- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: eCryptfs 'parse_tag_3_packet()' Packet Heap Based Buffer Overflow Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Search
Search Result
-
Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Mahara Admin Password Reset Security Bypass Vulnerability Read Full Article ...Sunday, 29 November 2009 -
Fly for $1 or Your Money Back!
Category: Network Security & Hacking News/Global Security News
... This Trojan is a downloader that will copy a password-stealing malware that targets the customers of Brazilian banks. The malware is currently hosted at hxxp://www.radfahrschule.at/html/modules/PagEd/browsepics/. ...Friday, 20 November 2009 -
Identity Management in 13 Easy Steps
Category: Network Security & Hacking News/Latest Security News
... April 2010: Preparing for Password Self-Service – password self-service is a key cost savings of IAM, but it’s harder than you might think. This article will help you prepare your policies and your users ...Thursday, 19 November 2009 -
Fedora 12 allows users install privilege - Update
Category: Network Security & Hacking News/Latest Security News
Fedora 12 has changed security policy to allow unprivileged users to install software without the root password Fedora 12 has changed security policy to allow unprivileged users to install software without ...Wednesday, 18 November 2009 -
Fedora 12 allows users install privilege - Update 2
Category: Network Security & Hacking News/Latest Security News
Fedora 12 has changed its security policy to allow unprivileged users to install software without requiring the root password Fedora 12 has changed its security policy to allow unprivileged users to ...Wednesday, 18 November 2009 -
Stop blaming the admins!
Category: Network Security & Hacking News/Latest Security News
... written poorly, or actually create vulnerabilities. For example lets make all the local admin passwords something really difficult and long, and… all the same so that we can easily administer ...Wednesday, 18 November 2009 -
Some Interesting Stats From My Bits Posts
Category: Network Security & Hacking News/Latest Security News
... quick wget call to Delicious (wget –no-check-certificate -O <output.file> https://<username>:<password>@api.del.icio.us/v1/posts/all?tag=<tagyouwant>), a little awk, sort, ...Tuesday, 17 November 2009 -
New York cafe WiFi passwords show Mac versus PC reality
Category: Network Security & Hacking News/Latest Security News
Photograph depicts password needed to use cafe WiFi. The Apple blog, Cult of Mac posted a picture of the day depicting the stark difference between a WiFi password needed for Apple laptops versus those ...Tuesday, 17 November 2009 -
Decompiling Flash Files with SWFScan
Category: Network Security & Hacking News/Latest Security News
... found one (actually lots). Let's fire up SWFScan and see what we can see. Open it and decompile the .swf. We see a hardcoded password. just to be sure that it actually does any checking Ok its ...Monday, 16 November 2009 -
Auditing 100,000 Hosts or More with Nessus
Category: Network Security & Hacking News/Latest Security News
... with a password policy that mandates requirements such as use of complex passwords, limiting who has access to them and changing them on a timely basis. In larger organizations, it can become politically ...Monday, 16 November 2009 -
Cyber-Ark Expands Into Superuser Access Control Market
Category: Network Security & Hacking News/Latest Security News
... and becomes the first vendor to provide a unified, policy-driven approach for shared-account/software-account password management (SAPM) and superuser privilege management (SUPM). New features of the ...Monday, 16 November 2009 -
Password theft via vulnerability in SSL/TLS protocol
Category: Network Security & Hacking News/Latest Security News
The vulnerability in the design of the SSL/TLS protocol revealed earlier this month can apparently be used for practical attacks after all, such as stealing Twitter login data The vulnerability in the ...Sunday, 15 November 2009 -
Reverse SSH Tunnel Watchdog
Category: Network Security & Hacking News/Latest Security News
... -p 1337 axon@localhost's password: Last login: Sat Nov 14 00:01:04 2009 from localhost.labs.h-i-r.net OpenBSD 4.5 (GENERIC) #1749: Sat Feb 28 14:51:18 MST 2009 Welcome to OpenBSD: The proactively secure ...Saturday, 14 November 2009 -
Darknet: Cain & Abel v4.9.35 Password Sniffer, Cracker and Brute-Forcing Tool
Category: Network Security & Hacking News/Latest Security News
Darknet: Cain Abel v4.9.35 Password Sniffer, Cracker and Brute-Forcing Tool Darknet: Cain & Abel v4.9.35 Password Sniffer, Cracker and Brute-Forcing Tool Read Full Article ...Thursday, 12 November 2009 -
Police website got hacked, so what?
Category: Network Security & Hacking News/Latest Security News
... and passwords that are used for the administration of the site." said Amichai Shulman, Imperva's CTO. “This is an unfortunate situation for the police, but does go to show that no one is protected from ...Wednesday, 11 November 2009 -
We need to learn more about the RBS Worldpay ATM attack
Category: Network Security & Hacking News/Latest Security News
... As an example, here is a paper on attacking the algoritm used by IBM 3624s which many ATMs are based on. Like password hash storage in Windows, backwards compatibility with older encryption formats can ...Wednesday, 11 November 2009 -
Looking back at 2009 through SQL Injection goggles
Category: Network Security & Hacking News/Global Security News
... itself was in the password reset function on one of their login pages. It is quite common for developers to go all out in securing their main login functionality and forgetting all about the “forgot/change ...Wednesday, 11 November 2009 -
Get out of Jail, not so free
Category: Network Security & Hacking News/Global Security News
... the secure shell service(SSH) he attempted to login using the default root user account password. instead of quietly taking a look at or copying the user’s SMS messages and emails, he decided to ...Tuesday, 10 November 2009 -
Detection, Prevention Best Measure for Risk
Category: Network Security & Hacking News/Latest Security News
... decision was made to focus not on mitigation of the risk, but on minimizing it. Steps were taken to replace the known compromised systems. Scans and password changes became the order of the day and entire ...Tuesday, 10 November 2009 -
The iPhone “Worm” Presents No Risk to Most Users
Category: Network Security & Hacking News/Latest Security News
... worm circulates by scanning the phone’s local IP address range for other iPhones running the SSH daemon, and if it finds any, attempts to log in using the default root password. It then copies a ...Tuesday, 10 November 2009 -
Apple ships 50+ security updates
Category: Network Security & Hacking News/Latest Security News
... in to any account without supplying a password. Another update, this one for a bug in Leopard' Dictionary program, is limited to users on the local network, but gives a whole new meaning to the Read ...Tuesday, 10 November 2009 -
Partially Spilled COFEE
Category: Network Security & Hacking News/Latest Security News
... commands. It does not grab browser history, nor password hashes: it only runs built-in Windows commands, sysinternals tools, and resource kit tools. It turns out the version of COFEE (Computer Online ...Tuesday, 10 November 2009 -
Password hole in GRUB boot loader closed
Category: Network Security & Hacking News/Latest Security News
The hole made it easier for an attacker to circumvent the simple authentication in the boot loader designed to protect the boot parameters from unauthorised modification The hole made it easier for an ...Tuesday, 10 November 2009 -
Pirates get a taste of Microsoft COFEE
Category: Network Security & Hacking News/Latest Security News
... analysis. In other words, it lets officers grab data from password-protected or encrypted sources. That ... Microsoft's Computer Online Forensic ...Monday, 09 November 2009 -
Nastygram: MySpace Phish Plants Spy Software
Category: Network Security & Hacking News/Latest Security News
... and then attempts to trick victims into installing password-stealing malicious software. Attackers began blasting out the junk e-mails early Monday, according to researchers at the University of Alabama, ...Monday, 09 November 2009 -
iPhone worm attacks jailbroken iPhones with default password
Category: Network Security & Hacking News/Latest Security News
The first known malware worm for the iPhone is targeting jailbreakers running SSH and default root passwords, "rickrolling" vulnerable iPhones by replacing the wallpaper image with an image of '90s pop ...Monday, 09 November 2009 -
Tenable Network Security Podcast - Episode 11
Category: Network Security & Hacking News/Latest Security News
... MITM attacks against not only HTTPS, but other protocols as well such as IMAPS/POPS and some are speculating SSL VPNs could also be affected. iPhone Worm Spreads via default password - Rick Ashtley ...Monday, 09 November 2009 -
iPhone worm Rickrolls jailbroken phones
Category: Network Security & Hacking News/Latest Security News
Security researchers warn iPhone users of the ikee worm, which uses SSH default passwords to hack the smartphone and change the wallpaper to a Rick Astlee photo. A hacker from Wollongong, New South Wales ...Monday, 09 November 2009 -
How-to: Cloning a (Laptop) Hard Drive using DD over the network
Category: Network Security & Hacking News/Latest Security News
... your password too). nc -l -p 9901 | dd of=/dev/sdc and hit enter The -l is to set up Netcat to listen, and -p is to tell it what port to listen on. The of switch of DD is to tell DD where to save the ...Sunday, 08 November 2009 -
First iPhone worm targets modified handsets
Category: Network Security & Hacking News/Latest Security News
... to jailbreak their iPhones come with a service known as Secure Shell (SSH). This service allows the devices to be accessed remotely over the Internet with a special password. The trouble is that the most ...Sunday, 08 November 2009 -
Vuln: Apache Tomcat Windows Installer Insecure Password Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Apache Tomcat Windows Installer Insecure Password Vulnerability Read Full Article ...Sunday, 08 November 2009 -
Phish of Banca Agricola Popolare di Ragusa has no URL but is in an attachment
Category: Network Security & Hacking News/Latest Security News
In almost every phish email there is an URL leading to the phishingsite where you are asked for a login, password and other personal information. With the latest phish targeting Banca Agricola Popolare ...Sunday, 08 November 2009 -
Are You Being (Facebook) Phished?
Category: Network Security & Hacking News/Latest Security News
... instructs them to click the URL provided in the email message. When the user clicks the URL, it points them to a spoofed Facebook website where they are required to input their password only as their email ...Saturday, 07 November 2009 -
Security 2009 report
Category: Network Security & Hacking News/Latest Security News
... two sessions I liked much. The first one being Per Thorsheim (http://twitter.com/thorsheim) talking about passwords. His been studying the subject for almost a decade, and he has some interesting points. ...Friday, 06 November 2009 -
Singe sign-in gains ground
Category: Network Security & Hacking News/Latest Security News
There seems to be a persisting problem: how to remember the passwords to all the websites you use and that require you to login? For myself, I chose to use a password manager and have just one passwor... ...Friday, 06 November 2009 -
Bredolab surges to new heights thanks to Cutwail botnet
Category: Network Security & Hacking News/Latest Security News
... where Facebook Password Reset Confirmation was perhaps one of the most widespread campaigns targeting social network users. But let’s not forget DHL tracking emails or the Western Union Payment. ...Thursday, 05 November 2009 -
The Register: Google opens up OAuth to tackle password chores
Category: Network Security & Hacking News/Latest Security News
The Register: Google opens up OAuth to tackle password chores The Register: Google opens up OAuth to tackle password chores Read Full Article ...Wednesday, 04 November 2009 -
The Register: Google opens up OAuth to tackle password chores
Category: Network Security & Hacking News/Latest Security News
The Register: Google opens up OAuth to tackle password chores The Register: Google opens up OAuth to tackle password chores Read Full Article ...Wednesday, 04 November 2009 -
Business e-banking and the 6-figure password
Category: Network Security & Hacking News/Latest Security News
... installed a password-stealing Trojan horse program named Zeus. From there, the attackers were able to initiate unauthorized payroll payments to Cutshall and about 20 other individuals similarly recruited ...Wednesday, 04 November 2009 -
Shutting Twitter backdoors
Category: Network Security & Hacking News/Latest Security News
If a Twitter password falls into the wrong hands, merely changing the password is not sufficient - there is also OAuth access to be taken care of If a Twitter password falls into the wrong hands, merely ...Wednesday, 04 November 2009 -
Spike in Social Media Malware, Phishing Attacks
Category: Network Security & Hacking News/Latest Security News
E-mail scams targeting users of social media sites like Twitter and Facebook are blurring the lines between traditional phishing attacks and those designed to plant password-stealing malicious software ...Wednesday, 04 November 2009 -
Security Briefing – November 4th
Category: Network Security & Hacking News/Latest Security News
... Behind Facebook Ads – Mckeay Cracking Passwords in the Cloud – Electric Alchemy We need to do more than raise the bar – Developing Security FBI Says ‘Money Mule’ Scams Now Top $100 ...Wednesday, 04 November 2009 -
Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR
Category: Network Security & Hacking News/Latest Security News
Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR Read Full Article ...Tuesday, 03 November 2009 -
The Register: Amazon's EC2 brings new might to password cracking "calculated the cost of waging a brute-force attack on various types of passwords using cloud computing services offered by Amazon"
Category: Network Security & Hacking News/Latest Security News
The Register: Amazon's EC2 brings new might to password cracking calculated the cost of waging a brute-force attack on various types of passwords using cloud computing services offered by Amazon The ...Tuesday, 03 November 2009 -
Smoking (Cloud) Crack
Category: Network Security & Hacking News/Latest Security News
... did make.This was a brute force password attackIf you happen to intercept PGP communication between two people, there's ... Making waves in the infosec blogosphere today: Cracking a PGP-protected ZIP ...Tuesday, 03 November 2009 -
Facebook Phishing Campaign Pushes ‘Cocktail’ Attack
Category: Network Security & Hacking News/Global Security News
... them that the Facebook account passwords have been changed. The malware downloads a keylogger to collect credit card numbers, social security number, and other passwords We have already discussed ...Tuesday, 03 November 2009 -
Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR
Category: Network Security & Hacking News/Latest Security News
Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR Electric Alchemy: Cracking Passwords in the Cloud - Breaking PGP on EC2 with EDPR Read Full Article ...Tuesday, 03 November 2009 -
Cracking keys on the cheap in the cloud
Category: Network Security & Hacking News/Latest Security News
Multiple cheap virtual machines in the cloud are reducing the cost of brute force attacks on keys and passwords. Long and complex keys are still too tough a nut for this process to crack Multiple cheap ...Tuesday, 03 November 2009 -
The Register: Amazon's EC2 brings new might to password cracking "calculated the cost of waging a brute-force attack on various types of passwords using cloud computing services offered by Amazon"
Category: Network Security & Hacking News/Latest Security News
The Register: Amazon's EC2 brings new might to password cracking calculated the cost of waging a brute-force attack on various types of passwords using cloud computing services offered by Amazon ...Monday, 02 November 2009 -
Elite Loader Goes Public
Category: Network Security & Hacking News/Latest Security News
... users to upload additional software to targeted systems to steal passwords or deploy spam or distributed denial of service (DDoS) modules that other cybercriminals can use. The bot’s C&C also ...Monday, 02 November 2009