Chercher :
Newsletter :  

Exoscan : audit gratuit de failles
Revue :
- Tous
- Français
- Par mot clé
- Par site
- Le tagwall



Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- Commentaires


Top :
- Ensemble
- Articles
- Revue
- Videos
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Exostat :
:: Détails tests
:: Top Failles
:: Top Divers
:: Top Tests


Secumail :
- Secunia
- Full Disclosure
- Bugtraq
- DailyDave
- Vulnwatch
- Vulndiscuss
- FunSec
- Focus-IDS
- WebAppSec
- Security-Basis


RSS/XML :
- Articles
- Brèves
- Commentaires
- Revue
- Revue FR
- Videos
- Secunia
- Full Disclosure
- Bugtraq
- DailyDave
- Vulnwatch
- Vulndiscuss
- FunSec
- Focus-IDS
- WebAppSec
- Security-Basis


RSS SecuObs :
- sécurité
- windows
- exploit
- microsoft
- réseau
- attaque


RSS Revue :
- security
- microsoft
- windows
- vulnérabilité
- network
- google


RSS Videos :
- virus
- spyware
- vmware
- firmware
- biometric
- lockpicking










Tous
Français



Revue de presse francophone :
- Prison ferme pour des pirates de distributeurs de billets
- La DGA lance le nouvel intranet des forces aéronavales
- Wikipedia pour adultes
- Près de 40 millions d'Américains victimes de pertes d´informations
- Criston et Citrix associent leur savoir-faire
- XOOPS mydirname : Injection de Code PHP Vulnérabilité
- Soholaunch Pro _SESSION[docroot_path] : Inclusion de Fichiers
- CuteNews Cross-Site Scripting et PHP : Vulnérabilités d'Exécution de Code
- Warez + TGI = juste de la malchance
- Audience de Grande Chambre Scoppola c. Italie
- Arrêt de Chambre Mangouras c. Espagne
- L'interrogatoire
- Un hacker fait croire au retrait de la candidature de Grenoble pour les Jeux Olympiques de 2018
- Un hacker fait croire au retrait de la candidature de Grenoble aux Jeux Olympiques de 2018
- 30 ans de prison pour un escroc lié au fameux piratage de TJX Maxx

Dernier articles de SecuObs :
- Une nouvelle technique pour la fiabilité et la portabilité des codes d'exploitation des routeurs Cisco
- Une attaque à venir sur la technologie Intel TXT pour les TPM des produits vPro
- Une nouvelle implémentation GSM libre
- Mettre en place des VPN anonymes à l'aide de Tor et de OnionCat
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- Exploitation de collisions MD5 pour des faux certificats générés dans la perfection de l'art
- Vista permet le monitoring Wifi quasiment “out of the box”
- Letdown, un outil gratuit de Déni de Service qui exploite les faiblesses du protocole TCP
- Un code d'exploitation disponible pour la faille non corrigée de Microsoft SQL Server
- Metasploit Decloak 2 et les fuites d'informations réseau via les services Web

Revue de presse internationale :
- Is risk homeostasis real?
- Microsoft?s January Patch Release Advance Notice
- Belize a new target for savy hackers
- Secunia Weekly Summary - Issue: 2009-2
- Probe led Fumo to boost security
- Minecode execs face prison terms for computer intrusion
- MeriTalk Cyber Comedy Study Asks What Did We Get for $27 Billion IT Security Investment?
- CFP: COLSEC 2009
- Axiom Housing Association purchases SoloProtect to ensuresafety of its outreach workers
- Two-thirds of UK businesses do not manage their Internet security

Annuaire des videos
- steganografietutorial
- Affordable Tech Support & Remote Computer Support with iYogi
- Unlock iPhone 3G on 2.2 Firmware
- Customize Working On 2.2 Firmware & More Info On iPod Touch ...
- Adware
- Automatic Jailbreak firmware 1.1.4 for any iPod Touch/iPhone
- Malware Bytes
- Interview with Mark Russinovich the future of Sysinternals 4/5
- Interview with Mark Russinovich the future of Sysinternals 5/5
- Interview with Mark Russinovich the future of Sysinternals 3/5

Mini-Tagwall
Revue de presse : security, microsoft, windows, vulnérabilité, network, google, vulnerability, hacker, attack, inject, remote, mobile, server

+ de mots clés pour la revue de presse

Annuaires des videos : virus, spyware, vmware, firmware, biometric, lockpicking, wimax, password, spammer, malware, kernel, windows, iphone

+ de mots clés pour les videos

Top des articles de SecuObs
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- UCSniff ou comment capturer des conversations VoIP en haute définition
- Une faille dans Gmail pour rediriger les mails des utilisateurs
- Des probabilités de visualisation des données en clair lors des connexions SSH
- WPA TKIP aurait été partiellement cassé
- Un nouveau type d'attaque distribuée sur les serveurs SSH
- Rustock.C, un rootkit robuste
- Exploitation de collisions MD5 pour des faux certificats générés dans la perfection de l'art
- Collecte d’informations et social engineering via les réseaux sociaux
- [Sécuriser un réseau sans fil - Partie 1] Introduction à la sécurité du WI-FI

Top de la revue de presse
- Une attaque de phishing cible les abonnés de Free
- Burundanga Drug Rumors Spread to Canada, Australia
- Sauvegarde à  chaud : ShadowProtect 3.3 est lancé
- Guide Websense des arnaques de Noël
- 15 minutes pour casser une clé WPA TKIP
- No-IP Linux Dynamic Update Client : Vulnérabilité de Dépassement de Tampon
- Easily Install and Download DirectX 10 for Windows XP
- La nouvelle DSi de Nintendo piraté !

Top de l'annuaire des videos
- HACK WINDOWS XP PASSWORD
- How to Install ESET Nod32 AntiVirus For FREE 2008
- Downgrade IPhone Firmware 2.2 to 2.1
- [Amazing] Hacking SSH Tunneling Exploit
- Download Free NOD32 Eset Antivirus Forever
- metasploit 3 autopwn
- Computer Virus, Spyware
- Fallout 3 Lockpicking tutorial
- Install OpenBSD 4.3 on VMWare
- How To Jailbreak iPod Touch Firmware 2.1

Exostats/Exoscan
Nombre de tests inclus
24761
Tests ajoutés
Aujourd'hui
Ce mois
11
31


[Message Precedent sur la mailing][Message Suivant sur la mailing][Precedent dans le fil][Prochain dans le fil][Index par Date][Index par fil] [security bulletin] HPSBMA02388 SSRT080059 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Cross Site Scripting (XSS)

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01607570 Version: 1 HPSBMA02388 SSRT080059 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Cross Site Scripting (XSS) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2008-11-19 Last Updated: 2008-11-19 Potential Security Impact: Remote cross site scripting (XSS) Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). The vulnerabilities could be exploited remotely to allow cross site scripting (XSS).

References: CVE-2007-6388, CVE-2007-5000 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP OpenView Network Node Manager (OV NNM) v7.01, v7.51, v7.53 running on HP-UX, Linux, and Solaris BACKGROUND CVSS 2.0 Base Metrics =============================================== Reference Base Vector Base Score CVE-2007-6388 (AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.3 CVE-2007-5000 (AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.3 =============================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.

RESOLUTION HP has made patches available to resolve the vulnerabilities.

The patches are available from link://[click] OV NNM v7.53 =========== Operating_System - HP-UX (IA) Resolved in Patch - PHSS_38148 or subsequent Operating_System - HP-UX (PA) Resolved in Patch - PHSS_38147 or subsequent Operating_System - Linux RedHatAS2.1 Resolved in Patch - LXOV_00085 or subsequent Operating_System - Linux RedHat4AS-x86_64 Resolved in Patch - LXOV_00086 or subsequent Operating_System - Solaris Resolved in Patch - PSOV_03514 or subsequent OV NNM v7.51 =========== Upgrade to NNM v7.53 and install the patches listed above. OV NNM v7.01 =========== Operating_System - HP-UX (PA) Resolved in Patch - PHSS_38761 or subsequent Operating_System - Solaris Resolved in Patch - PSOV_03516 or subsequent MANUAL ACTIONS: Yes - NonUpdate Apply the appropriate file as described in the Resolution. PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see link://[click] The following text is for use by the HP-UX Software Assistant.

AFFECTED VERSIONS (for HP-UX) For HP-UX OV NNM 7.53 HP-UX B.11.31 HP-UX B.11.23 (IA) ============= OVNNMgr.OVNNM-RUN action: install PHSS_38148 or subsequent URL: link://[click] HP-UX B.11.23 (PA) HP-UX B.11.11 ============= OVNNMgr.OVNNM-RUN action: install PHSS_38147 or subsequent URL: link://[click] For HP-UX OV NNM 7.51 HP-UX B.11.31 HP-UX B.11.23 HP-UX B.11.11 ============= OVNNMgr.OVNNM-RUN action: upgrade NNM v7.51 to NNM v7.53 and apply the appropriate patches For HP-UX OV NNM 7.01 HP-UX B.11.00 HP-UX B.11.11 ============= OVNNMgr.OVNNM-RUN action: install PHSS_38761 or subsequent URL: link://[click] END AFFECTED VERSIONS (for HP-UX) HISTORY Version:1 (rev.1) - 19 November 2008 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For further information, contact normal HP Services support channel.

Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@xxxxxx It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. To get the security-alert PGP key, please send an e-mail message as follows: To: security-alert@xxxxxx Subject: get key Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: link://[click] On the web page: ITRC security bulletins and patch sign-up Under Step1: your ITRC security bulletins and patches - check ALL categories for which alerts are required and continue.

Under Step2: your ITRC operating systems - verify your operating system selections are checked and save.

To update an existing subscription: link://[click] Log in on the web page: Subscriber's choice for Business: sign-in. On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections.

To review previously published Security Bulletins visit: link://[click] * The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: GN = HP General SW MA = HP Management Agents MI = Misc. 3rd Party SW MP = HP MPE/iX NS = HP NonStop Servers OV = HP OpenVMS PI = HP Printing & Imaging ST = HP Storage SW TL = HP Trusted Linux TU = HP Tru64 UNIX UX = HP-UX VV = HP VirtualVault System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement." ©Copyright 2008 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.

-----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBSSQhVOAfOvwtKn1ZEQIlVQCg4n4fABzC24c9qQ5gz68oPLMVKI0AoMbs A2UIaH3YB7z+o42Tm7Eg7ahn =lskD -----END PGP SIGNATURE-----


Archives de la liste de diffusion Secunia
Archives de la liste de diffusion BugTraq
Archives de la liste de diffusion DailyDave
Archives de la liste de diffusion FunSec
Archives de la liste de diffusion Full Disclosure
Archives de la liste de diffusion Focus-IDS (FD)
Archives de la liste de diffusion Webappsec (FD)
Archives de la liste de diffusion Security-basics (FD)
Archives de la liste de diffusion Vulndiscuss
Archives de la liste de diffusion Vulnwatch


Les derniers commentaires sur SecuObs :
- More Oracle Pwnage...I Lost Count...New Version Module http://www.secuobs.com/r
- Update on the update http://www.secuobs.com/revue/news/49561.shtml
- YARA: a malware identification and classification tool http://www.secuobs.com/re
- Update from Alexander Sotirov http://www.secuobs.com/revue/news/49201.shtml
- VOIP Scanning on the increase http://www.secuobs.com/revue/news/49189.shtml
- Creator of ZiPhone iPhone unlock hack calls it quits http://www.secuobs.com/revu
- IPv6 Tunnel on Windows XP Using Freenet6 http://www.secuobs.com/revue/news/48645
- RFIDIOt-0.1v.tgz http://www.secuobs.com/revue/news/48665.shtml
- VOIPPACK now available! http://www.secuobs.com/revue/news/48725.shtml
- Nine Years of Code Cruft: Microsoft?s Hidden Internet Explorer Failures http://w

Mini-Tagwall des articles publiés sur SecuObs :

Archives Failles Secunia :
- SA33400 Fedora update for am-utils
- SA33419 Fedora update for xterm
- SA32648 TSC2 Help Desk CTab ActiveX Control Caption List Buffer Overflow
- SA32609 ComponentOne SizerOne CTab ActiveX Control Caption List Buffer Overflow
- SA33342 vBulletin Personal Sticky Threads Add-on Security Bypass Vulnerability

Archives Mailing Full Disclosure :
- Full-disclosure Do you use nepenthes?
- Full-disclosure The war in Palestine && Pointless noise.
- Full-disclosure MDVSA-2009:001 openssl
- Re: Full-disclosure Full-Disclosure wouldn't let me post this message
- Re: Full-disclosure The war in Palestine

Archives Mailing Bugtraq :
- AST-2009-001: Information leak in IAX2 authentication
- LayerOne 2009 Call for Papers
- USN-705-1 NTP vulnerability
- Re: IBM Datapower XS40 Denial of Service
- CORE-2008-1128: Openfire multiple vulnerabilities

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :