ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Bigger than Heartbleed, 'Venom' security vulnerability threatens most datacenters | CyberSecurity

Bigger than Heartbleed, 'Venom' security vulnerability threatens most datacenters | CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it

"Heartbleed lets an adversary look through the window of a house and gather information based on what they see," said Geffner, using an analogy. "Venom allows a person to break in to a house, but also every other house in the neighborhood as well."

Geffner said that the company worked with software makers to help patch the bug before it was publicly disclosed Wednesday. As many companies offer their own hardware and software, patches can be applied to thousands of affected customers without any downtime.

Now, he said, the big concern is companies that run systems that can't be automatically patched.

To take advantage of the flaw, a hacker would have to gain access to a virtual machine with high or "root" privileges of the system. Geffner warned that it would take little effort to rent a virtual machine from a cloud computing service to exploit the hypervisor from there.

"What an adversary does from that position is dependent on the network layout," said Geffner, indicating that a datacenter takeover was possible.

Gust MEES's insight:

Heartbleed lets an adversary look through the window of a house and gather information based on what they see," said Geffner, using an analogy. "Venom allows a person to break in to a house, but also every other house in the neighborhood as well."

Geffner said that the company worked with software makers to help patch the bug before it was publicly disclosed Wednesday. As many companies offer their own hardware and software, patches can be applied to thousands of affected customers without any downtime.

Now, he said, the big concern is companies that run systems that can't be automatically patched.

To take advantage of the flaw, a hacker would have to gain access to a virtual machine with high or "root" privileges of the system. Geffner warned that it would take little effort to rent a virtual machine from a cloud computing service to exploit the hypervisor from there.

"What an adversary does from that position is dependent on the network layout," said Geffner, indicating that a datacenter takeover was possible.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Internet security researchers use Heartbleed bug to target hackers

Internet security researchers use Heartbleed bug to target hackers | ICT Security-Sécurité PC et Internet | Scoop.it
Anti-malware researchers have turned the tables on cyber criminals by using the Heartbleed bug to gain access to online forums where hackers congregate.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=Heartbleed


Gust MEES's insight:

Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=Heartbleed


No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Heartbleed : la NSA ne dévoile pas toutes les failles trouvées

Heartbleed : la NSA ne dévoile pas toutes les failles trouvées | ICT Security-Sécurité PC et Internet | Scoop.it
Mets-en de côté, ça peut servir.


La NSA ne dévoile pas toujours les failles qu'elle découvre. Il aurait fallu être naïf pour croire le contraire, et de nombreux indices et révélations vont dans ce sens depuis des années. Cela dit, que la Maison blanche l'admette et se fende d'un billet de blog pour détailler les procédures menant à la divulgation ou à la rétention de failles, c'est nouveau.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=NSA




Gust MEES's insight:

La NSA ne dévoile pas toujours les failles qu'elle découvre. Il aurait fallu être naïf pour croire le contraire, et de nombreux indices et révélations vont dans ce sens depuis des années. Cela dit, que la Maison blanche l'admette et se fende d'un billet de blog pour détailler les procédures menant à la divulgation ou à la rétention de failles, c'est nouveau.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=NSA




Gust MEES's curator insight, April 30, 2014 1:08 PM

La NSA ne dévoile pas toujours les failles qu'elle découvre. Il aurait fallu être naïf pour croire le contraire, et de nombreux indices et révélations vont dans ce sens depuis des années. Cela dit, que la Maison blanche l'admette et se fende d'un billet de blog pour détailler les procédures menant à la divulgation ou à la rétention de failles, c'est nouveau.

.


Scooped by Gust MEES
Scoop.it!

Up to 50 million Android devices could be vulnerable to Heartbleed attack. Here's how to check yours

Up to 50 million Android devices could be vulnerable to Heartbleed attack. Here's how to check yours | ICT Security-Sécurité PC et Internet | Scoop.it
Millions of Android smartphones and tablets are at risk of being attacked via the Heartbleed bug, more than a week after the security vulnerability was first made public.


So, the obvious question you should be considering is, are you running Jellybean 4.1.1 on your Android devices?


Here’s how you can check:

  • Enter System settings
  • Scroll the screen down to About
  • Look for your Android version number


read more in the article...


Learn more:



Gust MEES's insight:

So, the obvious question you should be considering is, are you running Jellybean 4.1.1 on your Android devices?


Here’s how you can check:

  • Enter System settings
  • Scroll the screen down to About
  • Look for your Android version number


read more in the article...


No comment yet.
Scooped by Gust MEES
Scoop.it!

Heartbleed Bug Claims First Confirmed Victims in Canada

Heartbleed Bug Claims First Confirmed Victims in Canada | ICT Security-Sécurité PC et Internet | Scoop.it
Canadian authorities reveal that social insurance numbers for 900 taxpayers were stolen before Heartbleed Bug was fixed.


Learn more:



Gust MEES's insight:


Canadian authorities reveal that social insurance numbers for 900 taxpayers were stolen before Heartbleed Bug was fixed.


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

NSA Denies Exploiting 'Heartbleed' Vulnerability

The NSA denied a report claiming it was aware of and even exploited the "Heartbleed" online security flaw to gather critical intelligence.


Learn more:




Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

NSA Said to Have Used Heartbleed Bug, Exposing Consumers

NSA Said to Have Used Heartbleed Bug, Exposing Consumers | ICT Security-Sécurité PC et Internet | Scoop.it
The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said.


The NSA’s decision to keep the bug secret in pursuit of national security interests threatens to renew the rancorous debate over the role of the government’s top computer experts.


Learn more:



Gust MEES's insight:


The NSA’s decision to keep the bug secret in pursuit of national security interests threatens to renew the rancorous debate over the role of the government’s top computer experts.


Learn more:



No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

How to protect yourself in Heartbleed's aftershocks

How to protect yourself in Heartbleed's aftershocks | ICT Security-Sécurité PC et Internet | Scoop.it
The companies know what to do about Heartbleed now. Here's what you, as an individual, need to do now.

.

You should also clear out all your Web browsers' cache, cookies, and history. That's never a bad idea anyway. You don't want old memorized passwords walking into trouble at an untrustworthy site. To do this with the most popular browsers...


Learn more:





Gust MEES's insight:


Learn more:



Gust MEES's curator insight, April 11, 2014 10:16 AM


You should also clear out all your Web browsers' cache, cookies, and history. That's never a bad idea anyway. You don't want old memorized passwords walking into trouble at an untrustworthy site. To do this with the most popular browsers...


Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Has the NSA Been Using the Heartbleed Bug as an Internet Peephole?

Has the NSA Been Using the Heartbleed Bug as an Internet Peephole? | ICT Security-Sécurité PC et Internet | Scoop.it
The Heartbleed bug is unusually worrisome because it could possibly be used by the NSA or other spy agencies to steal your usernames and passwords — for sensitive services like banking, ecommerce, and web-based email — as well as the private keys that vulnerable web sites use to encrypt your traffic to them.


Either way, there are now signatures available to detect exploits against Heartbleed, as Dutch security firm Fox-IT points out on its website, and depending on how much logging companies do with their intrusion-detection systems, it may be possible to review activity retroactively to uncover any attacks going back over the last two years.


Learn more:



Gust MEES's insight:


Either way, there are now signatures available to detect exploits against Heartbleed, as Dutch security firm Fox-IT points out on its website, and depending on how much logging companies do with their intrusion-detection systems, it may be possible to review activity retroactively to uncover any attacks going back over the last two years.


So might hear in a couple of months more then, probably!



Learn more:



Gust MEES's curator insight, April 10, 2014 11:00 AM


Either way, there are now signatures available to detect exploits against Heartbleed, as Dutch security firm Fox-IT points out on its website, and depending on how much logging companies do with their intrusion-detection systems, it may be possible to review activity retroactively to uncover any attacks going back over the last two years.


So might hear in a couple of months more then, probably!


Scooped by Gust MEES
Scoop.it!

Heartbleed, OpenSSL et la question de la sécurité expliqués simplement

Heartbleed, OpenSSL et la question de la sécurité expliqués simplement | ICT Security-Sécurité PC et Internet | Scoop.it
Lundi soir, une faille importante était annoncée au sein d'OpenSSL. Comme nous l'avions évoqué hier, celle-ci pourrait avoir des conséquences assez graves, mais...




Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

OpenSSL-Sicherheitslücke: Warum "Heartbleed" Millionen Web-Nutzer gefährdet

OpenSSL-Sicherheitslücke: Warum "Heartbleed" Millionen Web-Nutzer gefährdet | ICT Security-Sécurité PC et Internet | Scoop.it
IT-Experten schlagen Alarm: Eine schwere Sicherheitslücke macht viele eigentlich besonders gesicherte Webseiten anfällig für Angriffe. Login-Daten und sensible Informationen sind in Gefahr, Nutzer sollten vorsichtshalber ihre Passwörter ändern.


Learn more:



Gust MEES's insight:
No comment yet.
Scooped by Gust MEES
Scoop.it!

Anatomy of a data leakage bug - the OpenSSL "heartbleed" buffer overflow

Anatomy of a data leakage bug - the OpenSSL "heartbleed" buffer overflow | ICT Security-Sécurité PC et Internet | Scoop.it
An information disclosure vulnerability has been found, and promptly patched, in OpenSSL.

Paul Ducklin takes a look at what went wrong in the code...








Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

300.000 Server noch immer über Heartbleed angreifbar

300.000 Server noch immer über Heartbleed angreifbar | ICT Security-Sécurité PC et Internet | Scoop.it
Noch immer sind über 300.000 Server über die OpenSSL-Lücke Heartbleed angreifbar. Die Anzahl der ungeschützten Rechner verringert sich nur langsam.
Gust MEES's insight:

Noch immer sind über 300.000 Server über die OpenSSL-Lücke Heartbleed angreifbar. Die Anzahl der ungeschützten Rechner verringert sich nur langsam.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Près de 320 000 serveurs encore vulnérables à la faille Heartbleed

Près de 320 000 serveurs encore vulnérables à la faille Heartbleed | ICT Security-Sécurité PC et Internet | Scoop.it
Un chercheur indique que près de 320 000 serveurs sont encore vulnérables à la faille Heartbleed.


Pour trouver ce chiffre, il a scanné des millions de serveurs sur le port 443 qui est utilisé pour les communications TLS/SSL. A la découverte de la faille, plus de 600 000 serveurs étaient exposés. Robert Graham reste prudent sur ce chiffre de 320 000 en indiquant qu’il existe d’autres tests que le port 443 et qu’il peut donc y avoir plus de serveurs vulnérables.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=Heartbleed


Gust MEES's insight:

Pour trouver ce chiffre, il a scanné des millions de serveurs sur le port 443 qui est utilisé pour les communications TLS/SSL. A la découverte de la faille, plus de 600 000 serveurs étaient exposés. Robert Graham reste prudent sur ce chiffre de 320 000 en indiquant qu’il existe d’autres tests que le port 443 et qu’il peut donc y avoir plus de serveurs vulnérables.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=Heartbleed


No comment yet.
Scooped by Gust MEES
Scoop.it!

Heartbleed claims British mums and Canadian tax payers as victims

Heartbleed claims British mums and Canadian tax payers as victims | ICT Security-Sécurité PC et Internet | Scoop.it
The critical security vulnerability in OpenSSL known commonly as Heartbleed continues to raise alarms, with websites now warning that hackers have breached their systems by exploiting the bug, and stolen personal information about users.


Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

Heartbleed-Bug: Über 1.000 Android-Apps betroffen

Heartbleed-Bug: Über 1.000 Android-Apps betroffen | ICT Security-Sécurité PC et Internet | Scoop.it
Längst hat die Heartbleed-Lücke auch mobile Geräte erreicht: Sicherheitsexperten von Trend Micro zufolge, verbinden sich rund 1.300 Android-Apps mit angreifbaren Servern - darunter auch 15 Banking-Apps.





Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

Obama lets NSA use zero-day flaws given “clear national security” need

Obama lets NSA use zero-day flaws given “clear national security” need | ICT Security-Sécurité PC et Internet | Scoop.it
White House officials: policy dates back to January 2014, during review process.


President Barack Obama has explicitly decided that when any federal agency discovers a vulnerability in online security, the agency should come forward, rather than exploit it for intelligence purposes, according to The New York Times, citing unnamed “senior administration officials.”


Learn more:



Gust MEES's insight:


President Barack Obama has explicitly decided that when any federal agency discovers a vulnerability in online security, the agency should come forward, rather than exploit it for intelligence purposes, according to The New York Times, citing unnamed “senior administration officials.”

Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

Internet-Sicherheitslücke: NSA soll "Heartbleed"-Fehler systematisch genutzt haben

Internet-Sicherheitslücke: NSA soll "Heartbleed"-Fehler systematisch genutzt haben | ICT Security-Sécurité PC et Internet | Scoop.it

"Heartbleed" ist eine der größten Sicherheitslücken in der Geschichte des Internets - und der US-Geheimdienst NSA hat diese offenbar ausgenutzt. Laut Nachrichtenagentur Bloomberg soll der US-Geheimdienst schon lange davon gewusst haben.


Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Heartbleed Bug—Mobile Apps are Affected Too

Heartbleed Bug—Mobile Apps are Affected Too | ICT Security-Sécurité PC et Internet | Scoop.it
All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.

.

All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

.

Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.

Learn more:


.

Gust MEES's insight:


All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

.

The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.

.

All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

.

Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.


Learn more:




Gust MEES's curator insight, April 11, 2014 11:47 AM
All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

.

The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.

.

All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

.

Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.

.

Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

The Heartbleed Hit List: The Passwords You Need to Change Right Now

The Heartbleed Hit List: The Passwords You Need to Change Right Now | ICT Security-Sécurité PC et Internet | Scoop.it
Heartbleed: A look at which companies have issued a security patch to fix the Heartbleed bug.


Some Internet companies that were vulnerable to the bug have already updated their servers with a security patch to fix the issue. This means you'll need to go in and change your passwords immediately for these sites.

.

Even that is no guarantee that your information wasn't already compromised, but there's also no indication that hackers knew about the exploit before this week. The companies that are advising customers to change their passwords are doing so as a precautionary measure.

Learn more:



Gust MEES's insight:


Learn more:



Gust MEES's curator insight, April 11, 2014 10:05 AM


Some Internet companies that were vulnerable to the bug have already updated their servers with a security patch to fix the issue. This means you'll need to go in and change your passwords immediately for these sites.

.

Even that is no guarantee that your information wasn't already compromised, but there's also no indication that hackers knew about the exploit before this week. The companies that are advising customers to change their passwords are doing so as a precautionary measure.

Scooped by Gust MEES
Scoop.it!

Heartbleed bug advice about changing your passwords

Heartbleed bug advice about changing your passwords | ICT Security-Sécurité PC et Internet | Scoop.it
A lot of folks are going around at the moment telling the public to change all of their passwords in response to the serious Heartbleed internet security bug.

But it's not necessarily the wisest advice.


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

What the Heartbleed bug is, and how you can protect yourself (and your servers)

What the Heartbleed bug is, and how you can protect yourself (and your servers) | ICT Security-Sécurité PC et Internet | Scoop.it

Over the last couple of days, you may have heard about the rather ominous sounding Heartbleed bug -- a bug that affected hundreds of millions of websites, exposing usernames, passwords, encryption keys, and other sensitive data. This bug went undiscovered for two years, meaning it's highly likely that some of your data was exposed, and may have been scooped up by enterprising hackers -- and unfortunately, given the nature of this bug, there's almost nothing you can do about.


Learn more:



Gust MEES's insight:


Learn more:



No comment yet.
Scooped by Gust MEES
Scoop.it!

Heartbleed security patches coming fast and furious

Heartbleed security patches coming fast and furious | ICT Security-Sécurité PC et Internet | Scoop.it



Fixes for the highly dangerous OpenSSL Heartbleed security hole are arriving now. Update your servers ASAP.








Learn more:



Gust MEES's insight:


Learn more:



No comment yet.