View our reviews on Hot Scripts You can now obtain our example scripts and/or vote for them at Hotscripts. To visit Hotscripts click here.

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts


I just noticed that Littleton Coins' website has a security vulnerability that improperly handles/transmits passwords.
While recently visiting the Littleton Coin website, www.littletoncoin.com, I noticed that the logon Id and surprisingly enough the logon Password are sent in plain text via the URL when you visit your "My Account" page right after logging in. This means that anyone who can access the server log files (not the encrypted database entries), folks at your ISP, or ANYONE who can see what pages you visit can now obtain your user name and password to this site. When you combine this with the fact that many users store their credit card details on these eCommerce sites, it is not hard to imagine that given enough time, this could become quite a serious matter.

In the screenshots below, the example logonId is 'coin-user' and the example logonPassword is 'coin-pass.'

Logon ID screenshot

Password screenshot

Now, the site does use HTTPS which is good as it encrypts the communication between server and client. However, the technique of sending plain-text passwords via URLs should never be used in the real world, much less by a site that is classified as a substantial eCommerce site.

Bottom line, I like Littleton Coin...I am sure their web/IT guys make way more than I do...Never send plain-text passwords via URL

Observations: I can only seem to recreate this when I open a fresh browser connection to www.littletoncoin.com, then go to "Log In", then go straight to "My Account". At this point you should see both the logon Id and password within the URL. However, If I log in, then look at something before going to the "My Account" page, then I do not see the password being sent via the URL.

Update: As of today, Mar 12, 2013, I have spoken with an individual at Littleton Coin who has stated that this issue is being addressed and should be fixed by tomorrow.

It couldn't be...could it? Another error found on the Littleton Coin website: 1912 Buffalo Nickel? Come on guys!
[Read more ...]

Bookmark / Share:
StumpleUpon Ma.gnolia DiggIt! Del.icio.us Blinklist Yahoo Furl Technorati Simpy Spurl Reddit Google


Do you have a thought about this article? Post a comment and tell us about it!

The best way to protect yourself from an online financial scam is to diligently check your bank accounts. At least, until now. Security firm Trusteer has found an elaborate new computer virus that not only helps fraudsters steal money from bank accounts, it also covers its tracks.
Think of a crime plot involving a spy who plans to break into a high-security building and begins by swapping out security camera video so guards don't notice anything is amiss. Known as a surveillance camera hack, the technique has been used in dozens of movies.

A new version of the widely prevalent SpyEye Trojan horse works much the same way, only it swaps out banking Web pages rather than video, preventing account holders from noticing that their money is gone.
advertisement

The Trojan horse employs a powerful two-step process to commit the electronic crime. First, the virus lies in wait until a customer with an infected computer visits an online banking site, steals their login credentials and tricks the victim into divulging additional personal information such as debit card information. Then, after the stolen card number is used for a fraudulent purchase, the virus intercepts any further visits to the victim's banking site and scrubs transaction records clean of any fraud. That prevents -- or at least delays -- consumers from discovering fraud and reporting it to the bank, buying the fraudster critical extra time to complete the crime.

Trusteer calls it a "post transaction" attack, because much of the virus' effectiveness is attributable to its ability to control what victims see after fraudulent transactions occur. Amit Klein, chief technology officer for Trusteer, said he believes criminals have used the technique for a few months, and it has infected real consumers.

"I predict that the use of post transaction attack technology will significantly increase as it enables criminals to maximize the amount of fraud they can commit using their initial investment in malware toolkits and infection mechanisms," Klein said.

The new SpyEye came to Trusteer's attention when a large retail bank in the United States spotted it and shared with the firm, he said.

Read the entire article:
http://redtape.msnbc.msn.com/_news/2012/01/06/9986119-new-virus-raids-your-bank-account-but-you-wont-notice
[Read more ...]

Bookmark / Share:
StumpleUpon Ma.gnolia DiggIt! Del.icio.us Blinklist Yahoo Furl Technorati Simpy Spurl Reddit Google


Do you have a thought about this article? Post a comment and tell us about it!


An unpatched security flaw in Apple’s iTunes software allowed intelligence agencies and police to hack into users’ computers for more than three years, it’s claimed.
A British company called Gamma International marketed hacking software to governments that exploited the vulnerability via a bogus update to iTunes, Apple's media player, which is installed on more than 250 million machines worldwide.

The hacking software, FinFisher, is used to spy on intelligence targets’ computers. It is known to be used by British agencies and earlier this year records were discovered in abandoned offices of that showed it had been offered to Egypt’s feared secret police.

Apple was informed about the relevant flaw in iTunes in 2008, according to Brian Krebs, a security writer, but did not patch the software until earlier this month, a delay of more than three years.


Read the entire story here:
http://www.telegraph.co.uk/technology/apple/8912714/Apple-iTunes-flaw-allowed-government-spying-for-3-years.html
[Read more ...]

Bookmark / Share:
StumpleUpon Ma.gnolia DiggIt! Del.icio.us Blinklist Yahoo Furl Technorati Simpy Spurl Reddit Google


Do you have a thought about this article? Post a comment and tell us about it!


'Many types of electronic devices or information storage medium can be hacked to either give up information or perform actions it wasn't initially designed to do. The vulnerability of some of your everyday devices might surprise you.'

1. Medical implants

"Insulin pumps are apparently even more susceptible to outside interference, and at the recent Black Hat hacker conference in Las Vegas, the life-saving pumps were shown to be vulnerable from distances of up to a half mile. Using power radio antennas, hackers can hijack a pump's wireless signal and cause it to give a blast of insulin to a wearer, with potentially deadly results."


2. Baby monitors

"What most users probably don't realize, is that the dozen or so wireless channels that these helpful devices use can often be picked up outside the home — giving anyone with a similar device or wireless receiver an undetectable window into your home."


3. Automobiles

"These days, security experts are worried about much more tech-savvy car thieves who can unlock your car, or even start it, simply by shooting it a text message or two. Many automotive systems — such as OnStar — utilize the same type of cellular technology as a common cell phone"


4. Garage door openers

"Hackers can easily modify a standard door opener to accept a USB port, and software is readily available on the web to modify how it operates. A number of tutorials can be found online to walk an amateur hacker through the process of hacking your garage door in just minutes."


5. The human brain

"In fact, the Defense Advanced Research Projects Agency (DARPA) is funding a $4.9 million program to reverse-engineer the human brain in an effort to mine its computational abilities."



Read the entire article here:

http://news.yahoo.com/blogs/technology-blog/5-things-probably-didn-t-know-could-hacked-174330493.html


[Read more ...]

Bookmark / Share:
StumpleUpon Ma.gnolia DiggIt! Del.icio.us Blinklist Yahoo Furl Technorati Simpy Spurl Reddit Google


Do you have a thought about this article? Post a comment and tell us about it!