PLABS
softwareguidesstorewar roomaboutgo-home
Internet Storm Center Infocon Status
ISC StormCast for Monday, February 6th 2012 http://isc.sans.edu/podcastdetail.html?id=2305, (Mon, Feb 6th)
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Cybersecurity Legislation Components, (Sun, Feb 5th)
As many of us have seen in the media recently, the United States and other world governments are deeply entrenched in discussions over proposed cybersecurity le…

Apple Security Advisory 2012-001 v1.1, (Sat, Feb 4th)
Earlier today, Apple announced v 1.1 of the Security update 2012-001. The advisory announced the availability of Security Update for Mac OSX10.6.8 that addresse…

Sophos 2012 Security Threat Report, (Fri, Feb 3rd)
Last week Sophos released it 2012 Security Threat Report which highlighted some key finding from 2011: - Smartphones and tablets causing significant security ch…

ISC StormCast for Friday, February 3rd 2012 http://isc.sans.edu/podcastdetail.html?id=2302, (Fri, Feb 3rd)
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

PLABS Online Tools
World Clock
Reverse DNS Lookup (IP -> FQDN)


SecurityFocus
General Security Vulnerabilities
Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability
Pligg CMS 'status' Parameter SQL Injection Vulnerability…

Vuln: Mozilla Firefox/Thunderbird/SeaMonkey SVG Parsing Remote Code Execution Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey SVG Parsing Remote Code Execution Vulnerability…

Vuln: Joomla! Multiple Information Disclosure Vulnerabilities
Joomla! Multiple Information Disclosure Vulnerabilities…

Vuln: QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability
QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability…

Bugtraq: [ MDVSA-2012:013 ] mozilla
[ MDVSA-2012:013 ] mozilla…

Bugtraq: ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability
ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability…

Bugtraq: RFC 6528 on Defending against Sequence Number Attacks
RFC 6528 on Defending against Sequence Number Attacks…


Helpful Stuff
DShield.org Recommended Block List
This list summarized the top 20 attacking class C (/24) subnets over the last three days. The number of 'attacks' indicates the number of targets reporting scans from this subnet.
DShield.org Suspicious Domain List
GRC ShieldsUP!
Internet Vulnerability Profiling
Geo IP Location Service
This Geo Ip Location service (IP Address Map lookup service) is provided for FREE by Geobytes, Inc. to assist you in locating the geographical location of an IP Address.
IANA Port Number List
The port numbers are divided into three ranges: the Well Known Ports, the Registered Ports, and the Dynamic and/or Private Ports.
InterNIC Whois Search
A query and response protocol that is widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block, or an autonomous system.
Nessus
Latest Nessus Plugins Released
IBM WebSphere Application Server iscdeploy Script Insecure Permissions
Synopsis : The remote application server is susceptible to an insecure file permission vulnerability. Descri…

PHP 5.3.9 'php_register_variable_ex()' Code Execution
Synopsis : The remote web server uses a version of PHP that is affected by a code execution vulnerability. D…

IBM solidDB < 7.0 Fix Pack 1 / 6.5.0.8 Interim Fix 5 Denial of Service
Synopsis : The remote database server is affected by a denial of service vulnerability. Description : Accor…

RHSA-2012-0096: ghostscript
Synopsis : The remote host is missing the patch for the advisory RHSA-2012-0096 Description : Updated ghost…

RHSA-2012-0095: ghostscript
Synopsis : The remote host is missing the patch for the advisory RHSA-2012-0095 Description : Updated ghost…

Sourcefire
Vulnerability Research Team
Android.Counterclank: Malware or Adware?
This weekend I noticed a ComputerWorld article titled "Massive Android malware op may have infected 5 million…

A New Hope
Rep. Mike Rogers (R-MI) and Rep. Dutch Ruppersberger (D-MD) know a secret:  The Federal government is REA…

Cross-Platform Single-Request Web Server DoS From CCC
Security never sleeps, even if it is the week between Christmas and New Year's, and most of you are on vacatio…

Malware Mythbusting
The malware sandbox that I've previously discussed on this blog has made for a lot of useful Snort rules - but…

Microsoft Security Advisory 2639658
Microsoft recently added a new initiative to its Microsoft Active Protection Program (MAPP), called the Adviso…

RHEL
Red Hat Errata
RHEA-2012:0090-1: kexec-tools enhancement update
Red Hat Enterprise Linux: An updated kexec-tools package that adds one enhancement is now available for Red H…

RHSA-2012:0092-1: Critical: php53 security update
Red Hat Enterprise Linux: Updated php53 packages that fix one security issue are now available for Red Hat E…

RHSA-2012:0093-1: Critical: php security update
Red Hat Enterprise Linux: Updated php packages that fix one security issue are now available for Red Hat Ente…

RHSA-2012:0094-1: Important: freetype security update
Red Hat Enterprise Linux: Updated freetype packages that fix multiple security issues are now available for R…

RHSA-2012:0095-1: Moderate: ghostscript security update
Red Hat Enterprise Linux: Updated ghostscript packages that fix multiple security issues are now available fo…

Microsoft
Security Advisories
Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Version: 3.0
Revision Note: V3.0 (January 19, 2012): Revised to announce the release of an update for Windows Mobile 6.x, W…

Microsoft Security Advisory (2588513): Vulnerability in SSL/TLS Could Allow Information Disclosure - Version: 2.0
Revision Note: V2.0 (January 10, 2012): Advisory updated to reflect publication of security bulletin.

Microsoft Security Advisory (2659883): Vulnerability in ASP.NET Could Allow Denial of Service - Version: 2.0
Revision Note: V2.0 (December 29, 2011): Advisory updated to reflect publication of security bulletin.

Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege - Version: 2.0
Revision Note: V2.0 (December 13, 2011): Advisory updated to reflect publication of security bulletins.

Cisco
Security Advisories
DistroWatch
Latest Linux/BSD Distribution Releases Latest Linux/BSD Software Releases
02/04 Hanthana 15.5
Hanthana Linux is a Fedora remix suitable for desktop and laptop users. Hanthana comes in the form of a live D…
02/04 Netrunner 4.1
Netrunner is an Kubuntu-based distribution with a focus on desktop computing. It boasts a carefully tuned KDE…
02/04 Skolelinux 6.0.4-beta3
Skolelinux is the Debian-edu project's Custom Debian Distribution (CDD) in development. It is aiming to provid…
02/04 SimplyMEPIS 11.0.12
MEPIS Linux is a Debian-based desktop Linux distribution designed for both personal and business purposes. It…
02/04 KahelOS 020212
KahelOS is a Linux distribution based on Arch Linux. Its desktop edition comes with pre-configured GNOME as th…
02/04 Clonezilla 1.2.12-11
Clonezilla Live is a Debian-based live CD containing Clonezilla, a partition and disk cloning software similar…
02/03 Alpine 2.3.6
Alpine Linux is a community developed operating system designed for x86 routers, firewalls, VPNs, VoIP boxes a…
02/03 Salix 13.37 (Live Xfce)
Salix OS is a Slackware-based Linux distribution that is simple, fast, easy to use and compatible with Slackwa…
02/03 Mint 12 (KDE)
Linux Mint is an Ubuntu-based distribution whose goal is to provide a more complete out-of-the-box experience…
02/05 openshot 1.4.2
OpenShot: a video editor…
02/05 ImageMagick 6.7.5-2
ImageMagick: a software suite to create, edit, and compose bitmap images…
02/05 wicd 1.7.1
wicd: an open-source wired and wireless network manager for Linux…
02/05 cups 1.5.2
CUPS: a UNIX printing system based on the Internet Printing Protocol…
02/05 squid 3.1.19
Squid: a full-featured web proxy cache…
02/04 xine-lib 1.2.1
xine-lib: contains the libraries for xine, a free video player…
02/03 libvorbis 1.3.3
libvorbis: a free high-quality lossy audio codec library…
02/03 linux 3.2.4
Linux kernel: a UNIX clone written from scratch by Linus Torvalds…
02/02 php 5.3.10
PHP: a server-side HTML embedded scripting language…
Packet Storm
Latest Security Tool Files
Viper Network Sniffer Script
This is a bash script to use in conjunction with Backtrack that simplifies the spawning of various sniffers.

Port Tester 0.1
This is a simple little port scanning script written in python.

Dradis Information Sharing Tool 2.9.0
dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

WeBaCoo (Web Backdoor Cookie) 0.2.2
WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Ap…

Bluelog Bluetooth Scanner/Logger 1.0.1
Bluelog is a Bluetooth scanner/logger written with speed in mind. It is intended to be used as a site survey tool, concerned more about accurately detecting the number of discoverable Bluetooth devices than individual device specifics. Bluelog also includes the unique "Bluelog Live" mode, which puts discovered devices into a constantly updating liv…

GNU Privacy Guard 1.4.12
GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI,…

PgSql Brute Force
This is a small application built to demo the weakness in pgsql and networking. It is capable of running login attempts from multiple threads in parallel and can run up to 1024 concurrent connections.

HTTP Brute Force
This is a small application built to test the performance of a http authentication system using a lot of concurrent connections. It can also be used to try lots of password against a http server. It is capable of using up to 1024 (or more using multiple processes). However with this amount it is capable or reducing internet connections to a crawl a…

Lightidra IRC Router Scanner
Lightaidra is an IRC commanded tool that allows for scanning and exploiting routers. It also performs flooding.


© 2011 Procyon Labs / Randal T. Rioux

- advertisement -