From the monthly archives:

March 2010

iPhone, Firefox, Safari, IE8 Pwned!

by Mahesh Kukreja on March 25, 2010

The three day Pwn2Own contest at the CanSecWest security show is on.

And at the end of the day, 3 major browsers, Firefox, Safari and IE8 were successfully exploited.

Also a non-jailbroken iPhone was also hacked and its SMS database was stolen.

Vincenzo Iozzo and Ralf Philipp Weinmann redirected an iPhone to a web site they’d set up, crashing its browser and then stealing its entire SMS database (including some erased messages). It is possible, however, to set up a similar attack to work without crashing the browser, hackers claim, and set up different attack payloads. Iozzo and Weinmann won a $15,000 prize for successfully demonstrating the attack. Details about the attack will be released once Apple is notified and the security hole is patched.

A successful remote attack against a MacBook Pro running the latest version of Apple’s MacOS X was done by Charlie Miller – exploiting a unknown security vulnerability in the Safari browser to launch a remote shell and winning himself $10,000 plus the laptop for his work.

Peter Vreugdenhil managed to bypass Windows security features including Data Execution Prevention code via Internet Explorer 8 to take over a PC (running the latest patched version of Windows 7) – and again receiving $10,000 plus the hardware.

CNET provides all details of the hacks here.


Related Posts
Related Websites

{ 1 comment }

Facebook Hacking Alert! Beware!

by Mahesh Kukreja on March 25, 2010

I just checked my Junk/Spam folder of my Yahoo! Mail to see an email containing confirmation for Facebook Password Reset. The mail is attached with a .zip file (probably containing a virus).

facebook hack

I didn’t request any password reset for my account from Facebook. So, it’s probably a work of the Black Hats.

Beware of such emails. No site will send you an attached file even if you have requested for a password request. Don’t just download the attached file because the email came from @facebook.com. This is just done by email spoofing.

So, protect yourself from Hackers & Viruses.

Happy Social Networking.


Related Posts
Related Websites

{ 0 comments }

NameCheap coupon code for March 2010

by Mahesh Kukreja on March 2, 2010

Here is the coupon code for NameCheap.com for March 2010.

Coupon Code: NCSPRING – $8.81 domain name registration at NameCheap.


Related Posts

{ 0 comments }