Twitter
RSS

Posts Tagged ‘fbi’


CVE-2013-2094: Linux privilege escalation, (Tue, May 14th)

A vulnerability was discovered using fuzzing in linux kernels 2.6.37 till 3.8.9. The vulenrability requires the kernel to be compiled with PERF_EVENTS, but unfortunately that seems the case for quite some linux distributions

Read More...

Firefox & Thunderbird released, (Tue, May 14th)

Mozilla decided to join the mayhem on Black Tuesday this month and released Firefox and Thunderbird. This updates to: Firefox 21.0 Firefox ESR 17.0.6 Thunderbird 17.0.6 Thunderbird ESR 17.0.6 Release notes: https://www.mozilla.org/security/known-vulnerabilities/firefox.html Security content o fthe updates: MFSA 2013-48 Memory corruption found using Address Sanitizer CVE-2013-1676 , CVE-2013-1677 , CVE-2013-1678 , CVE-2013-1679 , CVE-2013-1680 and CVE-2013-1681 MFSA 2013-47 Uninitialized functions in DOMSVGZoomEvent CVE-2013-1675 MFSA 2013-46 Use-after-free with video and onresize event CVE-2013-1674 MFSA 2013-45 Mozilla Updater fails to update some Windows Registry entries CVE-2013-1673 and CVE-2012-1942 MFSA 2013-44 Local privilege escalation through Mozilla Maintenance Service CVE-2013-1672 MFSA 2013-43 File input control has access to full path CVE-2013-1671 MFSA 2013-42 Privileged access for content level constructor CVE-2013-1670 MFSA 2013-41 Miscellaneous memory safety hazards (rv:21.0 / rv:17.0.6) CVE-2013-0801 and CVE-2013-1669   — Swa Frantzen — Section 66 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read More...

Microsoft May 2013 Black Tuesday Overview, (Tue, May 14th)

Overview of the May 2013 Microsoft patches and their status. # Affected Contra Indications – KB Known Exploits Microsoft rating (**) ISC rating (*) clients servers MS13-037 The usual monthly MSIE cumulative patch, adding fixes for 11 more vulnerabilities. All but one are use after free vulnerabilities

Read More...

So what passwords are those ssh scanners trying?, (Tue, May 14th)

If you run an ssh server (especially if you still run it on the default port), you've no doubt had plenty of folks scan your machine and do password guessing attacks against it.  BTW, you'll never get in mine that way, I only allow public/private key authentication, but that is beside the point here.  I've done a couple of other reports analyzing passwords, and I really like pipal by Robin Wood for much of the analysis (you can grab it from here ).  I've been running a kippo ssh honeypot for the day job for about 2 years and I've done a couple of reports on the password guesses for the ThreatTraq webcast, but then I discovered that in addition to firewall logs and the 404 logs, we also collect kippo logs here at the SANS Internet Storm Center.  Ooh, more data!!  If you'd like contribute, please grab https://isc.sans.edu/kipposcript.pl .  So, without further ado, here is what I've found in our kippo data (as of about 15 April 2013).  I should note here, though, that these are the guesses the bad guys are making.  They've developed their lists most likely based on what has worked for someone at some point, so they will be somewhat different from what you find in analyzing passwords from breaches like my analysis of last year's Yahoo breach .

Read More...

ISC StormCast for Monday, May 13th 2013 http://isc.sans.edu/podcastdetail.html?id=3302, (Mon, May 13th)

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read More...

Extracting Digital Signatures from Signed Malware, (Sat, May 11th)

Sometimes attackers digitally sign their malicious software. Examining properties of the signature helps malware analysts understand the context of the incident.

Read More...

UPDATEDx1: Boston-Related Malware Campaigns Have Begun – Now with Waco Plant Explosion Fun, (Wed, Apr 17th)

UPDATE: 04-18-2013 @ 10:10 AM CDT – Some of the spam campaigns are now changing over to the Waco plant explosion. Basically the lure is the same, a subject that talks mentions the video and then an IP only url with /texas.html or /news.html.  The landing page has a few embedded YouTube videos and an iframe with malicious content at the end.

Read More...

Boston-Related Malware Campaigns Have Begun, (Wed, Apr 17th)

About mid-afternoon yesterday (Central time – US), Boston related spam campaigns have begun. The general “hook” is that it sends a URL with a subject about the video from the explosions. Similar to when Osama Bin Laden was killed and fake images were used as a hook, in this case, the video is relevant to the story and being used as a hook

Read More...

OperationKorea: Hana Bank of Korea Hacked, Database leaked

“Famous Hackers with the handle DigitalBoysUG have hacked the Hana Bank of Korea website (http://www. hanabank. com/) under Anonymous flag and named the operation #Operation Korea….”

Read More...

Israeli Hacker Retaliates, Hacks OpIsrael.com Website

“Israeli Hackers Retaliates on #OpIsrael, OpIsrael.

Read More...