Thursday, July 31, 2008
An Astonishing Collaboration
read more | digg story
Thursday, May 29, 2008
Latest phishing schemes target Apple - SC Magazine US
read more | digg story
Friday, May 23, 2008
Three Cisco advisories released today
read more | digg story
Monday, March 31, 2008
Data Loss Prevention: Where Do We Go From Here?
read more | digg story
Apple Mac trojan horse aims to steal money from Mac users
read more | digg story
Friday, March 28, 2008
Apple less secure than Microsoft!
read more | digg story
Mac is the first to fall in Pwn2Own hack contest
read more | digg story
Thursday, March 27, 2008
Have iTunes? "Free" upgrade to vulnerable browser for you!
read more | digg story
Monday, March 24, 2008
No security software for Apple Macintosh?
read more | digg story
Wednesday, March 19, 2008
Technical Cyber Security Alert TA08-079A - Apple Updates for Multiple Vulnerabilities
National Cyber Alert System
Technical Cyber Security Alert TA08-079A
Apple Updates for Multiple Vulnerabilities
Original release date: March 19, 2008
Last revised: --
Source: US-CERT
Systems Affected
* Apple Mac OS X versions prior to and including 10.4.11 and 10.5.2
* Apple Mac OS X Server versions prior to and including 10.4.11
and
10.5.1
* Apple Safari prior to 3.1, including both OS X and
Windows
versions
Overview
Apple has released the Apple Security Update 2008-002 and Apple
Safari
3.1 to correct multiple vulnerabilities affecting Apple Mac OS X,
Mac
OS X Server, and Apple Safari. Attackers could exploit
these
vulnerabilities to execute arbitrary code, gain access to
sensitive
information, execute cross-site scripting attacks or cause a denial
of
service.
I. Description
Apple Security Update 2008-002 and Apple Safari 3.1 to address
a
number of vulnerabilities affecting Apple Mac OS X, OS X Server,
and
Safari. Further details are available in the US-CERT
Vulnerability
Notes Database.
II. Impact
The impacts of these vulnerabilities vary. Potential
consequences
include arbitrary code execution, sensitive information
disclosure,
cross-site scripting, and denial of service.
III. Solution
Install updates from Apple
Install Apple Security Update 2008-002. These and other updates
are
available via Software Update or via Apple Downloads.
IV. References
* US-CERT Vulnerability Notes for Apple Security Update 2008-002 -
* About the security content of Apple Security Update 2008-002 -
* About the security content of Safari 3.1 -
* Mac OS X: Updating your software -
* Apple Support Downloads -
_______________________________________________
ENT_CYBER_STF mailing list
ENT_CYBER_STF@listsmart.osl.state.or.us
http://listsmart.osl.state.or.us/mailman/listinfo/ent_cyber_stf
Hosted by the Oregon State Library (503)378-4246
Please use this contact for technical list questions only.
For informational questions related to message content, please contact the sender of the message, by phone or email.
Cyber Security Alert SA08-079A - Apple Updates for Multiple Vulnerabilities
Hash: SHA1
National Cyber Alert System
Cyber Security Alert SA08-079A
Apple Updates for Multiple Vulnerabilities
Original release date: March 19, 2008
Last revised: --
Source: US-CERT
Systems Affected
* Apple Mac OS X
* Apple Safari for Mac and Windows
Overview
Apple Mac OS X and Apple Safari are affected by multiple
vulnerabilities. Apple has released Security Update 2008-002 and
Safari 3.1 to address these vulnerabilities, the most serious of
which may allow a remote attacker to take control of your computer.
Solution
Install an Update
Use Software Update to install Apple Security Update 2008-002 or
Safari 3.1.
Description
Apple Mac OS X is affected by multiple vulnerabilities. These
vulnerabilities could allow an attacker to run malicious programs
on your computer, crash your computer, or access your data without
your approval.
For more technical information, see US-CERT Technical Alert
TA08-079A.
References
* US-CERT Technical Cyber Security Alert TA08-079A -
* Vulnerability notes for Apple Security Update 2008-002 -
* About the security content of Security Update 2008-002 -
* About the security content of Safari 3.1 -
* Mac OS X: Updating your software -
_________________________________________________________________
The most recent version of this document can be found at:
_________________________________________________________________
Feedback can be directed to US-CERT Technical Staff. Please send
email to
subject.
_________________________________________________________________
For instructions on subscribing to or unsubscribing from this
mailing list, visit
_________________________________________________________________
Produced 2008 by US-CERT, a government organization.
Terms of use:
____________________________________________________________________
Revision History
March 19, 2008: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBR+FiIvRFkHkM87XOAQIxVAf/ScYjb31IbAATwvPA1JpHNgQq/lUuXATt
kaTBFJBK1Ih1ZAy7ht/dh2B6ADCMeytokRGtdhEIGd74M8pPJNL2tXbP4EuhMiH9
Lis56P6HM8+wXxbGvl+fFs5MrNgxmvz++EL3LwlZlN+hR2d0J1w3Gxh/GbcPsSRa
3WvbLEpnTAXs+oDydwoe3MYGMTh9tTwj/g8rPX3t692plYVSiDV9R1a4oFKJfZEA
z6zNu9K4xfE2U6qxev87JxaJHyRv22rWk+jo2tXv3SDcnNNlMvjHaxGpQ29/xd1a
A5CcmQmDeyXHfvpL4TbCpmsIlvkbgkn69ujOg1rNHYMJWvdWlULq4A==
=Xs7c
-----END PGP SIGNATURE-----
Apple Safari Prior to 3.1 Multiple Security Vulnerabilities
read more | digg story
Macintosh Computers Increasingly Vulnerable to Comprimise
read more | digg story
Should Mac Users Run Antivirus Software?
read more | digg story
Tuesday, March 18, 2008
Holes In Your Programs And How They Can Help Install Rootkit
read more | digg story
Monday, March 17, 2008
We Don’t Need No Education
read more | digg story
Mac Vs. PC, how about Apache Vs. IIS?
read more | digg story
Thursday, March 6, 2008
Built-in Windows commands to determine if a system has been
read more | digg story
Wednesday, February 27, 2008
Data loss prevention (DLP) tools: The new way to prevent ide
read more | digg story
Customized security for virtual machines
read more | digg story
Wednesday, December 5, 2007
Cover-up: special investigator "cures" virus with 7-stage hard drive wipe
read more | digg story
Wednesday, November 7, 2007
SANS Internet Storm Center - Quicktime 7.3 patches serious security bugs
read more | digg story
Friday, October 26, 2007
Malicious PDF files being spammed out in volume - F-Secure Weblog : News fr
read more | digg story
Symantec Security Response Weblog: We pwn your Desktop!
read more | digg story
Wednesday, October 24, 2007
McAfee Avert Labs Blog - PDF mailto Exploit: Seen in wild today!
read more | digg story
Wednesday, May 30, 2007
Windows firewall squeezes into USB key
read more | digg story
Friday, April 20, 2007
Eight in ten major Web sites highly vulnerable to attack
April 19, 2007 (PC World) -- Eight out of ten Web sites contain common flaws that can allow attackers to steal customer data, create phishing exploits, or craft a variety of other attacks, a security company reported today.
WhiteHat Security regularly scans hundreds of "very popular, very high-traffic sites" for its online business customers, says Jeremiah Grossman, the company's founder. "More than likely, you have shopped there, or bank there," he says. Thirty percent of scanned sites contain an urgent vulnerability, such as one that allows direct access to a company database with customer information, he says.
Two out of three scanned sites have one or more cross-site scripting (XSS) flaws, which take advantage of problems with sites' programming and are increasingly used in phishing attacks. A recent eBay scam used a now-fixed XSS hole on the auction site to direct anyone who clicked on a phony car auction to a phishing site.
Monday, April 16, 2007
Glitch Gives Woman Access To Others' Turbo Tax Information
read more | digg story
Thursday, April 12, 2007
DVD Security Group Says It Fixed Flaws
read more | digg story
Friday, April 6, 2007
Researcher has new attack for embedded devices
It was only a matter of time. The attackers go after our networks, and we protect them with firewalls, IDS/IPS, and ect., they go after our applications and we firewall, proxy, and securly code them. Now our "little helper" devices have become our enemy. What will be next?
Monday, April 2, 2007
PHP Hash Table Overwrite Arbitrary Code Execution Vulnerability
read more | digg story
Exploiting Microsoft DNS Dynamic Updates for Fun and profit
read more | digg story
Microsoft Windows Animated Cursor Handling Vulnerability
read more | digg story
PHP Insecurity - Register_Globals = off
read more | digg story
Friday, March 30, 2007
And we are still using Microsoft IE becuase?
Microsoft confirms Windows zero-day, drive-by exploits by ZDNet's Ryan Naraine -- [UPDATE: March 29, 2007 @ 1:15 PM Eastern] Microsoft has confirmed that this is indeed a zero-day flaw that will require a security update. Although Internet Explorer is the primary attack vector, this is a vulnerability in the way Windows handles animated cursor (.ani) files. From Redmond's security advisory: The threat is caused by insufficient [...]
When will we learn... just one more zero day attack that has to be managed. Honestly it would take less time to "patch" IE by switching to Mozilla Firefox. I noticed recently that while Mozilla is not "bug" free the time it takes to patch a reported vulnerability is hours, or days, at most. Probably an advantage to NOT having the browser integrated into the OS?
Thursday, March 29, 2007
Dell pre-installing Linux. Chalk one up for the penquin!
http://www.engadget.com/2007/03/29/dell-were-going-linux-and-its-all-because-of-you/
It was only a matter of time. Chalk up one for the Penguin. IBM, and now Dell, who will be next. And, will Linux become a mainstream option? Say goodbye to the Microsoft "tax" on new PC's. It will be interesting to see how Microsoft reacts to this state of affairs?
Of course Microsoft may be ahead of, and in charge of, this change. Novell and Microsoft are playing nice lately and Dell will be distributing Novell's SuSE Linux correct? I wonder if Microsoft will be providing the license for the Dell Linux versions?
Friday, March 23, 2007
Heavy metal music linked with gifted students
read more | digg story
Thursday, March 22, 2007
Nokia N800 Internet Tablet
read more | digg story
Down with RIAA: Tomorrow is "Bum Rush the Charts" day for iTunes shoppers
read more | digg story
Wednesday, March 14, 2007
Microsoft executive: Pirating software? Choose Microsoft
read more | digg story
Friday, March 9, 2007
Total Information Awareness (TIA) is back now at Homeland Security
read more | digg story
Thursday, March 8, 2007
Wednesday, March 7, 2007
Commodore Returns With New Gaming PCs
Source: http://www.pro-g.co.uk/news/06-03-2007-4930-1.html
The Commodore 64 was a pivotal experience and what has led me to my current career as a technologist. The idea that this platform will be re-introduced gets my hopes up so high I wonder if the platform will be able to live up to my expectations?
I am drooling over the March 15th time frame when we will find out more about this exciting announcement!
Monday, March 5, 2007
Microsoft Hit By U.S. DOT Ban On Windows Vista, Explorer 7, and Office 2007
read more | digg story
Vista activation cracked by brute force
It is a simple brute force attack, dumb as a rock that just tries keys. If it gets one, you manually have to check it and try activation. Is is ugly, takes hours, is far from point and click, but it is said to work. I don't have any Vista installs because of the anti-user licensing so I have not tested it personally.
"To make matters worse, Microsoft will have to decide if it is worth it to allow people to take back legit keys that have been hijacked, or tell customers to go away, we have your money already, read your license agreement and get bent, we owe you nothing."
posted by Zonk on Friday March 02, @10:02 on /.
My thoughts...
Microsoft will HAVE to deal with this issue and provide replacement keys. If they do not the run the risk of having "legitimate" customers turning pirate and using crackers tools to activate software that was purchased legally.
Activation is a huge mess and will never be effective. Some would even say that it promotes piracy. If Microsoft wants to really stop the problem with illegal copies of it's software than they will have to price it reasonably. Is Vista a new product, or an upgrade the fixes problems with legacy code? I have six computers at home and paying upwards of $1800 to move all of them to Vista is not going to happen, I'll stick with Linux and XP thank you very much. Now for $600 I would gladly purchase Vista and install it on each and every machine.
Vista activation cracked by brute force
read more | digg story
Vista activation cracked by brute force
read more | digg story
CNN parent hit by bot worm
read more | digg story
Friday, March 2, 2007
Microsoft and Novell
Let's not kid ourselves the kind of movement that should be seen towards Linux as a desktop is just not happening. Well, that is probably about to change. But that is a longer view right now good things are happening on the Microsoft/Novell server environment.
Microsoft and Novell just announced that not only will SuSE Linux run virtualized on Windows server BUT Windows Longhorn (vaperware as yet?) will run paravitualized under XEN on SuSE. That is an earthquake my friends.
If that wasn't enough Microsoft and Novell are working togather on an open document translator that will allow Office, and OpenOffice, to share files transparently. Will wonders never cease.
I expect we will see many great collaborations between Microsoft and Novell in the future. Will Microsoft assimilate Novell? Maybe. Is this the end of Linux as we know it? Probably. Am I worried? Not at all.
Viva the end of the Revolution. Linux deserves to be mainstream and now it has a chance. After all can't you order a Dell PC with Linux pre-installed? Or can you... that is another blog my friends.
Good day
Thursday, March 1, 2007
Ubuntu "Feisty Fawn" a step closer
read more | digg story
Computer glitch triggered Dow Jones plunge
read more | digg story
Sun Strikes Back at Worm Targeting Telnet Bug
read more | digg story
And California Makes Four
read more | digg story
Dell censors IdeaStorm Linux dissent
read more | digg story
Dell censors IdeaStorm Linux dissent
read more | digg story
Tuesday, February 27, 2007
Konami Slot Machines display subliminal message of Wining Jackpot
read more | digg story
Thursday, February 22, 2007
Vista security overview: too little too late
read more | digg story
Wednesday, February 21, 2007
SuperNova Not - Storm Large lost in portland!
First, where is Storm Large? A big disapointment that we did not see her at the SuperNova concert in her home town. On second thought that show as of such poor quality that I would not have shown up either.
After watching the second "Rockstar" show "Rockstar SuperNova" I had high hopes for the concert Friday the 17th, 2007 at the Memorial Coliseum in Portland Oregon. Having gone to the extremely good Rockstar INXS concert we were excited for the show. Unfortunately Supernova is a SuperDUD. If you want 40 minutes of screaming this is the act for you.
The only saving grace for the show as when Magni and Delanna performed. They rocked and I would have wished that they were the headliners.