Microsoft confirms critical SQL Server vulnerability

Monday, December 22nd, 2008

Microsoft late Monday issued a pre-patch advisory confirming a remote code execution vulnerability affecting its SQL Server line. The vulnerability, publicly disclosed with exploit code more than two weeks ago, affects Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine ...

Firefox extension protects against man-in-the-middle attacks

Tuesday, August 26th, 2008

Researchers at Carnegie Mellon University have released an extension for Firefox 3 that can protect wireless network users from so-called "man-in-the-middle" attacks. The software, dubbed "Perspectives," is available for download for free. Perspectives also protects against attacks that exploit a recently exposed flaw in the DNS system, which translates Web addresses into ...

Trend Micro session token insufficiently random

Monday, August 25th, 2008

Secunia, the security services provider, has issued a security advisory about a vulnerability in Trend Micro's OfficeScan 8.0 and Worry-Free Business Security 5.0 that makes it easier for attackers to take control of the web management of those products. According to Secunia, the web-based configuration interface uses a pseudo-random token ...

SIPcrack – SIP Login Dumper & Hash/Password Cracker

Friday, August 1st, 2008

SIPcrack is a suite for sniffing and cracking the digest authentication used in the SIP protocol.The tools offer support for pcap files, wordlists and many more to extract all needed information and bruteforce the passwords for the sniffed accounts.If you don’t have OpenSSL installed or encounter any building problems try ...

Security fixes in new version of Joomla!

Wednesday, July 9th, 2008

The development team behind Joomla! has released version 1.5.4 of its content management system. This includes fixes for security problems, as well as numerous improvements and bug fixes. These include a patch for a problem with LDAP which allowed unauthorised access to Joomla! administration pages. The developers have also fixed ...