Bad news

6 posts filed under this category.

Netvibes module developer collects web credentials, personal content

A French security blogger gained access to private user data on personal homepage service Netvibes last weekend, exposing stored usernames and passwords for popular integrated web services as well as user content loaded in the page. The blogger’s account has since been deleted from Blog*Spot (currently cached on Yahoo!), but he provided extended details to French blog Le blog de ¥€$ (English translation). Netvibes has since claimed to patch “a security vulnerability in webnotes” exploited by this developer. I alluded to some of these issues with stored user information, phishing, and general brand confusion in a post two months ago…

Buzzword laden startup launches

I just received a press release for a new startup launching today. The announcement is heavy with buzzwords, but doesn’t actually tell me what the site is all about. Here’s the actual first paragraph, with the name and industry removed. Web 2.0 changes the way we perceive information. [Company name] uses Web 2.0 in the [vertical name] (i.e. blogs, podcasts, ajax, tags, etc.) and is particularly attentive to RSS, which presents a formidable opportunity for this sector. The press release on the launch of this new company next explains what a typical RSS button on a website looks like, and…

LiveJournal XSS attack

A group of crackers named Bantown claims to have hijacked 46% of LiveJournal’s active accounts, over 900,000 total, via a cross-site scripting attack according to Brian Krebs of The Washington Post. The group was able to steal the cookies of LiveJournal users clicking on links created by the group on their hundreds of automated journal accounts. LiveJournal altered their URL structure last night to allow each user to have their own private cookie domain. The Bantown group continues looking for sites to BBQ, or swap user profiles for something a bit more sexual, often involving farm animals. Some of…

Kanoodle cookie bounty

Advertising network Kanoodle will now pay webmasters for planting a cookie on a visitor’s computer without ever showing an advertisement. Sites placing a cookie classifying a user’s browsing habits into one of 7,500 contextual ad categories. Publishers in the program will be paid 5% of the revenue earned when an advertisement served on the Kanoodle network is triggered by a cookie generated on the publisher’s site. Kanoodle advertisements are an integrated option for TypePad Pro users. Bloggers could profit from distributing cookies on their own personal weblogs for later monetization on a TypePad Pro site with advertising or other blogs…

Stealing citizen content

I am sitting in my hotel room in Seattle researching all the sites that used my photographs from yesterday’s Microsoft announcement in violation of my Creative Commons Attribution Non Commercial license. I broke a story with high-resolution photographs and commercial websites decided not only to use my content without attribution but in one case a site was selling prints of my photographs. Breaking news is very competitive and everyone wants the scoop in their search for full and in-depth coverage. Unlike a picture of the Golden Gate Bridge or something artsy I feel like these sites already have benefitted from…

Access to zombie PCs for sale

Byron Acohido and Jon Swartz of USA Today wrote an article about the use of zombie machines to send mass e-mails. They found the asking price for use of a network of 20,000 zombie computers to be $2,000 to $3,000. (via Slashdot)…

All categories