Posted on Thursday, July 20, 2006 @ 23:11:45 CDT in Security by Raven
nb1 writes: Managed IT security services provider SecureWorks announced Tuesday that they have seen a significant rise in the number of attempted SQL injection hacks aimed at some of its financial and utility company clients over the last three months. “From January through March, we blocked anywhere from 100 to 200 SQL Injection attacks per day,” said SecureWorks CTO Jon Ramsey. “As of April, we have seen that number jump from 1,000 to 4,000 to 8,000 per day,” said Ramsey.
“The majority of the attacks are coming from overseas," said Ramsey. “And although we certainly see a higher volume with other types of attacks, what makes the SQL Injection exploits so worrisome is that they are often indicative of a targeted attack.” This is a type of attack where the hacker has targeted a particular organization, versus a worm which spreads indiscriminately.
“The CardSystems security breach, where hackers stole 263,000 customer credit card numbers and exposed 40 million more, is a prime example of a SQL Injection attack,” said Ramsey. A more recent example of a SQL Injection attack occurred last December when Russian hackers broke into a Rhode Island government Web site and stole credit card information from individuals who had done business online with state agencies. The Russian hackers claimed to have stolen 53,000 credit card numbers during this attack.
SecureWorks
|
Posted on Wednesday, July 19, 2006 @ 09:45:51 CDT in Security by Raven
TITLE: Symantec pcAnywhere CIF Files Privilege Escalation
SECUNIA ADVISORY ID: SA21113
VERIFY ADVISORY: http://secunia.com/advisories/21113/
CRITICAL: Less critical
IMPACT: Privilege escalation
WHERE: Local system
SOFTWARE: Symantec pcAnywhere 12.x
http://secunia.com/product/11089/
DESCRIPTION: Zee has reported a security issue in Symantec pcAnywhere, which can be exploited by malicious, local users to gain escalated privileges. The problem is caused due to CIF files containing a superuser flag and being stored insecurely by default in "Documents and SettingsAll UsersApplication DataSymantecpcAnywhereHosts" where any user can read the contents of files and create new files. This can be exploited to gain administrative user privileges via pcAnywhere by crafting a new CIF file, setting the superuser flag, and placing the file in the "Hosts" directory.
The security issue has been reported in version 12.5. Other versions may also be affected.
SOLUTION: Grant only trusted users access to affected systems.
PROVIDED AND/OR DISCOVERED BY: Zee
ORIGINAL ADVISORY: http://www.digitalbullets.org/?p=3
|
Posted on Tuesday, July 18, 2006 @ 12:36:14 CDT in Security by Raven
Reprinted from http://nukescripts.net
This has been verified on Snopes.com (exact link listed below) and by the FBI (their link is also included below).
It is spreading fast so be prepared should you get this call. Most of us take those summons for jury duty seriously, but enough people skip out on their civic duty that a new and ominous kind of scam has surfaced.
Fall for it and your identity could be stolen, reports CBS. In this con, someone calls pretending to be a court official who threateningly says a warrant has been issued for your arrest because you didn't show up for jury duty. The caller claims to be a jury coordinator. If you protest that you never received a summons for jury duty, the scammer asks you for your Social Security number and date of birth so he or she can verify the information and cancel the arrest warrant. Sometimes they even ask for credit card numbers. Give out any of this information and bingo! Your identity just got stolen.
The scam has been reported so far in 11 states, including Oklahoma, Illinois, and Colorado. This (scam) is particularly insidious because they use intimidation over the phone to try to bully people into giving information by pretending they're with the court system. The FBI and the federal court system have issued nationwide alerts on their web sites, warning consumers about the fraud.
Check it out here:
Snopes
FBI
|
Posted on Tuesday, July 18, 2006 @ 11:25:23 CDT in Security by Raven
TITLE: PHP Event Calendar "path_to_calendar" File Inclusion
SECUNIA ADVISORY ID: SA21074
VERIFY ADVISORY: http://secunia.com/advisories/21074/
CRITICAL: Highly critical
IMPACT: System access
WHERE: >From remote
SOFTWARE: PHP Event Calendar 1.x
http://secunia.com/product/7964/
DESCRIPTION: Solpot has reported a vulnerability in PHP Event Calendar, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "path_to_calendar" parameter in cl_files/calendar.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.
The vulnerability has been reported in version 1.4. Other versions may also be affected.
SOLUTION: Update to version 1.5.1.
PROVIDED AND/OR DISCOVERED BY: Solpot
ORIGINAL ADVISORY: http://www.solpotcrew.org/adv/solpot-adv-01.txt
|
Posted on Tuesday, July 18, 2006 @ 11:17:02 CDT in Security by Raven
TITLE: phpBB Mail2Forum Module "m2f_root_path" File Inclusion
SECUNIA ADVISORY ID: SA21083
VERIFY ADVISORY: http://secunia.com/advisories/21083/
CRITICAL: Highly critical
IMPACT: System access
WHERE: >From remote
SOFTWARE: Mail2Forum 1.x (module for phpBB)
http://secunia.com/product/11080/
DESCRIPTION: OLiBekaS has reported a vulnerability in the Mail2Forum module for phpBB, which can be exploited by malicious people to compromise a vulnerable system. Input passed to the "m2f_root_path" parameter in m2f/m2f_phpbb204.php, m2f/m2f_forum.php, m2f/m2f_mailinglist.php, and m2f/m2f_cron.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.
Successful exploitation requires that "register_globals" is enabled.
The vulnerability has been reported in version 1.2. Other versions may also be affected.
SOLUTION: Edit the source code to ensure that input is properly verified.
PROVIDED AND/OR DISCOVERED BY: OLiBekaS
ORIGINAL ADVISORY: http://milw0rm.com/exploits/2019
|
forgotz writes: Having been approximately 4 months now, I must say am absolutely pleased with
Linux (Mandriva Linux 2006). As mentioned
in a
previous entry. I really just had gotten fed up with Microsoft products and
Windows specifically. Also this whole 'legitimized' business model
of spy ware/ad ware. It has in my opinion, become a de facto conspiracy between
major software publishers, computer manufacturers, first tier marketers and
technical support regimes. I see the ads on local cable network for computer
repair (or should I say, install Spybot, Ad-Aware and run scans), I wonder if
these guys get it? Or do they and are merely taking advantage of an
opportunity? Read More...
|