Drupalit weekly
The changing face of information security
Submitted by secgeeks on Thu, 26/06/2008 - 21:53.In the last eight years or so, I’ve probably been to more than 100 security conferences, workshops, trade shows and seminars and I’m hard-pressed to come up with one that’s been more informative or entertaining than the Workshop on Economics in Information Security that’s taking place at Dartmouth College this week. As you might expect, [...] read more »
Srizbi botnet blamed for malicious spam surge
Submitted by secgeeks on Wed, 25/06/2008 - 17:42.A sharp rise in the volume of malicious spam this month can be largely attributed to the Srizbi botnet, according to researchers at Marshal. Spam intended to infect users’ computers with malware tripled in one week, jumping from 3 percent of total spam at the beginning of June to 9.9 percent the following week.The Srizbi [...] read more »
TippingPoint reports Firefox 3.0 flaw
Submitted by secgeeks on Thu, 19/06/2008 - 16:14.TippingPoint said a researcher submitted a critical vulnerability affecting Firefox 3.0 to its Zero Day Initiative just five hours after Mozilla released the updated open-source browser Tuesday.In a blog post Wednesday, TippingPoint said its researchers verified the vulnerability it in its lab and quickly reported the flaw to Mozilla’s security team. The flaw could allow [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 102 reads
Could managed security services cause data woes?
Submitted by secgeeks on Thu, 19/06/2008 - 17:05.In this podcast, SearchSecurity.com editors discuss managed security services, the increase of SQL injection attacks and whether secure software coding is improving.
- Add new comment
- Get Our RSS Feeds
- report as spam
- 116 reads
Panda security researchers warn of new worm tool
Submitted by secgeeks on Thu, 19/06/2008 - 12:25.Security researchers at antivirus vendor Panda Security have discovered an application that turns executable files into a worm that can spread and cause damage on infected machines.The tool is so easy to use that researchers say very little technical knowledge is needed to pull off a successful attack. The worm can wreak havoc on an [...] read more »
Xpath Injection.
Submitted by secgeeks on Thu, 19/06/2008 - 17:05.Yesterday I wrote a quick proposal for the Synapse project. Since not everyone has access to the Synapse project, I will share some ideas here from time to time. I started with a proposal on how to detect Xpath vulnerabilities. Since Xpath can be used in combination with every server-side language, it is easy to write a detection flow for most languages. XPath injection attacks are similar to regular SQL injection, it is possible to inject the same kind of vectors as we normally do with a slight difference in ending syntax in most cases. read more »
Yahoo Mail flaw found and fixed
Submitted by secgeeks on Wed, 25/06/2008 - 16:19.- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- yahoo mail
Researchers at Cenzic discovered a vulnerability in Yahoo Mail they said could allow attackers to steal Yahoo identities and potentially access users’ sensitive information.The company, a Web application security provider based in Santa Clara, Calif., notified Yahoo of the cross-site scripting flaw in its popular Web mail program on May 23 and Yahoo fixed it [...] read more »
Canadian Pharmacy spammers target Microsoft - Part 2!!
Submitted by secgeeks on Thu, 19/06/2008 - 00:58.Now, Canadian Pharmacy spammers are directly targeting MSN! Spam mails now contain the following text:
About this mailing: read more »
Stop malwares using device control: a real life experience
Submitted by xmachine on Fri, 20/06/2008 - 16:01.If your one of those administrators who hardly try to keep their networks clean and prevent the next malware from infecting their systems, this is definitely for you…
Spending thousands of dollars on security solutions to protect the enterprise from the outside alone is an outdated concept. If you want to ask anyone works in the security arena? What are the main sources of malwares today? He’ll probably answer this: e-mail spam, websites, and removable drives.
Continue Reading ...
http://extremesecurity.blogspot.com/2008/06/stop-malwares-using-device-control-real.html
Email Blogging and spam?
Submitted by secgeeks on Sun, 29/06/2008 - 08:24.I just come to know about a new service which supports the blogging by email.you only needs to send a mail containing a blog post and then this service will create a blog for you.No doubt it makes life much simple but then it can be misused easily.consider a case when someone want to spam the site as there are no login required some one can easily sent tons of spam from different ips,emails and the result will be dangerous. read more »
Use default password, get hijacked
Submitted by xmachine on Fri, 13/06/2008 - 20:56.As the title says, use default password on your wireless/wired routers and wait for the new variant of the "Zlob" trojan to infect some machines, then try every default router username/password combinations from www.routerpassword.com. Or even check this text file, search for your current user/pass to make sure they are not in the list. http://blog.washingtonpost.com/securityfix/zlobpass.txt
Zlob (or as known DNSChanger) will modify the DNS settings to use other rogue DNS servers.
Continue reading ...
http://extremesecurity.blogspot.com/2008/06/use-default-password-get-hijacked.html
where am i?
Submitted by secgeeks on Fri, 13/06/2008 - 16:04.i am quite busy these days and not getting time to manage secgeeks from last few months.things are changing now and hopefully i can get some free time to work on secgeeks now :)
You Can.
Submitted by secgeeks on Tue, 24/06/2008 - 17:37.
It is better to have less thunder in the mouth and more lightning in the hand. -- Apache proverb. read more »
Researchers defend study on patch distribution insecurities
Submitted by secgeeks on Tue, 24/06/2008 - 17:39.A team of security resarchers warn that a patch-based exploit generation technique could be easily carried out by an attacker.
Symantec launches Endpoint Management Suite
Submitted by secgeeks on Tue, 24/06/2008 - 17:39.Symantec integrated its acquisition of Altiris with the release of Endpoint Management Suite 1.0.
- Add new comment
- Get Our RSS Feeds
- report as spam
- 104 reads
The Image Fulgurator.
Submitted by secgeeks on Wed, 02/07/2008 - 15:57.
Julius von Bismarck invented a very interesting hacking technique to manipulate images taken by people. His Image Fulgurator can project text or other images on an object that is being photographed, but only becomes visible on the photograph itself. People's great trust in their photographic reproductions of reality was what motivated Julius to develop the Image Fulgurator. read more »
Changeability.
Submitted by secgeeks on Wed, 02/07/2008 - 15:57.- nice journey
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
- web application security
Plus ca change, plus c'est la meme chose. read more »
Security Experts Expose Costly Vulnerability in Second Life
Submitted by secgeeks on Sun, 02/12/2007 - 06:25.Second Life users need to be cautious with Quicktime embedded videos in the game as it may be used to pick your pocket of Linden Dollars.
Charles Miller and Dino Dai Zovi, of Independent Security Evaluators, have found that by using a flaw in Quicktime, they can not only pick the pocket of any user within 100 virtual feet of the player, they can take complete control of the avatar. Once the account has been taken over, the hackers can then use that avatar to go to other lands, embed their virus loaded video, and it will continue to spread from land to land. read more »
Time to update your Skype
Submitted by secgeeks on Fri, 07/12/2007 - 10:26.Skype users will want to upgrade to version 3.6.0.216 for Windows to close a security hole attackers could exploit to run malicious code on vulnerable machines.According to Danish vulnerability clearinghouse Secunia, the problem is an error in the “skype4com” URI handler when processing short string values and can be exploited to corrupt memory. Successful exploitation [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 138 reads





