Thursday, November 5, 2009

Monetizing Life, Like Games, is Depressing...

Bye ... as you can see, I have not published much lately and find myself without the time or money to continue doing what is unpaid. So my Twitter account has been deleted, this blog going dormant...and on to something else...

Thursday, August 6, 2009

Top Ten Most Effective Tools Against Malware Binaries:

Sophos Labs
Microsoft Corporation
Grisoft Inc
Avira
Ikarus Security Software
Frisk Software International
Authentium
BitDefender Inc
Dr. Web
Kaspersky Lab

See SRI Malware Threat Center

Top Malware IP's to Block:

98.141.9.117
71.148.35.37
67.246.220.245
61.218.193.218
61.218.193.250
67.8.56.42
74.214.47.11
173.19.143.3
189.6.52.42
96.49.243.172

See SRI Malware Threat Center

Twitter Goin' Down Again...and Again...

Intermittently available at this time...

Potentially Exploitable Bugs from BugSpy

Potentially Exploitable Bugs

Twiki (critical severity): CSRF Fix for TWiki

Debian (critical severity): CVE-2009-2660: Multiple integer overflows

AltLinux (major severity): glusterfs: Buffer overflow on volume access

AbiWord (major severity): Other/Unknown: accessibility crashes everytime I open an

Debian (major severity): CVE-2009-2661: incomplete fix for CVE-2009-2185

Foswiki (normal severity): CSRF securing mechanisms anticipate the intranet installation of Foswiki

Gentoo (normal severity): Unspecified: hp-proliant-essentials license file is executable bit

Android (normal severity): Browser app is forced to terminate when access to a site with a 10MB gif image

Eclipse (minor severity): SQL Editor Framework: TVT35:TCT449: HUN - English strings in SQL Results window
Eclipse (minor severity): SQL Editor Framework: TVT35:TCT436: CHT: Duplicate mnemonic keys on Create SQL File wizard

Wednesday, August 5, 2009

Linux Bugs from BugSpy

Linux Kernel < 2.6.14.6 procfs Kernel Memory Disclosure Exploit

Debian (critical severity): ssl-cert: fails to install
Debian (critical severity): subversion: a succession of "svn up" can yield a working copy with local changes

AltLinux (critical severity): rp-pppoe-client: Зависит от устаревшено пакета modutils
AltLinux (critical severity): openoffice.org: DOS минут на 20 на некоторых документах из MS Office

Security Alerts (critical severity): Fedora update for firefox and xulrunner

SUSE Security Announcement Package: flash-player Announcement ID: SUSE-SA:2009:041

FreeBSD (major severity): java/linux-sun-jdk16: linux-sun-jre1.6.0 plugin doesn't work with a linux browser
FreeBSD (major severity): java/linux-sun-jre16: linux-sun-jre16 plugin doesn't work with linux-seamonkey
FreeBSD (major severity): [linux] [patch] Linux Emulation ENOTCONN error using non-blocking TCP

ATI Linux Drivers (stopper severity): Will you support the HD4670 boards in Linux (and linux-64bit)
ATI Linux Drivers (stopper severity): X Server: changed kernel on linux and machine just keeps resetting
ATI Linux Drivers (stopper severity): X Server: changed kernel on linux and machine just keeps resetting
ATI Linux Drivers (critical severity): 3D: Horrible texture quality in the Quake4 timedemo1 in Linux

NetBSD (major severity): pkgsrc: packages failed under Linux (PLIST problem) (version Linux)
NetBSD (major severity): devel/libgnome under Linux: 187 broken packages (version linux)

VirtualBox (major severity): 100% CPU usage on Linux host with single Linux guest


See BugSpy

Monday, July 20, 2009

Latest Exploits and Vulnerabilities Published:

KMplayer <= 2.9.4.1433 (.srt File) Local Buffer Overflow
powerUpload 2.4 (Auth Bypass) Insecure Cookie Handling
E-Xoopport 3.1 Module MyAnnonces (lid) SQLi
Soritong MP3 Player 1.0 (SKIN) Local Stack Overflow
Streaming Audio Player 0.9 (skin) Local Stack Overflow
Mozilla Firefox 3.5 (Font tags) Remote Heap Spray
Acoustica MP3 Audio Mixer 2.471(.m3u) Local Heap Overflow
Acoustica MP3 Audio Mixer 2.471 (.sgp file) Crash
Alibaba-clone CMS (SQL/bSQL) Remote SQLi
Medieval CUE Splitter Local Stack Overflow
wxWidgets 'wxImage::Create()' Integer Overflow
DD-WRT (httpd service) Remote Command Execution

See Milw0rm

ShareThis