User-Agent: *
Allow: /

Custom Search
Tampilkan postingan dengan label Downloads. Tampilkan semua postingan
Tampilkan postingan dengan label Downloads. Tampilkan semua postingan

Kamis, 08 Januari 2009

Top 10 security predictions for 2009 Part. 2

By Asavin Wattanajantra

More legitimate website hacking

It arose as a big problem in 2008 and is sure to continue next year, as criminals realise that hacking a legitimate website is a great way to persuade users to click and downloads malicious files.

Many users are still unfamiliar with web-based malware and 2009 could a boom year as cybercriminals look to capitalise on this ignorance. It is a very recent evolution to exploit flaws in browsers and web servers, and new toolkits are now constantly being made to take advantage.


The fact that these toolkits often don’t need users to have a great technical knowledge lowers the barrier for entry for cybercriminals and pushes the threat level even higher than before.

Unemployment creates more cybercriminals

The credit crunch will affect the security landscape in a number of ways. One of the scariest prospects is that the economic downturn will make it tempting for unemployed IT workers to use their technical knowledge to commit internet crime.

It’s a very lucrative business - and as mentioned before - the growth of malware-as-a-service will make it very easy for people to make money on the web, even if they lack the right technical knowledge.

It could also be a problem in developing countries, as the lack of IT jobs could force qualified and skilled technical workers into the arms of criminal gangs, who will exploit their skills in aid of making money over the web.

Security budgets unlikely to grow

Although the threats keep multiplying, most would agree that in the current economic climate, budgets are unlikely to grow significantly.

This means that there will be more consolidation in the security field and means that instead of multiple boxes carrying out single functions, it will be consolidated into single boxes.

In 2008 this has already been happening, but with budgetary pressures there is no doubt this will accelerate.

It will also be interesting to see how the new focus on data security will affect the way businesses work, and whether there will be a change of focus in security to securing the data, rather than protecting the network.

Mobile computing hacks

The growth in popularity of smartphones will make them a bigger target to criminals as they will not have the security protection that PCs have had for years.

Applications and associated data will be accessed from anywhere and make them a big target for hackers. IT administrators need to be on their guard as these threats will have multiple points of entry, targeting different devices and applications.

This is made even more important by the fact that the use of mobile internet will have increased significantly by the end of 2009.

The value of the data that new sophisticated phones will carry will mean that subscribers will expect mobile operators to take greater security measures to protect personal data, especially when mobile commerce takes off.

The new generation of botnets

At the end of 2008 many of the biggest botnets were taken down with the closing of the McColo server. MessageLabs predicted that these will find new hosting services in countries such as Russia or China, improving botnet technology.

A particular sophisticated type of botnet that was described takes the form of hypervisor technology, with malware existing as a virtualisation layer running directly on the hardware and incorporating key operating system calls.

The “real” operating system remains unaware of the existence of underlying malware controlling the computer. Particularly technical attacks like SQL injection and cross-site scripting will also continue, and become more commonplace in 2009.

Cyber hacking on virtual worlds

Like social networking, hackers are likely to move away from the traditional forms of email spamming and move towards the potential goldmine of virtual worlds.

This could be gaming universes like World of Warcraft, or more social reality-based worlds like Second Life, where stolen virtual goods could be sold for real hard cash.

Users are often more relaxed about their personal details in online worlds, and this means that there could be a good opportunity for criminals to create technology which steal this data.

The increasing use of virtual worlds by businesses will also be a factor, as the value of data that these worlds will carry may grow significantly. This will make it more profitable, and therefore attract more criminals.

Reputation hijacking flourishes

The vulnerability in the design of the Domain Name System (DNS) found by Dan Kaminsky could in theory poison a server’s cache causing people sending emails or requesting a website to be given the wrong IP address.

This could mean victims are sent to a fake website which is looking for personal details, but looks perfectly real. If organised gangs manage to exploit this DNS vulnerability it could mean a whole different set of problems in 2009.

There was a multi-vendor patch deployed in August to protect servers from attack, but it has been made clear that the vulnerability had only been slowed down – not eliminated.

source : www.itpro.co.uk

Read More...

Minggu, 04 Januari 2009

What Apple Can Teach Nintendo and Sony (Part. 2)

Sony: Admit that UMDs need to be thrown down a hole with all those Betamax machines. The UMD optical drive sucks power and doesn't deliver high-capacity storage compared with what even cheap flash memory cards now offer. You're better off bundling a streamlined system with a hard drive. Want to sell people games at a store? Sell them on Memory Sticks--as you probably should've done in the first place. Or take further advantage of the online store, which has already done a bang-up job offering PSP games as digital downloads.

The PSP has had a tough fight against the Nintendo DS since its launch. That said, as a gadget-head, I love all the connectivity features that sync up the PSP with the PlayStation 3. If Sony can create more games and applications that tether the two devices together, you might still make a case for PSP owners.

Both: The best advice I can give to both Nintendo and Sony is to remember your roots. I did a story a couple months back celebrating the indie community that has rallied around the R4 cartridge as a legitimate homebrew gaming tool. That same group is always looking for new ways to mod the PSP, as well. These dedicated coders do it simply for the love of games (or to build their resume for getting into the gaming biz). Open up the doors, and let people who want to make all sorts of apps release them into the wild. You want to vet them for quality control? Go right ahead.

Way I see it, Apple has the right idea. The code is out there for people to play with, and I'm seeing tons of cool, free, and cheap applications just waiting to be downloaded. Want a taste of what's available? Read on to learn more about the best iPhone games of 2008.

Source : http://www.pcworld.com

Read More...
free counters