Advertisement
Home arrow ITsec Advisories
Friday, 29 August 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  14102  79.00%
Win 2003  2666  14.94%
FreeBSD  574  3.22%
Win 2000  209  1.17%
SolarisSunOS  143  0.80%
Other  156  0.87%

Total attacks: 17850 of which 9051 single ip and 8799 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
ITsec Advisories


Microsoft Security Bulletin Summary for August 2008 PDF Print E-mail
User Rating: / 2
Written by Marcelo Almeida (Vympel)   
Wednesday, 13 August 2008
This bulletin summary lists security bulletins released for August 2008.

With the release of the bulletins for August 2008, this bulletin summary replaces the bulletin advance notification originally issued August 7, 2008. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance Notification.

For information about how to receive automatic notifications whenever Microsoft security bulletins are issued, visit Microsoft Technical Security Notifications.

Microsoft is hosting a webcast to address customer questions on these bulletins on August 13, 2008, at 11:00 AM Pacific Time (US & Canada). Register now for the August Security Bulletin Webcast. After this date, this webcast is available on-demand. For more information, see Microsoft Security Bulletin Summaries and Webcasts...

Write Comment (0 Comments)
Read more...
 
Joomla! "token" Password Change Vulnerability PDF Print E-mail
User Rating: / 13
Written by Marcelo Almeida (Vympel)   
Wednesday, 13 August 2008
  • Project: Joomla!
  • SubProject: com_user
  • Severity: Critical
  • Versions: 1.5.5 and all previous 1.5 releases
  • Exploit type: Password Reset Forgery
  • Reported Date: 2008-August-12
  • Fixed Date: 2008-August-12







Description

A flaw in the reset token validation mechanism allows for non-validating tokens to be forged. This will allow an unauthenticated, unauthorized user to reset the password of the first enabled user (lowest id). Typically, this is an administrator user. Note, that changing the first users username may lessen the impact of this exploit (since the person who changed the password does not know the login associated with the new password). However, the only way to completely rectify the issue is to upgrade to 1.5.6 (or patch the /components/com_user/models/reset.php file)...

Write Comment (2 Comments)
Read more...
 
HP-UX HP CIFS Server Multiple Vulnerabilities PDF Print E-mail
User Rating: / 0
Written by Marcelo Almeida (Vympel)   
Tuesday, 24 June 2008
HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious people to compromise a vulnerable system.

For more information:
Secunia adv SA27450
Secunia adv SA27760
Secunia adv SA30228

The vulnerabilities affect HP CIFS Server vA.02.01.*, vA.02.02.*, and vA.2.03.* prior to vA.02.03.04 running on HP-UX B.11.11, B.11.23, and B.11.31... Write Comment (0 Comments)
Read more...
 
SUSE update for kernel PDF Print E-mail
User Rating: / 1
Written by Marcelo Almeida (Vympel)   
Tuesday, 24 June 2008
SUSE Security Announcement

Package: kernel
Announcement ID: SUSE-SA:2008:030
Date: Fri, 20 Jun 2008 14:00:00 +0000
Affected Products: openSUSE 10.2
openSUSE 10.3
Vulnerability Type: remote denial of service
Severity (1-10): 9
SUSE Default Package: yes
Cross-References: CVE-2007-5500, CVE-2007-5904, CVE-2007-6206
CVE-2007-6282, CVE-2007-6712, CVE-2008-0600
CVE-2008-1367, CVE-2008-1375, CVE-2008-1615
CVE-2008-1669, CVE-2008-2136, CVE-2008-2148
CVE-2008-2358... Write Comment (0 Comments)
Read more...
 
AproxEngine "page" Local File Inclusion Vulnerability PDF Print E-mail
User Rating: / 0
Written by Marcelo Almeida (Vympel)   
Tuesday, 24 June 2008

SkyOut has discovered a vulnerability in AproxEngine, which can be exploited by malicious people to disclose potentially sensitive information.

Input passed to the "page" parameter in index.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources.

The vulnerability is confirmed in version 5.1.0.4. Other versions may also be affected...

Write Comment (1 Comments)
Read more...
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Results 1 - 15 of 9513
 
Top! Top!