ICT Security-Sécurité PC et Internet
88.3K views | +1 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Rescooped by Gust MEES from 21st Century Learning and Teaching
May 12, 2013 8:02 AM
Scoop.it!

20 ways to keep your internet identity safe from hackers

20 ways to keep your internet identity safe from hackers | ICT Security-Sécurité PC et Internet | Scoop.it
Cybercrime costs Britain £27bn a year, and it could cost you dear too if you don't take basic precautions. James Silver asked experts for their top tips
Gust MEES's insight:

 

The weakest link in a security chain is and still will be the human!!! A security by 100% doesn't exist!!!

 

===> Read the article, a MUST!!! <===> ALSO for MAC & Linux users!!! <===

 

Learn more:

 

https://gustmees.wordpress.com/2012/11/29/cyber-hygiene-ict-hygiene-for-population-education-and-business/

 

https://gustmees.wordpress.com/2012/11/05/naivety-in-the-digital-age/

 

http://www.symantec.com/connect/articles/social-engineering-fundamentals-part-i-hacker-tactics?API1=100&API2=3640290

 

 

Gust MEES's curator insight, May 12, 2013 7:58 AM

 

The weakest link in a security chain is and still will be the human!!! A security by 100% doesn't exist!!!

 

===> Read the article, a MUST!!! <===> ALSO for MAC & Linux users!!! <===

 

Learn more:

 

https://gustmees.wordpress.com/2012/11/29/cyber-hygiene-ict-hygiene-for-population-education-and-business/

 

https://gustmees.wordpress.com/2012/11/05/naivety-in-the-digital-age/

 

http://www.symantec.com/connect/articles/social-engineering-fundamentals-part-i-hacker-tactics?API1=100&API2=3640290

 

Gust MEES's curator insight, May 12, 2013 8:03 AM

 

The weakest link in a security chain is and still will be the human!!! A security by 100% doesn't exist!!!

 

===> Read the article, a MUST!!! <===> ALSO for MAC & Linux users!!! <===

 

Learn more:

 

https://gustmees.wordpress.com/2012/11/29/cyber-hygiene-ict-hygiene-for-population-education-and-business/

 

https://gustmees.wordpress.com/2012/11/05/naivety-in-the-digital-age/

 

http://www.symantec.com/connect/articles/social-engineering-fundamentals-part-i-hacker-tactics?API1=100&API2=3640290

 

 

Rescooped by Gust MEES from 21st Century Learning and Teaching
April 30, 2013 6:19 AM
Scoop.it!

Backdoor entdeckt: Angreifer kaperten schon hunderte Apache-Server

Backdoor entdeckt: Angreifer kaperten schon hunderte Apache-Server | ICT Security-Sécurité PC et Internet | Scoop.it
Bösartige Angreifer kapern Apache-Webserver und leiten deren Besucher auf Schad-Websites um. Die Tarnung der Malware ist fast perfekt.

 

Eine Hintertür, die von Administratoren nur schwer bemerkt werden kann, sorgt dafür, dass Internet-Anfragen an Apache-Server nicht in Logs aufgenommen werden. Die gesendeten http-Anfragen, die in Wirklichkeit einen Trojaner steuern, sind nicht ersichtlich. Der Rest des Angriffs läuft im Speicher ab, Bugfixes gibt es noch nicht.

 

29. April 2013 von Manfred Kohlen 0


Die Malware Linux/Cdorked.A ist eine raffinierte Hintertür, die alles tut, um den Internetverkehr auf schädliche Webseiten umzuleiten, schreibt Sicherheitsanbieter Eset in einer aktuellen Warnung.   Der Schädling sei so gut, dass er laut eigener Analysen schon hunderte von Webservern unter seine Kontrolle gebracht habe.

 

Gust MEES's insight:

 

Learn more:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Apache-vulnerabilities

 

Scooped by Gust MEES
March 21, 2013 5:54 PM
Scoop.it!

Linux-Lösch-Malware bei Südkorea-Attacke im Einsatz

Linux-Lösch-Malware bei Südkorea-Attacke im Einsatz | ICT Security-Sécurité PC et Internet | Scoop.it
Sicherheitsexperten analysieren derzeit die Cyberattacken auf Südkorea und liefern die ersten Ergebnisse. Demnach wurde unter anderem eine Malware eingesetzt, die das Ziel hat, Linux-Rechner auszuschalten.
Gust MEES's insight:

 

Nobody is perfect! Any OS can be...

 

No comment yet.
Scooped by Gust MEES
February 25, 2013 1:44 PM
Scoop.it!

Virus Bulletin : VB100 results SUSE Linux - February 2013

Virus Bulletin : VB100 results SUSE Linux - February 2013 | ICT Security-Sécurité PC et Internet | Scoop.it
View the results of the Virus Bulletin VB100 anti-virus product comparisons
Gust MEES's insight:

A MUST check for Linux users!!!

 

Check also:

 

http://www.scoop.it/t/securite-pc-et-internet?tag=Nobody-is-perfect

 

http://www.scoop.it/t/securite-pc-et-internet?q=Linux

 

Scooped by Gust MEES
January 3, 2013 3:38 AM
Scoop.it!

Malware is targeting Java HTTP servers

Malware is targeting Java HTTP servers | ICT Security-Sécurité PC et Internet | Scoop.it
Security researchers from antivirus vendor Trend Micro have uncovered a piece of backdoor-type malware that infects Java-based HTTP servers and allows attackers to execute malicious commands on the underlying systems.
Gust MEES's insight:

                       ===> Be AWARE of the MALWARE! <===

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
November 6, 2012 12:24 PM
Scoop.it!

Adobe Ships Election Day Security Update for Flash

Adobe Ships Election Day Security Update for Flash | ICT Security-Sécurité PC et Internet | Scoop.it

Adobe has released a critical security update for its Flash Player and Adobe AIR software that fixes at least seven dangerous vulnerabilities in these products.

 

===> Updates are available for Windows, Mac, Linux and Android systems. <===

 

Read more, a MUST and don't forget to update:

http://krebsonsecurity.com/2012/11/adobe-ships-election-day-security-update-for-flash/

 

No comment yet.
Scooped by Gust MEES
October 9, 2012 11:32 AM
Scoop.it!

Adobe fixes 25 critical security holes affecting Windows, Mac and Linux

Adobe fixes 25 critical security holes affecting Windows, Mac and Linux | ICT Security-Sécurité PC et Internet | Scoop.it
Adobe released an update for its Flash Player software on Monday, fixing 25 security holes in the commonly used product. The updates affect Flash running on Windows, Apple Mac and Linux systems in ...

 

Read more, a MUST:

http://nakedsecurity.sophos.com/2012/10/09/adobe-security-update/?utm_source=dlvr.it&amp;utm_medium=twitter&amp;utm_content=rss2&amp;utm_campaign=Feed

 

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
September 2, 2012 8:05 AM
Scoop.it!

Firesheep addon allows the clueless to hack Facebook, Twitter over Wi-Fi

Firesheep addon allows the clueless to hack Facebook, Twitter over Wi-Fi | ICT Security-Sécurité PC et Internet | Scoop.it
If you thought that capturing a user's social media session was only done by skilled hackers, now the Firesheep addon can allow even the truly clueless to become an Internet griefer.

 

Even if you were drunk and surfing at a Wi-Fi hotspot, you probably wouldn't stand up and shout your username and password for anyone who might want it. But an attacker does not need to find out your username and password. If you thought that capturing a user's social media session was only done by skilled hackers, now the Firesheep addon can allow even the truly clueless to become an Internet griefer.

 

If you were at a Wi-Fi hotspot, you probably would have no options and no encryption at all. Although many websites give lip service about how important their users' privacy and security is to them, very few have their entire site encrypted with HTTPS. Most sites encrypt the username and password during the login process, but most of those sites stop encrypting and protecting the user right there. As soon as a user moves on to a regular HTTP page on the site, an attacker can sniff and capture the user's cookie information.

 

Many of us are busy multitasking, so we log into Twitter or Facebook, or even Flickr, and then move on to surf other sites without first logging out of those accounts. If any of those future sites have a Twitter or Facebook widget, or even a Flickr image embedded, if you didn't log out of those sites before continuing to surf, then HTTP session jacking, also called "sidejacking," can happen and leak the user's cookie. Security researchers explained that if a person can steal the cookie, then they can steal your session and allow them to do anything the user could do on the site.

 

Gust MEES: a MUST READ for Mac, Linux and Windows users!!!

 

Read more:

http://blogs.computerworld.com/17226/firesheep_addon_allows_the_clueless_to_hack_facebook_twitter_over_wi_fi

 

No comment yet.
Scooped by Gust MEES
August 31, 2012 1:04 PM
Scoop.it!

FinFisher trojan for iOS and Android sighted

FinFisher trojan for iOS and Android sighted | ICT Security-Sécurité PC et Internet | Scoop.it
Mobile variants of the commercial FinFisher trojan target BlackBerry, Windows Mobile, Symbian, Android and iOS devices.

 

The commercial FinFisher FinSpy spyware trojan was created by Gamma International, and its development is believed to take place in Germany. The company sells its trojan toolkit – which is thought to currently support all major operating systems including Linux, Mac OS X and Windows – to governments for use by security agencies. Until now, relatively little was known about the mobile variant of the trojan.


Based on the available code samples, Citizen Lab is convinced that the mobile trojans it analysed are a mobile variant of FinSpy. The trojan is believed to be capable of monitoring rooms through silent calls, downloading files, tracking a user's location, and forwarding phone calls, SMS text messages and emails. FinSpy can also apparently intercept BlackBerry Messenger messages. The trojan typically infects smartphones via specially crafted emails.


The iOS variant requires iOS 4 or later and is executable on all iPad models, on iPhone 4 and 4S devices, and on third and fourth generation iPod Touch devices. The app installs in the background, downloads further code, and injects this code into the startup routine, anchoring itself deep into the system. The researchers found "FinSpyV2" references in the binary. As the binary contains a valid developer certificate and an ad-hoc distribution profile, iOS devices accept it without the need for a jailbreak. The certificate was issued to Martin Münch – the managing director of Gamma International's German subsidiary.

 

No comment yet.
Scooped by Gust MEES
August 28, 2012 2:11 PM
Scoop.it!

DR Web discovers the first Linux/OSX cross-platform trojan

DR Web discovers the first Linux/OSX cross-platform trojan | ICT Security-Sécurité PC et Internet | Scoop.it
Dr Web, the Russian anti-malware company that did much to expose the growth of the Flashback botnet, has found the first Linux/OSX cross-platform trojan – which it calls BackDoor.Wirenet.1...

 

 

 

Read more:

http://www.infosecurity-magazine.com/view/27833/dr-web-discovers-the-first-linuxosx-crossplatform-trojan/?utm_source=twitterfeed&amp;amp;utm_medium=twitter

 

No comment yet.
Scooped by Gust MEES
July 31, 2012 7:33 PM
Scoop.it!

Updates: Google Chrome 21 is out

Updates: Google Chrome 21 is out | ICT Security-Sécurité PC et Internet | Scoop.it

 

Summary: Google Chrome version 21.0.1180.60 (21.0.1180.57 for Mac and Linux) is out, fixing 15 security vulnerabilities in the search giant's browser.

 

===> Strictly from a security perspective, you should upgrade as soon as possible. <===

 

Read more:

http://www.zdnet.com/google-chrome-21-is-out-7000001920/

 

No comment yet.
Scooped by Gust MEES
July 16, 2012 5:38 PM
Scoop.it!

Cross-platform Trojan attacks Windows, Intel Macs, Linux

Cross-platform Trojan attacks Windows, Intel Macs, Linux | ICT Security-Sécurité PC et Internet | Scoop.it
Summary: A second cross-platform Trojan downloader has been discovered that detects if you're running Windows, Mac OS X, or Linux, and then downloads the corresponding malware for your platform.

 

Read more:

http://www.zdnet.com/cross-platform-trojan-attacks-windows-intel-macs-linux-7000000872/

 

No comment yet.
Scooped by Gust MEES
July 11, 2012 12:21 PM
Scoop.it!

Multi-Platform Java Exploit Targets Macs, Linux, Windows

Multi-Platform Java Exploit Targets Macs, Linux, Windows | ICT Security-Sécurité PC et Internet | Scoop.it
If allowed to run, a malicious Java applet checks the user's operating system and delivers a payload customized for that platform, whether it's Windows, Mac OS X, or Linux.

 

Read more:

http://www.securityweek.com/multi-platform-java-exploit-targets-macs-linux-windows

 

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
May 1, 2013 9:31 AM
Scoop.it!

'Sophisticated' backdoor malware opens up security blackhole in Apache web servers

'Sophisticated' backdoor malware opens up security blackhole in Apache web servers | ICT Security-Sécurité PC et Internet | Scoop.it
Malware that hides itself from admins has been found in the wild, allowing attackers to compromise web servers and redirect users to sites hosting exploit kits.

 

Researchers at security firm ESET have dubbed the malware Linux/Cdorked.A and are calling it "the most sophisticated Apache backdoor" due to its ability to evade detection. 

 

===> Apache web servers run about 50 percent of the world’s websites, according to UK-based internet security firm, Netcraft. <===

 

The researchers claim the malware has been installed on hundreds of compromised web servers, which have served up malicious redirects to thousands of visitors.

Gust MEES's insight:

 

===> Apache web servers run about 50 percent of the world’s websites, according to UK-based internet security firm, Netcraft. <===

 

Learn more:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Apache-vulnerabilities

 

 

Gust MEES's curator insight, May 1, 2013 9:27 AM

 

===> Apache web servers run about 50 percent of the world’s websites, according to UK-based internet security firm, Netcraft. <===

 

Learn more:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Apache-vulnerabilities

 

 

Scooped by Gust MEES
March 29, 2013 2:47 PM
Scoop.it!

Critical Flaw Threatens Millions of BIND Servers | threatpost

Critical Flaw Threatens Millions of BIND Servers | threatpost | ICT Security-Sécurité PC et Internet | Scoop.it

There is a critical vulnerability in several current versions of the BIND nameserver software that could allow an attacker to knock vulnerable DNS servers offline or compromise other applications running on those machines. The bug is present in several versions of the ubiquitous BIND software and the maintainers of the application have released a patch for it ===> that they recommend users install as soon as possible. <===

 

===> The vulnerability is in BIND 9.7, 9.8, and 9.9 for Unix systems, but Windows versions are not affected. <===

 

The problem lies in the way that the software handles certain regular expressions, and an attacker who exploits the vulnerability could not only cause a denial-of-service condition on the server but also could potentially compromise other software on the machine.

 

Gust MEES's insight:

 

The bug is present in several versions of the ubiquitous BIND software and the maintainers of the application have released a patch for it ===> that they recommend users install as soon as possible. <===

 

===> The vulnerability is in BIND 9.7, 9.8, and 9.9 for Unix systems, but Windows versions are not affected. <===

 

The problem lies in the way that the software handles certain regular expressions, and an attacker who exploits the vulnerability could not only cause a denial-of-service condition on the server but also could potentially compromise other software on the machine.

 

Check also:

 

http://www.scoop.it/t/securite-pc-et-internet?tag=Linux-Vulnerabilities

 

No comment yet.
Scooped by Gust MEES
March 11, 2013 3:36 AM
Scoop.it!

Linux kernel: denial of service via DCCP getsockopt

Linux kernel: denial of service via DCCP getsockopt | ICT Security-Sécurité PC et Internet | Scoop.it
This bulletin was written by Vigil@nce : http://vigilance.fr/offer SYNTHESIS OF THE VULNERABILITY A local attacker can use the getsockopt() (...)
Gust MEES's insight:

 

Check also:

 

http://www.scoop.it/t/securite-pc-et-internet?tag=Linux-Vulnerabilities

 

Selena Mini's comment, March 11, 2013 5:28 AM
It's great to see ..
Scooped by Gust MEES
February 25, 2013 10:51 AM
Scoop.it!

Linux-Rootkits missbrauchen SSH-Dienst

Linux-Rootkits missbrauchen SSH-Dienst | ICT Security-Sécurité PC et Internet | Scoop.it
Auf kompromittierten Linux-Systemen haben Sicherheitsexperten eine heimtückische Hintertür entdeckt, die sich über eine Bibliothek in den SSH-Dienst einklinkt.
Gust MEES's insight:

Check also:

 

http://www.scoop.it/t/securite-pc-et-internet?tag=Linux-Vulnerabilities

 

http://www.scoop.it/t/securite-pc-et-internet?tag=Nobody-is-perfect

 

No comment yet.
Scooped by Gust MEES
November 20, 2012 8:32 AM
Scoop.it!

Linux Rootkit Found Launching iFrame Injection Attacks

Linux Rootkit Found Launching iFrame Injection Attacks | ICT Security-Sécurité PC et Internet | Scoop.it
The Linux root kit targets 64-bit Linux platforms and uses advanced techniques to hide itself, and infects the websites hosted on attacked HTTP server working to launch drive-by download attacks.

 

“It's an outstanding sample, not only because it targets 64-bit Linux platforms and uses advanced techniques to hide itself, but primarily because of the unusual functionality of infecting the websites hosted on attacked HTTP server - and therefore working as a part of drive-by download scenario,” commented Marta Janus, a Kaspersky Lab Expert who examined the rootkit sample.

 

===> “This rootkit, though it's still in the development stage, shows a new approach to the drive-by download schema and we can certainly expect more such malware in the future.” <===

 

Read more:

http://www.securityweek.com/linux-rootkit-found-launching-iframe-injection-attacks

 

No comment yet.
Rescooped by Gust MEES from Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security...
November 1, 2012 12:12 PM
Scoop.it!

Jacksbot Java malware can take control of Windows, Mac, and Linux systems

Jacksbot Java malware can take control of Windows, Mac, and Linux systems | ICT Security-Sécurité PC et Internet | Scoop.it

Two weeks ago, Mac security software company Intego discovered malware which it classified as "a new Java backdoor trojan called Java/Jacksbot.A.” New threats are discovered all the time, but Intego later concluded that even though Jacksbot is a variant of the Java remote access tool (RAT) created by the jailbreaking group Redpois0n, it can target multiple platforms.

 

The malware writers behind JACKSBOT may just be testing the waters for a successful multiplatform malware; however for now they appear to be unwilling to invest the time and resources to develop the code more completely.

 

===> It’s likely that the authors will continue to improve the code to fully support infection for OS X and Linux. <===

 

Read more, a MUST:

http://thenextweb.com/2012/10/31/jacksbot-java-malware-can-take-control-of-windows-mac-and-linux-systems/?utm_source=dlvr.it&amp;amp;utm_medium=twitter

 

No comment yet.
Scooped by Gust MEES
September 3, 2012 9:03 AM
Scoop.it!

Hackers turn remote maintenance tool into trojan

Hackers turn remote maintenance tool into trojan | ICT Security-Sécurité PC et Internet | Scoop.it

Hackers are using remote maintenance tool NetWire, which can be used to monitor computers running Windows, Mac OS X, Linux and Solaris, as a trojan. Anti-virus software companies have responded by identifying the program as malware.

 

Read more:

http://www.h-online.com/security/news/item/Hackers-turn-remote-maintenance-tool-into-trojan-1697425.html

 

No comment yet.
Scooped by Gust MEES
September 1, 2012 9:53 AM
Scoop.it!

Linux users targeted by password-stealing 'Wirenet' Trojan

Linux users targeted by password-stealing 'Wirenet' Trojan | ICT Security-Sécurité PC et Internet | Scoop.it

 

===> Malware writers are interested in Linux after all. <===

 

Russian security firm Dr Web has reported finding a shadowy Trojan that sets out to steal passwords on the open source platform as well as OS X.

 

Cross platform malware is rare but not unheard of, the usual technique being to hook into Java in search of victims using OS X.

Malware specifically designed to steal credentials from Linux systems is almost unheard of but might, on the basis of this new discovery, become a little less so in future.

 

"We do not have explicit evidence that it uses Java. To my knowledge it does not. This file was received from Virustotal," Dr Web analyst Igor Zdobnov told Techworld.

 

Read more:

http://news.techworld.com/security/3378804/linux-users-targeted-by-password-stealing-wirenet-trojan/?olo=rss&amp;utm_source=dlvr.it&amp;utm_medium=twitter

 

 

No comment yet.
Scooped by Gust MEES
August 29, 2012 6:12 AM
Scoop.it!

Une faille non répertoriée de Java menace tous les ordinateurs

Une faille non répertoriée de Java menace tous les ordinateurs | ICT Security-Sécurité PC et Internet | Scoop.it
Une vulnérabilité, jugée très critique par les spécialistes en sécurité, vient d’être découverte dans la version 7 de Java. Windows, Linux et Mac OS X sont concernés.

 

En savoir plus :

http://www.01net.com/editorial/571657/une-faille-non-repertoriee-de-java-menace-tous-les-ordinateurs/

 

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
August 14, 2012 3:58 PM
Scoop.it!

Critical Security Fixes from Adobe, Microsoft

Critical Security Fixes from Adobe, Microsoft | ICT Security-Sécurité PC et Internet | Scoop.it

Adobe and Microsoft each issued security updates today to fix critical vulnerabilities in their software. Adobe’s fixes include a patch for a Flash Player flaw that is actively being exploited to break into Windows computers. Microsoft’s Patch Tuesday release includes nine patch bundles — more than half of them rated critical — addressing at least 27 security holes in Windows and related software.

 

Nevertheless, the underlying vulnerability being targeted exists in Windows, Mac and Linux versions of the software. Windows and Mac users can grab the latest version (v. 11.3.300.271) via the Flash Player download center.

 

Be sure to uncheck the “free” software scans that Adobe loves to bundle with updates, such as McAfee‘s obnoxious Security Scan Plus, if you don’t want it. Linux users should update to v. 11.2.202.238, and Chrome users want to be at v. 11.3.330.270 (normally Chrome auto-updates Flash, but recently it’s been sluggish to do so: my Chrome installation is still at v. 11.3.31.225. I will update this post in a bit with the direct links to the Flash Player downloads.

 

Read more, a MUST for any "OS":

 

http://krebsonsecurity.com/2012/08/critical-security-fixes-from-adobe-microsoft/

 

No comment yet.
Scooped by Gust MEES
July 17, 2012 9:37 AM
Scoop.it!

Banking on a Live CD — Krebs on Security

Banking on a Live CD — Krebs on Security | ICT Security-Sécurité PC et Internet | Scoop.it

The quickest way to temporarily convert your Windows PC into a Linux system is to use a Live CD. This involves burning an downloadable image file to a CD, inserting the disc into your computer, and rebooting. If this sounds difficult, don’t worry, it’s not.

 

Here’s a step-by-step guide that should get you up and running in no time flat, with Puppy Linux, an extremely lightweight and fast version of Linux. If you’d prefer to try another distribution, there are dozens to choose from.

 

Gust MEES: check also here to find more Live-CD's

http://www.scoop.it/t/ict-security-tools?tag=LIVE-CD-LIST&amp;amp;nbsp

 

 

Read more:

http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/?utm_source=dlvr.it&amp;amp;amp;utm_medium=twitter

 

 

No comment yet.
Scooped by Gust MEES
July 16, 2012 9:24 AM
Scoop.it!

Sicherheitslücke und Jailbreak bei Amazon Kindle Touch

Sicherheitslücke und Jailbreak bei Amazon Kindle Touch | ICT Security-Sécurité PC et Internet | Scoop.it
Der Webbrowser des eBook-Readers führt beim Besuch einer präparierten Webseite beliebige Shell-Befehle mit Root-Rechten aus. Die Jailbreak-Community setzt diese Lücke bereits zur Installation von nicht autorisierter Software ein.

 

Weiter lesen:

http://www.heise.de/security/meldung/Sicherheitsluecke-und-Jailbreak-bei-Amazon-Kindle-Touch-1636888.html

 

No comment yet.