| |
|
| |
Teleconferencing vendors defend product security features |
|
| |
 |
|
| |
 |
Teleconferencing vendors say they're trying to strike the right balance between security and usability after security researchers found they could dial in to the conference lines of major companies and manipulate video cameras to spy on boardrooms.H.D. Moore and Mike Tuchen revealed their research for security company Rapid7 on Monday, detailing how easily attackers can secretly spy on boardrooms where conferencing systems have been left open to receive calls from anyone by default.The problem boils down to auto-answer, a feature in products from companies such as Cisco, LifeSize and Polycom that automatically connects incoming video or audio calls. Moore, who is chief security officer at Rapid7, wrote a program to scan for teleconferencing systems in which administrators left this feature enabled, a major security issue.Moore's scan covered about 3 percent of the addressable internet and found 250,000 systems using the H.323 protocol, a specification for audio and video calls. Moore said he found more than 5,000 organizations had left auto-answer enabled in products from vendors including Polycom, Cisco, LifeSize and Sony. Overall, the findings mean up to 150,000 systems across the internet could be vulnerable, according to Rapid7.Once inside a conference room, Rapid7 said that even cheap videoconferencing systems could allow a person to "read a six-digit password from a sticky note over 20 feet away from the camera.""In an otherwise quiet environment, it was possible to clearly hear conversations down the hallway from the video conferencing systems," Moore wrote on Rapid7's blog. "A separate test confirmed the ability to monitor a user's keyboard and accurately capture their password, simply by aiming the camera and using a high-level zoom."But if all of the security features of the various teleconferencing systems were enabled, Moore "couldn't imagine anyone would use the product to make a phone call" due to the complexity, he said in an interview. More... |
|
|
| |
 |
|
| |
U.S. government online security website hacked |
|
| |
 |
|
| |
 |
Hackers under the AntiSec banner appeared to have hacked late Monday the website of OnGuardOnline.gov, the U.S. federal government's online security website, in protest against controversial legislation.In a message on the OnGuardOnline website and on Pastebin, the hackers threatened "a relentless war against the corporate internet", destroying what it said would be "dozens upon dozens" of government and company websites, if the Stop Online Privacy Act (SOPA), Protect IP Act (PIPA) and Anti-Counterfeiting Trade Agreement (ACTA) are passed.It also threatened to dump emails, passwords, bank accounts, and other information from the hacked websites. "We are sitting on hundreds of rooted servers getting ready to drop all your mysql dumps and mail spools," the Anonymous-affiliated hacker group said.OnGuardOnline.gov is a partnership of fourteen federal agencies managed by the U.S. Federal Trade Commission (FTC).FTC could not be immediately reached for comment on the hack of the security website. The website of web defacement archive, Zone-H was also defaced Monday, but it wasn't clear who was responsible.Earlier on Monday a video purported to be from Anonymous asked for people's support to launch a DDoS (distributed denial of service) attack using the Low Orbit Ion Cannon tool on Jan 28 on Facebook. AnonOps, an Anonymous account on Twitter, however said the threat to shut down Facebook was a fake. A similar threat against Facebook was made last year.Anonymous last week claimed responsibility for attacks on some government and company websites including those of Universal Music, the U.S. Department of Justice and the Recording Industry Association of America in retaliation for the government's removal of the Megaupload online storage and file-sharing websites. More... |
|
|
| |
 |
|
| |
Latest IT Security Topix |
|
| |
 |
|
| |
|
|
|
| |
|
| |
|
| Nsauditor Network Security Auditor |
 |
Nsauditor Network Security Auditor is a network security and vulnerability scanner that allows auditing and monitoring network computers for possible vulnerabilities. |
Download  |
Buy Now  |
More Info  |
 |
| Nsasoft Hardware Software Inventory |
 |
Nsasoft Hardware Software Inventory is
a powerful network inventory software for home, office and enterprise networks. The software scans all computers on a network and generates complete reports about computers hardware and software. |
Download  |
Buy Now  |
More Info  |
 |
| NBMonitor Network Bandwidth Monitor |
 |
NBMonitor tracks Internet bandwidth usage (upload and downloads) and shows process names initiated network connections. It displays real-time details about your network connections and network adapter's bandwidth usage. |
Download  |
Buy Now  |
More Info  |
 |
| BlueAuditor Bluetooth Auditor |
 |
BlueAuditor detects and monitors Bluetooth devices in a wireless network and allows network administrators to audit wireless networks against security vulnerabilities associated with the use of Bluetooth devices. |
Download  |
Buy Now  |
More Info  |
 |
| NetShareWatcher Monitors Network Shares |
 |
NetShareWatcher is network security improvement software and allows network administrators to monitor network shares, permissions and identify shares which are violating data access policy in their organization. |
Download  |
Buy Now  |
More Info  |
 |
| NetworkSleuth Network File Search Utility |
 |
RemShutdown allows Shutdown or Restart Network Computers Remotely. You can specify a delay during which a message you specify can be displayed and applications running on the Remote Computer at the time of shutdown can be allowed to close. In addition, RemShutdown offers the user the option to cancel the Shutdown. |
Download  |
Buy Now  |
More Info  |
 |
| RemShutdown Shutdown Network Computers |
 |
RemShutdown allows Shutdown or Restart Network Computers Remotely. You can specify a delay during which a message you specify can be displayed and applications running on the Remote Computer at the time of shutdown can be allowed to close. In addition, RemShutdown offers the user the option to cancel the Shutdown. |
Download  |
Buy Now  |
More Info  |
 |
| ShareAlarmPro Network Access Monitoring |
 |
ShareAlarmPro monitors network access to shared folders and resources, allows to see parameters of the workstation which tries to establish a connection with your computer. |
Download  |
Buy Now  |
More Info  |
 |
| SpotAuditor All-in-one Password Recovery Software |
 |
SpotAuditor is All-in-one password recovery program that offers administrators and users a comprehensive solution for recovering passwords and other critical business information saved in users' computers. |
Download  |
Buy Now  |
More Info  |
 |
| Backup Key Recovery Crashed Drive Keys Recovery |
 |
Backup Key Recovery retrieves product keys for Windows, MS Office, SQL Server, Adobe products and more than 2500 popular software products installed on your crashed hard disk drive. |
Download  |
Buy Now  |
More Info  |
 |
| Product Key Explorer Find, Recovery and Backup |
 |
Product Key Explorer retrieves over 3000 product keys from network computers and allows track the number of software licenses installed in your business, recover lost or forgotten serial keys, keep an up-to-date backup of all your software license keys in a central location. |
Download  |
Buy Now  |
More Info  |
 |
| |
|
| |
|