Palo Alto Networks: VPN-Webinterface mit überlangen Benutzernamen angreifbar

Ein Sicherheitsforscher der Heidelberger Firma ERNW hat eine Remote-Code-Execution-Lücke auf einer Palo-Alto-Appliance gefunden. Verantwortlich dafür war ein fehlender Längencheck bei der Eingabe des Benutzernamens. (Sicherheitslücke, Server)

Ein Sicherheitsforscher der Heidelberger Firma ERNW hat eine Remote-Code-Execution-Lücke auf einer Palo-Alto-Appliance gefunden. Verantwortlich dafür war ein fehlender Längencheck bei der Eingabe des Benutzernamens. (Sicherheitslücke, Server)

So about that $4 smartphone…

So about that $4 smartphone…

Indian startup Ringing Bells recently announced plans to launch a smartphone that would sell for less than $4. Not surprisingly, the company got a lot of attention for that. Also not surprisingly, a lot of people questioned whether this was possible… or if Ringing Bells was running some sort of scam. The fact that the early […]

So about that $4 smartphone… is a post from: Liliputing

So about that $4 smartphone…

Indian startup Ringing Bells recently announced plans to launch a smartphone that would sell for less than $4. Not surprisingly, the company got a lot of attention for that. Also not surprisingly, a lot of people questioned whether this was possible… or if Ringing Bells was running some sort of scam. The fact that the early […]

So about that $4 smartphone… is a post from: Liliputing

FBI cautions motorists to “maintain awareness” of automobile hacks

Bulletin speaks to the Internet of Things’ continued impact on the auto sector.

The National Highway Traffic Safety Administration and the Federal Bureau of Investigation are warning motorists to watch for signs that their vehicles may have been hacked.

"While not all hacking incidents may result in a risk to safety—such as an attacker taking control of a vehicle—it is important that consumers take appropriate steps to minimize risk," a bulletin from the agencies said. The announcement said the agencies "are warning the general public and manufacturers—of vehicles, vehicle components, and aftermarket devices—to maintain awareness of potential issues and cybersecurity threats related to connected vehicle technologies in modern vehicles."

The bulletin comes as the so-called "Internet of Things" is taking hold of the automotive sector. What's more, researchers are exposing remote vehicle exploits, and there's been high-profile vehicle recalls directly connected to hacking vulnerabilities. A video of a jeep Cherokee exploit that could affect more than a million vehicles triggered a large-scale recall of Jeep and Dodge vehicles last year. General Motors sent out an emergency update to its smartphone app that could allow hackers to unlock and start the engine of the Chevrolet Volt. BMW fixed a vulnerability where hackers could unlock doors on some 2.2 million vehicles.

Read 4 remaining paragraphs | Comments

Security: Neuer Stagefright-Exploit betrifft Millionen Android-Geräte

Stagefright bedroht viele nach wie vor ungepatchte Android-Geräte weltweit, gilt aber als schwierig auszunutzen. Eine neue Technik erfordert etwas Infrastruktur, dürfte aber größere praktische Relevanz haben. (Stagefright, Android)

Stagefright bedroht viele nach wie vor ungepatchte Android-Geräte weltweit, gilt aber als schwierig auszunutzen. Eine neue Technik erfordert etwas Infrastruktur, dürfte aber größere praktische Relevanz haben. (Stagefright, Android)

Digitalsucht im Theater: Mit Lasern gegen Smartphones

Auf Smartphones starrende Zuschauer nerven nicht nur im Kino, sondern besonders im Theater – wo sie nicht nur die anderen Zuschauer, sondern auch die Schauspieler stören. Ein Londoner Theater will Übeltäter jetzt mit Lasern an den Pranger stellen. (Smartphone, Handy)

Auf Smartphones starrende Zuschauer nerven nicht nur im Kino, sondern besonders im Theater - wo sie nicht nur die anderen Zuschauer, sondern auch die Schauspieler stören. Ein Londoner Theater will Übeltäter jetzt mit Lasern an den Pranger stellen. (Smartphone, Handy)

N. Korea launches ballistic missiles, claims miniaturized nuclear warhead

As if to seal THAAD deal, ballistic missiles flew 500 miles across Korean peninsula.

Kim Jung Un points at stuff at a nuclear missile assembly plant...or a mock-up of one. (credit: Rodong Sinmun (DPRK Party Central Committee Newspaper))

Just over a month after successfully putting a satellite into orbit, the government of the People's Democratic Republic of Korea (North Korea) claimed to have successfully built a miniaturized nuclear warhead capable of being placed on ballistic missiles. As if to add emphasis to that message, North Korea's military has gone on a missile testing binge.

On March 10, North Korea launched two "Scud" tactical ballistic missiles from North Hwanghae Province, the North Korean border region just north of Seoul, toward the Sea of Japan. Then on March 17, the North Korean military test-launched longer-ranged ballistic missiles from South Pyongan Province, near the Yellow Sea, across the Korean peninsula. The missiles flew 500 miles, again landing in the Sea of Japan. The latest launches took place early on Thursday morning local time, 20 minutes apart, according to a statement from the Republic of Korea (South Korea) joint chiefs of staff.

John Grisafi, director of intelligence for North Korean watchdog site NK News, believes the missiles launched Thursday were likely the Rodong-1 missile. “It’s beyond any known Scud variant’s range,” he said.

Read 4 remaining paragraphs | Comments

Fernsehen: Regulierung für Sendersortierung von Smart-TV und Settop-Box

Bisher ist die Reihenfolge der Veranstalter in Senderlisten in Smart-TVs und Set-Top-Boxen nicht geregelt. Die Auffindbarkeit dürfe kein eigenes Geschäftsmodell werden, fordert die Direktorenkonferenz der Landesmedienanstalten (DLM) und arbeitet an einem Gesetz dazu. (Tele Columbus, Set-Top-Box)

Bisher ist die Reihenfolge der Veranstalter in Senderlisten in Smart-TVs und Set-Top-Boxen nicht geregelt. Die Auffindbarkeit dürfe kein eigenes Geschäftsmodell werden, fordert die Direktorenkonferenz der Landesmedienanstalten (DLM) und arbeitet an einem Gesetz dazu. (Tele Columbus, Set-Top-Box)

Crossing platforms? Sony looking at “policy and business issues”

Exec says forging an Xbox Live connection “is much more complicated” than with PC

We'll stop reusing images from old PSN hacking stories when they stop being fascinating to look at.

Since Microsoft announced a new policy of cross-console openness regarding online play earlier this week, we've been stuck parsing vague statements from Sony on whether the PS4 would accept the Xbox One's metaphorically extended hand. Now, Sony Worldwide Studios head Shuhei Yoshida has offered another vague statement that suggests the possibility of a connection between PlayStation Network and Xbox Live without fully committing to anything.

In a video interview with Eurogamer, Yoshida leads off by pointing out Sony's history of allowing for cross-platform play between PlayStation systems and the PC, as in recent releases like Rocket League and Street Fighter V. From there, though, Yoshida goes on to suggest that interoperability between two competing consoles is different.

“Because PC is an open platform, it’s much more straightforward," he said. "Connecting two different closed networks is much more complicated, so we have to work with developers and publishers to understand what it is they are trying to accomplish."

Read 3 remaining paragraphs | Comments

Anti-Piracy Outfit Criticizes Authorities For Not Prosecuting Pirates

An anti-piracy group representing national and international rightsholders including Hollywood and the major labels has openly criticized authorities in Denmark over piracy. Despite being assured that these offenses would be dealt with as a priority, few results have been forthcoming, Rights Alliance says.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

piratekayIt’s hard to believe but it was more than eight years ago when a court in Denmark ordered a local Internet service provider to begin blocking The Pirate Bay.

The court found that ISP Tele2 had assisted in the file-sharing infringements of its customers, a decision that put Denmark on the map as the first European country to block the notorious site.

Since then most of the major torrent and streaming sites have also been blocked in Denmark but piracy has continued, much to the disappointment of rights holders.

Services like Popcorn Time haven’t improved the situation either, so it came as little surprise that users of the application were eventually targeted by trolls through the Danish legal system. Shortly after though, the state itself got tough, arresting the operators of two sites which allegedly spread information about the popular application.

In December, Denmark’s largest torrent site shutdown too, but that doesn’t appear to have had much of an effect either.

So for Rights Alliance, the anti-piracy outfit that counts all the big Hollywood studios and record labels among its members, much more needs to be done. Normally the group addresses its issues in private but this week took the unusual step of openly criticizing the authorities for their piracy failures.

In an open letter to the Prosecutor General, Rights Alliance director Maria Fredenslund says that not enough emphasis is being placed on the plight of the entertainment industries.

“As you know, we at Rights Alliance have worked to ensure that intellectual property crime is a priority focus, including that police and prosecutors take better care of intellectual property cases,” Fredenslund begins.

“However, we find that distribution of pirated copies is still extensively used as a platform and source of income for criminals.”

The Rights Alliance director says that public prosecution initiatives from 2013 and 2015 have failed to hit the mark and promises haven’t been kept.

“We write now because we do not see positive results in terms of the specific handling of intellectual property cases, as we were promised,” she writes.

Fredenslund wants public prosecutions of pirates to become a priority for the authorities and wants discussion to begin soon.

“There is from our side an urgent need to see concrete results in terms of cases handled, and a very clear communication from the authorities on what is illegal on the Internet,” she adds.

In publicly asking for a meeting with the Prosecutor General, Rights Alliance are clearly attempting to bring the issue of online piracy into the public eye. Quite what can be done remains up for debate.

With site blocking already in place and international efforts to physically remove sites such as The Pirate Bay from the internet failing, only targeting end users remains.

It’s understood that sending warning notices to Internet users caught pirating is still favored by rightsholders but whether those schemes have had any major effect on sales in other regions is still an unknown quantity.

The so-called “six strikes” system in the United States is still ongoing and has just been extended, but proclamations of the scheme’s successes have been almost entirely absent.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

CREO promises smartphone software updates so good it’s like “a new phone every month”

CREO promises smartphone software updates so good it’s like “a new phone every month”

Indian startup CREO plans to launch its first Android-powered smartphone soon.But the company is also promising that using it will be like getting a new phone every month, because CREO plans to roll out regular software updates that improve the features and functionality of the CREO Mark 1 smartphone. Details are a bit scarce at the […]

CREO promises smartphone software updates so good it’s like “a new phone every month” is a post from: Liliputing

CREO promises smartphone software updates so good it’s like “a new phone every month”

Indian startup CREO plans to launch its first Android-powered smartphone soon.But the company is also promising that using it will be like getting a new phone every month, because CREO plans to roll out regular software updates that improve the features and functionality of the CREO Mark 1 smartphone. Details are a bit scarce at the […]

CREO promises smartphone software updates so good it’s like “a new phone every month” is a post from: Liliputing