SECURITY RELATED RSS FEEDS

Latest Advisories/Security Related News

 
The Register - Security
Last Downloaded: Wed, 10 Mar 2010 11:23:53 GMT.
View The Raw XML Source Of The Register - Security. hide
  Max Clifford takes £1m to drop hack probe  

Kiss and don't tell

Celebrity publicist Max Clifford has agreed to accept a £1m plus payoff in exchange for dropping phone hacking allegations against the News of the World.…

  Suburban woman accused of using net to recruit terrorists  

Feds cuff JihadJane

A suburban Pennsylvania woman who went by the online alias JihadJane used the internet to recruit Islamic terrorists and to plot the assassination of a Swedish cartoonist who depicted the Prophet Mohammed, according to a federal indictment unsealed Tuesday.…

  Fraud-prevention service ponies up $12m for 'false' ads  

Agrees to safeguard customer data

An Arizona company that sells services designed to prevent identity theft has agreed to pay $12m to settle charges it oversold their effectiveness and didn't adequately protect sensitive customer data.…

  It's official: Adobe Reader is world's most-exploited app  

The new Microsoft

Adobe's ubiquitous Reader application has replaced Microsoft Word as the program that's most often targeted in malware campaigns, according to figures compiled by F-Secure.…

  New Internet Explorer code-execution attacks go wild  

IE 6 and 7 users targeted

Online thugs are exploiting a security bug in earlier versions of Internet Explorer that allows them to remotely execute malicious code, Microsoft warned on Tuesday.…

What is your recession sales strategy?

  FA launches security probe after England team bugged  

Lancaster Gate-gate

Reported attempts to sell recordings of conversations between England squad players and coaches have sparked a security breach investigation at the FA.…

  Smartphone app botnet experiment blows up a storm  

WeatherFist shows phone vulnerability, devs claim

Security researchers fooled nearly 8,000 iPhone and Android users into joining a mobile smartphone "botnet" under the guise of installing an apparently innocuous weather app.…

  Vodafone ships Mariposa-infected HTC Magic  

Android phone comes riddled with bots

Updated Vodafone has been blamed for shipping Mariposa botnet malware and other nasties on a HTC Magic Android smartphones it supplied.…

  Thailand approves extradition of credit card hack suspect  

Losses top $153m

A criminal court in Thailand has approved the extradition to the US of a Malaysian man suspected of participating in credit card thefts of more than $152m, according to a local news report.…

  'Crazy' man cuffed for plotting cyber extortion scheme  

Threatened to drag firm 'through the muddiest of waters'

A California man was charged with extortion after he allegedly threatened to send millions of emails and social networking messages that maligned a large life insurance company unless he was paid almost $200,000.…

  Ubisoft undone by anti-DRM DDoS storm  

Protests over anti-piracy controls hobble games firm

Ubisoft has confirmed its rights management servers were hit by a fierce DDoS attack over the weekend that left some customers unable to play its games for much of Sunday.…

  Paypal freezes Cryptome  

And sits on its cash

eBay Inc has suspended Cryptome's PayPal account, confiscating donations made to the site in the past two weeks. New York architect John Young has refunded around $5,300 to donors.…

What is your recession sales strategy?

  Botnet takedowns 'don't hurt crooks enough'  

Punching fog

The takedowns of the Mariposa and Waladec botnets last week were victories for the good guys, but security experts warn that although cybercrooks suffered a bloody nose they collectively retain the upper hand in their ongoing conflict with law enforcement and its security industry allies.…

  Energizer Duo software suffers backdoor Trojan bother  

Shh, I'm hunting wabbits

A Trojan backdoor found its way into Energizer Duo USB battery charger software downloads.…

  Patchy Windows patching leaves users insecure  

Third-party patch treadmill running too fast, warns security firm

Windows users need to patch their systems an average of every five days to stay ahead of security vulnerabilities, according to a study this week.…

  Opera says bug probably can't commandeer machines  

Get your DEP here just in case

A security vulnerability identified in Opera can be exploited to crash users' browsers, but probably can't lead to the remote execution of malware, a company spokesman said.…

Web threats: Why conventional protection doesn't work

  Think software patching is a hassle? You're not alone  

Help on the way

Underscoring a barrier to remaining secure online, the average Windows PC user has to install a software update every five days from 22 different providers, according to vulnerability tracking service Secunia.…

Case Study: WhatsUp keeps Legoland turnstyles ringing

  Scareware sellers fool Google with file switch  

Replacing pdfs with dodgy Flash files

Cybercrooks have developed a new technique for manipulating search engine results in order to promote the crud they sell, such as scareware packages.…

  Argos buries unencrypted credit card data in email receipts  

Laminated catalogue of errors

Catalogue firm Argos has been criticised for an email security breach that exposed customers’ credit card details and CCV security numbers.…

  Patch Tuesday will leave F1 hole unpatched  

Light spring sprinkle follows deluge

Microsoft is planning just two bulletins next week, covering vulnerabilities rated only as "important", as part of this month's Patch Tuesday.…

 
SecurityFocus News
Last Downloaded: Wed, 10 Mar 2010 15:26:19 GMT.
View The Raw XML Source Of SecurityFocus News. hide
  News: Change in Focus  Change in Focus
  News: Twitter attacker had proper credentials  Twitter attacker had proper credentials
  News: PhotoDNA scans images for child abuse   PhotoDNA scans images for child abuse

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: Conficker data highlights infected networks  Conficker data highlights infected networks
  Brief: Google offers bounty on browser bugs  Google offers bounty on browser bugs
  Brief: Cyberattacks from U.S. "greatest concern"   Cyberattacks from U.S. "greatest concern"

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Brief: Microsoft patches as fraudsters target IE flaw  Microsoft patches as fraudsters target IE flaw
  Brief: Attack on IE 0-day refined by researchers  Attack on IE 0-day refined by researchers
  News: Monster botnet held 800,000 people's details   Monster botnet held 800,000 people's details

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  News: Google: 'no timetable' on China talks  Google: 'no timetable' on China talks
  News: Latvian hacker tweets hard on banking whistle  Latvian hacker tweets hard on banking whistle
  News: MS uses court order to take out Waledac botnet   MS uses court order to take out Waledac botnet

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Infocus: Enterprise Intrusion Analysis, Part One  Enterprise Intrusion Analysis, Part One
  Infocus: Responding to a Brute Force SSH Attack  Responding to a Brute Force SSH Attack
  Infocus: Data Recovery on Linux and ext3   Data Recovery on Linux and <i>ext3</i>

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Infocus: WiMax: Just Another Security Challenge?  WiMax: Just Another Security Challenge?
  Gunter Ollmann: Time to Squish SQL Injection  Time to Squish SQL Injection
  Mark Rasch: Lazy Workers May Be Deemed Hackers   Lazy Workers May Be Deemed Hackers

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
  Adam O'Donnell: The Scale of Security  The Scale of Security
  Mark Rasch: Hacker-Tool Law Still Does Little  Hacker-Tool Law Still Does Little
powered by zFeeder


Latest Security Files/Exploits

 
Packet Storm Security Last 20
Last Downloaded: Wed, 10 Mar 2010 11:23:54 GMT.
View The Raw XML Source Of Packet Storm Security Last 20. hide
  TA10-068A.txt  Technical Cyber Security Alert 2010-68A - Microsoft has released updates to address vulnerabilities in Microsoft Windows and Microsoft Office.
  tor.uclibc.i686.20100309.iso  Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP.
  CORE-2009-1103.txt  Core Security Technologies Advisory - A memory corruption occurs on Microsoft Office Excel 2002 when parsing a .XLS file with a malformed DbOrParamQry record. This vulnerability could be used by a remote attacker to execute arbitrary code in the context of the currently logged on user, by enticing the user to open a specially crafted file.
  CORE-2009-0813.txt  Core Security Technologies Advisory - A vulnerability was found in Windows Movie Maker and Microsoft Producer, which can be triggered by a remote attacker by sending a specially crafted file and enticing the user to open it. This vulnerability results in a write access violation and can lead to remote code execution.
  rivercms-sql.txt  River CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
  MDVSA-2010-058.txt  Mandriva Linux Security Advisory 2010-058 - Multiple vulnerabilities have been found and corrected in PHP. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct these issues.
  nusnewssystem-sql.txt  NUs Newssystem version 1.02 suffers from a remote SQL injection vulnerability.
  jevci-disclose.txt  Jevci Siparis Formu Scripti suffers from a remote database disclosure vulnerability.
  ZDI-10-026.txt  Zero Day Initiative Advisory 10-026 - This vulnerability allows remote attackers to execute arbitrary commands on vulnerable installations of Hewlett-Packard Performance Insight. Authentication is not required to exploit this vulnerability. The specific flaw exists in the handling of requests to the helpmanager servlet running on the Performance Insight web server. Insufficient input validation and authentication allows for arbitrary JSP pages to be uploaded which can be leveraged to execute arbitrary OS commands. Exploitation of this vulnerability allows an attacker to gain control of the affected system under SYSTEM credentials.
  mhproducts-sql.txt  Mhproducts Kleinanzeigenmarkt suffers from a remote SQL injection vulnerability.
  easyftp.rb.txt  This Metasploit module exploits a stack overflow in the CWD verb in Easy~FTP Server. You must have valid credentials to trigger this vulnerability.
  HPSBMA02489-SSRT090065.txt  HP Security Bulletin - A potential vulnerability has been identified with HP Performance Insight. The vulnerability could be exploited remotely to execute arbitrary commands.
  energizer_duo_payload.rb.txt  This Metasploit module will execute an arbitrary payload against any system infected with the Arugizer trojan horse. This backdoor was shipped with the software package accompanying the Energizer Duo USB battery charger.
  orbital_viewer_orb.rb.txt  This Metasploit module exploits a stack-based buffer overflow in David Manthey's Orbital Viewer. When processing .ORB files, data is read from file into a fixed-size stack buffer using the fscanf function. Since no bounds checking is done, a buffer overflow can occur. Attackers can execute arbitrary code by convincing their victim to open an ORB file.
  rsstatic-sql.txt  Rsstatic suffers from a remote SQL injection vulnerability.
  uebimiauwebmail-disclose.txt  Uebimiau Webmail version 3.2.0-2.0 suffers from a remote email disclosure vulnerability.
  aef-xss.txt  AEF version 1.0.8 suffers from a cross site scripting vulnerability.
  ibmenovia-xss.txt  IBM ENOVIA SmarTeam version 5 suffers from a cross site scripting vulnerability.
  wildcms-sql.txt  WILD CMS suffers from a remote SQL injection vulnerability.
  eleanorcms-xss.txt  Eleanor CMS version Rc5.1 suffers from a cross site scripting vulnerability.
powered by zFeeder