RedTram News Search Engine
Русский  English Українська  Français  Polski  Deutsch  Italiano  Español  中文   
15 May 2008 year (time zone GMT 00:00)  Number of sources in English: 4473
Navigating the themes
Navigating the regions
All Themes Technologies Hard & Soft Information Security World
Information Security (World) RSS 2.0

Ubuntu: OpenVPN regression

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: USN-612-3 addressed a weakness in OpenSSL certificate and keys generation in OpenVPN by adding checks for vulnerable certificates and keys to OpenVPN. A regression was introduced in OpenVPN when using TLS and multi-client/server which caused OpenVPN to not start


Ubuntu: OpenSSH update

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: Matt Zimmerman discovered that entries in ~/.ssh/authorized_keys with options (such as "no-port-forwarding" or forced commands) were ignored by the new ssh-vulnkey tool introduced in OpenSSH (see USN-612-2). This could cause some compromised keys not to be listed in ssh-vulnkey's

Gentoo: OpenOffice.org Multiple vulnerabilities

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: Multiple vulnerabilities have been reported in OpenOffice.org, possibly allowing for user-assisted execution of arbitrary code.

Debian: New gforge packages fix insecure temporary files

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: Stephen Gran and Mark Hymers discovered that some scripts run by GForge, a collaborative development tool, open files in write mode in a potentially insecure manner. This may be exploited to overwrite arbitary files on the local system.

Gentoo: libid3tag Denial of Service

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: A Denial of Service vulnerability was found in libid3tag.

Encrypted Root LVM

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: I am assuming that you already know how to set up an encrypted file system using cryptsetup with luks (or something else). There are several howtos. I am also assuming that you are familiar with LVM2. This tutorial deals

GPG-Based Password Wallet

15.05.2008 23:45    linuxsecurity.com
LinuxSecurity.com: Like many Internet addicts, I have way too many user name/password accounts to remember: accounts on social-networking sites, rarely used logins at work, on-line banking and so on. One solution to this problem is to use the same user

Protecting Users Against Themselves

15.05.2008 22:35    windowsecurity.com
How to prevent your staff from unintentionally turning into an insider threat.

Brief: TJX completes Mastercard breach settlement

15.05.2008 22:25    securityfocus.com
TJX completes Mastercard breach settlement

Spam Evolution: March 2008

15.05.2008 19:05    viruslist.com
Spam in mail traffic averaged 90.7% in March 2008. A low of 83.5% was recorded on 27 March, while a high of 97.8% occurred on 1 March.
World    Spam    Articles

Drupal Site Documentation Module Information Disclosure

15.05.2008 18:28    secunia.com
A vulnerability has been reported in the Site Documentation module for Drupal, which can be exploited by malicious people to disclose sensitive information. The module displays data from arbitrary tables in the database. This can be exploited to e.g. get

Fusebox "FUSEBOX_APPLICATION_PATH" File Inclusion

15.05.2008 18:28    secunia.com
MajnOoNxHaCkEr has discovered a vulnerability in Fusebox, which can be exploited by malicious people to disclose sensitive information and to compromise a vulnerable system. Input passed to the "FUSEBOX_APPLICATION_PATH" parameter in fusebox5.php is not properly verified before being used to

phpVID "query" Cross-Site Scripting Vulnerability

15.05.2008 18:28    secunia.com
Russ McRee has reported a vulnerability in phpVID, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed to the "query" parameter in search_results.php is not properly sanitised before being returned to the user. This can

Bots Use SQL Injection Tool in Web Attack and Rant

15.05.2008 18:28    cgisecurity.com
The Asprox botnet, a relatively small botnet known mainly for sending phishing emails, has been spotted in the last few days installing an SQL injection attack tool on its bots. The bots then Google for .asp pages with specific terms

Tools: Peach Fuzzer Framework 2.1 BETA2 Released

15.05.2008 18:28    cgisecurity.com
The following was sent to the daily dave list today by Michael Eddington

Content Protection madness on Vista

15.05.2008 17:39    news.zdnet.com
UPDATE: For more on this issue, check out this post.] I'm a firm believer in the idea that if you pay for hardware, you should be able to make full use of it. However, DRM and content protection mechanisms are

With the Quickness: HD Moore sets new land speed record with exploitation of Debian/Ubuntu OpenSSL flaw

15.05.2008 17:39    news.zdnet.com
So, for those who haven't heard, a Debian packager modified the source used for OpenSSL on Debian based systems Debian and the whole of the Ubuntu family to remove the seed used for PRNG Pseudo Random Number Generator used when

News to know: Comcast-Plaxo; Icahn-Yahoo; Linux; Microsoft

15.05.2008 17:38    news.zdnet.com
Notable headlines: Larry Dignan: Comcast buys Plaxo: Will social networking and TV fly? Dennis Howlett: Comcast scoops up Plaxo: good move Dan Farber: Comcast goes social with Plaxo acquisition Techmeme EIC podcast: HP-EDS; Google; SaaS Adrian...

Security Researcher to release Cisco rootkit at EUSecWest

15.05.2008 17:38    news.zdnet.com
According to good friend Robert McMillan of IDG News, Sebastian Muniz, a researcher with Core Security Technologies, has developed malicious rootkit software for Cisco's routers, which he will release on May 22 at the EuSecWest conference in London. This will

Safari "Carpet Bomb" attack information released

15.05.2008 17:38    news.zdnet.com
Nitesh Dhanjani released information about some of his newest research on the Safari web browser this morning, and interestingly enough, Apple has decided NOT to fix some of the issues he presented. Dhanjani reported three issues, as follows below from

1 | 2 | 3 | 4 »