Graphics Engine threat

A recently added Graphics Engine, WebGL, in Firefox 4 and Chrome 9 are vulnerable to exploit.
The article provisions solutions to disabling this component in both browsers. I will quickly summarise how to disable WebGL in Firefox 4.
  1. Type in "about:config" in the address bar.
  2. Search for "webgl".
  3. Set value for "webgl.disabled" to "true".
  4. Restart Firefox.
Simple steps that will give you peace of mind.

"Armitage"

"Armitage" was a tool that I discovered from the cover of "Linux Journal" in "Page One" today. It shows how outdated I am with the latest fancy security tools available out there.
Visiting the website hosting the tool, I came across this demo video of the tool in action.

This video is easy to follow and comprehend. It saves me the effort of making a similar video. From the demo, the tool proves to be intuitive and logical. The learning curve is pretty gentle as it assists users through the logical flow of discovering vulnerable machines to identifying the applicable exploits that can be launched against the target in order to successfully compromise that system.
Definitely a must-have interface to enhance the capabilities of "Metasploit".

Websense Defensio

It has been almost 2 years since I last went to a Security seminar. I strongly believe that you learn when you attend an event with good content. Today was a classic example. I was enlightened about the available of a free service from "Websense" called "Defensio". It is a tool for social mediums to protect both users and their followers against threats in the form of unruly followers or hackers.
It is available as an app in "Facebook". Type "Defensio" into the search box to find it listed under "Applications". Add the app and allow it access to your profile to protect it. Access the settings section and choose your desired configurations. I tried posting an adult link to my wall and it was successfully blocked by "Defensio".

Terminal

Visited "OMG! Ubuntu!" today as I do everyday. I was presented by a terminal upon successfully accessing the site. My first instinct was that it was a mistake made by the server administrator as my request was redirected to "http://www.omgubuntu.co.uk/bash/". I typed in "help" as hinted in the terminal window. Typical Linux commands were revealed along with strange ones like "moo" and "fortune".
The funny outputs were indicative of an April Fool's prank. The comment "Enjoyed this April fools? click a few ads!" in the page source confirmed this.
I had already caught on and proceeded to continue my fun by running "wget" and "rm *". I also read articles published on the site in text format.
Typing "logout" brings you back to the homepage.

New 2FA

"PassWindow" is a new type of 2 factor authentication (2FA) in the market. The concept is different from what we are normally used to.

It is compact compared to "RSA" tokens. On the topic of "RSA", "RSA" was breached recently and sensitive data was stolen from their network.

Flash drive data purging issue

A new study discovers that employing traditional secure deletion techniques on solid state drives result in majority of data residing on those said drives being left intact. This is a security problem as most portable devices contain solid state drives due to their compact form.

Cross-platform Trojan

Cross-platform Trojan that infects Windows, Mac and Linux machines via Java. Interestingly enough, the Trojan is not persistent in Linux as it cannot survive reboots.
A breakdown of the infection rate by OS can be found here.

Kernel patching

Upgrading to a new kernel version is necessary from a security perspective but it inevitably introduces a new entry in Grub. You can remove those redundant entries by:
  1. Launching "Synaptic Package Manager".
  2. Searching for "Linux kernel image".
  3. Check "Mark for complete removal" for the kernel versions you no longer need.
  4. Click "Apply".
Update: There is a variation to my recommendation previously.

Secure your cookies

In light of the publicity created by Firesheep, HTTPS Everywhere has been updated to force websites to activate a secure flag in cookies used to authenticate their users.
I finally tested Firesheep. It is painfully easy to use for hijacking sessions. Here I start Firesheep on a Windows machine (via RDP) and I log into Facebook on a Ubuntu system. As seen in the screenshot, Firesheep quickly captures the cookie of that session and permits easy access to the active account.

Blacksheep

Security vendor, Zscaler, unleashes a tool named Blacksheep to warn users of the presence of a machine running Firesheep. It doesn't mitigate session hijacking but sounds an alarm to alert of a malicious party in close proximity.

Firesheep

Session hijacking is nothing new with early tools such as Ferret supporting this attack. This Firefox extension, Firesheep, has simplied the attack.
I can't wait for the Linux version to be released so that I can play with it. Ways of avoiding becoming a victim of session hijacking are:
  1. Using encrypted wireless networks.
  2. Using a VPN tunnel over insecure wireless networks.
  3. Use full HTTPS sessions. HTTPS Everywhere is one tool that automates the use of HTTPS for popular websites like Facebook.
  4. Be wary of links sent via email or instant messaging.

Ubuntu maintenance script

 Wrote a simple script for keeping packages and snaps updated in Ubuntu.