- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: eCryptfs 'parse_tag_3_packet()' Packet Heap Based Buffer Overflow Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Search
Search Result
-
Quickpost: SelectMyParent or Playing With the Windows Process Tree
Category: Network Security & Hacking News/Latest Security News
I read something very interesting in Windows via C/C++ today: starting with Windows Vista, CreateProcess can start a program where you specify the parent process! This is something forensic investigators ...Sunday, 22 November 2009 -
Best of Application Security (Friday, Nov. 20)
Category: Network Security & Hacking News/Latest Security News
... Reversing JavaScript Shellcode: A Step By Step How-To Brute-Forcing Compatibility Preventing Security Development Errors: Lessons Learned at Windows Live by Using ASP.NET MVC OWASP Board - Election Results ...Friday, 20 November 2009 -
GCN: Locking down Windows with virtualization
Category: Network Security & Hacking News/Latest Security News
GCN: Locking down Windows with virtualization GCN: Locking down Windows with virtualization Read Full Article ...Friday, 20 November 2009 -
Microsoft: No backdoor in Windows 7
Category: Network Security & Hacking News/Latest Security News
But NSA admits involvement in OS security guide But NSA admits involvement in OS security guide Read Full ArticleFriday, 20 November 2009 -
COFEE Break Turns Messy
Category: Network Security & Hacking News/Global Security News
... Working on Windows XP, COFEE consists of three major components: the GUI for the investigator, the command‐line application to be executed on the target machine, and the individual tools that are managed ...Friday, 20 November 2009 -
Curiosity as a Malicious PDF
Category: Network Security & Hacking News/Global Security News
... (CVE-2009-0927) vulnerabilities. This screenshot shows the beginning of the compressed JavaScript stream: In addition, two variants of ProcKill-EM are dropped into the Windows system folder, usually ...Friday, 20 November 2009 -
Computer World: Microsoft denies it built 'backdoor' in Windows 7 "Don't worry, company tells users; NSA involved only in security compliance standards"
Category: Network Security & Hacking News/Latest Security News
Computer World: Microsoft denies it built 'backdoor' in Windows 7 Don't worry, company tells users; NSA involved only in security compliance standards Computer World: Microsoft denies it built 'backdoor' ...Friday, 20 November 2009 -
PHP “multipart/form-data” denial of service
Category: Network Security & Hacking News/Global Security News
... tunable. 3. PHP on Windows: XAMPP ========================= XAMPP for Windows setup filename: xampp-win32-1.7.2.exe PHP Version 5.3.0 Timeline: 12:30 – started the attack 12:30 + few seconds: ...Thursday, 19 November 2009 -
Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability Read Full Article ...Thursday, 19 November 2009 -
Computer World: NSA helped with Windows 7 development
Category: Network Security & Hacking News/Latest Security News
Computer World: NSA helped with Windows 7 development Computer World: NSA helped with Windows 7 development Read Full Article ...Thursday, 19 November 2009 -
Update: bpmtk with hook-createprocess.dll
Category: Network Security & Hacking News/Latest Security News
There are no real changes in this new version of bpmtk, only a new DLL (hook-createprocess.dll) was added. You can use this DLL to protect your Windows machine from getting infected by the current malicious ...Thursday, 19 November 2009 -
JJ- Back in the lab: 802.1X and more
Category: Network Security & Hacking News/Latest Security News
... you! FYI. My current lab configuration uses Windows-based endpoints and servers. I have FreeRADIUS and Funk available as well, but most current play time will be conducted on Windows, including Windows ...Thursday, 19 November 2009 -
Security holes in Serv-U FTP server closed
Category: Network Security & Hacking News/Latest Security News
The 9.1.0.0 version of the Serv-U FTP Server for Windows closes two critical vulnerabilities which allow an attacker's code to infiltrate the system or restart it The 9.1.0.0 version of the Serv-U FTP ...Thursday, 19 November 2009 -
Are 64-bit Windows inherently safer?
Category: Network Security & Hacking News/Latest Security News
Microsoft has discovered a way to create the illusion that Windows 7 is more secure than its predecessors simply because it has a 64-bit version of the OS. As Joe Faulhaber of the Microsoft Malware... ...Wednesday, 18 November 2009 -
NSA helps Apple, Sun and Red Hat harden their systems
Category: Network Security & Hacking News/Latest Security News
The American National Security Agency also helped configure the system security of Windows 7 during the operating system's development The American National Security Agency also helped configure the ...Wednesday, 18 November 2009 -
Windows 7: The Definitive Guide: The Essential Resource for Professionals and Power Users (Paperback) newly tagged "operating systems"
Category: Network Security & Hacking Products/Operating Systems
Windows 7: The Definitive Guide: The Essential Resource for Professionals and Power Users (Paperback) By William R. Stanek Buy new: $37.79 30 used and new from $33.65 Customer ...Wednesday, 18 November 2009 -
Stop blaming the admins!
Category: Network Security & Hacking News/Latest Security News
... But what makes them a threat? Two thing: Everyone hates them so they are rarely updated (you know.. like Windows.. stay with me) Since they are rarely updated, and sometimes even those that are, are ...Wednesday, 18 November 2009 -
Microsoft Windows SMB Response Denial of Service Clarifications
Category: Network Security & Hacking News/Global Security News
A PoC was published recently on Full-Disclosure, completely hanging an up-to-date Windows 7 or Windows Server 2008 R2 system when an SMB connection is established to a malicious server. A PoC was published ...Wednesday, 18 November 2009 -
Computer World: 64-bit Windows safer, claims Microsoft "But lower infection rates for 64-bit won't stand, counters researcher"
Category: Network Security & Hacking News/Latest Security News
Computer World: 64-bit Windows safer, claims Microsoft But lower infection rates for 64-bit won't stand, counters researcher Computer World: 64-bit Windows safer, claims Microsoft "But lower infection ...Wednesday, 18 November 2009 -
New York cafe WiFi passwords show Mac versus PC reality
Category: Network Security & Hacking News/Latest Security News
... using a Windows PC. The picture was taken at the Lure Restaurant in New York City. Photograph depicts password needed to use cafe WiFi. The Apple blog, Cult of Mac posted a picture of the day depicting ...Tuesday, 17 November 2009 -
New Sasfis trojan in the wild
Category: Network Security & Hacking News/Latest Security News
... and several Windows registry modifications are executed. The trojan can make connection to the host 193.104.27.91 and request the following URLs: hxxp://193.104.27.91/limpopo/bb.php?id=&v=200&tm=2&b=4316315581 ...Tuesday, 17 November 2009 -
Microsoft warns of Windows 7 security hole
Category: Network Security & Hacking News/Latest Security News
Microsoft has confirmed reports of a security flaw in its Windows operating system that hackers could use to temporarily destabilize Windows 7 PCs. The software giant also acknowledged that blueprints ...Tuesday, 17 November 2009 -
Auditing 100,000 Hosts or More with Nessus
Category: Network Security & Hacking News/Latest Security News
... packets. One solution to this situation is to perform automated scheduled scans during defined scan windows - periods of time when a WAN connection is not heavily utilized such as off-peak business hours. ...Monday, 16 November 2009 -
Interesting Information Security Bits for 11/16/2009
Category: Network Security & Hacking News/Latest Security News
... a Car Multimedia System? Tags: ( fuzzing ) Want to some help on learning how to write windows stack-based exploits? Here you go. A whole mess of tutorials. The Professional Security Testers Warehouse ...Monday, 16 November 2009 -
Tenable Network Security Podcast - Episode 12
Category: Network Security & Hacking News/Latest Security News
Welcome to the Tenable Network Security Podcast - Episode 12 Announcements A new blog post has been released that covers my experiences scanning Windows 7 with the latest version of Nessus 4.2 (yet to ...Monday, 16 November 2009 -
Microsoft confirms 'detailed' Windows 7 exploit
Category: Network Security & Hacking News/Latest Security News
Exploit code for the vulnerability was released by researcher Laurent Gaffié after failed attempts to get Microsoft's security response center to acknowledge that this was an issue that needs to be patched. ...Monday, 16 November 2009 -
First Windows 7 zero-day bug confirmed by Microsoft
Category: Network Security & Hacking News/Latest Security News
The first Windows 7 vulnerability has been confirmed by Microsoft - a denial of service vulnerability in the Server Message Block (SMB) protocol that cannot be used to take control of or install malic... ...Monday, 16 November 2009 -
Check Point Awarded International Common Criteria EAL4 Certification for Full Disk Encryption
Category: Network Security & Hacking News/Latest Security News
... stays intact.” In addition to Full Disk Encryption for Windows, Mac OS X and Linux based computers, Check Point offers customers port and removable media protection through Check Point Media Encryption ...Monday, 16 November 2009 -
Check Point Positioned in the Leaders Quadrant of the Mobile Data Protection
Category: Network Security & Hacking News/Latest Security News
... and client with endpoint security.” In addition to Full Disk Encryption for Windows, Mac OS X and Linux based computers, Check Point offers customers port and removable media protection through Check ...Monday, 16 November 2009 -
Microsoft investigates vulnerability in Windows 7 and Server 2008 R2
Category: Network Security & Hacking News/Latest Security News
Microsoft is investigating a DoS vulnerability that can be exploited to cripple systems running Windows 7 or Windows Server 2008 R2. According to the vendor, however, no active attacks have been registered ...Sunday, 15 November 2009 -
Lifehacker: Stop Paying for Windows Security; Microsoft's Security Tools Are Good Enough
Category: Network Security & Hacking News/Latest Security News
Lifehacker: Stop Paying for Windows Security; Microsoft's Security Tools Are Good Enough Lifehacker: Stop Paying for Windows Security; Microsoft's Security Tools Are Good Enough Read Full Article ...Saturday, 14 November 2009 -
Microsoft confirms first Windows 7 zero-day bug
Category: Network Security & Hacking News/Global Security News
In a security advisory, Microsoft acknowledged that a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, could be used by attackers to cripple Windows 7 and Windows ...Friday, 13 November 2009 -
Man-in-the-middle attacks demoed on 4 smartphones
Category: Network Security & Hacking News/Latest Security News
Security researchers test four smartphones (Nokia N95, Windows HTC tilt, Android G1 and Apple iPhone 3G S) and demonstrate man-in-the-middle attacks conducted through compromised Wi-Fi spots. Security ...Friday, 13 November 2009 -
Security update for Apple's Safari Web browser
Category: Network Security & Hacking News/Latest Security News
Apple has shipped a new version of its Safari Web browser that fixes at least seven security vulnerabilities. The Safari 4.0.4 update is available for both Mac and Windows versions of the browser. Mac ...Friday, 13 November 2009 -
Patch Tuesday - November 2009
Category: Network Security & Hacking News/Latest Security News
... MS09-064 - Nessus Plugin ID 42438 (Credentialed Check) & Nessus Plugin ID 42443 (Uncredentialed Check) - This patch only affects Windows 2000 Servers. If you are running this operating system, you need ...Friday, 13 November 2009 -
Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash
Category: Network Security & Hacking News/Latest Security News
Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash Laurent Gaffi: Windows 7 / Server 2008R2 Remote Kernel Crash Read Full Article ...Thursday, 12 November 2009 -
Interesting Information Security Bits for 11/12/2009
Category: Network Security & Hacking News/Latest Security News
... released Tags: ( windows pentesting tools ) The Professional Security Testers Warehouse for the CEH GPEN QISP Q/ISP OPST CPTS – UCSniff 3.0 Released Tags: ( pentesting tools voip ) Researcher ...Thursday, 12 November 2009 -
c|net: Microsoft probing Windows 7 zero-day hole
Category: Network Security & Hacking News/Latest Security News
c|net: Microsoft probing Windows 7 zero-day hole c|net: Microsoft probing Windows 7 zero-day hole Read Full Article ...Thursday, 12 November 2009 -
Microsoft bracing for malware attacks from embedded fonts
Category: Network Security & Hacking News/Latest Security News
It's only a matter of time before malicious hackers start exploiting a critical Windows vulnerability via booby-trapped Web pages or Office (Word or PowerPoint) documents. It's only a matter of time ...Thursday, 12 November 2009 -
Scanning Windows 7 With Nessus 4.2
Category: Network Security & Hacking News/Latest Security News
Windows 7 - a "Shiny" New Operating System Most experts agree that producing Windows Vista was not a shining moment for Microsoft. It was plagued with problems from the start, including performance and ...Thursday, 12 November 2009 -
An Information Security Place Podcast – Episode 27
Category: Network Security & Hacking News/Latest Security News
... in Windows 7 – Link Here Awesomely funny story about an IT engineer in Iraq annoying the troops with some bogus war driving – Link Here Discussion Topic - Highlights from Michael’s NAISG Chapter Meeting ...Wednesday, 11 November 2009 -
DoS vulnerability in the SMB client of Windows 7 and Server 2008 R2
Category: Network Security & Hacking News/Latest Security News
A flaw in the SMB protocol implementation of the latest Windows versions can trigger a system crash. A successful attack only requires the client to make contact with a specially crafted server, which ...Wednesday, 11 November 2009 -
Computer World: Microsoft plugs 15 holes, including critical drive-by bug "Expect exploits soon for Windows' embedded font flaw, says researcher"
Category: Network Security & Hacking News/Latest Security News
Computer World: Microsoft plugs 15 holes, including critical drive-by bug Expect exploits soon for Windows' embedded font flaw, says researcher Computer World: Microsoft plugs 15 holes, including critical ...Wednesday, 11 November 2009 -
Why Room362?
Category: Network Security & Hacking News/Latest Security News
... asked how to register a domain and I took him through the whole process, set up my dinky 1.4ghz Celeron laptop as a Windows 2003 server as a Domain Controller with Exchange 2003 installed on it (yes I ...Wednesday, 11 November 2009 -
Apple Safari exposes Windows to drive-by download attacks
Category: Network Security & Hacking News/Latest Security News
A high-priority Safari update patches vulnerabilities that allow remote code execution (drive-by downloads) if a user simply surfs to a maliciously rigged Web site. A high-priority Safari update patches ...Wednesday, 11 November 2009 -
We need to learn more about the RBS Worldpay ATM attack
Category: Network Security & Hacking News/Latest Security News
... As an example, here is a paper on attacking the algoritm used by IBM 3624s which many ATMs are based on. Like password hash storage in Windows, backwards compatibility with older encryption formats can ...Wednesday, 11 November 2009 -
Major patch day for Excel
Category: Network Security & Hacking News/Latest Security News
What initially promised to be a relatively quiet patch day is turning into a patch orgy. Microsoft has announced six patch packages to fix a total of 15 "security vulnerabilities" in Microsoft Windows ...Tuesday, 10 November 2009 -
Animated Network Packet Structure Visualization
Category: Network Security & Hacking News/Latest Security News
... just what I have in there now.) The app then displays the packets over time....using a window of 1-N packets at a time (depending on the dataset, different windows help you see patterns you wouldnt otherwise). ...Tuesday, 10 November 2009 -
Vuln: Microsoft Windows 'KeAccumulateTicks()' SMB2 Packet Remote Denial of Service Vulnerability
Category: Network Security & Hacking News/Security Exploits and Security Patches
Microsoft Windows 'KeAccumulateTicks()' SMB2 Packet Remote Denial of Service Vulnerability Read Full Article ...Tuesday, 10 November 2009 -
Detailed study of MITM based Attack on Smartphones
Category: Web Links / Other Resources
... work: Devices tested: Nokia N 95 Windows HTC tilt T-Mobile G1 Android Apple iPhone 3G S 1. Detail information about how an attacker can perform the MITM attack on all the above devices to steal ...Friday, 06 November 2009