- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: eCryptfs 'parse_tag_3_packet()' Packet Heap Based Buffer Overflow Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Search
Search Result
-
Chinese Security Company Accused of Stealing from Rival
Category: Network Security & Hacking News/Latest Security News
... database of signatures of malicious applications that its software uses for detecting malware on customer computers. Malwarebytes then did something rather interesting in an attempt to verify the IP theft. ...Sunday, 22 November 2009 -
Poker Faced?
Category: Network Security & Hacking News/Latest Security News
In "An Unstoppable Force Meets..." Haseeb writes about "we have just witnessed a monumental event in the history of online poker the entrance of Isildur into our world of online poker." Huh? Really? The ...Saturday, 21 November 2009 -
An Ounce of Prevention is Worth a Pound of Cure
Category: Network Security & Hacking News/Latest Security News
... closely with a developer in a test environment to come up with the attack URL. It might take several more hours to write a script around that attack URL to mine the database. On the other hand, it would ...Friday, 20 November 2009 -
Out Law: Database anonymity at risk, warns researcher
Category: Network Security & Hacking News/Latest Security News
Out Law: Database anonymity at risk, warns researcher Out Law: Database anonymity at risk, warns researcher Read Full Article ...Friday, 20 November 2009 -
Alpha Software disclosure leads to confusion
Category: Network Security & Hacking News/Latest Security News
A few days ago, Security Fix heard from a reader who received a breach notification so casual in tone that he asked me to verify whether it was for real. Sure enough, Burlington, Mass.-based database application ...Friday, 20 November 2009 -
Two Ways To Encrypt Your Database
Category: Network Security & Hacking News/Latest Security News
File/operating system level-encryption is actually implemented outside the database engine -- but it's still a form of database encryption. And it's referred to as "transparent" encryption because it doesn't ...Friday, 20 November 2009 -
PHP “multipart/form-data” denial of service
Category: Network Security & Hacking News/Global Security News
PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we've reported some time ago. The problem is related with PHP's handling of RFC 1867 (Form-based File ...Thursday, 19 November 2009 -
Database anonymity at risk, warns researcher
Category: Network Security & Hacking News/Latest Security News
People might be more identifiable than previously thought from supposedly anonymised information contained in large databases, according to a technology law expert. New research recommends that privacy ...Thursday, 19 November 2009 -
JJ- Back in the lab: 802.1X and more
Category: Network Security & Hacking News/Latest Security News
Hi everyone! I know I've been missing in action yet again, so I thought I'd give you all a quick update. I've been on site quite a bit recently, working on various customer projects and security implementations. ...Thursday, 19 November 2009 -
Malicious Java Applet Poses as Carrie Prejean Video
Category: Network Security & Hacking News/Global Security News
McAfee Labs has observed various spam runs exploiting the recent sensational Carrie Prejean news. The Prejean video is rapidly becoming one of the most searched-for topics ever on the net since the existence ...Thursday, 19 November 2009 -
Security holes in Serv-U FTP server closed
Category: Network Security & Hacking News/Latest Security News
The 9.1.0.0 version of the Serv-U FTP Server for Windows closes two critical vulnerabilities which allow an attacker's code to infiltrate the system or restart it The 9.1.0.0 version of the Serv-U FTP ...Thursday, 19 November 2009 -
X-Flex Bomb-proof Wallpaper Could Save Your Life
Category: Network Security & Hacking News/Global Security News
object width=400 height=225param name=allowfullscreen value=true /param name=allowscriptaccess value=always /param name=movie value=http://vimeo.com/moogaloop.swf?clip_id=7558394amp;server=vimeo.comamp;show_title=1amp;show_byline=1amp;show_portrait=0amp;color=amp;fullscreen=1 ...Wednesday, 18 November 2009 -
Vuln: RhinoSoft Serv-U FTP Server 'rnto' Command Directory Traversal Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
RhinoSoft Serv-U FTP Server 'rnto' Command Directory Traversal Vulnerability Read Full ArticleWednesday, 18 November 2009 -
Vuln: RhinoSoft Serv-U FTP Server 'MKD' Command Directory Traversal Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
RhinoSoft Serv-U FTP Server 'MKD' Command Directory Traversal Vulnerability Read Full ArticleWednesday, 18 November 2009 -
Vulnerability in IBM SolidDB memory caching software
Category: Network Security & Hacking News/Latest Security News
Core Security disclosed a vulnerability that could affect large numbers of organizations using IBM’s SolidDB relational database management system, as well as those organizations using the many third ... ...Wednesday, 18 November 2009 -
Employee data breach at MassMutual
Category: Network Security & Hacking News/Latest Security News
Internetnews reports that the latest data breach to be discovered happened to MassMutual, a Massachussets-based insurance company. One of the companyaposs employees databases was accessed by a (so far) ...Wednesday, 18 November 2009 -
Cloud Security Front And Center
Category: Network Security & Hacking News/Latest Security News
Cloud computing is the latest trend that has the industry abuzz. Everywhere you go, there are cloud services for every functionality imaginable. Many believe that cloud computing can deliver massive business ...Wednesday, 18 November 2009 -
Microsoft Windows SMB Response Denial of Service Clarifications
Category: Network Security & Hacking News/Global Security News
A PoC was published recently on Full-Disclosure, completely hanging an up-to-date Windows 7 or Windows Server 2008 R2 system when an SMB connection is established to a malicious server. A PoC was published ...Wednesday, 18 November 2009 -
Google's free service opens up US legal search market
Category: Network Security & Hacking News/Latest Security News
Google has entered the market for legal information with a free service that allows users to search a database of US laws and court rulings. The move could endanger long-established legal publishers such ...Wednesday, 18 November 2009 -
Twitter accounts abused by spammers
Category: Network Security & Hacking News/Latest Security News
MX Lab detected a spam campaign where Twitter is being abused by spammers to promote online drug stores. The campaign is sent from random spoofed email addresses and has similar subjects like: 7U1 An amazing ...Tuesday, 17 November 2009 -
Interesting Information Security Bits for 11/17/2009
Category: Network Security & Hacking News/Latest Security News
... cool project. Get involved. Securosis Blog | An Open Metrics Model for Database Security: Project Quant for Databases Tags: ( metrics databases ) That’s it for today. Have fun! Subscribe to ...Tuesday, 17 November 2009 -
Protect Data or Get Fined
Category: Network Security & Hacking News/Global Security News
The Information Commisioners Office (ICO) or the privacy watchdog has published figures on data breaches that makes disturbing reading. What's more is that the ICO is getting so concerned that it will ...Tuesday, 17 November 2009 -
Microsoft warns of Windows 7 security hole
Category: Network Security & Hacking News/Latest Security News
Microsoft has confirmed reports of a security flaw in its Windows operating system that hackers could use to temporarily destabilize Windows 7 PCs. The software giant also acknowledged that blueprints ...Tuesday, 17 November 2009 -
Secure advanced Web server for Unix
Category: Network Security & Hacking News/Latest Security News
Hiawatha is a secure and advanced Web server for Unix. It features a rootjail, the ability to run CGIs under any UID/GID you want, prevention of SQL injection and cross-site scripting, banning of clie... ...Monday, 16 November 2009 -
Vuln: Home FTP Server 'MKD' Command Directory Traversal Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Home FTP Server 'MKD' Command Directory Traversal Vulnerability Read Full ArticleMonday, 16 November 2009 -
Vuln: DataWizard FtpXQ Server Multiple Remote Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
DataWizard FtpXQ Server Multiple Remote Vulnerabilities Read Full ArticleMonday, 16 November 2009 -
Auditing 100,000 Hosts or More with Nessus
Category: Network Security & Hacking News/Latest Security News
... However, I was usually assured it was not scanning that was in question; it was the fact that the network, routers, firewalls, servers, databases or whatever were “frozen”: nothing was to be done to them. ...Monday, 16 November 2009 -
Secret Security Operation Accidentally Exposed
Category: Network Security & Hacking News/Latest Security News
Hackers are always trying to find flaws that they can exploit to get to your personal information. Therefore, the experts need to always be a step ahead when it comes to finding and identifying any weaknesses. ...Monday, 16 November 2009 -
Extending Security Event Correlation
Category: Network Security & Hacking News/Latest Security News
Last year at this time I wrote a series of posts on security event correlation. I offered the following definition in the final post: Security event correlation is the process of applying criteria to ...Monday, 16 November 2009 -
First Windows 7 zero-day bug confirmed by Microsoft
Category: Network Security & Hacking News/Latest Security News
The first Windows 7 vulnerability has been confirmed by Microsoft - a denial of service vulnerability in the Server Message Block (SMB) protocol that cannot be used to take control of or install malic... ...Monday, 16 November 2009 -
Comscore selects Aster Data for data analytics
Category: Network Security & Hacking News/Latest Security News
... fast insights into their data. “By being able to take application logic and directly embed that in Aster’s massively parallel database, our analysts can produce relevant customer data that much quicker, ...Monday, 16 November 2009 -
Aster Data announces version 4.0, for ultra-fast analysis of Big Data
Category: Network Security & Hacking News/Latest Security News
... of terabytes to petabytes of data. The ability to push applications down into the MPP database also opens a new opportunity for companies to deliver new interactive, big data applications. Traditional ...Monday, 16 November 2009 -
Enquisite selects aster data to scale its Worldwide search data network
Category: Network Security & Hacking News/Latest Security News
... scalability and the ability to read-from and write-to the database at high speeds simultaneously, providing true, real-time analysis of very large datasets. Using Aster enabled Enquisite to amalgamate ...Monday, 16 November 2009 -
Database Processing (11th Edition) (Hardcover) newly tagged "databases"
Category: Network Security & Hacking Products/Databases
Database Processing (11th Edition) (Hardcover) By David Kroenke Buy new: $138.37 39 used and new from $89.99 Customer Rating: First tagged "databases" by Michael ...Sunday, 15 November 2009 -
Microsoft investigates vulnerability in Windows 7 and Server 2008 R2
Category: Network Security & Hacking News/Latest Security News
Microsoft is investigating a DoS vulnerability that can be exploited to cripple systems running Windows 7 or Windows Server 2008 R2. According to the vendor, however, no active attacks have been registered ...Sunday, 15 November 2009 -
Yahoo jobs site in SQL attack worry
Category: Network Security & Hacking News/Global Security News
This is theoretically less serious than a straight SQL injection attack because the attacker needs to infer returned information using carefully-crafted SQL queries to the target database, as opposed to ...Sunday, 15 November 2009 -
Reverse SSH Tunnel Watchdog
Category: Network Security & Hacking News/Latest Security News
We've covered tunneling before on HiR. I even wrote a little about reverse tunneling in my quick-and-dirty tunneling howto. This time, I'm building a setup to make an always-on reverse tunnel with a cron-powered ...Saturday, 14 November 2009 -
Beginning Database Design Solutions (Wrox Programmer to Programmer) (Paperback) newly tagged "databases"
Category: Network Security & Hacking Products/Databases
Beginning Database Design Solutions (Wrox Programmer to Programmer) (Paperback) By Rod Stephens Buy new: $29.69 45 used and new from $14.00 Customer Rating: First ...Saturday, 14 November 2009 -
Microsoft confirms first Windows 7 zero-day bug
Category: Network Security & Hacking News/Global Security News
In a security advisory, Microsoft acknowledged that a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, could be used by attackers to cripple Windows 7 and Windows ...Friday, 13 November 2009 -
Computer World: Guarding against database anti-forensics
Category: Network Security & Hacking News/Latest Security News
Computer World: Guarding against database anti-forensics Computer World: Guarding against database anti-forensics Read Full Article ...Friday, 13 November 2009 -
Microsoft IIS FTP Server NLST Buffer Overflow Clarifications
Category: Network Security & Hacking News/Global Security News
Working exploit code was recently published for a stack-based buffer overflow vulnerability in the FTP server component of Microsoft IIS when handling "NLST" commands. The reason for me writing this blog ...Friday, 13 November 2009 -
Imperva & WhiteHat Security Co-Present at Interop NY
Category: Network Security & Hacking News/Latest Security News
... also have a live application and database hacking demonstration. There are several other ... Interop New York is rapidly approaching. It's next week (11.16.2009 - 11.20.2009). Jeremiah ...Friday, 13 November 2009 -
Patch Tuesday - November 2009
Category: Network Security & Hacking News/Latest Security News
Another Tuesday, another round of security bulletins from Microsoft. Are you patched? Nessus contains credentialed local checks for all security bulletins, and a network-based uncredentialed check for ...Friday, 13 November 2009 -
WordPress 2.8.6 prevents malicious code from being uploaded
Category: Network Security & Hacking News/Latest Security News
A hole in the upload routine for blog post attachments allows PHP files to be disguised, for example, as images. Attackers can exploit the hole to execute arbitrary code. However, not all server configurations ...Friday, 13 November 2009 -
A Peek At Transparent Database Encryption
Category: Network Security & Hacking News/Latest Security News
There are several different ways to encrypt data stored within databases -- some residing inside the database, others outside. You can encrypt data programatically at the application layer or at the database ...Thursday, 12 November 2009 -
Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash
Category: Network Security & Hacking News/Latest Security News
Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash Read Full ArticleThursday, 12 November 2009 -
Vuln: IBM WebSphere Application Server Administrative Console HTML Injection Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
IBM WebSphere Application Server Administrative Console HTML Injection Vulnerability Read Full ArticleThursday, 12 November 2009 -
Vuln: XM Easy Personal FTP Server 'APPE' and 'DELE' Commands Remote Denial of Service Vulnerabilities
Category: Network Security & Hacking News/Security Exploits and Security Patches
XM Easy Personal FTP Server 'APPE' and 'DELE' Commands Remote Denial of Service Vulnerabilities Read Full ArticleThursday, 12 November 2009 -
Special Edition Using Microsoft Office Access 2007 (Paperback) newly tagged "databases"
Category: Network Security & Hacking Products/Databases
Special Edition Using Microsoft Office Access 2007 (Paperback) By Roger Jennings Buy new: $31.49 48 used and new from $27.48 Customer Rating: First tagged "databases" ...Thursday, 12 November 2009 -
MySQL
Category: Web Links / Joomla! Specific Links
The database that Joomla! uses ...Wednesday, 07 July 2004