SUSE Security Announcement – Flash Player
SUSE Security Announcement - Flash-Player was updated to version 10.3.188.5 to fix various buffer and integer overflows. Earlier flash-player versions can be exploited to...
Re: tabnapping
Posted by adam on Jun 09For anyone who is interested, Aza's original paper/demo can be found
here<http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/>
.
Source: Re: tabnapping
Winners of BackTrack Book Contest
Finally it is the time to announce the Winners of our recently concluded BackTrack book contest “Win Your Copy of “BackTrack 4: Assuring Security...
Ubuntu Security Notice USN-1193-1
Ubuntu Security Notice 1193-1 - Timo Warns discovered that the GUID partition parsing routines did not correctly validate certain structures. A local attacker with...
www.melbourneit.com.au XSS
OMGFAIL has discovered a vulnerability in www.melbourneit.com.au, which could be exploited by malicious people to conduct XSS attacks.
Source: www.melbourneit.com.au XSS
Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
This Metasploit module exploits a vulnerability in Real Networks Arcade Game's ActiveX control. The "exec" function found in InstallerDlg.dll (v2.6.0.445) allows remote attackers to...
[webapps] – IrIran Shoping Script SQL Injection Vulnerability
Source: - IrIran Shoping Script SQL Injection Vulnerability
ZDI-11-128: CA Total Defense Suite UnassignFunctionalUsers Stored Procedure SQL Injection Vulnerability
Posted by ZDI Disclosures on Apr 13ZDI-11-128: CA Total Defense Suite UnassignFunctionalUsers Stored Procedure SQL Injection Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-11-128
April 13, 2011
-- CVE ID:
CVE-2011-1653
-- CVSS:
10, (AV:N/AC:L/Au:N/C:C/I:C/A:C)
--...
Windows Security Renewal
Windows Security Renewal is a fake Antivirus. This rogue displays fake alerts to scare users. It replaces Windows Home Patron, Windows Virtual Firewall, Windows...
Attaque DDoS MegaMedusa : éclairage technique NETSCOUT
L’équipe ASERT de NETSCOUT a récemment analysé comment la Threat Intelligence peut contribuer à neutraliser l’efficacité d’une campagne d’attaques DDoS. Le cas de MegaMedusa...


