Security

Battle for Wesnoth 1.2.7 (stable) Released Due to DoS

I didn't expect to blog twice in the same day regarding Linux gaming, yet anyhow... Battle for Wesnoth is a free turn based strategy game for personal computers released under the GNU General Public License. The Wesnoth team has released a DoS update, bring the stable release to v1.2.7. This is a bugfix release for 1.2.x and it is compatible with the other 1.2.x versions. "The main reason for this release was an important fix where an utf8 char at the wrong position in a chatmessage could crash other clients." This bug was filled as CVE-2007-3917.Read more

What Happens When Our Encryption is Broken

The advent of quantum computers that can run a routine called Shor’s algorithm could have profound consequences. It means the most dangerous threat posed by quantum computing - the ability to break the codes that protect our banking, business and e-commerce data - is now a step nearer reality.

Shor knew that number theory provides a shortcut to finding prime factors. It involves determining the so-called “period” of a certain function, which is related to the number to be factored. Defining the period of such a function is not straightforward, but finding the period of a function related to the number 15 illustrates it.

First, find a number that has no factors in common with 15 other than 1. Suppose we pick 11. Read more

The Great Firewall of China Vs. Mind Over Mind

the Great Firewall is not really a barrier, but a surveillance system

China’s prohibition of the internet seems to have been more successful than predicted a few years ago. The system has been dubbed “the Great Firewall of China” calling to mind a barrier between China’s part of the internet and the rest of the world.

Great China Firewall Cop
The researchers call the Chinese censorship system a “panopticon” rather than a firewall. The concept of the design is to allow an observer to observe (-opticon) all (pan-) prisoners without the prisoners being able to tell if they are being observed or not, thus conveying a "sentiment of an invisible omniscience." A new mode of obtaining power of mind over mind, in a quantity hitherto without example.

In 2006, a team at the University of Cambridge, England, discovered that when the Chinese system detects a banned word in data traveling across the network, it sends a series of three "reset" commands to both the source and the destination. These "resets" effectively break the connection. But they also allow researchers to test words and see which ones are censored.Read more

TOR Vs Security (sniffing exit nodes )

The (IT) press is buzzing with attacks against the onion router (TOR).

The problem is lies in an atack performed and used to gain access to mailboxes by creating and sniffing the unencrypted side of some Tor exit nodes.

"Tor -tries to- provide anonymity. Anonymity and security are two different beasts. When passing unencrypted traffic (such as POP3, IMAP etc) you are basically not only handing the malicious Tor exit node the contents of your email, but also -in many cases- the keys (login and password) to your mailbox. - By Swa Frantzen [ http://isc.sans.org/diary.html?storyid=3366 ]Read more

China’s cyber army is preparing to march on America, says Pentagon

Chinese military hackers have prepared a detailed plan to disable America’s aircraft battle carrier fleet with a devastating cyber attack, according to a Pentagon report obtained by The Times. The blueprint for such an assault, drawn up by two hackers working for the People’s Liberation Army (PLA), is part of an aggressive push by Beijing to achieve “electronic dominance” over each of its global rivals by 2050,

the vulnerability of modern society

particularly the US, Britain, Russia and South Korea. [...]

President Bush, without referring directly to Beijing, said this week that “a lot of our systems are vulnerable to attackRead more

eBay Botnet Attack

Aladdin Knowledge Systems today announced that the Aladdin eSafe Content Security Response Team (CSRT) has uncovered significant new details surrounding the eBay botnet attack it first discovered on Monday. [...] "Through new infection and attack methods, this targeted threat shows that Trojans are continuing to evolve into extremely dynamic, adaptive tools for online criminals, resulting in a potentially damaging aftermath for its individual victims," said Ofer Elzam, director of product management for the Aladdin eSafe Business Unit and head of the Aladdin eSafe CSRT. "This eBay botnet attack is unique, and definitely not found through traditional security measures. Aladdin's innovative security specialists are closely monitoring this new threat and are notifying the Web sites we determine are infecting Web surfers."

Tags

Syndicate content