on

Attack On Apache Server Exposes Firewalls, Routers, Etc





on

Apache Hadoop Spins Cracking Code Injection Vulnerability YARN




on

Serious Apache Server Bug Gives Root To Baddies In Shared Environments




on

Contest Seeks The Most Diminutive XSS Worm




on

Attention Symantec - There Is A Bug Crawling On Your Website




on

Adobe Plagued By 16-Month-Old XSS Bug




on

RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence




on

XSS Vulnerabilities In 8 Million Flash Files




on

FreeBSD Intel SYSRET Privilege Escalation

This Metasploit module exploits a vulnerability in the FreeBSD kernel, when running on 64-bit Intel processors. By design, 64-bit processors following the X86-64 specification will trigger a general protection fault (GPF) when executing a SYSRET instruction with a non-canonical address in the RCX register. However, Intel processors check for a non-canonical address prior to dropping privileges, causing a GPF in privileged mode. As a result, the current userland RSP stack pointer is restored and executed, resulting in privileged code execution.




on

FreeBSD rtld execl() Privilege Escalation

This Metasploit module exploits a vulnerability in the FreeBSD run-time link-editor (rtld). The rtld unsetenv() function fails to remove LD_* environment variables if __findenv() fails. This can be abused to load arbitrary shared objects using LD_PRELOAD, resulting in privileged code execution.




on

macOS Kernel wait_for_namespace_event() Race Condition / Use-After-Free

In the macOS kernel, the XNU function wait_for_namespace_event() in bsd/vfs/vfs_syscalls.c releases a file descriptor for use by userspace but may then subsequently destroy that file descriptor using fp_free(), which unconditionally frees the fileproc and fileglob. This opens up a race window during which the process could manipulate those objects while they're being freed. Exploitation requires root privileges.







on

Hacker Almost Derailed Mandela Election In South Africa





on

Hackers Shut Down NDDC Website Over Presidential Inauguration






on

Ebola Outbreak Reaches City Of 1 Million Residents





on

Traffic Snags On Juniper Router Glitch





on

Juniper Bleeding Data And Money: Slaps Band-Aids All Over JunOS





on

Slackware Security Advisory - python Updates

Slackware Security Advisory - New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.




on

BlackBerry Users Get Free Remote Wipe, Backup And Location





on

Gadget-Hackers Post How-To On BlackBerry PlayBook Jailbreak













on

Blackberry In $1.4 Billion Deal To Buy Cylance





on

VMware Patches Privilege Escalation Vulnerability In Fusion, Horizon