|
|
Who's Online
There are 245 unregistered users and 0 registered users on-line.
You can log-in or register for a user account here.
Main Menu
Top Stories for Today
[699] 8 weird but cool Android apps
[451] Sun’s open source chief leaves after Oracle merger [345] No Trace: How to Completely Erase Your Hard Drives, SSDs and USB Drives [343] Douglas Duchak charged over bid to damage US security database [326] Schneier: Fight for privacy or kiss it good-bye [300] The top 10 geek anthems of all time [296] Four over-rated security technologies [267] No-Fly List Includes the Dead [243] Zeus Botnet Dealt a Blow as ISP Troyak Knocked out [225] EFF knocks Apple's 'secret' restrictive developer agreement [219] New Gestures coming to iPhone/iPad: Triple tap and long press [218] How deep can Intel get inside the smart grid? [205] Google Street View to cover 96 per cent of UK roads from tomorrow [201] Soft skills lacking in candidate-rich market [192] ARM Expects 50 Tablet Devices to Hit the Market This Year [191] F-Secure: Hackers love to exploit PDF bugs [180] Android native development kit updated [174] LED lights may be the future of broadband [171] Turkish police detain 23 PKK hackers in 13 provinces [169] 'Jihad Jane' Exposes Web's Dark Side [165] Reader exploit prompts Adobe update alert [165] Twitter Becomes More Proactive About Phishing [151] 12% of employees knowingly violate company IT policies [149] New Zealand's internet filter goes live [147] Our Apps Are Vulnerable -- And Constantly Attacked
Top 20 of the Last 2 Weeks
[1566] 6 Free Android Apps That Will Make You Drop Your iPhone
[1425] North Korea develops its own OS [1246] Porn Detection Stick seeks out salacious images [1243] Teen gets 15 years for Facebook blackmail [1090] Legal team hack Xbox memory for defence evidence [1078] How hackers took down Baidu [1076] Should CIOs look at virtual desktops? [1063] Steve Jobs says Apple must 'think big' with $40 billion in cash [1056] 7 of the Best Free Linux Configuration Management Tools [1033] Analyst thinks Apple may update MacBook Pro laptop [891] Mastermind of World's Worst Computer Virus Still at Large [825] Korean couple addicted to virtual life let real-life baby starve to death [807] Chinese man held by police over sex video clips [718] Run a Background Check on Yourself with Free Online Tools [699] 8 weird but cool Android apps [696] BITSTALKER: Accurately and effectively monitoring BitTorrent traffic [693] 'Severe' OpenSSL vuln busts public key crypto [671] Saudi Arabia wants to monitor all BlackBerry communications for 'security' [655] Confessions of a Windows 7 pirate [646] HSBC ramps up online banking security
Past Articles
|
HITB E-Zine ArchiveArchive for 2000
Issue #1 Archive for 2001
Issue #13 Archive for 2002
Issue #25 Archive for 2003 Archive for 2004 Archive for 2005 |
Login
HITB Ezine
Issue #38
HITBSecConf2010 - Dubai
Register now for the 4th annual deep-knowledge security conference in Dubai!
Keynote 1: John Viega (CTO, SaaS, McAfee Inc.) Keynote 2: Matt Watchinski (Senior Director of Vulnerability Research, Sourcefire Inc.) Conference Speakers (alphabetical order):
1.) Arnauld Mascret (Sogeti / Cap Gemini)
2.) Christophe Devaux (Sogeti / Cap Gemini)
3.) Daniel Mende (ERNW GmbH) 4.) Dino Covotsos (Managing Director, Telspace Systems)
5.) Fredric Raynal (Head of Research, Sogeti/Cap Gemini)
6.) Gynvael Coldwind (Researcher, Hispasec)
7.) Laurent Oudot (Founder, TEHTRI-Security)
8.) Marc Schoenefeld (Independent Network Security Specialist) 9.) Oliver Roeschke (ERNW GmbH) 10.) Saumil Shah (Founder, Net-Square)
11.) Shawn Merdinger (Security Researcher) 12.) The Grugq (Anti Forensics Specialist)
Last 15 Postings to HITB Forum
Packet Storm Security Latest
· ane-xsrf.txt
ANE CMS version 1 suffers from a cross site request forgery vulnerability. · ane-xss.txt ANE CMS version 1 suffers from a cross site scripting vulnerability. · USN-909-1.txt Ubuntu Security Notice 909-1 - William Grant discovered that dpkg-source did not safely apply diffs when unpacking source packages. If a user or an automated system were tricked into unpacking a specially crafted source package, a remote attacker could modify files outside the target unpack directory, leading to a denial of service or potentially gaining access to the system. · abton-sql.txt Abton CMS suffers from a remote SQL injection vulnerability. · dsa-2011-1.txt Debian Linux Security Advisory 2011-1 - William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content. · MDVSA-2010-060.txt Mandriva Linux Security Advisory 2010-060 - The htcpHandleTstRequest function in htcp.c in Squid 2.x and 3.0 through 3.0.STABLE23 allows remote attackers to cause a denial of service (crash) via crafted packets to the HTCP port, which triggers a NULL pointer dereference. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue. · cookiemonster_v1.6.zip Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible. · super-vulns.tgz SUPERAntiSpyware and Super Ad Blocker have almost identical device drivers in order to set up hooks and perform other duties from kernel space. These device drivers suffer from lack of validation of parameters passed from user mode. Additionally, some of the functions accessible from user mode are inherently insecure and lead to easy privilege escalation. All vulnerabilities are applicable to both applications. Proof of concept code included with full advisory.
Topics
· All topics
· AMD News (Feb 23, 2010) · Apple News (Mar 11, 2010) · Articles (Mar 03, 2009) · Ask Us (Feb 01, 2003) · Audio/Video (Mar 11, 2010) · Encryption (Mar 10, 2010) · Games (Mar 09, 2010) · Hardware (Mar 04, 2010) · HITB News (Feb 09, 2010) · Industry News (Mar 11, 2010) · Intel News (Mar 11, 2010) · Law and Order (Mar 11, 2010) · Linux (Feb 25, 2010) · Microsoft (Mar 10, 2010) · Networking (Mar 10, 2010) · PDAs (Feb 09, 2007) · Privacy (Mar 11, 2010) · Red Hat (Mar 09, 2010) · Science (Mar 10, 2010) · Security (Mar 11, 2010) · Software & Programming (Mar 11, 2010) · Spam (Jan 26, 2010) · Technology (Mar 11, 2010) · Transmeta (Jul 07, 2007) · Viruses & Malware (Mar 09, 2010) · Wireless (Mar 03, 2010)
HITB Affiliates
Warez Raid
Btscene Raid Network Rapidshare.net FullDownloadShare.com PlaystationHome.com TriniWarez Rapidsharedownload.net SCForum.info Pogoed Full Downloads Nitro Roms Gu1337 Twistys Download Ideal Torrent Egyptfans.net DirtyWarez.com RaidPIC Torrents Download RapidShareLink FreshDL Warez Linkers WarezFactor FullDDL.net Digital Vortex TorrentHub RealWarez Fullversion Search DreamDDL HackersNews.org Black-Zero MyPDACafe.com Guvenli.org Dark-Hack.net Dark Tavern HardlineNews.com ITDefence.ru Xatrix Computer Security shellcity.net EyeonSecurity HackerStickers.com Astalavista Go Hacking XSSed.com madirish.net Secumania.org Megapanzer If you own a PR4+ (Page Rank) network security or computer related website with 5,000 unique visits and would like to affiliate with HITB, email us. |
||