Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Monday, October 1, 2007

At Gap data of 800000 competitors have been stolen

Gap has informed on theft of the laptop, containing data about 800 thousand competitors of work from the USA, Puerto Rico and Canada. Laptop has disappeared from office of the foreign company employed Gap for work with data about applicants for work, and data have not been ciphered.

On the stolen computer there were names, addresses, numbers of social insurance and the resumes sent through the Internet or collected by phone from July, 2006 till June, 2007. Gap has begun the notification of competitors, whose numbers of social insurance have got to the third parties, and suggests to provide year monitoring of credit operations. Now information on use of the stolen data did not act.

Wednesday, September 26, 2007

Google: loads of new bugs

In services and products of Google on Monday, September, 24th, 2007, three vulnerabilities allowed the malefactor to execute an any code written in language JavaScript on behalf of a site and to steal requisites of registration record, kept in cookies have been found out, and in one case - to steal photos from online-storehouse. Vulnerability to between-sites scripting (CSS/XSS) have been found out in Google Groups, the search machine and Picasa.

Vulnerability in Google Groups to which at once there was a set of exploits, stealing requisites of access to GMail and sending contents of all mail box, has been eliminated. Exploites worked in four most known browsers: IE, Firefox, Opera and Konqueror. That vulnerability has worked, the victim should pass on specially generated URL, being in mail box GMail.

The second vulnerability of the same type is found out in search machines Google. Exploites, published in Mustlive blog, allowed to steal authentification cookies by means of specially generated URL, the leader on site ICANN and University of York.
The first has been eliminated ICANN, and the second while operates. Search in Google has shown, that approximately 200 thousand sites can be used for attack.

The third vulnerability allows to steal photos with Picasa, having enticed a victim on nocuous a web-page. Though in a basis lays between-sites scripting, for successful attack it is necessary a little making: use Flash, unreliability in URI proceeder and a fake of inquiries at data exchange between appendices. Vulnerability is not eliminated yet, however complexity of its operation will stop hackers for some time.

The previous large batch of bugs in Google has been found out in the end of May - the beginning of June. Then four vulnerabilities to between-sites scripting have existed for a week after detection.

Bug in Google Mail

There was an information about new vulnerability in Google web-mail which allows to organize interception of letters of the user privately. Known researcher Petko Petkov GNU Citizen has found out a bug, by the information from his blog having redirected logined Gmail user on a special site it is possible to create the filter which automatically will forward all messages with attachments on a mail box of the burglar in the mail.

Vulnerability is connected with the wrong data processing, transferred in forms (multipart/form-data POST). Petrkov has not laid out exploit for this vulnerability, however the colleague to whom hw showed breaking Gmail, confirm existence especially marking danger of a such mistake - " exploit works without any interaction with the user and it is absolutely imperceptible, it will be difficult to average user to notice, that its mail steal ". Google is engaged in studying of a mistake.

Friday, September 14, 2007

Condemned spamer struggles for a freedom of speech

One of the most active in the world of spammers Jeremiah Dzhejns sentenced for mass dispatch of advertising letters by nine years of prison, demands to recognize the law on an interdiction of a spam unconstitutional.

According to Dzhejnsa, the interdiction on a spam breaks its constitutional law on a freedom of speech. In due time Dzhejns dispatched on some hundreds thousand letters every day to the electronic addresses taken from stolen databases of companies America On Line and eBay.

In September, 2006 Dzhejnsa have planted in prison, and its sister who, under the version of consequence, helped Dzhejnsu to dispatch letters, has been fined for 7500 dollars.

It is necessary to note, that on rates of dispatches Dzhejns essentially lags behind the the colleague, the arrested person in the USA in May of the last year Alan Soloueja. This spammer offered potential customers dispatch of twenty millions letters for two weeks.

The Australian software producer has brought an action against the Internet forum

The Owner of the Australian site of IT-news Whirlpool has received the summons in court. Software company 2Clix demands from site AU$150000 for the negative statement about its products.

In the claim it is spoken that at a forum of a resource the reputation of the company has been discredited. So, in messages [" Anyone used 2Clix? " (" And what, somebody in general uses 2Clix? "), " 2Clix or Not 2Clix " (" 2Clix or Not 2Clix ")] users state the discontent in occasion of quality of software products, policy of the company, accuse it in a deceit of buyers, informs The Inquirer.

In the USA forums are protected from similar claims by clause 230 " the Certificate about norms of decency in telecommunications " (Communications Decency Act) according to which owners of the resources giving to users an opportunity to leave public messages, do not bear the responsibility for the maintenance of messages. In Australia the similar law is not present.

Wednesday, September 12, 2007

Europarlament is going to ban explosive in the Internet

Recently prevented acts of terrorism in Germany have provoked a new coil of toughening of the legislation directed on struggle against terrorism. Under the official version, three terrorists wished to arrange explosion at the airport of Frankfurt by means of a self-made explosive. Probably, offered innovations turn around of an explosive and planes. According to " the German wave ", the package of the amendments directed on increase of efficiency of struggle against terrorism, has been promulgated by the Eurocommissioner on justice, freedom and safety Ex Frattini.

First of all is offered to create system of the account of explosives within the limits of the European Union, data about which will be brought in special base and will be accessible to law enforcement bodies. Except this it is planned to create system of the emergency notification about theft or loss of an explosive. Whether in this base all European peroxide of hydrogen or ammoniac saltpeter will be considered, not informed. Besides is offered to count all passengers of the planes making flights from the countries of the European Union, having created for them other special base.

In addition, remembering that criminals used a self-made explosive, the Eurocommissioner has suggested to establish the criminal liability for the publication of its recipes on the Internet. However, it is not absolutely clear, as it will help to struggle with the sites, being outside the European Union (we shall tell, in the same America with its First amendment owing to which there there are rather odious sites to close which nobody gathers). Besides eurodeputies are assured of necessity to block an opportunity of corresponding search inquiries.

In general, the question on the responsibility for the publication of recipes of explosives is interesting. In the Russian legislation there are the general interdictions formulated in laws on mass media and counteraction to extremism. However, any sanctions for usual physical persons for it it is not stipulated.

As a result with such recipes struggle usually or militiamen methods of " the telephone right " or hosters, providing an interdiction on an explosive alongside with porno.

Monday, September 10, 2007

Google has demanded to carry out reforms in the patent legislation

Google company has demanded to carry out reforms in the patent legislation of the USA, to exclude cases of judicial claims from the various companies with the purpose to receive profit, using imperfection of laws. It is said in the official blog of Google by Michel Li (Michelle Lee), the chapter of a department of patents and patent strategy of the company, and Johanna Shelton, main Google lawyer.

As they said, the patent legislation of the USA is the extremely imperfect and because of it many large companies working in sphere of high technologies have to spend huge money for proceedings.
Possibly, the reason of such application is the last judicial claim from company Polaris IP which has accused Internet-companies among which Google, Yahoo! And Amazon, in illegal use of the patent for technology of processing e-mail messages.

Sunday, September 9, 2007

3 000 000 internet crimes in 2006 year

In 2006 year in the Internet it has been accomplished about three millions crimes, the experts of the company 1871 investigated a crime rate in the Network under the order of firm Garlik consider. On the average, cybercriminal makes a crime each 12 seconds, newspaper The Telegraph cites the given researches.

Law enforcement bodies do not know about 90 percent of similar crimes as frequently or cyber criminal's victims do not know that the law has been broken or consider, that the police will not begin investigate.

The majority of crimes, under version of 1871 is remarkable, that, online-squabbles, such as insults and threats and also their less widespread consequences, for example, blackmail concerns not financial frauds and seeming quite ordinary in life of the network community of elements.

Also experts have counted 207000 cases of financial frauds including using stolen data like numbers of credit cards and bank accounts, 144500 cases of breakings of computers and 850 thousand crimes in sexual sphere, such as uploading of a children's pornography or prosecution of minors.

Tuesday, September 4, 2007

Embassy's e-mails stolen

The Swedish hacker has taken hold of passwords from hundred electronic mail boxes of employees of embassies of the several countries. In this list also the Russian embassy in Sweden.

The hacker has published passwords and e-mail addresses to diplomatic representatives of Russia (embassy in Sweden), Iran, India and of some other states on the web site "DEranged Security".

Uzbek diplomats are the most unlucky: the hacker has published addresses and passwords from e-mails of more than two tens embassies of this country. About how the Swede could take hold of this information, messages did not act yet.

Pensioner is a phone terrorist

Tomsk, Russia.

Pensioner, dissatisfied by the speed of his internet connection has reported by the phone about underming of the building of the local internet provider.

At the saturday the police have received a call about a bomb in the building of TOMTEL company. Immdeiately special forces of police have arrived, but they were not able to find a bomb. The call has turned to be faked. In an hour specialists have found the phone terrorist.

Police reporting: "the phone terrorist is a 60-year pensioner, unsatisfied by service support of his personal PC. Internet connection was slower than he waited for and he had to wait when computer games will be downloaded from the net."

The pensioner will be under the court in the nearest time.

Tuesday, August 28, 2007

AllOfMP3.Com is going on its work

Famous mp3 music online store AllOfMP3.com is going to continue its work. It's announced in the formal blog of the store, posted from 31 august 2007.

I would like to remind that AllOfMP3.com has been closed in July, 2007 because of foreign possessors of the rights and USA authorities. This web-site (like majority of Russian music web sites and stores) offered music using licences of societies of collective management of composer rights in spite of real licences of possessors of rights.

The general director of the "MediaServices" company and owner of the AllOfMP3.com web-site Denis Kvasov has been justified by the court because of absence of crime.

In the formal blog it is not said if the store is going to change the principle of its business.

All in all, such business is legal according to the Russian legislation, but closing of AllOfMP3.com was one of the most important obstacles in the way to WTO for Russia because it's symbolizing the dynamic of Russian market. There are loads of actions against Russian music providers and online stores. It seems to me that AllOfMP3.com is going to continue its work in the beginning of september. Let's see the response from the foreign countries.

Friday, August 24, 2007

Gmail is forbidden in Germany

According to the decision of court, Google cannot use name Gmail in Germany as it breaks trade mark G-mail belonging businessman Daniel Girsh. As specify in Google, the judicial verdict will not prevent to give service of Web-mail in the country which will be offered by the company under name Google Mail. Under the same name Gmail operates in the Great Britain where also was a corresponding brand. Google has put service of Web-mail into operation in 2004, and for today owns trade mark Gmail more than in 60 countries. According to representatives of the company, after promulgation by court of its reasons in favour of decision-making against Gmail in Google still can try to appeal against an interdiction in the Supreme court of Germany. As Girsh informed, he has registered trade mark G-mail in 2000, but Google conducts judicial struggle last three years. Under brand G-mail, as he said, he offers "hybrid" service which unites usual post and e-mail.

Thursday, August 23, 2007

Popular Monster.com hack was carried out from Ukraine

Breaking of the world's largest recruiting site Monster.com, fixed in the end of the last week, has been carried out from a computer located in territory of Ukraine. To such conclusion have come experts from Symantec company which is responsible for the security of web site Monster.com.

Malefactors have stolen about 1,6 million records from Monster database. Though not each of them contained personal information of users of this site, in hands of hackers there were particularies on hundreds thousand person. Administration of Monster has promised "to arrange", however in what they will consist, is not specified yet. Access to databases of site on which placed more than 70 million resume, has been carried out by means of Trojan program Infostealer. Monstres. Users left the following information on: addresses, phones and e-mail; any data of numbers of credit cards and bank accounts was not on the Monster web site.

Malefactors have begun dispatches of letters ostensibly on behalf of Monster with the offer to establish a certain additional module for work with a site. Under a kind of the module hackers try to compel to establish users on the machines espionage programs.

To my mind, each protection system can be hacked, but security companies have to protect user's data. It is simply work of security companies, in this case such company is Symantec. In our real world I can't trust internet my confidential data like number of credit card or something like this because I know that it can be stolen. But when will we be protected completely? Let's wait for the evolution of internet...