recent infosec news http://www.infosecdaily.net/ Recent infosec news from dozens of sites around the world en-us jose@monkey.org Copyright 2008 2008-10-14T13:11:17 recent infosec news http://www.infosecdaily.net/infosec-daily.gif http://www.infosecdaily.net/ 144 35 Recent infosec news from dozens of sites arond the world Fake Microsoft security update spammed out to coincide with Patch Tuesday http://www.sophos.com/pressoffice/news/articles/2008/10/malicious-microsoft-update.html?_log_from=rss FrSIRT - Linksys WAP4400N Denial of Service and SNMPv3 Issues http://www.frsirt.com/english/advisories/2008/2805 FrSIRT - Lenovo Rescue and Recovery Privilege Escalation Vulnerability http://www.frsirt.com/english/advisories/2008/2806 FBI gebruikt illegale hackersite als lokaas http://www.security.nl/artikel/23302/1/FBI_gebruikt_illegale_hackersite_als_lokaas.html Google verdient miljoenen aan typosquatting http://www.security.nl/artikel/23303/1/Google_verdient_miljoenen_aan_typosquatting.html Chinese criminelen manipuleren pinautomaat in supermarkt http://www.security.nl/artikel/23304/1/Chinese_criminelen_manipuleren_pinautomaat_in_supermarkt.html LG ontwikkelt privacy-beeldscherm voor laptops http://www.security.nl/artikel/23305/1/LG_ontwikkelt_privacy-beeldscherm_voor_laptops.html Britse ambtenaren ontslagen wegens datamisbruik http://www.security.nl/artikel/23306/1/Britse_ambtenaren_ontslagen_wegens_datamisbruik_.html MS roll out exploit prediction with Patch Tuesday http://go.theregister.com/feed/www.theregister.co.uk/2008/10/14/ms_vulnerability_assessment/ Here is the attack forecast

Microsoft plans to debut impact predictions related to vulnerabilities with the next edition of its Patch Tuesday update cycle.

]]>
DarkMarket carder forum revealed as FBI sting http://go.theregister.com/feed/www.theregister.co.uk/2008/10/14/darkmarket_sting/ Cybercrooks bamboozled

Leaked documents have confirmed that carder forum DarkMarket was actually an FBI sting operation.

]]>
[3/5] RaidenFTPD Directory Name Buffer Overflow Vulnerability http://secunia.com/Advisories/32216/
http://secunia.com/Advisories/32216/

NOTE: This R ]]>
Apache and Setting Up SSL http://www.linuxsecurity.com/content/view/143141?rdf LinuxSecurity.com: The self-signed certificate is a certificate that you can create yourself that will provide SSL encryption but without the verification of your website from an outside source. The outside verification does cost ]]> Google's Android: Beware the malware? http://networks.silicon.com/mobile/0,39024665,39313847,00.htm GoogleNew threats ahead, warns security researcher

]]>
MoD admits losing nearly 2m recruits' details http://software.silicon.com/security/0,39024655,39313849,00.htm Home Office turns down Nasa hacker's appeal http://management.silicon.com/government/0,39024677,39313852,00.htm Vuln: Red Hat OpenSSH Backdoor Vulnerability http://www.securityfocus.com/bid/30794 Vuln: vsftpd FTP Server Pluggable Authentication Module (PAM) Remote Denial of Service Vulnerability http://www.securityfocus.com/bid/30364 FrSIRT - FUJITSU Products "RemoteFilterValve" Security Bypass Vulnerability http://www.frsirt.com/english/advisories/2008/2800 FrSIRT - WinFTP "PASV" Command Remote Denial of Service Vulnerability http://www.frsirt.com/english/advisories/2008/2801 FrSIRT - NoticeWare Email Server POP3 Remote Denial of Service Vulnerability http://www.frsirt.com/english/advisories/2008/2802 FrSIRT - XM Easy Personal FTP Server Remote Denial of Service Vulnerability http://www.frsirt.com/english/advisories/2008/2803 FrSIRT - RaidenFTPD "CWD" and "MLST" Commands DoS Vulnerability http://www.frsirt.com/english/advisories/2008/2804 Security suites fail exploit tests http://rss.feedsportal.com/c/270/f/3551/s/21df08c/l/0L0Stechworld0N0Csecurity0Cnews0Cindex0Bcfm0DRSS0GNewsID0F10A5674/story01.htm Atrocious preformance by leading suites.

Security suites don't protect users from real-world exploits, a bug tracking company has claimed after launching 300 test attacks against a dozen programs, including popular software from M ]]> Windows hit by fake security emails http://rss.feedsportal.com/c/270/f/3551/s/21e13cc/l/0L0Stechworld0N0Csecurity0Cnews0Cindex0Bcfm0DRSS0GNewsID0F10A5679/story01.htm Haxdoor malware tries new technique.

Scammers are sending out fake emails that claim to include critical Windows security alerts, Microsoft warned Monday.

Autisme kan NASA-hacker McKinnon niet redden http://www.security.nl/artikel/23301/1/Autisme_kan_NASA-hacker_McKinnon_niet_redden.html Use Gmail to fight spam http://www.networkworld.com/news/2008/101308-use-gmail-to-fight.html?fsrc=rss-security Europe and the U.S.: The one way mirror http://www.networkworld.com/news/2008/101308-europe-and-the-us-the.html?fsrc=rss-security Blue Coat, partners pitch less expensive data-leak prevention http://www.networkworld.com/news/2008/101308-blue-coat-dlp.html?fsrc=rss-security When the watchdog is the underdog http://www.networkworld.com/news/2008/101308-when-the-watchdog-is-the.html?fsrc=rss-security Microsoft readies first attack forecast http://www.networkworld.com/news/2008/101308-microsoft-readies-first-attack.html?fsrc=rss-security 'Experimental' security fix is malware, Microsoft says http://www.networkworld.com/news/2008/101308-experimental-security-fix-is-malware.html?fsrc=rss-security [3/5] Avaya Products Red Hat Tampered OpenSSH Packages http://secunia.com/Advisories/32241/
http://secunia.com/Advisories/32241/

NOTE: This RSS feed does not include information abo ]]>
[2/5] Debian update for linux-2.6 http://secunia.com/Advisories/32237/
http ]]>
[3/5] ENOVIA Document Viewer Security Bypass http://secunia.com/Advisories/32105/
http://secunia.com/Advisories/32105/

NOTE: ]]> [3/5] Avaya AES / MX Apache Tomcat Multiple Vulnerabilities http://secunia.com/Advisories/32266/ [3/5] Avaya Products libxml2 XML Entity Name Buffer Overflow Vulnerability http://secunia.com/Advisories/32265/
http://secunia.com/Advisories/32263/
[3/5] Linksys WAP4400N Denial of Service and SNMPv3 Vulnerability http://secunia.com/Advisories/32259/
http://secunia.co ]]>
[1/5] Firefox .url Shortcut File Information Disclosure http://secunia.com/Advisories/32192/
http://secunia.com/Advisories/32192/

NOTE: This RSS f ]]> [2/5] Lenovo Rescue and Recovery "tvtumon.sys" Privilege Escalation http://secunia.com/Advisories/32252/
http://secunia.com/Advisories/32252/
[3/5] IndexScript "parent_id" SQL Injection Vulnerability http://secunia.com/Advisories/32173/
http://secunia.com/Advisories/32173/

NOTE: This R ]]>
Security Suites falen detectie exploits http://www.security.nl/artikel/23298/1/Security_Suites_falen_detectie_exploits.html [DSA1650] DSA-1650-1 openldap2.3 http://www.nessus.org/plugins/index.php?view=single&id=34386 Cameron Hotchkies discovered that the OpenLDAP server slapd, a free
implementation of the Lightweight Directory Access Protocol, could be
crashed by sending malformed ASN1 requests.
For the stable distribution (etch), this problem ]]>
[DSA1651] DSA-1651-1 ruby1.8 http://www.nessus.org/plugins/index.php?view=single&id=34387 Several vulnerabilities have been discovered in the interpreter for
the Ruby language, which may lead to denial of service and other
security problems. The Common Vulnerabilities and Exposures project
identifies the following prob ]]>
[DSA1652] DSA-1652-1 ruby1.9 http://www.nessus.org/plugins/index.php?view=single&id=34388 Several vulnerabilities have been discovered in the interpreter for
the Ruby language, which may lead to denial of service and other
security problems. The Common Vulnerabilities and Exposures project
identifies the following prob ]]>
FreeBSD : drupal -- multiple vulnerabilities (1174) http://www.nessus.org/plugins/index.php?view=single&id=34389 The remote host is missing an update to the system

The following package is affected: drupal5

Solution : Update the package on the remote host
See also :
]]>
FreeBSD : mysql -- command line client input validation vulnerability (1172) http://www.nessus.org/plugins/index.php?view=single&id=34390 The remote host is missing an update to the system

The following package is affected: mysql-client

Solution : Update the package on the remote host
See also :
]]>
FreeBSD : cups -- multiple vulnerabilities (1173) http://www.nessus.org/plugins/index.php?view=single&id=34391 The remote host is missing an update to the system

The following package is affected: cups-base

Solution : Update the package on the remote host
See also :
]]>
Steal This Comic http://www.bspcn.com/2008/10/13/steal-this-comic/ World Bank denies hackers pwned key systems http://www.hackinthebox.org/index.php?name=News&file=article&sid=28630 Shell-shocked banks must safeguard data http://www.hackinthebox.org/index.php?name=News&file=article&sid=28631 Big leap in malicious Web sites http://www.hackinthebox.org/index.php?name=News&file=article&sid=28632 Cybercrime Supersite 'DarkMarket' Was FBI Sting, Documents Confirm http://www.hackinthebox.org/index.php?name=News&file=article&sid=28633 Top security suites fail exploit tests http://www.hackinthebox.org/index.php?name=News&file=article&sid=28634 Hackers hijack Patch Tuesday http://www.hackinthebox.org/index.php?name=News&file=article&sid=28635 WiFi in hotels provide security risks to users http://www.hackinthebox.org/index.php?name=News&file=article&sid=28636 Vietnamese student hacker arrested http://www.hackinthebox.org/index.php?name=News&file=article&sid=28637 Bush Signs Law Creating Copyright Czar http://www.hackinthebox.org/index.php?name=News&file=article&sid=28638 Hoping for AppleTV update at Apples notebook event http://www.hackinthebox.org/index.php?name=News&file=article&sid=28639 NSW Govt advised to give students Linux laptops http://www.hackinthebox.org/index.php?name=News&file=article&sid=28640 Microsoft to buy BlackBerry http://www.hackinthebox.org/index.php?name=News&file=article&sid=28641 Nokia poised to unveil first touchscreen N-Series http://www.hackinthebox.org/index.php?name=News&file=article&sid=28642 RSA survey shows employees everyday behaviours puts sensitive business information at risk http://www.hackinthebox.org/index.php?name=News&file=article&sid=28643 PSP And PS3 Gets Updates http://www.hackinthebox.org/index.php?name=News&file=article&sid=28644 Mozilla Labs pursues Web dev tools http://www.hackinthebox.org/index.php?name=News&file=article&sid=28645 Microsoft ready for Silverlight's second act http://www.hackinthebox.org/index.php?name=News&file=article&sid=28646 Survey: IT execs afraid of job losses http://www.hackinthebox.org/index.php?name=News&file=article&sid=28647 HP to manage PC manufacturing plant in China http://www.hackinthebox.org/index.php?name=News&file=article&sid=28648 Blackmailing hacker hijacks hotel emails http://www.hackinthebox.org/index.php?name=News&file=article&sid=28649 Reinventing SIP http://www.hackinthebox.org/index.php?name=News&file=article&sid=28650 Massive quantum network unveiled http://www.hackinthebox.org/index.php?name=News&file=article&sid=28651 Whopper of a Microsoft Patch Day for October http://www.watchguard.com/RSS/showarticle.aspx?pack=RSS.MS.Oct08.notify DSA-1653 linux-2.6 http://www.debian.org/security/2008/dsa-1653 Day 14 - Containment: a Personal IdentityTheft Incident, (Tue, Oct 14th) http://isc.sans.org/diary.php?storyid=5179&rss 'Experimental' security fix is malware, Microsoft says http://feeds.computerworld.com/click.phdo?i=3f68dd490b2471d1cea8a568f838fcb3 'Experimental' security fix is malware, Microsoft says http://feeds.computerworld.com/click.phdo?i=d9d485e8f4f2b25e7c1fbed760baf1e7 'Experimental' security fix is malware, Microsoft says http://feeds.computerworld.com/click.phdo?i=6c893f5eb76d9733ba4d86266f8893a7 'Experimental' security fix is malware, Microsoft says http://feeds.computerworld.com/click.phdo?i=017c9051f5661567bd6ec5881034ac13 'Experimental' security fix is malware, Microsoft says http://feeds.computerworld.com/click.phdo?i=df859adfc5799b728905c3e10a93b038 Bugtraq: [SECURITY] [DSA 1653-1] New Linux 2.6.18 packages fix several vulnerabilities http://www.securityfocus.com/archive/1/497297 Vuln: Linux Kernel 'truncate()' Local Privilege Escalation Vulnerability http://www.securityfocus.com/bid/31368 Brief: Apple closes open-source flaws with latest patch http://www.securityfocus.com/brief/837?ref=rss Google Downplays Talk of Security Vulnerabilities http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/73iioSz_bE8/ Judge orders Palin to preserve Yahoo e-mails http://feeds.computerworld.com/click.phdo?i=2c6a31cc4c295f22218e4ac957d8c11b MIT: Dirty coal to blame for China pollution--In a rare independent study of China's energy sector, researchers have found that ]]> Inside CNET Labs 17: Terrorize 'This'! http://www.cnet.com/8301-17914_1-10064479-89.html?part=rss&subj=news&tag=2547-1009_3-0-10 Security software performs poorly in exploit test http://www.networkworld.com/news/2008/101308-security-software-performs-poorly-in.html?fsrc=rss-security Top security suites fail exploit tests http://feeds.computerworld.com/click.phdo?i=0195700c49eb0c8c473f1cbf1ee1d48b Top security suites fail exploit tests http://feeds.computerworld.com/click.phdo?i=e31ea9c72f152aa22337aeebd688a122 Top security suites fail exploit tests http://feeds.computerworld.com/click.phdo?i=d0fa74165d9d06cc805f08068355f58e Top security suites fail exploit tests http://feeds.computerworld.com/click.phdo?i=56bdd455bea89fb5155f320c380aa872