“Using Framesniffing, it’s possible for a malicious webpage to run search queries for potentially sensitive terms on a SharePoint server and determine how many results are found for each query,” said Paul Stone, senior security consultant at Context. “For example, with a given company name it is possible to establish who their customers or partners are; and once this information has been found, the attacker can go on to perform increasingly complex searches and uncover valuable commercial information.”
Context researchers tested SharePoint 2007 and 2010 and found that by default, they do not send the X-Frame-Options header that instructs web browsers to disallow framing. This leaves these applications open to both Framesniffing and Clickjacking. As a result, any website that knows the URL of the SharePoint installation can load it in a frame and carry out these attacks, even if it is only accessible on an Intranet.
Following the discovery of this vulnerability, Context contacted Microsoft and was told: “We have concluded our investigation and determined that this is by-design in current versions of SharePoint. We are working to set the X-Frame options in the next version of SharePoint.”
Framesniffing can also be used to harvest confidential data from public websites, such as LinkedIn that don’t protect against framing. An attacker using a malicious website could build a profile of visiting users by piecing together small pieces of information leaked from different websites. For example, the product IDs of previously bought items from a shopping site could be combined with a person’s user ID from a social networking site.
Context’s blog published today at www.contextis.com/research/blog/framesniffing, includes a video that shows an attacker extracting sensitive information from a fictional corporate SharePoint installation. In the blog, Context also provides five simple steps to protect a website from this attack by adding the X-Frame-Options header. While Mozilla updated its Firefox web browser last year to prevent Framesniffing, the latest versions of Internet Explorer, Chrome and Safari are still vulnerable.
Fortunately, protecting a website from this attack is a simple matter of adding the X-Frame-Options header and in its blog, Context provides step-by-step instructions on how to do this. “Users of the Firefox browser are already protected against this attack,” said Stone. “We encourage other browser vendors to apply similar protection to their browsers but in the meantime, the onus is on individual websites to add framing protection via X-Frame-Options.”
View the original article here
The Samsung Galaxy Tab 10.1 sports a 10.1-inch WXGA PLS TFT HD display with 1280 x 800 resolution. It has a 1GHz dual-core NVIDIA Tegra 2 processor and runs Android Honeycomb (3.2) OS. The tablet has a 3.2MP rear-facing camera with auto-focus and 720p video recording along with a 2MP front-facing one. Users will have 32GB of internal memory to store music, movies, photos, and other files on the device. It is also lightweight and slim, weighing in at a little over 1lbs and measuring 0.34 inches in thickness.
The Android-powered tablet will run on U.S. Cellular’s 4G LTE network, which boasts speeds up to 10 times faster than 3G. It is the first device introduced in U.S. Cellular’s 4G LTE device line-up.
Customers can purchase the device for $499.99 after a $100 mail-in rebate. But for those living in markets currently covered by the 4G LTE network, there is an additional $100 mail-in rebate, bringing the total price down to $399.99. Check out the U.S. Cellular website for detailed information on pricing.
View the original article here
Aside from the usual ICS update, which will launch in April, Sony will bundle in additional photo functionality, like the ability to activate the tablets' cameras directly from their lock screen, edit photos in the gallery application, and take panoramic photos. The update also allows Sony Tablet users to watch programs they’ve recorded on their compatible Blu-Ray recorders with a downloadable app.
Another feature Sony adds is "Small Apps." Users will be able to launch a small calculator, remote control, or browser window on top of their currently running app.
In addition to the ICS upgrade for the Tablet P and the Tablet S, Sony announced a Wi-Fi-only version of the Tablet P for 5,000 Yen (roughly $600) on April 21. The Wi-Fi-only Tablet P will be customizable as customers can purchase an interchangeable front and back panel ranging in colors such as black, white, gold, pink, and blue. This is the same Tablet P that is available now, except without the 3G radio.
View the original article here
Subscribe to:
Posts (Atom)
