Exploits
Software exploits that can comprimise your privacy and security

 


















Subscribe to "Exploits" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.

 

 

  Wednesday, March 7, 2007


Heise online reports on a very interesting action Microsoft is taking during the installation of WGA.

When you start WGA setup and get to the license agreement page but decided NOT to install the highly controversial WGA component and cancel the installation, the setup program will send your info and the fact that you choose not to install WGA back to their servers.

In addition to that it seems that the setup program send some information stored in your registry to http://genuine.microsoft.com/. While it does not specifically identify the user, it looks like it does send some identification of your computer and Windows version (see picture) to Microsoft servers.
1:06:01 PM    

Microsoft WGA Phones Home Even When Told No. Aviran writes "When you start WGA setup and get to the license agreement page but decided NOT to install the highly controversial WGA component and cancel the installation, the setup program will send information stored in your registry and the fact that you choose not to install WGA back to Microsoft's servers." [Slashdot]
1:00:00 PM    

Radio listeners weary of hearing the same songs over and over may have something to cheer about: Broadcasters have tentatively agreed to anti-payola settlements that could shake up music playlists at some of the nation's largest radio chains.

Four major broadcast companies would pay the government $12.5 million and provide 8,400 half-hour segments of free airtime for independent record labels and local artists, The Associated Press has learned.

The agreement is aimed at curbing payola -- generally defined as radio stations accepting cash or other consideration from record companies in exchange for airplay. The practice has been around as long as the radio industry and was made illegal after scandals in the late 1950s.

Two Federal Communications Commission officials, who spoke on condition of anonymity because final language has not been approved by the full commission, said the monetary settlement is part of a consent decree between the FCC and Clear Channel Communications Inc., CBS Radio, Entercom Communications Corp. and Citadel Broadcasting Corp.

The settlement was reached at the same time as a separate deal designed to lead to more airtime for smaller record companies and their lesser-known artists as well as local musicians.


12:17:54 PM    

Malware Increased 172 Percent in 2006, According to Report. Amount of malware detected in 2006 same as past 15 years, combined. [GT: Security and Privacy]
11:57:37 AM    

March 05, 2007   (Reuters) -- CHICAGO - Wal-Mart Stores Inc. said today it fired a systems technician for intercepting text messages of people who were not Wal-Mart employees and for recording telephone conversations with a New York Times reporter without authorization.

Wal-Mart, the world's largest retailer, said an internal investigation found the technician had monitored and recorded phone calls between Wal-Mart public relations employees and a New York Times Co. reporter between September and January.

The Bentonville, Ark.-based retailer also said the technician, who worked in its information systems division, intercepted and stored text messages that contained certain key words, including those sent by people in the Bentonville area who were not Wal-Mart employees.

Wal-Mart spokeswoman Mona Williams said on a call with reporters that the technician "did this on his own."

While interviews with the technician gave the retailer an idea as to why he recorded the calls, Williams said she could not disclose the reasons because the case has been turned over to federal investigators.


11:52:20 AM    

Spying at Wal*Mart: Human nature run amuck?  Does the Wal-Mart eavesdropping debacle have the potential to be this year's HP scandal? A former IT security staffer for the retailer evaluates what might have happened. [Computerworld Privacy News]
11:46:37 AM    

Mass. motor vehicle registry warns of spoof site. The Massachusetts Registry of Motor Vehicles is warning customers about an online scam intended to trick them out of their credit card information and their money.  [Computerworld Privacy News]
11:44:41 AM    

Crack! Security expert hacks RFID in UK passport. The British government says that forgery of their new biometric passports is inconceivable, but a security expert has demonstrated a successful crack of the embedded RFID chip and its info. And he did it without taking the document out of its mailing envelope. [Computerworld Privacy News]
11:41:33 AM    


Click here to visit the Radio UserLand website. © Copyright 2007 Paul Hardwick.
Last update: 3/18/07; 5:44:56 PM.

March 2007
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Feb   Apr