Fuzbolero .'s Library tagged → View Popular
Drupal CMS and contributed modules: How to report a security issue | drupal.org
-
If you discover a vulnerability in Drupal core or contributed module, keep it confidential. Mail us at security@drupal.org, do not post in the issue tracker. The security team will investigate your report and create a fix. When the issue is about a contributed module, the team coordinates with a module maintainer. When a fix is ready, an advisory urging users to upgrade is published.
-
Some bugs take time to correct and the process may involve a review of the codebase for similar problems. Coordinating across time zones and work schedules can be time-consuming.
- 3 more annotations...
OpenID at risk due to DNS flaw, warns researcher : News : Security - ZDNet Asia
-
A fundamental issue affects the OpenID authentication system, due to its reliance on the Domain Name System, a Sun identity-technology specialist has warned.
-
Robin Wilton, a corporate architect for federated identity at Sun, described OpenID's reliance on the integrity of the Domain Name System (DNS) as a "multi-factor problem" in light of the discovery of a fundamental flaw in DNS by security researcher Dan Kaminsky.
"You may have seen the recent announcements about DNS cache poisoning, and the potential effect of this on all kinds of Internet-based applications' security," Wilton wrote in a blog post on Friday. "One area in which it can have a particularly significant impact is OpenID."
- 2 more annotations...
Cyber War Could Wreak Worldwide Havoc - www.esecurityplanet.com
-
With cyber warfare already a major component of countries' and terrorist groups' military efforts, it might seem surprising that the U.S. military refrained from unleashing its own cyber warfare arsenal when it had the chance.
But the Pentagon's decision to hold back during past conflicts for fear of the potential collateral damage -- revealed in a Saturday report in The New York Times -- seems justified, security experts say.
-
"Modern networks are so complex that we just don't understand how systems are interconnected or what the consequences can be," Michael Gregg, president of security auditor Superior Solutions, said in an e-mail to InternetNews.com. "In many ways cyber warfare is like biological warfare. It is unknown who these agents will infect or what types of casualties your own side may take."
UK national ID card cloned in 12 minutes | 6 Aug 2009 | ComputerWeekly.com
-
The prospective national ID card was broken and cloned in 12 minutes, the Daily Mail revealed this morning.
The newspaper hired computer expert Adam Laurie to test the security that protects the information embedded in the chip on the card.
Using a Nokia mobile phone and a laptop computer, Laurie was able to copy the data on a card that is being issued to foreign nationals in minutes.
He then created a cloned card, and with help from another technology expert, changed all the data on the new card. This included the physical details of the bearer, name, fingerprints and other information.
SA-CORE-2009-005 - Cross site scripting - Drupal core security patch | drupal.org
-
- Advisory ID: DRUPAL-SA-CORE-2009-005
- Project: Drupal core
- Version: 5.x, 6.x
- Date: 2009-April-29
- Security risk: Moderately critical
-
Certain byte sequences that are valid in the UTF-8 specification are potentially dangerous when interpreted as UTF-7. Internet Explorer 6 and 7 may decode these characters as UTF-7 if they appear before the <meta http-equiv="Content-Type" /> tag that specifies the page content as UTF-8, despite the fact that Drupal also sends a real HTTP header specifying the content as UTF-8. This behaviour enables malicious users to insert and execute Javascript in the context of the website if site visitors are allowed to post content.
Our fancy Internet infrastructure operates on a wire and a prayer | Between the Lines | ZDNet.com
-
The fiber-optic outage—actually sabotage—in the Bay Area on Thursday reveals a dirty little secret: Our infrastructure is ridiculously vulnerable and it only takes a few vandals (or terrorists) to bring communication to its knees.
-
What’s truly scary is that we’re not just talking about the Internet here. The electric grid is vulnerable
- 2 more annotations...
Security Advisories for Firefox 3.0 - mozilla.org/security/known-vulnerabilities/firefox30.html
German researchers score Conficker detection breakthrough | Zero Day | ZDNet.com
(Time to make sure the computers have updated malware and virus protection.)
-
Just days ahead of an April 1st activation date for the Conficker worm squirming through the Windows operating system, security researchers at the Honeynet Project have scored a major breakthrough, finding a way to fingerprint the malware on infected networks.
Now, with the help of Dan Kaminsky and Rich Mogull, off-the-shelf network scanning vendors have the ability remotely (and anonymously) detect Conficker infections.
“You can literally ask a server if it’s infected with Conficker, and it will tell you,” Kaminsky explained. “Usually, we get to scan for a vulnerability but, because Conficker actually changes the way that Windows looks on a network, we now get to scan and get a “this box is infected” message which is pretty rare.”
-
Here’s why you shouldn’t fear the worm’s activation date:
- 1 more annotations...
Hackers steer clear of Google Chrome, say too challenging | Googling Google | ZDNet.com
-
Chrome was pretty much in another league. Their “sandbox” makes it extremely difficult to exploit — not only do you need to find a problem, but you also have to figure out how to get out of their Sandbox (an environment that has no access to anything on the computer).
Browser security recommendation: NoScript :: Firefox Add-ons - addons.mozilla.org
"The best security you can get in a web browser! Allow active content to run only from sites you trust, and protect yourself against XSS and Clickjacking attacks. "
General recommendation: use Firefox' splendid NoScript extension.
Install: https://addons.mozilla.org/en-US/firefox/addon/722
Documentation: http://noscript.net
"What is Clickjacking?"
http://noscript.net/faq#qa7_1
SA-2007-023 - Public service announcement: PHP exploit using Drupal circulating | drupal.org
(Drupal hosting environment should have "register_globals" disabled.)
-
An exploit for this is widely circulating. The attack will not work when "register_globals" is set to off.
Drupal 6.10 and 5.16 released | drupal.org
-
Drupal 6.10 and 5.16, maintenance releases fixing problems reported using the bug tracking system, as well as a critical security vulnerability, are now available for download.
-
We recommend you do the full upgrade (which is also detailed in the security announcement) as the patches do not contain the additional bugfixes that went into the releases. Applying the patches will leave your site in an unversioned state and confuse the update status module, which will keep reminding you to upgrade to 6.10 or 5.16. Please read the announcement for details on the patch.
- 2 more annotations...
Kaspersky: no personal information lifted during web hack • The Register
-
Anti-virus provider Kaspersky Lab on Monday moved to reassure customers that none of their personal information was accessed during a 10-day security lapse that exposed a database used to run a support site for its US users.
The company also apologized for the blunder and said it was bringing in database security expert David Litchfield to conduct an independent audit of Kaspersky's website and to publicly share his findings.
Gmail Labs - Gmail new features testing ground - mail.google.com
Beware, this may wreck your mailbox! Interesting list to monitor, though.
"Gmail Labs: our testing ground for experimental features
Gmail engineers come up with new ideas all the time. Gmail Labs is our place to try them out and get your feedback. None of these features are really ready for prime time yet, so they may change, break or disappear at any time. Learn more about Gmail Labs
If (when) a Labs feature breaks, and you're having trouble getting into your account, there's an escape hatch -- just go to http://mail.google.com/mail/?labs=0 and Labs will be temporarily disabled."
FTP Bounce - CERT Advisory CA-1997-27
-
In some implementations of FTP daemons, the PORT command can be
misused to open a connection to a port of the attacker's choosing on a
machine that the attacker could not have accessed directly. There have
been ongoing discussions about this problem (called "FTP bounce") for
several years, and some vendors have developed solutions for this
problem.The CERT/CC staff urges you to install a comprehensive patch if one
is available. Until then, we recommend the wu-ftpd package identified
in Section III.B. as a workaround.
"Forgot your password" links the easy way in for hackers : Christopher Null : Yahoo! Tech
-
Never mind creating a password with at least eight characters, two of which are numbers, one of which is a capital letter, and one of which is a symbol like (*&^%$). The easiest way for a hacker to weasel into your account is likely the "Forgot your password?" link.
-
Your mother's maiden name may really be Jones, but that you can't pretend it wasn't Mxlpxlxl!7631.
Selected Tags
Related Tags
Sponsored Links
Top Contributors
Groups interested in vulnerab...
Highlighter, Sticky notes, Tagging, Groups and Network: integrated suite dramatically boosting research productivity. Learn more »
Join Diigo
