Sniffer hijacks secure traffic from unpatched iPhones

July 28, 2011

If  Iphone or Ipad devices aren’t patched (version 4.34) , attackers can easily intercept and decrypt secure traffic — the kind guarded by SSL, which is used by banks, e-tailers and other sites — at a public Wi-Fi hotspot.

Link


RSA attack explained by their security officer: Anatomy of an Attack

July 28, 2011

The attacker in this case sent two different phishing emails over a two-day period. The two emails were sent to two small groups of employees; you wouldn’t consider these users particularly high profile or high value targets. The email subject line read “2011 Recruitment Plan.”

The email was crafted well enough to trick one of the employees to retrieve it from their Junk mail folder, and open the attached excel file. It was a spreadsheet titled “2011 Recruitment plan.xls.

Link