BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks

 

Tracking GhostNet: Investigating a Cyber Espionage Network

This report documents the GhostNet – a suspected cyber espionage network of over 1,295 infected computers in 103 countries, 30% of which are high-value targets, including ministries of foreign affairs, embassies, international organizations, news media, and NGOs.
The capabilities of GhostNet are far-reaching. The report reveals that Tibetan computer systems were compromised giving attackers access to [...]

Read More About - Tracking GhostNet: Investigating a Cyber Espionage Network »

Conficker Worm Targets Microsoft Windows Systems

US-CERT is aware of public reports indicating a widespread infection of the Conficker worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across the network if the host is not patched with MS08-067.
The presence of a Conficker infection may be detected if a user is unable to [...]

Read More About - Conficker Worm Targets Microsoft Windows Systems »

Java Security Vulnerabilities

Sun Releases Updates for Java SE
added March 26, 2009 at 08:54 am
Sun has released updates for Java SE to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or operate with escalated privileges.
US-CERT encourages users to review the Sun Java SE 6 Update Release Notes and upgrade [...]

Read More About - Java Security Vulnerabilities »

Microsoft Updates for Multiple Vulnerabilities

Source: US-CERT
As part of the Microsoft Security Bulletin Summary for March 2009, Microsoft released updates to address vulnerabilities that affect Microsoft Windows and Windows Server.
A remote, unauthenticated attacker could gain elevated privileges, poison the DNS cache, execute arbitrary code, or cause a vulnerable application to crash.
Solution
Microsoft has provided updates for these vulnerabilities in the Microsoft [...]

Read More About - Microsoft Updates for Multiple Vulnerabilities »

Is Your Computer Part of a Zombie Army?

(NAPS) — Hackers and spammers may be using your computer right now. They invade secretly and hide software to get access to the information on your computer, including your e-mail program. Once on your computer, they can spy on your Internet surfing, steal your personal information and use your computer to send spam to [...]

Read More About - Is Your Computer Part of a Zombie Army? »

Waledac Trojan Horse Spam Campaign Circulating

US-CERT is aware of public reports of malicious code circulating via spam email messages related to bogus terror attacks in the recipient’s local area. These messages use subject lines implying that a fatal bomb attack has occurred near the recipient and contain a link to “breaking news.” Users who click on the link will be [...]

Read More About - Waledac Trojan Horse Spam Campaign Circulating »

Economic Stimulus Email and Website Scams

US-CERT is aware of reports of economic stimulus scams circulating. These scams are being conducted through both email and malicious websites.
Some of the email scam messages request personal information, which can then be used for identity theft. Other email scam messages offer to deposit the stimulus funds directly into users’ bank accounts. If users provide [...]

Read More About - Economic Stimulus Email and Website Scams »

Mozilla Foundation Releases Firefox 3.0.7

Mozilla Foundation has released Firefox 3.0.7 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof the location bar. The Mozilla Foundation Security Advisories also indicate that these vulnerabilities affect Thunderbird and SeaMonkey.
US-CERT encourages users to review the following Mozilla Foundation Security [...]

Read More About - Mozilla Foundation Releases Firefox 3.0.7 »

RSS BugTraq

  • VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability
    Posted by VUPEN Security Research on Mar 12VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability http://www.vupen.com/english/research.php I. BACKGROUND --------------------- "Safari is a web browser developed by Apple. As of February 2010, Safari was the fourth most widely used browser, with 4.45% of the worldwide usag […]
  • [XSS] I found a xss in phpmyadmin 3.3.0 when we create new database in interface!
    Posted by lis cker on Mar 12there is a xss in phpmyadmin 3.3.0 when we create new database in interface, the "new_db" parameter do not filter characters when users enter. attacker can enter malicious code, like "alert(/liscker/);". it also can be true in post and get. but in post, we can not encode xss code, or , the xss will faild. For e […]
  • [SECURITY] [DSA 2013-1] New egroupware packages fix several vulnerabilities
    Posted by Moritz Muehlenhoff on Mar 12------------------------------------------------------------------------ Debian Security Advisory DSA-2013-1 security () debian org http://www.debian.org/security/ Moritz Muehlenhoff March 11, 2010 http://www.debian.org/security/faq ------------------------------------------------------------------------ Package : egroup […]
  • [SECURITY] [DSA 2014-1] New moin packages fix several vulnerabilities
    Posted by Giuseppe Iuculano on Mar 12------------------------------------------------------------------------ Debian Security Advisory DSA-2014-1 security () debian org http://www.debian.org/security/ Giuseppe Iuculano March 12, 2010 http://www.debian.org/security/faq ------------------------------------------------------------------------ Package : moin Vul […]
  • iDefense Security Advisory 03.11.10: Multiple Vendor WebKit HTML Element Use After Free Vulnerability
    Posted by iDefense Labs on Mar 12iDefense Security Advisory 03.11.10 http://labs.idefense.com/intelligence/vulnerabilities/ Mar 11, 2010 I. BACKGROUND WebKit is an open source web browser engine. It is currently used by Apple Inc.'s Safari browser, as well as by Google's Chrome browser. For more information, see the vendor's site at the follow […]