Google Search

Showing posts with label review. Show all posts
Showing posts with label review. Show all posts

Friday, December 28, 2012

Monday review - the hot 22 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Android, Apple, Data loss, Denial of Service, Facebook, Google, Law & order, Malware, Microsoft, OS X, Privacy, Social networks, Technologies, Twitter, Windows

Tags: Acai Berry, Adobe, Albania Pirate Group, Android, award, BlackHole, DDoS, Facebook, Facebook Black, ftc, hack, IE 9, ios, linkedin. freebsh, monday review, NASA, OS X, papa johns, Patch Tuesday, Petraeus, review, skype, SMS, SQL Injection, ssh, Tibet, TNS24, Trojan, VB100, Windows Phone 8


View the original article here

Friday, December 14, 2012

Monday review: the hot 20 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Android, Data loss, Facebook, Featured, Firefox, Google, Law & order, Malware, Privacy, Security threats, Spam, Vulnerability

Tags: Adobe, Barnes and Noble, BlackHole, boarding pass, Cybercrime, eftpos, Facebook, flashing, ftc, gmail, hack, hotmail, Huawei, identity theft, intellectual property, law, Law and Order, Malware, open redirect, Privacy, ps3, redirect, risky.biz, Scam, shockwave, Sony, Spam, TSA, yahoo


View the original article here

Saturday, December 1, 2012

Monday review: the hot 31 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Apple, Data loss, Denial of Service, Facebook, Featured, Google, iOS, Java, Law & order, Malware, Mobile, Oracle, OS X, Privacy, Security threats, Social networks, Spam, Twitter, Vulnerability

Tags: Android, Apple, DDoS, DHL, FBI, gmp, Google, HSBC, india, ios 6, Java, LulzSec, Manchester, McKinnon, Mobile, OS X, repair, Spam, testing, Tracking, Wordpress, YouTube


View the original article here

Saturday, November 24, 2012

Monday review: the hot 24 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tags: chrome, games, Huawei, IT, kiosk, Mitt Romney, piracy, scada, threat response, virus removal, warcraft, WoW, ZTE


View the original article here

Tuesday, November 13, 2012

Monday review: the hot 21 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Android, Facebook, Fake anti-virus, Internet Explorer, Law & order, Malware, Mobile, Phishing, Security threats, Social networks, Spam, Twitter, Vulnerability

Tags: Android, Apple discount cards, Bing, Blackhat, bsd, bugbear, China, defibrillators, Facebook, ftc, hacking, Insulin Pumps, Japan, keccak, Microsoft, nitol, scareware, SEO Poisoning, TinKode, Twitter, White House, wifi


View the original article here

Thursday, October 25, 2012

Monday review: the hot 26 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe Flash, Android, Apple, Data loss, Denial of Service, Featured, iOS, Java, Law & order, Malware, Privacy, Social networks, Vulnerability

Tags: Adobe, Android, Anti-virus, Anti-virus for Android, APSA 12-01, Bank of America, Banking, DDoS, denial of service, Do Not Track, Facebook, flash, ftc, hacking, IEEE, Java, Joe Lieberman, Kim Dotcom, Malware, Microsoft Windows Update, NFC, PHP, phpMyAdmin, ransomware, Security Explorations, Sophos Mobile Security, Sophos Support, sourceforge, Telvent, Twitter, Virus Bulletin


View the original article here

Saturday, October 20, 2012

Monday review: the hot 18 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tags: Android, BlackHole, BMW, chrome, CVE-2012-4969, Do Not Track, Exploit, face, Facebook, facial recognition, false positive, Fix it, Home Depot, Internet Explorer, Justin Lee, Lock Poker, Malware, Microsoft, Poison Ivy, Poker, RSA, Sophos, Subway, vulnerability, Zero Day, ZeroAccess


View the original article here

Sunday, October 14, 2012

Book review: Practical Malware Analysis

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Earlier this year, no starch press, sent SophosLabs an unrequested copy of the book Practical Malware Analysis: The hands-On Guide to Dissecting Malicious Software with a letter saying "If you do enjoy the book, I hope that you will consider posting a review ...". Well I enjoyed the book and so here is the review :)

Both authors, Michael Sikorsji and Andrew Honig, have impressive resumes (NSA, MIT and DoD) and list of reviewers looks impressive including: Sal Solfo (Columbia University) and Ilfak Guilfanov (IDA).

The book is well written and, like an academic textbook, each chapter ends with a series of questions and lab exercises. What is more, unlike text books, the teacher's answer copy is in the Appendix - it accounts for nearly *half* the book.

The book consists of 6 parts plus the Appendices:

Part 1: Basic AnalysisPart 2: Advanced Static AnalysisPart 3: Advanced Dynamic AnalysisPart 4: Malware FunctionalityPart 5: Anti-reverse-engineeringPart 6: Special TopicsAppendix A: Important Windows FunctionalityAppendix B: Tools for malware analysisAppendix C: Solutions to Labs

The book is a great primer on malware analysis, but there are more topics it could have covered (non-Windows and ARM analysis). Also, some of the topics that are covered could benefit from a bit more detail. As an example of this, Chapter 2: Malware Analysis in a Virtual Machine focuses on VMWare. It's certainly well written and edited, but it didn't touch VirtualBox or discuss how to use virtual machines to automate analysis. Which is a shame.

With the rise of eReaders and tablets, this could be one of the last books of this type. Monolithic book likes these means that you need to buy the next edition of the book to get any updates. Electronic books allow for small and incremental updates to the content at little or no cost to the user and to the publishers.

Once you have read Practical Malware Analysis, you will be able to top up your knowledge quite easily using the powers of the internet.

Would I buy this book if I saw it sitting in a shop window? Probably not. But go back 15 years when I was just starting out in the field, this would have been a goldmine of information.

So, if you're starting out in malware analysis (like our SophosLabs' intern Julian), or if you are are coming to analysis from another discipline, I'd recommend having a nose.

Follow @nakedsecurity
Follow @SophosLabs


View the original article here

Sunday, October 7, 2012

Monday review: the hot 22 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tags: Adobe, Android, anonymous, Apple, BlackHole, bot, Chip and PIN, digital certificate, flash, GoDaddy, IE, Internet Explorer, iPhone, iPhone 5, Malware, Microsoft, nitol, Patch Tuesday, Pinterest, ransomware, RFID, SMS, Spam, UDID, zombie


View the original article here

Wednesday, September 26, 2012

Monday review: the hot 20 stories of the week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

In case you missed any of these stories, here's everything we wrote in the last seven days:

Polls

Which web browser do you recommend? [POLL]

Do you have a special email address for websites that might send you spam? [POLL]

Apache Foundation creates firestorm over user privacy choices [POLL]

Malware and vulnerabilities

Free-press organisations targeted in malware attack

Google releases Chrome 21, shells out $3,500 for security holes

Attacks on Java security hole hidden in bogus Microsoft Services Agreement email

Cloud storage firm flags malware as "Copyrighted Material," boots security researcher

Microsoft RDP - Remote Desktop Protocol or Routine Darkside Probe?

Fingerprint scanner maker cries foul over Russian firm's security warning

Warbiking in London - insecure WiFi hotspots exposed [VIDEO]

Privacy

Honeypot reveals mass surveillance of BitTorrent downloaders

RoMOS - Russia rolls its own secure tablet because it doesn't trust Google Android

Is Opera *really* the safest browser?

Data loss

Romney tax returns allegedly hacked, supposedly held for $1 million ransom

Bitcoin exchange floored in virtual bank robbery - $250,000 stolen in security lapse

12 million iPhone and iPad device IDs hacked from the FBI, Anonymous claims

FBI hits back at Anonymous - your claims are TOTALLY FALSE

Spam

Watch this - the funniest spam video you'll ever see [VIDEO]

Law and order

Child abuse photo collector forgets to encrypt his USB stick - Bad security is a good thing

Podcast

SSCC 97 - Black Hat and DEF CON review, broken crypto, Frak, smart meters and hacking transit

Follow @NakedSecurity

Days of the week image from Shutterstock.

Tags: Android, anonymous, Apache, bitcoin, BitTorrent, chrome, cloud, DNT, Elcomsoft, FBI, Firefox, Java, monday, monday review, opera, Podcast, poll, RDP, romney, russia, Video, wifi


View the original article here

Tuesday, September 25, 2012

SSCC 97 - Black Hat and DEF CON review, broken crypto, Frak, smart meters and hacking transit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sophos Security Chet Chat logoThis Chet Chat is the last one from our summer hiatus and features Peter Szabo and I discussing a few more of our favorite talks from Black Hat and DEF CON 2012.

I started our discussion with Moxie Marlinspike and David Hulton's talk "Defeating PPTP VPNs and WPA2 Enterprise with MS-CHAPv2". They explained some of the mistakes Microsoft engineers made in their implementation of MS-CHAPv2 a common authentication protocol used for VPNs and WiFi access points.

Because of these flaws, the cryptographic strength is somewhere in the neighborhood of 56 bits. This allowed Marlinspike and Hulton to launch a service using general purpose FPGAs that can crack any key in 24 hours or less for approximately $200.

Peter went to a talk on reverse engineering firmware titled "Embedded Device Firmware Vulnerability Hunting Using FRAK, the Firmware Reverse Analysis Konsole". The tool is not yet available, but will be released allowing anyone to peer inside of firmware blobs for printers, routers, phones or any other flashable device.

I attended a very sensible talk about smart meter security called "Looking Into The Eye Of The Meter" in reference to the infrared "eye" that can be used to talk to this latest generation of meters.

SecureState have released a toolkit to assist others in performing vulnerability assessments of meter infrastructure.

Pete wrapped up by sharing the entertaining talk he attended on hacking public transit systems called "How to Hack All the Transport Networks of a Country". The presenter explored all the different ways that technical skills and social engineering can be combined to manipulate any large, complicated system.

(10 August 2012, duration 14:34 minutes, size 8.4 MBytes)

You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 97, subscribe on iTunes or our RSS feed. You can see all of the Sophos Podcasts by visiting our archive.

http://twitter.com/chetwisniewski

View the original article here

Thursday, September 20, 2012

Monday review: the hot 27 stories of last week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Monday review time - here's a little recap, in case you missed any of our stories last week:

Java flaw

Unpatched Java exploit spreads like wildfire

Java flaws already included in Blackhole exploit kit, Oracle was informed of vulnerabilities in April

Zero-day Java flaw exploited in targeted tax email malware attack

How to turn off Java on your browser - and why you should do it now

Oracle releases out of cycle fixes for Java

Sophos Techknow - All about Java [PODCAST]

Malware and vulnerabilities

FLAMING RETORT: Frankenstein Malware - the future of cyberwar, or just a catchy headline?

Oil giant Saudi Aramco back online after 30,000 workstations hit by malware

Android malware authors take a crack at the Japanese market

DDoS attack stymies vote in Miss Hong Kong beauty contest

Firefox 15 released: Seven critical vulnerabilities patched and stealthy updates too!

Reveton/FBI ransomware - exposed, explained and eliminated [VIDEO]

Phishing without a webpage - researcher reveals how a link *itself* can be malicious

Privacy and social networks

Facebook friend added a new photo of you? Beware spammed-out malware attack

Spammers flood Facebook's own Help Center

Dropbox two-factor authentication available to early adopters

Facebook given one week to stop breaching privacy laws

Facebook troll outed as policeman

Facebook glitch lets spear phishers impersonate users' friends and family

Law and order

Woman gets 2.5 years in prison for managing ATM-sucking gang of fraudsters

What is the TPP, and why should you care?

Suspected LulzSec member arrested by FBI for Sony Pictures hack

Times reporter arrested over NightJack blogger email hack

Android SMS malware firm fined £50,000 and ordered to refund victims

Data loss

Toyota says it was hacked by ex-IT contractor, sensitive information stolen

Cancer Care Group leaves unencrypted server backups in car, loses data on 55,000 patients and staff

Guild Wars 2 accounts shuttered due to gold-seller hacking and idiocy

Follow @NakedSecurity

Days of the week image from Shutterstock.

Tags: Android, dropbox, Facebook, FBI, Firefox 15, Frankenstein malware, Java, Java Exploit, Java flaw, LulzSec, reveton, TPP, troll


View the original article here

Monday, August 27, 2012

Monday review: the hot 23 stories of last week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tags: Adobe, amd, Apple, bitcoin, correcthorsebatterystaple, dropbox, Facebook, Facedeals, ftc, geolocation, hacking, Java, Kim Dotcom, megaupload, michael dell, Microsoft, Oracle, OS X, password policy, passwords, Patch Tuesday, Practical IT, Pwnium 2, Quora, Steve Jobs, Twitter, WeKnowYourHouse, Wikileaks, wikileaks.org


View the original article here

Wednesday, August 22, 2012

Monday review: the hot 21 stories of last week

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.


View the original article here