home contact keylogger.org add keylogger.org to favorites set keylogger.org as homepage Anti-Keylogger.org
Keylogger testing and reviews

Keylogger testing policy

Press-releases

Keylogger developers

Links
Monitoring Software Keylogger articles

Get Free Software

Keylogger chat

Keylogger forum

Sponsorship & services
Advertising
Your Ad Here
Site News
Current section
Keylogger.Org Site News

October 17, 2008

New version of KeyProwler Pro added!

Security World News
Keylogger.Org Security World News

November 20, 2008

International Challenges in PCI Security

Security firm Finjan raises $22 million

iTunes customers angry over copy protection moves at Apple

Have lessons of last year's HMRC fiasco sunk in?

Secerno and F5 hook up on network security

Mozilla warns of Firefox China add-on

Google opens up for mashup security

Cotton Traders tightens credit card protections

Gov't: Most biometric checks will bypass ID database

Antivirus firms unfazed by free Microsoft product

Teenager pleads guilty to botnet, 'swatting' charges

How much does spam cost you? Google will calculate

Feds urged to provide cybersecurity incentives

Fortinet beefs up midrange FortiGate security appliance

Voting

We are planning to redesign our site. We would like You to express your opinion in this respect. Would you like to leave the site as it is? What changes would you like to suggest?

Yes, I like the site as it is.
It's ok, but some changes are necessary.
It should be changed completely.
VotingView results
DISCLAIMER: Logging other people's keystrokes or breaking into other people's computer without their permission can be considered illegal by the courts of many countries. The monitoring software reviewed here is ONLY for authorized system administrators and/or owners of computers. We assume no liability and are not responsible for any misuse or damage caused by the keylogging software. The end user of this software is obliged to obey all applicable local, state, federal and other laws in his country of residence.

October 08, 2008

'Clickjackers' could hijack Webcams, microphones, Adobe warns

Adobe Systems Inc. warned users Tuesday that hackers could use recently-reported "clickjacking" attack tactics to secretly turn on a computer's microphone and Web camera.

Flash on all platforms is susceptible to clickjacking attacks, Adobe said in an advisory posted Tuesday. By duping users into visiting a malicious Web site, hackers could hijack seemingly-innocent clicks that, in reality, would be used to grant the site access to the computer's Webcam and microphone without the user's knowledge.

"This potential 'Clickjacking' browser issue affects Adobe Flash Player's microphone and camera access dialog," acknowledged David Lenoe, the company's security program manager, in a post to Adobe's security blog.

Although a patch is not ready -- Lenoe said one would be issued by the end of October -- Adobe's advisory listed steps users can take immediately to block Webcam and microphone hijacking. Adobe recommended that users access Flash's Settings Manager using a browser to select the "Always deny" option.

Adobe rated the vulnerability as "critical," its highest threat ranking.

According to Robert Hansen, one of the two security researchers who first raised the warning about clickjacking last month, Adobe will patch the bug in Flash 10, which already has been pegged for other fixes, including a flaw that's been used by attackers for over a month to poison clipboards with URLs to malicious sites.

Hansen noted that Macs are particularly vulnerable to the Flash clickjacking attack, since all recent Apple notebooks and desktop systems include built-in cameras and microphones.

At the same time that Adobe posted its advisory, it gave Hansen and his research partner, Jeremiah Grossman, the green light to reveal clickjacking details that they had kept confidential at Adobe's request.

Hansen posted a long entry to his blog that spelled out a dozen different clickjacking attack scenarios. Two weeks ago, when they provided only a general description of clickjacking, Hansen stressed that it was not a single exploit, but a new class of exploits.

He hammered that theme again on Tuesday. "There are multiple variants of clickjacking," Hansen said in his blog post. "Some of it requires cross-domain access, some doesn't. Some overlays entire pages over a page, some uses iframes to get you to click on one spot. Some requires JavaScript, some doesn't. Some variants use [cross-site request forgery] to pre-load data in forms, some don't."


Source: ComputerWorld




All news for November 20, 2008:
13:26International Challenges in PCI Security
13:22Security firm Finjan raises $22 million
13:21iTunes customers angry over copy protection moves at Apple
13:18Have lessons of last year's HMRC fiasco sunk in?
13:16Secerno and F5 hook up on network security
13:15Mozilla warns of Firefox China add-on
13:13Google opens up for mashup security
13:12Cotton Traders tightens credit card protections
12:58Gov't: Most biometric checks will bypass ID database
12:57Antivirus firms unfazed by free Microsoft product
12:55Teenager pleads guilty to botnet, 'swatting' charges
12:54How much does spam cost you? Google will calculate
12:54Feds urged to provide cybersecurity incentives
12:49Fortinet beefs up midrange FortiGate security appliance

All news for November 19, 2008:
13:51Cybersecurity is focus of new University of Texas start-up incubator
13:50Branch office security, traffic management get a lift
13:49Latest robots showcase security, teaching skills
13:46Will Microsoft's antivirus move draw antitrust fire?
13:45Unisys survey looks beyond cybersecurity
13:41UK citizens ready for biometrics
13:41Global firms ignoring web-based threats
13:40Imprivata improves access management
13:39BNP membership details leaked online
13:32Virus downs systems at three London hospitals
13:32Microsoft replaces OneCare with free product
13:28Hosting firm takedown bags 500,000 bots
13:27Court halts sale of spyware program



All news for November, 2008
All news for 2008 year
All news for 2007 year
All news for 2006 year
All news for 2005 year
All news for 2004 year


DONATION: Keylogger.org is an independent research project supported by a team of enthusiasts. If you find this project useful or would like to help foster its continued development please consider making a donation using PayPal`s online secure payment service.

A PayPal account is not required. All major credit cards are accepted (MasterCard/Eurocard, Visa/Delta/Electron, American Express, Switch/Maestro, Solo). Simply click the button below.

Any amount would be useful and appreciated!

Thanks in advance for your support!

Advertising
| home | testing and reviews | testing policy | press_releases | developers |

| articles | contest | chat | forum | sponsorship & services | contacts | links |
Copyright © 2003-2008, Keylogger.Org Team. All Rights Reserved.
Use of any information from this website is permitted only with hypertext link to www.keylogger.org.