heise online

IT news, features and forums at heise online UK

News

20 May 2008
Foxit Reader executes injected code

There is a gaping security hole in the Foxit PDF reader that lets attackers inject and execute program code via manipulated PDF files. more…

20 May 2008
Zango denies Storm worm conspiracy theories

Trend Micro has discovered Storm worm variants which appear to be installing Zango adware. Following discussions with the developers of the Storm worm, the adware company denies the conspiracy theories. more…

20 May 2008
Spam domains use small number of registrars

In an analysis of links in several million spam emails, the anti-spam activists at Knujon have found that 90 per cent of all spam domains use only 20 registrars. more…

20 May 2008
Security holes in CA ARCserve Backup allow code injection

CA warns of security holes in its ARCserve Backup software that allow attackers to inject arbitrary program code from the internet into installations of the program without having to log on. more…

20 May 2008
Chinese websites under mass attack

China has now fallen victim to massive scale SQL injection attacks similar to those recently perpetrated on European web sites. more…

20 May 2008
Napster opens MP3 on-line shop

As announced in January, the music shop will offer MP3s without copy protection - but only in the US. more…

20 May 2008
Social networks popular among mobile Opera users

According to an analysis of traffic data that the Norwegian software vendor has just published, users of the Opera Mini cell phone browser like to use social networks, such as Facebook and MySpace. more…

20 May 2008
HP's memristor the field leader for new memory technology?

Predicted by theory in 1971, this fourth basic circuit element, apparently now proven to exist in HP's labs, could form the basis of a new form of non-volatile memory. more…

19 May 2008
British government in Google tie-up

The Prime Minister today presented a plan for increasing IT use in the public sector at Google's Zeitgeist Conference in London. more…

19 May 2008
Teenage web site vandals arrested

Five people aged 16 to 20 have been arrested in Spain for a three-year campaign of web site defacements. more…

19 May 2008
Cross-site scripting hole in Paypal casts doubt on EV-SSL

The US media report a cross-site scripting hole in a Paypal web page. Despite the hole, Internet Explorer displays a valid extended SSL certificate and a green address bar suggesting the page is safe. more…

19 May 2008
Bug or feature? Apple's Safari Web browser

Apple's Safari Web browser stores data it cannot use in a standard directory without asking users. The software vendor does not believe this poses a security problem. more…

16 May 2008
XO laptop now shipping with Windows XP

After a development period of over a year, Windows XP is now available for the OLPC laptop. Developers plan to give the machine dual-boot capability and to increase its flash storage. more…

16 May 2008
Warrantless access to UK ISP customer activity records imminent

Records will be kept for a year and may be released to law enforcement without the need for a Court order. more…

16 May 2008
Security hole in Internet Explorer allows attackers to execute arbitrary programs

Aviv Raff has discovered a hole in Internet Explorer which allows attackers to execute arbitrary programs on a computer when the user prints a crafted document. more…

16 May 2008
F-Secure issues Linux Security 7.00 warning

A serious bug in F-Secure's Linux scanner has prompted the vendor to issue a warning not to use the software in client mode and to recall the product. more…

16 May 2008
Symantec Altiris Deployment Solution holes allow code injection

Several holes in Symantec's Altiris Deployment Solution may allow remote attackers to inject code and local users to escalate their privileges. more…

16 May 2008
Fallout from the OpenSSL debacle

The bug in the Debian OpenSSL package has sparked discussions on responsibility for patches and bug fixes. Details of the vulnerability and initial exploits for SSH keys are coming to light. more…

16 May 2008
Hackers present new rootkit techniques

At upcoming security conferences, hackers plan to present new rootkit techniques. Sebastian Muñiz has developed a rootkit for Cisco routers, while Shawn Embleton and Sherri Sparks exploit a little known mode in Intel processors. more…

16 May 2008
Closure of 77 Currys.digital stores

Store closures and dividend cuts are part of a revival strategy formed by DSG International, owners of PC World and Currys. more…

16 May 2008
DivX launches Beta phase of its own H.264 decoder

Following its takeover of MainConcept last year DivX Networks has undertaken further steps to compete on the decoder market with the beta phase of its own H.264 video decoder. more…

16 May 2008
Yahoo publishes do-it-yourself search engine

Yahoo's SearchMonkey mainly addresses website operators who want to use a powerful local search engine to output more than standard hit lists, but do not want to spend a lot of time programming. more…

15 May 2008
Vulnerabilities in Citrix Presentation Server and Access Gateway

Unauthorised users can access networks via Citrix Access Gateway and gain desktop sessions in Presentation Server, and Presentation Server does not always encrypt adequately. more…

15 May 2008
Asus expands its Splashtop Linux support

Asus is adding the Splashtop embedded Linux desktop, “instant-on” technology, to four new motherboard models. Asus' long term plan is to have Splashtop on all their motherboards. more…

15 May 2008
Asprox botnet now equipped with SQL injection tool

A new SQL injection module masquerading as a "Microsoft Security Center Extension" has been uploaded to the botnet. It searches Google for vulnerable pages and contaminates them with an iframe. more…

Are you missing an important news story? Please email us!