BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks


BuyLow.com | Resources | Contact Us


 

Don’t Let Personnel Issues Become Security Issues

Terminate Computer Access Before You End a Contract or Tell People They Are Fired
Shortly before a labor union strike in August 2006, two Los Angeles transportation engineers allegedly disconnected traffic signals at four busy intersections. Subsequently, these disgruntled employees were accused of unauthorized access to a computer, identity theft and unauthorized disruption or denial of [...]

Read More About - Don’t Let Personnel Issues Become Security Issues »

Identifying Hoaxes and Urban Legends

Chain letters are familiar to anyone with an email account, whether they are sent by strangers or well-intentioned friends or family members. Try to verify the information before following any instructions or passing the message along.
Why are chain letters a problem?
The most serious problem is from chain letters that mask viruses or other [...]

Read More About - Identifying Hoaxes and Urban Legends »

Widespread P2P Data Breaches

The Federal Trade Commission has notified almost 100 organizations that personal information, including sensitive data about customers and/or employees, has been shared from the organizations’ computer networks and is available on peer-to-peer (P2P) file-sharing networks to any users of those networks, who could use it to commit identity theft or fraud. The agency also has [...]

Read More About - Widespread P2P Data Breaches »

How To Choose An ISP

National Cyber Alert System
Understanding ISPs
ISPs offer services like email and internet access. Compare factors like security, services, and cost so that you find an ISP that supports all of your needs.
What is an ISP?
An ISP, or internet service provider, is a company that provides its customers access to the internet and other web [...]

Read More About - How To Choose An ISP »

Fraudulent Web Sites

We are aware of public reports indicating that attackers are using legitimate web pages to run malicious code on victims’ machines.
Reports, including a posting by Sophos, indicate that these messages
* Include keywords and names related to a current event (such as, the 9/11/2001 terrorist attack)
* Prompt users [...]

Read More About - Fraudulent Web Sites »

7 Practices for Computer Security

1. Protect your personal information. It’s valuable.
2. Know who you’re dealing with.
3. Use security software that updates automatically.
4. Keep your operating system and Web browser up-to-date, and learn about their security features.
5. Protect your passwords.
6. Back up important files.
7. Learn what to do in an e-mergency.
Access to information and entertainment, credit and financial services, products [...]

Read More About - 7 Practices for Computer Security »

Alert: Apple iTunes

Apple Releases iTunes 8.2 and QuickTime 7.6.2
Apple has released iTunes 8.2 and QuickTime 7.6.2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
US-CERT encourages users to review Apple articles HT3592 and HT3591 and apply any necessary updates to help mitigate the risks.
Available for: Mac [...]

Read More About - Alert: Apple iTunes »

BlackBerry Security Advisory

Research In Motion has released security advisory KB18327 to address multiple vulnerabilities in the PDF distiller of the BlackBerry Attachment Service. By convincing a user to open a specially crafted PDF file on a BlackBerry smartphone, an attacker may be able to execute arbitrary code on the computer hosting the BlackBerry Attachment Service.
US-CERT encourages [...]

Read More About - BlackBerry Security Advisory »

Obama Creating A “Cyber Czar”

Washington, DC — President Barack Obama considers computer security a top priority. Immediately after taking office, the President ordered the National Security and Homeland Security Advisors to conduct an immediate Cyber Security Review. The creation of the positioin “Cyber Czar” is a direct result of the security review.
——————————————
President Obama Directs the [...]

Read More About - Obama Creating A “Cyber Czar” »

HP Notebook Batteries Fire Hazard

HP Recalls Notebook Computer Batteries Due to Fire Hazard
WASHINGTON, D.C. – The U.S. Consumer Product Safety Commission, in cooperation with the firm named below, today announced a voluntary recall of the following consumer product. Consumers should stop using recalled products immediately unless otherwise instructed.
Name of Product: Lithium-Ion batteries used in Hewlett-Packard and Compaq notebook computers
Units: [...]

Read More About - HP Notebook Batteries Fire Hazard »

RSS BugTraq

  • QuickZip 0day detailed write-up
    Posted by Security on Mar 15In case some of you missed it - I published 2 articles on the Offensive Security Blog (last one was published a few hours ago), explaining the process of building a (not so typical) SEH based exploit for a QuickZip 0day vulnerability. Part 1 : http://www.offensive-security.com/blog/vulndev/quickzip-stack-bof-0day-a-box-of-chocolat […]
  • New vulnerabilities in Abton
    Posted by MustLive on Mar 15Hello Bugtraq! I want to warn you about new vulnerabilities in Abton. It's commercial Ukrainian CMS. ----------------------------- Advisory: New vulnerabilities in Abton ----------------------------- URL: http://websecurity.com.ua/3618/ ----------------------------- Timeline: 17.02.2009 - found the vulnerabilities. 23.10.2009 […]
  • ZDI-10-029: Apple WebKit innerHTML element Substitution Remote Code Execution Vulnerability
    Posted by ZDI Disclosures on Mar 15ZDI-10-029: Apple WebKit innerHTML element Substitution Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-029 March 15, 2010 -- CVE ID: CVE-2010-0050 -- Affected Vendors: Google Apple -- Affected Products: Google Chrome Apple WebKit Apple Safari -- TippingPoint(TM) IPS Customer Protectio […]
  • Multiple DOM-Based XSS in Dojo Toolkit SDK
    Posted by labs on Mar 15=========================================================== Multiple DOM-Based XSS in Dojo Toolkit SDK Public Release Date: 3/12/2010 Adam Bixby - Gotham Digital Science (labs () gdssecurity com) Affected Software: Dojo Toolkit SDK […]
  • ZoneAlarm 9 (ForceField) Security Disclosure
    Posted by Andrew Barkley on Mar 15Hi, This disclosure pertains to ZoneAlarm 9 (ForceField). ZoneAlarm have been informed. The following discusses similar issues as was previously disclosed regarding ZoneAlarm 8. ZoneAlarm 9 (ForceField) ZoneAlarm version:9.1.007.002 TrueVector version:9.1.007.002 Driver version:9.1.007.002 Introduction The following illustra […]