Google Search

Showing posts with label catches. Show all posts
Showing posts with label catches. Show all posts

Saturday, September 1, 2012

Steve Jobs calls home to Apple and catches an iPad thief!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Geolocation and related technologies that keep track of you and your devices have loomed large and Big Brotherishly in recent Naked Security coverage.

We've written about TrapWire, a surveillance system that makes use of real-time facial profiling to search databases of red-flagged individuals.

We've reported on the social networking overexuberance of Michael Dell's daughter Alexa, leading to her being suspended from Twitter for being too open with details of the family's activities and whereabouts on social networks.

And - having advised Alexa Dell to turn geolocation off, on the grounds that regular and precise updates of your whereabouts are a form of personally identifiable information - Naked Security has looked more closely into the risks of geolocation, as exemplified by WeKnowYourHouse, a website which aims to show everyone where you live based on your tweets.

Is there a good side to geolocation and on-line tracking?

Seems there is.

About a month ago, a down-on-his-luck burglar allegedly pinched goods to the value of $60,000 from the Silicon Valley house of Laurene Powell Jobs, widow of the late turtleneck afficionado and Apple co-founder, Steve.

The accused tea-leaf, a certain Mr McFarlin, apparently couldn't resist using one of the iPads he'd nicked to access his own iTunes account.

McFarlin obviously failed to notice the late Mr Jobs's driving licence in the wallet he trousered along with all the other loot - which was a costly oversight.

Of all the call home signals received by Apple's infrastructure, you'd want to bet that a beyond-the-grave WHOOP! WHOOP! STOLEN IPAD ALERT! report from a Jobsian device (and in this context, I mean Jobsian quite literally, not merely in a general economico-spiritual sense) would enjoy the same sort of special attention as "Friend Request from Elvis" and "Voicemail from Alexander Graham Bell."

And so it turned out.

The iPad's call home provided both identity and location for the most likely suspect, who was arrested and is now stuck in jail.

(McFarlin couldn't make the $500,000 bail. Not even with the contents of Steve Jobs's wallet - he was down to his last $1, apparently.)

Follow @duckblog
-

Geolocation "booooooop" image courtesy of Shutterstock.


View the original article here

Saturday, June 25, 2011

Wordpress catches hackers red-handed - GMANews.TV

Open-source blog and publishing platform WordPress intercepted this week what could have been an attempt by hackers to break in to it by placing backdoors on three of its popular plug-ins.

In a blog post, WordPress said it has temporarily shut down access to the plug-in repository and forced users to reset their passwords as a security precaution.

"We?re still investigating what happened, but as a prophylactic measure we?ve decided to force-reset all passwords on WordPress.org. To use the forums, trac, or commit to a plugin or theme, you?ll need to reset your password to a new one. (Same for bbPress.org and BuddyPress.org.)," WordPress founder Matt Mullenweg said.

He said that the WordPress team noticed suspicious commits to popular plugins such as AddThis, WPtouch, and W3 Total Cache.

These plugins were found to contain "cleverly disguised backdoors," he said.

"We determined the commits were not from the authors, rolled them back, pushed updates to the plugins, and shut down access to the plugin repository while we looked for anything else unsavory," Mullenweg said.

He advised users to make sure to never use the same password for two different services, and encouraged them not to reset your passwords to be the same as their old ones.

"If you use AddThis, WPtouch, or W3 Total Cache and there?s a possibility you could have updated in the past day, make sure to visit your updates page and upgrade each to the latest version," he added.

Computer security firm Sophos said Web-based backdoors can be extremely dangerous.

"If you're a WordPress user, you'll know that the WordPress platform includes a complete and powerful administration interface, password-protected, via a URL such as 'site.example/wp-admin.' A WordPress backdoor might offer something with similar functionality, but using a different, unexpected, URL, and using a password known to the hacker, instead of to you," Sophos Asia Pacific head of technology in Asia PAcific Paul Ducklin said. ? TJD, GMA News


View the original article here