<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-25726447</id><updated>2011-04-21T13:43:54.848-07:00</updated><title type='text'>Security By Default</title><subtitle type='html'>” out of the box configuration syndrome “</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securitybydefault.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-25726447.post-115378337030589937</id><published>2006-07-24T16:20:00.000-07:00</published><updated>2006-07-24T16:22:50.313-07:00</updated><title type='text'>PayPal XSS Exploit available for two years?</title><content type='html'>The &lt;a href="http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html"&gt;cross-site scripting (XSS) vulnerability&lt;/a&gt;, which was harnessed by fraudsters to execute a convincing phishing attack against PayPal users, may have been exploitable for two years previously.&lt;br /&gt;&lt;p&gt;  Despite the prompt action taken by PayPal to address the security flaw after it was &lt;a href="http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html"&gt;reported by Netcraft&lt;/a&gt; last month, it became apparent that the very same flaw had been discovered and documented  &lt;a href="http://web.archive.org/web/20040603154914/http://www.penguin-skills.com/index.php?action=view&amp;id=1"&gt;two years earlier&lt;/a&gt;.  The page - cached by the &lt;a href="http://archive.org/"&gt;Wayback Machine&lt;/a&gt; - describes a cross site scripting attack that affected donation pages for suspended users, and is the exact method exploited by the phishing attack in June 2006. &lt;/p&gt;  &lt;p&gt; Chris Marlow tried to warn PayPal about the flaw in June 2004, but claims the PayPal representative he spoke to did not understand what cross-site scripting was, and - due to company policy - was unable to provide an email address to allow a proof-of-concept exploit to be demonstrated. Frustrated at being unable to convey the seriousness of the issue, Mr Marlow then posted details about the exploit to his web site but did not receive any response from PayPal. &lt;/p&gt;  &lt;p&gt;  PayPal &lt;a href="http://news.com.com/PayPal+fixes+phishing+hole/2100-7349_3-6084974.html"&gt;fixed the flaw&lt;/a&gt; after &lt;a href="http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html"&gt;reports of the phishing attack&lt;/a&gt; were published by Netcraft. A PayPal company spokesman initially said that they did not know how many people had fallen victim to the scam, although as the fraud was committed using PayPal's own web site, analysis of log files, if available, would have allowed PayPal to identify users at risk and take appropriate action. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-115378337030589937?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115378337030589937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115378337030589937'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/07/paypal-xss-exploit-available-for-two.html' title='PayPal XSS Exploit available for two years?'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-115318593954223438</id><published>2006-07-17T18:22:00.000-07:00</published><updated>2006-07-17T18:25:39.543-07:00</updated><title type='text'>Citibank Fraudsters Defeat Two-Factor Authentication</title><content type='html'>&lt;p&gt; An ongoing phishing attack against &lt;a href="http://www.citibank.com/"&gt;Citibank&lt;/a&gt; is using man-in-the-middle tactics to defeat two-factor authentication and gain access to online banking accounts. &lt;/p&gt;  &lt;p&gt;The second authentication factor used by Citibank is provided by a security token – a physical item possessed by an account holder – which generates a one-time password that remains valid for approximately one minute. One-time passwords are useless to an attacker if they are captured via keylogging trojans, as they will not work immediately after the victim has used them, nor will the attacker be able to gain access to the victim's account at a later date. &lt;/p&gt;  &lt;p&gt;However, by tricking a victim into entering these items of data into a form, the attacker's site can automatically relay the authentication credentials to the real Citibank site instantly. Effectively, this allows the attacker to successfully log in on behalf of the victim.&lt;br /&gt;&lt;/p&gt;&lt;p&gt; Guidance issued by the Federal Financial Institutions Examination Council (&lt;a href="http://www.ffiec.gov/"&gt;FFIEC&lt;/a&gt;) has called for banks to provide additional protection for high-risk transactions, such as those that involve moving funds or accessing sensitive customer information, but it is now clear that fraudsters are already making efforts to bypass the protection features being added by banks.&lt;/p&gt;&lt;p&gt; The &lt;a href="http://toolbar.netcraft.com/"&gt;Netcraft Toolbar&lt;/a&gt; community has to date reported 35 sites that have used this method to attack Citibank customers. All of the reported sites have used Russian country-code top level domains (.ru), although the hosting location varies from site to site.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-115318593954223438?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115318593954223438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115318593954223438'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/07/citibank-fraudsters-defeat-two-factor.html' title='Citibank Fraudsters Defeat Two-Factor Authentication'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-115255414639449504</id><published>2006-07-10T10:52:00.000-07:00</published><updated>2006-07-10T10:55:46.403-07:00</updated><title type='text'>Security Threat in CMS Application (Mambo, Joomla)</title><content type='html'>&lt;p&gt;Potentially serious security flaws have been found in existing versions of the &lt;a href="http://www.mamboserver.com/"&gt;Mambo&lt;/a&gt; and &lt;a href="http://www.joomla.org/"&gt;Joomla&lt;/a&gt; content management systems, and developers of the two projects are advising users to install upgrades or security patches as soon as possible. Both programs are vulnerable to SQL injection attacks, which allow remote attackers to execute commands on the web server in by typing SQL code into form fields. Joomla is a &lt;a href="http://www.mamboserver.com/index.php?option=com_content&amp;task=view&amp;amp;id=186&amp;amp;Itemid=137"&gt;fork of Mambo&lt;/a&gt;, with both programs  derived from the same code base.&lt;/p&gt; &lt;p&gt;Mambo and Joomla are open source projects which use the PHP scripting language and MySQL database. These applications are popular with web site owners because they are powerful, user-friendly, and can be installed by users with little or no PHP coding experience. They are also frequently &lt;a href="http://news.netcraft.com/archives/2006/01/31/php_apps_a_growing_target_for_hackers.html"&gt;targeted by Internet criminals&lt;/a&gt; seeking to crack web servers for use in botnets, phishing scams and distributed denial of service (DDoS) attacks. The Internet Storm Center said it is receiving reports that older versions of Mambo are being &lt;a href="http://isc.sans.org/diary.php?storyid=1446"&gt;actively targeted and exploited&lt;/a&gt; using unpatched vulnerabilities.&lt;/p&gt;&lt;p&gt;Ideally, user input in web forms is sanitized - checked to ensure that users are not attempting to introduce code to give instructions to the web server. Content management systems typically bring together blogs, forums, news feeds and link directories in a single application, making it easy for webmasters to manage large communities of users. As a result, CMS apps include a large number of forms accepting user input, increasing the likelihood that some form fields may not be properly secured, providing an opportunity for SQL injection attacks.&lt;/p&gt;     Open source CMS programs often find and fix security holes promptly. But as is the case with most web software, a significant number of users fail to install security patches in a timely fashion. This provides an opportunity for hackers, who typically use public advisories to identify security flaws in specific programs and files, and then query search engines to locate vulnerable versions of the software.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-115255414639449504?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115255414639449504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115255414639449504'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/07/security-threat-in-cms-application.html' title='Security Threat in CMS Application (Mambo, Joomla)'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-115019239214011063</id><published>2006-06-13T02:52:00.000-07:00</published><updated>2006-06-13T02:53:12.150-07:00</updated><title type='text'>Your Internet Privacy Is At Risk</title><content type='html'>&lt;span style="font-size:-1;"&gt; Minimizing the risks related to the Internet security is of primary concern for any online business site. Internet security is very important and must be guarded severely at all costs. Minimizing the risks related to online security will ensure that you will be able to attract many customers to your online sites. Many security measures can be installed in an online site for lessening the risk of Internet security.&lt;br /&gt;&lt;br /&gt;If the customers are not sure about the security of their personal details and financial statements, they will never conduct online business. Internet privacy security is very important for any online business site.&lt;br /&gt;&lt;br /&gt;Internet privacy is at risk due to the presence of different elements. The presence of spyware is one factor of risk for Internet privacy security. The spyware that is present in your computer can track your online behavior. Spyware software is enabled with the advanced features that allow the spyware manufacturers to surreptitiously track the actions of a computer user. The information gathered through this process can be used to commit frauds and other illegal activities.&lt;br /&gt;&lt;br /&gt;The cookies that are deposited in your computer when you visit different sites can also pose a risk to your Internet privacy security. Cookies are data that is sent from a website to be stored in your computer. The cookies of the different websites can be used to track the user’s activities for a particular span of time. If the information falls into wrong hands many illegal activities can take place as a result. With the advancement in technology, it is very natural to be worried about online privacy and security.&lt;br /&gt;&lt;br /&gt;A person with a criminal intention is always on the look out for ways and means to invade Internet privacy security of the people. If he can get information about a person’s bank details and other personal details, he can misuse them. The person can assume your identity online and deal with your bank or other agencies in your capacity. The victim may be completely unaware about the fraud that is taking place in his name. This can lead to the huge losses to the person whose privacy has been invaded.&lt;br /&gt;&lt;br /&gt;You will have to adopt various means to safe guard your Internet privacy security. Installing a spyware in your computer can be one option for you to safe guard your privacy. The software will efficiently remove all traces of the presence of any kind of spyware from your computer. If it is difficult to remove all spyware installed in your computer, seek online advice on the manual removal of such spyware.&lt;br /&gt;&lt;br /&gt;Imagine yourself in a situation where someone else is able to monitor every move that you make. This is a terrifying situation to face. The best way for you to escape such a situation is to install the best security features in your computer. You will then be able to surf online peacefully without constantly worrying about your Internet privacy security.&lt;br /&gt;&lt;br /&gt; About the author:&lt;br /&gt;    Matt Garrett, &lt;a href="http://www.internet-privacy-systems.com/" target="_blank" class="navigation"&gt;http://www.internet-privacy-systems.com&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-115019239214011063?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115019239214011063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/115019239214011063'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/06/your-internet-privacy-is-at-risk.html' title='Your Internet Privacy Is At Risk'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114632099903336521</id><published>2006-04-29T07:16:00.000-07:00</published><updated>2006-04-29T09:00:04.593-07:00</updated><title type='text'>Microsoft Blackmail All Windows User</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Due to recent move by Microsoft to implement Nag watermark to all unlicense Windows usage, we can see that Microsoft has started to blackmail all windows user to either buy the license version or received humiliation by embossed nag to the Operating System.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;After all these year, i have told others long time ago that Microsoft will do this sooner or later. All the monopolised that Microsoft has won all these year, the court order that they have won, we will see that the Giant (Bill Gates) is a same as any Mafia Godfather. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;Well for me, as I don't condone any pirate (unlicensed) software usage, I don't even like the way Microsoft do. After all this while, we're all know that Microsoft has put a tools or spyware in the Operating System. That's why they don't want US Government or anybody else review their Operating System source code. They said that it's under copyright reserved.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;So, these so called "smart move" by the Microsoft should trigger the Anti-Microsoft movement using Linux or Open Source as a guidelines. If we (user) don't take action regarding this "smart move", sooner or later we will all be blackmailed by Microsoft using other method. So don't update your "unlicense" Microsoft Windows Operating System at all. Be safe than sorry.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Hail to the Open Source communities..&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114632099903336521?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114632099903336521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114632099903336521'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/microsoft-blackmail-all-windows-user.html' title='Microsoft Blackmail All Windows User'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114473228132904375</id><published>2006-04-10T21:57:00.000-07:00</published><updated>2006-04-10T22:11:21.340-07:00</updated><title type='text'>Asian Government Server Prone To Hacking</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Right now, many Asian country has been developing their e-government system using Linux and Windows server. Their system mainly under PHP, ASP and .NET. Many of these server located in govermental datacenter located in the heart of their organization.&lt;br /&gt;&lt;br /&gt;Singapore, Malaysia, Thailand and Phillipines has being doing this quite aggresively. But on top of that, many system developed by them is either not secure enough or not even have any security. You can test some of them by using Retina, Nmap (Stealth function) and other security assessement tools.&lt;br /&gt;&lt;br /&gt;You can also found out that many e-government server have neither upgraded their Operating System patches nor do they upgraded their firewall firmware and tools. Some installation only use one type of firewall like Watchguard or Sonicwall, but without any IDS or any monitoring system.&lt;br /&gt;&lt;br /&gt;You can DDOS or spam these server without much hassle. Last few years, Malaysian Parliament webserver has been defaced without much problem. Only after 8 hours later they found that what happen to their server. Some server has being set-up with out of the box configuration (by default).&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114473228132904375?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114473228132904375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114473228132904375'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/asian-government-server-prone-to.html' title='Asian Government Server Prone To Hacking'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114468405778562530</id><published>2006-04-10T08:28:00.000-07:00</published><updated>2006-04-11T18:40:41.896-07:00</updated><title type='text'>Phone Eavesdropping</title><content type='html'>&lt;span style="font-family:verdana;"&gt;After 9/11 incident, many country has been set-up an Terrorist Emergency Response Team. Developed country like Indonesia, Singapore, Malaysia, Philipines, India, Thailand and Arabs Country has been setting it up fast.&lt;br /&gt;&lt;br /&gt;Some even block any usage of prepaid cellular phone account while other has been using a registration system to register all the cellular phone which handle by that country. Many telco's has been investing more money prior to this matter.&lt;br /&gt;&lt;br /&gt;But, some others country has bee started to scanned and eavesdropping any communication beyond these cellular network. Singapore has been eavesdropping the communication far more early with the help from American and Israel.&lt;br /&gt;&lt;br /&gt;As a consumer, our privacy is being compromised every day and night. It's a human right. No one's should argue with this matter. Maybe in a couple of year you can see (Encrypted Mobile Cellular) type of model in the market soon enough. With this we can secure our conversation without BigBoys monitored all our inbound/outbound calls.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114468405778562530?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114468405778562530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114468405778562530'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/phone-eavesdropping.html' title='Phone Eavesdropping'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114460922148317879</id><published>2006-04-09T11:49:00.000-07:00</published><updated>2006-04-09T17:29:27.290-07:00</updated><title type='text'>GPS Tracking</title><content type='html'>&lt;span style="font-family:verdana;"&gt;Nowadays many motorist used GPS to locate and track their destination. The usage of Mobile Civilian GPS equipment have taken a leap in this millenium. With as low as USD$100 per unit, the GPS is becoming a household needs.&lt;br /&gt;&lt;br /&gt;We can see the benefits of GPS usage, but do we see it on security level. Anyone with a GPS signal tracking devices can track any GPS equipment who send a small signal upward to the satellite to triangulate their coordinates. Meaning that, with a little tweaking in GPS technology and some knowledge in electronic, anyone can track others GPS enable car.&lt;br /&gt;&lt;br /&gt;It will make us feel unsafe because anyone can track where are we going. There is no privacy if this tracking is allowed. The Russian has been developed a small equipment to jammed any GPS signal within two or three miles. But it's for military purposes. Do we civillian have the access to this equipment with lower radius and low cost?&lt;br /&gt;&lt;br /&gt;Hope to get some before FEDs tracking me down.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114460922148317879?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460922148317879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460922148317879'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/gps-tracking.html' title='GPS Tracking'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114460440438220767</id><published>2006-04-09T10:28:00.000-07:00</published><updated>2006-04-09T10:46:14.666-07:00</updated><title type='text'>Vista Unsecured</title><content type='html'>&lt;span style="font-family:verdana;"&gt;Do you think that Microsoft Windows Vista will inherits some or many Windows XP and 2000 flaws and bugs? Well, I have already survey people who use Windows Operating System on this matter. Around 75% surveyed people says that they think the same problems that happen in WinXP and 2000 will be seen in Vista.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If Microsoft still have a long way to produce clean code for Longhorn, so you'll see the same problem arise in Vista. Well more hype for the unpublished product. Many have seen Vista in beta version. Vista is good for Multimedia and Internet functionality, but maybe lack in security.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Virus will always trying to attack the flaws in Microsoft product. Spyware, Malware, Trojan and other will also taken their turn to test Vista in real operational function. Will Microsoft strengthen their inhouse antivirus and implemented a full heuristic function in Vista.&lt;br /&gt;&lt;br /&gt;Nobody know what Vista will capable of. Will either Vista be totally secured from any viral infection or prone to many of the generics viruses. We will know it in the matter of time. So let look to the future.&lt;br /&gt;&lt;br /&gt;And hope that Vista will finally landed to our personal computer at last.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114460440438220767?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460440438220767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460440438220767'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/vista-unsecured.html' title='Vista Unsecured'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-25726447.post-114460200285141185</id><published>2006-04-09T09:59:00.000-07:00</published><updated>2006-04-09T10:46:31.433-07:00</updated><title type='text'>WiFi Unsecured</title><content type='html'>&lt;div class="entry"&gt;      &lt;p style="font-family: verdana;"&gt;Nowadays, there are many WiFi installation you can see around you. No matter you are in big or small town, you can see and found-out that these small hotspot scattered near you.&lt;/p&gt; &lt;p style="font-family: verdana;"&gt;Yes, this WiFi technology is good because there is no need to lay out cables around to implement a small network. WiFi technology can minimised your time to set-up small network. But, there is a thing or two that should limit the access to WiFi.&lt;/p&gt; &lt;p style="font-family: verdana;"&gt;The first is how to secure your small network? Do you need to implement firewall to separate your server and your peers. Do you need to implement WEP or WPA? Is WEP or WPA is secure enough to handle all your network security.&lt;/p&gt; &lt;p style="font-family: verdana;"&gt;I’ve found out many “Out Of Box” configuration that WiFi Hotspot implementor used to set it up. I’ve tested more that 300 WiFi spot and found out 95% of them is not secure at all. You can use many tools like “NetworkView” and “Retina” to search and found all the configuration within these small WiFi spot.&lt;/p&gt; &lt;p&gt;&lt;span style="font-family:verdana;"&gt;I hope that anyone who want to set-up small network using WiFi equipment should consider to secure all their network first before set-up the network. Use a hardened WEP and WPA equipment or consider to connect the network based on MAC address only.&lt;/span&gt; &lt;/p&gt;     &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25726447-114460200285141185?l=securitybydefault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460200285141185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25726447/posts/default/114460200285141185'/><link rel='alternate' type='text/html' href='http://securitybydefault.blogspot.com/2006/04/wifi-unsecured.html' title='WiFi Unsecured'/><author><name>thecreakers</name><uri>http://www.blogger.com/profile/05461529832269983153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
