BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks

BuyLow.com | Resources | Contact Us


 

Conficker Worm Targets Microsoft Windows Systems

US-CERT is aware of public reports indicating a widespread infection of the Conficker worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across the network if the host is not patched with MS08-067.
The presence of a Conficker infection may be detected if a user is unable to [...]

Read More About - Conficker Worm Targets Microsoft Windows Systems »

Java Security Vulnerabilities

Sun Releases Updates for Java SE
added March 26, 2009 at 08:54 am
Sun has released updates for Java SE to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or operate with escalated privileges.
US-CERT encourages users to review the Sun Java SE 6 Update Release Notes and upgrade [...]

Read More About - Java Security Vulnerabilities »

Microsoft Updates for Multiple Vulnerabilities

Source: US-CERT
As part of the Microsoft Security Bulletin Summary for March 2009, Microsoft released updates to address vulnerabilities that affect Microsoft Windows and Windows Server.
A remote, unauthenticated attacker could gain elevated privileges, poison the DNS cache, execute arbitrary code, or cause a vulnerable application to crash.
Solution
Microsoft has provided updates for these vulnerabilities in the Microsoft [...]

Read More About - Microsoft Updates for Multiple Vulnerabilities »

Is Your Computer Part of a Zombie Army?

(NAPS) — Hackers and spammers may be using your computer right now. They invade secretly and hide software to get access to the information on your computer, including your e-mail program. Once on your computer, they can spy on your Internet surfing, steal your personal information and use your computer to send spam to [...]

Read More About - Is Your Computer Part of a Zombie Army? »

Waledac Trojan Horse Spam Campaign Circulating

US-CERT is aware of public reports of malicious code circulating via spam email messages related to bogus terror attacks in the recipient’s local area. These messages use subject lines implying that a fatal bomb attack has occurred near the recipient and contain a link to “breaking news.” Users who click on the link will be [...]

Read More About - Waledac Trojan Horse Spam Campaign Circulating »

Economic Stimulus Email and Website Scams

US-CERT is aware of reports of economic stimulus scams circulating. These scams are being conducted through both email and malicious websites.
Some of the email scam messages request personal information, which can then be used for identity theft. Other email scam messages offer to deposit the stimulus funds directly into users’ bank accounts. If users provide [...]

Read More About - Economic Stimulus Email and Website Scams »

Mozilla Foundation Releases Firefox 3.0.7

Mozilla Foundation has released Firefox 3.0.7 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof the location bar. The Mozilla Foundation Security Advisories also indicate that these vulnerabilities affect Thunderbird and SeaMonkey.
US-CERT encourages users to review the following Mozilla Foundation Security [...]

Read More About - Mozilla Foundation Releases Firefox 3.0.7 »

Next World Cyber-security Contest

Next World Cyber-security Contest Launched by FIRST, CERT Coordination Center
Pittsburgh, PA, February, 25 2009 – The second international competition honoring best practices and advances in safeguarding the security of computer systems and networks was announced today by FIRST (the Forum of Incident Response and Security Teams) and the Carnegie Mellon Software Engineering Institute CERT Coordination [...]

Read More About - Next World Cyber-security Contest »

New Variant of Conficker/Downadup Worm Circulating

US-CERT is aware of public reports concerning a new variant of the Conficker/Downadup worm, named Conficker B++. This variant propagates itself via multiple methods, including exploitation of the previously patched vulnerability addressed in MS08-067, password guessing, and the infection of removable media. Most significantly, Conficker B++ implements a new backdoor with “auto-update” functionality, allowing machines [...]

Read More About - New Variant of Conficker/Downadup Worm Circulating »

Adobe Acrobat and Reader Vulnerability

National Cyber Alert System
Technical Cyber Security Alert TA09-051A
Systems Affected
* Adobe Reader version 9 and earlier
* Adobe Acrobat (Professional, 3D, and Standard) version 9 and earlier
Overview
Adobe has released Security Bulletin APSB09-01, which describes a vulnerability that affects Adobe Reader and Acrobat. This vulnerability could allow a remote attacker [...]

Read More About - Adobe Acrobat and Reader Vulnerability »

RSS BugTraq

  • [ MDVSA-2010:166 ] libgdiplus
    Posted by security on Aug 31 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2010:166 http://www.mandriva.com/security/ _______________________________________________________________________ Package : libgdiplus Date : August 31, 2010 Affected: 2009.0, 2009.1, 2010.0, 2010.1, Enterprise Server 5 […]
  • Tortoise SVN DLL Hijacking Vulnerability
    Posted by nikhil_uitrgpv on Aug 311. Overview Tortoise SVN is vulnerable to Windows DLL Hijacking Vulnerability. Version 1.6.10, Build 19898 (latest available on 30th August 2010 was tested) is vulnerable. 2. Vulnerability Description Tortoise SVN passes insufficiently qualified path for the dll "dwmapi.dll" while opening a file using TortoiseProc […]
  • [security bulletin] HPSBMA02571 SSRT100034 rev.1 - HP Insight Diagnostics Online Edition, Remote Cross Site Scripting (XSS)
    Posted by security-alert on Aug 31SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02492472 Version: 1 HPSBMA02571 SSRT100034 rev.1 - HP Insight Diagnostics Online Edition, Remote Cross Site Scripting (XSS) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2010-08-30 Last Updated: 2010-08-30 Pote […]
  • django in combination with mod wsgi on apache on default debian and ubuntu installations does not place any bounds on the maximum size of a file upload
    Posted by dave b on Aug 31Summary: In the default setup of wsgi, apache and django (at least on ubuntu and debian) by default there are no limits on the size of a file that an attacker can upload. http://cwe.mitre.org/top25/#CWE-770 and see example 2 at http://cwe.mitre.org/data/definitions/770.html Vendor response: " If you have your Apache install con […]
  • [USN-981-1] libwww-perl vulnerability
    Posted by Marc Deslauriers on Aug 31=========================================================== Ubuntu Security Notice USN-981-1 August 31, 2010 libwww-perl vulnerability CVE-2010-2253 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 Ubu […]