Numerous vulnerabilities in VMware products

Tuesday, November 24th, 2009

VMware has advised of a total of 93 vulnerabilities in several of its products, including ESX Server, Server, VirtualCenter and vCenter. Most of the vulnerabilities are in Java, Tomcat and the kernel and have been known for some time. Some of them can be exploited to compromise a system, however, ...

Metasploit 3.3 released

Wednesday, November 18th, 2009

Nearly one year after the release of Metasploit 3.2, the Metasploit Project developers have announced the availability of version 3.3 of the Metasploit Framework. The comprehensive programming framework for developing exploits for vulnerabilities is used by security researchers, penetration testers and black hat crackers alike. The latest release includes a ...

New Flash Attack Has No Real ‘Fix’

Friday, November 13th, 2009

Researchers have discovered a new attack that exploits the way browsers operate with Adobe Flash -- and there's no simple patch for it. The attack can occur on Websites that accept user-generated content -- anything from Webmail to social networking sites. An attacker basically takes advantage of the fact that a ...

Critical Flaw Found in Linux Kernel

Thursday, November 5th, 2009

There is a NULL pointer dereference flaw in the Linux kernel that can be exploited by attackers to gain root access to a vulnerable machine.The vulnerability is in version 2.6.21 of the Linux kernel and some Linux vendors already have taken steps to fix the vulnerability. Red Hat has released ...

Scrawlr – Tool for finding SQL Injection

Wednesday, October 28th, 2009

Scrawlr, developed by the HP Web Security Research Group in coordination with the MSRC, is short for SQL Injector and Crawler. Scrawlr will crawl a website while simultaneously analyzing the parameters of each individual web page for SQL Injection vulnerabilities. Scrawlr is lightning fast and uses our intelligent engine technology ...