PHP patches - see http://www.php.net/ChangeLog-5.php - fixes CVE2013-2110,...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, June 7th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article100% Compliant (for 65% of the systems), (Fri, Jun 7th)
At a community college where I'm helping out whenever they panic on security issues, I recently was confronted with the odd reality of a lingering malware infection on their network, even though they...
View ArticleExim/Dovecot exploit making the rounds, (Fri, Jun 7th)
One of our readers wrote in to let us know that he had received an attempted Exim/Dovecot exploit attempt against his email server. Â The exploit partially looked like this: From:...
View ArticleISC StormCast for Monday, June 10th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWhen Google isn't Google, (Mon, Jun 10th)
Like many other exploit scripts, the recent "Plesk" exploit used a fake user agent of "Googlebot". Attackers assume that most web applications are happy to be indexed by Google and possibly ably no or...
View ArticleISC StormCast for Tuesday, June 11th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMicrosoft June 2013 Black Tuesday Overview, (Tue, Jun 11th)
Overview of the June 2013 Microsoft patches and their status. # Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*) clients servers MS13-047 The usual monthly MSIE...
View ArticleOther Microsoft Black Tuesday News, (Tue, Jun 11th)
Microsoft Security Advisory 2854544 was released today. It adds functionality to manage and use Cetificate Trutst Lists. Microsoft released a few days ago a fixit to allow one to control the...
View Articlevmware security advisory VMSA-2013-0008, (Tue, Jun 11th)
VMware joined the Black Tuesday frenzy with a release of a security bulletin VMSA-2013-008. It covers CVE-2013-3520, a vulnerability in handling file uploads in the vCenter Chargeback Manager that...
View ArticleAdobe June 2013 Black Tuesday Overview, (Tue, Jun 11th)
Adobe released their June 2013 Black Tueday bulletins: # Affected CVE Adobe rating APSB13-16 Flash Player & AIR CVE-2013-3343 Critical -- Swa Frantzen -- Section 66 (c) SANS Internet Storm Center....
View ArticleStore passwords the right way in your application, (Tue, Jun 11th)
I suspect most of our readers know this, but it can't hurt to repeat this every so often as there is a lot of confusion on the issue. One thing that gets to me is seeing reports of website compromises...
View ArticleISC StormCast for Wednesday, June 12th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleStupid Little IPv6 Tricks, (Wed, Jun 12th)
With the IPv6 Summit on Friday, various IPv6 related topics are of course on my mind. So I figured to put together a quick laundry list of "stupid little IPv6 tricks/topics". Let me know what issues...
View ArticleISC StormCast for Thursday, June 13th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWhen Hotel Alarms Sound, (Fri, Jun 14th)
I often wondered what an 'average' reaction would be to a fire alarm sounding in a hotel. My question was answered a couple of weeks ago in misty San Franscico, CA. It was checking into SANSFire 2013...
View ArticleISC StormCast for Friday, June 14th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWebsense Appliance at 100% CPU, (Wed, Jul 10th)
Some readers have reported in (Thanks!) that their inline Websense appliances are spiking to 100% after an update. The Websense team is aware and quickly working on a fix we are told. If you are...
View Article.NL Registrar Compromisse, (Wed, Jul 10th)
Based on a note on the website of SIDN [1], as SQL injection vulnerability was used to compromisse the site and place malicious files in the document root. SIDN is the registrar for the .NL country...
View ArticleISC StormCast for Thursday, July 11th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article