Archive

Posts Tagged ‘Security’

Firefox v3.5 Memory corruption vulnerability discovered

July 15th, 2009

         If you want to upgrade your Firefox to the latest 3.5 then think again.

     SBerry released code on Milw0rm, has issued an advisory warning of a memory corruption error in Mozilla’s newest version of Firefox, version 3.5. The vulnerability, if exploited, allows code execution that could lead to system compromise.

       The vulnerability is caused due to an error when processing JavaScript code handling e.g. "font" HTML tags and can be exploited to cause a memory corruption.

         

Here is SBerry Posted code.

     Secunia is offering advice to Firefox users that until this newest vulnerability is patched, they should avoid untrusted websites and links. However, Brian Krebs took the smart road in his advice on the issue. Krebs, who is a reporter for the Washington Post, advised his users to disable "javascript.options.jit.content" in about:config. This fix has a drawback however, it will lower the rendering speeds of JavaScript, which is one of the major performance improvements in Firefox 3.5. If you are willing to take the trade, then his fix should work fine.

DNS INFORMATION LEAK

     There is another little glitch in firefox that exposes DNS information for users wanting to remain anonymous using proxy settings.

    Tw1zl3r reports that, “The DNS Leak issue in FireFox 3.5 is a BIG BUG because even if you use the about:Config force remote DNS look ups using a proxy the requests are still sent to your local DNS. The local DNS query leaks your web searches out for anyone with a brain cell and WireShark to view a users web query’s in plain text. FireFox 3.5 has the toggle network.proxy.socks_remote_dns option in it but when adding the option in about:Config it does nothing and is all show no go. The setting does nothing and allows DNS to Leak.”

      However, some users who tested his point wonder if the DNS leak has more to do with an add-on than Firefox itself. However, if it is a Mozilla issue, then it would need to be addressed as soon as possible.

[Source]

Norton Internet Security and Antivirus 2010 Beta

July 5th, 2009

        

     The Symantec not to be forgotten amid the release of Kaspersky, Panda and Microsoft Security Essential. On 2 july 09 , Symantec  announced its new line of Beta products.Norton Internet Security 2010 Beta and Norton Antivirus 2010 Beta.

 

Major Updates:-

  • Total Compatibility with Windows 7 .
  • Faster.
  • Increased power detection system (SONAR 2).
  • Protection against malware exclusive.
  • New Norton Insight system that identifies trusted applications to speed up the scanning.

     Right now, for me it is difficult to comment, whether Norton Antivirus 2010 or Norton Internet Security 2010 are good, many consume resources or have good power of detection.

    So be the one… try their beta version and don’t forget to share your experience with us via comments.

Note:- After clicking on the download links you will be directed  to a page where it is necessary register before you download.

   There are chances that you get an error message (see below)

    If that the case then you can use US proxy for downloading Norton Beta Products.

 

Download Norton Internet Security 2010 Beta

Download Norton Antivirus 2010 Beta

Home Page

 

Enjoy!

 

Another Major Web Threat : Nine-Ball Compromises More Than 40,000 Legitimate Websites

June 21st, 2009

        Just as we were getting ready to declare victory over Conficker (and settling in for a long battle with Gumblar), along comes Nine-Ball, another difficult-to-defeat offensive that hijacks Web sites and tries to load malware onto a user’s PC. The worm has a trick up its sleeve, repeat visitors to infected sites are dumped to Ask.com, a sneaky move that prevents security experts and investigators from being able to discover too much about the host of the malware.

What is Nine-Ball?

     Nine-Ball is a multi-layered Web browser attack targeting legitimate Web sites to redirect users to malicious sites owned by the attacker. The downloaded malware attempts to infect user’s computer through a number of exploits including Adobe Reader, QuickTime, Microsoft Data Access Components (MDAC) and AOL SuperBuddy.

     The attack name "Nine Ball" refers to the name of the final landing page which is full of malicious drive-by exploits that are automatically downloaded to computers without user’s consent or knowledge. Once infected, anything the victim types could be monitored and used to commit identity theft, such as stealing credit card numbers, passwords or other sensitive data.

How does the threat work?

1. Victim visits legitimate infected site.

2. Victim is redirected to a series of different sites owned by attacker.

3. The final redirect is to a malicious drive-by download site, which attempts to download malware to victim’s computer through a number of exploits including MDAC, AOL SuperBuddy, Adobe Reader, and QuickTime exploits.

4. The malicious programs typically attempt to steal information from the victim via a keystroke logger.

     

5. Once a user has already visited the malicious web page, these repeat visitors are re-directed to the search engine site Ask.com. We assume this design is a technique to evade investigation.

       According to Internet security firm Websense , Nine Ball has already compromised over 40,000 Web sites.

      There is currently no sure-fire way to protect yourself from or clean up an infection by Nine-Ball (except reinstalling Windows). All you can do is to make sure that all your software packages, including those targeted by the attack, are up-to-date, and to install the appropriate security software.

For More Visit Here and here

 

Free BitDefender Total Security 2009 License for 6 months

June 20th, 2009

      Previously I’ve shared with you BitDefender Antivirus license for 2 months and now today I’m sharing with you another BitDefender promotion by PC Magazine Germany but this time it is for Total Security 2009.The product key is valid for 6 months.

      BitDefender Total Security 2009 provides comprehensive proactive protection against all Internet security threats, along with system maintenance and backup, without slowing down your PCs.

Confidently download, share and open files from friends, family, co-workers – and even total strangers!

  • Improved: Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time
  • Proactively protects against new virus outbreaks using advanced heuristics

Protect your identity: shop, bank, listen, watch privately and securely

  • Blocks attempted identity theft (phishing)
  • Improved: Prevents personal information from leaking via e-mail, web or instant messaging

Guard your conversations with top-of-the line encryption

  • Instant Messaging Encryption
  • File Vault securely stores personal information or sensitive files
  • Backs up files and folders locally
  • Provides secure on-line storage

Connect securely to any network at home, in the office or away

  • Automatically modifies firewall protection settings to suit location
  • Wi-Fi monitor helps prevent unauthorized access to your Wi-Fi network

Protect your family and their computers!

  • Blocks access to inappropriate websites and e-mail
  • Schedules and limits kids’ access to Internet and to applications

Play safe, play seamlessly!

  • Improved: Reduces the system load and avoids requesting user interaction during games

Get fine-tuned performance from your computer !

  • Uses few system resources
  • Laptop mode prolongs battery life
  • Removes unnecessary duplicates of files and registry entries
  • Irrecoverably erases unwanted files and "traces" of files

How To Get It? Follow these Steps:-

 

    
1.Use web proxy ( http://www.surf-proxy.de/ ) and type in http://www.bitdefender.de/site/Promotions/pcmag2009 into searching bar and click ‘Go’.

2. Then enter in your first,last name and email ,click ‘Registrieren’.

3. The 6 months Bitdefender Internet Security 2009 product key inside your register email.

   

They are delivering the same license key therefore I’m not hiding it from my image.

 

Download BitDefender2009

Enjoy BitDefender Total Security 2009 ;)

 

Free Norton Antivirus 2009 subscription valid for 360 days

June 19th, 2009

          If you missed out Free Norton Antivirus 2009 product key for 1 year, you have another chance to get Norton Antivirus 2009 (360 days) without any problem.

                                          

       The concept on how to get a total of 360 days subscription for Norton Internet Security 2009 is the same. I found a total of 3 NAV 2009 OEM installers (2 x 90 days + 1 x 180 days) and  If you’re unable to uninstall Norton Internet Security 2009, you can use removal tool by Norton to manually uninstall it however there is a small  problem: the first two (90 days) are already in English and 180 days is in German.

  

    I believe that those who already use the program for some time found no problems in handling it, however, I am trying to find a way to translate it or if someone knows, then you can express that in the comments.

FREE Norton Antivirus 2009

1. NAV2009_16.0_Build_0000001_OEM90_Microsoft.exe (90 Days)

2. PRNAV2009-90ML.exe (90 days)

3. NAVPCWelt180.exe(German 180 days)

 

    The installation of any of them is very simple and the end of the process you will see a small screen so you can fill in your name, e-mail etc. ..and that’s not a big deal.

  Feel free to express your views.

Enjoy!