Details of Major Internet Flaw Posted by Accident

Tuesday, July 22nd, 2008

The bug has to do with the way DNS clients and servers obtain information from other DNS servers on the Internet. When the DNS software does not know the numerical IP (Internet Protocol) address of a computer, it asks another DNS server for this information. With cache poisoning, the attacker ...

Facebook bug leaks members’ birthday data

Thursday, July 17th, 2008

A glitch in a test version of Facebook's Web site inadvertently exposed the birthdays of Facebook's 80 million members this week. The bug was discovered over the weekend by Graham Cluley, a senior technology consultant at Sophos. While checking out Facebook's new design, Cluley noticed that the birth dates of some ...

Critical vulnerability in BlackBerry Enterprise Server

Wednesday, July 16th, 2008

Crafted Portable Document Format files can allow an attacker to gain control of a BlackBerry server. According to a security advisory from BlackBerry vendor RIM, the bug is in the PDF Distiller component of the Attachment Service, which runs on the server and prepares PDF email attachments for display on ...

Finding the name behind a gmail address

Tuesday, July 15th, 2008

Ever wondered what name is behind some obscure gmail address? Maybe your preferred gmail address was taken and you’re wondering who took it? Here’s a cute vulnerability in the gmail system that comes from the strong tie-ins between gmail, the google calendar and all the other services. Source: http://blogs.securiteam.com/index.php/archives/1113

DoS vulnerability in Sophos antivirus products

Friday, July 11th, 2008

Antivirus software vendor Sophos has reported the discovery of a DoS vulnerability in some of its products. According to the security advisory, specially crafted attachments to emails can bring down Sophos E-mail Appliance, Pure Message for UNIX and Sophos Anti-Virus Interface (SAVI). For the attack to succeed, the MIME attachment ...