- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: Google Chrome prior to 3.0.195.32 Multiple Security Vulnerabilities
- Vuln: Multiple Horde Products Cross-Site Scripting Vulnerabilities and File Overwrite Vulnerability
- Vuln: Mod_Perl Path_Info Remote Denial Of Service Vulnerability
- Vuln: Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
- Vuln: FreeBSD 'fifo_vnops.c' Resource Leak Local Denial of Service Vulnerability
- Vuln: Citrix NetScaler and Access Gateway Denial Of Service Vulnerability
- Vuln: PDFLib 'open_basedir' Restriction Bypass Vulnerability
- Vuln: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
Search
Search Result
-
Fragus exploit pack’s pricy business model locks users in
Category: Network Security & Hacking News/Latest Security News
The $800 attack toolkit comes with a self-destruct mechanism after a certain time period Security researchers at Symantec are closely monitoring the Fragus exploit pack, an $800 package of tools developed ...Friday, 06 November 2009 -
Facebook and Myspace bolt Flash backdoors
Category: Network Security & Hacking News/Latest Security News
The social networking sites had both been overgenerous in giving out access rights to their servers As a result, Flash applets hosted on a malicious website would have been able to read all Facebook data ...Thursday, 05 November 2009 -
Sun Alert 272230 Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data
Category: Network Security & Hacking News/Global Security News
Product: Solaris 10, OpenSolarisTwo security vulnerabilities exist in the Apache 2 mod_perl2(3) module components which affect the Apache 2.0 web server bundled with Solaris 10 and the Apache 2.2 web server ...Wednesday, 04 November 2009 -
Vuln: Pablo Software Solutions Baby Web Server Multiple Request Remote Denial of Service Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Pablo Software Solutions Baby Web Server Multiple Request Remote Denial of Service Vulnerability Read Full ArticleWednesday, 04 November 2009 -
Facebook Phishing Campaign Pushes ‘Cocktail’ Attack
Category: Network Security & Hacking News/Global Security News
We have already discussed the Facebook phishing campaign. Now the scammers are using the phishing campaign not just for spamming but also for a cocktail attack. The scammers have targeted Facebook, telling ...Tuesday, 03 November 2009 -
Video: Tenable Appliance Installation & Configuration
Category: Network Security & Hacking News/Latest Security News
The Tenable Appliance is an easy way to get up and running quickly with Tenable products such as Nessus and Security Center. The Tenable Appliance is a virtual machine image that is compatible with: VMware ...Tuesday, 03 November 2009 -
Video: Tenable Appliance Installation & Configuration
Category: Network Security & Hacking News/Latest Security News
The Tenable Appliance is an easy way to get up and running quickly with Tenable products such as Nessus and Security Center. The Tenable Appliance is a virtual machine image that is compatible with: VMware ...Tuesday, 03 November 2009 -
Symantec patches Altiris solutions
Category: Network Security & Hacking News/Latest Security News
The web-based management servers install a vulnerable ActiveX control in Internet Explorer that allows attackers to inject and execute arbitrary code in a client The web-based management servers install ...Tuesday, 03 November 2009 -
Wave Federation Begins
Category: Network Security & Hacking News/Latest Security News
Google has begun allowing private Wave servers to connect to its Wave Sandbox, opening up the development of private collaboration servers Google has begun allowing private Wave servers to connect to ...Tuesday, 03 November 2009 -
Elite Loader Goes Public
Category: Network Security & Hacking News/Latest Security News
A few days ago, I got access to the source code of the well-known Elite Loader for free. Yes. It was published on one of the Russian underground forums. It even had a detailed description and screenshots ...Monday, 02 November 2009 -
Sun Alert 270476 Two Security Vulnerabilities in the Java Runtime Environment With Decoding DER Encoded Data and Parsing HTTP Headers may Result in a Denial of Service (DoS)
Category: Network Security & Hacking News/Global Security News
Product: Java Platform, Standard Edition (Java SE) Two vulnerabilities in the Java Runtime Environment with decoding DER encoded data and parsing HTTP headers may separately allow a remote client to cause ...Monday, 02 November 2009 -
Vuln: Retired: Cherokee Web Server Malformed Packet Remote Denial of Service Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Retired: Cherokee Web Server Malformed Packet Remote Denial of Service Vulnerability Read Full ArticleMonday, 02 November 2009 -
My WAF went W00F!
Category: Network Security & Hacking News/Latest Security News
We have finally made it this week into Mathieu Dessus'slist of fingerprinted WAFs. Wow! You're probably wondering by now what is this list and why should you care about it? Well, let me tell you all about ...Monday, 02 November 2009 -
Weekly Intelligence Summary: 2009 – 10 – 30
Category: Network Security & Hacking News/Latest Security News
Most of the threat activity for this week was directed towards Facebook and Twitter users. Large e-mail campaigns for password reset confirmations led to compromised Facebook accounts and Trojan installations, ...Monday, 02 November 2009 -
Email with subject “Hello Darling” contains Cutwail trojan
Category: Network Security & Hacking News/Latest Security News
MX Lab intercepted new emails containing a new variant of the Cutwail trojan listening to the names Win32:Cutwail-AA (Avast) or W32/Trojan3.BLU (F-Prot). At Virus Total, only 11 of the 41 AV engines detect ...Monday, 02 November 2009 -
Cutwail trojan variant out in the wild
Category: Network Security & Hacking News/Latest Security News
MX Lab is intercepting quite a lot of viruses these days. Since October 27th, 2009, when we reported about the Facebook Password Reset Confirmation-campaign, we notice an serious increase in viruses. We ...Friday, 30 October 2009 -
356 big reasons for UK CIOs to switch to encrypted drives revealed
Category: Network Security & Hacking News/Latest Security News
Reports that UK chief information officers reported a whacking 356 data loss incidents in the last 12 months - approaching double that of the year previous - should sent shivers down the spine of any self- ...Friday, 30 October 2009 -
Finjan says controlled access Web portals now prime target of cybercriminals
Category: Network Security & Hacking News/Latest Security News
As news of the Guardian web site hack broke on Sunday, Finjan, the business Internet security specialist, said that identity information on consumers and companies continues to be a prime target for criminal ...Friday, 30 October 2009 -
Finjan warns companies as China prepares for cyber-espionage
Category: Network Security & Hacking News/Latest Security News
A report commissioned by a US Congressional advisory panel monitoring the security implications of trading with China has warned that China has started spying on the US government and major companies. ...Friday, 30 October 2009 -
SanDisk Cruzer Enterprise Flash Drives Earn Certification
Category: Network Security & Hacking News/Latest Security News
SanDisk Corporation, the global leader in flash memory cards, today announced that the SanDisk Cruzer Enterprise FIPS edition secure USB flash drive has received Common Criteria EAL2 certification, making ...Friday, 30 October 2009 -
Defeating Zombies: Five Ways To Improve Defenses
Category: Network Security & Hacking News/Latest Security News
Defeating Zombies Attackers have a number of avenues leading directly into your network, and more importantly, into your data. Each week I read about new data losses, phishing scams and the release of ...Friday, 30 October 2009 -
Microsoft releases fix for crypto patch
Category: Network Security & Hacking News/Latest Security News
Designed to prevent the processing of spoofed SSL certificates, the patch also caused an important service to malfunction. As a result, Live Communications Server 2005 and Office Communications Server ...Friday, 30 October 2009 -
Understanding Risk
Category: Network Security & Hacking News/Latest Security News
People tend to not prioritize their risk correctly. SANS Top Cyber Security report in September 2009 pointed out that people are not patching third party applications or taking care of web servers correctly. ...Thursday, 29 October 2009 -
A closer look at Acunetix Web Vulnerability Scanner 6.5
Category: Network Security & Hacking News/Latest Security News
Web applications are accessible 24 hours a day, 7 days a week and control valuable data since they often have direct access to backend data such as customer databases. SSL and locked-down servers are ... ...Thursday, 29 October 2009 -
Upgraded to Windows 7? Find out which patches you need
Category: Network Security & Hacking News/Latest Security News
Windows users who have been unimpressed by the features (and problems) offered by Vista have been rushing out and buying Windows 7. The reviews, so far, have been largely favourable but, as is the case ...Thursday, 29 October 2009 -
CubeCart 4 session management bypass leads to administrator access
Category: Network Security & Hacking News/Global Security News
Release Date: 2009/10/29 Author: Bogdan Calin (bogdan acunetix com) Severity: Critical Vendor Status: Vendor has released an updated version Release Date: 2009/10/29 Author: Bogdan Calin (bogdan ...Thursday, 29 October 2009 -
Ubuntu 9.10 Karmic Koala released
Category: Network Security & Hacking News/Latest Security News
Released today, Ubuntu 9.10 Desktop Edition and Server Edition bring a host of new features and further position Ubuntu as a viable competitor to Windows 7. Ubuntu 9.10 features a redesigned, fas... Released ...Thursday, 29 October 2009 -
Links for 2009-10-28 [del.icio.us]
Category: Network Security & Hacking News/Latest Security News
Hackers Access Llywelyn's Pub Credit Server - Kansas City News Story - KMBC Kansas City This is goofy. First off, Credit Server would indicate a payment processor breach. Not likely the case if this one ...Wednesday, 28 October 2009 -
Sun Alert 269208 A Security Vulnerability With Verifying HMAC-based XML Digital Signatures in the XML Digital Signature Implementation Included With the Sun GlassFish Enterprise Server v2.1 may Allow Authentication to be Bypassed
Category: Network Security & Hacking News/Global Security News
Product: Sun GlassFish Enterprise Server v2.1 A security vulnerability with verifying HMAC-based XML digital signatures in the XML Digital Signature implementation included with webservices component of ...Wednesday, 28 October 2009 -
Sun Alert 270408 Security Vulnerabilities in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS) or Privilege Escalation
Category: Network Security & Hacking News/Global Security News
Product: Solaris 10, OpenSolaris Security vulnerabilities affecting the PostgreSQL software shipped with Solaris may allow an authenticated PostgreSQL user to cause a denial of service (DoS) to the PostgreSQL ...Wednesday, 28 October 2009 -
Vuln: Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability Read Full Article ...Wednesday, 28 October 2009 -
Wi-Fi Cable Modems Leave Customers Vulnerable
Category: Network Security & Hacking News/Latest Security News
PC World recently wrote a story about Wi-Fi cable modem routers and how a security hole left thousands of Time Warner customers vulnerable to hackers. Incredibly, the company isn’t responsible for uncovering ...Wednesday, 28 October 2009 -
OAMP: OpenBSD 4.6 + Chroot Apache + MySQL + PHP
Category: Network Security & Hacking News/Latest Security News
IntroductionI'm combining the OAMP howto with chroot from the start this time because it's really the proper and secure thing to do. You can read more about how chroot works in my last article about it, ...Wednesday, 28 October 2009 -
Installing OpenBSD 4.6, Virtual machine snapshots
Category: Network Security & Hacking News/Latest Security News
OpenBSD's install process changed for the first time in a very long time with the release of 4.6.For the most part, I feel like the changes are for the better. The install script asks fewer questions, ...Tuesday, 27 October 2009 -
Ongoing FDIC Spam Campaign Serves Zeus Crimeware
Category: Network Security & Hacking News/Latest Security News
An ongoing spam campaign impersonating The Federal Deposit Insurance Corporation, is attempting to drop zeus samples by enticing users into installing pdf.exe and word.exe. "Subject: FDIC has officially ...Tuesday, 27 October 2009 -
Another acquisition in the Web security service space — Cisco Systems acquires ScanSafe
Category: Network Security & Hacking News/Latest Security News
Cloud security service is hot, hot, hot. My last blog post highlighted the acquisition of Purewire by Barracuda earlier this month. Today, Cisco Systems announced the intention to acquire ScanSafe, another ...Tuesday, 27 October 2009 -
Toata Scanning for Zen Shopping Cart with Brain File
Category: Network Security & Hacking News/Latest Security News
If you've been a long time reader of this blog, then you know about our ongoing efforts to help stem the tide of web application infections. Here is another example of this effort in action. A couple of ...Tuesday, 27 October 2009 -
Event Analysis Training- Basic Virus Analysis
Category: Network Security & Hacking News/Latest Security News
I recently worked with a customer who asked for advice on the following “virus” events: They were seeing “virus” traffic more or less continually. If you run a network IDS, and operate a busy email server, ...Monday, 26 October 2009 -
Bredolab masked as Facebook Password Reset Confirmation
Category: Network Security & Hacking News/Latest Security News
MX Lab detected a new Bredolab variant masking itself as the Facebook Password Reset Confirmation. The From address in the email is shown as The Facebook Team service@facebook.com but the real SMTP from ...Monday, 26 October 2009 -
IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security
Category: Network Security & Hacking News/Latest Security News
Have you ever noticed how security often takes a back-seat when trying something new? When I am trying out a protocol out for the first time I barely skim the Security Considerations section of the RFC. ...Monday, 26 October 2009 -
Alleged critical vulnerability in Sun Java System Web Server
Category: Network Security & Hacking News/Latest Security News
A commercial exploit package allegedly contains a zero day exploit for Sun's web platform A commercial exploit package allegedly contains a zero day exploit for Sun's web platform Read Full Article ...Monday, 26 October 2009 -
Vuln: Sun Java System Web Server Unspecified Remote Buffer Overflow Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Sun Java System Web Server Unspecified Remote Buffer Overflow Vulnerability Read Full ArticleSunday, 25 October 2009 -
Vuln: Apache 'mod_proxy' Remote Denial Of Service Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Apache 'mod_proxy' Remote Denial Of Service Vulnerability Read Full Article ...Sunday, 25 October 2009 -
RSA Europe 2009 – Day 3 Recap
Category: Network Security & Hacking News/Latest Security News
The final day of RSA Europe 2009 was particularly special to me since it was my speaking debut at an RSA function. About 20 minutes before I was due to go on I tweeted 6 VMs, a slide deck and me typingeasy ...Sunday, 25 October 2009 -
Cybercrime Visualization on youtube
Category: Network Security & Hacking News/Latest Security News
Hi all, Team Cymru has posted a movie of some of the visualizations we've made on youtube. www.youtube.com/watch?v=8IBy87mVpcw This movie shows DDoS attacks, botnet command and control servers, malware ...Saturday, 24 October 2009 -
The Register: Google Spanner - instamatic redundancy for 10 million servers?
Category: Network Security & Hacking News/Latest Security News
The Register: Google Spanner - instamatic redundancy for 10 million servers? The Register: Google Spanner - instamatic redundancy for 10 million servers? Read Full ArticleSaturday, 24 October 2009 -
Microsoft anti-virus software dawdles over updates
Category: Network Security & Hacking News/Latest Security News
Tests by heise Security have show that in some situations Microsoft Security Essentials fails to download updates for a whole week, despite new anti-virus signatures being available to download from Microsoft's ...Friday, 23 October 2009 -
Fake email from Microsoft Update Center regarding update for Outlook
Category: Network Security & Hacking News/Latest Security News
MX Lab intercepted some messages coming from the Microsoft Update Center noreply@microsoft.com, an emailaddress that is obviously spoofed, with subjects like: * Install Update for Microsoft Outlook * Microsoft ...Friday, 23 October 2009 -
Paypal phishing: take online survey and receive money
Category: Network Security & Hacking News/Latest Security News
MX Lab is intercepting phishing messages that target PayPal users. The email comes from the spoofed address Pay Pal.Inc Account0909Sur@pay.com with the subject Confirm refund request Identity Verification. ...Friday, 23 October 2009 -
Vuln: Pidgin 'protocols/jabber/auth.c' JABBER Server XMPP Specifications Man In The Middle Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Pidgin 'protocols/jabber/auth.c' JABBER Server XMPP Specifications Man In The Middle Vulnerability Read Full ArticleThursday, 22 October 2009
