CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer
image Advisories!: Latest Advisories (9/30/03) image
Cyber Security
Latest Advisories
2003-09-30

Secunia
Security Tracker
Security Focus
Symantec
FTC

The Federal Trade Commission is warning consumers about
fake credit report sites sent over e-mail that cash-in on your personal information. The scam is called "phishing," and it asks people to release personal information on Credit Report Web sites that look legitimate, but are in fact fake. The F-T-C says do not reply to these e-mail credit report offers. For more information about this scam go to FTC

Secunia

Secunia Highlights:
Special Update: Microsoft Internet Explorer Multiple Vulnerabilities
Microsoft has issued a cumulative patch for Internet Explorer, which fixes multiple vulnerabilities. The worst vulnerability can lead to execution of arbitrary code on the client system via HTML emails or web sites.
Microsoft Windows RPCSS Service DCOM Interface Vulnerabilities
Three vulnerabilities have been identified in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system or cause a DoS (Denial of Service).


Sun Solaris Sadmind Insecure Default Configuration

Sun has issued a security alert for Sun Solaris to raise awareness of the known insecure default configuration of sadmind (Solstice Administration Daemon) because an exploit has been discovered in the wild.
Latest 15 Secunia Security Advisories:
2003-09-30
- SGI IRIX update for sendmail

- Geeklog Cross Site Scripting Vulnerabilities

- winShadow Denial of Service Vulnerability

- A-Cart signin.asp Cross-Site Scripting Vulnerability

- Open UNIX/UnixWare Frame Padding Vulnerability

- ArGoSoft FTP Server XCWD Buffer Overflow Vulnerability



2003-09-29
- Mandrake update for Apache

- Apache 2 CGI Denial of Service Vulnerability

- Open UNIX/UnixWare update for OpenSSH

- Open UNIX/UnixWare update for Sendmail

- Mandrake update for ProFTPD

- Trustix update for ProFTPD

- Smoothwall update for OpenSSH

- Debian update for freesweep

- SGI IRIX DCE Denial of Service Vulnerability
More Advisories


Security Tracker



Freesweep Buffer Overflows Let Local Users Obtain 'games' Group Privileges

Some buffer overflow vulnerabilities were reported in the Freesweep game software. A local user may be able to obtain elevated privileges on the system.

Impact: Execution of arbitrary code via local system, User access via local system



Geeklog Input Validation Flaws Permit SQL Injection and Cross-Site Scripting Attacks

Lorenzo Hernandez Garcia-Hierro reported several vulnerabilities in Geeklog. A remote user can inject SQL commands. A remote user can also conduct cross-site scripting attacks.

Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information



Invision Power Board Configuration File Permission Flaw Lets Local Users Inject Malicious Code

f3rm0r of Media Assasins reported a file permission vulnerability in Invision Power Board. A local user can modify a global configuration file.

Impact: Execution of arbitrary code via local system, Modification of user information, User access via local system



A-CART Input Validation Flaw in 'signin.asp' Permits Remote Cross-Site Scripting Attacks

G00db0y from Zone-h Security Team reported an input validation vulnerability in A-CART. A remote user can conduct cross-site scripting attacks.

Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information



Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service

A denial of service vulnerability was reported in the Apache 2.0 web server. A user with the ability to place CGI scripts on the server can cause the web service to hang.

Impact: Denial of service via local system




SecurityFocus BugTraq
SecurityFocus Vulnerabilities
09/29/2003 Re: SMC Router Denial of Service exploit Ranjeet Shetye
09/29/2003 sendmail prescan() vulnerability on IRIX SGI Security Coordinator
09/29/2003 Re: cfengine2-2.0.3 remote exploit for redhat Keith Matthews
09/29/2003 Re: SMC Router Denial of Service exploit Claus A
09/29/2003 [ANNOUNCE] kses 0.2.1 Härnhammar, Ulf
09/29/2003 Re: cfengine2-2.0.3 remote exploit for redhat Stephen Smoogen
09/29/2003 [CLA-2003:750] Conectiva Security Announcement - proftpd Conectiva Updates
09/29/2003 Re: Geeklog Multiple Versions Vulnerabilities Chris Kulish us ing com
09/29/2003 [SECURITY] [DSA-392-1] New webfs packages fix buffer overflows, file and directory exposure Matt Zimmerman
09/29/2003 GLSA: net-ftp/proftpd (200309-16) aliz gentoo org (Daniel Ahlberg)
09/29/2003 GLSA: media-video/mplayer (200309-15) aliz gentoo org (Daniel Ahlberg)
09/29/2003 Shattering SEH III Brett Moore
09/29/2003 ECHU.ORG Alert #4: GuppY makes XSS attacks easy David Suzanne
09/29/2003 [RELEASE] GenXE - Generate Xss Exploit Liu Die Yu
09/29/2003 TSLSA-2003-0037 - proftpd Trustix Secure Linux Advisor

2003-09-26: Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability
2003-09-26: Sun One Application Server LDAP Incorrect Authentication Vulnerability
2003-09-26: Savant Web Server Page Redirect Denial Of Service Vulnerability
2003-09-26: Sendmail Ruleset Parsing Buffer Overflow Vulnerability


Symantec SSR
W32.HLLW.Gaobot.AN
W32.HLLW.Gaobot.AF September 29, 2003 September 30, 2003
Trojan.PWS.QQPass.E September 28, 2003 September 29, 2003
Trojan.Vardo September 28, 2003 September 29, 2003
W32.Galil.C@mm September 28, 2003 September 29, 2003
W32.HLLW.Donk.B
W32/Sdbot.worm [McAfee], Backdoor.SdBot.gen [KAV] September 27, 2003 September 29, 2003
XM.VNN
XF/Sic.gen [McAfee], X97M_WISAB.A [Trend] September 27, 2003 September 29, 2003
W32.HLLP.Spreda.B
W32.HLLP.Savno, W32/HLLP.Savno!p2p [McAfee], Win32.HLLP.Savno [KAV] September 26, 2003 September 29, 2003
Posted on Tuesday, 30 September 2003 @ 06:56:17 UTC by phoenix22 (1656 reads)
[ Trackback ]
image

"Advisories!: Latest Advisories (9/30/03)" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· MandrakeSoft
· Red Hat
· Debian GNU/Linux
· Linux Games
· Microsoft
· Microsoft
· HotScripts
· Apache Web Server
· W3 Consortium
· CSS Standard
· HTML Standard
· More about Cyber Security
· News by phoenix22


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer