(Posted 26 Jul 2011 by falko)
Security Revealed
(Posted 26 Jul 2011 by falko)
Perhaps you’ve heard the news? JailbreakMe 3.0 went live yesterday. What’s JailbreakMe? It’s an easy way to jailbreak an Apple iOS device using a PDF (related) vulnerability.It’s done with a “drive-by” style exploit.All somebody needs to ja…
Vulnerability Summary for the Week of July 11, 2011
Vulnerability Summary for the Week of July 18, 2011
Oracle Updates for Multiple Vulnerabilities
Compression of files is a necessity these days. It’s not only helps you in saving your space but also helps you in quick sharing and back up purposes. Text files compresses more than the web images and videos because they are already in the compresse…
Computer World: ‘War Texting’ SMS attack to steal a car or control SCADA systems?
[Frank] sent in a link to this fantastic wooden clock. The design was dreamed up by [Clayton Boyer] and he’s got full-sized templates for sale on his site. We’ve marveled at his creations in the past, having featured his useless machine that was made from wooden gears. This “Bird of Paradise” clock steps up the [...]![]()
Installing Subversion And Configuring Access Through Different Protocols On Debian Squeeze
Subversion
(svn) is an open-source version control system (VCS), used in the
development of many software projects. This tutorial shows how to
install Subver…
(Posted 26 Jul 2011 by finid)
Nothing says Cold War like a map of the work with LEDs embedded in it. Throw in some analog dials for good measure and you’ve got a piece that would be comfortable mounted next the WOPR in everyone’s favorite ’80s-computers-run-amok movie. We think [Dima] really hit the mark when building this status panel for OpenDNS [...]![]()
An interview with Linux Mint leader Clement Lefebvre about his desktop Linux setups. If you’ve ever wondered what goes into creating Linux Mint, this is a good place to start.
Microsoft Updates for Multiple Vulnerabilities
In this episode of Founder Stories;, Chris Dixon sits down with Thrillist Co-founder and CEO, Ben Lerer (who is also a partner with his father Ken Lerer in Lerer Ventures). Targeted towards young men, Thrillist is a “platform for guys” that offers “both local and national content and commerce smooshed into one place” says Lerer.
Inspired by Bob Pitman’s Daily Candy (Pitman is an early investor in Thrillist), Lerer founded Thrillist a couple years out of college. Before he figured out that he wanted to create a city guide for guys, he and his co-founder went through a lot of “get rich quick schemes” with the common thread that they knew nothing about any of them. The only thing they really knew about was “frivolous fun and buying stupid shit.” And thus Thrillist was born. A guide for guys with the voice of a national men’s magazine but a local focus.
![]()
(Posted 27 Jul 2011 by aweber)
[Frank], like many people, has a soft spot in his heart for the Commodore 64. He prefers to play his C64 games on his computer nowadays, but likes using his old school Competition Pro rather than some modern controller with remapped buttons. The only problem with using the controller is that his new computer doesn’t [...]![]()
ndisc6 consists of three command line tools (ndisc6, rdisc6, and traceroute6) that perform ICMPv6 Neighbor Discovery, ICMPv6 Router Discovery, and IPv6 tcptraceroute/traceroute respectively. It is primarily meant for IPv6 networking diagnostics and mon…
This Metasploit module exploits a stack-based buffer overflow in Actfax FTP Server versions 4.27 and earlier. Actfax fails to check input size when parsing ‘USER’ command. This vulnerability results in arbitrary code execution. This Metasploit module h…
Hong Kong Firms Internet Services CMS suffers from multiple remote SQL injection vulnerabilities.
Digital Scribe version 1.5 suffers from multiple post cross site scripting vulnerabilities. Input thru the POST parameters ‘title’, ‘last’ and ‘email’ in register.php is not sanitized allowing the attacker to execute HTML code into user’s browser sessi…
The Silver Bullet 2011 Call For Papers has been announced. It will be held from November 12th through the 13th, 2011 in Sao Paulo, Brazil.
(Posted 27 Jul 2011 by falko)
(Posted 28 Jul 2011 by falko)
The Call For Papers for ClubHack 2011 has been announced. For a full list of topics and more information on the convention, hit the home page.
Rebound suffers from local file inclusion and remote SQL injection vulnerabilities. A SQL injection vulnerability allows for authentication bypass.
Elgg versions 1.7.9 and below suffer from multiple cross site scripting vulnerabilities.
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Jun | Aug » | |||||
| 1 | 2 | 3 | ||||
| 4 | 5 | 6 | 7 | 8 | 9 | 10 |
| 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| 18 | 19 | 20 | 21 | 22 | 23 | 24 |
| 25 | 26 | 27 | 28 | 29 | 30 | 31 |
