James breaks down a few news stories from the previous week. The following stories were discussed, including some brief points.
- Microsoft Accidentally pushes test patch http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/
- Of course the community assumes hack.
- Oversight that allowed a test patch to be released.
- They are working to remove it.
- Credit Card Liability Shift Is here
- Starting October 1, 2015 if your a vendor and use the magnetic stripe on a chip enabled card, certain fraudulent transactions will fall to you, instead of the bank.
- This doesn’t change the liability for consumers.
- James' interview on Channel 4 News in Jacksonville http://www.news4jax.com/news/new-credit-card-technology/35391900
- WinRAR exploit – Is it just hype? http://www.theregister.co.uk/2015/09/30/500m_winrar_users_open_to_remote_code_execution_zero_day/
- Requires you to execute an exe, which is something we are taught not to do from untrusted sources.
- Estimates say this effects 500 million users, but let’s be realistic on the risk here. It requires you to execute an executable.
- Remember not to run attachments or files unless they are from a trusted source and you are expecting the item.
- Huge iOS 9 Security Flaw (or maybe not?) https://www.yahoo.com/tech/s/huge-ios-9-security-flaw-lets-anyone-see-134547688.html
- Can bypass the lock screen to see photos and contacts.
- Uses Siri (so it has to be enabled on the lock screen).
- Requires physical access to the device.
Send us a text
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.