<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Taranfx - Your Gateway To Technology &#187; vulnerable</title>
	<atom:link href="http://www.taranfx.com/tag/vulnerable/feed" rel="self" type="application/rss+xml" />
	<link>http://www.taranfx.com</link>
	<description>Latest in Technology</description>
	<lastBuildDate>Fri, 30 Jul 2010 16:24:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.taranfx.com/?pushpress=hub'/>
		<item>
		<title>IE Flaw Makes local Files Public</title>
		<link>http://www.taranfx.com/ie-flaw-public-files</link>
		<comments>http://www.taranfx.com/ie-flaw-public-files#comments</comments>
		<pubDate>Thu, 04 Feb 2010 19:08:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[vulnerable]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/ie-flaw-public-files</guid>
		<description><![CDATA[<p><a href="http://www.taranfx.com/wp-content/uploads/2010/02/ieflawed.jpg"><img class="alignleft" title="ie-flawed" src="http://www.taranfx.com/wp-content/uploads/2010/02/ieflawed_thumb.jpg" border="0" alt="ie-flawed" width="225" height="158" /></a> The end of Internet Explorer is finally here. Series of events: <a href="http://www.taranfx.com/google-shutdown-china">Google Hacking</a>, removal of support for Google apps, several other vulnerabilities are forcing <em>users</em> to move to alternates.</p>
<p>Recently, at <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-archives.html" target="_blank">Black Hat DC conference</a>, a security consultant (Jorge Luis Alvarez Medina) demoed how it&#8217;s possible to exploit a flaw in <a href="http://www.taranfx.com/tag/ie">Internet Explorer browser</a> that turns your personal computer into a public file server. In other words, attacker can remotely read files on the victim&#8217;s local drive.</p>
<p>There are a few ways to initiate the attack, which is somewhat complex because you have to &#8220;string alot of the features together to build an attack tool,&#8221; Medina said. One method involves enticing the victim to click a link to a malicious Web site.</p>
<p><a <a href='http://www.taranfx.com/ie-flaw-public-files' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesBrowser Fingerprinting: Privacy is a MythPwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome StandsVulnerabilities in HTML 5 and Future170M Downloadable Facebook Profiles, Privacy #FAILSafari 5 gets ExtensionsFacebook bug lets Hackers delete User&#8217;s FriendlistReverse Phone Lookup &#8211; Weapon of Choice for Unsolicited CallsGMail now Warns for Simultaneous LoginsALL Windows PC Exploited by HackCode that Hacked [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.taranfx.com/wp-content/uploads/2010/02/ieflawed.jpg"><img class="alignleft" title="ie-flawed" src="http://www.taranfx.com/wp-content/uploads/2010/02/ieflawed_thumb.jpg" border="0" alt="ie-flawed" width="225" height="158" /></a> The end of Internet Explorer is finally here. Series of events: <a href="http://www.taranfx.com/google-shutdown-china">Google Hacking</a>, removal of support for Google apps, several other vulnerabilities are forcing <em>users</em> to move to alternates.</p>
<p>Recently, at <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-archives.html" target="_blank">Black Hat DC conference</a>, a security consultant (Jorge Luis Alvarez Medina) demoed how it&#8217;s possible to exploit a flaw in <a href="http://www.taranfx.com/tag/ie">Internet Explorer browser</a> that turns your personal computer into a public file server. In other words, attacker can remotely read files on the victim&#8217;s local drive.</p>
<p>There are a few ways to initiate the attack, which is somewhat complex because you have to &#8220;string alot of the features together to build an attack tool,&#8221; Medina said. One method involves enticing the victim to click a link to a malicious Web site.</p>
<p><a <a href='http://www.taranfx.com/ie-flaw-public-files' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/browser-fingerprinting" title="Browser Fingerprinting: Privacy is a Myth">Browser Fingerprinting: Privacy is a Myth</a></li><li><a href="http://www.taranfx.com/most-secure-browser" title="Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands">Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands</a></li><li><a href="http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps" title="Vulnerabilities in HTML 5 and Future">Vulnerabilities in HTML 5 and Future</a></li><li><a href="http://www.taranfx.com/download-facebook-profiles" title="170M Downloadable Facebook Profiles, Privacy #FAIL">170M Downloadable Facebook Profiles, Privacy #FAIL</a></li><li><a href="http://www.taranfx.com/safari-5-extensions" title="Safari 5 gets Extensions">Safari 5 gets Extensions</a></li><li><a href="http://www.taranfx.com/facebook-hack" title="Facebook bug lets Hackers delete User&#8217;s Friendlist">Facebook bug lets Hackers delete User&#8217;s Friendlist</a></li><li><a href="http://www.taranfx.com/reverse-phone-lookup" title="Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls">Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls</a></li><li><a href="http://www.taranfx.com/gmail-simultaneous-logins" title="GMail now Warns for Simultaneous Logins">GMail now Warns for Simultaneous Logins</a></li><li><a href="http://www.taranfx.com/windows-hacking" title="ALL Windows PC Exploited by Hack">ALL Windows PC Exploited by Hack</a></li><li><a href="http://www.taranfx.com/google-hacking-aurora" title="Code that Hacked Google IDs [Aurora]">Code that Hacked Google IDs [Aurora]</a></li><li><a href="http://www.taranfx.com/how-twitter-was-hacked" title="How Twitter was Hacked">How Twitter was Hacked</a></li><li><a href="http://www.taranfx.com/spyphone-app-steals-personal-data-from-all-iphones" title="SpyPhone App Steals Personal Data from ALL iPhones">SpyPhone App Steals Personal Data from ALL iPhones</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/ie-flaw-public-files/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>ALL Windows PC Exploited by Hack</title>
		<link>http://www.taranfx.com/windows-hacking</link>
		<comments>http://www.taranfx.com/windows-hacking#comments</comments>
		<pubDate>Wed, 20 Jan 2010 18:12:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/windows-hacking</guid>
		<description><![CDATA[<p><a href="http://www.taranfx.com/wp-content/uploads/2010/01/windows-hack.png"><img class="alignleft size-thumbnail wp-image-3360" title="windows hackingh" src="http://www.taranfx.com/wp-content/uploads/2010/01/windows-hack-150x150.png" alt="" width="150" height="150" /></a>There exists an encryption that has been <a href="http://www.taranfx.com/the-encrypted-message-left-unbroken-since-1942-world-war-2">left UnBroken since 1942</a> approximately time around the World war 2.  This is called <a href="http://www.taranfx.com/tag/security">security </a>&#8211; when encryption algorithm lasts long, really long.</p>
<p>Unfortunately, <a href="http://www.taranfx.com/tag/microsoft">Microsoft </a>has a different story. After 17 years of <a href="http://www.taranfx.com/tag/windows">windows</a>, <a href="http://www.h-online.com/security/news/item/Windows-hole-discovered-after-17-years-Update-908917.html" target="_blank">someone </a>found a hole that makes every windows PC on this earth prone to <a href="http://www.taranfx.com/tag/hacking">hacking</a>.</p>
<p>This hole allows users with restricted access to escalate their privileges to system level – This is possible on all 32bit <a href="http://www.taranfx.com/tag/windows">Windows <a href='http://www.taranfx.com/windows-hacking' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesCode that Hacked Google IDs [Aurora]How Twitter was HackedHacking the Unsecure GSM EncryptionHackers Hack Cars Remotely, disable Engines, brakesHow I would Hack your PC, Mac with USB HIDPwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome StandsChinese Google Hacker TrackedWindows 7 Rogue WiFi HackChina Busts Black-Hawk HackersIE Flaw Makes local Files PublicSecure iPhone from HackingNASA [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.taranfx.com/wp-content/uploads/2010/01/windows-hack.png"><img class="alignleft size-thumbnail wp-image-3360" title="windows hackingh" src="http://www.taranfx.com/wp-content/uploads/2010/01/windows-hack-150x150.png" alt="" width="150" height="150" /></a>There exists an encryption that has been <a href="http://www.taranfx.com/the-encrypted-message-left-unbroken-since-1942-world-war-2">left UnBroken since 1942</a> approximately time around the World war 2.  This is called <a href="http://www.taranfx.com/tag/security">security </a>&#8211; when encryption algorithm lasts long, really long.</p>
<p>Unfortunately, <a href="http://www.taranfx.com/tag/microsoft">Microsoft </a>has a different story. After 17 years of <a href="http://www.taranfx.com/tag/windows">windows</a>, <a href="http://www.h-online.com/security/news/item/Windows-hole-discovered-after-17-years-Update-908917.html" target="_blank">someone </a>found a hole that makes every windows PC on this earth prone to <a href="http://www.taranfx.com/tag/hacking">hacking</a>.</p>
<p>This hole allows users with restricted access to escalate their privileges to system level – This is possible on all 32bit <a href="http://www.taranfx.com/tag/windows">Windows <a href='http://www.taranfx.com/windows-hacking' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/google-hacking-aurora" title="Code that Hacked Google IDs [Aurora]">Code that Hacked Google IDs [Aurora]</a></li><li><a href="http://www.taranfx.com/how-twitter-was-hacked" title="How Twitter was Hacked">How Twitter was Hacked</a></li><li><a href="http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret" title="Hacking the Unsecure GSM Encryption">Hacking the Unsecure GSM Encryption</a></li><li><a href="http://www.taranfx.com/car-hacking" title="Hackers Hack Cars Remotely, disable Engines, brakes">Hackers Hack Cars Remotely, disable Engines, brakes</a></li><li><a href="http://www.taranfx.com/pc-mac-usb-hid-hack" title="How I would Hack your PC, Mac with USB HID">How I would Hack your PC, Mac with USB HID</a></li><li><a href="http://www.taranfx.com/most-secure-browser" title="Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands">Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands</a></li><li><a href="http://www.taranfx.com/google-hackers-china" title="Chinese Google Hacker Tracked">Chinese Google Hacker Tracked</a></li><li><a href="http://www.taranfx.com/windows-7-rogue-wifi" title="Windows 7 Rogue WiFi Hack">Windows 7 Rogue WiFi Hack</a></li><li><a href="http://www.taranfx.com/china-busts-hackers" title="China Busts Black-Hawk Hackers">China Busts Black-Hawk Hackers</a></li><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li><li><a href="http://www.taranfx.com/change-iphone-ssh-password" title="Secure iPhone from Hacking">Secure iPhone from Hacking</a></li><li><a href="http://www.taranfx.com/nasa-security-breached-thousand-times" title="NASA Security Breached, a Thousand Times">NASA Security Breached, a Thousand Times</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/windows-hacking/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Code that Hacked Google IDs [Aurora]</title>
		<link>http://www.taranfx.com/google-hacking-aurora</link>
		<comments>http://www.taranfx.com/google-hacking-aurora#comments</comments>
		<pubDate>Sat, 16 Jan 2010 19:31:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/google-hacking-aurora</guid>
		<description><![CDATA[<p><img class="alignleft" title="Hacking" src="http://farm3.static.flickr.com/2431/3776425166_c692381bdc_o.jpg" alt="Hacking" width="218" height="154" />Chinese hackers changed the face of Internet forever by taking the wrong step &#8212; trying to <a href="www.taranfx.com/google-shutdown-china">hack the search giant and several other giants</a>.</p>
<p>Apparently, we know that hackers exploited a <a href="http://www.taranfx.com/tag/vulnerable">Vulnerability</a> in <a href="http://www.taranfx.com/tag/ie">Internet Explorer</a>, but little was known about it untill the <a href="http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js" target="_blank">code that hacked Google became public</a>.</p>
<p>So what does this code do ?</p>
<p><em>In Easy Words: </em>Basically, the script creates a blank element on the page. This element has an &#8220;address&#8221; like a house. Then the element &#8220;moves out&#8221; and something else takes up the space of the house (it might even move the house around, or be larger than the house and contain it). But the script still knows where the house was, and can put things in there and if another bit of the program happens to overlap, some code put in that place might <a href='http://www.taranfx.com/google-hacking-aurora' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesChinese Google Hacker TrackedChina Busts Black-Hawk HackersALL Windows PC Exploited by HackHow Twitter was HackedHacking the Unsecure GSM EncryptionHackers Hack Cars Remotely, disable Engines, brakesHow I would Hack your PC, Mac with USB HIDGMail gets OAuth, Secures 3rd-Party Apps AccessPwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome StandsGoogle SkipFish: Web-Application Security ScannerWindows 7 Rogue [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Hacking" src="http://farm3.static.flickr.com/2431/3776425166_c692381bdc_o.jpg" alt="Hacking" width="218" height="154" />Chinese hackers changed the face of Internet forever by taking the wrong step &#8212; trying to <a href="www.taranfx.com/google-shutdown-china">hack the search giant and several other giants</a>.</p>
<p>Apparently, we know that hackers exploited a <a href="http://www.taranfx.com/tag/vulnerable">Vulnerability</a> in <a href="http://www.taranfx.com/tag/ie">Internet Explorer</a>, but little was known about it untill the <a href="http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js" target="_blank">code that hacked Google became public</a>.</p>
<p>So what does this code do ?</p>
<p><em>In Easy Words: </em>Basically, the script creates a blank element on the page. This element has an &#8220;address&#8221; like a house. Then the element &#8220;moves out&#8221; and something else takes up the space of the house (it might even move the house around, or be larger than the house and contain it). But the script still knows where the house was, and can put things in there and if another bit of the program happens to overlap, some code put in that place might <a href='http://www.taranfx.com/google-hacking-aurora' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/google-hackers-china" title="Chinese Google Hacker Tracked">Chinese Google Hacker Tracked</a></li><li><a href="http://www.taranfx.com/china-busts-hackers" title="China Busts Black-Hawk Hackers">China Busts Black-Hawk Hackers</a></li><li><a href="http://www.taranfx.com/windows-hacking" title="ALL Windows PC Exploited by Hack">ALL Windows PC Exploited by Hack</a></li><li><a href="http://www.taranfx.com/how-twitter-was-hacked" title="How Twitter was Hacked">How Twitter was Hacked</a></li><li><a href="http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret" title="Hacking the Unsecure GSM Encryption">Hacking the Unsecure GSM Encryption</a></li><li><a href="http://www.taranfx.com/car-hacking" title="Hackers Hack Cars Remotely, disable Engines, brakes">Hackers Hack Cars Remotely, disable Engines, brakes</a></li><li><a href="http://www.taranfx.com/pc-mac-usb-hid-hack" title="How I would Hack your PC, Mac with USB HID">How I would Hack your PC, Mac with USB HID</a></li><li><a href="http://www.taranfx.com/gmail-oauth-3rd-party-apps" title="GMail gets OAuth, Secures 3rd-Party Apps Access">GMail gets OAuth, Secures 3rd-Party Apps Access</a></li><li><a href="http://www.taranfx.com/most-secure-browser" title="Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands">Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands</a></li><li><a href="http://www.taranfx.com/skipfish-web-application-security-scanner" title="Google SkipFish: Web-Application Security Scanner">Google SkipFish: Web-Application Security Scanner</a></li><li><a href="http://www.taranfx.com/windows-7-rogue-wifi" title="Windows 7 Rogue WiFi Hack">Windows 7 Rogue WiFi Hack</a></li><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/google-hacking-aurora/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How Twitter was Hacked</title>
		<link>http://www.taranfx.com/how-twitter-was-hacked</link>
		<comments>http://www.taranfx.com/how-twitter-was-hacked#comments</comments>
		<pubDate>Fri, 18 Dec 2009 21:04:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/how-twitter-was-hacked</guid>
		<description><![CDATA[<p><img class="alignleft" title="Twitter hacked" src="http://www.thetechherald.com/media/images/200951/Twittwe_hijack_top.jpg" alt="" width="252" height="168" />Internet faced World Wide Panic as Twitter.com was defaced to run out of service. Soon after the attack Users were able to see a page that claimed work of &#8220;Iranian Cyber Hackers&#8221;.</p>
<p>In simple words, it was nothing but a DNS hijacking attack in which Twitter&#8217;s DNS records were altered. That means  surfers trying to reach the website directly via name resolution  services were redirected to a fake domain, while the Twitter servers were running. As a result,  applications that depended upon <a href="http://www.taranfx.com/blog/tag/twitter">Twitter&#8217;s </a><a href="http://www.taranfx.com/blog/tag/api">API </a>- such  as TweetDeck or<a href="http://www.taranfx.com/blog/tag/mobile"> mobile phone</a> <a href="http://www.taranfx.com/blog/tag/apps">apps </a>- were unaffected by the attack. Hence, Twitter servers were never <a href="http://www.taranfx.com/blog/tag/hacking">hacked</a>!</p>
<p>Rik Ferguson, a security consultant at Trend Micro, explains that  this type of DNS hijacking usually involves compromising the systems at  the registrar responsible <a href='http://www.taranfx.com/how-twitter-was-hacked' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesALL Windows PC Exploited by HackCode that Hacked Google IDs [Aurora]Hacking the Unsecure GSM EncryptionHackers Hack Cars Remotely, disable Engines, brakesHow I would Hack your PC, Mac with USB HIDPwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome StandsChinese Google Hacker TrackedWindows 7 Rogue WiFi HackChina Busts Black-Hawk HackersIE Flaw Makes local Files PublicSecure iPhone [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Twitter hacked" src="http://www.thetechherald.com/media/images/200951/Twittwe_hijack_top.jpg" alt="" width="252" height="168" />Internet faced World Wide Panic as Twitter.com was defaced to run out of service. Soon after the attack Users were able to see a page that claimed work of &#8220;Iranian Cyber Hackers&#8221;.</p>
<p>In simple words, it was nothing but a DNS hijacking attack in which Twitter&#8217;s DNS records were altered. That means  surfers trying to reach the website directly via name resolution  services were redirected to a fake domain, while the Twitter servers were running. As a result,  applications that depended upon <a href="http://www.taranfx.com/blog/tag/twitter">Twitter&#8217;s </a><a href="http://www.taranfx.com/blog/tag/api">API </a>- such  as TweetDeck or<a href="http://www.taranfx.com/blog/tag/mobile"> mobile phone</a> <a href="http://www.taranfx.com/blog/tag/apps">apps </a>- were unaffected by the attack. Hence, Twitter servers were never <a href="http://www.taranfx.com/blog/tag/hacking">hacked</a>!</p>
<p>Rik Ferguson, a security consultant at Trend Micro, explains that  this type of DNS hijacking usually involves compromising the systems at  the registrar responsible <a href='http://www.taranfx.com/how-twitter-was-hacked' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/windows-hacking" title="ALL Windows PC Exploited by Hack">ALL Windows PC Exploited by Hack</a></li><li><a href="http://www.taranfx.com/google-hacking-aurora" title="Code that Hacked Google IDs [Aurora]">Code that Hacked Google IDs [Aurora]</a></li><li><a href="http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret" title="Hacking the Unsecure GSM Encryption">Hacking the Unsecure GSM Encryption</a></li><li><a href="http://www.taranfx.com/car-hacking" title="Hackers Hack Cars Remotely, disable Engines, brakes">Hackers Hack Cars Remotely, disable Engines, brakes</a></li><li><a href="http://www.taranfx.com/pc-mac-usb-hid-hack" title="How I would Hack your PC, Mac with USB HID">How I would Hack your PC, Mac with USB HID</a></li><li><a href="http://www.taranfx.com/most-secure-browser" title="Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands">Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands</a></li><li><a href="http://www.taranfx.com/google-hackers-china" title="Chinese Google Hacker Tracked">Chinese Google Hacker Tracked</a></li><li><a href="http://www.taranfx.com/windows-7-rogue-wifi" title="Windows 7 Rogue WiFi Hack">Windows 7 Rogue WiFi Hack</a></li><li><a href="http://www.taranfx.com/china-busts-hackers" title="China Busts Black-Hawk Hackers">China Busts Black-Hawk Hackers</a></li><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li><li><a href="http://www.taranfx.com/change-iphone-ssh-password" title="Secure iPhone from Hacking">Secure iPhone from Hacking</a></li><li><a href="http://www.taranfx.com/nasa-security-breached-thousand-times" title="NASA Security Breached, a Thousand Times">NASA Security Breached, a Thousand Times</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/how-twitter-was-hacked/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerabilities in HTML 5 and Future</title>
		<link>http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps</link>
		<comments>http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps#comments</comments>
		<pubDate>Sun, 13 Sep 2009 09:34:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[HTML 5]]></category>
		<category><![CDATA[Web languages]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[vulnerable]]></category>
		<category><![CDATA[web standard]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1902</guid>
		<description><![CDATA[<p><img class="alignleft" src="http://farm3.static.flickr.com/2477/3915246870_0fbc0277af.jpg" alt="" width="202" height="350" />HTML 5 comes with alot of promise for the web.  It has <a href="http://www.taranfx.com/blog/?p=1212" target="_blank">lot of new features</a> that could make Web Browsers and Apps much more powerful than they ever were.</p>
<p>Let&#8217;s go by an example. Try accessing <a href="http://www.taranfx.com/blog/?tag=gmail" target="_blank">Gmail </a>on <a href="http://www.taranfx.com/blog/?tag=iphone" target="_blank">iPhone </a>or <a href="http://www.taranfx.com/blog/?tag=android" target="_blank">Android </a> phone,  you will have notice some differences from what it used to be a month ago. The new thing worth noticing is the introduction of the <em>offline access</em>.</p>
<p><a href="http://www.taranfx.com/blog/what-made-gmail-go-down-google-explains" target="_blank">Gmail went down, offline</a> in September, but credits to Gears, Gmail was still up and running with select Browsers. On the other side, iPhone Safari doesn&#8217;t have a Gears plugin, so how was it still running?</p>
<p>The answer lies with the <a href="http://www.taranfx.com/blog/?p=1212" target="_blank">HTML 5</a> standard, more <a href='http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesIE Flaw Makes local Files PublicHTML5 Client-side Local StorageREST vs. SOAP &#8211; The Right WebServiceHTML 5 drops most awaited open source Video codec170M Downloadable Facebook Profiles, Privacy #FAILFacebook bug lets Hackers delete User&#8217;s FriendlistHow I would Hack your PC, Mac with USB HIDReverse Phone Lookup &#8211; Weapon of Choice for Unsolicited CallsBrowser Fingerprinting: Privacy [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://farm3.static.flickr.com/2477/3915246870_0fbc0277af.jpg" alt="" width="202" height="350" />HTML 5 comes with alot of promise for the web.  It has <a href="http://www.taranfx.com/blog/?p=1212" target="_blank">lot of new features</a> that could make Web Browsers and Apps much more powerful than they ever were.</p>
<p>Let&#8217;s go by an example. Try accessing <a href="http://www.taranfx.com/blog/?tag=gmail" target="_blank">Gmail </a>on <a href="http://www.taranfx.com/blog/?tag=iphone" target="_blank">iPhone </a>or <a href="http://www.taranfx.com/blog/?tag=android" target="_blank">Android </a> phone,  you will have notice some differences from what it used to be a month ago. The new thing worth noticing is the introduction of the <em>offline access</em>.</p>
<p><a href="http://www.taranfx.com/blog/what-made-gmail-go-down-google-explains" target="_blank">Gmail went down, offline</a> in September, but credits to Gears, Gmail was still up and running with select Browsers. On the other side, iPhone Safari doesn&#8217;t have a Gears plugin, so how was it still running?</p>
<p>The answer lies with the <a href="http://www.taranfx.com/blog/?p=1212" target="_blank">HTML 5</a> standard, more <a href='http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li><li><a href="http://www.taranfx.com/html-5-client-storage" title="HTML5 Client-side Local Storage">HTML5 Client-side Local Storage</a></li><li><a href="http://www.taranfx.com/rest-vs-soap-using-http-choosing-the-right-webservice-protocol" title="REST vs. SOAP &#8211; The Right WebService">REST vs. SOAP &#8211; The Right WebService</a></li><li><a href="http://www.taranfx.com/html-5-drops-most-awaited-open-source-video-codec" title="HTML 5 drops most awaited open source Video codec">HTML 5 drops most awaited open source Video codec</a></li><li><a href="http://www.taranfx.com/download-facebook-profiles" title="170M Downloadable Facebook Profiles, Privacy #FAIL">170M Downloadable Facebook Profiles, Privacy #FAIL</a></li><li><a href="http://www.taranfx.com/facebook-hack" title="Facebook bug lets Hackers delete User&#8217;s Friendlist">Facebook bug lets Hackers delete User&#8217;s Friendlist</a></li><li><a href="http://www.taranfx.com/pc-mac-usb-hid-hack" title="How I would Hack your PC, Mac with USB HID">How I would Hack your PC, Mac with USB HID</a></li><li><a href="http://www.taranfx.com/reverse-phone-lookup" title="Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls">Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls</a></li><li><a href="http://www.taranfx.com/browser-fingerprinting" title="Browser Fingerprinting: Privacy is a Myth">Browser Fingerprinting: Privacy is a Myth</a></li><li><a href="http://www.taranfx.com/gmail-simultaneous-logins" title="GMail now Warns for Simultaneous Logins">GMail now Warns for Simultaneous Logins</a></li><li><a href="http://www.taranfx.com/html5-video-player-code" title="Html5 Video Player that works on All Browsers, compatible with Flash">Html5 Video Player that works on All Browsers, compatible with Flash</a></li><li><a href="http://www.taranfx.com/edit-test-javascript-css-online" title="Edit, Test JavaScript, CSS, HTML Online">Edit, Test JavaScript, CSS, HTML Online</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/pros-cons-of-html-5-local-database-storage-and-future-of-web-apps/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hacking the Unsecure GSM Encryption</title>
		<link>http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret</link>
		<comments>http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret#comments</comments>
		<pubDate>Fri, 28 Aug 2009 09:19:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1752</guid>
		<description><![CDATA[<p><img class="alignleft" src="http://adventuresinsecurity.com/images/GSM_monitor.jpg" alt="" width="244" height="183" />Sometimes its ridiculous how the most common (and important) technology in our daily-life is vulnerable to kinds of attacks that could bring nightmares. Still, no one is aware, no one is doing anything. Such is the Case of Today&#8217;s GSM &#8212; The most popular Cellphone Technology.</p>
<p>Every year, some hacker comes out and breaks something crucial to us, which makes us and authorities learn it the HARD WAY, &#8220;We are not safe&#8221;.</p>
<p>The best work is done by <a href="http://www.taranfx.com/blog/?tag=blackhat" target="_blank">BlackHat </a>and <a href="http://www.taranfx.com/blog/?tag=defcon" target="_blank">DEFCON</a>, which are open forums for Hackers, especially DEFCON, which has open hacking challenges.</p>
<p>If you ever went to the DEFCONs, you know what I&#8217;m talking about. These guys can take down a military of servers down in couple of hours. They can hack anything from a conventional &#8220;lock&#8221; to GSM phones.</p>
<p>This year was no exception. <a href="http://www.cs.virginia.edu/~kn5f/" target="_blank">Karsten Nohl</a>,  a PhD candidate from the University of Virginia gave <a href='http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesALL Windows PC Exploited by HackCode that Hacked Google IDs [Aurora]How Twitter was HackediPhone SMS Hack Fix via Firmware UpdateHackers Hack Cars Remotely, disable Engines, brakesHow I would Hack your PC, Mac with USB HIDReverse Phone Lookup &#8211; Weapon of Choice for Unsolicited CallsPwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome StandsChinese Google Hacker [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://adventuresinsecurity.com/images/GSM_monitor.jpg" alt="" width="244" height="183" />Sometimes its ridiculous how the most common (and important) technology in our daily-life is vulnerable to kinds of attacks that could bring nightmares. Still, no one is aware, no one is doing anything. Such is the Case of Today&#8217;s GSM &#8212; The most popular Cellphone Technology.</p>
<p>Every year, some hacker comes out and breaks something crucial to us, which makes us and authorities learn it the HARD WAY, &#8220;We are not safe&#8221;.</p>
<p>The best work is done by <a href="http://www.taranfx.com/blog/?tag=blackhat" target="_blank">BlackHat </a>and <a href="http://www.taranfx.com/blog/?tag=defcon" target="_blank">DEFCON</a>, which are open forums for Hackers, especially DEFCON, which has open hacking challenges.</p>
<p>If you ever went to the DEFCONs, you know what I&#8217;m talking about. These guys can take down a military of servers down in couple of hours. They can hack anything from a conventional &#8220;lock&#8221; to GSM phones.</p>
<p>This year was no exception. <a href="http://www.cs.virginia.edu/~kn5f/" target="_blank">Karsten Nohl</a>,  a PhD candidate from the University of Virginia gave <a href='http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/windows-hacking" title="ALL Windows PC Exploited by Hack">ALL Windows PC Exploited by Hack</a></li><li><a href="http://www.taranfx.com/google-hacking-aurora" title="Code that Hacked Google IDs [Aurora]">Code that Hacked Google IDs [Aurora]</a></li><li><a href="http://www.taranfx.com/how-twitter-was-hacked" title="How Twitter was Hacked">How Twitter was Hacked</a></li><li><a href="http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update" title="iPhone SMS Hack Fix via Firmware Update">iPhone SMS Hack Fix via Firmware Update</a></li><li><a href="http://www.taranfx.com/car-hacking" title="Hackers Hack Cars Remotely, disable Engines, brakes">Hackers Hack Cars Remotely, disable Engines, brakes</a></li><li><a href="http://www.taranfx.com/pc-mac-usb-hid-hack" title="How I would Hack your PC, Mac with USB HID">How I would Hack your PC, Mac with USB HID</a></li><li><a href="http://www.taranfx.com/reverse-phone-lookup" title="Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls">Reverse Phone Lookup &#8211; Weapon of Choice for Unsolicited Calls</a></li><li><a href="http://www.taranfx.com/most-secure-browser" title="Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands">Pwn2Own 2010 &#8211; Firefox, Safari Browsers Hacked, Chrome Stands</a></li><li><a href="http://www.taranfx.com/google-hackers-china" title="Chinese Google Hacker Tracked">Chinese Google Hacker Tracked</a></li><li><a href="http://www.taranfx.com/windows-7-rogue-wifi" title="Windows 7 Rogue WiFi Hack">Windows 7 Rogue WiFi Hack</a></li><li><a href="http://www.taranfx.com/china-busts-hackers" title="China Busts Black-Hawk Hackers">China Busts Black-Hawk Hackers</a></li><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Linux Kernel Bug, Vulnerability that went for Eight years Un-Noticed, Un-Fixed</title>
		<link>http://www.taranfx.com/the-linux-kernel-bug-vulnerability-that-went-for-eight-years-un-noticed-un-fixed</link>
		<comments>http://www.taranfx.com/the-linux-kernel-bug-vulnerability-that-went-for-eight-years-un-noticed-un-fixed#comments</comments>
		<pubDate>Sat, 15 Aug 2009 07:28:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1605</guid>
		<description><![CDATA[<p><img class="alignleft" title="linux bug" src="http://www.vinux.info/wp-content/tux-vs-msn.png" alt="" width="150" height="180" />Sometimes, we overlook a critical aspect which could mean that our efforts of decade can be blasted within seconds. Such is a bug found in Linux 2.4 Kernel.</p>
<p>According to security researchers, <a href="http://www.theregister.co.uk/2009/08/14/critical_linux_bug/" target="_blank">a bug in the Linux kernel has just been uncovered</a> that makes just about <strong>every distribution utilizing kernel 2.4 and 2.6 </strong>on just about all architectures since May of 2001 vulnerable to a certain kind of attack.</p>
<p>You can imagine. Out of Today&#8217;s Linux systems, 95% use &gt;2.4 &lt;=2.6, so almst every Linux kernel is Vulnerable to this attack.</p>
<p>The bug allows an attacker to escalate local privileges and completely compromise the entire system. Julien Tinnes, a security researcher who <em>does</em> know his way around kernel code, <a href="http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html">wrote the following details about the bug</a>.</p>
<blockquote>
<div class="cquote">At first sight, the code in af_ipx.c looks correct and seems to initialize .sendpage properly. <a href='http://www.taranfx.com/the-linux-kernel-bug-vulnerability-that-went-for-eight-years-un-noticed-un-fixed' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesInstall Ubuntu on Nexus OneInstall Android, Ubuntu on HTC HD2Google Services now available from CommandLine Linux ToolUpgrade Ubuntu Karmic 9.1 to Lucid 10.04Ubuntu 10.04 Lucid Lynx is here [Features]Sony Removes Linux Support from PS3 PhatUbuntu 10.04 Lucid Lynx Beta [UI, Video]Sync iPhone in Linux [Ubuntu]IE Flaw Makes local Files PublicALL Windows PC Exploited by [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="linux bug" src="http://www.vinux.info/wp-content/tux-vs-msn.png" alt="" width="150" height="180" />Sometimes, we overlook a critical aspect which could mean that our efforts of decade can be blasted within seconds. Such is a bug found in Linux 2.4 Kernel.</p>
<p>According to security researchers, <a href="http://www.theregister.co.uk/2009/08/14/critical_linux_bug/" target="_blank">a bug in the Linux kernel has just been uncovered</a> that makes just about <strong>every distribution utilizing kernel 2.4 and 2.6 </strong>on just about all architectures since May of 2001 vulnerable to a certain kind of attack.</p>
<p>You can imagine. Out of Today&#8217;s Linux systems, 95% use &gt;2.4 &lt;=2.6, so almst every Linux kernel is Vulnerable to this attack.</p>
<p>The bug allows an attacker to escalate local privileges and completely compromise the entire system. Julien Tinnes, a security researcher who <em>does</em> know his way around kernel code, <a href="http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html">wrote the following details about the bug</a>.</p>
<blockquote>
<div class="cquote">At first sight, the code in af_ipx.c looks correct and seems to initialize .sendpage properly. <a href='http://www.taranfx.com/the-linux-kernel-bug-vulnerability-that-went-for-eight-years-un-noticed-un-fixed' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/install-ubuntu-on-nexus-one" title="Install Ubuntu on Nexus One">Install Ubuntu on Nexus One</a></li><li><a href="http://www.taranfx.com/install-android-ubuntu-on-htc-hd2" title="Install Android, Ubuntu on HTC HD2">Install Android, Ubuntu on HTC HD2</a></li><li><a href="http://www.taranfx.com/google-commandline-linux-tool" title="Google Services now available from CommandLine Linux Tool">Google Services now available from CommandLine Linux Tool</a></li><li><a href="http://www.taranfx.com/upgrade-ubuntu-karmic-to-lucid" title="Upgrade Ubuntu Karmic 9.1 to Lucid 10.04">Upgrade Ubuntu Karmic 9.1 to Lucid 10.04</a></li><li><a href="http://www.taranfx.com/ubuntu-10-04-lucid-lynx-features" title="Ubuntu 10.04 Lucid Lynx is here [Features]">Ubuntu 10.04 Lucid Lynx is here [Features]</a></li><li><a href="http://www.taranfx.com/ps3-linux-support" title="Sony Removes Linux Support from PS3 Phat">Sony Removes Linux Support from PS3 Phat</a></li><li><a href="http://www.taranfx.com/ubuntu-10-04-lucid-lynx" title="Ubuntu 10.04 Lucid Lynx Beta [UI, Video]">Ubuntu 10.04 Lucid Lynx Beta [UI, Video]</a></li><li><a href="http://www.taranfx.com/sync-iphone-linux" title="Sync iPhone in Linux [Ubuntu]">Sync iPhone in Linux [Ubuntu]</a></li><li><a href="http://www.taranfx.com/ie-flaw-public-files" title="IE Flaw Makes local Files Public">IE Flaw Makes local Files Public</a></li><li><a href="http://www.taranfx.com/windows-hacking" title="ALL Windows PC Exploited by Hack">ALL Windows PC Exploited by Hack</a></li><li><a href="http://www.taranfx.com/google-hacking-aurora" title="Code that Hacked Google IDs [Aurora]">Code that Hacked Google IDs [Aurora]</a></li><li><a href="http://www.taranfx.com/google-ext4" title="Google upgrades to EXT4 FileSystem">Google upgrades to EXT4 FileSystem</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/the-linux-kernel-bug-vulnerability-that-went-for-eight-years-un-noticed-un-fixed/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BGP 4byte ASN Vulnerable to DoS on Cisco IOS, IOS XE &#8211; Fix Released</title>
		<link>http://www.taranfx.com/bgp-4byte-asn-vulnerable-to-dos-on-cisco-ios-ios-xe-fix-released</link>
		<comments>http://www.taranfx.com/bgp-4byte-asn-vulnerable-to-dos-on-cisco-ios-ios-xe-fix-released#comments</comments>
		<pubDate>Tue, 04 Aug 2009 20:53:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cisco]]></category>
		<category><![CDATA[IOS]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1542</guid>
		<description><![CDATA[<p><img class="alignleft" src="http://www.techshout.com/images/cisco-logo-patches.jpg" alt="" width="192" height="192" />4byte ASN (autonomous system numbers) was incorporated into most BGP routers recently. Since we are running out of ASN no. given to service providers, authority have stopped using previous Internet 2byte BGP ASN routing Updates.</p>
<p>The newly found vulnerabilities affect only devices running Cisco IOS and Cisco 	 IOS XE Software (here after both referred to as simply Cisco IOS) with support 	 for RFC4893 and that have been configured for BGP routing.</p>
<p>This feature has a critical vulnerability on all recent IOS that support it. Cisco last week issued &#8212; and today updated &#8212; a <a href="http://www.cisco.com/warp/public/707/cisco-sa-20090729-bgp.shtml" target="_blank">security advisory</a> for its IOS software.</p>
<p>Cisco IOS supporting RFC 4893 for four octet AS number spaces in BGP are susceptible to <a href="http://www.taranfx.com/blog/?tag=dos" target="_blank">denial of service</a> attacks when handling BGP updates. There are two <a href="http://www.taranfx.com/blog/?tag=dos+ddos" target="_blank">DoS vulnerabilities</a> in the software, according to the advisory:</p>
<p>1. Vulnerability <a href='http://www.taranfx.com/bgp-4byte-asn-vulnerable-to-dos-on-cisco-ios-ios-xe-fix-released' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesArista Networks EOS (Highly Modular)Did Cisco copy JUNOS to make IOS XE?Did Cisco copy JUNOS to make IOS XE?Cisco CRS-3 Boosts Internet Backbone Speeds to 322 TerabitsCisco targets Mobile Internet, acquires StarentCisco could become 4G Leader: WiMax and Now LTECisco, VMWare create &#8220;Disaster Avoidance&#8221; VMotion over Long DistanceNew Approach to Detect and Tackle Network [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://www.techshout.com/images/cisco-logo-patches.jpg" alt="" width="192" height="192" />4byte ASN (autonomous system numbers) was incorporated into most BGP routers recently. Since we are running out of ASN no. given to service providers, authority have stopped using previous Internet 2byte BGP ASN routing Updates.</p>
<p>The newly found vulnerabilities affect only devices running Cisco IOS and Cisco 	 IOS XE Software (here after both referred to as simply Cisco IOS) with support 	 for RFC4893 and that have been configured for BGP routing.</p>
<p>This feature has a critical vulnerability on all recent IOS that support it. Cisco last week issued &#8212; and today updated &#8212; a <a href="http://www.cisco.com/warp/public/707/cisco-sa-20090729-bgp.shtml" target="_blank">security advisory</a> for its IOS software.</p>
<p>Cisco IOS supporting RFC 4893 for four octet AS number spaces in BGP are susceptible to <a href="http://www.taranfx.com/blog/?tag=dos" target="_blank">denial of service</a> attacks when handling BGP updates. There are two <a href="http://www.taranfx.com/blog/?tag=dos+ddos" target="_blank">DoS vulnerabilities</a> in the software, according to the advisory:</p>
<p>1. Vulnerability <a href='http://www.taranfx.com/bgp-4byte-asn-vulnerable-to-dos-on-cisco-ios-ios-xe-fix-released' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/arista-networks-eos-highly-modular" title="Arista Networks EOS (Highly Modular)">Arista Networks EOS (Highly Modular)</a></li><li><a href="http://www.taranfx.com/929-revision-2" title="Did Cisco copy JUNOS to make IOS XE?">Did Cisco copy JUNOS to make IOS XE?</a></li><li><a href="http://www.taranfx.com/did-cisco-copy-junos-to-make-ios-xe" title="Did Cisco copy JUNOS to make IOS XE?">Did Cisco copy JUNOS to make IOS XE?</a></li><li><a href="http://www.taranfx.com/cisco-crs-3" title="Cisco CRS-3 Boosts Internet Backbone Speeds to 322 Terabits">Cisco CRS-3 Boosts Internet Backbone Speeds to 322 Terabits</a></li><li><a href="http://www.taranfx.com/cisco-targets-mobile-internet-acquires-starent" title="Cisco targets Mobile Internet, acquires Starent">Cisco targets Mobile Internet, acquires Starent</a></li><li><a href="http://www.taranfx.com/cisco-could-become-4g-leader-wimax-and-now-lte" title="Cisco could become 4G Leader: WiMax and Now LTE">Cisco could become 4G Leader: WiMax and Now LTE</a></li><li><a href="http://www.taranfx.com/cisco-vmware-create-disaster-avoidance-vmotion-over-long-distance" title="Cisco, VMWare create &#8220;Disaster Avoidance&#8221; VMotion over Long Distance">Cisco, VMWare create &#8220;Disaster Avoidance&#8221; VMotion over Long Distance</a></li><li><a href="http://www.taranfx.com/new-approach-to-detect-and-tackle-network-latency-issues-effectively" title="New Approach to Detect and Tackle Network Latency Issues Effectively">New Approach to Detect and Tackle Network Latency Issues Effectively</a></li><li><a href="http://www.taranfx.com/cisco-ios-jumble-how-easy-is-it-for-cisco-and-customers" title="Cisco and IOS jumble. How easy is it for Cisco and Customers?">Cisco and IOS jumble. How easy is it for Cisco and Customers?</a></li><li><a href="http://www.taranfx.com/cisco-crs-1-celebrates-5years" title="Cisco CRS-1 celebrates 5years">Cisco CRS-1 celebrates 5years</a></li><li><a href="http://www.taranfx.com/juniper-ex8216-is-a-cloud-switch-delivers-124-terabits" title="Juniper EX8216 is a Cloud switch, Delivers 12.4 Terabits">Juniper EX8216 is a Cloud switch, Delivers 12.4 Terabits</a></li><li><a href="http://www.taranfx.com/routing-for-the-future-cisco-asr-running-ios-xe" title="Routing for the future: Cisco ASR IOS XE">Routing for the future: Cisco ASR IOS XE</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/bgp-4byte-asn-vulnerable-to-dos-on-cisco-ios-ios-xe-fix-released/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone SMS Hack Fix via Firmware Update</title>
		<link>http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update</link>
		<comments>http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update#comments</comments>
		<pubDate>Fri, 31 Jul 2009 15:47:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[iPhone News, Jailbreak, Unlock Guides, Hacks]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1505</guid>
		<description><![CDATA[<div>
<p><img class="alignleft" src="http://www.unlockappleiphone.com/iphone-hack-apps-games.jpg" alt="" width="168" height="126" />Apple had been silent on the Critical Vulnerability <a href="http://www.taranfx.com/blog/?p=1503" target="_blank">found by BlackHat&#8217;s security expert presenter, till Google went ahead with the similar fix for the Android</a> platform.</p>
<p>I haven&#8217;t heard the official news coming directly Apple, but Carriers are doing it. First one to do is O2 UK, which announced that Apple will be releasing fix by weekend. <img src='http://www.taranfx.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>There&#8217;s no news from AT&amp;T yet, but they are not far from.</p>
<p>It&#8217;s an admirably quick fix to a comically terrible problem. Probably, it will come as 3.0.1 or something similar. But at least Apple&#8217;s got an update infrastructure to match their relatively quick remedy; what&#8217;s really worrying is that some other vulnerable phones—mostly Windows Mobile handsets—are still vulnerable, and whatever updates Microsoft have in store may have a slightly harder time blanketing users without the near-daily update checking built into the <a href='http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesiPhone and Android SMS HacksHacking the Unsecure GSM EncryptionAndroid 2.2 Froyo Open SourcediOS 4 vs Android 2.2 &#8211; War is OveriPhone 4 vs. Motorola Droid XInstall Android 2.2 Froyo on iPhoneiPhone 4 vs Android Evo 4G vs Incredible vs Nexus OneiPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;HowTo: Install Android on iPhone 3G, [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><img class="alignleft" src="http://www.unlockappleiphone.com/iphone-hack-apps-games.jpg" alt="" width="168" height="126" />Apple had been silent on the Critical Vulnerability <a href="http://www.taranfx.com/blog/?p=1503" target="_blank">found by BlackHat&#8217;s security expert presenter, till Google went ahead with the similar fix for the Android</a> platform.</p>
<p>I haven&#8217;t heard the official news coming directly Apple, but Carriers are doing it. First one to do is O2 UK, which announced that Apple will be releasing fix by weekend. <img src='http://www.taranfx.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>There&#8217;s no news from AT&amp;T yet, but they are not far from.</p>
<p>It&#8217;s an admirably quick fix to a comically terrible problem. Probably, it will come as 3.0.1 or something similar. But at least Apple&#8217;s got an update infrastructure to match their relatively quick remedy; what&#8217;s really worrying is that some other vulnerable phones—mostly Windows Mobile handsets—are still vulnerable, and whatever updates Microsoft have in store may have a slightly harder time blanketing users without the near-daily update checking built into the <a href='http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat" title="iPhone and Android SMS Hacks">iPhone and Android SMS Hacks</a></li><li><a href="http://www.taranfx.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret" title="Hacking the Unsecure GSM Encryption">Hacking the Unsecure GSM Encryption</a></li><li><a href="http://www.taranfx.com/android-2-2-froyo-open-sourced" title="Android 2.2 Froyo Open Sourced">Android 2.2 Froyo Open Sourced</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-android-2-2" title="iOS 4 vs Android 2.2 &#8211; War is Over">iOS 4 vs Android 2.2 &#8211; War is Over</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-droid-x" title="iPhone 4 vs. Motorola Droid X">iPhone 4 vs. Motorola Droid X</a></li><li><a href="http://www.taranfx.com/install-android-2-2-froyo-on-iphone" title="Install Android 2.2 Froyo on iPhone">Install Android 2.2 Froyo on iPhone</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-android-evo-4g-vs-incredible-vs-nexus-one" title="iPhone 4 vs Android Evo 4G vs Incredible vs Nexus One">iPhone 4 vs Android Evo 4G vs Incredible vs Nexus One</a></li><li><a href="http://www.taranfx.com/iphone-hd4g-vs-android-froyo" title="iPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;">iPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;</a></li><li><a href="http://www.taranfx.com/howto-install-android-on-iphone-3g-2g" title="HowTo: Install Android on iPhone 3G, 2G">HowTo: Install Android on iPhone 3G, 2G</a></li><li><a href="http://www.taranfx.com/facebook-hack" title="Facebook bug lets Hackers delete User&#8217;s Friendlist">Facebook bug lets Hackers delete User&#8217;s Friendlist</a></li><li><a href="http://www.taranfx.com/android-on-iphone-3g" title="Android on iPhone 3G">Android on iPhone 3G</a></li><li><a href="http://www.taranfx.com/android-on-iphone" title="Install Android on iPhone">Install Android on iPhone</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone and Android SMS Hacks</title>
		<link>http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat</link>
		<comments>http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat#comments</comments>
		<pubDate>Thu, 30 Jul 2009 15:59:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[iPhone News, Jailbreak, Unlock Guides, Hacks]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.taranfx.com/blog/?p=1503</guid>
		<description><![CDATA[<p><img class="alignleft" src="http://static.arstechnica.com/iphone/iphone3g_blackhat_exploit.png" alt="" width="300" height="169" />BlackHat is a yearly security conference where Industry&#8217;s most Dark side secrets are revealed.</p>
<p>Few years back, Sir Lenin identified a Cisco security flaw that could bring down EVERY SINGLE CISCO ROUTER in the world. Lenin was from ISS (Internet Security Systems), he was fired &amp; tortured, and what not. Cisco, at no cost, wanted their secrets to be revealed. Well, that was years back. since that year, we have more darker sides of the IT world.</p>
<div class="storyDekFull">This year, Security researchers have identified several SMS vulnerabilities that can be used to deny service to mobile phones. They&#8217;re presenting Today but their findings have been published.</div>
<div class="storyDekFull">
<div class="storyDekFull"><strong>Detail</strong></div>
<p>A serious security flaw that could allow a remote attacker to take control of the victim’s iPhone by sending a specially constructed SMS message. The vulnerability might be publicly demonstrated and explained <a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-schedule.html" target="_blank">as per the schedule here </a> <a href='http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat' rel="nofollow">.. <b>Read Further &raquo; </b></a></p>Related StoriesiPhone SMS Hack Fix via Firmware UpdateiOS 4 vs Android 2.2 &#8211; War is OveriPhone 4 vs. Motorola Droid XInstall Android 2.2 Froyo on iPhoneiPhone 4 vs Android Evo 4G vs Incredible vs Nexus OneiPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;HowTo: Install Android on iPhone 3G, 2GAndroid on iPhone 3GInstall Android on [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://static.arstechnica.com/iphone/iphone3g_blackhat_exploit.png" alt="" width="300" height="169" />BlackHat is a yearly security conference where Industry&#8217;s most Dark side secrets are revealed.</p>
<p>Few years back, Sir Lenin identified a Cisco security flaw that could bring down EVERY SINGLE CISCO ROUTER in the world. Lenin was from ISS (Internet Security Systems), he was fired &amp; tortured, and what not. Cisco, at no cost, wanted their secrets to be revealed. Well, that was years back. since that year, we have more darker sides of the IT world.</p>
<div class="storyDekFull">This year, Security researchers have identified several SMS vulnerabilities that can be used to deny service to mobile phones. They&#8217;re presenting Today but their findings have been published.</div>
<div class="storyDekFull">
<div class="storyDekFull"><strong>Detail</strong></div>
<p>A serious security flaw that could allow a remote attacker to take control of the victim’s iPhone by sending a specially constructed SMS message. The vulnerability might be publicly demonstrated and explained <a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-schedule.html" target="_blank">as per the schedule here </a> <a href='http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat' rel="nofollow">.. <b>Read Further &raquo; </b></a></p><h3  class="related_post_title">Related Stories</h3><ul class="related_post"><li><a href="http://www.taranfx.com/iphone-sms-hack-fix-available-this-weekend-via-firmware-update" title="iPhone SMS Hack Fix via Firmware Update">iPhone SMS Hack Fix via Firmware Update</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-android-2-2" title="iOS 4 vs Android 2.2 &#8211; War is Over">iOS 4 vs Android 2.2 &#8211; War is Over</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-droid-x" title="iPhone 4 vs. Motorola Droid X">iPhone 4 vs. Motorola Droid X</a></li><li><a href="http://www.taranfx.com/install-android-2-2-froyo-on-iphone" title="Install Android 2.2 Froyo on iPhone">Install Android 2.2 Froyo on iPhone</a></li><li><a href="http://www.taranfx.com/iphone-4-vs-android-evo-4g-vs-incredible-vs-nexus-one" title="iPhone 4 vs Android Evo 4G vs Incredible vs Nexus One">iPhone 4 vs Android Evo 4G vs Incredible vs Nexus One</a></li><li><a href="http://www.taranfx.com/iphone-hd4g-vs-android-froyo" title="iPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;">iPhone HD/4G vs Android, Steve: &#8216;You Won&#8217;t be Disappointed&#8217;</a></li><li><a href="http://www.taranfx.com/howto-install-android-on-iphone-3g-2g" title="HowTo: Install Android on iPhone 3G, 2G">HowTo: Install Android on iPhone 3G, 2G</a></li><li><a href="http://www.taranfx.com/android-on-iphone-3g" title="Android on iPhone 3G">Android on iPhone 3G</a></li><li><a href="http://www.taranfx.com/android-on-iphone" title="Install Android on iPhone">Install Android on iPhone</a></li><li><a href="http://www.taranfx.com/adobe-iphone-android" title="Adobe ditches iPhone, Bets on Android">Adobe ditches iPhone, Bets on Android</a></li><li><a href="http://www.taranfx.com/silverlight-iphone-android" title="Open Source Silverlight Coming to iPhone, Android">Open Source Silverlight Coming to iPhone, Android</a></li><li><a href="http://www.taranfx.com/apple-iphone-patent-htc-android" title="Apple&#8217;s 20 Patent Claims Could Mean Android Ban">Apple&#8217;s 20 Patent Claims Could Mean Android Ban</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.taranfx.com/iphone-and-android-sms-hack-highlights-at-blackhat/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
