<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Infosec Events &#187; Vendor News</title>
	<atom:link href="http://infosecevents.net/category/vendor-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Mon, 26 Jul 2010 04:33:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Week 29 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/07/25/week-29-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/07/25/week-29-in-review-2010/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 04:33:59 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[DEFCON]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1140</guid>
		<description><![CDATA[Events Related:

(Def) #ConSurvival &#8211; h-i-r.net
Some practical tips on how to get through DefCon
BlackHat and DefCon Tips: 2010/N00b Edition &#8211; it.toolbox.com
More things to remember on your next Vegas security event
BlackHat Track Schedule &#8211; uktek.com
A full schedule of the when and where certain talks are going to be held.

Tools:

Ubitack 0.2 &#8211; code.google.com/p/ubitack/
This tool automates some of the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.h-i-r.net/2010/07/def-consurvival.html">(Def) #ConSurvival</a> &#8211; h-i-r.net<br />
Some practical tips on how to get through DefCon</li>
<li><a href="http://it.toolbox.com/blogs/securitymonkey/blackhat-and-defcon-tips-2010n00b-edition-40150">BlackHat and DefCon Tips: 2010/N00b Edition</a> &#8211; it.toolbox.com<br />
More things to remember on your next Vegas security event</li>
<li><a href="http://uktek.com/bh.htm">BlackHat Track Schedule</a> &#8211; uktek.com<br />
A full schedule of the when and where certain talks are going to be held.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://code.google.com/p/ubitack/">Ubitack 0.2</a> &#8211; code.google.com/p/ubitack/<br />
This tool automates some of the tasks you might need on a (wireless) penetration test or while you are on the go.</li>
<li><a href="http://voipsecurityblog.typepad.com/marks_voip_security_blog/2010/07/sipvicious-026-available.html">SIPVicious 0.2.6 Available</a> &#8211; voipsecurityblog.typepad.com<br />
SIPVicious was written in python and can be used on Linux, Windows, FreeBSD 6.2 and Mac OS X.</li>
<li>Open source GSM cracker released<br />
I have named this beast Kraken, after a Norse mythological creature capable of eating many things for breakfast. Kraken feeds of an exclusive diet of A5/1 encrypted data.</p>
<ul>
<li><a href="http://www.cio.com/article/600213/New_Kraken_GSM_Cracking_Software_is_Released">New &#8216;Kraken&#8217; GSM-Cracking Software is Released</a> &#8211; cio.com</li>
<li><a href="http://lists.lists.reflextor.com/pipermail/a51/2010-July/000683.html">The call of Kraken</a> &#8211; reflextor.com</li>
<li><a href="http://marcoramilli.blogspot.com/2010/07/gsm-cracking-tool-yes-its-open-source.html">GSM Cracking Tool. Yes it&#8217;s open source</a> &#8211; marcoramilli.blogspot.com</li>
</ul>
</li>
<li><a href="http://www.darknet.org.uk/2010/07/sagan-real-time-system-event-log-syslog-monitoring-system/">Sagan – Real-time System &amp; Event Log (syslog) Monitoring System</a> &#8211; darknet.org.uk<br />
Sagan can alert you when events are occurring in your syslogs that need your attention right away, in real time!</li>
<li><a href="http://theplugbot.com/">PlugBot</a> &#8211; theplugbot.com<br />
PlugBot is a research project led by Jeremiah Talamantes, a penetration tester and security researcher for RedTeam Security.</li>
<li><a href="http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Main_Page">WATOBO &#8211; THE Web Application Toolbox</a> &#8211; sourceforge.net/apps/mediawiki/watobo/<br />
We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities.</li>
<li><a href="https://code.google.com/p/webenum/">WebEnum 0.1</a> &#8211; code.google.com/p/webenum/<br />
WebEnum is a tool to enumerate http responses to dynamically generated queries.</li>
<li><a href="http://code.google.com/p/dic/">dic</a> &#8211; code.google.com/p/dic/<br />
&#8220;Download Indexed Cache&#8221; is a Proof of Concept (PoC) which implements the Google SOAP Search API to retrieve content indexed within the Google Cache to support the &#8220;Search Engine Reconnaissance&#8221; section of the OWASP Testing Guide v3</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.andlabs.org/2010/07/shell-of-future-reverse-web-shell.html">Shell of the Future – Reverse Web Shell Handler for XSS Exploitation</a> &#8211; andlabs.org<br />
In pentests XSS is usually considered as a dead-end vulnerability &#8211; you discover it, take a screenshot and move on to something else.</li>
<li><a href="http://threatpost.com/en_us/blogs/identifying-suspicious-urls-071910">Identifying Suspicious URLs</a> &#8211; threatpost.com<br />
In the Google TechTalk, Justin Ma, a PhD candidate at UC San Diego, discusses a novel method for determining which URLs are malicious by applying large-scale online learning techniques.</li>
<li>Stuxnet and .lnk related studies
<ul>
<li><a href="http://www.sophos.com/blogs/chetw/g/2010/07/20/shortcut-mitigation-certificate-revocation/">CPLINK Shortcut mitigation and certificate revocation</a> &#8211; sophos.com</li>
</ul>
<ul>
<li><a href="http://www.attackvector.org/lnk-exploit-demonstration/">Windows ‘LNK’ Exploit Demonstration</a> &#8211; attackvector.org</li>
<li><a href="http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/">Mitigating .LNK Exploitation With SRP</a> &#8211; didierstevens.com</li>
<li>Details for the LNK issue along with <a href="http://bit.ly/azpDvF">a live sample</a> &#8211; @hdmoore</li>
<li><a href="http://blog.mandiant.com/archives/1236">Stuxnet Memory Analysis and IOC creation</a> &#8211; mandiant.com</li>
<li><a href="http://www.attackvector.org/file-server-lnkstuxnet-protection/">File Server LNK/stuxnet Protection</a> &#8211; attackvector.org</li>
<li><a href="http://www.symantec.com/connect/de/blogs/distilling-w32stuxnet-components">Distilling the W32.Stuxnet Components</a> &#8211; symantec.com</li>
</ul>
</li>
<li><a href="http://voipsa.org/blog/2010/07/22/weaponizing-the-nokia-n900-part-1/">Weaponizing the Nokia N900 – Part 1</a> &#8211; voipsa.org<br />
Broadly speaking, the objective of this series of blog posts is to introduce folks to the tools available and the potential for this phone as a security testing platform.</li>
<li><a href="http://blog.happypacket.net/2010/07/fun-with-metasploit-payload-generation.html">Fun with Metasploit payload generation</a> &#8211; happypacket.net<br />
My goal was to figure out how to add the msfencode functionality into the generate_simple function that is used by both XMLRPC and the console so that you can encode payloads and all that fun stuff from within Metasploit.</li>
<li>iSEC is releasing this <a href="http://bit.ly/a58Ryk">pre-advisory for Kerberos flaws</a> to be discussed at BH. Must read for AD Admins. &#8211; @alexstamos</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>More news about the Stuxnet Flaw<br />
The said malware exploits a newly-discovered vulnerability in shortcut files, which allows random code to be executed on the user’s system.</p>
<ul>
<li><a href="http://it.slashdot.org/story/10/07/18/1950210/Microsoft-Has-No-Plans-To-Patch-New-Flaw">Microsoft Has No Plans To Patch New Flaw</a> &#8211; slashdot.org</li>
<li><a href="http://eddywillems.blogspot.com/2010/07/microsoft-lnk-usb-worm-rootkit-issue.html">The Microsoft LNK / USB worm / rootkit &#8216;issue&#8217; will kill WIN XP SP2 and WIN2000 earlier&#8230;</a> &#8211; eddywillems.blogspot.com</li>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/07/19/shortcut-zeroday-attack-code-public/">Shortcut zero-day attack code goes public</a> &#8211; sophos.com</li>
<li><a href="http://threatpost.com/en_us/blogs/stuxnet-saga-evolves-new-digitally-signed-binaries-072010">Stuxnet Saga Evolves With New Digitally Signed Binaries</a> &#8211; threatpost.com</li>
<li><a href="http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/">Tool Blunts Threat from Windows Shortcut Flaw</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://siblog.mcafee.com/critical_infrastructure/stuxnet-a-view-from-an-energy-perspective/">Stuxnet-A View From an Energy Perspective</a> &#8211; mcafee.com</li>
</ul>
</li>
<li><a href="http://xs-sniper.com/blog/2010/07/19/twitter-xss-bug/">Twitter XSS Bug</a> &#8211; xs-sniper.com<br />
99% of XSS bugs are fairly straightforward and this bug was no exception.</li>
<li><a href="http://www.theregister.co.uk/2010/07/20/browser_info_disclosure_weaknesses/">IE and Safari lets attackers steal user names and addresses</a> &#8211; theregister.co.uk<br />
Jeremiah Grossman, CTO of White Hat Security, plans to detail critical weaknesses that are enabled by default in the browsers, which are the four biggest by market share.</li>
<li><a href="http://threatpost.com/en_us/blogs/old-wireless-security-flaws-still-haunting-networks-072010">Old Wireless Security Flaws Still Haunting Networks</a> &#8211; threatpost.com<br />
The attack is specifically designed to work against the Cisco Aironet 1200 Series access points and is a twist on existing attacks that have shown WEP to be an eminently defeatable protocol.</li>
<li><a href="http://vigilance.fr/vulnerability/SAP-GUI-command-execution-via-wadmxhtml-9771">SAP GUI: command execution via wadmxhtml</a> &#8211; vigilance.fr<br />
An attacker can use the wadmxhtml.dll ActiveX of SAP GUI, in order to execute code on computers of victims displaying a malicious HTML page.</li>
<li><a href="http://www.networkworld.com/newsletters/wireless/2010/072610wireless1.html">WPA2 vulnerability found</a> &#8211; networkworld.com<br />
Hole 196 lends itself to man-in-the-middle-style exploits, whereby an internal, authorized Wi-Fi user can decrypt, over the air, the private data of others, inject malicious traffic into the network and compromise other authorized devices using open source software, according to AirTight.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Adobe to use sandboxing to mitigate onslaught of Reader-focused attacks<br />
The next major version of Adobe&#8217;s PDF Reader will feature new sandboxing technology aimed at curbing a surge in malicious hacker attacks against the widely deployed software.</p>
<ul>
<li><a href="http://www.zdnet.com/blog/security/adobe-adding-sandbox-to-pdf-reader-to-ward-off-hacker-attacks/6886">Adobe adding &#8217;sandbox&#8217; to PDF Reader to ward off hacker attacks</a> &#8211; zdnet.com</li>
<li><a href="http://krebsonsecurity.com/2010/07/adobe-sandbox-will-stave-off-reader-attacks/">Adobe: ‘Sandbox’ Will Stave Off Reader Attacks</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://download.cnet.com/8301-2007_4-20010857-12.html">New plug-in tester mimics Mozilla&#8217;s</a> &#8211; cnet.com<br />
Qualys&#8217; BrowserCheck helpfully targets out-of-date plug-ins, and provides links to download updates.</li>
<li><a href="http://news.cnet.com/8301-27080_3-20010945-245.html">VeriSign adds malware scanning to SSL services</a> &#8211; cnet.com<br />
VeriSign is adding malware scanning to its authentication services for Web site operators, the company announced on Monday.</li>
<li>Siemens SCADA comes with hard-coded password, doesn&#8217;t recommend changing it.<br />
A sophisticated new piece of malware that targets command-and-control software installed in critical infrastructures uses a known default password that the software maker hard-coded into its system.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2010/07/siemens-scada/">SCADA System’s Hard-Coded Password Circulated Online for Years</a> &#8211; wired.com</li>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/07/20/malware-scada-password-siemens/">Yes, there&#8217;s malware. But don&#8217;t change your SCADA password, advises Siemens</a> &#8211; sophos.com</li>
</ul>
</li>
<li><a href="http://lifehacker.com/5591972/dell-kace-secure-browser-sandboxes-your-browsing">Dell KACE Secure Browser Sandboxes Your Browsing</a> &#8211; lifehacker.com<br />
Secure Browser is designed so even if you find yourself on a site that could harm your computer, the harmful effects are contained within the browser sandbox.</li>
<li><a href="http://krebsonsecurity.com/2010/07/skimmers-siphoning-card-data-at-the-pump/">Skimmers Siphoning Card Data at the Pump</a> &#8211; krebsonsecurity.com<br />
Forced to re-issue an unusually high number of bank cards due to fraudulent charges on the accounts, a regional bank serving Colorado and surrounding states recently began searching for commonalities among the victimized accounts.</li>
<li><a href="http://threatpost.com/en_us/blogs/google-ups-bug-bounty-ante-311370-072010">Google Ups the Bug Bounty Ante to $3133.7</a> &#8211; threatpost.com<br />
The maximum reward for a single bug has been increased to $3,133.7. We will most likely use this amount for SecSeverity-Critical bugs in Chromium.</li>
<li><a href="http://www.newscientist.com/blogs/shortsharpscience/2010/07/pc-giant-warns-of-hardware-tro.html">PC giant warns of hardware trojan</a> &#8211; newscientist.com<br />
Further information posted on Dell&#8217;s community forum reveals that the trojan in the affected motherboards is stored in onboard flash memory rather than firmware ROMs.</li>
<li><a href="http://www.sophos.com/blogs/chetw/g/2010/07/20/certified-uncertainty/">Certified uncertainty</a> &#8211; sophos.com<br />
Second, this particular component of the threat was signed on January 25th, 2010. This implies the perpetrators of this attack have been planning their strategy for quite some time.</li>
<li><a href="http://threatpost.com/en_us/blogs/how-mass-sql-injection-attacks-have-become-epidemic-072110">How Mass SQL Injection Attacks Became an Epidemic</a> &#8211; threatpost.com<br />
Mass compromises of legitimate sites really began in earnest in 2007, and the volume and severity of the attacks has increased significantly since then.</li>
<li><a href="http://blog.eset.com/2010/07/22/why-steal-digital-certificates">Why Steal Digital Certificates?</a> &#8211; eset.com<br />
In theory the digital signature also tells you who signed the file, and who issued the digital certificate so you can decide if you trust the person or company who signed the file and if you trust the organization who issued the certificate.</li>
<li><a href="http://gizmodo.com/5594990/forget-walmart-hackers-conference-badges-show-the-future-of-rfid-tracking">Forget Walmart. Hackers Conference Badges Show The Future of RFID Tracking</a> &#8211; gizmodo.com<br />
This year, HOPE&#8217;s Attendee Meta-Data or AMD badge reached new heights, and suggested more about what you could do with RFID attached to people—both good and bad.</li>
<li><a href="http://www.youtube.com/watch?v=WijVqtORa0Y&amp;feature=player_embedded">Backtrack vs Windows</a> &#8211; youtube.com<br />
Spoof of evo vs iphone with an influence in security .. DEFCON 18</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1140&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/07/25/week-29-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 28 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/07/19/week-28-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/07/19/week-28-in-review-2010/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 09:56:17 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[HOPE]]></category>
		<category><![CDATA[RECON]]></category>
		<category><![CDATA[SOUPS]]></category>
		<category><![CDATA[The Next HOPE]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1131</guid>
		<description><![CDATA[Events Related:

RECON 2010: The best conference ever in the worst hotel ever &#8211; ncircle.com
It was held in Montreal from July 9th to the 11th at a supposedly posh hotel where the air-conditioning wasn’t working at all building-wide during a heat wave.
SOUPS Keynote &#38; Slides &#8211; emergentchaos.com
In “Engineers Are People, Too” Adam Shostack will address an [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.ncircle.com/blogs/vert/archives/2010/07/recon_2010_the_best_conference.html">RECON 2010: The best conference ever in the worst hotel ever</a> &#8211; ncircle.com<br />
It was held in Montreal from July 9th to the 11th at a supposedly posh hotel where the air-conditioning wasn’t working at all building-wide during a heat wave.</li>
<li><a href="http://emergentchaos.com/archives/2010/07/soups-keynote-slides.html">SOUPS Keynote &amp; Slides</a> &#8211; emergentchaos.com<br />
In “Engineers Are People, Too” Adam Shostack will address an often invisible link in the chain between research on usable security and privacy and delivering that usability: the engineer.</li>
<li><a href="http://laughingsquid.com/photos-the-next-hope-hackers-on-planet-earth/">Photos: The Next HOPE (Hackers On Planet Earth)</a> &#8211; laughingsquid.com<br />
Pictures from the the Hotel Pennsylvania event.</li>
<li>Assange is a no-show<br />
A Wikileaks editor, deciding not to risk a confrontation with federal agents, skipped a high-profile speaking engagement at a hacker conference here on Saturday.</p>
<ul>
<li><a href="http://www.boingboing.net/2010/07/17/hope-wikileaks-julia.html">HOPE: scheduled keynote by Julian Assange of Wikileaks</a> &#8211; boingboing.net</li>
<li><a href="http://news.cnet.com/8301-1009_3-20010866-83.html">Wikileaks editor skips NYC hacker event</a> &#8211; cnet.com</li>
</ul>
</li>
</ul>
<p><strong>Resources:</strong></p>
<p><strong> </strong></p>
<ul>
<li><a href="http://dirk-loss.de/python-tools.htm">Python tools for penetration testers</a> &#8211; dirk-loss.de<br />
If you are involved in vulnerability research, reverse engineering or penetration testing, I suggest to try out the Python programming language.</li>
<li><a href="http://www.icsalabs.com/news-article/see-20-minute-video-presentation-how-choose-ips">See 20 Minute Video Presentation on How to Choose an IPS</a> &#8211; icsalabs.com<br />
Considering which network IPS is the best fit for your enterprise or SMB?</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://invalid-packet.blogspot.com/2009/12/belch-v10-burp-external-channel.html">Belch v1.0 &#8211; Burp external channel manipulator</a> &#8211; invalid-packet.blogspot.com<br />
Belch is a plug-in for burp suite designed to aid protocol analysis and manipulation, it is fairly simple.</li>
<li><a href="http://pke.nu/scan/en/">ScanPW</a> &#8211; pke.nu/scan<br />
ScanPW it&#8217;s a free web application that let&#8217;s you, in a fast and secure way, analize a webpage source code.</li>
<li><a href="http://blog.metasploit.com/2010/07/metasploit-framework-341-released.html">Metasploit Framework 3.4.1 Released!</a> &#8211; metasploit.com<br />
This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month.</li>
<li><a href="http://blog.roychowdhury.org/2010/06/25/facetime-on-iphone-4-vanilla-unencrypted-stun-and-sip/">Facetime on Iphone 4: Vanilla unencrypted STUN and SIP</a> &#8211; roychowdhury.org<br />
No hacking needed – just an on the wire black box inspection – its just plain SIP and STUN for firewall discovery.</li>
<li><a href="http://www.kismetwireless.net/">Kismet</a> &#8211; kismetwireless.net<br />
Kismet identifies networks by passively collecting packets and detecting standard named networks, detecting (and given time, decloaking) hidden networks, and infering the presence of nonbeaconing networks via data traffic.</li>
<li><a href="http://www.h-online.com/security/news/item/Crypto-tool-predicts-password-cracking-time-1038121.html">Crypto tool predicts password cracking time</a> &#8211; h-online.com<br />
Instead of indicating password quality via coloured bars, the Windows crypto tool Thor&#8217;s Godly Privacy (TGP) informs users about the estimated time required for a successful brute-force attack on the chosen password.</li>
<li><a href="http://code.google.com/p/pescrambler/">PEScrambler</a> &#8211; code.google.com/p/pescrambler/<br />
PEScrambler is a tool to obfuscate win32 binaries automatically. It can relocate portions of code and protect them with anti-disassembly code.</li>
<li>SIFT Workstation out now<br />
A new version of SIFT Workstation is out, here the new features: VMware Appliance, ready to tackle forensics, and cross compatibility between Linux and Windows among others.</p>
<ul>
<li><a href="http://marcoramilli.blogspot.com/2010/07/sans-investigative-forensic-toolkit.html">SANS Investigative Forensic Toolkit</a> &#8211; marcoramilli.blogspot.com</li>
<li><a href="https://computer-forensics2.sans.org/community/siftkit/">SANS Investigative Forensic Toolkit (SIFT) Workstation: Version 2.0*</a> &#8211; sans.org</li>
</ul>
</li>
<li><a href="http://code.google.com/p/skipfish/downloads/detail?name=skipfish-1.51b.tgz">skipfish v 1.51</a> &#8211; code.google.com/p/skipfish<br />
A fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://nmap.org/download.html">NMAP 5.35DC1 released</a> &#8211; nmap.org<br />
Nmap and Zenmap (the graphical front end) are available in several versions and formats.</li>
<li><a href="http://www.binary-auditing.com/">Binary Auditor</a> &#8211; binary-auditing.com<br />
Educate yourself in the field of Binary Auditing and Reverse Code Engineering for FREE!</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li>Metasploit Basics Series
<ul>
<li><a href="http://www.digitalbond.com/index.php/2010/07/12/metasploit-basics-part-3-pivoting-and-interfaces/">Metasploit Basics – Part 3: Pivoting and Interfaces</a> &#8211; digitalbond.com</li>
<li><a href="http://www.digitalbond.com/index.php/2010/07/14/metasploit-basics-%E2%80%93-part-4-exploit-and-attack-example/">Metasploit Basics – Part 4: Exploit and Attack Example</a> &#8211; digitalbond.com</li>
</ul>
</li>
<li><a href="http://www.kb.cert.org/vuls/id/732671">Cisco Industrial Ethernet 3000 Series switches have hardcoded SNMP community strings</a> &#8211; cert.org<br />
Successful exploitation of the vulnerability could result in an attacker obtaining full control of the device.</li>
<li><a href="http://www.darkoperator.com/blog/2010/7/14/metasploit-new-gui.html">Metasploit New GUI</a> &#8211; darkoperator.com<br />
A new GUI for Metasploit was added yesterday by ScriptJunkie to the Metasploit SVN Repository, this is the first version of a development version  as part of the Framework that is going to be improved and worked one as time progress.</li>
<li><a href="http://blog.mandiant.com/archives/1207">Malware Persistence without the Windows Registry</a> &#8211; mandiant.com<br />
The malware needs to be installed persistently, meaning that it will remain active in the event of a reboot.</li>
<li><a href="http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/">Mitigating .LNK Exploitation With Ariad</a> &#8211; didierstevens.com<br />
When you load the CD-ROM with the PoC (I use an ISO file inside a VM) and take a look at DbgView’s output, you’ll notice that payload gets executed.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Firefox Add-On Exploited<br />
It was discovered that this add-on contains code that intercepts login data submitted to any website, and sends this data to a remote location.</p>
<ul>
<li><a href="http://blog.mozilla.com/addons/2010/07/13/add-on-security-announcement/">Mozilla Sniffer</a> &#8211; mozilla.com</li>
<li><a href="http://news.netcraft.com/archives/2010/07/15/firefox-security-test-add-on-was-backdoored.html">Firefox security test add-on was backdoored</a> &#8211; netcraft.com</li>
</ul>
</li>
<li><a href="http://anti-virus.by/en/tempo.shtml">Rootkit.TmpHider</a> &#8211; anti-virus.by<br />
Modules of current malware were first time detected by &#8220;VirusBlokAda&#8221; company specialists on the 17th of June, 2010 and were added to the anti-virus bases as Trojan-Spy.0485 and Malware-Cryptor.Win32.Inject.gen.2.</li>
<li>USB Shortcuts Introduce New Can Of Worms To Windows Systems<br />
Researchers have discovered a sophisticated new strain of malicious software that piggybacks on USB storage devices and leverages what appears to be a previously unknown security vulnerability in the way Microsoft Windows processes shortcut files.</p>
<ul>
<li><a href="http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/">Experts Warn of New Windows Shortcut Flaw</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.sophos.com/pressoffice/news/articles/2010/07/stuxnet.html">Zero-Day vulnerability allows USB malware to run automatically, Sophos reports</a> &#8211; sophos.com</li>
<li><a href="http://www.sophos.com/blogs/chetw/g/2010/07/16/windows-day-attack-works-windows-systems/">Windows zero-day attack works on all Windows systems</a> &#8211; sophos.com</li>
</ul>
</li>
<li><a href="http://www.symantec.com/connect/de/blogs/trojansasfis-closer-look">Trojan.Sasfis: A Closer Look</a> &#8211; symantec.com<br />
In our recent article on Trojan.Sasfis we focused on the spam angle of the attack and in this piece we will take a deeper look at this somewhat persistent threat which our global sensors indicate is recently on the rise.</li>
<li><a href="http://www.computerworld.com/s/article/9179224/Researchers_Authentication_crack_could_affect_millions">Researchers: Authentication crack could affect millions</a> &#8211; computerworld.com<br />
A well-known cryptographic attack could be used by hackers to log into Web applications used by millions of users, according to two security experts who plan to discuss the issue at an upcoming security conference.</li>
<li><a href="http://www.sophos.com/blogs/sophoslabs/?p=10477">Malware exploiting x86 machine code redundancy</a> &#8211; sophos.com<br />
By definition an emulator will never be exactly like ‘the real thing’, and malware authors continually try to exploit this fact in order to evade detection.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Microsoft&#8217;s New Patch Tuesday<br />
As part of our usual monthly update cycle, today Microsoft is releasing four security bulletins to address five vulnerabilities in Windows and Microsoft Office.</p>
<ul>
<li><a href="http://blogs.technet.com/b/msrc/archive/2010/07/13/july-2010-security-bulletin-release.aspx">July 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-042.mspx?pubDate=2010-07-13">Microsoft Security Bulletin MS10-042 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-043.mspx?pubDate=2010-07-13">Microsoft Security Bulletin MS10-043 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-044.mspx?pubDate=2010-07-13">Microsoft Security Bulletin MS10-044 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-045.mspx?pubDate=2010-07-13">Microsoft Security Bulletin MS10-045 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/07/13/ms10-042-vulnerability-in-help-and-support-center.aspx">MS10-042: Vulnerability in Help and Support Center</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/07/13/ms10-045-microsoft-office-outlook-remote-code-execution-vulnerability.aspx">MS10-045: Microsoft Office Outlook Remote Code Execution vulnerability</a> &#8211; technet.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-july-2010">Microsoft Patch Tuesday &#8211; July 2010</a> &#8211; symantec.com</li>
<li><a href="http://www.h-online.com/security/news/item/Express-patch-for-Windows-Help-Center-1037609.html">Express patch for Windows Help Center</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://www.h-online.com/security/news/item/Winamp-5-58-eliminates-critical-FLV-vulnerabilities-1037900.html">Winamp 5.58 eliminates critical FLV vulnerabilities</a> &#8211; h-online.com<br />
According to French security services provider VUPEN, the problem is related to integer and buffer overflow issues within the VP6 decoder &#8220;vp6.w5s&#8221; used by Winamp when opening a specially crafted Flash Video (FLV) file.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2010/07/eta/">FBI Raids ‘Electronik Tribulation Army’ Over Witness Intimidation</a> &#8211; wired.com<br />
Jesse William McGraw, aka “GhostExodus,” pleaded guilty in May to computer-tampering charges for putting malware on a dozen machines at the Texas hospital where he worked as a security guard.</li>
<li><a href="http://sunbeltblog.blogspot.com/2010/07/gfi-software-acquires-sunbelt-software.html">GFI Software acquires Sunbelt Software</a> &#8211; sunbeltblog.blogspot.com<br />
Today, it was announced that Sunbelt Software has been acquired by GFI Software.</li>
<li><a href="http://swreflections.blogspot.com/2010/07/developers-just-dont-go-to-security.html">Developers just don’t go to security conferences</a> &#8211; swreflections.blogspot.com<br />
Developers and managers need to choose carefully where to spend their company’s money and time – or their own.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=9172">Secunia Half Year Report for 2010 shows interesting trends</a> &#8211; sans.edu<br />
Since 2005, no significant up-, or downward trend in the total number of vulnerabilities in the more than 29,000 products covered by Secunia Vulnerability Intelligence was observed.</li>
<li><a href="http://threatpost.com/en_us/blogs/talk-chinese-cyber-army-pulled-black-hat-071510?utm_source=Personalities+Pod&amp;utm_medium=Home+Page+Personalities&amp;utm_campaign=Personalities+Dennis">Talk on Chinese Cyber Army Pulled From Black Hat</a> &#8211; threatpost.com<br />
A talk on China&#8217;s state-sponsored offensive security efforts scheduled for the Black Hat conference later this month has been pulled from the conference after concerns were raised by some people within the Chinese and Taiwanese government about the talk&#8217;s content.</li>
<li><a href="http://blogs.forbes.com/firewall/2010/07/13/millions-of-home-routers-vulnerable-to-web-hack/">&#8220;Millions&#8221; Of Home Routers Vulnerable To Web Hack</a> &#8211; forbes.com<br />
The upcoming Black Hat security conference in Las Vegas offers an annual parade of security researchers revealing new ways to break various elements of the Internet.</li>
<li><a href="http://threatpost.com/en_us/blogs/mozilla-bumps-bug-bounty-3000-071610?utm_source=Personalities+Pod&amp;utm_medium=Home+Page+Personalities">Mozilla Bumps Bug Bounty to $3,000</a> &#8211; threatpost.com<br />
In an effort to enlist more help finding bugs in its most popular software, such as Firefox, Thunderbird and Firefox Mobile, Mozilla is jacking up the bounty it pays to researchers who report security flaws to $3,000</li>
<li><a href="http://threatpost.com/en_us/blogs/ms-windows-token-kidnapping-problems-resurface-071610">MS Windows Token Kidnapping Problems Resurface</a> &#8211; threatpost.com<br />
Cesar Cerrudo, founder and CEO of Argeniss, a security consultancy firm based in Argentina, first reported the token kidnapping hiccup to Microsoft in 2008 and after waiting in vain for a patch, he released the details during the Month of Kernel Bugs project.</li>
<li><a href="http://arstechnica.com/security/news/2010/07/dns-root-zone-finally-signed-but-security-battle-not-over.ars">DNS root zone finally signed, but security battle not over</a> &#8211; arstechnica.com<br />
This is an important step in the deployment of DNSSEC, the mechanism that will finally secure the DNS against manipulation by malicious third parties.</li>
</ul>
<ul></ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1131&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/07/19/week-28-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week 26 in Review 2010</title>
		<link>http://infosecevents.net/2010/07/04/week-26-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/07/04/week-26-in-review-2010/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 06:02:26 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[Hack in the Box]]></category>
		<category><![CDATA[HITB]]></category>
		<category><![CDATA[Next Hope]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SHB]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1117</guid>
		<description><![CDATA[Events Related:

Third SHB Workshop &#8211; schneier.com
This is a two-day gathering of computer security researchers, psychologists, behavioral economists, sociologists, philosophers, and others.
HiTB News
HiTB  organizes conferences for a while in Dubaï and Kuala Lumpur but this is the first time that an event is held in Europe and not too far from Belgium.

Hack in the Box Day [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.schneier.com/blog/archives/2010/06/third_shb_works.html">Third SHB Workshop</a> &#8211; schneier.com<br />
This is a two-day gathering of computer security researchers, psychologists, behavioral economists, sociologists, philosophers, and others.</li>
<li>HiTB News<br />
HiTB  organizes conferences for a while in Dubaï and Kuala Lumpur but this is the first time that an event is held in Europe and not too far from Belgium.</p>
<ul>
<li><span style="font-size: 13.3333px"><a href="http://blog.rootshell.be/2010/07/01/hack-in-the-box-day-1-wrap-up/">Hack in the Box Day #1 Wrap Up</a></span> &#8211; rootshell.be</li>
<li><span style="font-size: 13.3333px"><a href="http://blog.rootshell.be/2010/07/02/hack-in-the-box-day-2-wrap-up/">Hack in the Box Day #2 Wrap Up</a> &#8211; rootshell.be</span></li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://michael-coates.blogspot.com/2010/07/notes-from-owasp-bay-area-security.html">Notes from OWASP Bay Area Security Summit</a> &#8211; michael-coates.blogspot.com<br />
However the portion on dynamic identification and quarantine of malicious scripts was very interesting.</li>
<li><a href="http://travisgoodspeed.blogspot.com/2010/06/hacking-next-hope-badge.html">Hacking the Next Hope Badge</a> &#8211; travisgoodspeed.blogspot.com<br />
The following are some notes that will help enterprising neighbors to hack these badges, which will be running an MSP430 port of the OpenBeacon firmware.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://blog.portswigger.net/2010/06/comparing-web-application-scanners-part.html">Comparing web application scanners, part 2</a> &#8211; portswigger.net<br />
Scanners were scored based on their ability to identify different types of vulnerabilities in different scanning modes.</li>
<li><a href="http://www.digitalbond.com/index.php/2010/07/01/cisco-ios-auditing/">Cisco IOS Auditing</a> &#8211; digitalbond.com<br />
Earlier this month Tenable released a new policy compliance plugin for Nessus that allows auditing of Cisco router and switch configuration.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/07/third-party-web-widget-security-faq.html">Third-Party Web Widget Security FAQ</a> &#8211; jeremiahgrossman.blogspot.com<br />
Millions of websites such as online news, blogs, e-commerce, banks, webmail, social networking and more utilize third-party hosted content on their webpages in the form of JavaScript, Adobe Flash, Microsoft Silverlight, HTML IFrames, and images.</li>
<li><a href="http://www.terminal23.net/2010/07/securityacts_it_security_ezine.html">securityacts it security e-zine issue 3</a> &#8211; terminal23.net<br />
If you&#8217;re looking for a new security-related e-zine to read, check out SecurityActs.</li>
<li><a href="http://www.f-secure.com/weblog/archives/00001980.html">New AMTSO guidelines</a> &#8211; f-secure.com<br />
Anti-Malware Testing Standards Organization (AMTSO), which F-Secure is a member of, had a meeting in Helsinki in May.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li>BackTrack<br />
BackTrack started as a personal side project well over 5 years ago and by now has been downloaded over 5 million times.</p>
<ul>
<li><a href="http://www.backtrack-linux.org/backtrack/backtrack-present-and-future/">BackTrack, Present and Future</a> &#8211; backtrack-linux.org</li>
<li><a href="http://www.backtrack-linux.org/bt/roadmap/">BackTrack 4 Development Roadmap</a> &#8211; backtrack-linux.org</li>
</ul>
</li>
<li><a href="http://blogs.sans.org/computer-forensics/2010/06/28/autoruns-dead-forensics/">Autoruns and Dead Computer Forensics</a> &#8211; sans.org<br />
It is essentially a targeted registry dump, peering into at least a hundred different Windows Registry keys that the boot and logon processes rely upon.</li>
<li><a href="http://www.mavitunasecurity.com/blog/netsparker-community-edition-1500-released/">Netsparker Community Edition 1.5.0.0 Released</a> &#8211; mavitunasecurity.com<br />
There are not many new features in Community Edition but this release addresses the most common issues and includes several improvements.</li>
<li><a href="http://code.google.com/p/skipfish/">Skipfish 1.46beta</a> &#8211; code.google.com/p/skipfish/<br />
A fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/">FxCop – .NET Framework Security Analysis Tool</a> &#8211; darknet.org.uk<br />
FxCop is an application that analyzes managed code assemblies.</li>
<li><a href="http://www.notsosecure.com/folder2/2010/07/01/bsqlbf-v-2-6/">bsqlbf v. 2.6</a> &#8211; notsosecure.com<br />
The new addition is the execution of any metasploit payload after executing OS code against Oracle database server by exploiting SQL Injection from web apps.</li>
<li><a href="http://tmacuk.co.uk/?p=240">upSploit – Press Release</a> &#8211; tmacuk.co.uk<br />
This Vulnerability Advisory Gateway (VAG) should break down the barriers for security researchers and professionals to pass details of vulnerabilities to vendors in a structured easy to follow process.</li>
<li><a href="http://s7ephen.github.com/SandKit/">SandKit</a> &#8211; s7ephen.github.com<br />
SandKit is a toolset that is intended to assist with the investigation of Sandbox technologies.</li>
<li><a href="http://hexblog.com/2010/07/ida_pro_57_highlights.html">IDA Pro 5.7 highlights</a> &#8211; hexblog.com<br />
We have released a IDA Pro 5.7 few days ago.</li>
<li><a href="http://www.winpcap.org/install/default.htm">WinPcap</a> &#8211; winpcap.org<br />
The latest stable WinPcap version is 4.1.2.</li>
<li><a href="http://code.google.com/p/ostinato/">ostinato 0.1.1</a> &#8211; code.google.com/p/ostinato/<br />
Ostinato is an open-source, cross-platform packet/traffic generator and analyzer with a friendly GUI.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://bernardodamele.blogspot.com/2010/06/got-database-access-own-network.html">Got database access? Own the network!</a> &#8211; bernardodamele.blogspot.com<br />
The presentation highlights techniques to exploit a MySQL, PostgreSQL or Microsoft SQL Server database server in real world.</li>
<li><a href="http://rdist.root.org/2010/06/28/ssl-gives-point-to-point-not-end-to-end-security/">SSL gives point-to-point, not end-to-end security</a> &#8211; root.org<br />
SSL provides good point-to-point privacy and integrity protection. However, there is no guarantee to upper layers that SSL is indeed in use.</li>
<li><a href="http://pandalabs.pandasecurity.com/hcp-vulnerability-exploited-in-the-wild/">HCP Vulnerability Exploited in the Wild</a> &#8211; pandasecurity.com<br />
This vulnerability disclosure has fueled an intense debate amongst security professionals on responsible disclosure, as the Google researcher only allowed Microsoft 5 days before going public with the flaw details.</li>
<li><a href="http://inner-knowledge.blogspot.com/2010/06/curious-case-of-jboss-hacking.html">The curious case of JBoss Hacking</a> &#8211; inner-knowledge.blogspot.com<br />
It is not so rare seeing jboss where the jmx-console is not password protected.</li>
<li><a href="http://gunslingerc0de.wordpress.com/2010/06/29/linux-buffer-overflow-ii/">Linux buffer overflow II</a> &#8211; gunslingerc0de.wordpress.com<br />
In the first edition of my tutorial tutorial explains berbuffer 400-byte buffer overflow.</li>
<li><a href="http://www.room362.com/blog/2010/6/28/set-wallpaper-meterpreter-script.html">Set Wallpaper Meterpreter Script</a> &#8211; room362.com<br />
Certainly nothing to fuss over, but I&#8217;ve had a fascination with setting my target&#8217;s wallpaper as sort of a calling card for years now.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=9091&amp;rss">Vulnerability Assessment Testing Automation Part I</a> &#8211; sans.edu<br />
In my SANSFire presentation I described how and why to automate parts of the security testing process.</li>
<li><a href="http://www.petefinnigan.com/weblog/archives/00001323.htm">V3rity has released a redo log mining tool to extract DDL from redo logs</a> &#8211; petefinnigan.com<br />
V3rity is the new company founded by David Litchfield in March 2010 since he left NGS and until recently his site had little on it.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/06/full-disclosure-our-turn.html">Full-Disclosure, Our Turn</a><a href="http://jeremiahgrossman.blogspot.com/2010/06/full-disclosure-our-turn.html"> </a> &#8211; jeremiahgrossman.blogspot.com<br />
No Web applications, no forms, no log-in, no user-supplied input where XSS can hide.</li>
<li><a href="http://www.attackvector.org/social-security-number-format/">Social Security Number Format</a> &#8211; attackvector.org<br />
First, for those of you who live under a rock, or across the pond, a social security number is in the format of xxx-xx-xxxx.</li>
<li><a href="http://holisticinfosec.blogspot.com/2010/06/csrf-flaws-that-pack-punch.html">CSRF flaws that pack a punch</a> &#8211; holisticinfosec.blogspot.com<br />
A year after DEFCON 17, cross-site request forgery (still one of my favorite bugs) continues to present itself in some mighty interesting places.</li>
<li><a href="http://trustedsignal.blogspot.com/2010/06/i-had-privilege-of-being-invited-to.html">Wifi Security Slides</a> &#8211; trustedsignal.blogspot.com<br />
There are a few canned video demos in the PPT version that are obviously not in the PDF version and the PPT version contains copious notes, not found in the PDF.</li>
<li><a href="http://blog.mandiant.com/archives/1102">Memory acquisition and the pagefile(s)</a> &#8211; mandiant.com<br />
The easiest way to do this with Memoryze is to use the MemoryDD.bat script from the command line or to use the UI, Audit Viewer.</li>
<li><a href="http://bernardodamele.blogspot.com/2010/06/sqlmap-and-soap-based-web-services.html">sqlmap and SOAP based web services</a> &#8211; bernardodamele.blogspot.com<br />
Last week a sqlmap user, Chilik Tamir, provided me with a patch to add basic support for SOAP based requests to the tool.</li>
<li><a href="http://www.sophos.com/blogs/chetw/g/2010/06/29/lessons-criminals-good-passwords-matter/">Lessons from criminals &#8211; Good passwords matter</a> &#8211; sophos.com<br />
Unless this is an elaborate public relations stunt, it appears the integrity of AES-256 as a military-grade encryption standard has been proven in a rather public way.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/426">more with rpcclient</a> &#8211; carnal0wnage.attackresearch.com<br />
Got asked to help remotely locate local admins on boxes on a network.</li>
<li><a href="http://chirashi.zensay.com/2010/07/you-want-the-blackberry-event-log-beg-damnit/">You want the BlackBerry Event Log? beg damnit!</a> &#8211; chirashi.zensay.com<br />
If I succeeded at understanding this topic, I would be able to directly connect to a BlackBerry device and collect all the information that I wanted.</li>
<li>Twitter updates
<ul>
<li>Looks like it&#8217;s possible to infinitely brute force Windows passwords without hitting lockout policy using &#8220;Change Passwd&#8221; Is that old news? &#8211; <a href="http://twitter.com/ax0n/statuses/17514181847">ax0n</a></li>
<li>Arduino + MetaSploit + USB wireless presenter dongle == VNC remote access on the box. &#8211; <a href="http://twitter.com/hdmoore/statuses/17494338846">hdmoore</a></li>
<li>@ax0n you have to be authenticated to the domain to access the SAM function though right? Once you have an account, it works &#8211; <a href="http://twitter.com/hdmoore/statuses/17516610705">hdmoore</a></li>
</ul>
</li>
<li><a href="http://gunslingerc0de.wordpress.com/2010/07/02/how-to-write-shellcode/">How to write shellcode</a> &#8211; gunslingerc0de.wordpress.com<br />
I previously had written an article about buffer overflow, it is time I wrote an article how to write shellcode.</li>
<li><a href="http://taosecurity.blogspot.com/2010/07/secunia-survey-of-dep-and-aslr.html">Secunia Survey of DEP and ASLR</a> &#8211; taosecurity.blogspot.com<br />
At the FIRST conference last month, Dave Aitel said something to the effect that DEP and ASLR are the only two noteworthy technologies produced by Microsoft since starting their security initiative.</li>
<li><a href="http://blog.teusink.net/2010/07/hacking-wireless-presenters-with.html">Hacking wireless presenters with an Arduino and Metasploit</a> &#8211; teusink.net<br />
Someone in the audience can control the slides and can send any keystroke you want to the victim, as if they were sitting at the keyboard.</li>
<li><a href="http://blog.teusink.net/2009/05/ciscoworks-tftp-directory-traversal.html">CiscoWorks TFTP directory traversal exploit</a> &#8211; teusink.net<br />
So far I have not seen any details published so I decided to see if I could find the bug.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Critical-hole-closed-in-PNG-reference-library-1030043.html">Critical hole closed in PNG reference library</a> &#8211; h-online.com<br />
As numerous browsers use libpng to display images, specially crafted web pages could infect visitors&#8217; PCs with malicious code.</li>
<li>Adobe Patches PDF /Launch Hole<br />
Adobe today shipped a critical Reader/Acrobat patch to cover a total of 17 documented vulnerabilities that expose Windows, Mac and UNIX users to malicious hacker attacks.</p>
<ul>
<li><a href="http://blogs.adobe.com/psirt/2010/06/security_updates_released_for.html">Security updates released for Adobe Reader and Acrobat</a> &#8211; adobe.com</li>
<li><a href="http://threatpost.com/en_us/blogs/critical-pdf-reader-patch-fixes-launch-command-attack-vector-062910">Critical PDF Reader Patch Fixes &#8216;/Launch&#8217; Command Attack Vector</a> &#8211; threatpost.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://research.zscaler.com/2010/06/likejacking-what-is-it.html">&#8216;LikeJacking&#8217; &#8211; What is it?</a> &#8211; zscaler.com<br />
The term has been adopted enough, that there is a Wikipedia page for it, with a very straight-forward definition.</li>
<li><a href="http://www.infoworld.com/t/instant-messaging/privacy-problems-persist-in-latest-windows-messenger-2011-beta-536">Privacy problems persist in latest Windows Messenger 2011 beta</a> &#8211; infoworld.com<br />
Earlier versions of Messenger played fast and loose with your privacy.</li>
<li><a href="http://www.esecurityplanet.com/features/article.php/3890171/SSL-Certificates-In-Use-Today-Arent-All-Valid.htm">SSL Certificates In Use Today Aren&#8217;t All Valid</a> &#8211; esecurityplanet.com<br />
Ivan Ristic, director of engineering at Qualys, said that he found that only about 23 million of the sites were actually running SSL.</li>
<li><a href="http://www.darkreading.com/securityservices/security/government/showArticle.jhtml?articleID=225701705">White House Cybersecurity Czar Unveils National Strategy For Trusted Online Identity</a> &#8211; darkreading.com<br />
Devil&#8217;s in the details for Obama administration&#8217;s draft plan for eliminating passwords and advancing authentication, security expert says.</li>
<li><a href="http://www.theregister.co.uk/2010/06/30/unsafe_surfing/">Regular domains beat smut sites at hosting malware</a> &#8211; theregister.co.uk<br />
A study by free anti-virus firm Avast found 99 infected legitimate domains for every infected adult web site.</li>
<li><a href="http://techbuddha.wordpress.com/2010/07/02/ibm-to-acquire-bigfix-hallelujah-can-i-get-a-witness/">IBM to Acquire BigFix – Hallelujah! Can I Get a Witness?!</a> &#8211; techbuddha.wordpress.com<br />
I will post more later but given all the blood, sweat, and tears we have poured into BigFix we are extremely excited about this move.</li>
<li><a href="http://krebsonsecurity.com/2010/07/top-apps-largely-forgo-windows-security-protections/">Top Apps Largely Forgo Windows Security Protections</a> &#8211; krebsonsecurity.com<br />
Many of the most widely used third-party software applications for Microsoft Windows do not take advantage of two major lines of defense built into the operating system.</li>
<li><a href="http://www.ethicalhack3r.co.uk/security/738/">Why Johnny Can’t Pentest</a> &#8211; ethicalhack3r.co.uk<br />
The three authors of the paper (Adoupe, Marco, Vigna) test the black-box scanners against their custom vulnerable web application they called WackoPicko.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1117&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/07/04/week-26-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week 24 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/06/21/week-24-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/06/21/week-24-in-review-2010/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 10:13:11 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[BSides Las Vegas]]></category>
		<category><![CDATA[KartCon]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SANS Penetration Testing Summit]]></category>
		<category><![CDATA[Security BSides]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1090</guid>
		<description><![CDATA[Events Related:

Security BSides Las Vegas announcements &#8211; uncommonsensesecurity.com
The first few talks confirmed are great and there are plenty more killer talks to be announced.
KartCon2010 &#8211; owasp.org
RSVP now to the 5th Annual OWASP KartCon 2010!
Penetration Testing Summit 2010 &#8211; tenablesecurity.com
The SANS Penetration Testing Summit was held this year at the Hyatt Baltimore in Baltimore, MD on [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.uncommonsensesecurity.com/2010/06/security-bsides-las-vegas-announcements.html">Security BSides Las Vegas announcements</a> &#8211; uncommonsensesecurity.com<br />
The first few talks confirmed are great and there are plenty more killer talks to be announced.</li>
<li><a href="http://www.owasp.org/index.php/KartCon2010">KartCon2010</a> &#8211; owasp.org<br />
RSVP now to the 5th Annual OWASP KartCon 2010!</li>
<li><a href="http://blog.tenablesecurity.com/2010/06/penetration-testing-summit-2010.html">Penetration Testing Summit 2010</a> &#8211; tenablesecurity.com<br />
The SANS Penetration Testing Summit was held this year at the Hyatt Baltimore in Baltimore, MD on June 14 &#8211; 15 and was focused on “What Works in Penetration Testing&#8221;.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://darknet-consulting.com/video/vector2/meta101.wmv">Metasploit 101</a> &#8211; darknet-consulting.com<br />
Are you a security professional that needs to learn the basis of metasploit but haven&#8217;t found a source?</li>
<li><a href="http://www.irongeek.com/i.php?page=security%2Fmutillidae-deliberately-vulnerable-php-owasp-top-10">Mutillidae: A Deliberately Vulnerable Set Of PHP Scripts That Implement The OWASP Top 10</a> &#8211; irongeek.com<br />
What I&#8217;m attempting to do with Mutillidae is implement the OWASP Top 10 in PHP, and do it in such a way that it is easy to demonstrate common attacks to others.</li>
<li><a href="http://www.f-secure.com/weblog/archives/00001970.html">Have you ever configured your Adobe Flash Player?</a> &#8211; f-secure.com<br />
Flash&#8217;s settings are rather curious as the controls themselves aren&#8217;t located on the computer but are instead accessed through a Flash object hosted by Adobe.</li>
<li><a href="http://ifraudalert.org/">Internet Fraud Alert</a> &#8211; ifraudalert.org<br />
Internet Fraud Alert creates a trusted and effective mechanism for participating researchers to report stolen account credentials discovered online to the appropriate institution responsible for that account.</li>
<li><a href="http://jukt-micronics.com/2010/06/17/book-review-chained-exploits-advanced-hacking-attacks-from-start-to-finish/">Book Review: Chained Exploits: Advanced Hacking Attacks from Start to Finish</a> &#8211; jukt-micronics.com<br />
To its credit, Chained Exploits: Advanced Hacking Attacks from Start to Finish is fairly well written.</li>
<li><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-26.pdf">Insecure 26 Now Available</a> &#8211; net-security.org<br />
Insecure 26 is available, and as usual, has plenty of interesting articles such as a lengthy one on analyzing Flash content for vulnerabilities.</li>
<li><a href="http://politics.slashdot.org/story/10/06/18/2146221/Wikileaks-Source-Outed-To-Stroke-Hackers-Own-Ego">Penetration Testing versus Vulnerability Scanning</a> &#8211; plynt.com<br />
Penetration Testing is usually referred to testing by an ethical hacker to break into a target network with limited information about the said network.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://freeworld.thc.org/thc-hydra/">THC-Hydra</a> &#8211; freeworld.thc.org<br />
A very fast network logon cracker which support many different services</li>
<li><a href="http://freeworld.thc.org/thc-ipv6/">THC-IPV6</a> &#8211;  freeworld.thc.org<br />
A complete tool set to attack the inherent protocol weaknesses of IPV6 and ICMP6, and includes an easy to use packet factory library.</li>
<li><a href="http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/">Onapsis Bizploit – ERP Penetration Testing Framework</a> &#8211; darknet.org.uk<br />
Bizploit is expected to provide the security community with a basic framework to support the discovery, exploration, vulnerability assessment and exploitation of ERP systems.</li>
<li><a href="http://www.thespanner.co.uk/2010/06/16/astalanumerator-07/">Astalanumerator 0.7</a> &#8211; thespanner.co.uk<br />
This version contains various CSS fixes and tracks each object within links and via the astalanumerator object.</li>
<li><a href="http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Main_Page">WATOBO &#8211; THE Web Application Toolbox </a>- sourceforge.net/apps/mediawiki/watobo/<br />
WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities.</li>
<li><a href="http://blog.mandiant.com/archives/1075">Web Historian: Reloaded</a> &#8211; mandiant.com<br />
This release is a complete rewrite and revamp of our very popular web history extraction tool.</li>
<li><a href="http://blog.websecurify.com/2010/06/websecurify-06rc2-is-available-for.html">Websecurify 0.6RC2 Is Available for Download</a> &#8211; websecurify.com<br />
0.6RC2 fixes several bugs detected during the 0.6RC1 stage (thanks for the bug submissions), improves on the UI and introduces more internal changes to simplify and enhance future developments of the platform.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://ha.ckers.org/blog/20100614/turning-xss-into-clickjacking/">Turning XSS into Clickjacking</a> &#8211; ha.ckers.org<br />
Those of us who do a lot of work in the security world have come to realize that there is a ton of cross site scripting (XSS) out there.</li>
<li><a href="http://recursion.com/interpolique.html">Interpolique</a> &#8211; recursion.com<br />
Generic security flaws were supposed to go away with memory safe languages.</li>
<li><a href="http://www.symantec.com/connect/de/blogs/zero-day-connection">A Zero-day Connection</a> &#8211; symantec.com<br />
While investigating the recent Adobe Remote Code Execution Vulnerability, we came across some interesting similarities to the malware and shellcode that were used in the &#8216;iepeers.dll&#8217; Remote Code Execution tacks from March 2010.</li>
<li><a href="http://blog.metasploit.com/2010/06/meterpreter-for-pwned-home-pages.html">Meterpreter for Pwned Home Pages</a> &#8211; metasploit.com<br />
About a year ago, while looking through various buggy, backdoored PHP shells, I decided it might be useful to have some of Meterpreter&#8217;s networking features in the web&#8217;s most pwnable language.</li>
<li><a href="http://ha.ckers.org/blog/20100614/lighttpd-and-slowloris/">Lighttpd and Slowloris</a> &#8211; ha.ckers.org<br />
I had heard various different reports from people who use lighttpd during the initial investigation of slowloris that it was not vulnerable.</li>
</ul>
<ul>
<li>SANS PenTest Summit slides
<ul>
<li><a href="http://spl0it.org/files/talks/sans_pentest_  summit10/Goal_Oriented_Pentesting.pdf">&#8220;Goal  Oriented Pentesting&#8221; slides from @Jabra</a> &#8211; spl0it.org</li>
<li><a href="http://pauldotcom.com/PostExploitation-Doin  gTheHappyDanceAndMore.pdf">&#8220;Post  Exploitation: Doing the happy dance and more&#8221; slides from @pauldotcom</a> &#8211; pauldotcom.com</li>
<li><a href="http://www.metasploit.com/data/confs/sanspt 2010/PenTestAutomation.pdf">&#8220;Penetration Test Automation&#8221; from @hdmoore</a> &#8211; metasploit.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://blogs.23.nu/RedTeam/2010/06/new-whitepaper-jboss-as-deploying-wars-with-the-deploymentfilerepository-mbean/">New Whitepaper: JBoss AS – Deploying WARs with the DeploymentFileRepository MBean</a> &#8211; blogs.23.nu/RedTeam<br />
It explains how to deploy WAR files with the DeploymentFileRepository MBean and how this is even possible with Cross Site Request Forgery (CSRF).</li>
<li><a href="http://blog.commandlinekungfu.com/2010/06/episode-99-needle-in-haystack.html">Episode #99: The .needle in the /haystack</a> &#8211; commandlinekungfu.com<br />
I whipped up a quick some PowerShell to give me a quick overview of the file types in the directory tree.</li>
<li><a href="http://www.attackvector.org/browser-headers-and-information-leaks/">Browser headers and information leaks</a> &#8211; attackvector.org<br />
In this post, I point out a few browser headers which leak information that can be used for malicious purposes.</li>
<li><a href="http://ha.ckers.org/blog/20100616/using-dns-to-find-high-value-targets/">Using DNS to Find High Value Targets</a> &#8211; ha.ckers.org<br />
Because companies tend to point their DNS to those SaaS providers for white labeling, often you’ll see a convergence of a lot of sub-domains all pointing to a single IP address or set of IP addresses.</li>
<li><a href="http://securitybraindump.blogspot.com/2010/06/post-exploitation-pivoting-with-windows.html">Post Exploitation Pivoting with the Windows 7 Vault</a> &#8211; securitybraindump.blogspot.com<br />
While I generally agree with this, the emerging capabilities of attack and forensic tools that acquire volatile memory from a host (and consequently decrypted credentials), only require a bit more patience.</li>
<li><a href="http://blog.fortinet.com/the-ozdok-botnet-and-des-security/">The Ozdok Botnet and DES Security</a> &#8211; fortinet.com<br />
It soon developed that the encryption used was DES (Data Encryption Standard), in ECB mode.</li>
<li><a href="http://www.attackvector.org/brute-force-with-thc-hydra/">Brute Force with THC Hydra</a> &#8211; attackvector.org<br />
Sometimes the only way in is to resort to password cracking (or, “brute forcing”). I would consider this to be another one of those last resort methods that I use when all else has failed.</li>
<li><a href="http://www.symantec.com/connect/de/blogs/clickjack-baddie-whack">Clickjack Baddie Whack</a> &#8211; symantec.com<br />
To prevent these kinds of attacks it’s important to use caution when browsing the Web, but unfortunately this can only go so far, and it’s not really feasible to disable JavaScript altogether because of the key role it plays in today’s Web.</li>
<li><a href="http://blog.fortinet.com/security-risks-in-asynchronous-patch-release-schedules/">Security Risks in Asynchronous Patch Release Schedules</a> &#8211; fortinet.com<br />
As software becomes more complex and integrate, code becomes shared and recycled. If a security risk (vulnerability) were to be discovered and fixed in the main trunk of code, it should also be fixed through its derivatives at the same time.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/06/anti-waf-software-security-only.html">Anti-waf-software-security-only-zealotry</a> &#8211; jeremiahgrossman.blogspot.com<br />
Recently on Twitter I asked why some people feel oddly compelled to rely upon the shortcomings of Web Application Firewalls (WAFs) as a means to advocate for a Secure Development Lifecycle (SDL).</li>
<li><a href="http://blog.happypacket.net/2010/06/sharing-data-remotely-through.html">Sharing data remotely through Metasploit</a> &#8211; happypacket.net<br />
I&#8217;m working on some more integration between tools, but for now I have written a db module for Metasploit&#8217;s XMLRPC engine which allows remote processes to get information from the database.</li>
<li><a href="http://www.digininja.org/blog/finding_interesting_db_data.php">Finding Interesting Database Data</a> &#8211; digininja.org<br />
In one of the early chapters he discusses the Asprox Botnet and explains the way it trawls through any databases it finds looking for columns that are of a type that will take text.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=9037">DNS Sinkhole ISO  Available for Download</a> &#8211; sans.edu<br />
Last week, during the SANSFire conference, I did a talk on DNS Sinkhole  and made an ISO available for download.</li>
<li><a href="http://www.f-secure.com/weblog/archives/00001972.html">XSS</a> &#8211; f-secure.com<br />
A typical XSS demonstration showing a funny dialog box on somebody else&#8217;s site just emphasizes how harmless such an attack looks.</li>
<li><a href="http://grey-corner.blogspot.com/2010/06/bypassing-restrictive-proxies-part-1.html">Bypassing Restrictive Proxies Part 1, Encoded Executables and DNS Tunneling</a> &#8211; grey-corner.blogspot.com<br />
This scenario simply involves creating a vbscript file that contains an encoded copy of your chosen executable, that when run will decode the file, write it to disk, and then run it.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/sql-injection-attacks-aimed-stealing-gaming-credentials-experts-say-061410">SQL Injection Attacks Aimed at Stealing Gaming Credentials, Experts Say</a> &#8211; threatpost.com<br />
The mass SQL injection attack that has been ongoing for a week or so now is designed mainly to steal credentials for online games and is quite well planned and organized, experts say.</li>
<li><a href="http://news.cnet.com/8301-27080_3-20007785-245.html">Unpatched Windows XP-related hole exploited in attacks</a> &#8211; cnet.com<br />
Malicious hackers were found to be exploiting a hole on Tuesday affecting Windows XP that a Google researcher disclosed last week before Microsoft had a chance to fix it, the software giant confirmed.</li>
<li><a href="https://net-ninja.net/blog/?p=124">Bypassing ASLR and DEP under Windows</a> &#8211; net-ninja.net<br />
We will discuss this techniques in relation to stack based buffer overflows only for now.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.zdnet.com/blog/security/apple-plugs-28-mac-os-x-security-holes/6707">Apple plugs 28 Mac OS X security holes</a> &#8211; zdnet.com<br />
Apple has shipped another mega Mac OS X patch bundle to fix a total of 28 documented security vulnerabilities affecting the Mac ecosystem.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>Likejacking in Facebook<br />
This is very similar to a campaign they ran over the weekend, where the   lure was &#8220;96 hottest women&#8221;, so they either found five more, or they  are  just incrementing the numbers.</p>
<ul>
<li><a href="http://thompson.blog.avg.com/2010/06/more-likejacking-on-facebook.html">More  LikeJacking on FaceBook</a> &#8211; avg.com</li>
<li><a href="http://www.sophos.com/pressoffice/news/articles/2010/06/clickjacking.html">Clickjacking attack spreads virally across Facebook, Sophos reports </a>- sophos.com</li>
<li><a href="http://www.sophos.com/blogs/sophoslabs/?p=10001">More likejacking targets: Farmville, Sex And The City 2, Kendra Wilkinson, …</a> &#8211; sophos.com</li>
</ul>
</li>
<li><a href="http://www.securelist.com/en/blog/2201/Offensive_attacks_and_the_World_Cup_2010">Offensive attacks and the World Cup 2010</a> &#8211; securelist.com<br />
The cyber criminals didn’t want to lose such “good” opportunity for them and already took advantage in some ways like sending spam leading to phishing sites, to spread malware and so on.</li>
<li><a href="http://www.wired.com/politics/law/magazine/17-04/ff_diamonds?currentPage=all">The Untold Story of the World&#8217;s Biggest Diamond Heist</a> &#8211; wired.com<br />
In February 2003, Notarbartolo was arrested for heading a ring of Italian thieves.</li>
<li>News on the iPad fiasco at AT&amp;T
<ul>
<li><a href="http://mobile.slashdot.org/story/10/06/14/210205/ATampT-Breach-May-Be-Worse-Than-Initially-Thought">AT&amp;T Breach May Be Worse Than Initially Thought</a> &#8211; slashdot.org</li>
<li><a href="http://www.veracode.com/blog/2010/06/website-vulnerability-research-and-disclosure/">Website Vulnerability Research and Disclosure</a> &#8211; veracode.com</li>
<li><a href="http://erratasec.blogspot.com/2010/06/ipad-hack-vs-owasp-top-10.html">iPad hack vs. OWASP Top 10</a> &#8211; erratasec.blogspot.com</li>
<li><a href="http://blog.vodun.org/2010/06/at-is-wrong-about-ipad-breach-i-have.html">AT&amp;T is Wrong About the iPad Breach &amp; I have code to prove it</a> &#8211; vodun.org</li>
</ul>
</li>
<li><a href="http://news.cnet.com/8301-27080_3-20007672-245.html">Money trumps security in smart-meter rollouts, experts say</a> &#8211; cnet.com<br />
In a rush to take advantage of U.S. stimulus money, utilities are quickly deploying thousands of smart meters to homes each day&#8211;smart meters that experts say could easily be hacked.</li>
<li>Card cloners nabbed<br />
According to Spanish police the organization stole more than 20 million  Euros, and was also involved with robbery, fraud, extortion, sexual  exploitation, and money laundering.</p>
<ul>
<li><a href="http://krebsonsecurity.com/2010/06/police-arrest-178-in-u-s-europe-raid-on-credit-cards-cloning-labs/">Police  Arrest 178 in U.S.-Europe Raid on Credit Card ‘Cloning Labs’</a> &#8211;  krebsonsecurity.com</li>
<li><a href="http://garwarner.blogspot.com/2010/06/178-international-credit-card.html">178 International Credit Card Fraudsters arrested</a> &#8211; garwarner.blogspot.com</li>
</ul>
</li>
<li><a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=225700088">Kaminsky Issues Developer Tool To Kill Injection Bugs</a> &#8211; darkreading.com<br />
Researcher&#8217;s new startup offers up new approach to preventing common SQL injection, XSS vulnerabilities in software .</li>
<li><a href="http://www.zdnet.com/blog/security/liebermans-cyber-security-bill-the-good-the-bad-the-ugly/6686">Lieberman&#8217;s cyber-security bill: The good, the bad, the ugly</a> &#8211; zdnet.com<br />
There is little in our world today that is as poorly managed, rapidly changing and outright dangerous as “cyberspace”.</li>
<li>Some blog stirrings from the Wikileaks fiasco
<ul>
<li><a href="http://www.attackvector.org/my-02-on-lamo-the-media-whore/">My .02 on Lamo – The Media Whore.</a> &#8211; attackvector.org</li>
<li><a href="http://politics.slashdot.org/story/10/06/18/2146221/Wikileaks-Source-Outed-To-Stroke-Hackers-Own-Ego">Wikileaks Source Outed To Stroke Hacker&#8217;s Own Ego</a> &#8211; slashdot.org</li>
<li><a href="http://www.boingboing.net/2010/06/19/wikileaks-a-somewhat.html">Wikileaks: a somewhat less redacted version of the Lamo/Manning logs</a> &#8211; boingboing.net</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/researchers-find-government-site-hosting-phshing-data-061610">Researchers Find Government Site Hosting Phishing Data</a> &#8211; threatpost.com<br />
Phishing gangs have been getting bolder of late, and there&#8217;s no clearer evidence than the cache of phishing data that researchers at Sunbelt found on a site owned by the Paraguayan government.</li>
<li><a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=225700219">New Crypto-Cracking Tool To Target Databases</a> &#8211; darkreading.com<br />
&#8216;Poet&#8217; takes advantage of commonly weak encryption-key deployment.</li>
<li><a href="http://mashable.com/2010/06/18/https-everywhere/">HTTPS Everywhere Encrypts Your Connection with Major Websites</a> &#8211; mashable.com<br />
It encrypts your web communication with several major websites that support — but may not default to secure — HTTPS connection.</li>
<li><a href="http://www.thedailybeast.com/blogs-and-stories/2010-06-18/new-bill-would-let-obama-police-internet-for-national-security-reasons/?cid=hp:exc">Can Obama Shut Down the Internet?</a> &#8211; thedailybeast.com<br />
A new bill rocketing through Congress would give the president sweeping powers to police the Web for national-security reasons.</li>
<li><a href="http://torrentfreak.com/huge-security-flaw-makes-vpns-useless-for-bittorrent-100617/">Huge Security Flaw Makes VPNs Useless for BitTorrent</a> &#8211; torrentfreak.com<br />
Millions of BitTorrent users who have chosen to hide their identities through a VPN service may not be as anonymous as they would like to be.</li>
<li><a href="http://praetorianprefect.com/archives/2010/06/did-ligatt-securitys-ceo-threaten-the-life-of-a-security-professional/">Did LIGATT Security’s CEO Threaten the Life of a Security Professional?</a> &#8211; praetorianprefect.com<br />
So how did one of these men come to threaten the lives of the other and his family?</li>
<li><a href="http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0423.html">TEHTRI-Security released 13 0days against web tools used by evil attackers</a> &#8211; neohapsis.com<br />
We have given new methods to counter-strike intruders with our new exploits giving you remote shells, remote SQL injection, permanent XSS and dangerous XSRF, against remote tools used by attackers.</li>
<li><a href="http://news.bbc.co.uk/2/hi/technology/10349001.stm">Fighting back against web attacks</a> &#8211; bbc.co.uk<br />
Hi-tech criminals are not very good at securing the tools they use to attack websites, suggests research.</li>
<li><a href="http://praetorianprefect.com/archives/2010/06/4305/">LIGATT’s Evans Strikes Back</a> &#8211; praetorianprefect.com<br />
Gregory Evans, the CEO of LIGATT Security, is not taking the criticism  heaped upon himself and his firm or his latest book lying down.</li>
</ul>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1090&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/06/21/week-24-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week 23 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/06/14/week-23-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/06/14/week-23-in-review-2010/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 11:46:03 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[HackMiami]]></category>
		<category><![CDATA[WEIS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1087</guid>
		<description><![CDATA[Events Related:

The Ninth Workshop on the Economics of Information Security (WEIS 2010) &#8211; econinfosec.org
Program for the upcoming Harvard security event.
HackMiami Pwn-Off &#8211; n00bz.net
Time to fire up the test machines because we have a battle royal.
Workshop on the economics of information security 2010 &#8211; lightbluetouchpaper.org
The workshop kicked off with a keynote talk from Tracey Vispoli of [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://weis2010.econinfosec.org/program.html">The Ninth Workshop on the Economics of Information Security (WEIS 2010)</a> &#8211; econinfosec.org<br />
Program for the upcoming Harvard security event.</li>
<li><a href="http://www.n00bz.net/canvas-vs-core-vs-metasploit/">HackMiami Pwn-Off</a> &#8211; n00bz.net<br />
Time to fire up the test machines because we have a battle royal.</li>
<li><a href="http://www.lightbluetouchpaper.org/2010/06/07/workshop-on-the-economics-of-information-security-2010/">Workshop on the economics of information security 2010</a> &#8211; lightbluetouchpaper.org<br />
The workshop kicked off with a keynote talk from Tracey Vispoli of Chubb Insurance.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.abysssec.com/blog/2010/05/past-present-future-of-windows-exploitation/">Past, Present, Future of Windows Exploitation</a> &#8211; abysssec.com<br />
This is v0.1 of this post and in this post i’m going to have a review and brief history on exploitation with focus on windows.</li>
<li><a href="http://www.abysssec.com/blog/2010/03/attention-in-php-source-code-auditing/">Additional notes in PHP source code auditing</a> &#8211; abysssec.com<br />
Today, I decide talk about some of my experience about methods of vulnerability discovery techniques through source code auditing.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://blog.mandiant.com/archives/994">New Memoryze, Audit Viewer, and Training</a> &#8211; mandiant.com<br />
The new version of the software includes all of the memory analysis features that are available in the newly released MANDIANT Intelligent Response (MIR) 1.4.</li>
<li>Poet cracks server-encrypted session data<br />
Two researchers have released a tool which can be used to crack web server-encrypted session data contained in cookies and parameters hidden in HTML pages.</p>
<ul>
<li><a href="http://netifera.com/research/">Padding Oracle Exploit Tool</a> &#8211; netifera.com</li>
<li><a href="http://www.h-online.com/security/news/item/Tool-for-cracking-encrypted-session-data-1017626.html">Tool for cracking encrypted session data</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://blog.0x0lab.org/2010/06/dirbuster-dictionary-populator/">DirBuster Dictionary Populator</a> &#8211; 0&#215;0lab.org<br />
Dirbuster and dirb are in the toolset of all web application security fans.</li>
<li><a href="http://dirb.sourceforge.net/">DIRB</a> &#8211; dirb.sourceforge.net<br />
DIRB is a tool for automating the search of (normally hidden) web applications.</li>
<li><a href="http://www.rapid7.com/contact/metasploit-express-contact.jsp">Try Metasploit Express Edition</a> &#8211; rapid7.com<br />
Metasploit Express Edition was specifically designed for penetration testers and security professionals, addressing many of the key limitations of the existing market.</li>
<li><a href="http://www.darknet.org.uk/2010/06/knock-v1-3b-subdomain-enumerationbrute-forcing-tool/">Knock v1.3b – Subdomain Enumeration/Brute-Forcing Tool</a> &#8211; darknet.org.uk<br />
Knock is a python script designed to enumerate sub-domains on a target domain through a wordlist.</li>
<li><a href="http://arpon.sourceforge.net/">ArpON 2.0 released!</a> &#8211; arpon.sourceforge.net<br />
ArpON (Arp handler inspectiON) is a portable handler daemon that make Arp secure in order to avoid Arp Spoofing/Poisoning &amp; co.</li>
<li><a href="http://www.wireshark.org/news/20100609.html">Wireshark 1.2.9, 1.0.14, and 1.4.0rc1 Released</a> &#8211; wireshark.org<br />
Installers for Windows, Mac OS X 10.5.5 and above (Intel and PPC), and source code are now available.</li>
<li><a href="http://www.darknet.org.uk/2010/06/samurai-web-testing-framework-v0-8-released-pen-testing-security-livecd/">Samurai Web Testing Framework v0.8 Released – Pen Testing Security LiveCD</a> &#8211; darknet.org.uk<br />
This is quite a major release with the integration of metasploit, target applications and tons of tool updates.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://www.offensive-security.com/vulndev/evocam-remote-buffer-overflow-on-osx/">Evocam Remote Buffer Overflow on OSX</a> &#8211; offensive-security.com<br />
After discovering a buffer overflow vulnerability in EvoCam, a WebCam application on OS X, I thought it would be a good idea to try and develop an exploit for it.</li>
<li><a href="http://blog.0x0lab.org/2010/06/bypassing-safari-5-xss-auditor/">Bypassing Safari 5 XSS Auditor</a> &#8211; 0&#215;0lab.org<br />
It took me just under a couple of minutes to discover that the following bypassed the filter just fine.</li>
<li><a href="http://www.thespanner.co.uk/2010/06/09/can-all-mozilla-people-look-away-now-please/">Can All Mozilla People Look Away Now Please</a> &#8211; thespanner.co.uk<br />
Custom setters syntax are being removed from Firefox in the next version.</li>
<li><a href="http://www.sensepost.com/blog/4798.html">SensePost Corporate Threat(Risk) Modeler</a> &#8211; sensepost.com<br />
The original principle behind the tool, first released in 2007 at CSI NetSec, was to throw out existing threat modeling techniques and start from scratch.</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://www.f-secure.com/weblog/archives/00001963.html">Exploit.PDF-Dropper.Gen</a> &#8211; f-secure.com<br />
Our telemetry indicates that several thousand customers have already been exposed to the exploit.</li>
<li>June security bulletins<br />
Three have a maximum severity rating of Critical and seven have a maximum severity rating of Important.</p>
<ul>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/06/08/assessing-the-risk-of-the-june-security-bulletins.aspx">Assessing the risk of the June Security Bulletins</a> &#8211; technet.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-june-2010">Microsoft Patch Tuesday &#8211; June 2010</a> &#8211; symantec.com</li>
<li><a href="http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx">June 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-032 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-033 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-034 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-035 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-036 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-037.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-037 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-038 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-039 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-040.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-040 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx?pubDate=2010-06-08">Microsoft Security Bulletin MS10-041 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/06/08/ms10-032-vulnerabilities-in-windows-kernel-mode-drivers-could-allow-elevation-of-privilege.aspx">MS10-032: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/06/08/ms10-035-cross-domain-information-disclosure-vulnerability.aspx">MS10-035: Cross-Domain Information Disclosure Vulnerability</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/06/08/ms10-041-xml-signature-hmac-truncation-bypass-vulnerability.aspx">MS10-041: XML Signature HMAC Truncation Bypass Vulnerability</a> &#8211; technet.com</li>
</ul>
</li>
<li>Adobe Zero-Day in the Wild<br />
We have received notification that a proof of concept (POC) has been found in malware taken from the wild and is currently being exploited.</p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=8932">Adobe POC in the Wild</a> &#8211; sans.edu</li>
<li><a href="http://www.symantec.com/connect/de/blogs/analysis-zero-day-exploit-adobe-flash-and-reader">Analysis of a Zero-day Exploit for Adobe Flash and Reader</a> &#8211; symantec.com</li>
<li><a href="http://blog.fortinet.com/flash-player-vmware-vulnerability/">Flash Player + VMware = Vulnerability</a> &#8211; fortinet.com</li>
</ul>
</li>
<li>The Help Center Vulnerability<br />
The vulnerability allows bypassing checks normally performed when helpctr.exe receives the &#8220;-FromHCP&#8221; command-line parameter when opening an HCP URI.</p>
<ul>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspx">Help and Support Center vulnerability full-disclosure posting</a> &#8211; technet.com</li>
<li><a href="http://www.zdnet.com/blog/security/googler-releases-windows-zero-day-exploit-microsoft-unimpressed/6659">Googler releases Windows zero-day exploit, Microsoft unimpressed</a> &#8211; zdnet.com</li>
<li><a href="http://secunia.com/blog/103/">Microsoft Windows helpctr.exe Unofficial Hotfix Inadequate</a> &#8211; secunia.com</li>
<li><a href="http://ha.ckers.org/blog/20100610/windows-help-centre-vuln/">Windows Help Centre Vuln</a> &#8211; ha.ckers.org</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/mass-sql-injection-attack-hits-sites-running-iis-061010">Mass SQL Injection Attack Hits Sites Running IIS</a> &#8211; threatpost.com<br />
There&#8217;s a large-scale attack underway that is targeting Web servers running Microsoft&#8217;s IIS software, injecting the sites with a specific malicious script.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=225500033">Microsoft Patches IE Flaw Used In Attack That Bypassed Its Built-In Security Controls</a> &#8211; darkreading.com<br />
Winning &#8216;Pwn2Own&#8217; flaw was memory corruption bug, its patch among 10 released by Microsoft today.</li>
<li>New Adobe Flash Version Plus Security Holes<br />
As promised, Adobe has released a new version of its Flash Player software to fix a critical security flaw that hackers have been exploiting to break into vulnerable systems.</p>
<ul>
<li><a href="http://blogs.adobe.com/psirt/2010/06/security_bulletin_-_adobe_flas_3.html">Security Bulletin &#8211; Adobe Flash Player</a> &#8211; adobe.com</li>
</ul>
<ul>
<li><a href="http://gizmodo.com/5560354/adobe-flash-player-101-finalized-you-can-download-now">Adobe Flash Player 10.1 Finalized, You Can Download Now</a> &#8211; gizmodo.com</li>
<li><a href="http://krebsonsecurity.com/2010/06/adobe-flash-update-plugs-32-security-holes/">Adobe Flash Update Plugs 32 Security Holes</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>Military officer arrested in light of Wikileaks whistle blowing<br />
High-profile hacker Adrian Limo turned over SPC Brad Manning after the latter allegedly delivered classified US military document to Wikileaks.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2010/06/leak/">U.S. Intelligence Analyst Arrested in Wikileaks Video Probe</a> &#8211; wired.com</li>
<li><a href="http://news.bbc.co.uk/2/hi/technology/10255887.stm">Hacker explains why he reported &#8216;Wikileaks source&#8217;</a> &#8211; bbc.co.uk</li>
<li><a href="http://www.wired.com/threatlevel/2010/06/wikileaks-chat/">‘I Can’t Believe What I’m Confessing to You’: The Wikileaks Chats</a> &#8211; wired.com</li>
<li><a href="http://www.wired.com/threatlevel/2010/06/conscience/">Suspected Wikileaks Source Described Crisis of Conscience Leading to Leaks</a> &#8211; wired.com</li>
</ul>
</li>
<li>Big breach exposes email addresses of A-list iPad users<br />
A security breach has exposed iPad owners including dozens of CEOs, military officials, and top politicians.</p>
<ul>
<li><a href="http://gawker.com/5559346/apples-worst-security-breach-114000-ipad-owners-exposed">Apple&#8217;s Worst Security Breach: 114,000 iPad Owners Exposed</a> &#8211; gawker.com</li>
<li><a href="http://blog.laptopmag.com/ipad-owners-email-addresses-harvested">Over 114 Thousand 3G iPad Owners’ Email Addresses Harvested – Is Spam The Worst Consequence For Users?</a> &#8211; laptopmag.com</li>
</ul>
</li>
<li><a href="http://www.schneier.com/blog/archives/2010/06/hiring_hackers.html">Hiring Hackers</a> &#8211; schneier.com<br />
Would you hire someone convicted of a computer crime to fill a position of trust in your computer network?</li>
<li><a href="http://www.theaustralian.com.au/australian-it/certs-role-still-unclear-government-owned-and-operated-national-cert/story-e6frgakx-1225867906806">CERT&#8217;s role still unclear: government-owned and operated national CERT</a> &#8211; theaustralian.com.au<br />
Defence Minister John Faulkner launched CERT Australia in January, with the opening of a Cyber Security Operations Centre in the Defence Signals Directorate.</li>
<li><a href="http://www.theregister.co.uk/2010/06/10/drupal_security_changes/">Drupal clarifies security rules after White-House gaper</a> &#8211; theregister.co.uk<br />
Webmasters running unfinished modules for Drupal do so at their own risk after the open-source CMS updated its guidelines on fixing security vulnerabilities.</li>
<li><a href="http://ha.ckers.org/blog/20100610/fierce-20-to-be-released/">Fierce 2.0 To Be Released</a> &#8211; ha.ckers.org<br />
Jabra completely re-wrote Fierce, taking in my wish-list and a whole new set of features he wanted, like XML support to quickly integrate with nmap and all kinds of other stuff.</li>
<li><a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225600304">Tool Automates Social Engineering In Man-In-The-Middle Attack</a> &#8211; darkreading.com<br />
Researchers demonstrate attack that dupes victims in online chats.</li>
<li><a href="http://www.h-online.com/security/news/item/IRC-server-had-backdoor-in-source-code-for-months-Update-1020987.html">IRC server had backdoor in source code for months &#8211; Update</a> &#8211; h-online.com<br />
The backdoor allows anyone to execute commands on the server running UnrealIRCd, with the privileges of the user running the IRC daemon, even if the IRC server is a hub or requires passwords to access it normally.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1087&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/06/14/week-23-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 22 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/06/06/week-22-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/06/06/week-22-in-review-2010/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 06:50:21 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[FROC]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1085</guid>
		<description><![CDATA[


Events Related:

Front Range OWASP Conference 2010 &#8211; owasp.org
The official wiki/site of the FROC 2010 


Resources:

The History of Hacking &#8211; onlinemba.com
Hacking has been around as long as computers as a way to reconfigure or reprogram a system to give access to someone who otherwise shouldn’t have access. 


Tools:

Released Buster Sandbox Analyzer 1.23 &#8211; offensivecomputing.net 
Version 1.23 introduces the automatic [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010">Front Range OWASP Conference 2010</a> &#8211; owasp.org<br />
The official wiki/site of the FROC 2010 </li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.onlinemba.com/blog/the-history-of-hacking/">The History of Hacking</a> &#8211; onlinemba.com<br />
Hacking has been around as long as computers as a way to reconfigure or reprogram a system to give access to someone who otherwise shouldn’t have access. </li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.offensivecomputing.net/?q=node/1577">Released Buster Sandbox Analyzer 1.23</a> &#8211; offensivecomputing.net <br />
Version 1.23 introduces the automatic malware analysis mode.</li>
<li><a href="http://www.ollydbg.de/version2.html">OllyDbg 2.0</a> &#8211; ollydbg.de<br />
This time, I have missed a crash in the popup menu of the breakpoint window.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://research.zscaler.com/2010/06/infected-javascript-file.html">Infected Javascript file</a> &#8211; zscaler.com<br />
We recently found the following malicious code appended to a static Javascript file on an Indian Telecom website.</li>
<li><a href="http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/">web application firewall bypass with a XSS attack</a> &#8211; acunetix.com<br />
In the following demo video, Sandro Gauci of EnableSecurity shows how an attacker can switch off dotDefender in order to bypass any “protection” offered by the WAF.  </li>
<li><a href="http://blogs.sans.org/computer-forensics/2010/06/04/wmic-draft/">WMIC for incident response</a> &#8211; sans.org<br />
 I mentioned at the end of that post that I’ve been using WMIC in place of psexec and that I’d have more on that later.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=8896">Top 10 Things you may not know about tcpdump</a> &#8211; sans.edu<br />
What are the things you may not know about tcpdump? Here are some of the favorite items I ran into and please fill free to submit more.</li>
<li><a href="http://www.room362.com/blog/2010/6/2/av-bypass-made-stupid.html">AV Bypass Made Stupid</a> &#8211; room362.com<br />
I started with fgdump, a well known hashdumping/pwdump tool. It’s detected by 80% of all AVs and by all the top 10.</li>
<li><a href="http://www.l1pht.com/2010/06/culling-files-while-riding-spiders/">pigtoddler.py – Culling Files By Riding Spiders</a> &#8211; l1pht.com<br />
I wanted a troubled little script that didn’t require much care and had a little more “dice roll” type attitude. </li>
<li><a href="http://blog.clearnetsec.com/2010/06/04/pro-tip-get-lucky-by-scanning-for-192-168-20-1">pro tip: get lucky by scanning for 192.168.20.1</a> &#8211; clearnetsec.com<br />
ut as I just witnessed at a client, none of their historical vulnerability scan results discovered the cards because this client doesn’t use that IP block, yet several Dell servers had default DRAC cards waiting for some love. <br />
 </li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>About the Adobe Zero-Day<br />
A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. </p>
<ul>
<li><a href="http://www.adobe.com/support/security/advisories/apsa10-01.html">Security Advisory for Flash Player, Adobe Reader and Acrobat</a> - adobe.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/0-day-attack-wild-adobe-flash-reader-and-acrobat">0-Day Attack in the Wild for Adobe Flash, Reader, and Acrobat</a> &#8211; symantec.com</li>
</ul>
</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx">Microsoft Security Bulletin Advance Notification for June 2010</a> &#8211; microsoft.com<br />
Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. </li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=225200733">House OKs Cybersecurity Reforms</a> - darkreading.com<br />
Bill calls for creation of a permanent National Office for Cyberspace and Office of the Federal Chief Technology Officer within the White House.<a href="http://www.wired.com/threatlevel/2010/06/wikileaks-documents/"></a></li>
<li><a href="http://www.wired.com/threatlevel/2010/06/wikileaks-documents/">WikiLeaks Was Launched With Documents Intercepted From Tor</a> - wired.com<br />
WikiLeaks bootstrapped itself with a cache of documents obtained through an internet eavesdropping operation by one of its activists, according to a new profile of the organization’s founder. </li>
<li><a href="http://www.readwriteweb.com/enterprise/2010/05/massive-iphone-security-issue-could-endanger-enterprise-adoption.php">Massive iPhone Security Issue Could Endanger Enterprise Adoption</a> &#8211; readwriteweb.com <br />
This flaw was discovered by Bernd Marienfeld, an information security professional and blogger, last week.</li>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/05/31/viral-clickjacking-like-worm-hits-facebook-users/">Viral clickjacking &#8216;Like&#8217; worm hits Facebook users</a> &#8211; sophos.com<br />
Hundreds of thousands of Facebook users have fallen for a social-engineering trick which allowed a clickjacking worm to spread quickly over Facebook this holiday weekend.</li>
<li><a href="http://blog.absolute.com/tabnapping-new-phishing-attack/">Tabnapping: New Phishing Attack</a> &#8211; absolute.com<br />
The content of the original tab is changed to a fake site, most often a login screen to a common site like Facebook or Gmail.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/06/microsoft-security-is-good-enough-and.html">Microsoft security IS “good enough” and that’s the problem</a> &#8211; jeremiahgrossman.blogspot.com<br />
No shortage of vulnerabilities resulting in widespread and devastating compromises with patches unpredictable and long in coming.</li>
<li><a href="http://www.developer.com/features/article.php/3885946/PHP-Remains-Strong-Despite-Security-Flaws.htm">PHP Remains Strong Despite Security Flaws</a> &#8211; developer.com<br />
But even after so many identified security issues in MOPS, PHP experts argue that the language is not necessarily insecure. </li>
<li><a href="http://krebsonsecurity.com/2010/06/atm-skimmers-separating-cruft-from-craft/">ATM Skimmers: Separating Cruft from Craft</a> &#8211; krebsonsecurity.com<br />
The truth is that most of these skimmers openly advertised are little more than scams designed to separate clueless crooks from their ill-gotten gains.</li>
<li><a href="http://www.thetruthaboutcars.com/nhtsas-complaint-database-leaks-private-information-like-a-sieve/">NHTSA’s Complaint Database Leaks Private Information Like A Sieve</a> &#8211; thetruthaboutcars.com<br />
Our Canadian pal carquestions took a look through NHTSA’s public complaint database, and found four examples of personal information that NHTSA should have redacted but didn’t.</li>
</ul>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1085&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/06/06/week-22-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Week 19 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/05/16/week-19-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/05/16/week-19-in-review-2010/#comments</comments>
		<pubDate>Mon, 17 May 2010 06:26:55 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1054</guid>
		<description><![CDATA[Resources:

Two Thumbs Up For These Security Podcasts &#8211; matthewneely.com
I am going to discuss the security podcasts I listen to, with a short description of each one.
&#8220;Useable&#8221; CVE Security Vulnerability Data &#8211; cvedetails.com
his is an effort to provide an easy to use web interface to CVE vulnerability information.
Gary McGraw on BSIMM2, Software Security and Cargo Cult [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.matthewneely.com/blog/2010/5/9/two-thumbs-up-for-these-security-podcasts.html">Two Thumbs Up For These Security Podcasts</a> &#8211; matthewneely.com<br />
I am going to discuss the security podcasts I listen to, with a short description of each one.</li>
<li><a href="http://www.cvedetails.com/">&#8220;Useable&#8221; CVE Security Vulnerability Data</a> &#8211; cvedetails.com<br />
his is an effort to provide an easy to use web interface to CVE vulnerability information.</li>
<li><a href="http://threatpost.com/en_us/blogs/gary-mcgraw-bsimm2-software-security-and-cargo-cult-science-051210">Gary McGraw on BSIMM2, Software Security and Cargo Cult Science</a> &#8211; threatpost.com<br />
Dennis Fisher talks with Gary McGraw of Cigital about the release of the BSIMM2 model.</li>
<li><a href="http://www.cigital.com/justiceleague/2010/05/12/bsimm2/">BSIMM2</a> &#8211; cigital.com<br />
We’re pleased today to announce the publication of BSIMM2.</li>
<li><a href="http://www.irongeek.com/i.php?page=videos/metasploit-class">Metasploit Class Videos</a> &#8211; irongeek.com<br />
The instructors were David &#8220;ReL1K&#8221; Kennedy, Martin &#8220;PureHate&#8221; Bos, Elliott &#8220;Nullthreat&#8221; Cutright, Pwrcycle and Adrian &#8220;Irongeek&#8221; Crenshaw.</li>
<li><a href="http://hakin9.org/magazine/1057-flash-memory-mobile-forensic">Hakin9 Magazine is now FREE &#8212; Get your copy NOW!</a> &#8211; hakin9.org<br />
Download May issue of Hakin9 magazine today!</li>
</ul>
<div>
<p><strong>Tools<br />
</strong></p>
<ul>
<li><a href="http://iscanner.isecur1ty.org/download/iscanner.tar.gz">iScanner v0.5</a> &#8211; iscanner.isecur1ty.org<br />
iScanner is free open source tool lets you detect and remove malicious codes and web pages viruses from your Linux/Unix server easily and automatically.</li>
<li><a href="http://pythonpaste.org/webtest/">WebTest 1.2.1</a> &#8211; pythonpaste.org/webtest/<br />
WebTest helps you test your WSGI-based web applications.</li>
<li><a href="http://www.skullsecurity.org/blog/?p=779">Metasploit Express Beta &#8211; First Look</a> &#8211; skullsecurity.org<br />
This is just initial impressions of a beta product.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://carnal0wnage.attackresearch.com/node/420">Playing with the MS09-012 Windows Local Exploit</a> &#8211; carnal0wnage.attackresearch.com<br />
The gist is you an run the Churrasco binary and it will execute a command for you as SYSTEM from NETWORK SERVICE.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/421">Using the Metasploit PHP Remote File Include Module</a> &#8211; carnal0wnage.attackresearch.com<br />
Metasploit has a nifty PHP Remote File Include module that allows you to get a command shell from a RFI.</li>
<li><a href="http://www.mcgrewsecurity.com/2010/05/10/live-hacking-cd-vs-backtrack-4/">Live Hacking CD vs. Backtrack 4</a> &#8211; mcgrewsecurity.com<br />
Dr. Ali Jahangiri made claims that “Live Hacking CD is much easier than BackTrack and its tools are updated”</li>
<li><span style="font-size: 13.1944px"><a href="http://ddanchev.blogspot.com/2010/05/dissecting-mass-dreamhost-sites.html">Dissecting the Mass DreamHost Sites Compromise</a> &#8211; ddanchev.blogspot.com<br />
What&#8217;s particularly interesting about the campaign, is not just the Hilary Kneber connection, but also, the fact that a key command and control domain part of the Koobface botnet, is residing within the same AS where the nameservers. ]</span></li>
<li><span style="font-size: 13.1944px"><a href="http://www.f-secure.com/weblog/archives/00001950.html">Targeted Attack Using Journalists as a Lure</a> &#8211; f-secure.com<br />
We found a new malicious XLS file which contains lots of names, details and contact information for journalists around the world. </span></li>
<li><span style="font-size: 13.1944px"><a href="http://reusablesec.blogspot.com/2010/05/theyll-let-anyone-graduate-dissertation.html">They&#8217;ll Let Anyone Graduate: My Password Cracking Dissertation</a> &#8211; reusablesec.blogspot.com<br />
A lot of it is going to look fairly familiar if you&#8217;ve seen my talks or been reading this blog, which makes sense since my dissertation is a summary of what I&#8217;ve been up to for the last three years. </span></li>
<li><span style="font-size: 13.1944px"><a href="http://www.attackvector.org/?p=207">Network Discovery via DHCP using Python &amp; Scapy</a> &#8211; attackvector.org<br />
It sends a DHCP Discover packet out to the network and sniffs, listening for a response. </span></li>
<li><span style="font-size: 13.1944px"><a href="https://www.securepla.net/?p=314">Fuzzing 101 With Sulley</a> &#8211; securepla.net<br />
Sully is a great tool to find bugs and overflows in applications that could allow for remote exploitation. </span></li>
</ul>
</div>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Microsoft&#8217;s May round of patches<br />
Microsoft issued two critical bulletins on Tuesday fixing holes in its e-mail programs and the Visual Basic for Applications programming language implementation built into Office.</p>
<ul>
<li><a href="http://blogs.technet.com/msrc/archive/2010/05/11/may-2010-security-bulletin-release.aspx">May 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/05/11/ms10-030-malicious-mail-server-vulnerability.aspx">MS10-030: Malicious Mail server vulnerability</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/05/11/ms10-031-vbe6-single-byte-stack-overwrite.aspx">MS10-031: VBE6 Single-Byte Stack Overwrite</a> &#8211; technet.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-may-2010">Microsoft Patch Tuesday &#8211; May 2010</a> &#8211; symantec.com</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8776">May 2010 Microsoft Patches</a> &#8211; sans.org</li>
<li><a href="http://news.cnet.com/8301-27080_3-20004694-245.html">Microsoft releases critical fixes for Windows, Office holes</a> &#8211; cnet.com</li>
</ul>
</li>
<li><a href="http://www.h-online.com/security/news/item/XSS-vulnerability-fixed-in-Drupal-module-Update-998101.html">XSS vulnerability fixed in Drupal module &#8211; Update</a> &#8211; h-online.com<br />
The development team behind the Drupal module Context have released version 6.x-2.0-rc4, which fixes a cross-site scripting (XSS) vulnerability when displaying block descriptions.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://indiaevm.org/">India&#8217;s EVMs are Vulnerable to Fraud</a> &#8211; indiaevm.org<br />
This site presents an independent scientific study about the security of the electronic voting machines (EVMs) used in India.</li>
<li>Yet more news on the WordPress attack<br />
We have also received reports that this not only affected WordPress installations, but Joomla and other php-based platforms.</p>
<ul>
<li><a href="http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-holasionweb-on-go-daddy/">Breaking News: WordPress Hacked with holasionweb on Go Daddy!</a> &#8211; wpsecuritylock.com</li>
<li><span style="font-size: 13.1944px"><a href="http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html">Large-scale attack on WordPress</a> &#8211; h-online.com</span></li>
<li><span style="font-size: 13.1944px"><a href="http://blog.sucuri.net/2010/05/lots-of-sites-reinfected-now-using.html">Lots of sites reinfected &#8211; Now using holasionweb.com</a> &#8211; sucuri.net</span></li>
<li><span style="font-size: 13.1944px"><a href="http://blog.sucuri.net/2010/05/found-code-used-to-inject-malware-at.html">Found code used to inject the malware at GoDaddy</a> &#8211; sucuri.net</span></li>
</ul>
</li>
<li><a href="http://www.wired.com/threatlevel/2010/05/watt-reports-to-prison/">Coder Journeys From Wall Street to Prison</a> &#8211; wired.com<br />
Stephen Watt, 26, wrote a custom packet-sniffing program dubbed “blabla” for Gonzalez, as a favor for his best friend.</li>
<li><a href="http://www.engadget.com/2010/05/10/meganets-dominator-i-snoops-on-four-gsm-convos-at-once-fits-in/">Meganet&#8217;s Dominator I snoops on four GSM convos at once, fits in your overnight bag</a> &#8211; engadget.com<br />
The system consists of two nondescript white boxes, two directional antennas and a laptop to get a glimpse at all of the phones currently connected to your nearest cell site and record up to four active calls simultaneously.</li>
<li>Superexploit claims to pass through AVs, uses old bait-and-switch technique<br />
Researchers say they&#8217;ve devised a way to bypass protections built in to dozens of the most popular desktop anti-virus products, including those offered by McAfee, Trend Micro, AVG, and BitDefender.</p>
<ul>
<li><a href="http://www.theregister.co.uk/2010/05/07/argument_switch_av_bypass/">New attack bypasses virtually all AV protection</a> &#8211; theregister.co.uk</li>
<li><a href="http://www.zdnet.com/blog/hardware/update-new-attack-bypasses-every-windows-security-product/8268">New attack bypasses EVERY Windows security product</a> &#8211; zdnet.com</li>
<li><a href="http://www.h-online.com/security/news/item/New-attack-bypasses-anti-virus-software-997621.html">New attack bypasses anti-virus software</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://lifehacker.com/5536466/plug+in-check-identifies-vulnerable-or-out+of+date-plug+ins-in-all-browsers">Plug-In Check Identifies Vulnerable or Out-of-Date Plug-Ins in All Browsers</a> &#8211; lifehacker.com<br />
The Plug-In Check tool gives users a quick, simple way to determine if they&#8217;re running vulnerable or out-of-date plug-ins.</li>
<li><a href="http://krebsonsecurity.com/2010/05/fbi-promises-action-against-money-mules/">FBI Promises Action Against Money Mules</a> &#8211; krebsonsecurity.com<br />
Patrick Carney, acting chief of the FBI’s cyber criminal section, said mules are an integral component of an international crime wave that is costing U.S. banks and companies hundreds of millions of dollars.</li>
<li><a href="http://www.computerworld.com/s/article/9176573/Update_Senate_confirms_Alexander_as_chief_of_U.S._Cyber_Command">Update: Senate confirms Alexander as chief of U.S. Cyber Command</a> &#8211; computerworld.com<br />
In his new role, Alexander will be responsible for directing operations of the U.S. Department of Defense&#8217;s military information networks.</li>
<li><a href="http://techcrunch.com/2010/05/11/another-security-hole-found-on-yelp-facebook-data-once-again-put-at-risk/">Another Security Hole Found On Yelp, Facebook Data Once Again Put At Risk</a> &#8211; techcrunch.com<br />
The exploit used a technique called Cross Site Scripting (XSS) to inject malicious code into Yelp, and took advantage of the controversial Instant Personalization feature to harvest the Facebook user data.</li>
<li><a href="http://www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html">Facebook Privacy: A Bewildering Tangle of Options</a> &#8211; nytimes.com<br />
Facebook&#8217;s 2010 privacy policy is longer than other social networks, even exceeding the United States Constitution without its amendments.</li>
<li><a href="http://arstechnica.com/gaming/news/2010/05/how-removing-ps3-linux-hurts-the-air-force.ars">Air Force may suffer collateral damage from PS3 firmware update</a> &#8211; arstechnica.com<br />
When Sony issued a recent PlayStation 3 update removing the device&#8217;s ability to install alternate operating systems like Linux, it did so to protect copyrighted content—but several research projects suffered collateral damage.</li>
<li><a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/news/2010/051410-car-hackers-can-kill-brakes.html&amp;pageurl=http://www.networkworld.com/news/2010/051410-car-hackers-can-kill-brakes.html&amp;site=printpage">Car hackers can kill brakes, engine, and more</a> &#8211; networkworld.com<br />
University researchers have taken a close look at the computer systems used to run today&#8217;s cars and discovered new ways to hack into them, sometimes with frightening results.</li>
<li><a href="http://arstechnica.com/security/news/2010/05/phishing-servers-being-killed-off-faster-than-ever.ars">Phishing servers being killed off faster than ever</a> &#8211; arstechnica.com<br />
Most phishing attacks appear to originate from Eastern Europe, with one organization responsible for about two thirds of all attacks.</li>
</ul>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1054&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/05/16/week-19-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 18 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/05/10/week-18-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/05/10/week-18-in-review-2010/#comments</comments>
		<pubDate>Mon, 10 May 2010 11:18:52 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[SOURCE Boston]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1050</guid>
		<description><![CDATA[Events Related:

SOURCE Boston Re-Cap &#8211; tenablesecurity.com
The SOURCE conferences, founded by Stacy Thayer, are small in size but big on content.

Resources:

Google&#8217;s cheesy web app course
Google has released a new online training course for Web application developers designed to teach them how to avoid common programming mistakes

Web Application Exploits and Defenses &#8211; jarlsberg.appspot.com
Google Releases Web App Security [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.tenablesecurity.com/2010/05/source-boston-re-cap.html">SOURCE Boston Re-Cap</a> &#8211; tenablesecurity.com<br />
The SOURCE conferences, founded by Stacy Thayer, are small in size but big on content.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li>Google&#8217;s cheesy web app course<br />
Google has released a new online training course for Web application developers designed to teach them how to avoid common programming mistakes</p>
<ul>
<li><a href="http://jarlsberg.appspot.com/">Web Application Exploits and Defenses</a> &#8211; jarlsberg.appspot.com</li>
<li><a href="http://threatpost.com/en_us/blogs/google-releases-web-app-security-course-050410">Google Releases Web App Security Course</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/didier-stevens-pdf-hacking-and-security-050410">Didier Stevens on PDF Hacking and Security</a> &#8211; threatpost.com<br />
Dennis Fisher talks with Didier Stevens, the security researcher who developed the innovative method for using the /launch command in PDF readers to execute code on remote machines.</li>
<li><a href="http://chuvakin.blogspot.com/2010/05/my-best-pci-dss-presentation-ever.html">My Best PCI DSS Presentation EVER!</a> &#8211; chuvakin.blogspot.com<br />
Addressing an audience of about 130 mostly University IT, IT security and finance (!) professionals in charge of their payment and PCI DSS programs was a fun challenge.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.securityaegis.com/netsparker-community-edition-%E2%80%93-%E2%80%9Cthe-sparkler%E2%80%9D/">Netsparker Community Edition – “The Sparkler”</a> &#8211; securityaegis.com<br />
Netsparker announced today that it is releasing a community edition, lacking only a few features of the pro version.</li>
<li><a href="http://www.wireshark.org/news/20100505.html">Wireshark 1.2.8, 1.0.13, and 1.3.5 Released</a> &#8211; wireshark.org<br />
The new versions pack in the usual security fixes and a fix for the DOCSIS and interface bugs.</li>
<li><a href="http://code.google.com/p/fuu/">FUU v0.1</a> &#8211; code.google.com/p/fuu/<br />
FUU (Faster Universal Unpacker) is a GUI Windows Tool with a set of tools (plugins) to help you to unpack, decompress and decrypt most of the programs packed with programs like UPX, ASPack, FSG, ACProtect, etc.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li>Why Buffer Overflow Exploitation Took So Long to Mature, a two-part series<br />
Executing code via a buffer overflow was published at least as early as 1972.</p>
<ul>
<li><a href="http://rdist.root.org/2010/05/03/why-buffer-overflow-exploitation-took-so-long-to-mature/">Why buffer overflow exploitation took so long to mature</a> &#8211; root.org</li>
<li><a href="http://rdist.root.org/2010/05/05/why-buffer-overflow-exploitation-took-so-long-to-mature-part-2/">Why buffer overflow exploitation took so long to mature (part 2)</a> &#8211; root.org</li>
</ul>
</li>
<li><a href="http://pandalabs.pandasecurity.com/bad-%E2%80%9Cvisual%E2%80%9D-pdf/">Bad “Visual” PDF</a> &#8211; pandasecurity.com<br />
Last week a PDF document which downloaded malware fell into my hands.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/417">More with Metasploit and WebDAV</a> &#8211; carnal0wnage.attackresearch.com<br />
You&#8217;ll want to make sure you pay attention to the part about allowing your IUSR_WHATEVER account to have have write access or you can set up a windows account to use authentication.</li>
<li><a href="http://blog.didierstevens.com/2010/05/04/writing-win32-shellcode-with-a-c-compiler/">Writing WIN32 Shellcode With a C-compiler</a> &#8211; didierstevens.com<br />
The advantage of my method is that you can debug your shellcode inside the Visual Studio IDE.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/418">Metasploit Lotus Domino Version Scanner</a> &#8211; carnal0wnage.attackresearch.com<br />
I pushed out the first of a few Lotus Domino modules I&#8217;ve been working on to the metasploit trunk last nite [sic].</li>
<li><a href="http://www.lovemytool.com/blog/2010/05/wireshark-and-tshark-decrypt-sample-capture-file-by-joke-snelders.html">Wireshark and TShark: Decrypt Sample Capture File (by Joke Snelders)</a> &#8211; lovemytool.com<br />
In this article I will describe how you can decrypt packets in a sample capture file.</li>
<li><a href="http://blog.fortinet.com/0day-or-not-today-exploit-in-the-wild/">0day or not today: exploit in the wild</a> &#8211; fortinet.com<br />
In this post I will dissect a PDF document using this trick, indeed found in the wild.</li>
<li><a href="http://cktricky.blogspot.com/2010/05/android-ssl-apps-burp.html">Android SSL Apps &amp; Burp</a> &#8211; cktricky.blogspot.com<br />
The app refused to communicate with Burp because of the certificate mismatch error.</li>
<li><a href="http://www.sans.org/reading_room/whitepapers/testing/identifying-load-balancers-penetration-testing_33313">&#8220;Identifying Load Balancers in Penetration Testing&#8221; &#8211; whitepaper</a> &#8211; sans.org<br />
Here is a good whitepaper on load balancers and how to deal with them while doing penetration testing.</li>
<li><a href="http://www.room362.com/blog/2010/5/7/0exploit-privilege-escalation.html">0exploit Privilege Escalation</a> &#8211; room362.com<br />
This user has Read and Execute, but no Write access, and a very limited field of view to boot.</li>
<li><a href="http://www.nullthreat.net/blog/2010/5/4/fuzzing-and-exploit-development-with-metasploit-louisville-m.html">Fuzzing and Exploit Development With Metasploit &#8211; Louisville Metasploit Class</a> &#8211; nullthreat.net<br />
We start with fuzzing and go through the basic steps of development.</li>
<li><a href="http://www.secmaniac.com/march/generate-an-ntlm-hash-in-3-lines-of-python/">Generate an NTLM hash in 3 lines of Python…</a> &#8211; secmaniac.com<br />
While combing through the RFC and found that writing this was extremely easy.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/419">Metasploit jboss deployment file repository exploit</a> &#8211; carnal0wnage.attackresearch.com<br />
MC pushed out a new exploit today.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.computerworld.com/s/article/9176308/Foxit_Reader_update_blocks_new_PDF_attack_tactic">Foxit Reader update blocks new PDF attack tactic</a> &#8211; computerworld.com<br />
Adobe Reader rival adds &#8217;safe mode&#8217; to stymie embedded-malware attacks.</li>
<li><a href="http://www.computerworld.com/s/article/9176373/Security_firm_reveals_Microsoft_s_silent_patches">Security firm reveals Microsoft&#8217;s &#8217;silent&#8217; patches</a> &#8211; computerworld.com<br />
Microsoft acknowledges fixing internally-found flaws without disclosing details.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>United States Treasury Websites Hacked<br />
The websites involved were bep.gov (Bureau of Engraving and Printing), bep.treas.gov and moneyfactory.gov.</p>
<ul>
<li><a href="http://thompson.blog.avg.com/2010/05/treasury-website-hacked.html">Treasury Website Hacked</a> &#8211; avg.com</li>
<li><a href="http://www.theregister.co.uk/2010/05/03/treasury_websites_attack/">Hacked US Treasury websites serve visitors malware</a> &#8211; theregister.co.uk</li>
<li><a href="http://pandalabs.pandasecurity.com/usa-treasury-website-hacked-using-exploit-kit/">U.S. Treasury Website Hacked Using Exploit Kit</a> &#8211; pandasecurity.com</li>
<li><a href="http://ddanchev.blogspot.com/2010/05/us-treasury-site-compromise-linked-to.html">U.S. Treasury Site Compromise Linked to the NetworkSolutions Mass WordPress Blogs Compromise</a> &#8211; ddanchev.blogspot.com</li>
<li><a href="http://www.eset.com/blog/2010/05/06/godaddy-wordpress-is-china-involved">Malware Injection Campaign: A Retaliation?</a> &#8211; eset.com</li>
</ul>
</li>
<li><a href="http://www.networkworld.com/community/node/60804">Metasploit&#8217;s HD Moore from (almost) rags to (not quite) riches</a> &#8211; networkworld.com<br />
Metasploit might become an example of how a fully FOSS project grows up to turn a profit.</li>
<li><a href="http://www.wired.com/threatlevel/2010/05/thor/">Former Con Man Helps Feds Thwart Alleged ATM Hacking Spree</a> &#8211; wired.com<br />
A North Carolina grocery worker is being held on attempted computer hacking charges after inadvertently partnering with an undercover FBI agent in an alleged citywide ATM-reprogramming caper.</li>
<li><a href="http://www.threatchaos.com/home-mainmenu-1/16-blog/552-cybersecurity-acto-of-2010-is-a-bad-bill">Cybersecurity Act of 2010 is a bad bill</a> &#8211; threatchaos.com<br />
It is time for the security industry to take a close look at this $1.82 billion bill as it contains some pretty drastic measures that are going to be very disruptive, and I believe detrimental.</li>
<li><a href="http://www.networkworld.com/news/2010/050510-wi-fi-key-cracking-kits-sold-in.html?source=nww_rss">Wi-Fi key-cracking kits sold in China mean free Internet</a> &#8211; networkworld.com<br />
Dodgy salesmen in China are making money from long-known weaknesses in a Wi-Fi encryption standard, by selling network key-cracking kits for the average user.</li>
<li><a href="http://www.wpsecuritylock.com/dangerous-malware-alert-hacked-godaddy-responds/">Dangerous Malware Alert &#8211; Self-Hosted Sites Hack Update &#8211; Go Daddy Responds!</a> &#8211; wpsecuritylock.com<br />
We have had reports for not only WordPress installations, but Joomla, Pligg and &#8220;Simple Machines Forum&#8221; as well.</li>
<li><a href="http://news.yahoo.com/s/pcworld/20100506/tc_pcworld/hackerdevelopsmultiplatformrootkitforatms">Hacker Develops Multi-platform Rootkit for ATMs</a> &#8211; yahoo.com<br />
Security researcher Barnaby Jack plans to deliver the talk and disclose a new ATM rootkit at the computer security conference.</li>
<li><a href="http://blogs.bankinfosecurity.com/posts.php?postID=546">The ABC&#8217;s of ACH Fraud</a> &#8211; bankinfosecurity.com<br />
It&#8217;d be foolish to think that ACH fraud will go away after a single symposium.</li>
<li>Losing the desktop security battle<br />
Many organizations, particularly in the financial services industry, have gotten to the point of assuming that their customers&#8217; desktops are compromised.</p>
<ul>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/05/ceding-desktop-security-battle-almost.html">Ceding the desktop security battle, almost the war</a> &#8211; jeremiahgrossman.blogspot.com</li>
<li><a href="http://threatpost.com/en_us/blogs/have-we-lost-desktop-security-battle-050610">Have We Lost the Desktop Security Battle?</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2010/05/fun-with-atm-skimmers-part-iii/">Fun with ATM Skimmers, Part III</a> &#8211; krebsonsecurity.com<br />
According to the European ATM Security Team (EAST), a not-for-profit payment security organization, ATM crimes in Europe jumped 149 percent form 2007 to 2008.</li>
<li>More news on the recent WordPress-related breach<br />
We are seeing multiple reports today of Wordpress sites (running their latest version) getting compromised.</p>
<ul>
<li><a href="http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/">Breaking News: WordPress Hacked with Zettapetta on DreamHost</a> &#8211; wpsecuritylock.com</li>
<li><a href="http://blog.sucuri.net/2010/05/new-attack-today-against-wordpress.html">New attack today against Wordpress</a> &#8211; sucuri.net</li>
<li><a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html">Simple cleanup solution for the latest Wordpress hack</a> &#8211; sucuri.net</li>
<li><a href="http://www.ivonson.com/wordpress/wordpress-hidden-link-injection-fix-webmoviepedia/">Wordpress Hidden Link Injection Fix</a> &#8211; ivonson.com</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/verizon-partners-us-secret-service-data-breach-report-050710">Verizon Partners With U.S. Secret Service on Data Breach Report</a> &#8211; threatpost.com<br />
Verizon&#8217;s invaluable Data Breach Investigations Report will now include data from hundreds of computer crime cases investigated by the U.S. Secret Service, the company announced this week.</li>
<li><a href="http://blog.sucuri.net/2010/05/continuing-attacks-at-network-solutions.html">Continuing attacks at Network Solutions?</a> &#8211; sucuri.net<br />
This morning we started to receive reports of a very similar kind of attack against sites on their shared servers.</li>
<li><a href="http://www.securityninja.co.uk/your-choice-of-programming-language-doesn%E2%80%99t-matter-they-are-all-insecure">Your choice of programming language doesn’t matter, they are all insecure!</a> &#8211; securityninja.co.uk<br />
I believe that secure code is the product of a secure development process and real business commitment to deliver secure applications which includes developer education.</li>
<li><a href="http://www.binint.com/2010/05/facebook-leaks-ip-addresses.html">Facebook Leaks IP Addresses</a> &#8211; binint.com<br />
You will get the IP address of your friend and clicking on it will get a geolocation-based map.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1050&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/05/10/week-18-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 16 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/04/25/week-16-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/04/25/week-16-in-review-2010/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 06:36:40 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[Black Hat Europe]]></category>
		<category><![CDATA[Hack in the Box]]></category>
		<category><![CDATA[HITB]]></category>
		<category><![CDATA[Security BSides]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1003</guid>
		<description><![CDATA[Events Related:

Presentation Materials from HITB Dubai available for Download &#8211; hitb.org
Presentation materials from the 4th annual Hack In The Box Security Conference are now available for download!
Black Hat Europe 2010 Media Archives &#8211; blackhat.com
Presentations, video, papers and other media from this Barcelona event.
Security BSides Boston on Flickr &#8211; flickr.com
Pictures of this security event.

Resources:

OWASP Top 10 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://conference.hitb.org/hitbsecconf2010dxb/materials/">Presentation Materials from HITB Dubai available for Download</a> &#8211; hitb.org<br />
Presentation materials from the 4th annual Hack In The Box Security Conference are now available for download!</li>
<li><a href="http://blackhat.com/html/bh-eu-10/bh-eu-10-archives.html">Black Hat Europe 2010 Media Archives</a> &#8211; blackhat.com<br />
Presentations, video, papers and other media from this Barcelona event.</li>
<li><a href="http://www.flickr.com/photos/jack_daniel/sets/72157623922432966/">Security BSides Boston on Flickr</a> &#8211; flickr.com<br />
Pictures of this security event.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP Top 10 for 2010</a> &#8211; owasp.org<br />
The Open Web Application Security Project (OWASP) today issued the final version of its new Top 10 list of application security risks.</li>
<li><a href="http://blogs.vmware.com/security/2010/04/vsphere-40-hardening-guide-released.html">vSphere 4.0 Hardening Guide Released</a> &#8211; vmware.com<br />
This version incorporates the extensive feedback from the VMware community on the previous draft release.</li>
<li><a href="http://www.schneier.com/blog/archives/2010/04/nist_on_protect.html">NIST on Protecting Personally Identifiable Information</a> &#8211; schneier.com<br />
Just published: Special Publication (SP) 800-122, &#8220;Guide to Protecting the Confidentiality of Personally Identifiable Information (PII).&#8221; </li>
<li><a href="https://www.hackinthebox.org/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=35995&amp;mode=thread&amp;order=0&amp;thold=0">HITB Ezine &#8211; Issue #002</a> &#8211; hackinthebox.org<br />
The people of Hack In the Box, decided to make the ezine available for free in the continued spirit of HITB in “Keeping Knowledge Free”. </li>
<li><a href="http://hakin9.org/newsletter">Hakin9 Magazine now FREE in Digital Format</a> &#8211; hakin9.org<br />
All you need to do in order to get a new issues each month is subscribe to our newsletter. </li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://code.google.com/p/fuzzdb/">Fuzzdb</a> &#8211; code.google.com/p/fuzzdb/<br />
A comprehensive set of fuzzing patterns for discovery and attack during highly targeted brute force testing of web applications.</li>
<li><a href="http://www.appsec.co.il/Managed_Code_Rootkits">ReFrameworker v1.1</a> &#8211; appsec.co.il<br />
ReFrameworker performs the required steps of runtime manipulation by tampering with the binaries containing the framework’s classes.</li>
<li><a href="http://www.syhunt.com/?n=Sandcat.Sandcat">Sandcat v4.0</a> &#8211; syhunt.com<br />
Sandcat allows web administrators to perform aggressive and comprehensive scans of an organization’s web server to isolate vulnerabilities and identify security holes.</li>
<li><a href="http://codecrawler.codeplex.com/releases/view/43887">OWASP Code review Guide v2.7</a> &#8211; codecrawler.codeplex.com<br />
A tool aimed at assisting code review practitioners.</li>
<li><a href="http://www.open-scap.org/">OpenSCAP v0.5.9</a> &#8211; open-scap.org<br />
It is the goal of OpenSCAP to provide a simple, easy to use set of interfaces to serve as the framework for community use of SCAP.</li>
<li><a href="http://www.xplico.org/">Xplico v0.5.6</a> &#8211; xplico.org<br />
Xplico is an open source Network Forensic Analysis Tool (NFAT).</li>
<li><a href="http://www.securityninja.co.uk/security-ninja-security-tool-more-than-a-sneak-preview">Security Ninja security tool, more than a sneak preview!</a> &#8211; securityninja.co.uk<br />
This idea was inspired by the Application Security Portfolios blog post that Nick Coblentz published in 2009.</li>
<li><a href="https://www.gdssecurity.com/l/t/d.php?k=Blazentoo">Blazentoo</a> &#8211; gdssecurity.com<br />
Blazentoo is an Adobe AIR application that can be used to exploit insecure Adobe BlazeDS and LiveCycle Data Services ES servers.</li>
<li><a href="http://skipfish.googlecode.com/files/skipfish-1.33b.tgz">Skipfish v1.33B</a> &#8211; skipfish.googlecode.com<br />
Skipfish is an active web application security reconnaissance tool.</li>
<li><a href="http://sites.google.com/site/sipinspectorsite/download">SIP Inspector</a> &#8211; sites.google.com/site/sipinspectorsite/<br />
SIP Inspector is a tool written in JAVA to simulate different SIP messages and scenarios.</li>
<li><a href="http://www.aircrack-ng.org/downloads.html">Aircrack-ng v1.1</a> &#8211; aircrack-ng.org<br />
It implements the standard FMS attack along with some optimizations like KoreK attacks.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://intrepidusgroup.com/insight/2010/04/pdf-ownage-it-is-getting-ugly-out-there/">PDF Ownage: It is getting ugly out there</a> &#8211; intrepidusgroup.com<br />
he current news is that the Zeus botnet is being used to push a malicious PDF that attempts to abuse /Launch actions.</li>
<li><a href="http://www.skullsecurity.org/blog/?p=433">Stuffing Javascript into DNS names</a> &#8211; skullsecurity.org<br />
If you&#8217;ve installed nbtool, you may have noticed that, among other programs it comes with, one of them is called dnsxss.</li>
<li>Metasploit Express posts<br />
We will be introducing Metasploit Express, an easy to use security solution that is designed to bring penetration testing capabilities to security professionals everywhere.</p>
<ul>
<li><a href="http://blog.metasploit.com/2010/04/approaching-metasploit-340-and.html">Approaching Metasploit 3.4.0 and Metasploit Express</a> &#8211; metasploit.com</li>
<li><a href="http://www.metasploit.com/express/">Metasploit Express</a> &#8211; metasploit.com</li>
</ul>
</li>
<li><a href="http://reusablesec.blogspot.com/2010/04/optimizing-john-rippers-single-mode-for.html">Optimizing John the Ripper&#8217;s &#8220;Single&#8221; Mode for Dictionary Attacks</a> &#8211; reusablesec.blogspot.com<br />
I decided to optimize John the Ripper&#8217;s &#8220;Single&#8221; mode word mangling rules for use in normal dictionary based attacks.</li>
<li><a href="http://labs.snort.org/nrt/">Near Real-Time Detection (NRT)</a> &#8211; labs.snort.org<br />
Today&#8217;s client side attack threats represent a boon for the attacker in ways to obfuscate, evade, and hide their attacks methods.</li>
<li><a href="http://vrt-sourcefire.blogspot.com/2010/04/new-detection-framework.html">A New Detection Framework</a> &#8211; vrt-sourcefire.blogspot.com<br />
I worked on deep parsing and detection on PDF files and Patrick worked on ways to provide me the full file data.</li>
<li><a href="http://www.gdssecurity.com/l/b/2010/04/23/owasp-nynjmetro-pentesting-adobe-flex-applications/">OWASP NYNJMetro – Pentesting Adobe Flex Applications</a> &#8211; gdssecurity.com<br />
I’ve uploaded my slides from the presentation I gave last week at the OWASP NYC Chapter on Pentesting Adobe Flex Applications. </li>
<li><a href="http://blog.fortinet.com/black-hat-presentation-on-abusing-adobe-pdf-reader-memory-management-white-paper-source-code-and-case-study/">Black Hat Presentation: Abusing Adobe PDF Reader memory management</a> &#8211; fortinet.com<br />
The slides include a real-world case study, involving a “former-zero-day” vulnerability (CVE-2010-1241, previously CVE-2010-2000). </li>
<li><a href="http://reusablesec.blogspot.com/2010/04/optimizing-jtrs-single-mode-follow-up.html">Optimizing JtR&#8217;s Single Mode Follow Up</a> &#8211; reusablesec.blogspot.com<br />
One of my concerns though has always been over-training my password cracking techniques.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8686">Manual Verification of SSL/TLS Certificate Trust Chains using Openssl</a> &#8211; sans.org<br />
Firefox 3.6.3 (the latest available version) displayed a digital certificate error when accessing the ISC login page through SSL/TLS. </li>
<li><a href="http://pauldotcom.com/2010/04/using-meterpreter-to-control-n.html">Using Meterpreter to control netcat and third party exploits</a> &#8211; pauldotcom.com<br />
Metasploit has A LOT of exploits, but from time to time you will very likely need to use exploits that are not part of the framework. </li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://blogs.zdnet.com/security/?p=6221">Security gone awry: IE 8 XSS filter exposes sites to XSS attacks</a> &#8211; zdnet.com<br />
The cross-site scripting filter on Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites otherwise be immune to this threat.</li>
<li>McAfee security breach causes chaos for users<br />
McAfee&#8217;s &#8220;DAT&#8221; file version 5958 is causing widespread problems with Windows XP SP3.</p>
<ul>
<li><a href="http://brianseekford.com/index.php/2010/04/21/how-to-fix-the-mcafee-svchost-crash-from-the-virus-definition-update/">How to fix the McAfee SVCHOST crash from the virus definition update</a> &#8211; brianseekford.com</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8656">McAfee DAT 5958 Update Issues</a> &#8211; sans.org</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8671">How McAfee turned a Disaster Exercise Into a REAL Learning Experience&#8230;</a> &#8211; sans.org</li>
<li><a href="http://siblog.mcafee.com/support/a-long-day-at-mcafee/">A Long Day at McAfee</a> &#8211; mcafee.com</li>
</ul>
</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.darknet.org.uk/2010/04/paypal-patches-critical-security-vulnerabilities/">PayPal Patches Critical Security Vulnerabilities</a> &#8211; darknet.org.uk<br />
A security researcher has uncovered multiple vulnerabilities affecting PayPal, the most critical of which could have enabled attackers to access PayPal’s business and premier reports back-end system.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>WebOS hacked thru SMS<br />
Security researchers have hacked into Palm&#8217;s new WebOS platform, using nothing more than text messages to exploit a slew of dangerous web app vulnerabilities.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/palm-pwned-researchers-hack-webos-text-messages-041910">Palm Pwned: Researchers Hack WebOS With Text Messages</a> &#8211; threatpost.com</li>
<li><a href="http://www.neowin.net/news/palm039s-webos-hacked-via-sms-message">Palm&#8217;s WebOS hacked via SMS message</a> &#8211; neowin.net</li>
</ul>
</li>
<li>Network Solutions mass hack attack revealed<br />
Network Solutions&#8217; security team is battling a mysterious attack that has silently infected a &#8220;huge&#8221; number of the websites it hosts with malicious code.</p>
<ul>
<li><a href="http://www.theregister.co.uk/2010/04/19/network_solutions_mass_hack/">Network Solutions customers hit by mass hack attack</a> &#8211; theregister.co.uk</li>
<li><a href="http://stopmalvertising.com/malvertisements/corpadsinccom-redirecting-network-solutions-customers-again">corpadsinc.com redirecting Network Solutions customers again</a> &#8211; stopmalvertising.com</li>
<li><a href="http://www.computerworld.com/s/article/9175783/Network_Solutions_sites_hacked_again">Network Solutions sites hacked again</a> &#8211; computerworld.com</li>
<li><a href="http://blog.networksolutions.com/2010/we-feel-your-pain-and-are-working-hard-to-fix-this/">We feel your pain and are working hard to fix this</a> &#8211; networksolutions.com</li>
<li><a href="http://krebsonsecurity.com/2010/04/network-solutions-again-under-siege/">Network Solutions Again Under Siege</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=224500053">Network Solutions Cleaning Up After Second Round Of Attacks</a> &#8211; darkreading.com</li>
</ul>
</li>
<li>Truth in Caller ID Act posts<br />
The bill aims to prevent misrepresentation of the called-from number on voice calls through any channel.</p>
<ul>
<li><a href="http://www.ecommercetimes.com/story/House-Passes-Bill-Outlawing-Caller-ID-Spoofing-69791.html">House Passes Bill Outlawing Caller-ID Spoofing</a> &#8211; ecommercetimes.com</li>
<li><a href="http://www.pcworld.com/businesscenter/article/194319/caller_id_spoofing_ban_is_bad_for_business.html">Caller ID Spoofing Ban is Bad for Business</a> &#8211; pcworld.com</li>
</ul>
</li>
<li>Follow up stories about the Google hack last December<br />
The program, code named Gaia for the Greek goddess of the earth, was attacked in a lightning raid taking less than two days last December.</p>
<ul>
<li><a href="http://www.nytimes.com/2010/04/20/technology/20google.html">Cyberattack on Google Said to Hit Password System</a> &#8211; nytimes.com</li>
<li><a href="http://news.cnet.com/8301-30684_3-20002315-265.html">Google CEO: &#8216;We&#8217;re now paranoid&#8217; about security</a> &#8211; cnet.com</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2010/04/mozilla-disables-insecure-java-plugin-in-firefox/">Mozilla Disables Insecure Java Plugin in Firefox</a> &#8211; krebsonsecurity.com<br />
Mozilla is disabling older versions of the Java Deployment Toolkit plugin for Firefox users, in a bid to block attacks against a Java security hole.</li>
<li>Second-hand photocopiers might be carrying sensitive information on your company<br />
Nearly every digital copier built since 2002 contains a hard drive &#8211; like the one on your personal computer &#8211; storing an image of every document copied, scanned, or emailed by the machine.</p>
<ul>
<li><a href="http://www.cbsnews.com/stories/2010/04/19/eveningnews/main6412439.shtml">Digital Photocopiers Loaded With Secrets</a> &#8211; cbsnews.com</li>
<li><a href="http://www.darkreading.com/database_security/security/privacy/showArticle.jhtml?articleID=224600001">Health Insurer Notifies More Than 409,000 Of Potential Breach</a> &#8211; darkreading.com</li>
<li><a href="http://www.h-online.com/security/news/item/Stored-images-on-photocopiers-a-security-risk-983088.html">Stored images on photocopiers a security risk</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://lifehacker.com/5521990/passwordcard-hides-mentally-encrypted-passwords-in-your-wallet">PasswordCard Hides Mentally Encrypted Passwords in Your Wallet</a> &#8211; lifehacker.com<br />
The PasswordCard itself is printed in color, and has different symbols heading each column, and a different color for each row.</li>
<li>Gmail accounts hit by spammers<br />
Google is investigating a growing number of reports that hackers are breaking into legitimate Gmail accounts and then using them to send spam messages.</p>
<ul>
<li><a href="http://www.pcworld.com/businesscenter/article/194635/drugdealing_spammers_hit_gmail_accounts.html">Drug-dealing Spammers Hit Gmail Accounts</a> &#8211; pcworld.com</li>
<li><a href="http://mail.google.com/support/bin/answer.py?ctx=gmail&amp;answer=45938">Checking if your Gmail has been breached</a> &#8211; google.com</li>
</ul>
</li>
<li><a href="http://garwarner.blogspot.com/2010/04/dmitry-naskovets-of-callservicebiz-meet.html">Dmitry Naskovets of CallService.biz, Meet the FBI</a> &#8211; garwarner.blogspot.com<br />
When the FBI designed to take over the management of the CallService.biz website, they did a little relocation first.</li>
<li><a href="http://hackademix.net/2010/04/21/microsoft-recommends-noscript/">Microsoft Recommends NoScript</a> &#8211; hackademix.net<br />
The technical core of this research is very worth reading, if you’re interested in XSS attack and defense techniques.</li>
<li>Someone might be able to hack into your cellphone privacy<br />
The first part of the operation involves getting a target&#8217;s cell phone number from a public database that links names to numbers for caller ID purposes.</p>
<ul>
<li><a href="http://news.cnet.com/8301-27080_3-20002986-245.html">Legal spying via the cell phone system</a> &#8211; cnet.com</li>
<li><a href="http://www.darkreading.com/database_security/security/privacy/showArticle.jhtml?articleID=224500142">New Hack Pinpoints Cell Phone User&#8217;s Location, Personal And Business Relationships</a> &#8211; darkreading.com</li>
</ul>
</li>
<li><a href="http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=224500077">Why Employees Break Security Policy (And What You Can Do About It)</a> &#8211; darkreading.com<br />
Companies that monitor network behavior say many employees still break rules in order to get their jobs done.</li>
<li><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=224400719">Researcher Demonstrates How To Counterattack Against A Targeted Attack</a> &#8211; darkreading.com<br />
Proof-of-concept turns the tables on attackers who wage targeted attacks on enterprises.</li>
<li><a href="http://blogs.zdnet.com/security/?p=6248&amp;tag=col1;post-6248">Hundreds of high profile sites unprotected from domain hijacking</a> &#8211; zdnet.com<br />
A MarkMonitor review shows that less than 10% of the top 300 most highly trafficked sites were protected using it.</li>
<li><a href="http://www.seattlepi.com/local/418746_video.html">Local computer security expert investigates police practices</a> &#8211; seattlepi.com<br />
Rachner discovered through sleuthing that police had withheld video-recorded evidence in his case.</li>
<li><a href="http://www.newsweek.com/id/236717">Can America win a cyberwar</a> &#8211; newsweek.com<br />
The United States economy depends on the Internet more than any other developed country in the world.</li>
<li><a href="http://gizmodo.com/5522948/blippy-reveals-credit-card-numbers-on-google">Blippy Reveals Credit Card Numbers On Google</a> &#8211; gizmodo.com<br />
It&#8217;s a huge, huge privacy concern, and if you have a Blippy account I&#8217;d recommend taking immediate action.</li>
<li><a href="http://searchsecurity.techtarget.com.au/articles/40337-HP-researchers-prppose-human-centric-web-app-security-tests">HP researchers propose human-centric web app security tests</a> &#8211; searchsecurity.techtarget.com.au<br />
Two application security experts are working on a way to improve the testing of Web applications by incorporating application data flow maps.</li>
<li><a href="http://news.cnet.com/8301-27080_3-20003312-245.html">Microsoft pulls faulty patch, plans re-release</a> &#8211; cnet.com<br />
A patch for the hole, which could allow an attacker to take control of a system, was released during Patch Tuesday last week.</li>
<li><a href="http://www.nzherald.co.nz/connect/news/article.cfm?c_id=1501833&amp;objectid=10640757">Facebook hacker claims to be in NZ</a> &#8211; nzherald.co.nz<br />
A Russian hacker who says he is living in New Zealand attempted to sell the login details of millions of Facebook users.</li>
<li><a href="http://www.technologyreview.com/web/25159/?a=f">Peeking Into Users&#8217; Web History</a> &#8211; technologyreview.com<br />
A team of European researchers found that they were able to hijack Google&#8217;s personalized search suggestions to reconstruct users&#8217; Web search histories.</li>
<li><a href="http://www.eset.com/blog/2010/04/24/facebook-checked-out-1-5-million-accounts-overdue-for-password-changes">Facebook checked out, 1.5 million accounts overdue for password changes?</a> &#8211; eset.com<br />
It remains to be seen if so many accounts have indeed been breached or if Kirllos the criminal hacker is perhaps running an audacious scam on fellow fraudsters.</li>
<li><a href="http://www.sqlmag.com/print/sql-server/A-New-Law-that-Will-Change-the-Way-You-Build-Database-Applications.aspx">A New Law Could Change the Way You Build Database Applications</a> &#8211; sqlmag.com<br />
Massachusetts recently passed a sweeping new data security law that will have a profound impact on the way the United States manages and develops data-centric applications.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1003&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/04/25/week-16-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 15 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/04/19/week-15-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/04/19/week-15-in-review-2010/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 03:58:04 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=987</guid>
		<description><![CDATA[
Events Related:

Announcing 1st Workshop: Malicious PDF Analysis &#8211; brucon.org
Didier Stevens talks about PDFiD and pdf-parser at Brucon this year.
MSU Red Team – Fun, Success &#8211; mcgrewsecurity.com
This CCDC was a “practice” run for two Alaskan teams and two Hawaiian teams.


Resources:

Cell Phone Security &#8211; cellphones.org
With the increased capabilities and conveniences of today’s cell phones comes the increased [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.brucon.org/2010/04/announcing-1st-workshop-malicious-pdf.html">Announcing 1st Workshop: Malicious PDF Analysis</a> &#8211; brucon.org<br />
Didier Stevens talks about PDFiD and pdf-parser at Brucon this year.</li>
<li><a href="http://www.mcgrewsecurity.com/2010/04/12/red-team-fun/">MSU Red Team – Fun, Success</a> &#8211; mcgrewsecurity.com<br />
This CCDC was a “practice” run for two Alaskan teams and two Hawaiian teams.</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://cellphones.org/blog/cell-phone-security/">Cell Phone Security</a> &#8211; cellphones.org<br />
With the increased capabilities and conveniences of today’s cell phones comes the increased risk of viruses, malware and identity theft.</li>
<li><a href="http://www.offensive-security.com/blog/offsec/questions-information-security-training-provider/">How to choose your Information Security Training</a> &#8211; offensive-security.com<br />
Welcome to our “10 questions you should be asking your Information Security Training Provider“.</li>
<li><a href="http://www.vs-db.info/">Vulnerable Sites Database</a> &#8211; vs-db.info<br />
Just what it says, a database of vulnerable sites on the web</li>
<li><a href="http://www.phpbbexploit.com/">phpBB Exploits aggregator v1</a> &#8211; phpbbexploit.com<br />
A collection of phpBB flaws.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.openinfosecfoundation.org/index.php/downloads">Suricata v0.8.1</a> &#8211; openinfosecfoundation.org<br />
The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine.</li>
<li><a href="http://winautopwn.co.nr/">winAUTOPWN v2.2</a> &#8211; winautopwn.co.nr<br />
winAUTOPWN is an auto (hacking) shell gaining tool.</li>
<li><a href="http://owasp.blogspot.com/2010/04/hi-all-here-is-follow-up-2.html">JBroFuzz 2.1</a> &#8211; owasp.blogspot.com<br />
Some new features are daily logs, custom fuzzers and more.</li>
<li><a href="http://xss.codeplex.com/releases/43170/download/115610#">x5s – Automated XSS Security Testing Assistant</a> &#8211; xss.codeplex.com<br />
x5s is a Fiddler add-on which aims to assist penetration testers in finding cross-site scripting vulnerabilities.</li>
<li><a href="http://www.notsosecure.com/folder2/2010/04/13/bsqlbf-v2-5/">bsqlbf v2.5</a> &#8211; notsosecure.com<br />
SYS.KUPP$PROC.CREATE_MASTER_PROCESS() and BMS_JAVA_TEST.FUNCALL now included.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8617">Web App Testing Tools</a> &#8211; sans.org<br />
Security testers are always on the lookout for new or updated tools to test the security of web based applications.</li>
<li><a href="http://packetstormsecurity.org/filedesc/netcatscripts.tar-gz.html">netcatscripts</a> &#8211; packetstormsecurity.org<br />
This tarball has a couple of bash scripts that use netcat to brute force ftp and scan for local and remote file inclusion vulnerabilities.</li>
<li><a href="http://www.darknet.org.uk/2010/04/pbnj-network-architecture-monitoring-tool/">PBNJ – Network Architecture Monitoring Tool</a> &#8211; darknet.org.uk<br />
PBNJ is a suite of tools to monitor changes on a network over time. It does this by checking for changes on the target machine(s).</li>
<li><a href="http://www.netinfinity.org/download/">Ubuntu Pentest Edition v2.03</a> &#8211; netinfinity.org<br />
Ubuntu Pentest Edition is a gnome based linux designed as a complete system which can also be used for penetration testing.</li>
<li><a href="http://runplaybook.com/flint">Flint 1.0.6</a> &#8211; runplaybook.com<br />
Just fixing some parser bugs that Jacob Kitchel helped us track down.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://www.securitybalance.com/2010/04/pentesting/">Pentesting</a> &#8211; securitybalance.com<br />
It is important to differentiate between Risk and vulnerability assessments, pentests and vulnerability research.</li>
<li><a href="http://blog.red-database-security.com/2010/04/12/man-in-the-middle-attacks-at-upcoming-black-hat-europe/">Man-in-the-Middle attacks at upcoming Black Hat Europe</a> &#8211; red-database-security.com<br />
A upcoming talk on how to steal credentials by downgrading authentication mechanisms as well as overtaking existing user sessions.</li>
<li><a href="http://www.schneier.com/blog/archives/2010/04/man-in-the-midd_2.html">Man-in-the-Middle Attacks Against SSL</a> &#8211; schneier.com<br />
A discussion on MITM, SSL and more.</li>
<li><a href="http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/">WinPE 3.0 &amp; Forensics</a> &#8211; praetorianprefect.com<br />
You may find this analysis interesting if you are a Windows expert performing a forensics analysis.</li>
<li><a href="http://pauldotcom.com/2010/04/exploring-the-facebook-api.html">Exploring the Facebook API</a> &#8211; pauldotcom.com<br />
The Ethical Hacker Challenges are always a lot of fun.</li>
<li><a href="http://blogs.sans.org/computer-forensics/2010/04/13/dd/">An anti-forensics dd primer</a> &#8211; sans.org<br />
dd is the swiss army knife of file tools – with /dev/tcp it can also be a network tool (but nc is simpler).</li>
<li><a href="http://blog.metasploit.com/2010/04/persistent-meterpreter-over-reverse.html">Persistent Meterpreter over Reverse HTTPS</a> &#8211; metasploit.com<br />
Botnet agents and malware go through inordinate lengths to hide their command and control traffic.</li>
<li><a href="http://www.acunetix.com/blog/web-security-zone/articles/exploit-cross-site-script-mambo/">Exploiting a Cross Site Scripting vulnerability in Mambo CMS</a> &#8211; acunetix.com<br />
In this video we look into the details of how an attacker is able to exploit a Cross Site Scripting vulnerability in Mambo CMS (version: 4.6.5).</li>
<li><a href="http://www.lovemytool.com/blog/2010/04/top-10-wireshark-filters-by-chris-greer.html">Top 10 Wireshark Filters (by Chris Greer)</a> &#8211; lovemytool.com<br />
The filtering capabilities of Wireshark are very comprehensive.</li>
<li><a href="http://blog.ksplice.com/2010/04/exploiting-kernel-null-dereferences/">Much ado about NULL: Exploiting a kernel NULL dereference</a> &#8211; ksplice.com<br />
I’ve prepared a trivial kernel module that will deliberately cause a NULL pointer derefence.</li>
<li><a href="http://www.sensepost.com/blog/4620.html">GlypeAhead: Portscanning through PHP Glype proxies</a> &#8211; sensepost.com<br />
The proxy industry flourished with many proxy owners generating passive incomes from their proxy networks.</li>
<li><a href="http://blog.fortinet.com/reversing-the-symbian-enoriv-malware/">Reversing the Symbian Enoriv malware</a> &#8211; fortinet.com<br />
On Symbian phones, most malware are either implemented natively in C++ (over the Symbian API) or in Java (midlets).</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/414">Buby.kicks_ass? =&gt; true</a> &#8211; carnal0wnage.attackresearch.com<br />
Buby combines two things I use on at least every web application penetration test, if not every penetration test.</li>
<li><a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=224400129">Next-Generation Clickjacking Attacks Revealed</a> &#8211; darkreading.com<br />
Researcher at Black Hat Europe will also release new, free tool for executing these attacks.</li>
<li><a href="http://www.securityninja.co.uk/burp-suite-tutorial-sequencer-tool">Burp Suite Tutorial – Sequencer Tool</a> &#8211; securityninja.co.uk<br />
This blog post will explain how to use the Sequencer tool.</li>
<li><a href="http://blogs.technet.com/bluehat/archive/2010/04/15/software-security-people-process-technology.aspx">Software Security == People &amp;&amp; Process &amp;&amp; Technology</a> &#8211; technet.com<br />
Despite some popular misconceptions in order to be an effective Agile team you need to be disciplined, which actually plays in well to thinking about security.</li>
<li>All about cracking Oracle<br />
Dennis Yurichev has released a new password cracker (brute-force) called ops_sse2 for Oracle DES passwords.</p>
<ul>
<li><a href="http://blogs.conus.info/node/45">My two oracle passwords crackers</a> &#8211; conus.info</li>
<li><a href="http://blog.red-database-security.com/2010/04/15/new-fast-oracle-des-password-cracker-ops_sse2/">New fast Oracle DES password cracker OPS_SSE2</a> &#8211; red-database-security.com</li>
</ul>
</li>
<li><a href="http://blog.metasploit.com/2010/04/java-web-start-argument-injection.html">The Java Web Start Argument Injection Vulnerability</a> &#8211; metasploit.com<br />
This service controls whether or not the WebDAV Mini-Redirector functionality is enabled.</li>
<li><a href="http://taosecurity.blogspot.com/2010/04/response-to-dan-geer-article-on-apt.html">Response to Dan Geer Article on APT</a> &#8211; taosecurity.blogspot.com<br />
This &#8220;least expensive defense&#8221; is not insane, just ineffective because the offense is a sentient being with a strategic advantage.</li>
<li><a href="http://djtechnocrat.blogspot.com/2010/04/abusing-internet-explorer-8s-xss.html">Abusing Internet Explorer 8&#8217;s XSS Filters</a> &#8211; djtechnocrat.blogspot.com<br />
Internet Explorer 8 implements an anti Cross-site Scripting (XSS) mechanism to detect certain types of XSS attacks.</li>
<li><a href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=224400589">Taking Penetration Testing In-House</a> &#8211; darkreading.com<br />
Weighing the risks and benefits of do-it-yourself pen testing.</li>
<li><a href="http://intrepidusgroup.com/insight/2010/04/webos-examples-of-sms-delivered-injection-flaws/">WebOS: Examples of SMS delivered injection flaws</a> &#8211; intrepidusgroup.com<br />
An informative post on exploits delivered via cellular.</li>
<li><a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Amazon EC2 SIP Brute Force Attacks on Rise</a> &#8211; voiptechchat.com<br />
There are various techniques to assist with minimizing DDoS and Brute Force attacks.</li>
<li><a href="http://www.sophos.com/blogs/chetw/g/2010/04/14/events-blackhat-seo/">Events and blackhat SEO</a> &#8211; sophos.com<br />
I had an opportunity to sit down with one of our researchers who helped write the paper, Onur Komili.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Java Exploit found<br />
Tavis Ormandy  said he could abuse a feature in Java to launch arbitrary applications on a Windows PC using a specially-crafted Web site.</p>
<ul>
<li><a href="http://krebsonsecurity.com/2010/04/unpatched-java-exploit-spotted-in-the-wild/">Unpatched Java Exploit Spotted In-the-Wild</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://djtechnocrat.blogspot.com/2010/04/sun-java-0-day-being-exploited-in-wild.html">Sun Java 0-Day Being Exploited In-The-Wild</a> &#8211; djtechnocrat.blogspot.com</li>
<li><a href="http://threatpost.com/en_us/blogs/java-zero-day-attacks-wild-041410">Java Zero-Day Attacks In The Wild</a> &#8211; threatpost.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=6161">Java zero-day flaw under active attack</a> &#8211; zdnet.com</li>
<li><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=224202581">Most Java Versions Affected By Latest Zero-Day Vulnerability</a> &#8211; darkreading.com</li>
<li><a href="http://blog.fireeye.com/research/2010/04/who-is-exploiting-the-java-0day.html">Who is Exploiting the Java 0-day?</a> &#8211; fireeye.com</li>
</ul>
</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>VMWare patches things with their products<br />
Virtualisation specialist VMware has released security updates for a number of its products, closing a total of ten security vulnerabilities.</p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/VMware-patches-vulnerabilities-in-its-products-975567.html">VMware patches vulnerabilities in its products</a> &#8211; h-online.com</li>
<li><a href="http://www.exploit-db.com/exploits/12188">VMware Remote Console Plug-in</a> &#8211; exploit-db.com</li>
</ul>
</li>
<li>Adobe fixes Reader and Acrobat holes<br />
Adobe has also released updates for their Reader and Acrobat products.</p>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">Security update available for Adobe Reader and Acrobat</a> &#8211; adobe.com</li>
<li><a href="http://threatpost.com/en_us/blogs/adobe-releases-quarterly-patches-enables-auto-updater-041310">Adobe Releases Quarterly Patches, Enables Auto Updater</a> &#8211; threatpost.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=6135">Critical flaws haunt Adobe PDF Reader, Acrobat</a> &#8211; zdnet.com</li>
<li><a href="http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/">Adobe Reader 9.3.2 Security Update Released</a> &#8211; ghacks.net</li>
<li><a href="http://blogs.adobe.com/asset/2010/04/an_update_on_staying_up-to-dat.html">An Update on Staying Up-To-Date</a> &#8211; adobe.net</li>
</ul>
</li>
<li>Microsoft introduces a slew of patches
<ul>
<li><a href="http://blogs.technet.com/msrc/archive/2010/04/13/april-2010-security-bulletin-release.aspx">April 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/04/12/assessing-the-risk-of-the-april-security-bulletins.aspx">Assessing the risk of the April Security Bulletins</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-019 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-020 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/04/12/smb-client-update-blog-post.aspx">MS10-020: SMB Client Update</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-021 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/04/12/registry-vulnerabilities-addressed-by-ms10-021.aspx">Registry vulnerabilities addressed by MS10-021</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-022 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-023 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-024 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-025 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-026 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-027 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-028 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx?pubDate=2010-04-13">Microsoft Security Bulletin MS10-029 &#8211; Moderate</a> &#8211; microsoft.com</li>
<li><a href="https://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx">Microsoft Security Bulletin Summary for April 2010</a> &#8211; microsoft.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-20002385-245.html">Microsoft, Adobe, Oracle offer fixes in big Patch Tuesday</a> &#8211; cnet.com</li>
<li><a href="http://threatpost.com/en_us/blogs/microsoft-plugs-critical-drive-download-holes-041310">Microsoft Plugs Critical Drive-By Download Holes</a> &#8211; threatpost.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=6128">MS Patch Tuesday: Exploits expected for severe drive-by-download flaws</a> &#8211; zdnet.com</li>
<li><a href="http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/">Microsoft Security Updates April 2010</a> &#8211; ghacks.net</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-april-2010">Microsoft Patch Tuesday &#8211; April 2010</a> &#8211; symantec.com</li>
</ul>
</li>
<li>Oracle releases a fix for 47 security issues<br />
Oracle Corp. has shipped a new version of its Java software that nixes a feature in Java that hackers have been using to foist malicious software.</p>
<ul>
<li><a href="http://isc.sans.org/diary.html?storyid=8632">Oracle has released 47 critical patches (Includes SUN patches)</a> &#8211; sans.org</li>
<li><a href="http://threatpost.com/en_us/blogs/sun-about-face-out-cycle-java-update-patches-critical-flaw-041510">Sun About Face: Out-of-Cycle Java Update Patches Critical Flaw</a> &#8211; threatpost.com</li>
<li><a href="http://krebsonsecurity.com/2010/04/java-patch-targets-latest-attacks/">Java Patch Targets Latest Attacks</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.darknet.org.uk/2010/04/oracle-releases-emergency-patch-for-java-vulnerability/">Oracle Releases Emergency Patch for Java Vulnerability</a> &#8211; darknet.org.uk</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/cisco-plugs-critical-secure-desktop-activex-hole-041610">Cisco Plugs Critical Secure Desktop ActiveX Hole</a> &#8211; threatpost.com<br />
The company issued a patch alongside a warning that successful exploitation of this vulnerability could result in a &#8220;complete compromise of the affected system.&#8221;</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>FarmVille used in PoC data harvesting exploit<br />
Security engineer Joey Tyson has detailed a major security hole in Facebook Platform — one that would allow a malicious website to silently access a user’s profile information.</p>
<ul>
<li><a href="http://theharmonyguy.com/2010/04/10/facebook-platform-vulnerability-enabled-silent-data-harvesting/">Facebook Platform Vulnerability Enabled Silent Data Harvesting</a> &#8211; theharmonyguy.com</li>
<li><a href="http://techcrunch.com/2010/04/10/researcher-uncovers-another-major-facebook-security-exploit/">Researcher Uncovers (Another) Major Facebook Security Exploit</a> &#8211; techcrunch.com</li>
</ul>
</li>
<li>More on the Bank of America ATM tech-heist<br />
A Bank of America worker was able to siphon at least $200,000 from hacked machines before he was caught.=</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2010/04/atm-hack/">Take From ATM Malware Caper Exceeded $200,000</a> &#8211; wired.com</li>
<li><a href="http://www.wired.com/threatlevel/2010/04/malware-targeted-100-atms/">Bank Worker Pleads Guilty to Hacking 100 ATMs</a> &#8211; wired.com</li>
</ul>
</li>
<li>News on the Wordpress Hack<br />
Malicious hackers have found a way to hijack WordPress database credentials.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/wordpress-hack-linked-database-password-hijack-041210">WordPress Hack Linked to Database Password Hijack</a> &#8211; threatpost.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=6111">WordPress blogs hacked, redirecting to malware</a> &#8211; zdnet.com</li>
<li><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=224300052">&#8216;Design Flaw&#8217; Led To Wave Of Attacks On Hundreds Of WordPress Blogs</a> &#8211; darkreading.com</li>
<li><a href="http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php">How to Diagnose and Remove the WordPress Pharma Hack</a> &#8211; pearsonified.com</li>
</ul>
</li>
<li><a href="http://blogs.zdnet.com/security/?p=6087">Researchers get funding to build new secure OS</a> &#8211; zdnet.com<br />
Researchers have received a $1.15 million grant to build a new computer operating system based on virtual machines and the concept of isolation.</li>
<li><a href="http://www.eset.com/blog/2010/04/12/hr-4061-what-three-bucks-buys-you">HR 4061: What Three Bucks buys you…</a> &#8211; eset.com<br />
According to the CBO report, three dollars from every citizen of the United States each year for four years is what the final cost of the new Cybersecurity Act will be.</li>
<li><a href="http://www.news.com.au/travel/news/dubbo-airport-pin-number-taped-to-security-gate/story-e6frfq80-1225852130691">Dubbo airport PIN taped to security gate</a> &#8211; news.com.au<br />
Federal Government officials will next week review security at Dubbo airport in the state&#8217;s Central West after it was alerted to the blatant breach of security.</li>
<li><a href="http://lifehacker.com/5516188/shift-your-fingers-one-key-to-the-right-for-easy+to+remember-but-awesome-passwords">Shift Your Fingers One Key to the Right for Easy-to-Remember but Awesome Passwords</a> &#8211; lifehacker.com<br />
Stick with your weak, dictionary password if you must; just move your fingers over a space on the keyboard.</li>
<li><a href="http://www.boston.com/bostonglobe/ideas/articles/2010/04/11/please_do_not_change_your_password/">Please do not change your password</a> &#8211; boston.com<br />
Most security advice simply offers a poor cost-benefit trade-off to users.</li>
<li>Apache hit by a direct attack<br />
The hackers hit the server hosting the software that Apache.org uses to it to track issues and requests and stole passwords from all users.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/apache-foundation-hit-targeted-xss-attack-041310?utm_source=Personalities+Pod&amp;utm_medium=Home+Page+Personalities&amp;utm_campaign=Personalities+Ryan">Apache Foundation Hit by Targeted XSS Attack</a> &#8211; threatpost.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=6123">Apache.org hit by targeted XSS attack, passwords compromised</a> &#8211; zdnet.com</li>
<li><a href="http://www.darknet.org.uk/2010/04/hackers-penetrate-apache-org-in-direct-targeted-attack/">Hackers Penetrate Apache.org In Direct Targeted Attack</a> &#8211; darknet.org.uk</li>
<li><a href="http://www.acunetix.com/blog/web-security-zone/articles/xss-to-root-apache-org/">The road to glory, from XSS to Root on apache.org</a> &#8211; acunetix.com</li>
<li><a href="http://www.h-online.com/security/news/item/Apache-s-Atlassian-JIRA-system-compromised-976465.html">Apache&#8217;s Atlassian JIRA system compromised</a> &#8211; h-online.com</li>
<li><a href="http://tacticalwebappsec.blogspot.com/2010/04/apacheorg-compromised-through-xss.html">Apache.org Compromised Through XSS</a> &#8211; tacticalwebappsec.blogspot.com</li>
</ul>
</li>
<li>VB100-related news<br />
A total of 60 anti-virus products running on the Windows XP platform were put to the test.</p>
<ul>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/04/13/vb100-win-sophos-virus-bulletins-largest-comparative-review/">VB100 win for Sophos in Virus Bulletin&#8217;s largest ever comparative review</a> &#8211; sophos.com</li>
<li><a href="http://www.virusbtn.com/news/2010/04_13.xml">Record breaking 60 anti-malware products undergo VB100 testing on Windows XP</a> &#8211; virusbtn.com</li>
</ul>
</li>
<li><a href="http://www.wired.com/threatlevel/2010/04/brokerage-firm-fined/">Brokerage Firm Fined $375,000 for Unsecured Data</a> &#8211; wired.com<br />
Brokerage firm DA Davidson has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers.</li>
<li><a href="http://www.technologyreview.com/web/25032/">China&#8217;s Internet Paradox</a> &#8211; technologyreview.com<br />
A woman who uses the online pseudonym Xiaomi sat down for another day of outwitting Internet censorship.</li>
<li><a href="http://news.cnet.com/8301-13639_3-20002463-42.html">Air Force to add cyberwarfare training</a> &#8211; cnet.com<br />
U.S. Air Force recruits will be trained in the basics of cyberwarfare, according to statements made by four-star Air Force Gen. Robert Kehler.</li>
<li><a href="http://threatpost.com/en_us/blogs/attackers-using-malicious-pac-files-phishing-attacks-041410">Attackers Using Malicious PAC Files in Phishing Attacks</a> &#8211; threatpost.com<br />
Attackers have begun using proxy auto-config (PAC) files, which are designed to enable browsers to automatically select which proxy server to use to get a specific URL. <span style="font-size: 13.1944px"> </span></li>
<li>Senate hearing on response to cyber attacks<br />
Lt. Gen. Keith Alexander said the U.S. should not be deterred from taking action against countries such as Iran and North Korea just because they might launch cyber attacks.</p>
<ul>
<li><a href="http://www.google.com/hostednews/ap/article/ALeqM5jATLd9Qzrn-ioGcLQ4oDf99TgscAD9F2T3GO0">Military asserts right to return cyber attacks</a> &#8211; google.com</li>
<li><span style="font-size: 13.1944px"><a href="http://www.wired.com/threatlevel/2010/04/cyberwar-commander/">Cyberwar Commander Survives Senate Hearing</a> &#8211; wired.com</span></li>
<li><span style="font-size: 13.1944px"><a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=224400518">NSA Director Tells Senate He Won&#8217;t Overstep In Role As U.S. Cyber Command Director</a> &#8211; darkreading.com</span></li>
</ul>
</li>
<li><a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/04/14/AR2010041404159.html">Boy, 9, accused of hacking into Fairfax schools&#8217; computer system</a> &#8211; washingtonpost.com<br />
A 9-year-old McLean boy hacked into the Blackboard Learning System used by the county school system to change teachers&#8217; and staff members&#8217; passwords, among other things.</li>
<li>Java flaw hits lyrics website<br />
It was found exploit code on servers in Russia that was triggered by computers visiting English-language site Songlyrics.com.</p>
<ul>
<li><span style="font-size: 13.1944px"><a href="http://news.cnet.com/8301-27080_3-20002530-245.html">Unpatched Java hole exploited at lyrics site</a></span> &#8211; cnet.com</li>
<li><span style="font-size: 13.1944px"><a href="http://www.h-online.com/security/news/item/Java-vulnerability-when-lyric-sites-attack-Update-978283.html">Java vulnerability &#8211; when lyric sites attack &#8211; Update</a> &#8211; h-online.com</span><span style="font-size: 13.1944px"> </span></li>
</ul>
</li>
<li><a href="http://www.wired.com/threatlevel/2010/04/toey_sentence/">Final Conspirator in Credit Card Hacking Ring Gets 5 Years</a> &#8211; wired.com<br />
Damon Patrick Toey was sentenced in Boston on Thursday to 5 years in prison.</li>
<li><a href="http://arstechnica.com/security/news/2010/04/almost-all-fortune-500-companies-show-zeus-botnet-activity.ars">Almost all Fortune 500 companies show Zeus botnet activity</a> &#8211; arstechnica.com<br />
Up to 88% of Fortune 500 companies may have been affected by the Zeus trojan.</li>
<li><a href="http://blogs.msdn.com/david_leblanc/archive/2010/04/16/don-t-use-office-rc4-encryption-really-just-don-t-do-it.aspx">Don’t Use Office RC4 Encryption. Really. Just don’t do it.</a> &#8211; msdn.com<br />
The paper really just shows how an attack discovered by Hongjun Wu where we committed the error of key stream reuse can actually be implemented.</li>
<li><a href="http://krebsonsecurity.com/2010/04/ipack-exploit-kit-bites-windows-users/">iPack Exploit Kit Bites Windows Users</a> &#8211; krebsonsecurity.com<br />
The software vulnerabilities targeted by exploits contained in this package are all for Windows platforms.</li>
<li><a href="http://taosecurity.blogspot.com/2010/04/vulnerable-sites-database-more.html">Vulnerable Sites Database: More Intrusion as a Service</a> &#8211; taosecurity.blogspot.com<br />
With www.vs-db.info we get details like &#8220;local file inclusion&#8221; or &#8220;SQL injection.&#8221;</li>
<li><a href="http://news.cnet.com/8301-1009_3-20002667-83.html">Security researchers demo Cisco Wi-Fi flaws</a> &#8211; cnet.com<br />
Enno Rey and Daniel Mende of German testing firm ERNW demonstrated how to hack into two separate generations of the Cisco Wi-Fi kit.</li>
<li><a href="http://www.networkworld.com/news/2010/041410-researcher-shows-new-clickjacking.html?hpg1=bn">Researcher shows new clickjacking methods</a> &#8211; networkworld.com<br />
Stone showed one demonstration that used the drag-and-drop API (application programming interface) implemented in all browsers.</li>
<li><a href="http://www.crunchgear.com/2010/04/16/riaa-mpaa-would-like-to-scan-your-hard-drive-for-infringing-content/">RIAA, MPAA would like to scan your hard drive for infringing content</a> &#8211; crunchgear.com<br />
There really isn’t any particular point to the following story other than to get you riled up as your begin your weekend.</li>
<li><a href="http://www.bbc.co.uk/programmes/b00rmssw">GCHQ: Cracking the Code</a> &#8211; bbc.co.uk<br />
Gordon Corera gains unprecedented access to Britain&#8217;s ultra secret listening station.</li>
<li><a href="http://www.betanews.com/article/Security-researcher-Trivially-easy-to-buy-SSL-certificate-for-domain-you-dont-own/1270072287">Security researcher: &#8216;Trivially easy&#8217; to buy SSL certificate for domain you don&#8217;t own</a> &#8211; betanews.com<br />
Those keys can then be used to sign certificates as any other Web site, enabling a law enforcement authority to spoof virtually any other site.</li>
<li><a href="http://blog.sucuri.net/2010/04/network-solutions-hacked-again.html">Network Solutions hacked again</a> &#8211; sucuri.net<br />
Just today we were notified of more than 50 sites hacked with a malware javascript.</li>
<li><a href="http://gizmodo.com/5518911/celebrity-hacker-microsoft-leads-industry-in-security">Celebrity Hacker: Microsoft Leads Industry In Security</a> &#8211; gizmodo.com<br />
Security expert Marc Maiffret parlayed his teen hacking skills into getting paid to find holes in Microsoft software.</li>
</ul>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=987&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/04/19/week-15-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
