|
|
|
16 months later, Adobe still plagued by XSS bug it invented |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
16 months later, Adobe still plagued by XSS bug it invented Par Hack In The BoxLe [2009-05-14] à 06:39:16
Présentation : More than 16 months after researchers warned that critical vulnerabilities in Adobe Flash files leave websites vulnerable to phishing and other serious attacks, a wide array of pages - some hosted on Adobe.com itself - remain vulnerable. The problem stems from buggy SWF files that generate banner ads and other animated content. In December 2007, a team of researchers discovered the files could be exploited by attackers to tamper with websites belonging to banks, government agencies and other trusted organizations. Over the next few months, the researchers repeatedly warned webmasters the problem would be difficult to fix, because it would require potentially millions of graphics files to be regenerated, often from scratch. Those warnings now appear to be prescient. As the website XSSed has documented, even Adobe.com has failed to contain the offending SWF files. Other offenders include the Marfin Egnatia Bank and Greek electronics vendor Plaiso.gr. At time of writing, more than 24 hours after the XSSed item was published, all three sites remained vulnerable.
Les mots clés de la revue de presse pour cet article : adobe Les éléments de la revue Twitter pour les mots clés : adobe
Les derniers articles du site "Hack In The Box" :
- Honda security breach exposes 283,000 customers - Aussie banks cancel 10,000 credit cards - What Your Wireless Carrier Knows About You - Lloyds TSB suffers internet banking problems - Bulging tweet lewd photo leaves politician red-faced - Skype partner update leads to worm fears - Latest hack on PBS news site is the best hack ever - Hackers breached US defense contractors - Hidden URLs in phone and tablet browsers - HITBSecNews - The Revolution Begins 1st June 2011
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|