Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?Need help customizing or designing scripts?Please contact us via the Contact Us option for further details and pricing.
Websense Security Labs(tm) ThreatSeeker(tm) Network has discovered spam emails offering recipients links to unpublished videos and pictures of singer Michael Jackson. According to news reports Michael Jackson's death was confirmed yesterday.
The spam email appears to offer a link to a YouTube video, but instead sends the recipient to a Trojan Downloader hosted on a compromised Web site. The file offered is called Michael.Jackson.videos.scr (MD5: 664cb28ef710e35dc5b7539eb633abca). This file is located on a legitimate Web site hosted in Australia belonging to a radio broadcasting station. Upon executing the file, a legitimate Web site at http://musica.uol.com.br/ultnot/2009/06/25/michael-jackson.jhtm is opened by the default browser in order to distract the user by presenting a news article for them to read.
In the background, three further information-stealing components are downloaded and installed by the malware. One of the downloaded files is called michael.gif, which has low AV detection rates - see VT results here. The malware then installs a malicious BHO that is registered with this file %windir%Dynamic.dll and this GUID {FCADDC14-BD46-408A-9842-CDBE1C6D37EB}. Another component is bound to startup at %windir%system32kproces.exe. Another malicious file installed by the malware is %windir%system32fotos.exe.
Translation of the email is as follows:
::
Posted by Raven on Friday, June 26, 2009 @ 09:33:44 EDT (890 reads) (Read More... | 2786 bytes more | Score: 0)
RavenNuke(tm) v2.30.02 Security Fixpack has been released
Note that this upgrade is for RavenNuke(tm) v2.30.01 only. If you are not using RavenNuke(tm) v2.30.01 then you need to FIRST upgrade to v2.30.01 and then apply this fix.
The FULL release downloads for v2.30.02 (v2.30.01 with the Fixpack already applied) are also available for downloading.
Note:Admin Note: The upgrade link has been fixed - Sorry!
Posted by Raven on Thursday, June 25, 2009 @ 18:33:57 EDT (912 reads) ( | Score: 0)
Zen Cart Administration Security Bypass Vulnerability
DESCRIPTION: A vulnerability has been discovered in Zen Cart, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is confirmed in version 1.3.8a (full fileset 12112007). Other versions may also be affected.
Posted by Raven on Wednesday, June 24, 2009 @ 20:20:50 EDT (1482 reads) (Read More... | 1389 bytes more | Score: 0)
Shockwave Player Arbitrary Code Execution Vulnerability
DESCRIPTION: A vulnerability has been reported in Shockwave Player, which can be exploited by malicious people to compromise a user's system. The vulnerability is reported in versions prior to 11.5.0.600. The vulnerability is caused due to an unspecified error when processing Shockwave Player 10 content and can be exploited to execute arbitrary code.
SOLUTION: Uninstall versions prior to 11.5.0.600, restart the system, and install version 11.5.0.600: http://get.adobe.com/shockwave/
PROVIDED AND/OR DISCOVERED BY: The vendor credits Paul Kurczaba, reported via ZDI.
ORIGINAL ADVISORY: http://www.adobe.com/support/security/bulletins/apsb09-08.html
Posted by Raven on Wednesday, June 24, 2009 @ 20:12:51 EDT (687 reads) ( | Score: 0)
Phpnuke SEO packages Released
webmidas writes "Outshine Solutions feels proud to announce that they have taken initiative to make php nuke CMS SEO friendly, launches SEO packages for php nuke users.
Php Nuke is a content management system that lacks certain SEO features. These packages has been launched to make any php nuke based website more search engine friendly so that they can rank well in search engines.
Featres of php nuke SEO packages:
"
Note:From Admin: These SEO packages are not free. They range in price from $199 to $499.
Posted by Raven on Wednesday, June 24, 2009 @ 14:09:25 EDT (788 reads) (Read More... | 757 bytes more | Score: 0)
NukeC 3.7.3 Released
nuken writes "The XHTML 1.0 transitional release of NukeC is available for download at Trickedoutnews.com. This release addresses many, many bug/issue fixes. The only remaining issue known is custom content admin feature still does not work. The blocks all work but are not XHTML compliant. Full change list available on my site. Enjoy."
Posted by Raven on Sunday, June 21, 2009 @ 14:55:36 EDT (565 reads) ( | Score: 0)
Spam IP Module for PHP-Nuke Check and Submit IP's!
link writes "With the new Spam IP module for php-nuke you can quickly and accurately check spammers ip addresses against a database of over 80,000+ ips. Want to help us and others in the fight against php-nuke spam? Download and install the module. If you find a spammer in your forum please submit his IP to us. We are working on an IP Ban SQL file that will add this projects protection to your php-nuke file. So check back for updates please. Download the module here. See the module in action here.
Thanks for helping keep php-nuke spam free!"
Posted by Raven on Friday, June 19, 2009 @ 09:41:08 EDT (751 reads) ( | Score: 0)
New theme release pmcct-ruby
papamike writes "Hi,
I just released my newest theme pmcct-ruby. Well it's not actually new, it was the theme I used on my site until last week.
Posted by Raven on Tuesday, June 09, 2009 @ 15:35:15 EDT (769 reads) (Read More... | 1885 bytes more | Score: 0)
Release NUKE Platinum
rjdias writes "NUKE Platinum developed and it is in the release of the version NUKE Platinum 7.6.b.4.v2.
The bugs were corrected, it is as good as the release of the version PHP NUKE 8.0.
The original liberation exists in www.futurenuke.com, and
a release in Portuguese from Brazil that can be found of www.nukeplatinumbrasil.net.br. "
Posted by Raven on Tuesday, June 09, 2009 @ 15:28:54 EDT (781 reads) (Read More... | 899 bytes more | Score: 0)