Showing posts with label hacked. Show all posts
Showing posts with label hacked. Show all posts

Monday, July 1, 2013

Pale Moon browser 20.2 released


Here is the list from palemoon.org
  • (CVE-2013-1692) Fix for the inclusion of body data in an XMLHttpRequest HEAD request, making cross-site request forgery (CSRF) attacks via a crafted web site more difficult.
  • (CVE-2013-1697) Fix to restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges.
  • (CVE-2013-1694) Fix to properly handle the lack of a wrapper, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.
  • Fix to prevent arbitrary code execution from the profiler developer tool.
  • Fix for a crash when rapidly reloading pages.
  • Fix for cross-document selections.
  • Fixes for several crashes in JavaScript.
  • Fixes for several memory safety hazards and uncommon memory leaks.
The best browser for Penzu.com journals on Windows 7 ?




Saturday, January 12, 2013

Java JMX MBean flaw


CERT says
Due to the number and severity of this and prior Java vulnerabilities, it is recommended that Java be disabled temporarily in web browsers
http://www.us-cert.gov/current/#us_cert_releases_oracle_java

http://www.kb.cert.org/vuls/id/625617

http://www.us-cert.gov/cas/techalerts/TA13-010A.html



Wednesday, April 27, 2011

SONY PlayStation network user credit card info hacked

 
The SONY admission that a hacker may have accessed all user info short of credit card 4-digit CSC's should lead to a class-action lawsuit in the USA.

Users should have had the option to use their hardware as the basis for a public-private key encryption of personal information.

The main reason not to do so is greed: SONY required access to pursue fraud and non-payment.  Let SONY now balance this against their present plight.

In all likelihood Oracle relational databases were used by SONY.  Storing strings in relational tables is easy for the developer and a joy for the hacker.  But what functionality could have required relational tables for the personal information of users? Well, it may have made things easier, faster and cheaper for the SONY info tech folks.  Manager gets bonus but users get ...

Sadly, the focus now is likely to be on network security.  And a Master appointed to advise a judge would likely come from the world in which Oracle DB tables are the norm for any and all data.

Access to data should have been on a process basis and no hacker should have been able to fork such a process: only such a process should have been able to convert that data into readable and usable information.

So ... had SONY used Erlang, would their customers be in this sad situation today?  And that is only one option from their asset stables.

Users will have a different view: regardless, of the technology in play, they should have been notified pronto.  Forget KISS, CRUD and ACID. The term of the day is PRONTO.

With any luck, the hacker was in for cred and not credit cards.  But SONY is a giant and this should be a sobering moment for corp IT that is public-facing.  And for users? Well, caveat emptor.  And then get a lawyer with a proven record in class actions.