Última actualització: 01/02/2007; 00:54:27
Weblog d'en Xavi Caballé Weblog d'en Xavi Caballé
«En la fèrtil, rica e deleitosa illa d'Anglaterra habitava un cavaller valentíssim, noble de llinatge e molt més de virtuds»
«Tirant lo Blanc» de Joanot Martorell

dissabte, 20 / gener / 2007


[ComputerWorld Security] The Surprising Security Threat: Your Printers. Malgrat que el Blaster ja va demostrar que les impressores podien audar en la transmissió de determinats cucs, encara avui en dia pràcticament no se'ls hi dóna cap mena d'importància alhora de considerar la seguretat d'una xarxa.
In essence, networked printers need to be treated like servers or workstations for security purposes — not like dumb peripherals.

At the Black Hat conference in Las Vegas in August, O’Connor delivered a blow-by-blow presentation on how to bypass authentication, inject commands at the root level and create shell code to take over printers in Xerox Corp.’s WorkCentre line of printers, which run on Linux operating systems. He described the kinds of mischief you could do with a compromised printer, including password-catching, password-snarfing (changing passwords), hijacking functions, grabbing print jobs and playing with a billing program.

O’Connor, who says he has proved in his research lab that these hacks are possible, showed a video of himself exploiting these vulnerabilities in his lab during his Black Hat presentation
 


Envia-ho a la tafanera Desa-ho a del.icio.us | 21:31 (# Enllaç permanent) | Comentaris: | Trackback:


Saló del Tinell



Envia-ho a la tafanera Desa-ho a del.icio.us | 20:57 (# Enllaç permanent) | Comentaris: | Trackback:


ISS manté aquesta Port knowledgebase, una base de dades on es documenta la llista de ports TCP i UDP habituals i el seu significat.


Envia-ho a la tafanera Desa-ho a del.icio.us | 20:56 (# Enllaç permanent) | Comentaris: | Trackback:


[News.com] Swedish bank hit by 'biggest ever' online heist. El banc suec Nordea confirma que ha perdut poc més d'un milió de dòlars com conseqüència d'un frau a la seva banca online.
Nordea believes that 250 customers have been affected by the fraud, after falling victim to phishing e-mails containing the Trojan. According to McAfee, Swedish police believe Russian-organized criminals are behind the attacks. Currently, 121 people are suspected of being involved.

The attack started by a tailor-made Trojan sent in the name of the bank to some of its clients, according to McAfee. The sender encouraged clients to download a "spam fighting" application. Users who downloaded the attached file, called raking.zip or raking.exe, were infected by the Trojan, which some security companies call haxdoor.ki.

Haxdoor typically installs keyloggers to record keystrokes, and hides itself using a rootkit. The payload of the .ki variant of the Trojan was activated when users attempted to log in to the Nordea online banking site. According to the bank, users were redirected to a false home page, where they entered important log-in information, including log-in numbers.
 


Envia-ho a la tafanera Desa-ho a del.icio.us | 20:52 (# Enllaç permanent) | Comentaris: | Trackback:

© Copyright 1996-2007 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
Wishlist
Gener 2007
Diu Dil Dim Dim Dij Div Dis
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      
Des   Feb

RSS




Contingut actualitzat




Categories


Darrers comentaris

Arxiu

Contingut antic
(ja no s'actualitza)


Articles
(fins maig 2003)



Versions anteriors
d'aquesta pàgina

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter