Last updated:
Mon Sep 6 01:14:01 2010 GMT
  2010 FIRST Annual Conference in Miami - Register now


Recent bugs
via SecurityFocus,
HP-UX Software Distributor Unspecified Local Privilege Escalation Vulnerability
Icarus 'PGN' File Remote Stack Buffer Overflow Vulnerability
Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
KSP '.m3u' File Buffer Overflow Vulnerability
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
Adobe Flash Player and AIR (CVE-2010-2214) Unspecified Memory Corruption Vulnerability
Linux Kernel Controller Area Network Protocol Local Privilege Escalation Vulnerability
Fedora SSSD Kerberos Authentication Security Bypass Vulnerability
Wireshark 0.10.8 to 1.0.14 and 1.2.0 to 1.2.9 Multiple Vulnerabilities
PDF-XChange Viewer 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
Recent advisories
via Secunia, US-CERT,
TA10-238A: Microsoft Windows Insecurely Loads Dynamic Libraries
TA10-231A: Adobe Reader and Acrobat Vulnerabilities
TA10-223A: Adobe Flash and AIR Vulnerabilities
TA10-222A: Microsoft Updates for Multiple Vulnerabilities
TA10-194A: Microsoft Updates for Multiple Vulnerabilities
TA10-194B: Oracle Updates for Multiple Vulnerabilities
TA10-162A: Adobe Flash and AIR Vulnerabilities
TA10-159A: Adobe Flash, Reader, and Acrobat Vulnerability
TA10-159B: Microsoft Updates for Multiple Vulnerabilities
TA10-131A: Microsoft Updates for Multiple Vulnerabilities
TA10-103A: Microsoft Updates for Multiple Vulnerabilities
TA10-103B: Oracle Updates for Multiple Vulnerabilities
TA10-103C: Adobe Reader and Acrobat Vulnerabilities
TA10-089A: Microsoft Internet Explorer Vulnerabilities
TA10-068A: Microsoft Updates for Multiple Vulnerabilities
TA10-055A: Malicious Activity Associated with "Aurora" Internet Explorer Exploit
TA10-040A: Microsoft Updates for Multiple Vulnerabilities
TA10-021A: Microsoft Internet Explorer Vulnerabilities
TA10-013A: Adobe Reader and Acrobat Vulnerabilities
TA10-012A: Oracle Updates for Multiple Vulnerabilities
Bugtraq Topics
via SecurityFocus,
Re: Re: IIS5.1 Directory Authentication Bypass by using ?:$I30:$Index_Allocation?
[security bulletin] HPSBMA02572 SSRT100082 rev.1 - HP Operations Agent Running on Windows, Local Elevation of Privileges and Remote Execution of Arbitrary Code
[ MDVSA-2010:170 ] wget
[SECURITY] [DSA-2102-1] New barnowl packages fix arbitrary code execution
VUPEN Security Research - Google Chrome Focus Processing Memory Corruption Vulnerability (VUPEN-SR-2010-249)
[USN-982-1] Wget vulnerability
[ MDVSA-2010:169 ] mozilla-thunderbird
Vulnerabilities in CMS WebManager-Pro
{PRL} Novell Netware OpenSSH Remote Stack Overflow
XSS vulnerability in Rumba CMS
Top Worms and Viruses
via Sophos,
Troj/Invo-Zip
W32/Netsky
Mal/EncPk-EI
Troj/Pushdo-Gen
Troj/Agent-HFU
Mal/Iframe-E
Troj/Mdrop-BTV
Troj/Mdrop-BUF
Troj/Agent-HFZ
Troj/Agent-HGT
Latest MS bulletins
via Microsoft,
MS10-060 - Critical: Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (2265906)
MS10-059 - Important: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege (982799)
MS10-058 - Important: Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886)
MS10-057 - Important: Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)
MS10-056 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)
MS10-055 - Critical: Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)
MS10-054 - Critical: Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)
MS10-053 - Critical: Cumulative Security Update for Internet Explorer (2183461)
MS10-052 - Critical: Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)
MS10-051 - Critical: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2079403)
Stock Watch
via Yahoo! Finance
Updated 9/3/2010
NASDAQ 2233.75 +33.74
JNPR 28.99 +0.71
SYMC 13.98 +0.01
CSCO 21.04 +0.52
MFE 47.35 +0.10
CKP 19.87 +0.44
MSFT 24.29 +0.35
IBM 127.58 +2.54
INTC 18.43 +0.15
AMD 6.09 +0.16
SNWL 0.00 N/A
CIC.TO 10.03 +0.03
CA 19.09 +0.42
TMICY.PK 29.39 +0.60
WBSN 20.67 -0.03
BCSI 21.55 +0.29
SCLD 0.00 N/A
CWDW.OB 0.06 -0.01
VRSN 30.10 +0.36
INTZ.OB 1.09 unch
TMWD 0.00 unch
PKTR 0.00 unch
FIRE 28.34 +0.70

 

Recent News

DSA-2103 smbind
Debian Security
sql injection

Germany to launch antibotnet program for consumers
Hack In The Box
Germany will soon launch a service to help consumers remove malicious software from their computers in an attempt to stem the spread of spam-sending botnets. The German Anti-Botnet Initiative, which has a budget of 2 million (US$2.7 million), is being fu

Quantum key distribution in superposition of "insecure" and "unneeded"
Hack In The Box
It's apparent that the physics lexicon has been dragged kicking and screaming out of the 19th century with a recent paper published in Nature Photonics titled "Hacking commercial quantum cryptography systems by tailored bright illumination." I never thoug

Hacker attacks raise cyber security concerns in Philippines
Hack In The Box
The vulnerability of the Philippines government web sites was again exposed by hackers last week, prompting renewed calls for the introduction of an updated Cybercrime Bill which has been on the legislative backburner for a decade. Ivan Uy, the recently

Hackers Give Sony Two Finger Salute After PS3 Ban Granted
Hack In The Box
Despite being granted a permanent ban on the sale of a PSJailbreak "dongle" Sony Computer Entertainment have been given a two finger salute by hackers who have now released the software for free on the Internet as PS Groove. The ban which was granted on

Armin van Buuren's credit card details for sale
Hack In The Box
Armin Van Buuren is one of the world's most well-known trance music DJs. He also apparently has had his credit card details stolen. Investigators with Ultrascan, a company that investigates credit card fraud and other kinds of online crime, were doing re

Apple had two months to fix critical QuickTime bug, says researcher
Hack In The Box
A critical bug in QuickTime was reported to Apple two months before a second researcher independently revealed the vulnerability this week, the director of a bug bounty program said today. The duplicate discovery was just one of an increasing number of o

U.N. exec: Cyberwar could be 'worse than tsunami'
Hack In The Box
International cyberwar would be "worse than a tsunami" and should be averted by a global cybersecurity peace treaty, according to the head of the International Telecommunication Union. Hamadoun Tour, who has been secretary-general of the U.N. agency sinc

Sun Tzu's 13 lessons to combat hackers
Hack In The Box
In January, it was discovered that more than 75,000 computer systems in 2500 companies around the world were hacked in one of the largest and most sophisticated attacks by cyber criminals. And a month later we saw the Australian Parliament website shutter

Samsung Galaxy Tab Rooted... A Month Before Release
Hack In The Box
The folks at Sera-Apps, a German group of Android developers, have not only managed to get their hands on a prototype of the Samsung Galaxy Tab a month before the device goes on sale, but they managed to root the device at IFA, the worlds largest consumer

Security flaw found in HP Printers
Hack In The Box
Web servers have become commonplace on just about every hardware device from printers to switches. Such an addition makes sense as all devices require a management interface and making that interface web accessible is certainly more user friendly than req

PS3 jailbreak adapted to Nokia N900, Palm Pre
Hack In The Box
Two weeks ago you'd have to pay an Australian importer for a specialized USB key. Four days ago open-source software let you roll your own. Today, there's no need for any of that -- you can hack your PS3 with a tethered smartphone. Working closely with th

Mark Hurd may take job at Oracle, report says
Hack In The Box
When Mark Hurd resigned unexpectedly from Hewlett-Packard last month he found an outspoken supporter in the form of Oracle CEO Larry Ellison. It appears now that Hurd may end up working for Ellison, according to a report Saturday in the Wall Street Journa

Music execs gunning for Android iTunes rival
Hack In The Box
If you don't like Apple's arrogant presence and its mindset that being its customer is a privilege, you're not alone. Music companies are very eager to get on Google's side as it seems more likely that a new service will launch on Android. In a Los Angel

Accidental Pirate tightens disclosure rule
Hack In The Box
The pro-copyright lobby group behind the Accidental Pirate website has changed a legal clause that allowed it to disclose the personal information of users to any third party. iTnews reported earlier this week that the clause had raised suspicions that t

Malaysian web crackdown
Hack In The Box
Malaysia has formed a taskforce to scour the internet for blog postings deemed harmful to national unity, in the latest action against new media. The Home Ministry's deputy secretary-general for security, Abdul Rahim Mohamad Radzi, said the unit would in

Microsoft Claims Silverlight Beats HTML5
Hack In The Box
While acknowledging the importance of HTML5, Microsoft stressed this week that its Silverlight rich Internet technology extends the Web beyond what HTML5 allows. Standards-based multimedia features offered by HTML5 have taken the spotlight lately from pr

TSA accidentally reveals airport security secrets
Hack In The Box
The Transportation Security Administration inadvertently revealed closely guarded secrets related to airport passenger screening practices when it posted online this spring a document as part of a contract solicitation, the agency confirmed Tuesday. The

Nasty Data-Stealing Bug Haunts Internet Explorer 8
Hack In The Box
There's an unpatched vulnerability in Internet Explorer 8 that enables simple data-stealing attacks by Web-based attackers and could lead to an attacker hijacking a user's authenticated session on a third-party site. The flaw, which a researcher said may

HP-UX Security patch : PHCO_41200
Nessus.org Plugins
Synopsis :

The remote host is missing HP-UX PHCO_41200 security update

Description :

Software Distributor Cumulative Patch

Solution :

HP-UX Security patch : PHCO_41201
Nessus.org Plugins
Synopsis :

The remote host is missing HP-UX PHCO_41201 security update

Description :

Software Distributor Cumulative Patch

Solution :

HP-UX Security patch : PHCO_41202
Nessus.org Plugins
Synopsis :

The remote host is missing HP-UX PHCO_41202 security update

Description :

11.31 Software Distributor Cumulative Patch

Solution :

Debian Security Advisory - New smbind packages fix sql injection (DSA-2103-1)
Help Net Security - Advisories
- ------------------------------------------------------------------------ Debian Security Advisory DSA-2103-1 security@debian.org http://www.debian.org/security/ ...

US Department of Defense and National Policy, (Sun, Sep 5th)
SANS Internet Storm Center, InfoCON: green
A recent article released by the US Department of Defense (DoD) spoke of the worst compromise in DoD ...(more)...

Vigil@nce - IIS: authentication bypass via Index_Allocation
Vigil@nce - public vulnerabilities
An attacker can use an Alternate Data Stream, in order to access to files located in a directory protected by an IIS authentication.

Google pays $8.5m to settle Buzz privacy invasion suit
The Register - Security

The price of a Tweetbookish Gmail mod

Google has agreed to pay $8.5 million to settle a class action lawsuit claiming it violated the privacy of Gmail users when it released Google Buzz, a Gmail bolt-on that turned the email service into a Twe

[DSA2102] DSA-2102-1 barnowl
Nessus.org Plugins
Synopsis :

The remote host is missing the DSA-2102 security update

Description :

It has been discovered that in barnowl, a curses-based instant-messaging
client, the return codes of calls to the ZPending and ZR

Fedora 12 2010-12847
Nessus.org Plugins
Synopsis :

The remote host is missing the patch for the advisory FEDORA-2010-12847.

Description :

Small Footprint CIM Broker (sfcb) is a CIM server conforming to the
CIM Operations over HTTP protocol.
It

Fedora 13 2010-13127
Nessus.org Plugins
Synopsis :

The remote host is missing the patch for the advisory FEDORA-2010-13127.

Description :

This module is aimed at environments with central file servers that a
user wishes to mount on login and unmount

Fedora 12 2010-13155
Nessus.org Plugins
Synopsis :

The remote host is missing the patch for the advisory FEDORA-2010-13155.

Description :

A library for:
- rbtree with key-value pair extension
- deques (double-ended queues) (Stacks (LIFO) / Queu

Fedora 13 2010-13388
Nessus.org Plugins
Synopsis :

The remote host is missing the patch for the advisory FEDORA-2010-13388.

Description :

Python 3 is a new version of the language that is incompatible with the 2.x
line of releases. The language is mo

FreeBSD : lftp -- multiple HTTP client download filename vulnerability (5303)
Nessus.org Plugins
Synopsis :

The remote host is missing a security update

Description :

The following package needs to be updated: lftp

See also :

FreeBSD : wget -- multiple HTTP client download filename vulnerability (5304)
Nessus.org Plugins
Synopsis :

The remote host is missing a security update

Description :

The following package needs to be updated: wget-devel

See also :

Device Information (devinfo.xml)
Nessus.org Plugins
Synopsis :

The remote web server provides device information.

Description :

It was possible to download the file 'devinfo.xml' from the remote
web server.

This file is intended to be read by a set

Investigating Malicious Website Reports, (Sat, Sep 4th)
SANS Internet Storm Center, InfoCON: green
This morning we received a report from Holger about a website that was triggering ale ...(more)...

What's not to Like about "Like?", (Sat, Sep 4th)
SANS Internet Storm Center, InfoCON: green
Get off of my lawn! I admidt that I have a suspicous, curmedgeonly strea ...(more)...

Internet Explorer 8 kwetsbaar voor DLL-kapers
Security.NL nieuws
Hackers hebben een exploit voor Internet Explorer 8 online gezet, waarmee het mogelijk is om kwaadaardige code op systemen uit te voeren.

Nederland belangrijkste doelwit Roemeense skimmers
Security.NL nieuws
Nederland is het belangrijkste doelwit van Oost-Europese skimmers geworden, die op grote schaal pinpassen kopiren.

Afgesloten botnet bevat 78GB aan e-mailadressen
Security.NL nieuws
Het Pusdo-botnet dat vorig week kortstondig werd afgesloten, bevatte 78GB aan e-mailadressen, zo hebben onderzoekers ontdekt.

Google vereenvoudigt privacybeleid
Security.NL nieuws
Het privacybeleid van Google is voor de meeste mensen te lastig om te begrijpen, daarom gaat de zoekgigant verschillende aanpassingen doorvoeren.

Nigeriaanse 419 scammer krijgt 12,5 jaar cel
Security.NL nieuws
Een Nigeriaanse man die internetgebruikers voor 1 miljoen euro oplichtte, is in de Verenigde Staten tot een gevangenisstraf van 12,5 jaar veroordeeld.

"Einde bankafschrift goed nieuws voor malware"
Security.NL nieuws
Het verdwijnen van het papieren bankafschrift is goed nieuws voor virusschrijvers, dat zegt Righard Zwienenberg van anti-virusbedrijf Norman tegenover Security.nl.

HCCnet.nl op blacklist door gehackte gebruiker
Security.NL nieuws
Door de acties van een gehackte gebruiker is de website home.hccnet.nl op zowel de blacklist van Norton als Firefox terechtgekomen.

Microsoft Tool 'Hardens' Mission Critical Apps
InternetNews.com Security News
The new Enhanced Mitigation Experience Toolkit 2.0 is designed to head off potential security threats.

DSA-2102 barnowl
Debian Security
unchecked return value

Older News

Apple's Ping Inundated with Spam Comments (PC Magazine)
Yahoo! News: Security News

Facebook Glitch Let Spammer Post to Walls (PC World)
Yahoo! News: Security News

Apple Releases Two Security Updates (One for OSX, One for iTunes) : http://support.apple.com/kb/HT4312 and http://support.apple.com/kb/HT4328, (Fri, Sep 3rd)
SANS Internet Storm Center, InfoCON: green

Fedora 12 2010-12255
Nessus.org Plugins

Fedora 13 2010-12271
Nessus.org Plugins

Fedora 13 2010-13416
Nessus.org Plugins

Fedora 12 2010-13427
Nessus.org Plugins

Fedora 13 2010-13549
Nessus.org Plugins

Fedora 12 2010-13557
Nessus.org Plugins

Fedora 12 2010-13696
Nessus.org Plugins

Fedora 12 2010-13903
Nessus.org Plugins

[GLSA-201009-01] wxGTK: User-assisted execution of arbitrary code
Nessus.org Plugins

MDVSA-2010:169: mozilla-thunderbird
Nessus.org Plugins

MDVSA-2010:170: wget
Nessus.org Plugins

SuSE9 Security Update: Security update for IBM Java (12626)
Nessus.org Plugins

USN982-1 : wget vulnerability
Nessus.org Plugins

Google, Skype Targeted in India Security Crackdown
Enterprise Security Today

U.N. Official Calls BlackBerry Data Requests Legitimate
Enterprise Security Today

Consumer Watchdog Attacks Google in Times Square
Enterprise Security Today

Spammers Take Over Apple's New Ping Social Network
Enterprise Security Today

Nigerian man gets 12 years for $1.3m 419 scam
The Register - Security

iTunes Ping's Latest Problem: Spam (Mashable)
Yahoo! News: Security News

Germany to Launch Antibotnet Program for Consumers (PC World)
Yahoo! News: Security News

Spammers Take Over Apple's New Ping Social Network (NewsFactor)
Yahoo! News: Security News

VMware Tools for Windows Remote Binary Planting Vulnerability
SecuriTeam.com

VMware Tools for Windows Local Binary Planting Vulnerability
SecuriTeam.com

Vigil@nce - WebSphere AS: vulnerability of JAX-WS
Vigil@nce - public vulnerabilities

Black hole discovery could boost quantum computers
Techworld.com Security News

Apple's Ping a Scammer's Haven? Security Experts Say Watch Out (PC World)
Yahoo! News: Security News

U.N. exec: Cyberwar could be 'worse than tsunami'
CNET News.com - Security

Apple's Ping dinged by spam
CNET News.com - Security

Debian Security Advisory - New barnowl packages fix arbitrary code execution (DSA-2102-1)
Help Net Security - Advisories

SUSE Security Announcement - kernel (SUSE-SA:2010:038)
Help Net Security - Advisories

Virtualize your browser to prevent drive-by malware attacks
LinuxSecurity.com - Latest News

Security program automatically tracks down missing patches
LinuxSecurity.com - Latest News

Spammers curse Apple's new Ping service with iPhone scams
Sophos security news

Onapsis to launch ERP vulnerability testing suite
Techworld.com Security News

Foute netwerkconfiguratie voorname oorzaak aanvallen
Security.NL nieuws

Google topman Schmidt is 'evil ijscoman'
Security.NL nieuws

"Sun Tzu's 13 lessen om hackers te bestrijden"
Security.NL nieuws

Microsoft silent on Windows apps vulnerable to DLL hijacking attacks
Techworld.com Security News

Facebook introduces new security measures to kick out spammers
Techworld.com Security News

Women are better at protecting corporate secrets
Techworld.com Security News

Monsterpatch Google Chrome dicht 16 lekken
Security.NL nieuws


all content is copyright its respective owner or owners. the tools and components behind this page are copyright © 2003-2010 jose nazario, all rights reserved. this page is available as RSS 2.0.