Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

ZDNET
Charlie Miller Skipping Pwn2Own As New Rules Change Hacking Game
Annual hacker contest troubled by new rules, controversy over disclosure

ZDNET
FBI Warns Congress Of Terrorist Hacking
Terrorist groups may employ hackers to attack the United States, Mueller warns

THE REGISTER
Researchers Find MYSTERY Programming Language In Duqu Trojan
Researchers ask for help in identifying unknown programming language

SECURELIST
DNSChanger -- Cleaning Up 4 Million Infected Hosts
Disinfection will take time, expert warns

WIRED
Researchers Seek Help In Solving DuQu Mystery Language
Kaspersky Lab researchers are asking for help in identifying the thus far unknown language with which the communications module of Duqu was written

GAWKER
'I'm Not Scared of Jail': My Phone Call With Sabu, The FBI's Anonymous Informant
Reporter details his phone conversation with Sabu last year where he may have been attempting to spread disinformation via the FBI

ARS TECHNICA
"Everything Incriminating Has Been Burned": Anons Fight Panic After Sabu Betrayal
"Avunit," the last of the original LulzSec members who has not yet been caught, doesn't know whether he faces charges and is preparing to leave Anonymous altogether after literally burning all evidence of his activities with the group

H ONLINE
Android Anti-Virus Software Is Frequently Unreliable
AV-Test found only seven Android AV products achieving a detection rate of 95% percent or more and 24 with rates below 65 percent

ICSA LABS
Sponsored Ads Serving Up Scams On Facebook
A look at what appears to be an Amazon ad, but instead takes the user to a page that hides its owner via a proxy service

THE REGISTER
The One Tiny Slip That Put Lulzsec Chief Sabu In The FBI's Pocket
The alleged LulzSec kingpin Hector Xavier Monsegur was discovered by the FBI after he made the mistake of logging into an IRC chat server without using the Tor anonymization service, according to Errata Security

RATIONAL SURVIVABILITY
Funny Thing Happened On My Way To Malware Removal...
The blog was infected in the wake of the Dreamhost password compromise in January, via an automated injection of malicious PHP code into a plug-in directory that had poor permissions

ARBOR BLOG
Analysis Of The Crypto Used By The Trojan.Khan DDoS Bot
The DDoS botnet obfuscates its command and control URLs using a custom crypto algorithm

THE REGISTER
Panda Cops Anonymous Retribution
Defacing of website appears to be backlash for Lulzsec arrests

THREATMETRIX
ThreatMetrix Labs Report February 2012 -- Man-In-The-Browser: Apple Mac OSX Edition
Second in a series of reports on now to launch MiB attacks on Apple devices

THE AGE
Irish Email Blunder Led To FBI Leak
An Irish police officer's email mistake led to leak of conference call between FBI and Scotland Yard

HELP NET SECURITY
The Decline Of Trust In Social Networking Platforms
Cloudmark study says consumers are worried about security threats to popular platforms

WDTV
Spammers Use Election To Target Your Bank Account
Legitimate-looking election emails are really phishing attacks, authorities say

CSO ONLINE
Can Corporate Hacking Have A Bright Side?
Stratfor hack might be a wake-up call for the industry

CHICAGO TRIBUNE
Chicago Man, 27, Charged In Cyberattack
Jeremy Hammond tells federal authorities he is a member of AntiSec

COMPUTING.CO.UK
Companies Ignoring Threat From Meeting Room Hackers, Warns Security Expert
Conference room spies may be listening in to private conversations, Zscaler's Sutton warns

SYMANTEC
Anonymous Supporters Tricked Into Installing Zeus Trojan
On the day of the MegaUpload raid, an attacker modified a Pastebin guide used by Anonymous for denial-of-service tools and injected a Trojanized version of the Slowloris tool

TORRENT FREAK
Police Censor Google, Facebook And 8,000 Other Sites By Accident
Thousands of websites were blocked at the DNS level yesterday for Danish users due to "human error" by the High Tech Crime Unit

NETWORK WORLD
FBI: Cyberattacks Could Shove Aside Terrorism As No. 1 Threat To US
Terrorism remains the FBI's top priority, but FBI director says he expects cyberthattacks to usurp that in the near future

WIRED
Is Antivirus Software A Waste Of Money?
Several security experts don't run antivirus software because they feel if someone is going to try and attack them, they're likely to use a new technique, one that most antivirus products will miss

DVLABS BLOG
Pwn2Own 2012 And Google Pwnium
ZDI responds to Google's withdrawl of sponsorship of this year's Pwn2Own contest and plans for a similar contest focused solely only on its products

THREAT POST
The Security Game Needs To Change
Frustation was clear at RSA as industry is wondering whether there's any change or improvement on the horizon as security approaches have failed

SEARCHSECURITY
OpenDNS Hires Websense CTO To Guide Enterprise DNS Security Services
DNS services provider OpenDNS is laying the groundwork for a variety of DNS layer security services and products aimed at enterprises

THE REGISTER
FBI Boss Warns Online Threats Will Outpace Terrorism
In the not-too-distant future, cyber will become the No. 1 threat to the U.S., Mueller says

PC WORLD
Concern Rises Over The Capabilities Of Anonymous Hacktivists
Hacktivist group openly discusses potential threats to Internet DNS, power grid

FOX NEWS
Internet Outage At The Pentagon
Defense Information Systems Agency says downtime is not the result of a cyberattack

THREAT POST
Debate Over Active Defense And Hacking Back Crops Up At RSA
Former intelligence officials and technologists say offensive defense need to differentiate between retaliating against a known attacker and using offensive techniques to deter a potential attacker

EWEEK
Google Privacy Policy Changes Coming Despite Regulatory Disdain
Google contends that its new privacy policy will quality of service to users, but critics say it's just another way for Google to target ads

CNET
In The World Of Big Data, Privacy Invasion Is The Business Model
Privacy invasion is the business model in the information economy as companies sell your information

SEARCH SECURITY
Research Into Cryptographic System Limitations Crucial, RSA Panel Says
Cryptographer's Panel at RSA concluded that while the cryptosystems have remained unbroken for years, researchers are doing key work by testing these technologies

CIO
NTIA: Mobile Privacy May Be A Top Priority In New Push
The National Telecommunications and Information Administration solicits public comments as it begins to write privacy codes of conduct

WASHINGTON TECHNOLOGY
Mantech Deal Expands Cybersecurity Chops
In an a move to expand its cybersecurity capabilities, ManTech International Corp. plans to acquire HBGary

CSO ONLINE
FBI Vows To Catch Insider Traders On Facebook And Skype
The FBI is upping its Operation Perfect Hedge investigations aimed at catching hedge funds and associates involved in illegal trading

NETWORK WORLD
Microsoft's Azure Cloud Suffers Serious Outage
Microsoft's Azure cloud infrastructure and development service went down on Wednesday after its service management component experienced a serious outage worldwide

THE LA TIMES
Smartphone Security Gap Exposes Location, Texts, Email, Expert Says
A researcher with startup CrowdStrike says his team has converted a remote access tool out of China to take control over an Android smartphone

FORBES
WikiLeaks Tightens Ties To Anonymous In Leak Of Stratfor Emails
WikiLeaks announced that it will release 5.5 million emails from Stratfor in what it says will show Stratfor's involvement in monitoring activists and insider trading


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)