Monday, June 22, 2009

Could Opera 10 Be Banned in Corporations?

The new version of Opera, version 10, will include a web server as part of a platform called Unite. Opera is touting it for home users who want to be able to publish content but don’t know how to configure their firewalls or are getting blocked by ISP’s. This also means that anyone on your corporate network could setup a web server to serve up files from your network (sound scary? It should.)

Security researchers say this could be a perfect opportunity for botmasters to use the browser as a command and control channel. Not only that but Opera users could unknowingly give access to critical system files as well. The platform uses a group of extensions to the widget system Opera uses to provide enhanced functionality to the browser. While Opera warns developers of the risks, it is up to the developer in the end to decide how careful they are going to be. It also places a significant responsibility on the end user to determine what parts of Unite and the other Opera widgets could give up control to the less honest people on the web.

Other researchers are also warning that it could spur malware authors to write specifically for the Opera browser. As it passes through the Beta phase I’m sure we’ll see more about this and likely some POC code.

Sunbelt Software
Network World – “Could Opera be a Botmaster’s Best Friend
Geeks are Sexy - “Opera Unite – should be “Untie”?”
Opera Software – Opera Unite

Wednesday, June 10, 2009

Accidental Google Hack

Google is a great source of information both good and not so good. Be careful what you post on forums, discussion groups, etc. This is a very interesting blog post:

http://synjunkie.blogspot.com/2009/06/accidental-google-hack.html

“Oh dear...within seconds Bob found a password. Surely it was old and probably not active anymore?”

Friday, June 5, 2009

Checklist a Day: Residential Wireless Audit

If you aren’t sure if your home wireless network is secure (or you don’t think it should be) you should read this document. It takes very little time and will make sure your personal information is secure.

Home Network Audit

Microsoft and Adobe to Issue Patches Tuesday June 9

Adobe is releasing a round of patches Tuesday June 9 that will cover Acrobat 7.x – 9.x for Windows and OS X.

Also on Tuesday Microsoft is releasing 10 patches to cover vulnerabilities in Windows, Excel, and IE.

Get ready to do some heavy testing on Tuesday.