A Web search box some users are seeing on their Facebook interface wasn't inserted by Facebook and could be the result of malware or a rogue browser plug-in or application.
AllFacebook, a blog devoted to Facebook-related news, first reported that a second search box had begun to appear on Facebook interfaces, right next to the legitimate site search bar.
The mysterious Web search box appeared perfectly integrated into the Facebook page layout, as if it were a native Facebook feature. However, Facebook is now saying that it didn't put that second search box there and that it could be a sign of malware infection.
"We are not testing the placement of a separate web search field and have no plans to do so. We believe the second search field or 'Search the Web" box appeared on peoples' accounts as the result of unknown actions by a third party targeting the browser -- potentially a browser plugin or malware -- unrelated to Facebook," a Facebook official told technology news blog Search Engine Land.
As Facebook members, users who think they might be affected by this situation have access to a free, browser-based virus scanning tool from McAfee, according to the company.
As the most popular social network and one of the world's largest sites, Facebook is in a constant battle against malicious hackers and online scammers who want to take advantage of its massive user base to commit fraud and spread malware.
At this point, it's not clear whether the sinister search box is the result of an external malware exploit or the work of a rogue Facebook application.
Sunday, March 27, 2011
Google patches 6 serious Chrome bugs
Google on Thursday patched six vulnerabilities in Chrome, and silently updated users' copies of the browser.
The update to Chrome 10.0.648.204 also included two more entries to the browser's blacklist, a move related to last week's theft of nine digital certificates from a Comodo reseller.
All six bugs were rated "high," Google's second-most-serious ranking in its threat scoring system. Of the half-dozen bugs, two were "use after free" flaws -- a type of memory management bug that can be exploited to inject attack code -- while a second pair were pegged by Google as "stale pointer" vulnerabilities, another kind of memory allocation flaw.
As is Google's practice, the company locked down its bug-tracking database, blocking access to the technical details of the patched vulnerabilities. Google usually unlocks the bug entries several weeks, sometimes months later, to give users time to update before the information goes public.
Google paid out $8,500 in bounties to three different researchers for finding and reporting the six vulnerabilities. So far this year, Google has cut bounty checks totaling $58,145.
Frequent-contributor Sergey Glazunov took home $7,000 for reporting four of the bugs patched Thursday, bringing his 2011 bounty total to $20,634. Glazunov has become the most prolific of the independent researchers who specialize in rooting out Chrome flaws, reporting 14 of the 54 bugs attributed to outsiders.
Yesterday was the sixth time Google patched security vulnerabilities in its browser this year.
Google said the update also added support for the browser's password manager on Linux, and included performance and stability fixes. According to the Chrome change list, it also blacklisted more SSL (secure socket layer) certificates, the digital certificates that encrypt traffic between users and sites. Those new entries appeared to be for reissues of certificates originally blacklisted by Google on March 17.
The additions to the SSL blacklist are connected to last week's theft of several certificates from a Comodo reseller, an event that prompted Comodo to revoke the stolen certificates. Since then, Google, Mozilla and Microsoft have each issued updates
Comodo has cited circumstantial evidence that points to Iran, perhaps the Iranian government, being involved in the certificate theft.
Chrome 10 can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.
The update to Chrome 10.0.648.204 also included two more entries to the browser's blacklist, a move related to last week's theft of nine digital certificates from a Comodo reseller.
All six bugs were rated "high," Google's second-most-serious ranking in its threat scoring system. Of the half-dozen bugs, two were "use after free" flaws -- a type of memory management bug that can be exploited to inject attack code -- while a second pair were pegged by Google as "stale pointer" vulnerabilities, another kind of memory allocation flaw.
As is Google's practice, the company locked down its bug-tracking database, blocking access to the technical details of the patched vulnerabilities. Google usually unlocks the bug entries several weeks, sometimes months later, to give users time to update before the information goes public.
Google paid out $8,500 in bounties to three different researchers for finding and reporting the six vulnerabilities. So far this year, Google has cut bounty checks totaling $58,145.
Frequent-contributor Sergey Glazunov took home $7,000 for reporting four of the bugs patched Thursday, bringing his 2011 bounty total to $20,634. Glazunov has become the most prolific of the independent researchers who specialize in rooting out Chrome flaws, reporting 14 of the 54 bugs attributed to outsiders.
Yesterday was the sixth time Google patched security vulnerabilities in its browser this year.
Google said the update also added support for the browser's password manager on Linux, and included performance and stability fixes. According to the Chrome change list, it also blacklisted more SSL (secure socket layer) certificates, the digital certificates that encrypt traffic between users and sites. Those new entries appeared to be for reissues of certificates originally blacklisted by Google on March 17.
The additions to the SSL blacklist are connected to last week's theft of several certificates from a Comodo reseller, an event that prompted Comodo to revoke the stolen certificates. Since then, Google, Mozilla and Microsoft have each issued updates
Comodo has cited circumstantial evidence that points to Iran, perhaps the Iranian government, being involved in the certificate theft.
Chrome 10 can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.
Friday, March 25, 2011
Microsoft warns of hack attempt on Windows Live, Google, Yahoo, Skype, Mozilla
Microsoft has issued a warning that a root certificate authority named Comodo Group has issued nine fraudulent digital certificates. Although the certificates were quickly revoked, their initial release still poses a threat to browser users, including users of Internet Explorer. This is not a security flaw in Microsoft software, the company says, but it released a security update for Windows all the same.
The nine fake certificates affect the following Web sites, Microsoft says:
- login.live.com (Windows Live)
- mail.google.com
- www.google.com
- login.yahoo.com (3 certificates)
- login.skype.com
- addons.mozilla.org
- "Global Trustee"
An alternative way for Web browsers to validate the identity of a digital certificate is by using the Online Certificate Status Protocol (OCSP). OCSP allows interactive validation of a certificate by connecting to an OCSP responder, hosted by the Certificate Authority (CA) which signed the digital certificate. Every certificate should provide a pointer to the OCSP responder location through the Authority Information Access (AIA) extension in the certificate. In addition, OCSP stapling allows the Web server itself to provide an OCSP validation response to the client.
OCSP validation is enabled by default on Internet Explorer 7 and later versions of Internet Explorer on supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. On these operating systems, if the OCSP validation check fails, the browser will validate the certificate by contacting the CRL Location. For more information on certificate revocation checking, see the TechNet article, Certificate Revocation and Status Checking.
So, if the browser will automatically check to see if the certificate is valid and, discover that it isn't, why issue a patch at all?
The OCSP system relies on being able to reach the CA's Certificate Revocation List (CRL). If the users can't get to that server, the browser assumes that the certificate issued by a trusted root authority is A-OK, uses it and by then the damage could be done.
Explains Microsoft:
Even when CRL and OCSP validation is enabled, validation techniques are not sufficiently robust to guarantee that users are protected against malicious use of these certificates. When the CRL location and OCSP responder can be reached, validation checks are highly reliable and effective.
However, when certificate revocation checks fail due to network and connectivity issues, browsers and other client applications, including Internet Explorer, may ignore these errors and consider the certificate trustworthy due to the lack of proof otherwise. In these scenarios, customers may still be affected.
Microsoft says it has not seen any attacks in the wild. Nevertheless, its Windows patch will be pushed out to users of its Windows Automatic Updates to ensure that the fraudulent certificates are not treated by IE as if they were valid. For enterprises that don't use Automatic Updates, the patch is available from the Microsoft Download Center.
The patch does not require a reboot. Here is more information on Security Advisory 2524375.
Thursday, March 24, 2011
Download Final Version of Firefox 4
You can download firefox 4 – final version from here.
Below are download links for firefox 4.
- Windows – Firefox 4.0 Final (12MB)
- Mac – Firefox 4.0 Final (27MB)
- Linux – Firefox 4.0 Final (15MB)
Below are download links for International Releases
Links below points to FTP directory. Just select your language code and you will link to exe/dmg/bz2 file in your language depending on your platform selection.
Worst is over: chip makers start recovery
According to IDG News Service Japanese chip makers have resumed their operations, first time after earthquake and tsunami hit Japan. While some Factories have started recovering others are coping with damage and power shortage.
Shin-Etsu Chemical, the world's second-largest supplier of 300-millimeter (12-inch) silicon wafers, vital to chip production, said that two of its four factories shut down after the earthquake are back and running. Company is assessing damage to other two factories. It further added that it will be transferring production equipment from one of its plant to elsewhere in Japan.
Silicon wafers are the raw material on which chips are etched. Japan supplies 72% of the world's 300mm silicon wafers, according to investment bank.
Japanese DRAM maker Elpida Memory has said a chip testing and assembly plant located in northeastern Japan is back and running after an initial closure caused by power outages related to the earthquake. The company said the facility was not damaged by the earthquake.
Both of these companies said that power outages remain an issue.
The 9.0-magnitude earthquake and resulting tsunami knocked several power plants offline in northeastern Japan, according to Tokyo Electric Power Co. The company continues to work to restore power to companies and residents, and started rotating power outages from Monday due to a shortage of capacity.
Chip makers that fabricate chips, the sensitive etching work that takes the most time in chip production, would not be able to resume operations until the earthquake activity settles down in northeastern Japan, according to IHS iSuppli.
"Earthquakes ranging from 4 to 7 on the Richter scale will make it impossible to fully restart these labs until the aftershocks stop happening with such frequency," IHS iSuppi said. "Every time a quake tops 5, the equipment automatically shuts down."
Northeastern Japan continues to be rocked by earthquakes, the latest a fairly strong 5.4-magnitude temblor Friday evening, according to the Japan Meteorological Agency.
Japan continues to recover after the biggest earthquake in its history. On Friday, the National Police Agency of Japan published dead and missing figures almost double the numbers from Wednesday. The number of people confirmed dead now stands at 6,539 with 10,354 missing. The tsunami spawned by the temblor swept away entire towns, leaving hundreds of thousands homeless, while an emergency at the Fukushima Daiichi Nuclear Power Station caused by the tsunami continues to plague officials in Japan.
Shin-Etsu Chemical, the world's second-largest supplier of 300-millimeter (12-inch) silicon wafers, vital to chip production, said that two of its four factories shut down after the earthquake are back and running. Company is assessing damage to other two factories. It further added that it will be transferring production equipment from one of its plant to elsewhere in Japan.
Silicon wafers are the raw material on which chips are etched. Japan supplies 72% of the world's 300mm silicon wafers, according to investment bank.
Japanese DRAM maker Elpida Memory has said a chip testing and assembly plant located in northeastern Japan is back and running after an initial closure caused by power outages related to the earthquake. The company said the facility was not damaged by the earthquake.
Both of these companies said that power outages remain an issue.
The 9.0-magnitude earthquake and resulting tsunami knocked several power plants offline in northeastern Japan, according to Tokyo Electric Power Co. The company continues to work to restore power to companies and residents, and started rotating power outages from Monday due to a shortage of capacity.
Chip makers that fabricate chips, the sensitive etching work that takes the most time in chip production, would not be able to resume operations until the earthquake activity settles down in northeastern Japan, according to IHS iSuppli.
"Earthquakes ranging from 4 to 7 on the Richter scale will make it impossible to fully restart these labs until the aftershocks stop happening with such frequency," IHS iSuppi said. "Every time a quake tops 5, the equipment automatically shuts down."
Northeastern Japan continues to be rocked by earthquakes, the latest a fairly strong 5.4-magnitude temblor Friday evening, according to the Japan Meteorological Agency.
Japan continues to recover after the biggest earthquake in its history. On Friday, the National Police Agency of Japan published dead and missing figures almost double the numbers from Wednesday. The number of people confirmed dead now stands at 6,539 with 10,354 missing. The tsunami spawned by the temblor swept away entire towns, leaving hundreds of thousands homeless, while an emergency at the Fukushima Daiichi Nuclear Power Station caused by the tsunami continues to plague officials in Japan.
Indian Prime Minister lying said Wikileaks founder
According to Wikileaks founder Julian Assange Indian Prime Minister Manmohan Singh is deliberately misleading the public by suggesting that the veracity of cables between U.S government and Indian embassy cannot be established.
Since November Wikileaks has been publishing leaked cables in partnership with certain newspaper. Indian newspaper “The Hindu” started publishing cables related to it on March 15. Due to these publication of leaked cables, an uproar was sparked in India’s Parliament because some of these cables suggested that India’s ruling Congress party has given bribe to members of Parliament to survive avote of confidence. During that time left party has withdrawn their support from coalition government as they were oppose to a civilian nuclear deal between India and U.S.
Manmohan Singh denied these allegations against his party in Parliament due to which Julian Assange reacted by saying on NDTV that the cables are authentic, there is no doubt about that.
Since November Wikileaks has been publishing leaked cables in partnership with certain newspaper. Indian newspaper “The Hindu” started publishing cables related to it on March 15. Due to these publication of leaked cables, an uproar was sparked in India’s Parliament because some of these cables suggested that India’s ruling Congress party has given bribe to members of Parliament to survive avote of confidence. During that time left party has withdrawn their support from coalition government as they were oppose to a civilian nuclear deal between India and U.S.
Manmohan Singh denied these allegations against his party in Parliament due to which Julian Assange reacted by saying on NDTV that the cables are authentic, there is no doubt about that.
Subscribe to:
Posts (Atom)