ISC Stormcast For Friday, April 7th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleTracking Website Defacers with HTTP Referers, (Fri, Apr 7th)
In a previous diary, I explained how pictures may affect your website reputation[1]. Although asuggestedrecommendation was to prevent cross-linking by using the HTTP referer, this is a control that I...
View ArticleVuln: Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
View ArticleVuln: Ruby 'dl/handle.c' Security Bypass Vulnerability
Ruby 'dl/handle.c' Security Bypass Vulnerability
View ArticleVuln: HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
View ArticleVuln: LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
View ArticleVuln: Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML...
Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
View ArticleBugtraq: SEC Consult SA-20170407-0 :: Server-Side Request Forgery in MyBB forum
SEC Consult SA-20170407-0 :: Server-Side Request Forgery in MyBB forum
View ArticleVuln: Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
View ArticleVuln: Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure...
Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure Vulnerability
View ArticleDo you want to play a game? Ransomware asks for high score instead of money
Rensenware's warning screen asks for a high score, rather than the usual pay off, to decrypt your files. At this point, Ars readers have heard countless tales of computer users being forced to pay...
View ArticleVuln: ImageWorsener 'iwgif_record_pixel()' Function Denial of Service...
ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
View ArticleVuln: WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
View ArticleVuln: ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service...
ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
View ArticleVuln: Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
View ArticleWikiLeaks just dropped the CIA’s secret how-to for infecting Windows
Enlarge / The logo of the CIA's Engineering Development Group (EDG), the home of the spy agency's malware and espionage tool developers. (credit: Central Intelligence Agency) WikiLeaks has published...
View ArticleVuln: Firejail CVE-2017-5207 Local Privilege Escalation Vulnerability
Firejail CVE-2017-5207 Local Privilege Escalation Vulnerability
View ArticleBooby-trapped Word documents in the wild exploit critical Microsoft 0day
(credit: Rob Enslin) There's a new zeroday attack in the wild that's surreptitiously installing malware on fully-patched computers. It does so by exploiting a vulnerability in most or all versions of...
View ArticleDomain Whitelisting With Alexa and Umbrella Lists, (Sat, Apr 8th)
I read an interesting blogpost: Domain Whitelist Benchmark: Alexa vs Umbrella The author reported that around 1400 domains on Malwarebytes hpHosts EMD blacklist were in the top 1,000,000 domains Alexa...
View Article