Pages

Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Wednesday, January 5, 2011

Android gets a Vulnerability!!

A new vulnerability in Android based web browser has been found which allows attackers to access the contents of files stored on the device's SD card, credentials stored in the browser, browser history, spy on your web transactions, even in encrypted.


The vulnerability is present in a code written by software company PacketVideo; contributed an open version of their core multimedia application to Android where it became the multimedia subsystem for the Android web browser. Google says that a fix will be released as soon as it will be available.

HTC Desire, Google Nexus One, Samsung Galaxy Tab etc. (even with Android 2.2) are vulnerable to this kind of attack.

Tips to protect you from hacking until Google issues a security patch:

1)Do not use the Android web browser. If this is not possible, only visit trusted sites and only over the T-Mobile network (avoid Wi-Fi). Use browser such as Opera Mobile; which prompts the user before downloading files.


2)Disable JavaScript in the browser.

Check for suspicious automatic downloads, which should be flagged in the notification area. This shouldn’t be happening completely in the background.


3)Unmounting the SD card.



We thank our loyal reader Shipra
Sahai for providing us with this article

Tuesday, December 28, 2010

Hope 2011 is better!!

Recently security vendor Bit9 released its annual "Dirty Dozen" list. According to statistics obtained from International Institute of Standard and Technology and International Vulnerability Database, it lists top 12 software with most vulnerabilities for 2010. From January to October this year, Google Chrome browser vulnerability has been discovered up to 76, which tops the list.

Besides Google Chrome, Apple's Safari browser and Microsoft Office's vulnerabilities are also getting more exposure, respectively 60 and 57 in the past year, ranking second and third. The software included in the list are frequently used. Here is the specific list:

1. Google Chrome, 76 vulnerabilities;
2. Apple Safari, 60 vulnerabilities;
3. Microsoft Office, 57 vulnerabilities;
4. Adobe Acrobat, 54 vulnerabilities;
5. Mozilla Firefox, 51 vulnerabilities;
6. Sun JDK, 36 vulnerabilities;
7. Adobe Shockwave Player, 35 vulnerabilities;
8. Microsoft IE, 32 vulnerabilities;
9. RealNetworks RealPlayer, 14 vulnerabilities;
10. Apple Webkit, 9 vulnerabilities;
11. Adobe Flash Player, 8 vulnerabilities;

12. Apple Quicktime and Opera browser, 6 vulnerabilities.


Article from: Top 12 Software with Most Vulnerabilities for 2010

Monday, October 25, 2010

Vulnerability:- Adobe Shockwave Player

A critical vulnerability exists in Adobe Shockwave Player 11.5.8.612 and earlier versions on the Windows and Macintosh operating systems.
This vulnerability (CVE-2010-3653) could cause a crash and potentially allow an attacker to take control of the affected system. While details about the vulnerability have been disclosed publicly, Adobe is not aware of any attacks exploiting this vulnerability against Adobe Shockwave Player to date.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available.
As always, Tech-da-Hack recommends that users follow best security practices by keeping their anti-malware software and definitions up to date.