x
 You are from United States and your IP is 216.73.216.30 - Hide your IP and Location with a the Best VPN Provider when torrenting and streaming, and unblock the entire web.  
HIDE ME NOW!
Jump to content

Search the Community

Showing results for tags 'security flaw'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Site Related
    • News & Updates
    • Site / Forum Feedback
    • Support
    • Member Introduction
  • News
    • General News
    • FileSharing News
    • Mobile News
    • Software News
    • Security & Privacy News
    • Technology News
  • Downloads
    • nsane.down
  • General Discussions & Support
    • Filesharing Chat
    • Security & Privacy Center
    • Software Chat
    • Mobile Mania
    • Technology Talk
    • Entertainment Exchange
    • Guides & Tutorials
  • Off-Topic Chat
    • The Chat Bar
    • Jokes & Funny Stuff
    • Polling Station

Categories

  • Drivers
  • Filesharing
    • BitTorrent
    • eDonkey & Direct Connect (DC)
    • NewsReaders (Usenet)
    • Other P2P Clients & Tools
  • Internet
    • Download Managers & FTP Clients
    • Messengers
    • Web Browsers
    • Other Internet Tools
  • Multimedia
    • Codecs & Converters
    • Image Viewers & Editors
    • Media Players
    • Other Multimedia Software
  • Security
    • Anti-Malware
    • Firewalls
    • Other Security Tools
  • System
    • Benchmarking & System Info
    • Customization
    • Defrag Tools
    • Disc & Registry Cleaners
    • Management Suites
    • Other System Tools
  • Other Apps
    • Burning & Imaging
    • Document Viewers & Editors
    • File Managers & Archivers
    • Miscellaneous Applications
  • Linux Distributions

Categories

  • General News
  • File Sharing News
  • Mobile News
  • Software News
  • Security & Privacy News
  • Technology News

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Found 4 results

  1. A new report claims that there is a serious flaw in Microsoft's Skype chat mobile apps that could allow a hacker to detect a user's IP address. The flaw is reportedly enabled just by sending a link through Skype's text message feature, and the link does not have to be clicked on for the IP address to be revealed. The new flaw, as reported by 404Media.co, was first discovered by an independent security researcher who goes by the handle "Yossi". The article describes how this issue worked: To start, Yossi sent me a link via Skype text chat to google.com. The link was to the real Google site, and not an imposter. I then opened Skype on an iPad and viewed the chat message. I didn’t even click the link. But very soon after, Yossi pasted my IP address into the chat. It was correct. The article adds that this issue only affects Skype's mobile apps and does not appear to work on Skype on the desktop. Details about how this issue works on the hacker side were not revealed for security reasons, but the article claims the flaw is "trivially easy to exploit and involves changing a certain parameter related to the link." Yossi sent over his info about the flaw to Microsoft. The company's initial response to Yossi was that the IP address exposure in Skype "does not meet the definition of a security vulnerability for servicing which would require immediate servicing." However, when 404media.com asked Microsoft for comment, the company did state that while this issue with Skype was not an immediate security issue based just on the IP address exposure, "we will be addressing it in a future product update as a defense in depth improvement to help keep customers protected." As of this writing, Microsoft has yet to fix this problem. Source
  2. Paint 3D for Windows 10 had a Remote Code Execution flaw Microsoft’s Paint 3D was never popular, but it turns out the app was also actually dangerous to your system health after ZDI researchers discovered a Remote Code Execution Flaw in the 3D modelling software. The exploit, which was discovered by fuzzing, requires a user to load a compromised file and has now been patched by Microsoft in the latest Patch Tuesday. The issue is described in CVE-2021-31946 and reads as such: Microsoft Paint 3D GLB File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Paint 3D. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GLB files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process at low integrity. The flaw had a medium severity, as it required that the attacker had already escalated their privileges on your system. Microsoft has issued an update to the software which fixes the issue, but Windows 11 users need not worry, as the software is no longer pre-installed in that OS. Paint 3D for Windows 10 had a Remote Code Execution flaw
  3. An exploit patched last month could have allowed attackers to access anyone’s browser just by knowing their user ID. A security researcher revealed a “catastrophic” vulnerability in the Arc browser that would have allowed attackers to insert arbitrary code into other users’ browser sessions with little than an easily findable user ID. The vulnerability was patched on August 26th and disclosed today in a blog post by security researcher xyz3va, as well as a statement from The Browser Company. The company says that its logs indicate no users were affected by the flaw. The exploit, CVE-2024-45489, relied on a misconfiguration in The Browser Company’s implementation of Firebase, a “database-as-a-backend service,” for storage of user info, including Arc Boosts, a feature that lets users customize the appearance of websites they visit. In its statement, The Browser Company writes: Or, in the words of xyz3va, You can get someone’s creatorID in several ways, including referral links, shared easels, and publicly shared Boosts. With that info, an attacker could have created a boost with arbitrary code in it and added it to the victim’s Arc account without any action on the victim’s part. That’s bad. The Browser Company responded quickly — xyz3va reported the bug to cofounder Hursh Agrawal, demonstrated it within minutes, and was added to the company Slack within half an hour. The bug was patched the next day, and the company’s statement details a list of security improvements it says it’s implementing, including setting up a bug bounty program, moving off of Firebase, disabling custom Javascript on synced Boosts, and hiring additional security staff. Source RIP Matrix | Farewell my friend Hope you enjoyed this news post. Thank you for appreciating my time and effort posting news every single day for many years. 2023: Over 5,800 news posts | 2024 (till end of August): 3,792 news posts
  4. Security problems are usually discovered by geeks and people with a lot of time on their hands, but this is not always the case. In fact a flaw in the security of Xbox One was recently discovered by a five year old boy! While using his father's console,Kristoffer Von Hassel was able to log into his dad's account without having to enter the password used to protect it. The boy was understandably excited at the prospect of gaining unfettered access to the account: "I was, like, "yeah!" " he said. The hack was incredibly simple. After having been presented with the password screen and entering an incorrect password, Kristoffer found out that just by filling up the password field with spaces he was able to log in. The flaw was then reported by Kristoffer's father. Microsoft has already fixed the problem and by way of thanks has given Kristoffer a life-time subscription to Xbox Live, $50 and four games. He also appears in the list of"Security Researchers" for March on TechNet. The company issued a statement saying "We're always listening to our customers and thank them for bringing issues to our attention. We take security seriously at Xbox and fixed the issue as soon as we learned about it." Source
×
×
  • Create New...
x
 You are from United States and your IP is 216.73.216.30 - Hide your IP and Location with a the Best VPN Provider when torrenting and streaming, and unblock the entire web.  
HIDE ME NOW!