SECURITY RELATED RSS FEEDS

Latest Advisories/Security Related News

 
The Register - Security
Last Downloaded: Sat, 05 Jul 2008 11:47:22 GMT.
View The Raw XML Source Of The Register - Security. hide
  MS readies Vista code injection risk fix  

Redmond security gnomes get tough

Critical bug fixes are on the agenda for this month's monthly patch update from Microsoft.…

  Microsoft touts trustworthy browsing with IE8  

If it asks if you'd like to see some puppies, just say no

Microsoft has detailed a raft of security improvements due to appear in Internet Explorer 8. The second beta of Redmond's web browser will be packed full of features designed to thwart phishing and drive-by download attacks, Redmond explained on Wednesday.…

  Scareware runs amok on PlayStation site  

Sony gamed by hackers

Gamers visiting the US Sony PlayStation website risk malware infection after the site was hit by hackers.…

  Built-in browser expiry proposed to fight botnet menace  

45% fail to update surfing software, report finds

Nearly half (45.2 per cent) of all internet surfers neglect to regularly update their browser software. Slackness in applying updates in a timely fashion leaves an estimated 637 million surfers vulnerable to drive-by download attacks, according to a new survey.…

  UK most popular destination for 419 scams  

One in four Nigerian spams sent to Blighty

The United Kingdom is the most popular destination for 419 scams - emails which promise huge riches in exchange for up-front arrangement fees.…

  Tech giants team for online ID cards  

Passwords are so passé

A group of software and online payment companies are teaming up to find a better way than passwords to protect, and prove, your identity online.…

  19-year-old p2p botnet pioneer agrees to plead guilty  

'Nugache was mine'

The author of a Trojan that broke new ground by incorporating peer-to-peer technology into botnet design has agreed to plead guilty to secretly infecting thousands of victims' machines so that he could steal their personal data and launch attacks on websites.…

  Ankle-biting hackers storm net's overlords, hijack their domains  

IANA and ICANN succumb to NetDevilz

The websites of two of the net's most critical oversight organizations were hijacked by Turkish hackers who sent visitors to rogue pages that challenged the overseers' authority.…

  Singapore forum 'scammer' faces caning and prison  

Blagger facing flogging

A British man faces caning and a prison sentence for allegedly conning members of an IT forum in Singapore.…

  Microsoft and HP tackle SQL-injection scourge  

A modest proposal

With successful attacks against websites reaching epidemic levels, Microsoft and HP have released a free set of tools that help developers check their web applications for the mistakes that leave them open to exploits that can steal sensitive information and harm visitors.…

  Fired IT manager accused of venting spleen on organ bank  

$70,000 tissue tussle

A technology director who was fired from her job has been accused of hacking in to the organ donation company where she worked and deleting donor information and accounting files.…

  Security: Protect and survive with El Reg  

Get involved with the experts

Reg security debates El Reg invites you to tighten up your security as we hook up with some of the industry's biggest names and you - the UK's biggest technology community - for two live and fully interactive events exploring the latest menaces and threat-busting initiatives. Whether you're a CTO, developer, consultant or home user, if the security of your IT is important to you make sure these two are in your diary.…

  Trojan heralds OS X's 'new phase of exposure to malware'  

Modular malware comes to the Mac

The Mac security scene is heating up, with the discovery in recent weeks of a serious vulnerability in OS X and at least two Trojan horse programs that target the Apple OS.…

  Spam DDoS assault cuts off south Pacific state  

(Un)happy Talking

Citizens of the Marshall Islands in the South Pacific have been left without a functioning email systems following a denial of service attack on the country's sole ISP.…

  Dutch government gags Oyster researchers  

Don’t kill the messenger

The publication of a scientific paper by Radboud University that discusses design flaws of the MIFARE chip in cards such as the Oyster travelcard may be in jeopardy. Dutch secretary of state Tineke Huizinga has urged the university not to publish any secrets that may lead to abuse.…

  Yahoo! Mail! vuln! fixed!  

Buddy hacker account compromise risk plugged

Yahoo! has fixed a vulnerability that left users of its popular webmail service at risk of having their login credentials stolen.…

  Tennis sites hit by drive-by download attacks  

You cannot be serious

Two high-profile tennis websites are among scores of victims of a new wave of SQL injection attacks. The website of game regulators ITF and ATP, the professional players tour, were hit by automated attacks in the run-up to this week's Wimbledon championship.…

  HSBC scripting flaws play into the hands of phishers  

XSS calamity

Several HSBC websites are subject to scripting flaws that create a possible mechanism for crooks to create more convincing phishing scams.…

  Almost half of malicious sites tied to 10 networks  

China mostly to blame, but so is Google

Almost half the websites pushing malware are hosted by just 10 networks, according to a new report that adds new support to the growing argument that a relatively few number of actors are responsible for most of the net-based threats.…

  Scareware package greets marks by name  

Fakeale redux

Malware authors have created a strain of scareware packages that lifts the name of an infected user from the registry of an infected PC in order to create more convincing scams.…

 
SecurityFocus News
Last Downloaded: Sat, 05 Jul 2008 15:57:02 GMT.
View The Raw XML Source Of SecurityFocus News. hide
  News: Web surfers, it's time to patch  Web surfers, it's time to patch
  News: Breach-notification laws not working?  Breach-notification laws not working?
  News: Ransomware resisting crypto cracking efforts   Ransomware resisting crypto cracking efforts

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: Boycott spotlights antivirus testing issues  Boycott spotlights antivirus testing issues
  Brief: Apple closes holes in Mac OS X, Safari  Apple closes holes in Mac OS X, Safari
  Brief: World of Warcraft to get bank-like security   World of Warcraft to get bank-like security

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Brief: Feds: Companies need to report cybercrimes  Feds: Companies need to report cybercrimes
  Brief: EU advisors: Secure ISPs, form "cyber-NATO"  EU advisors: Secure ISPs, form "cyber-NATO"
  News: TJX employee fired for exposing shoddy security   TJX employee fired for exposing shoddy security

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: Thoughts of a Teenage Bot Master  Thoughts of a Teenage Bot Master
  News: Radio Free Europe hit by DDoS attack  Radio Free Europe hit by DDoS attack
  News: Flash vuln fells Vista   Flash vuln fells Vista

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: Nigeria enlists Microsoft to fight spam scammers  Nigeria enlists Microsoft to fight spam scammers
  News: Cross-Site Scripting Worm Hits MySpace  Cross-Site Scripting Worm Hits MySpace
  News: Another data security bill in the works   Another data security bill in the works

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: FTC sues company over spyware  FTC sues company over spyware
  Infocus: Integrating More Intelligence into Your IDS, Part 2  Integrating More Intelligence into Your IDS, Part 2
  Infocus: Integrating More Intelligence into Your IDS, Part 1   Integrating More Intelligence into Your IDS, Part 1

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Infocus: A Guide to Different Kinds of Honeypots  A Guide to Different Kinds of Honeypots
  Infocus: Proactively Managing Security Risk  Proactively Managing Security Risk
powered by zFeeder


Latest Security Files/Exploits

 
Packet Storm Security Last 20
Last Downloaded: Sat, 05 Jul 2008 13:59:27 GMT.
View The Raw XML Source Of Packet Storm Security Last 20. hide
  browser_insecurity_iceberg_2008.pdf  Understanding the Web browser threat: Examination of vulnerable online Web browser populations and the insecurity iceberg .
  SSRT080039.txt  HP Security Bulletin - A potential security vulnerability has been identified with HP System Management Homepage (SMH) for Linux and Windows. This vulnerability could by exploited remotely to allow cross site scripting (XSS).
  25C3-CFP.txt  The Call For Papers for the 25th Chaos Communication Congress (25C3) has been announced.
  SCANIT-2008-003.txt  Wordtrans versions 1.1pre15 and below suffer from a remote command execution vulnerability.
  SCANIT-2008-002.txt  Wordtrans versions 1.1pre15 and below suffer from a remote command execution vulnerability.
  SCANIT-2008-001.txt  QNX RTOS phgrafx version 6.3.2 and 6.3.0 suffer from a privilege escalation vulnerability.
  usurdat.zip  Proof of concept denial of service exploit for SOLDNER - Secret Wars versions 33724 and below which suffer from an endless loop vulnerability.
  usurdat.txt  SOLDNER - Secret Wars versions 33724 and below suffer from an endless loop vulnerability.
  glsa-200807-02.txt  Gentoo Linux Security Advisory GLSA 200807-02 - Nico Golde reported an off-by-one error within the read_client() function in the webhttpd.c file, leading to a stack-based buffer overflow. Stefan Cornelius (Secunia Research) reported a boundary error within the same function, also leading to a stack-based buffer overflow. Both vulnerabilities require that the HTTP Control interface is enabled. Versions less than 3.2.10.1 are affected.
  glsa-200807-01.txt  Gentoo Linux Security Advisory GLSA 200807-01 - Multiple integer overflows may allow for Denial of Service. Versions less than 2.4.4-r13 are affected.
  blogparticle-traverse.txt  Blog Particle version 8.0 suffers from directory traversal and database credential disclosure vulnerabilities.
  hbr-rfi.txt  HIOX Banner Rotator (HBR) version 1.3 suffers from a remote file inclusion vulnerability.
  0806-exploits.tgz  Packet Storm new exploits for June, 2008.
  mambongal-sql.txt  The Mambo n-gallery component suffers from multiple SQL injection vulnerabilities.
  psys070-sql.txt  pSys version 0.7.0 suffers from a remote SQL injection vulnerability in chatbox.php.
  pivot-disclosure.txt  Pivot version 1.40.5 Dreamwind load_template() credential disclosure exploit.
  USN-617-2.txt  Ubuntu Security Notice 617-2 - USN-617-1 fixed vulnerabilities in Samba. The upstream patch introduced a regression where under certain circumstances accessing large files might cause the client to report an invalid packet length error. This update fixes the problem. Samba developers discovered that nmbd could be made to overrun a buffer during the processing of GETDC logon server requests. When samba is configured as a Primary or Backup Domain Controller, a remote attacker could send malicious logon requests and possibly cause a denial of service. Alin Rad Pop of Secunia Research discovered that Samba did not properly perform bounds checking when parsing SMB replies. A remote attacker could send crafted SMB packets and execute arbitrary code.
  rcm-sql.txt  RCM Revision Web Development suffers from a remote SQL injection vulnerability in products.php.
  barenuked-admin.txt  BareNuked CMS version 1.1.0 arbitrary add administrator exploit.
  faname10-xss.txt  Fa Name version 1.0 suffers from multiple cross site scripting vulnerabilities.
 
milw0rm.com
Last Downloaded: Sat, 05 Jul 2008 11:23:47 GMT.
View The Raw XML Source Of milw0rm.com. hide
  Kasseler CMS 1.3.0 (LFI/XSS) Multiple Vulnerabilities  
  Thelia 1.3.5 Multiple Vulnerabilities Exploit  
  Site@School <= 2.4.10 (fckeditor) Session Hijacking / File Upload Exploit  
  Panda Security ActiveScan 2.0 (Update) Remote BOF Exploit  
  Joomla Component DBQuery <= 1.4.1.1 RFI Vulnerability  
  Joomla Component altas 1.0 Multiple Remote SQL Injection Exploit  
  1024 CMS <= 1.4.4 Multiple Remote/Local File Inclusion Vulnerabilities  
  pHNews CMS Multiple Local File Inclusion Vulnerabilities  
  phpWebNews 0.2 MySQL Edition (det) SQL Injection Vulnerability  
  phpWebNews 0.2 MySQL Edition (id_kat) SQL Injection Vulnerability  
powered by zFeeder