Archive for the ‘Software’ Category

Firefox 3.0.1 More Secure and Stable

Wednesday, July 16th, 2008

In Firefox's Help menu choose Check for Updates to download Firefox 3.0.1, a minor update that fixes Firefox 3's most common causes of crashes. This update won't cause any add-on incompatibilities. Source: http://lifehacker.com/398700/firefox-301-out-now-more-security-and-stability

Critical vulnerability in BlackBerry Enterprise Server

Wednesday, July 16th, 2008

Crafted Portable Document Format files can allow an attacker to gain control of a BlackBerry server. According to a security advisory from BlackBerry vendor RIM, the bug is in the PDF Distiller component of the Attachment Service, which runs on the server and prepares PDF email attachments for display on ...

Finding the name behind a gmail address

Tuesday, July 15th, 2008

Ever wondered what name is behind some obscure gmail address? Maybe your preferred gmail address was taken and you’re wondering who took it? Here’s a cute vulnerability in the gmail system that comes from the strong tie-ins between gmail, the google calendar and all the other services. Source: http://blogs.securiteam.com/index.php/archives/1113

DNS Protocol Flaw: Don`t Panic, Just Patch

Monday, July 14th, 2008

The exploit discovered by IOActive's Dan Kaminsky, takes advantage of a fundamental flaw in the DNS (Domain Name Server) protocol. Organizations should move quickly to patch vulnerable DNS servers against a flaw revealed last week. Dan Kaminsky said the bug can be exploited to redirect Internet traffic, but the problem ...

FWAuto v1.1 - Firewall Auditing & Ruleset Analyzer Tool

Monday, July 14th, 2008

FWAuto (Firewall Rulebase Automation) is a Perl script and should work on any system with Perl installed. Provide the running config of a PIX firewall to fwauto. It will analyze and give you a list of weak rules in your rule base and store the result in multiple output files. Maybe ...

DoS vulnerability in Sophos antivirus products

Friday, July 11th, 2008

Antivirus software vendor Sophos has reported the discovery of a DoS vulnerability in some of its products. According to the security advisory, specially crafted attachments to emails can bring down Sophos E-mail Appliance, Pure Message for UNIX and Sophos Anti-Virus Interface (SAVI). For the attack to succeed, the MIME attachment ...

ZoneAlarm updated after Microsoft’s DNS patch

Thursday, July 10th, 2008

On Thursday, Check Point Software Technologies released updated versions of all its ZoneAlarm products, addressing an incompatibility with a patch Microsoft released earlier this week.The fix requires ZoneAlarm users to download the latest version, 7.0.438.000, from its site. A reboot is required to complete installation.Since Tuesday, ZoneAlarm customers have complained ...

Updates for Java eliminate many security holes

Thursday, July 10th, 2008

Sun Microsystems has issued updates for Java to eliminate many errors and vulnerabilities in the Java Development Kit (JDK) and the Java Runtime Environment (JRE). These include DoS vulnerabilities, buffer overflows and other errors that could cause a crash or allow a crafted applet to access certain resources, the filing ...

Zero day Word flaw exploited by Trojan

Wednesday, July 9th, 2008

Microsoft warns that an unpatched Word vulnerability has become the subject of targeted attacks.The flaw - which is restricted to Microsoft Office Word 2002 Service Pack 3 - creates a mechanism for hackers to inject hostile code onto vulnerable systems. Redmond has published workarounds as a stop-gap measure while its ...

Microsoft DNS Security Fix Knocks ZoneAlarm Users Offline

Wednesday, July 9th, 2008

The problem began when Microsoft on Tuesday sent patch number KB951748 to Windows users. The patch is designed to plug a security vulnerability that leaves computers vulnerable to so-called DNS attacks.The vulnerability is widespread and affects products made by numerous networking and software vendors beyond Microsoft. It was discovered by ...