Security Watch


Are you surfing safely? Try Better and Safer Computing

TrendMicro.com


ISS Threat Index page

SecurityFocus.com
Vuln: SimpleIrcBot Authentication Unspecified Security Bypass Vulnerability
SimpleIrcBot Authentication Unspecified Security Bypass Vulnerability 2009-01-06

Vuln: L2J Multiple Unspecified Security Vulnerabilities
L2J Multiple Unspecified Security Vulnerabilities 2009-01-06

Vuln: Walusoft TFTPServer2000 TFTP Server Directory Traversal Vulnerability
Walusoft TFTPServer2000 TFTP Server Directory Traversal Vulnerability 2009-01-06

Vuln: PHPAuctions 'profile.php' SQL Injection and Cross Site Scripting Vulnerabilities
PHPAuctions 'profile.php' SQL Injection and Cross Site Scripting Vulnerabilities 2009-01-06

Bugtraq: New WHID web hacking incidents
New WHID web hacking incidents

Bugtraq: Re: php 4.x php5.2.x all "show_source()" ,"highlight_file()" bypass‏
Re: php 4.x php5.2.x all "show_source()" ,"highlight_file()" bypass‏



News: Group attacks flaw in browser crypto security
Group attacks flaw in browser crypto security

News: Commission calls for cybersecurity czar
Commission calls for cybersecurity czar

News: Microsoft hopes free security means less malware
Microsoft hopes free security means less malware

>> Advertisement <<


News: Researchers find more flaws in wireless security
Researchers find more flaws in wireless security

Brief: Survey: One in seven SSL certificates are weak
Survey: One in seven SSL certificates are weak

Brief: Microsoft's music players die for a day
Microsoft's music players die for a day

>> Advertisement <<



ISTS Dartmouth News


Incidents.org
OSSEC HIDS being detected as malware, (Mon, Jan 5th)
Daniel from OSSEC has reported that a couple Antivirus products are currently detecting the Windows ...(more)... Tue, 06 Jan 2009 13:50:16 GMT


An interesting article from the TimesOnline - http://www.timesonline ...(more)... Tue, 06 Jan 2009 13:44:10 GMT


Reader Tomasz sent in a message discussing the demise of JournalSpace. JournalSpace was a rela ...(more)... Sun, 04 Jan 2009 16:09:54 GMT


Several readers have sent us information about a phishing attempt based on Twitter and possibly Face ...(more)... Sun, 04 Jan 2009 15:45:09 GMT


Emails have been trickling into the ISC with information about the ongoing Cyberwar accompanying the ...(more)... Sun, 04 Jan 2009 00:08:06 GMT


Every year I create a list of things I would like to do with my spare time over the holiday break.n ...(more)... Sat, 03 Jan 2009 23:11:52 GMT


Insecure.org
http://seclists.org/bugtraq/2009/Jan/0024.html">New WHID web hacking incidentsPosted by Ofer Shezaf on Jan 06<p>
New WHID web hacking incidentsPosted by Ofer Shezaf on Jan 06<p><br />...http://seclists.org/bugtraq/2009/Jan/0024.htmlhttp://seclists.org/bugtraq/2009/Jan/0024.html

http://seclists.org/bugtraq/2009/Jan/0023.html">[USN-703-1] xterm vulnerabilityPosted by Kees Cook on Jan 5<p>
[USN-703-1] xterm vulnerabilityPosted by Kees Cook on Jan 5<p><p>Ubuntu...http://seclists.org/bugtraq/2009/Jan/0023.htmlhttp://seclists.org/bugtraq/2009/Jan/0023.html

http://seclists.org/bugtraq/2009/Jan/0022.html">Re: php 4.x php5.2.x all quotshow_source()quot ,quothighlight_file()quot bypassamp8207Posted by Slack Traq on Jan 6<p>
Re: php 4.x php5.2.x all quotshow_source()quot ,quothighlight_file()quot bypassamp8207Posted by Slack Traq on Jan 6<p><p>--- On Sun, 1/4/09,...http://seclists.org/bugtraq/2009/Jan/0022.htmlhttp://seclists.org/bugtraq/2009/Jan/0022.html

http://seclists.org/bugtraq/2009/Jan/0021.html">[SECURITY] [DSA 1694-2] New xterm packages fix regressionPosted by Florian Weimer on Jan 06<p>
[SECURITY] [DSA 1694-2] New xterm packages fix regressionPosted by Florian Weimer on Jan 06<p>January 06, 2009 ...http://seclists.org/bugtraq/2009/Jan/0021.htmlhttp://seclists.org/bugtraq/2009/Jan/0021.html

http://seclists.org/bugtraq/2009/Jan/0020.html">[Suspected Spam]quotSecurity Assessment of the Internet Protocolquot amp the IETFPosted by Fernando Gont on Jan 05<p>
[Suspected Spam]quotSecurity Assessment of the Internet Protocolquot amp the IETFPosted by Fernando Gont on Jan 05<p>explained in the Preface of the document itself. (The...http://seclists.org/bugtraq/2009/Jan/0020.htmlhttp://seclists.org/bugtraq/2009/Jan/0020.html

http://seclists.org/bugtraq/2009/Jan/0019.html">[USN-702-1] Samba vulnerabilityPosted by Marc Deslauriers on Jan 05<p>
[USN-702-1] Samba vulnerabilityPosted by Marc Deslauriers on Jan 05<p><p>This...http://seclists.org/bugtraq/2009/Jan/0019.htmlhttp://seclists.org/bugtraq/2009/Jan/0019.html


http://seclists.org/incidents/2008/Dec/0007.html">Re: incidents from historyPosted by moto kawasaki on Dec 02<p>
Re: incidents from historyPosted by moto kawasaki on Dec 02<p><p>...http://seclists.org/incidents/2008/Dec/0007.htmlhttp://seclists.org/incidents/2008/Dec/0007.html

http://seclists.org/incidents/2008/Dec/0006.html">Re: incidents from historyPosted by Jay D. Dyson on Dec 1<p>
Re: incidents from historyPosted by Jay D. Dyson on Dec 1<p>&gt; It was a...http://seclists.org/incidents/2008/Dec/0006.htmlhttp://seclists.org/incidents/2008/Dec/0006.html

http://seclists.org/incidents/2008/Dec/0005.html">Re: incidents from historyPosted by Tony Maupin on Dec 1<p>
Re: incidents from historyPosted by Tony Maupin on Dec 1<p>systematic attack to...http://seclists.org/incidents/2008/Dec/0005.htmlhttp://seclists.org/incidents/2008/Dec/0005.html

http://seclists.org/incidents/2008/Dec/0004.html">Re: incidents from historyPosted by Geoffrey J Gowey on Dec 1<p>
Re: incidents from historyPosted by Geoffrey J Gowey on Dec 1<p>&gt; I want to know if someone can name the greatest...http://seclists.org/incidents/2008/Dec/0004.htmlhttp://seclists.org/incidents/2008/Dec/0004.html

http://seclists.org/incidents/2008/Dec/0003.html">RE: incidents from historyPosted by Dario Ciccarone on Dec 1<p>
RE: incidents from historyPosted by Dario Ciccarone on Dec 1<p><p>...http://seclists.org/incidents/2008/Dec/0003.htmlhttp://seclists.org/incidents/2008/Dec/0003.html

http://seclists.org/incidents/2008/Dec/0002.html">Re: incidents Digest 1 Dec 2008 20:41:14 -0000 Issue 920Posted by Kristian Erik Hermansen on Dec 1<p>
Re: incidents Digest 1 Dec 2008 20:41:14 -0000 Issue 920Posted by Kristian Erik Hermansen on Dec 1<p>&gt; Date: Sat, 29 Nov 2008 16:48:22...http://seclists.org/incidents/2008/Dec/0002.htmlhttp://seclists.org/incidents/2008/Dec/0002.html


US-CERT.gov
TA08-352A: Microsoft Internet Explorer Data Binding Vulnerability
Microsoft Internet Explorer Data Binding Vulnerability


TA08-350A: Apple
Apple


TA08-344A: Microsoft Updates for Multiple Vulnerabilities
Microsoft Updates for Multiple Vulnerabilities


TA08-340A: Sun Java Updates for Multiple Vulnerabilities
Sun Java Updates for Multiple Vulnerabilities


TA08-319A: Mozilla Updates for Multiple Vulnerabilities
Mozilla Updates for Multiple Vulnerabilities



Secunia.com
[1/5] Sun Solaris NFS Local Denial of Service Vulnerability
A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).


[2/5] Nokia Phones SMS Denial of Service Vulnerability
Tobias Engel has reported a vulnerability in various Nokia phones, which can be exploited by malicious people to cause a DoS (Denial of Service).


[3/5] PHPAuctions Multiple Vulnerabilities
Some vulnerabilities have been reported in PHPAuctions, which can be exploited by malicious people to conduct SQL injection and cross-site scripting attacks, and bypass certain security restrictions.


[2/5] SemanticScuttle Cross-Site Request Forgery Vulnerabilities
Some vulnerabilities have been reported in SemanticScuttle, which can be exploited by malicious people to conduct cross-site request forgery attacks.


[3/5] SolucionWeb "id_area" SQL Injection Vulnerability
Ehsan_Hp200 has reported a vulnerability in SolucionWeb, which can be exploited by malicious people to conduct SQL injection attacks.


[3/5] Ubuntu update for xterm
Ubuntu has issued an update for xterm. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.


[2/5] Poll Pro Cross-Site Request Forgery Vulnerability
The_0nur-n0x has discovered a vulnerability in Poll Pro, which can be exploited by malicious people to conduct cross-site request forgery attacks.



Links to resources

TropTech.com home page
Security by nsfetcu
[ Join Now | Ring Hub | Random | << Prev | Next >> ]