In March, NTA found a password flaw in Nortel's Contivity VPN client for Microsoft Windows. NTA is urging companies to install a software patch that was issued by Nortel on Friday. It's possible to identify Nortel VPN routers using UDP backoff...
The software is aimed at a range of systems, from consumer desktops to large corporate mail servers, meaning the flaw could be used to take control of key corporate systems or to install programs to grab people's identity data.
An email purporting to offer a link to amateur video footage of the events on the London Underground in the aftermath of the bomb blast will install a Trojan on users' machines if they click on the attachment.
It recommended that customers install virus-protection software on their handhelds and also that they activate the password protection features on the device. Backdoor server and Trojan horse programs often use enticing file names to trick users...
Programs that illustrate how to take advantage of such holes are known as "exploit code" and are seemingly being developed faster, coming out soon after the first notification of a flaw, a recent study by Symantec found.
I discovered one small reference to a dictionary attack vulnerability against user passwords, which I felt was insufficient notification for such a critical flaw in the protocol. Unlike LEAP, the new protocol does not allow hackers to limit the...