBIT logo Instead of complex mathematical problems, researchers at the Karlsruhe Institute of Technology are using errors in radio wave propagation to generate cryptographic keys more »

4 March 2010
Lost+Found: VIPs, bot test, Chuck Norris, data leaks, scary URLs, URL filters

L+F icon Too small for news, too good to lose: In this edition, Mark Shuttleworth on Full Disclosure, a Waledac online test, an old bot with a new name, a data leak study, an alternative to shortening URLs and failing URL filters more »

4 March 2010
Worth reading: Pass-the-hash attacks on Windows

Open padlock If you can extract NTLM or LM hashes from a system, you don't necessarily need to crack them to be able to make use of them. It is frequently possible to use the hashes directly more »

3 March 2010
Spanish police release details about Mariposa arrests

Global network icon Three Spaniards have reportedly been arrested in connection with "Mariposa", one of the largest botnets worldwide. The arrests took place over the past few weeks and the suspects stand accused of having taken control of more than 13 million computers and of operating the botnet since the end of 2008 more »

3 March 2010
Apple hires ex-Mozilla security chief

Apple logo Window Snyder is joining Apple as senior security product manager. Her experience could help Apple deal with security problems on a range of fronts more »

3 March 2010
Microsoft re-releases 'blue screen' patch

Microsoft Windows logo Microsoft is re-deploying patch MS10-015 as an automatic update. However, the patch won't install itself on systems where certain "abnormal conditions" exist more »

3 March 2010
Kaspersky introduces new "Pure" security package

Kaspersky logo PURE, the vendor's new product offers more functions than the conventional security suite and is specifically designed to meet the needs of multi-PC households more »

3 March 2010
Study on cloud security threats

Cloud icon A new study by the Cloud Security Alliance (CSA) commissioned by systems vendor Hewlett-Packard investigates the risks involved in cloud computing and offers protective strategies more »

Got news? Let us know!





The H open source

The H Security

The H Internet Toolkit