ESET Nod32 Antivirus | Antispyware | Console d administration
Chercher :
Newsletter :  

Revues :
- Presse
- Presse FR
- Vidéos
- Twitter
- Secuobs




Abonnez vous � Nessus Professional Feed !

Sponsors :

Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- Commentaires


Revue Presse:
- Tous
- Francophone
- Par mot clé
- Par site
- Le tagwall


Top bi-hebdo:
- Ensemble
- Articles
- Revue
- Videos
- Twitter
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Twitter :
- Tous
- Par mot clé
- Par compte
- Le tagwall


Commentaires :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


Secumail :
- Secunia
- Full Disclosure
- Bugtraq
- DailyDave
- Vulnwatch
- Vulndiscuss
- FunSec
- Focus-IDS
- WebAppSec
- Security-Basis


RSS/XML :
- Articles
- Brèves
- Commentaires
- Revue
- Revue FR
- Videos
- Twitter
- Secunia
- Full Disclosure
- Bugtraq
- DailyDave
- Vulnwatch
- Vulndiscuss
- FunSec
- Focus-IDS
- WebAppSec
- Security-Basis


RSS SecuObs :
- sécurité
- exploit
- windows
- microsoft
- réseau
- attaque


RSS Revue :
- security
- microsoft
- windows
- hacker
- attack
- network


RSS Videos :
- vmware
- security
- virus
- biometric
- windows
- lockpicking


RSS Twitter :
- security
- linux
- botnet
- attack
- metasploit
- cisco


RSS Comments :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS OPML :
- Français
- International









Abonnez vous � Nessus Professional Feed !


Revue de presse francophone :
- Vendetta, le pirate de Belgacom, interpellé - lesoir.be
- Synology lance DiskStation DS410
- Websense, Triton la plateforme unifiée pour protéger contre les attaques du Web 2.0
- Everial dématérialise plus de 770 000 pages pour Merial en moins de 6 semaines
- McAfee Labs nouveau scam ciblant tous les utilisateurs de Facebook
- Florian Carrière, SoluCom Pour pérenniser votre PCA, développez sa valeur
- Equinix inaugure un second DataCentre à Genève
- Acronis lance un programme de formation et de certification
- Intego lance Washing Machine 2
- Enterasys améliore sa solution HiPath Wireless
- BitDefender met en garde contre un Trojan ciblant les utilisateurs de Facebook
- Orange Business Services classé dans le Leaders Quadrant par trois rapports Magic Quadrant
- Kroll Ontrack présente les dernières tendances en matière de récupération de données
- Sopra Group récompensé lors des E-DOC Awards 2010 pour sa Solution De Facto
- Trophées 2010 des Paiements Innovants Keynectis récompensée dans la catégorie Authentification forte pour sa solution K.Access

Dernier articles de SecuObs :
- VASTO une extension Metasploit dédiée à l'exploitation des infrastructures virtuelles
- Hogger automatise la création des tables d'attributs Snort à partir des scans Nmap
- Edenwall obtient une subvention de la DGA
- Imposter 0.9 une plateforme de phishing ciblant les navigateurs Web
- Une faille dans l’implémentation RSA de OpenSSL
- Flint un scanner pour simuler, vérifier et nettoyer les règles de filtrage
- SET 0.4.1 - Social Engineering Toolkit - une plateforme de Social Engineering
- 100 000 dollars pour le Pwn2own 2010
- Un botnet qui rapporte gros
- Webraider offre un reverse shell contre une simple injection SQL

Revue de presse internationale :
- Intel Launches Security Focused Data Center Processors
- Supply Chain Data Real-Time Speed Is Seductive, Dangerous
- Fired CISO says his comments never put Penn.'s data at risk
- IE8, iPhone will fall first day of hacking contest, predicts organizer
- Microsoft says its contentious relationship with open source is changing
- Nmap Primer Video Tutorial
- phpscripte24 Niedrig Gebote Pro Auktions System II Blind SQL Injection
- Nensor CMS 2.01 Multiple Remote Vulnerabilities
- 8-Bit NYC
- High School spy bot-net
- Ep0530 Setting up the samson C01u in linux
- Uh oh Trojan
- Estonia defense minister talks about 2007 cyberattacks
- CISSP Seminar in Malta
- Palm CEO We could have been bigger than Droid

Annuaire des videos
- Shmoocon 2010 Cyborg Information Security Defense Against the Dark Arts 2 5
- Shmooncon 2010 Detection of rogue access points using clock skews does it really
- RSA Conference USA 2010 Defeating the Enemy The Road to Confidence 2
- Shmoocon 2010 Infrastructural Weaknesses in Distributed Wireless Communication Services 2 6
- Iron Geek Challenge at South by Southwest
- Shmooncon 2010 Detection of rogue access points using clock skews does it really
- Shmoocon 2010 The Splendiferous Story of Archive Team and the Disappearing Digital Heritage 5
- Living Guru Poison part 8 of 9 wmv
- Shane Lawson The Kwikset Smart Key Decoder
- Shmoocon 2010 An Existential Threat To Security As We Know It 2
- Surviving the Zombie Apocalypse Notacon 7 Preview
- Vision x19 for Hak5
- Hak5 CES 2009 Day 1 Pow wow
- Catching up with Hak5 at CES 2010
- Homebrew Multitouch Hak5

Revue Twitter
- @sfoak well there is another one... but hes not a PCI guy
- Note to self: log into VPN *before* freaking out because server is unresponsive.
- Couldn't do it in Windows. Couldn't do it in the cloud. So, rebooted my Macbook and it took 20 seconds.
- OWASP Long Island tonight. Who am I going to see there?
- Watching @dguido talk at OWASP Long Island
- RT @wardspan: lookie i'm talking about PCI again http://bit.ly/bKEx0V Who's picture did they use? That's not you, is it?
- @joshcorman You CAN do risk management without PCI. But too many companies think I'm not at risk and ignore security without PCI.
- @joshcorman Co.'s who do good risk mngmt should be able to factor PCI in the equation. Co.'s who don't do good RM will be helped by PCI
- RT @smalm: new pci asv program guide is out. blog post is up: it takes a village to raise the (pci) bar... http://bit.ly/ad5sDw
- RT @danchodanchev: Managed obfuscation services http://bit.ly/bE1Oq6, and their legitimate alternatives http://bit.ly/aaFzGb are both, u ...

Mini-Tagwall
Revue de presse : security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone

+ de mots clés pour la revue de presse

Annuaires des videos : vmware, security, virus, biometric, windows, lockpicking, password, botnet, metasploit, tutorial, attack, crypt, linux

+ de mots clés pour les videos

Revue Twitter : security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall

+ de mots clés pour la revue Twitter



Top bi-hebdo des articles de SecuObs
- Apprendre à parler Skype pour mieux le faire taire !
- Une faille dans l’implémentation RSA de OpenSSL
- Imposter 0.9 une plateforme de phishing ciblant les navigateurs Web
- VASTO une extension Metasploit dédiée à l'exploitation des infrastructures virtuelles
- Flint un scanner pour simuler, vérifier et nettoyer les règles de filtrage
- Keimpx un outil d'audit pour les réseaux Microsoft Windows
- SET 0.4.1 - Social Engineering Toolkit - une plateforme de Social Engineering
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Webraider offre un reverse shell contre une simple injection SQL
- Edenwall obtient une subvention de la DGA

Top bi-hebdo de la revue de presse
- Sun Ray interception de données des DTU
- How to Jailbreak iPhone 3.1.3 IPSW with PwnageTool 3.1.5
- Dev Team Confirms iPhone 3.1.3 IPSW Jailbreak
- Rozlyn Papa sex tape rumours lead to malware
- FREE Kaspersky Internet Security 2010 Activation Code Valid for 6 Months
- installer backtrack 4 [tuto]
- Nouveau dictionnaire WPA Livebox
- IIS 6 may stop responding after you install Microsoft update KB 973917
- La Face cachée de Facebook
- Téléchargements Ados de mal en pis

Top bi-hebdo de l'annuaire des videos
- Comment creer un server botnet!!!!(Réseau de pc zombies)
- Ettercap Tutorial Man In The Middle Arp Attack
- vSphere 4 0 update 1 VMware Update Manager and EMC PowerPath VE
- install MacOSX Snow Leopard in Windows PC using Vmware Workstation as virtual machine
- Blaze botnet in action www opensc ws
- Windows XP Pro SP3 in VMWare off iSCSI Target using gPXE over 802.11n
- Running Wireshark on Mac OS X 10 6 Snow Leopard
- Shmoocon 2010 Firetalks SHODAN for Penetration Testers 1 2
- Avast Internet Security 5 0 396 Final Free Full Download Licensed with Serial Key
- BackTrack 4 on Windows XP with VMware Workstation Tutorial by Puridee HD

Top bi-hebdo de la revue Twitter
- How to secure a Cisco router http://ping.fm/FkG7O
- RT @manicode: Very interesting Java ESAPI-like library coming out of Apache : http://bit.ly/9poefg
- Wirshark + SSH = Wireshark Remote Capturing - http://www.howtoforge.com/wireshark-remote-capturing (via @welias)
- Nux Keylogger 0.0.1 http://packetstormsecurity.org/filedesc/nuxkeylogger0.0.1.c.html
- Nessus Scan through a Meterpreter Session (demo) http://vimeo.com/10203481 #PaulDotCom #nessus #meterpreter
- Exploit for Apache mod_isapi = 2.2.14 Dangling Pointer (CVE2010-0425) vulnerability ported to Metasploit http://bit.ly/ctDQjk
- Collection of security checks for Linux http://bit.ly/a7IH7m
- RT @FrikiFeeds: The newbie's guide to hacking the Linux kernel | TuxRadar Linux http://dlvr.it/6sQp
- Discoverer: Automatic Protocol Reverse Engineering from Network Traces #pdf http://ow.ly/1gHd1
- RT @DidierStevens: cmd.dll reverse shell in memory payload used with PDF exploit: http://bit.ly/96thpF

Top des articles les plus commentés
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Microsoft !Exploitable un nouvel outil gratuit pour aider les développeurs à évaluer automatiquement les risques
- Webshag, un outil d'audit de serveur web
- Les navigateurs internet, des mini-systèmes d’exploitation hors de contrôle ?
- CAINE un Live[CD|USB] pour faciliter la recherche légale de preuves numériques de compromission
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- Microsoft Gazelle, mini-OS virtuel basé sur MashupOS pour une navigation Web sécurisée par isolation
- Nessus 4.0 placé sous le signe de la performance, de l'unification et de la personnalisation
- GreenSQL un proxy MySQL pour filtrer les requêtes SQL et contrer les injections

Rickrolled Get Ready for the Hail Mary Cloud
Les derniers commentaires publiés sur SecuObs (1-5):
- ESRT @opexxx @synopsi - Remote stack overflows
- ESRT @postmodern_mod3 @tmm1 - memprof now displays stack frames and threads
- ESRT @_MDL_ @gollmann - Locking botnet agents to specific victim systems in o
- CsFire 0.4.1 autonomously protects against dangerous or malicious cross-domai
- Seccubus v1.4.1 - Nessus 4.2 compatibility release

Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]

S'abonner au fil RSS global de la revue de presse



Rickrolled Get Ready for the Hail Mary Cloud

Par That grumpy BSD guy
Le [2009-11-15] à 17:02:35



Présentation : If you publish your user name and password, somebody who is not you will use it, sooner or later. It's been a fun few weeks. Over in Microsoft land, it must have been a big issue that according to malware hunters Sophos, the newly released Windows 7 with no extras is roughly as vulnerable as its older siblings. No great surprises there, I suppose. For those of us with a more Unixish leaning, the more interesting piece of news involved Apple iPhones. These phones apparently run a version of MacOS that has enough Unix in it that with a bit of tinkering, it is possible to install a variety of Unix software, such as the ubiquitous secure shell daemon sshd. To some, there is a certain attraction in knowing that you have an SSH server in your pocket or handbag. Too bad, then that enough of those adventurous iPhone owners never read up on the instructions and chose to run their toy with the default password for the root account and were vulnerable to a wonderful prank perpetrated by a programmer down under. The prank described in the inimtable The Register style here demonstrated just how bad an idea it is to publish your user name and password. If you followed the news around last weekend you would notice that a large segment of the Microsoft-attached instapunditry got their facts wrong as usual with the this proves that Apple and by extension any Unix and of course Linux is just as vulnerable as Microsoft mantra repeated over and over. In fact, there are two historical incidents that point to Unix being no silver bullet the 2002 Linux Slapper Worm and the original network-enabled worm, the 1988 Morris Worm. Those two prove mainly that yes, some bugs are exploitable, and the way forward is to fix bugs and make them harder to exploit in the first place alternates here and here . Now these two famous exploits is possibly to be joined by a third, the rickrolling prank. I beg to differ. The rickroller is about bad passwords, no more, no less. I've spent considerable time ranting about passwords in earlier columns, and this incident only underscores what we've been repeating until your eardrums wear thin an my vocal cords swell from exhaustion Publishing your username and password is a really bad idea. It's almost as bad as picking a guessable password. Add to this that the fact, as we've noted here earlier, there is a whole cloud of hijacked machines out there beavering away at guessing passwords right now, and they have been at it for quite a while. The most remarkable of these botnets is the one that tries to avoid detection by distributing the password guessing for any target across a large number of hosts, so each guesser never shows high enough rates of activity to trigger any of the traditional bruteforce detection mechanism. The attempts look something like this in your authentication log Nov 13 21 10 14 rosalita sshd 50401 error PAM authentication error for illegal user mars from 125.40.69.208 Nov 13 21 10 14 rosalita sshd 50401 Failed keyboard-interactive pam for invalid user mars from 125.40.69.208 port 38052 ssh2 Nov 13 21 11 20 rosalita sshd 50419 reverse mapping checking getaddrinfo for 115-186-131-90.nayatel.pk 115.186.131.90 failed - POSSIBLE BREAK-IN ATTEMPT Nov 13 21 11 20 rosalita sshd 50419 Invalid user mars from 115.186.131.90 Nov 13 21 11 21 rosalita sshd 50419 error PAM authentication error for illegal user mars from 115.186.131.90 Nov 13 21 11 21 rosalita sshd 50419 Failed keyboard-interactive pam for invalid user mars from 115.186.131.90 port 42235 ssh2 Nov 13 21 13 43 rosalita sshd 50428 Invalid user mars from 58.247.222.163 Nov 13 21 13 43 rosalita sshd 50428 error PAM authentication error for illegal user mars from 58.247.222.163 Nov 13 21 13 43 rosalita sshd 50428 Failed keyboard-interactive pam for invalid user mars from 58.247.222.163 port 35134 ssh2 Nov 13 21 15 59 rosalita sshd 50440 Invalid user mars from 89.76.186.99 Nov 13 21 16 00 rosalita sshd 50440 error PAM authentication error for illegal user mars from chello089076186099.chello.pl Nov 13 21 16 00 rosalita sshd 50440 Failed keyboard-interactive pam for invalid user mars from 89.76.186.99 port 52156 ssh2 Nov 13 21 17 16 rosalita sshd 50448 Invalid user mars2 from 88.134.166.31 Nov 13 21 17 16 rosalita sshd 50448 error PAM authentication error for illegal user mars2 from 88-134-166-31-dynip.superkabel.de Nov 13 21 17 16 rosalita sshd 50448 Failed keyboard-interactive pam for invalid user mars2 from 88.134.166.31 port 39254 ssh2 Nov 13 21 18 14 rosalita sshd 50452 Invalid user room from 62.198.66.107 Nov 13 21 18 14 rosalita sshd 50452 error PAM authentication error for illegal user room from 62.198.66.107 Nov 13 21 18 14 rosalita sshd 50452 Failed keyboard-interactive pam for invalid user room from 62.198.66.107 port 47557 ssh2 Nov 13 21 19 27 rosalita sshd 50458 Invalid user room from 61.74.75.43 Nov 13 21 19 27 rosalita sshd 50458 error PAM authentication error for illegal user room from 61.74.75.43 Nov 13 21 19 27 rosalita sshd 50458 Failed keyboard-interactive pam for invalid user room from 61.74.75.43 port 57794 ssh2 Nov 13 21 21 41 rosalita sshd 50472 Invalid user room from 212.243.41.9 Nov 13 21 21 41 rosalita sshd 50472 error PAM authentication error for illegal user room from 212.243.41.9 Nov 13 21 21 41 rosalita sshd 50472 Failed keyboard-interactive pam for invalid user room from 212.243.41.9 port 38396 ssh2 Nov 13 21 22 58 rosalita sshd 50491 reverse mapping checking getaddrinfo for static-ip-cr1901468058.cable.net.co 190.146.80.58 failed - POSSIBLE BREAK-IN ATTEMPT Nov 13 21 22 58 rosalita sshd 50491 Invalid user room from 190.146.80.58 Nov 13 21 22 58 rosalita sshd 50491 error PAM authentication error for illegal user room from 190.146.80.58 Nov 13 21 22 58 rosalita sshd 50491 Failed keyboard-interactive pam for invalid user room from 190.146.80.58 port 4420 ssh2 Nov 13 21 24 01 rosalita sshd 50509 Invalid user room from 62.23.130.173 Nov 13 21 24 01 rosalita sshd 50509 error PAM authentication error for illegal user room from host.173.130.23.62.rev.coltfrance.com Nov 13 21 24 01 rosalita sshd 50509 Failed keyboard-interactive pam for invalid user room from 62.23.130.173 port 3904 ssh2 Nov 13 21 25 21 rosalita sshd 50517 reverse mapping checking getaddrinfo for hn.kd.ny.adsl 125.40.69.208 failed - POSSIBLE BREAK-IN ATTEMPT Nov 13 21 25 21 rosalita sshd 50517 Invalid user room from 125.40.69.208 Nov 13 21 25 21 rosalita sshd 50517 error PAM authentication error for illegal user room from 125.40.69.208 Nov 13 21 25 21 rosalita sshd 50517 Failed keyboard-interactive pam for invalid user room from 125.40.69.208 port 3294 ssh2 and so on. I put it to you What you see here is the cybercrime equivalent of the Hail Mary Pass. Each attempt in theory has monumental odds against succeeding, but occasionally the guess will be right and they have scored a login. As far as we know, this is at least the third round of password guessing from the Hail Mary Cloud see the archives for earlier postings about slow bruteforcers , but there could have been earlier rounds that escaped our attention. The fact that we see the Hail Mary Cloud keeping up the guessing is a strong indicator that there are a lot of guessable passwords and possibly badly maintained systems out there, and that even against the very long odds they are succeeding often enough in their attempts to gain a foothold somewhere that it is worth keeping up the efforts. For one thing, the cost of using other people's equipment is likely to be quite low. There are a lot of things about the Hail Mary Cloud and its overseers that we do not know. People who responded to the earlier articles with reports of similar activity also reported pretty consistently something like a sixty to seventy percent match in hosts making the attempts. With 1767 hosts in the current sample it is likely that we have a cloud of at least several thousand, and most likely no single guessing host in the cloud ever gets around to contacting every host in the target list. The busier your SSH deamon is with normal traffic, the harder it will be to detect the footprint of Hail Mary activity, and likely a lot of this goes undetected. The data, as I am sure you have been waiting for it, is available in these forms Raw log data, with 3-4 lines per attempt as illustrated above and requested by some correspondents , one line per attempt shows the pattern a little more clearly , a list of the hosts participating in the Hail Mary Cloud sorted by number of attempts, and the user names attempted, sorted by number of attempts. The pattern is fairly familiar by now, but this time the alphabetic cycles are shorter and at times the coordination seems to have broken down. My guess is that the apparent breakdowns are due to silly factors like the guessing machines running without time synchronization or other signs of incompetence. And finally, some words of advice for those of you who want to avoid both rickrolling and getting cracked by other password guessing. You should at least consider setting a password policy and enforcing it with something like John the ripper, which more than likely is available at the cost of a few keystrokes from your package system. And of course there is the fine art of sshd configuration. Some of the things you could do are, in no particular order disable root logins over the network use packet filtering or other means to restrict where users can log in from disable password logins entirely allowing only key-based logins set up your sshd to listen on a non-standard port whatever your users can bear to live with. If you see traces of the Hail Mary Cloud's activity in your logs and you want to share and study, I would very much like to hear from you. I will most likely be updating the log data and extracts at intervals. --------------------------------------------------------------------- If you found this article useful, enjoyable or irritating, please drop me a line. Material related to this article is available free via links from my web space. Some additional material will be made available for reasonable research purposes. If you want more extensive assistance, please contact FreeCode to make arrangements. ---------------------------------------------------------------------




AddThis Social Bookmark Widget



Les derniers articles du site "That grumpy BSD guy" :

- The Goodness of Men and Machinery
- Rickrolled Get Ready for the Hail Mary Cloud
- I Must Be Living in a Parallel Universe, Then
- A year ends what to do next
- Riga, here we come, OpenBSD 4.3 on the horizon
- Does anybody here remember Artie Eff
- Network devices that lie
- Fake Address Round Trip Time 13 days
- I challenge your response, backscatterer
- More than 40,000 served




S'abonner au fil RSS global de la revue de presse

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]



Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail





Les derniers commentaires publiés sur SecuObs (6-25):
- ESRT @JGamblin @threatpost - Hackers say they will definitely break into an A
- ESRT @hdmoore @iagox86 - Weaponizing dnscat - first version of dnscat shellco
- iWep PRO 1.1.3 Released
- FireCAT v1.6.2 updated with Framework Detector
- ESRT @opexxx - FireCAT v1.6.2 updated with BackendInfo
- sipwitch 0.7.4
- Oracle XDB FTP service UNLOCK buffer overflow exploit that spawns a reverse s
- XSSploit XSS scanner multiplatfom v0.5 available
- Network forensics in IRB xtractr Ruby gem
- GreenPois0n Possible Jailbreak Software for iPad OS 32
- Blazing fast password recovery with new ATI cards
- ESRT @wireheadlance - How to secure a Cisco router
- Device Fingerprinting to Fight Real-time Transaction Fraud
- Penetrating Intranets through Adobe Flex Applications
- Updated the OWASP Fuzzing Code Database
- ESRT @jcran - how to convert a NASL check to a NeXpose check
- The New Disclosure Debate and the Evil Mr. Moore
- Charlie Miller Will Expose 20 Hackable Apple Security Flaws
- Digital Forensics Framework v0.5 released
- OSSIM v2.2 Multiple Vulnerabilities


SecuToolBox :

Mini-Tagwall des articles publiés sur SecuObs :

Archives Failles Secunia :
- SA38969 OSSIM Multiple Vulnerabilities
- SA38861 TR-069 Remote Management SQL Injection Vulnerability
- SA38955 MaxDB Handshake Packet Buffer Overflow Vulnerability
- SA38922 Ubuntu update for linux and linux-source-2.6.15
- SA38967 PhpKobo Real Estate Contact Form LANG_CODE Local File Inclusion

Archives Mailing Full Disclosure :
- Full-disclosure Claude Mercier/CLSC-CHSLD BVLV/Reg03/SSSS est absent(e).
- Re: Full-disclosure Fingerprinting Paper with Laser
- Re: Full-disclosure Fingerprinting Paper with Laser
- Full-disclosure AboCMS SQL injection (abocms.ru)
- Full-disclosure SECURITY DSA-2018-1 New php5 packages fix null pointer dereference

Archives Mailing Bugtraq :
- Sahana 0.6.2.2 Authentication Bypass
- Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability
- Secunia Research: Quicksilver Forums Backup Information Disclosure
- Secunia Research: Quicksilver Forums mysqldump Password Disclosure
- Miranda IM silent TLS failure
- Vulnerabilities in VXDate for Joomla

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :

Mini-Tagwall des Tweets de la revue Twitter :