Blog Posts Tagged with "vulnerability"

A58bf865b185e0e3f665473bf8f3ca6d

ICS-CERT Alerts of Mitsubishi MX SCADA Vulnerability

April 03, 2013 Added by:Steve Ragan

ICS-CERT has issued a warning this week after vulnerability details concerning Mitsubishi’s MX Component started to gain attention online.

Comments  (0)

219bfe49c4e7e1a3760f307bfecb9954

MongoDB Remote Command Execution Vulnerability: Nightmare or Eye-Opener?

April 03, 2013 Added by:Rohit Sethi

The March 24th public disclosure of a MongoDB zero-day vulnerability (CVE-2013-1892) has been raising eyebrows and initiating discussion among IT security and developers alike. Here’s why we think it stands out...

Comments  (0)

306708aaf995cf6a77d3083885b60907

Podcast: Vupen CEO Chaouki Bekrar Talks About Selling Zero Days at CanSecWest

March 08, 2013 Added by:Mike Lennon

Ryan Naraine talks to Vupen CEO Chaouki Bekrar about the controversies surrounding the sale of zero-day vulnerabilities and exploits, his company’s business dealings and the work that goes into winning the CanSecWest Pwn2Ownhacker contest.

Comments  (0)

7d55c20d433dd60022642d3ab77b8efb

Oracle Has Yet Again Underestimated The Criticality Of Vulnerabilities. Now in JD Edwards ERP

February 26, 2013 Added by:Alexander Polyakov

ERPScan researchers helped Oracle to eliminate a dangerous vulnerability in JD Edwards' Enterprise One, in the way the thick client is used on workstations. The vulnerability was closed in the January patch by Oracle (CVE-2012-1678).

Comments  (1)

306708aaf995cf6a77d3083885b60907

Latest Adobe Zero-day is Serious Business

February 14, 2013 Added by:Mike Lennon

The exploits have been seen in extremely targeted attacks against high profile targets, and are a sophisticated effort that appear to be the first to successfully escape Adobe’s “protected mode” sandbox. Make no mistake about it; this attack is serious business and not the work of amateurs.

Comments  (0)

7fef78c47060974e0b8392e305f0daf0

ICS-CERT: Key Management Errors in RuggedCom’s ROS

August 23, 2012 Added by:Infosec Island Admin

ICS-CERT is aware of a report of hard-coded RSA SSL private key within RuggedCom’s Rugged Operating System (ROS). The vulnerability with proof-of-concept (PoC) exploit code by security researcher Justin W. Clarke can be used to decrypt SSL traffic between an end user and a RuggedCom network device...

Comments  (0)

7fef78c47060974e0b8392e305f0daf0

ICS-CERT: Siemens Synco OZW Web Server Vulnerability

August 13, 2012 Added by:Infosec Island Admin

Siemens has reported to ICS-CERT that a default password vulnerability exists in the Siemens Synco OZW Web Server device used for building automation systems. Siemens urges their customers to set a secure password on their device’s web interface. This vulnerability could be exploited remotely...

Comments  (0)

7fef78c47060974e0b8392e305f0daf0

ICS-CERT: SpecView Directory Traversal Vulnerability

August 08, 2012 Added by:Infosec Island Admin

ICS-CERT is aware of a public report of a directory traversal vulnerability with proof-of-concept (PoC) exploit code affecting SpecView when a specially crafted request is passed to the web server running on Port 80\TCP. Successful exploitation could result in data leakage...

Comments  (0)

7fef78c47060974e0b8392e305f0daf0

ICS-CERT: Siemens Simatic Step 7 DLL Vulnerability

July 25, 2012 Added by:Infosec Island Admin

Siemens self-reported a DLL hijacking vulnerability in SIMATIC STEP 7 and SIMATIC PCS 7 software. This vulnerability can be remotely exploited and public exploits are known to target this vulnerability. Siemens has produced a patch that resolves this vulnerability...

Comments  (0)

9a824a3f55b26adad5431f6715dbec2e

Cyberoam DPI Vulnerability Alarms Tor Project

July 10, 2012 Added by:Pierluigi Paganini

Tor Project found a vulnerability in Cyberoam DPI where all share the same digital certificate and the private key is the same for every device. The implications are serious, as it could be possible to catch traffic from any user by extracting the key and importing it into other DPI devices for interception...

Comments  (0)

7d55c20d433dd60022642d3ab77b8efb

Critical Vulnerability in SAP Message Server: A Worldwide Scan

July 04, 2012 Added by:Alexander Polyakov

Two buffer overflow vulnerabilities in SAP Message Server can be exploited remotely so that exploit code can be executed. Out of 1000 companies that use SAP worldwide, randomly selected in the course of the research, 4% expose SAP Message Server to the Internet. This can lead to critical consequences...

Comments  (0)

69dafe8b58066478aea48f3d0f384820

KeePass Vulnerability Exposes Password Lists

June 28, 2012 Added by:Headlines

“The bug will be injected on the remote way, affects the local validation (html/xml) and change the technic back when remotely transferring the password lists. The injection of the malicious URL/domain context can be done via auto save of URLs (victim) or manually (reproduce)," the researchers stated...

Comments  (1)

7fef78c47060974e0b8392e305f0daf0

ICS-CERT: Sielco Sistemi Winlog Buffer Overflow

June 18, 2012 Added by:Infosec Island Admin

ICS-CERT is aware of a public report of a buffer overflow vulnerability with proof-of-concept exploit code affecting Sielco Sistemi Winlog. The vulnerability is exploitable by sending specially crafted requests to TCP/46824 which could result in a denial of service and remote code execution...

Comments  (0)

Baed7cd90281d85b6943e9bf3cfc9fe0

ZOMG: LinkedIn was Hacked and our Passwords Were Leaked

June 10, 2012 Added by:Scot Terban

LinkedIn and other companies like Sony have shown time and again, they DON’T CARE about YOUR data. Always remember this people. So, you want an account on these places, then you best make a throw away password and limit your data on the sites that host it. Otherwise, your data will be up for the taking...

Comments  (1)

D8853ae281be8cfdfa18ab73608e8c3f

SUDOERS Commented Code Includes Use for Evil

May 31, 2012 Added by:Rob Fuller

When I started looking into appending or inserting lines into /etc/sudoers for CCDC, I happened upon an interesting function of that file. Near the end of the file there are two lines that look commented out, but in actuality are interpreted and acted upon, an evil way to stay hidden on a 'nix box...

Comments  (0)

Baed7cd90281d85b6943e9bf3cfc9fe0

The Biggest Attack Surface is US

May 30, 2012 Added by:Scot Terban

As technologies advance and the human nature side of things continues to allow for strides in security as well as the inevitable setbacks, you will become the ultimate target of the easy score for data that could lead to compromise. After all, what do you think the real persistent threats rely on? Human nature...

Comments  (0)

Page « < 1 - 2 > »