WordPress still insecure by design

Some major WordPress design flaws have led to widespread attacks on our and your servers. The only hope is reasonably long and strong passwords or WordPress security plugins. The first flaw. By default WordPress have enabled “feature”, when you visit your blog with author query string appended, it nicely reveals your usernames. For example, if …

Windows Update leads to spam site (hus.parkingspa.com/hc3.asp) today

Today when trying to update one of my Microsoft Windows – Windows 7 Ultimate 64-bit, and clicking to More Information link, it led my browser to SPAM site (DO NOT VISIT IT!): http://hus.parkingspa.com/hc3.asp – DO NOT VISIT IT! It happens only for update – Update for Windows 7 for KB2505438, when you click on more …

FireWire port is a big security hole

Today, reading Larry Osterman’s blog, I learned something new. I always knew, that physical access to computer / server almost always means, that it may be compromised in one or another way, like Cryogenically frozen RAM bypasses all disk encryption methods. More here. One thing I didn’t know, is FireWire (IEEE 1394 interface) Security issues. …