Proaktive IT-Sicherheit
 

Sicherheits-Center

Neuste Beiträge - Exploit analysis

BEAST (Browser Exploit Against SSL/TLS)

A successful attack is not particularly easy to carry out, as it depends on several prerequisites.

» mehr Informationen

Dangerous images

Recent weeks have shown that images are used as a malware spreading technique; particularly images that appear after performing a Google image search.

» mehr Informationen

The RTLO unicode hole - sequence manipulation as an attack vector

Do not rely on any file attachment or file on any device to be safe based on its file name.

» mehr Informationen

Reflections on the PDF vulnerability

Earlier this month we wrote about a vulnerability in the PDF specification that could be utilized to run malicious programs embedded in a PDF file. Proof-of-concept code was published, and it was expected that real-life malware that used this technique might appear soon.

» mehr Informationen

Scary technique utilizing functionality in the PDF specification

Exploitation of how applications handle files in the Portable Document Format (PDF) is one of the most used techniques to successfully create malicious software. Usually this is accomplished by utilizing vulnerabilities in the applications used to read PDF documents, like the very popular free program, Adobe Reader.

» mehr Informationen

Aurora Attack - Zero day exploit in IE6

Aurora attacks, which is known to be originated from china, is a major attack in the recent past which used an Internet explorer exploit code to attack companies like Google and Adobe and succeeded in stealing some intellectual properties.

» mehr Informationen

Use-after-free vulnerability in Adobe

Recently a new vulnerability has been discovered in Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). The vulnerability resides in Doc.media.newPlayer method. It’s a use-after-free vulnerability which can allow an attacker to execute arbitrary code.

» mehr Informationen

Neuste Blog-Einträge [EN]

The insecurity paradox

2011-08-29
The formula here attempts to explain a paradox in security analysis: If it is true that security is only as strong as its weakest link, why are not those who use insecur...
mehr >>

The 10 most insecure passcodes

2011-06-16
Earlier this week I read an extremely interesting and impressing blog item by Daniel Amitay: Most Common iPhone Passcodes. Amitay has analyzed more than 200 000 passcodes used in an app with a similar...
mehr >>

Purchasing and downloading outdated software

2011-05-23
Last week in the "JoshMeister On Security" blog, the topic was about Apple's Mac App Store, and the fact that software available from this store may not be the latest version. The blog's aut...
mehr >>