Gmail Vulnerable to a Change PW Attack!
Comments OffSecuriteam has made an announcement that Gmail has an issue. I will quote:
GMail is vulnerable to CSRF attacks in the “Change Password” functionality. The only token for authenticate the user is a session cookie, and this cookie is sent automatically by the browser in every request.
An attacker can create a page that includes requests to the “Change password” functionality of GMail and modify the passwords of the users who, being authenticated, visit the page of the attacker.The attack is facilitated since the “Change Password” request can be realized across the HTTP GET method instead of the POST method that is realized habitually across the “Change Password” form.
[Via Securiteam]
One way to prevent this to a point is right now having GMAIL automatically connect securely. You would go into your settings in gmail and make sure it uses https connection:
This is one way to prevent the cookie attack but is still needing to be fixed. Since it is using the HTTP GET method it should use the HTTPS method as soon as you try accessing the site. Google needs to change to the HTTPS Get method instead to prevent this type of attack. If you have any other ideas for Google just leave a comment.
ThePirateBay might be blocked in the US
Comments OffI was looking around on Google and thought I just for giggles check out the Piratebay complaints. I tried going to the site and here’s what Popups:
Digital Convert boxes for Feburary 17, 2008
Comments OffIt being close to the change over, I’d figure I’d show you some of them and talk about them. To better help people make up there minds on what might be there choice of a Digital Converter Box. This is to help people get the most out of there products.
The Specs for this Converter is:
Zenith DTT901 Digital TV Tuner Converter Box

- Digital TV Tuner Coverter Box
- Analog Pass-Through for Low-Power TV Stations broadcasts
- On-Screen Program Information with Remote Control
- Simple Connection to TV with supplied RF Cable
- Parental Control to Manage TV Programs and advanced Closed Captioning
It could be on sale so check the link for more price options. I also found this one that is a little more expensive but supposed to be better:
GE 23333 Digital to Analog TV Converter Box

- Smart Antenna Interface
- Simple Setup
- Analog Pass Through
- Dolby(R) Digital Sound
- Receives Over-Air Hdtv Signals
$76.99 Free Shipping
Are you patched, Secunia Says NO
Comments Off
Think you’ve got nothing to worry about, according to Secunia 98% of computers are not fully patched and are vulnerable to some kinda of attack.
If you have a system that is off of the Net you could use the Clone of Autopatcher Program to do it for you. You also need to update all your secondary programs such as Audacity, Open Office, and other programs that you use weekly.
Vista To release Service Pack 2 in April 2009

Time to Change your clocks.
Time to change those clocks of ours
Beginning in 2007, Daylight Saving Time is extended one month and the schedule for the states of the United States that adopt daylight saving time will be:
2 a.m. on the Second Sunday in March
to
2 a.m. on the First Sunday of November.
So that saying goes it “Fall back, Spring Forward“ So now here are some great programs to better help you get your computer clock up to snuff:
Worldtimeclock Atomic Clock Sync Program – It is a free program for you to use with your Windows. Although you have to make sure your selected the right timezone once it is installed all you will need in an internet connection to sync your windows time with the atomic clock.
Bandwidth Tools For Monitoring your bandwidth
Comments OffSo I’ve done some looking around for bandwidth programs. So here’s what I found so far. The programs I’ve got listed are not test and are therefore your responsible for any and all use of the programs.
-
FreeMeter Bandwidth Monitor For Windows – Monitor network bandwidth (C#.NET 2k/XP+). Desktop and Systray graph. Configurable connection speed, update interval, color, transparency. Monitor any or all network interfaces. Ping/Trace/UPnP utilities. Email notifier (POP/IMAP). Requires .NET 2.0.
-
Pipelog – Windows Bandwidth Meter — Pipelog is a Windows bandwidth meter that gives live statistics of accumulated bandwidth usage. It is written in C# and runs on the .NET Framework.
-
Windows Service Monitor – Monitor and automatically restart Windows Services with this small Win32 command line utility. Windows Service Monitor (WinSMon) can monitor several services, restart services that stop/fail and limit the number of restart times.
-
iptotal — iptotal is an IP traffic monitor. It listens to a network interface in non-promiscuous mode, and measures IP bandwidth usage. After the specified number of seconds, the average throughput is printed at total, input and output usage.











