turvallisuus.org
|
Digitoday / Tietoturva Digitoday - uusimmat uutisotsikot ICT-alalta Lex Karpela on hengenvaarallinen Ahvenanmaan maakuntahallituksen internet-yhteyden katkaiseminen olisi voinut osua vaikka sairaalan yhteyksiin ja aiheuttaa hengenvaaran, arvioi Electronic Frontier Finland ry (Effi). Rajussa kritiikissä Effi muistuttaa, että kyseessä on täysin kotimainen lakipykälä. Pankkitunnukset parilla tonnilla Tietoturvayhtiön tutkija paljasti rikollisten nettipalvelun, josta voi ostaa nettipankkitilien tunnuksia ja salasanoja. Facebook-käyttäjien iät joutuvat syyniin Yhteisöverkosto Facebook lisää keinoja joilla nuoria käyttäjiä suojellaan ahdistelijoilta ja asiattomalta materiaalilta. Erityisesti käyttäjien iät joutuvat tarkkailuun. Ahvenanmaalla skandaali musiikin jakelusta maakuntahallituksesta Ahvenanmaan käräjäoikeus on määrännyt Tekijänoikeuden tiedotus- ja valvontakeskuksen TTVK:n hakemuksesta paikallisen teleyrityksen Ålands Datakommunikationin keskeyttämään tekijänoikeudella suojatun aineiston jakelun maakuntahallituksen liittymästä. Microsoft päivittää kolme kriittistä haavoittuvuutta Microsoft julkaisee tiistaina 13. toukokuuta kello 20 Suomen aikaa neljä tietoturvapäivitystä, joista kolme korjaa Microsoftin mukaan korkeimmalta vakavuusluokitukseltaan kriittisen haavoittuvuuden. Supo: Nettihyökkäykset uhkaavat ministeriöitä Suojelupoliisin mukaan perinteinen vakoilu on pysynyt entisellään. Uutena uhkana on verkon kautta tulevat hyökkäykset. Uusi tapa varastaa käyttäjätunnuksia ja salasanoja Roskapostittajat ovat keksineet uuden, mielenkiintoisen tavan varastaa käyttäjätunnuksia ja salasanoja, ilmenee tietoturvayhtiö Symantecin uudesta roskapostiraportista. Yhdysvaltain ulkoministeriöltä kateissa tuhat kannettavaa Erikoistarkastus on paljastanut, että Yhdysvaltain ulkoministeriöltä on kateissa noin tuhat kannettavaa tietokonetta. Osa koneista sisältää arkaluontoisia tiedostoja. Kiina: internet pysyy niin avoimena kuin mahdollista Kiinan kontrolli internetistä on huolestuttanut muun muassa Yhdysvaltoja olympialaisten lähestyessä. Kiina sanoo estävänsä olympialaistenkin aikaan pääsyä joillekin sivustoille. Valtioneuvosto: Tietoverkoissa iso rikollinen infrastruktuuri Tietoverkkoihin on syntynyt huomattavat mittasuhteet saavuttanut rikollinen infrastruktuuri, todetaan valtioneuvoston tänään keskiviikkona hyväksymässä sisäisen turvallisuuden ohjelmassa. Krakkerit aiheuttivat fyysistä tuskaa USA:n epilepsiasäätiö joutui häijyn ja epätavallisen krakkerihyökkäyksen kohteeksi. Motiivina oli ilmeisesti rahan sijaan ihmisten vahingoittaminen. PHP-kieli entistä ehommaksi Ohjelmointikieli PHP sai päivityksen, joka korjaa kielestä yli 120 ohjelmistovirhettä ja useita haavoittuvuuksia. Filmiyhtiöt haluavat piraateilta kymmenen miljoonaa euroa Tukholma - Jo neljän elokuvan ja yhden televisiosarjan luvaton levitys antaa aiheen noin kymmenen miljoonan euron korvaukseen, tuumivat elokuva-ajan jättiläiset jättäessään torstaina oikeuteen Pirate Baylle osoitetun huikean vaatimuksensa. Antipiraateilta iso korvausvaatimus Pirate Baylle Tukholma - Pirate Baylle osoitettujen korvausvaatimusten summa sen kuin kasvaa. Filmi- ja peliteollisuutta edustava Antipiratbyrån haluaa piraateilta huomattavan summan viitaten muun muassa "hypoteettisiin lisenssimaksuihin". FBI nöyrtyi nettikirjaston edessä Yhdysvaltalainen digitaalinen kirjastopalvelu Internet Archive kieltäytyi luovuttamasta liittovaltion poliisi FBI:n vaatimia tietoja eräästä asiakkaastaan. FBI päätti nyt perua vaatimuksensa. Schneier on Security A blog covering security and security technology. Friday Squid Blogging: Squid Fishing Lures In a variety of colors. EDITED TO ADD (4/10): Link fixed.... Schneier Talks Last month I gave a talk at InfoSecurity Europe in London. The title was "Reconceptualizing Security," or maybe "The Theater of Security," and it is a follow-on to my work on the psychology of security. I haven't yet written this work up, but you can listen to or watch my talk.... Making Security Cuddly I don't know what I think of Sweet Dreams Security.... Cell Phone Spying A handy guide: A service called World Tracker lets you use data from cell phone towers and GPS systems to pinpoint anyone?s exact whereabouts, any time ? as long as they?ve got their phone on them. All you have to do is log on to the web site and enter the target phone number. The site sends a single text... History of the U.S. Surveillance Debate Excellent article, chronicling the surveillance debate from the mid 1980s until today. Don't expect good coverage of the current debate, however: the legality of the NSA's recent domestic eavesdropping program, and the legality of the assistance provided by the telcos.... Tourists, Not Terrorists Remember the two men who were exhibiting "unusual behavior" on a Washington-state ferry last summer? The agency's Seattle field office, along with the Washington Joint Analytical Center, was still seeking the men's identities and whereabouts Wednesday as ferry service was temporarily shutdown when a suspicious package was found in a ferry bathroom and taken away by authorities. "We had various... Third Annual Movie-Plot Threat Contest Semi-Finalists A month ago I announced the Third Annual Movie-Plot Threat Contest: For this contest, the goal is to create fear. Not just any fear, but a fear that you can alleviate through the sale of your new product idea. There are lots of risks out there, some of them serious, some of them so unlikely that we shouldn't worry about... Al Qaeda Threat Overrated Seems obvious to me: "I reject the notion that Al Qaeda is waiting for 'the big one' or holding back an attack," Sheehan writes. "A terrorist cell capable of attacking doesn't sit and wait for some more opportune moment. It's not their style, nor is it in the best interest of their operational security. Delaying an attack gives law enforcement... London's Cameras Don't Reduce Crime News here and here: Massive investment in CCTV cameras to prevent crime in the UK has failed to have a significant impact, despite billions of pounds spent on the new technology, a senior police officer piloting a new database has warned. Only 3% of street robberies in London were solved using CCTV images, despite the fact that Britain has more... State Department Loses Hundreds of Laptops Oops: As many as 400 of the unaccounted for laptops belong to the department?s Anti-Terrorism Assistance Program, according to officials familiar with the findings. Bet you anything those laptops weren't encrypted.... Dual-Use Technologies and the Equities Issue On April 27, 2007, Estonia was attacked in cyberspace. Following a diplomatic incident with Russia about the relocation of a Soviet World War II memorial, the networks of many Estonian organizations, including the Estonian parliament, banks, ministries, newspapers and broadcasters, were attacked and -- in many cases -- shut down. Estonia was quick to blame Russia, which was equally quick... Security Engineering, by Ross Anderson I just received the second edition of Ross Anderson's Security Engineering in the mail. It's beautiful. This is the best book on the topic there is, and I recommend it to everyone working in this field -- and not just because I wrote the foreword. You can download the preface and six chapters. (You can also download the entire first... The Register - Security Biting the hand that feeds IT Vista security credentials tarnished in malware survey Better off with a Win 2000 box Windows Vista is better at protecting against malware than XP but more easily infected than Windows 2000, according to a study by Australian anti-virus firm PC Tools.? India and Belgium decry Chinese cyber attacks Join the ranks Belgium and India have joined the growing ranks of countries voicing concerns about cyber attacks originating from China. Earlier this week, officials from both countries said computer networks inside their borders are routinely targeted by hackers trying to ferret information that could benefit the Chinese government.? I Was A Teenage Bot Master The Confessions of SoBe Owns Exclusive One day in May 2005, a 16-year-old hacker named SoBe opened his front door to find a swarm of FBI agents descending on his family's three-story house in Boca Raton, Florida. With an arm and leg in casts from a recent motorcycle accident, one agent grabbed his good arm while others seized thousands of dollars worth of computers, video game consoles and other electronics. His parents looked on.? Facebook agrees to child-safety measures Reining in Web 2.0 predators Facebook has reached an agreement with 50 attorneys general to permanently deploy measures designed to rein in pedophiles and other predators on the social networking site.? Interpol appeal unmasks US actor as child abuse suspect Operation IDent-ification A man matching the description of a suspected child abuser who became the target of an international manhunt earlier this week has been arrested in the US.? Renault F1 comp site spills entrants' details You will never break the chain A Grand Prix competition from Renault hit the barriers on Thursday after it emerged that the motoring firm was inadvertently leaking entrants' personal details onto the web.? HSBC in further data loss Stolen Hong Kong server contained data on 159K Security-incident prone bank HSBC has admitted losing a server containing transaction data on 159,000 Hong Kong-based account holders.? Firefox language pack provides adware back-door Ho Chi Hack trail Mozilla has warned that the Vietnamese language pack of Firefox 2 was compromised as a result of a viral infection.? Rare SCADA bug poses power plant risk Wonderware scare Security watchers warn of a rare vulnerability involving software used to control industrial systems. A denial of service vulnerability in monitoring software from Invensys poses a severe risk to the factories and utilities running its Wonderware subsidiary's InTouch SuiteLink application.? FBI withdraws secret Internet Archive probe Abuse of power alleged The FBI has withdrawn a secret order that used new anti-terrorism powers to demand information about a user of the Internet Archive without a court order after attorneys challenged it as an unconstitutional abuse of power.? Rogue MP3 Trojan streaks across P2P networks Worst viral outbreak in three years Hundreds of thousands of examples of a new Trojan that poses as a media file have flooded onto P2P networks.? Peter Gabriel's website is back Womad is safe... Peter Gabriel's website and the website and ticket buying site for Womad, the world music festival he founded, are back online today after their servers and routers were stolen at the weekend.? Private sector saviours wanted for desperate ID scheme Home Office chucks in the cards? Plans for the widespread introduction of fingerprint passports and ID cards, already delayed until 2012, have receded further into the distance with the publication of the latest Identity & Passport Service cost report for the ID scheme. This effectively pulls the plugs on the network of IPS-run interview centres, and lobs future responsibility for these and for biometric enrolment over to private sector companies.? MS UK kills mystery 'Live to Code' site Misconfigured marketing offshoot pulled Microsoft has pulled an apparently rogue internal marketing project that sat quietly, but not unnoticed, on the same servers as its main UK website for at least a fortnight.? Google launches security group for open source oCERT to make the world safe for GPL Google is spearheading a volunteer workforce it hopes will become the centralized authority for responding to security issues in open source software.? NIST IT Security : News IT security news updated throughout the day. Focusing on risk mitigation and compliance issues; data encryption, NIST FIPS and SP 800 requirements, FISMA, HSPD-12, Federal Government Policies, Procedures, Guidelines, PIV II, A-130, HIPAA, NIST Publications, Sarbanes-Oxley and POA M reporting. Featuring a compliance forum, requirements whitepapers, downloads, anti-virus information, NIST - IT Security Compliance and vulnerabilities, general security information and tips. WordPress Sites Need To Upgrade, The Rest Of Us Need To Watch This Too. A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. SQL Injections Continue ? 100s of Thousands of URL's Infected No one is sure of the number of SQL servers are infected but the guess is over 100,000. Symantec Raises Threat Level Due To In The Wild Image File Exploits Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution. SANS Internet Storm Center Starts Monthly Podcast If you dont have the time or interest to read about the latest IT security news the SANS.org podcast or some of the other security podcasts might help you keep up. FBI Reports Online Crime At All Time High The U.S. FBI reports that online crime is at an all time high. So why are we hearing so little about it? Symantec Antivirus ActiveX Vulnerability Vulnerabilities have been discovered in an ActiveX control that ships with several Symantec products, including Norton AntiVirus MS Excel "Extremely Critical" Vulnerability Allows Remote Code Execution Microsoft has posted information about a new "Extremely Critical" zeroday vulnerability in MS Excel. This vulnerability effects most versions of Excel on both Windows and Mac OS X. RealPlayer Buffer Overflow Vulnerability ? Highly Critical The current problem is identified as ?RealPlayer Unspecified Buffer Overflow Vulnerability? and can be used to run arbitrary executable code. Highly Critical and Extremely Critical Vulnerabilities in Lotus Notes and App... Lotus Notes contains a Highly Critical vulnerability with its Lotus 123 viewer. Apple Quicktime contains an Extremely Critical vulnerability. Infosec Writers Latest Security Papers Papers submitted by security professionals are published on the site and archived for readers. Categories include cryptography, E-mail security, exploitation, firewalls, forensics, honeypots, IDS, malware & wireless security. An Approach to Web Application Threat Modeling The aim of this paper, written by Akash Shrivastava, is to identify relevant threats and vulnerabilities in the Web Application and build a Security Framework to help in designing a secure Web Application. Computer Forensics Procedures, Tools, and Digital Evidence Bags: What They Ar... This paper, written by Brett Pladna, will try to demonstrate the importance of computer forensics by describing procedures, tools and differences in the use for individuals/small organizations vs. large organizations. Security Needs in Embedded Systems The paper discusses the hardware and software security requirements in an embedded device that are involved in the transfer of secure digital data. The paper gives an overview on the security processes like encryption/decryption, key agreement, digital signatures and digital certificates that are used to achieve data protection during data transfer. The paper also discusses the security requirements in the device to prevent possible physical attacks to expose the secure data such as secret keys from the device. The paper also briefs on the security enforced in a device by the use of proprietary security technology and also discusses the security measures taken during the production of the device. A Guide E-Mail Systems and Security Brian Donadio contributes his paper which provides information on secure methods of sending and receiving E-Mail over the Internet. A Comparison of VNC Connection Methods This paper, written by Frank Isaacs, discusses different methods of deploying VNC with an emphasis on the security considerations of each method, and the tradeoffs associated with the convenience of each method. Three Linux Security Basics This paper, written by Jeff Drake, outlines some basic security issues and concerns as they relate to Linux server security and tools and techniques that can be implemented to harden the system. Server Virtualization and Information Security Concerns Daniel James and William J. Sparks discusses virtualization, the benefits, security and financial imapact. Privacy? Protecting Consumer Data in a Wireless World Robin Link submits this paper on the personal information vulnerable over wireless retail networks and how PCI plays a part in all of it. Extensible Authentication Protocol (EAP) Security Issues This document, written by Samuel Sotillo, presents an overview on some security issues that affect the Extensible Authentication Protocol as defined by the IETF RFC 3748. Malware – What It Is and How to Avoid It Daniel James submits this study on the different types of malware and how to protect against them. SecurityFocus News SecurityFocus is the most comprehensive and trusted source of security information on the Internet. We are a vendor-neutral site that provides objective, timely and comprehensive security information to all members of the security community, from end users, security hobbyists and network administrators to security consultants, IT Managers, CIOs and CSOs. News: Groups warn travelers to limit laptop data Groups warn travelers to limit laptop data News: Patches pose significant risk, researchers say Patches pose significant risk, researchers say News: U.S. gov't pushes cybersecurity at con U.S. gov't pushes cybersecurity at con >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News: Web developers, fix thy Flash Web developers, fix thy Flash Brief: Proposed cybersecurity bill to pressure DHS Proposed cybersecurity bill to pressure DHS Brief: India, Belgium warn of Chinese attacks India, Belgium warn of Chinese attacks >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Brief: Vietnamese pack infects Firefox users Vietnamese pack infects Firefox users Brief: Senators quizz gov't on cybersecurity initiative Senators quizz gov't on cybersecurity initiative News: Thoughts of a Teenage Bot Master Thoughts of a Teenage Bot Master >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News: Radio Free Europe hit by DDoS attack Radio Free Europe hit by DDoS attack News: Flash vuln fells Vista Flash vuln fells Vista News: Estonia fines man for DDoS attacks Estonia fines man for DDoS attacks >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News: Nigeria enlists Microsoft to fight spam scammers Nigeria enlists Microsoft to fight spam scammers News: Cross-Site Scripting Worm Hits MySpace Cross-Site Scripting Worm Hits MySpace News: Another data security bill in the works Another data security bill in the works >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Dark Reading: Dark Reading News Analysis Dark Reading - The Business of IT Security Tech Insight: Finding & Prioritizing Web Application Vulnerabilities Web app flaws are rapidly becoming the most serious threat to your data. Do you know how to identify them - and which ones to fix first? Hacker's Choice: Top Six Database Attacks It doesn't take a database expert to break into one Ex-Feds Start Up ID Theft Protection Service iSekurity promises to find out who stole your identity - or pay you $11,000 Free 'AxBan' Tool Kills Bad ActiveX Controls Errata Security offers freebie ActiveX 'killbit' tool for users Who Killed My Hard Drive? University study examines the causes and costs of hard drive failure New Spam Attack Exploits Edunet Servers Exploit demonstrates creativity, but little damage caused so far, BitDefender says Business Continuity News Business continuity and disaster recovery news from around the world. Provided by Continuity Central, the international business continuity news and information portal. Human resilience strategies: the reflective phase The last in a series of articles looking at human resource aspects of business continuity management. SGX issues consultation paper on business continuity management framework Business continuity management requirements will have to be adopted and implemented by SGX member firms. Business Continuity Awards 2008 : the winners On the evening of 8th May 2008, CIR magazine presented its Business Continuity Awards to this year's winners. The awards went to... New study shows high threat of big California quake California has more than a 99 percent chance of having a magnitude 6.7 or larger earthquake within the next 30 years, according to scientists using a new model to determine the probability of big quakes. UK remains under-prepared for flooding, warns EFRA Select Committee The infrastructure to deal with last year's floods was, and still is, in an 'unclear and chaotic state'. Business continuity briefs Short news pieces. RSS by CARP |