Facebook Hack #641,287: The “Dislike” Button

Facebook users by and large have the inherent gullibility of a 2-year old. They'll fall for anything, which makes them the proverbial low-hanging fruit of the internet. The latest shiny thing they can be tricked into clicking on is the "Dislike Button", which of course is just another way to trick them into displaying their […]

How to Hack Millions of Routers

More Good News: most home routers, like the one you're using right now, are "easily hackable".  A researcher named Craig Heffner from the security consultancy company Seismic says about half the existing models of home routers are vulnerable to hackers. This includes most Linksys, Dell, and Verizon FiOS or DSL routers, plus others. The technique […]

Spammers Move To “Disposable Domains”

Spammers, like all primitive forms of life, continue to evolve in ways calculated to enhance their viability or survival potential. The most recently observed wrinkle they've come up with is using short-lived or "disposable" domain names.  These are domains that they use for only a few hours before switching to the next one.

Basic Security Guidelines for Programming In Any Language

If you have a website, it's being attacked, probably on a daily basis. Looking at your server logs will almost undoubtedly show you many, many attempts at gaining entry by password-guessing bots or by repeated attempts to exploit your web forms. Expect that every form you use will be attacked mindlessly over and over by […]

Security Through Ubiquity? For Botnets, It Works

You may be familiar with "security through obscurity", a principle in security engineering which attempts to use secrecy of design, implementation, or other factors to provide security. Security through obscurity is a poor design concept in general and is widely derided among professionals. But what about security through ubiquity, "ubiquity" in this case meaning multiple […]

The New “Simplified” Facebook Privacy Settings

Facebook has taken a lot of heat over their deceptive and abusive privacy policy, and also over the fact that the privacy settings on Facebook are a nightmare to manage- more than 50 different settings with over 170 options spread across seven pages. Many of the settings are poorly labeled or unclear in the scope […]

A Fun New Exploit Called “Tab-napping”

Named with a nod to the word "kidnapping", Brian Krebs details a nifty new exploit that's bound to make it's way to your browser sooner or later. This new phishing exploit relies on user inattention and your trust in browser tabs, and  is likely to fool even the most security-savvy web surfers. Mozilla Firefox creative […]

The Newest Hacking Threat: Rogue Subdomains

It seems that in their never-ending quest to find new ways to avoid detection, hackers have have ramped up the use of an exploit technique that has, up to now, not been widely used. The technique involves modifying a (compromised) site's DNS settings to use add "hidden" subdomains that serve up malware, either directly or […]

Facebook, MySpace Lie To You Again

From the "I'm-Shocked!-Shocked-I-Tell-You" department: Facebook, MySpace, LiveJournal, Hi5, Xanga, Digg and other social-networking sites deliberately broke their own stated privacy policies and sent data to advertising companies that could be used to find and identify users' names and other personal details. Facebook calls it a "privacy loophole". I call it dirty dealing, lying, and outright […]

Every Oracle Error Known To Man

PSOUG.org has just launched their Oracle Error Reference tool, listing every Oracle "ORA error" in the known universe. Well, probably not every one, since Oracle seems to keep minting new ones almost daily, but this is a pretty comprehensive list of over 18,000 Oracle error codes, their meanings, causes, and remedies. The searchable list also […]

