In association with heise online

Top News

The H Week - Faster password cracking and Linux 2.6.34 in testing

The H Week logo On The H this week; FOSS at CeBIT, Linux 2.6.34 in testing, new faces at the W3C and OSI, SCO vs. Linux continues, ZigBee hacking, SSD accelerated password cracking, smartphone malware and Mandriva's health checked more »

Top Feature

Shortened-breaks

Network Teaser Logo When people click on short URLs from services like bit.ly or tr.im, they don't always know where they'll land until they've actually arrived. The next generation of short URLs even go one step further more »

IT security news and features

News & Features

12 March 2010
Alert!Safari 4.0.5 patches 16 holes

Safari logo Apple has released Safari 4.0.5, an update which addresses sixteen vulnerabilities in the browser, along with a number of stability and performance improvements more »

12 March 2010
Google Chrome to do away with unique IDs

Google Chrome logo From version 4.1, Chrome will delete the ID token immediately after it is run for the first time – a symbolic step which takes the wind out of critics' sails more »

12 March 2010
ICANN boss creates a stir with DNS security warning

Global networking icon By warning of acute danger to the domain name system, ICANN boss Rod Beckstrom has incurred the displeasure of domain operators. They are concerned that governments could get the wrong end of the stick more »

12 March 2010
SecurityFocus to partially shut down

SecurityFocus Logo Symantec has announced that it plans to shut down part of its SecurityFocus security information portal. The company says that only the Mailing Lists, including Bugtraq, and its Vulnerability Database will remain online more »

11 March 2010
Alert!Exploit for new IE hole

Microsoft logo A public exploit for the new hole in Internet Explorer 6 and 7 has become available. This will probably force Microsoft to release an out-of-cycle patch more »

10 March 2010
Vodafone sold an Android smartphone infected with Mariposa

Android Logo Vodafone Spain sold a HTC Magic Android smartphone which had the Mariposa bot installed on its memory card more »

10 March 2010
Twitter to detect, intercept and prevent bad links

Twitter Logo Twitter has announced that it is launching a new service to protect its users against phishing and other attacks by attempting to detect, intercept and prevent "bad links" before a user has a chance to click on them more »

10 March 2010
Alert!Attacks on newly discovered vulnerability in IE 6 and 7

Microsoft Logo Microsoft warns of an unpatched vulnerability in Internet Explorer 6 and 7, which is already being actively exploited in targeted attacks to infect Windows PCs with a Trojan more »

10 March 2010
Password cracker 100 times faster with an SSD

Padlock Broken Teaser The security specialist Objectif Sécurité has optimised its rainbow tables - a common tool used to crack password hashes - to make use of SSDs more »

10 March 2010
Alert!Microsoft closes seven holes in Excel

Microsoft Logo Microsoft has released two security updates to close one hole in Windows Movie Maker and seven holes in Excel more »

9 March 2010
Researchers show infecting smartphones with malware is relatively easy

Mobile At the RSA conference, two security specialists presented the results of an investigation into how easy it is to inject a malicious program into thousands of Android smartphones and jail-broken iPhones more »

9 March 2010
OpenSSH 5.4 couples standard local input with server ports

OpenSSH Logo As well as a range of bug fixes, OpenSSH 5.4 includes a netcat mode which couples a local system's standard input to another computer's network port. There are also enhancements to the SFTP subsystem more »

9 March 2010
Alert!Update for Apache 2.2 web server closes various security holes

Apache Feather Version 2.2.15 fixes numerous bugs and closes three security holes. One of the holes is rated critical but only affects the Windows version of Apache more »

8 March 2010
ZigBee: attack of the killer bees

ZigBee logo KillerBee is a collection of open source Linux tools for testing the security of ZigBee wireless networks more »

8 March 2010
Windows tool to eliminate update hassle

Every five days, the average Windows user must install an update to close a potential security hole in a Windows application. A new version of the Personal Software Inspector is to automate this procedure more »

8 March 2010
Alert!Dangerous security hole in Opera

Opera logo Secunia and others say the problem can be exploited to execute arbitrary code on a vulnerable system. Opera remain unconvinced. more »

6 March 2010
The H Week - CeBIT, a bid on Novell, Ubuntu's new look and botnet arrests

The H Week logo Highlights for The H in this past week include CeBIT, a bid on Novell, the IIPA attacked countries over their open source policies and Ubuntu announcing a new look. A scrap developed over a defective patch for a PHP extension and Spanish police closed a major botnet operation more »

5 March 2010
Hardware attack on RSA implementation

Crypto icon Researchers have shown how, in one specific case, it is possible to calculate the private key from specific erroneous RSA signatures. Whether the attack has practical utility is questionable more »

5 March 2010
Cisco patches vulnerabilities in voice solutions

Cisco logo Vulnerabilities in Cisco's Unified Communications Manager and Digital Media Manager can be exploited to eavesdrop on and to disrupt, voice networks more »

5 March 2010
Second maintenance release for PHP 5.3

PHP logo PHP 5.3.2 fixes more than 60 bugs, offers various updates and closes security holes more »

5 March 2010
Several known vulnerabilities to remain unpatched on forthcoming Microsoft patch day

Microsoft logo Microsoft plans to release just two security updates to fix eight vulnerabilities in Windows and Office on its forthcoming patch day. Vulnerabilities in Internet Explorer will, however, remain unpatched more »

4 March 2010
US government publishes parts of its cyber security directive

Closed Padlock icon The US government has published a document which allows some insight into the cyber security directive issued by George W. Bush in 2008 although parts of the directive remain under cover more »

4 March 2010
Worth reading: Security on BlackBerry devices

BlackBerry logo Security firm SMobile has examined the effectiveness of BlackBerry security functions and questions whether the information conveyed by BlackBerry warning messages allows users to make the right decisions more »

4 March 2010
CeBIT 2010: Generating keys from radio echoes

CeBIT logo Instead of complex mathematical problems, researchers at the Karlsruhe Institute of Technology are using errors in radio wave propagation to generate cryptographic keys more »

4 March 2010
Lost+Found: VIPs, bot test, Chuck Norris, data leaks, scary URLs, URL filters

L+F icon Too small for news, too good to lose: In this edition, Mark Shuttleworth on Full Disclosure, a Waledac online test, an old bot with a new name, a data leak study, an alternative to shortening URLs and failing URL filters more »

Got news? Let us know!





The H open source

The H Security

The H Internet Toolkit