New Windows worm spreads by attacking weak passwords

A new Windows worm is working its way through company networks by taking advantage of weak passwords, security researchers said over the weekend.

The worm, dubbed “Morto” by Microsoft and Helsinki-based F-Secure, has been circulating since at least last week, when company administrators noticed systems generating large numbers of unexplained connections to the Internet.

According to Microsoft, Morto is the culprit.

To continue reading, register here to become an Insider. You’ll get free access to premium content from CIO, Computerworld, CSO, InfoWorld, and Network World.

Read more…

Drop $1000 and you can crack OS X passwords on a sleeping computer

Passwords are a tricky thing. Some people take the simple, if slightly unsafe, approach and use a pet name. Other more determined people hammer out a convoluted string of characters. None of it matters for Mac users though because Passware’s new password cracking program can grab any user login.

The Passware Kit Forensic v11 exploits a Mac OS vulnerability that lies within passwords stored in system memory. Passwords are stored when the computer is locked or put into sleep mode.

The program works over FireWire to grab memory, analyze it, and extract the password. Apparently, it takes just minutes. T

Read more…

Worst Possible Passwords

Do you really spend much time coming up with passwords for the variety of different websites that you utilize? Do you ever think about whether or not they’re really secure? Now if its some unimportant website that just happens to need a password, then maybe its not a big deal, but if its something like your online banking, then I think that you should definitely pay a little more attention.

This December, the popular photo sharing site, rockyou.com, was hacked. A list of user names and passwords was exposed on the Web for everyone to see. A Read more…