Resource links for Security Now! Episode #52:
A Busy Week for Security Troubles
- GRC's script-free pure-CSS menuing system demo:
Clickable links within the menu are generally pointing nowhere, or to our "default.htm" page, since we knew that clicking the links was easy. The tough part was getting all of the mouse-hovering menuing to work correctly. So clicking the menu links is not meant to and generally does not take you where the menu indicates.
- The new eBay / Botnet Scam
This article details the new eBay/Botnet scam which uses widely spread "bots" (Trojans) running on compromised PCs to create fake positive feedback to lure unsuspecting ebay buyers into purchasing fraud.
- LogMeIn Acquires Hamachi
This LogMeIn press release provides additional details about LogMeIn's acquisition of Hamachi.
- The eEye D-Link Security Advisory
This is eEye's aging (February 27th, 2006) security advisory which D-Link has been ignoring.
- eEye's PDF Presentation at Blackhat (1.57 MB)
This is a PDF file of eEye's presentation of the D-Link router exploit as it was presented during the Blackhat Conference in Europe. There's little point in hoping that this is still unknown.
- JavaScript Anyone?
This is the SPI Dynamics story explaining the details of their recent Javascript discovery.
- Scan any IP range with JavaScript
This is the SPI Dynamics "Proof of Concept" conclusively demonstrating that JavaScript is not your friend. You can bet that malicious hackers will soon be having a field day with this, since they've been provided with everything they need.
- Intel's Main Centrino Security Page
This main page provides links to the details of the three different recently uncovered security problems in the Windows drivers for Intel's Centrino wireless chips.
- Direct Link to Centrino Identification Utility (257 KB)
This is a direct download link for v3.03 of the Intel PRO/Wireless Network Connection ID Tool. This will tell you whether you have any Intel Centrino chips in your PC, and if so which ones. You can then determine whether you should download the large driver update software.