Latest Post

Facebook Launches Login Approvals, New Way to Secure Access to Your Account

Written By Unknown on Friday, 13 May 2011 | 19:38

Yesterday morning, Facebook launched a new feature called "login approvals," which offers users the ability to further secure access to their Facebook account through the introduction of a second step to the login process. Once opted-in to this security feature, users enter in their email address and password as usual, but will then receive a second code sent to them on their mobile phone. This short, numeric code must also be entered before being able to access Facebook from that computer.

While an extra step may not be to everyone's liking, for those looking for additional ways to secure access to their account, this feature will be welcomed.

Two-Factor Authentication Increases Security

This type of security feature is known as "two-factor authentication," a term which refers to the two separate steps taken to ensure a user is who they say they are. A username (in this case, the email address registered with Facebook) and a password can easily become compromised, as anyone who's had their Facebook account hacked can tell you. What's less likely, however, is for anyone else to gain physical access to your mobile phone.

By requiring that this second code is sent to a device you have in your possession, you can easily keep unwanted third-parties from getting into your Facebook account.

How to Use the Login Approvals Feature

To turn on login approvals, you'll first need to confirm what computer you'll be using, by entering in a security code sent via text message to your phone. Once you enter the code, you'll be asked to save the device to your account, so you don't see the message again when using that same computer.




After this initial setup is complete, if you ever login from an unrecognized device, you'll be asked to enter in another security code sent to your phone. You will also be notified of this change upon the following login to Facebook, and asked to verify the attempted account access.

If it wasn't you who had attempted to sign in from the other device, you'll be able to change your Facebook password to re-secure the account immediately. However, you can be assured that the person who attempted to hack into your account would not have been able to access it, as they did not have the code sent to your mobile phone at the time.

And if you ever lose your phone, you can return to any previously authorized device to log back into Facebook.

To enable this feature, go to the "Account Security" section of the Account settings page on Facebook, and look for the new "Login Approvals" option. You can access your Account settings by clicking on the "Account" link at the top-right of the Facebook homepage.

Microsoft Acquires Skype for $8.5 Billion

Written By Unknown on Wednesday, 11 May 2011 | 06:19

After rumors that first Facebook and then Microsoft were in talks to acquire Skype, the latter announced that it has acquired the VoIP giant for $8.5 billion in cash.

Skype will be integrated into Microsoft devices and systems such as Xbox and Kinect, Xbox Live, the Windows Phone, Lync and Outlook, Microsoft said in a statement. The company has pledged to continue supporting and developing Skype clients on non-Microsoft platforms as well.

The deal, which was spearheaded by Microsoft CEO Steve Ballmer with assistance from Charles Songhurst, the company’s head of corporate strategy, was completed Monday evening, AllThingsD reported earlier.

The acquisition is an expensive one for Microsoft. Not only is it the largest price Microsoft has paid for a company in decades, Skype is not yet profitable. Despite revenues totaling $860 million last year and operating profits of $264 million, the company lost $6.9 million overall, according to documents filed with the SEC. And the company carries $686 million in debt.

Much of the company’s appeal rests in its largest user base of 663 million, 145 million of which use Skype monthly (Update: Microsoft says Skype has 170 million regular users), and 8.8 million of which are paying customers.

There is one clear set of winners here: Skype’s investors. A group including Silver Lake, Index Ventures, Andreessen Horowitz and the Canada Pension Plan (CPP) Investment Board purchased the company from eBay for $2.75 billion in September 2009.

In August, Skype filed for an IPO but put plans on hold after Tony Bates joined the company as CEO in October. Bates will take on the title of president of the Microsoft Skype Division and report directly to Ballmer.

Facebook caught exposing millions of user credentials

Facebook Tricks
Facebook has leaked access to millions of users' photographs, profiles and other personal information because of a years-old bug that overrides individual privacy settings, researchers from Symantec said.

The flaw, which the researchers estimate has affected hundreds of thousands of applications, exposed user access tokens to advertisers and others. The tokens serve as a spare set of keys that Facebook apps use to perform certain actions on behalf of the user, such as posting messages to a Facebook wall or sending RSVP replies to invitations. For years, many apps that rely on an older form of user authentication turned over these keys to third parties, giving them the ability to access information users specifically designated as off limits.

The Symantec researchers said Facebook has fixed the underlying bug, but they warned that tokens already exposed may still be widely accessible.

“There is no good way to estimate how many access tokens have already been leaked since the release [of] Facebook applications back in 2007,” Symantec's Nishant Doshi wrote in a blog post published on Tuesday. “We fear a lot of these tokens might still be available in log files of third-party servers or still being actively used by advertisers.”

While many access tokens expire shortly after they're issued, Facebook also supplies offline access tokens that remain valid indefinitely. Facebook users can close this potential security hole by changing their passwords, which immediately revokes all previously issued keys.

The flaw resides in an authentication scheme that predates the roll out of a newer standard known as OAUTH. Facebook apps that rely on the legacy system and use certain commonly used code variables will leak access tokens in URLs that are automatically opened by the application host. The credentials can then be leaked to advertisers or other third parties that embed iframe tags on the host's page.

“The Facebook application is now in a position to inadvertently leak the access tokens to third parties potentially on purpose and unfortunately very commonly by accident,” Doshi wrote. “In particular, this URL, including the access token, is passed to third-party advertisers as part of the referrer field of the HTTP requests.”

A Facebook spokeswoman said there is no evidence the weakness has been exploited in ways that would violate the social network's privacy policy, which steadfastly promises: “We never share your personal information with our advertisers.” Facebook on Tuesday also announced it was permanently retiring the old authentication routine.

Doshi, who was assisted by fellow researcher Candid Wueest, said there's no way to know precisely how many apps or Facebook users were affected by the glitch. They estimate that as of last month, almost 100,000 applications were enabling the leakage and that over the years “hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties.”

Facebook over the years has regularly been criticized for compromising the security of its users, which now number more than 500 million. The company has rolled out improvements, such as always-on web encryption, although users still must be savvy enough to turn it on themselves, since the SSL feature isn't enabled by default.

As indicated above, all previously issued access tokens can be cleared by changing your Facebook password. Readers who aren't sure if they're affected might want to err on the side of security and update their password now. ®

VUPEN Whitehats break out of Google Chrome sandbox


Researchers say they've developed attack code that pierces key defenses built into Google's Chrome browser, allowing them to reliably execute malware on end user machines.

The attack contains two separate exploits so it can bypass the security counter measures, which include address space layout randomization (or ASLR), data execution prevention (or DEP), and a “sandbox” designed to isolate browser functions from core operating-system operations. So far, there have been relatively few reported exploits that can penetrate the sandbox, and that's one of the reasons the browser has managed to emerge unscathed during the annual Pwn2Own hacker competition for three years in a row.

“While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP,” researchers from France-based Vupen Security wrote in a blog post published on Monday.

They included a video showing the latest version of Chrome running on a 64-bit version of Windows 7. By loading the address of a specially designed website, the researchers are able to force the browser to download and run a calculator application without crashing or showing any other signs of anything amiss.



The Vupen researchers said they plan to share technical details of the exploit only with government customers “for defensive and offensive security.” Neither Google nor the public will be privy to the specifics.

“We're unable to verify VUPEN's claims at this time as we have not received any details from them,” a Google spokesman said. “Should any modifications become necessary, users will be automatically updated to the latest version of Chrome.”

Google to date has awarded more than $150,000 under its bug bounty program, which pays as much as $3133.7 for reports of serious security bugs.

As is typical with attacks that bypass security sandboxes, the Vupen proof-of-concept actually contains two separate exploits, said Chaouki Bekrar, the company's CEO. In an email, he expanded:
The first one results in a memory disclosure and corruption leading to the bypass of ASLR/DEP and execution of the first payload as low integrity level (inside the sandbox). A second payload is then used to exploit another vulnerability which allows the bypass of the sandbox and execution of the final payload with Medium integrity level (outside the sandbox).
Bekrar described one of the exploited flaws as a memory-corruption vulnerability and the other as a design error. ®

Chat Anonymously through Command Prompt

Written By Unknown on Monday, 9 May 2011 | 10:21

1.What you need? > you need your friend's IP Address and Command Prompt

2.Open Notepad and write this code :
@echo off
:A
Cls
echo MESSENGER
set /p n=User:
set /p m=Message:
net send %n% %m%
Pause
Goto A
3.Save this as "Messenger.Bat".

4.Open command prompt

5.Drag bat file over to Command Prompt and press Enter

6.This should came up


7.Now, type the IP Address of the computer you want to contact and press enter
You will see something like this:


8.Now all you need to do is type your message and press Enter.

Enjoy.

Dont forgot to post your reply and share it with your friends.

Skype for Mac update will fix a dangerous security hole

VOICE OVER IP (VoIP) and chat Skype for Mac users will get an update this week closing a dangerous security hole that can allow a hacker to take over a Mac computer simply by sending a message.

Gordon Maddern of security firm Pure Hacking first discovered the vulnerability and created a proof of concept exploit using the Metasploit tool. He said, "The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victim's Mac. It is extremely wormable and dangerous."

Skype didn't make it easy for Maddern to flag the hole, with the researcher claiming he had "a lot of trouble trying to find the right person to notify". Then over a month later, Maddern thought the vulnerability was still open as Skype hadn't informed him of any patch release.

But it turns out that Skype did release a patch, but very, very quietly. In a blog post, Adrian Asher of Skype security said it released a patch for the problem on 14 April, but only a manual update as there were no reports of the exploit being used in the wild. Users aren't prompted for the update, but can download it now by clicking on 'Check for Updates'.

This week will see an update for Skype for Mac that will notify users with a prompt that they need to download it. This release will carry some additional updates and bug fixes.

Skype has been pretty busy on the security front recently. Last month there were some fairly major vulnerabilities with the Skype Android app.

JonDo

Written By Unknown on Thursday, 5 May 2011 | 15:05






Você quer esconder seu endereço IP real e se proteger em quando navega pela internet? 
JAP Anon Proxy  permite a você navegar anonimamente pela web, garantindo sua privacidade. 
Isso significa que nem o servidor sendo usado ou qualquer outra pessoa na Internet saberá quais páginas você visitou.

Normalmente, cada computador na Internet se comunica com um endereço rastreável. 

Isso significa que o site que você visitou e seus dados no seu servico de Internet (ISP) ficam registrados e podem ser visualizados, se interceptados.


O JAP / JonDo utiliza um endereço estático único que é compartilhado por vários usuários JAP. 
Dessa forma, nem o site visitado ou qualquer outro dado pode cair em mãos erradas.

O JAP / JonDo surgiu a partir do projeto Anonymity in the Internet. 

Já que muitos usuários utilizam o serviço de anonimidade AN.ON ao mesmo tempo, as conexões de Internet de cada usuário estão misturadas com as de todos os outros usuários. 
Cada usuário pode ser responsável por qualquer conexão. Ninguém, nenhuma outra pessoa ou entidade, nem mesmo o operador do serviço AN.ON pode determinar que conexão internet foi requisitado por um usuário específico, garantindo a anonimidade dos usuários.


DOWNLOAD: LINK
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger