BuyLow.com Computers And Internet - Internet Security, Computers, Mobile Devices, Networks


BuyLow.com | Resources | Contact Us


 

Tracking GhostNet: Investigating a Cyber Espionage Network

This report documents the GhostNet – a suspected cyber espionage network of over 1,295 infected computers in 103 countries, 30% of which are high-value targets, including ministries of foreign affairs, embassies, international organizations, news media, and NGOs.
The capabilities of GhostNet are far-reaching. The report reveals that Tibetan computer systems were compromised giving attackers access to [...]

Read More About - Tracking GhostNet: Investigating a Cyber Espionage Network »

Conficker Worm Targets Microsoft Windows Systems

US-CERT is aware of public reports indicating a widespread infection of the Conficker worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across the network if the host is not patched with MS08-067.
The presence of a Conficker infection may be detected if a user is unable to [...]

Read More About - Conficker Worm Targets Microsoft Windows Systems »

Java Security Vulnerabilities

Sun Releases Updates for Java SE
added March 26, 2009 at 08:54 am
Sun has released updates for Java SE to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or operate with escalated privileges.
US-CERT encourages users to review the Sun Java SE 6 Update Release Notes and upgrade [...]

Read More About - Java Security Vulnerabilities »

Microsoft Updates for Multiple Vulnerabilities

Source: US-CERT
As part of the Microsoft Security Bulletin Summary for March 2009, Microsoft released updates to address vulnerabilities that affect Microsoft Windows and Windows Server.
A remote, unauthenticated attacker could gain elevated privileges, poison the DNS cache, execute arbitrary code, or cause a vulnerable application to crash.
Solution
Microsoft has provided updates for these vulnerabilities in the Microsoft [...]

Read More About - Microsoft Updates for Multiple Vulnerabilities »

RSS BugTraq

  • CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability
    Posted by CORE Security Technologies Advisories on Mar 17 eFront-learning PHP file inclusion vulnerability 1. *Advisory Information* Title: eFront-learning PHP file inclusion vulnerability Advisory Id: CORE-2010-0311 Advisory URL: http://www.coresecurity.com/content/efront-php-file-inclusion Date published: 2010-03-16 Date of last update: 2010-03-16 Vendors […]
  • Sahana 0.6.2.2 Authentication Bypass
    Posted by Christopher on Mar 17Ability to completely disable authentication via stream.php and commented out module authentication code within it. http://victim//index.php?mod=admin&act=acl_enable_acl Authenticates correctly. http://victim//stream.php?mod=admin&act=acl_enable_acl Does not. […]
  • Secunia Research: Quicksilver Forums "mysqldump" Password Disclosure
    Posted by Secunia Research on Mar 17====================================================================== Secunia Research 17/03/2010 - Quicksilver Forums "mysqldump" Password Disclosure - ====================================================================== Table of Contents Affected Software....................................................1 […]
  • Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability
    Posted by Secunia Research on Mar 17====================================================================== Secunia Research 17/03/2010 - Quicksilver Forums Cross-Site Request Forgery Vulnerability - ====================================================================== Table of Contents Affected Software....................................................1 S […]
  • Secunia Research: Quicksilver Forums Backup Information Disclosure
    Posted by Secunia Research on Mar 17====================================================================== Secunia Research 17/03/2010 - Quicksilver Forums Backup Information Disclosure - ====================================================================== Table of Contents Affected Software....................................................1 Severity.... […]