Hirantha 的个人资料{ pointy end of the curl...日志列表留言簿 工具 帮助
3月30日

Locate Conficker infected hosts with a network scan

Technorati Tags: ,,,

The Honeynet Project has discovered an anomaly in Conficker that makes it possible to detect infected hosts with an elaborate fingerprint scan over the network. This is great news if you suspect an infection and have no other means to check, or if you simply want to double-check information that your other defense mechanisms (IDS, AntiVirus, etc) provide.

The write-up and scanning tool are available on the Honeynet Website.

3月27日

Firefox and Seamonkey Vulnerabilities

Technorati Tags: ,,

In addition to the "pwn2own" vulnerability used at CanSecWest last week in order to compromise a system with the Firefox web browser, a new vulnerability has been published which involves XSL Transforms.  This vulnerability impacts both the latest Firefox 3.0.7 and Seamonkey 1.1.15 browsers.

Mozilla is working on updates for both packages and they expect the updated versions to be released by April 1

A proof-of-concept exploit for the XSL Transform vulnerability has been released.  If the attack succeeds, arbitrary code can be run in the context of the browser.  If the attack fails, a DoS condition is likely for the browser.

For more information about the XSL Transform issue, see:

BugTraq
Secunia Advisory
VUPEN Advisory
Bugzilla Entry
Mozilla Security Blog

Google Street View is coming to Canada

Technorati Tags: ,

Google will soon be coming to 11 of Canada's largest cities including Halifax, Montreal, Winnipeg and Calgary. The Internet giant will be driving around cities in the coming weeks to map the streets of Canada to include a street-eye view of streets, buildings and their surroundings.

The street view will provide users to help locate meeting spots, buildings and a better idea of their destination. With the added bonus of being able to see your own home on Google, many people raise privacy concerns, which Google is ready to handle. Images of people's faces and licence plates will be automatically blurred out, and any requested offensive images will be removed from the web site.

Google Street View - Canada will be added to the small list of available countries, including Australia, France and Britain. The popular service has been in use on Google for some time on mapping U.S. cities and streets for public view. Some popular street data has already been collected in Canada, where it will be made public soon, along with the 11 new major cities in Canada.

 

More info : Globe and Mail

3月26日

Sun Java JDK / JRE Multiple Vulnerabilities

Technorati Tags: ,,,,

Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a user's system.

More Info : http://secunia.com/advisories/34451/

Windows 7 Developer Guide

Technorati Tags: ,

Build applications on a solid foundation; enable richer application experiences; and integrate the best of Windows and web services. The features and technologies of the Windows 7 operating system enable you to build the next generation of software applications.

More Info and Download : http://code.msdn.microsoft.com/Win7DeveloperGuide

Cisco Releases IOS Bundle of Vulnerabilities

Technorati Tags: ,

Cisco has officially released a "bundle" of vulnerability notices for their IOS software.  The issues related to these notifications are varied and relate to TCP, UDP, Mobile and VPN vulnerabilities.

  • Cisco IOS cTCP DoS Vulnerability
  • Cisco IOS Multiple Features IP Sockets Vulnerability
  • Cisco IOS Mobile IP and Mobile IPv6 Vulnerabilities
  • Cisco IOS Secure Copy Privilege Escalation Vulnerability
  • Cisco IOS Session Initiation Protocol DoS Vulnerability
  • Cisco IOS Multiple Features Crafted TCP Sequence Vulnerability
  • Cisco IOS Multiple Features Crafted UDP Packet Vulnerability
  • Cisco IOS WebVPN and SSLVPN Vulnerabilities

More info : http://www.cisco.com/warp/public/707/cisco-sa-20090325-bundle.shtml

Cisco Releases IOS Bundle of Vulnerabilities

Cisco has officially released a "bundle" of vulnerability notices for their IOS software.  The issues related to these notifications are varied and relate to TCP, UDP, Mobile and VPN vulnerabilities.

  • Cisco IOS cTCP DoS Vulnerability
  • Cisco IOS Multiple Features IP Sockets Vulnerability
  • Cisco IOS Mobile IP and Mobile IPv6 Vulnerabilities
  • Cisco IOS Secure Copy Privilege Escalation Vulnerability
  • Cisco IOS Session Initiation Protocol DoS Vulnerability
  • Cisco IOS Multiple Features Crafted TCP Sequence Vulnerability
  • Cisco IOS Multiple Features Crafted UDP Packet Vulnerability
  • Cisco IOS WebVPN and SSLVPN Vulnerabilities

More info : http://www.cisco.com/warp/public/707/cisco-sa-20090325-bundle.shtml