ot Microsoft Windows Unquoted Service Path Privilege Escalation By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 20:01:59 GMT This Metasploit module exploits a logic flaw due to how the lpApplicationName parameter is handled. When the lpApplicationName contains a space, the file name is ambiguous. Take this file path as example: C:program fileshello.exe; The Windows API will try to interpret this as two possible paths: C:program.exe, and C:program fileshello.exe, and then execute all of them. To some software developers, this is an unexpected behavior, which becomes a security problem if an attacker is able to place a malicious executable in one of these unexpected paths, sometimes escalate privileges if run as SYSTEM. Some software such as OpenVPN 2.1.1, OpenSSH Server 5, and others have the same problem. Full Article
ot The US Shot Down A Mysterious Enemy Drone Over Syria By packetstormsecurity.com Published On :: Mon, 12 Jun 2017 14:23:08 GMT Full Article headline usa cyberwar syria
ot Patriotic Hackers Face Off In South China Sea By packetstormsecurity.com Published On :: Fri, 27 Apr 2012 14:46:33 GMT Full Article headline china cyberwar philippines
ot 55 Million Voters' Details Leaked In The Philippines By packetstormsecurity.com Published On :: Thu, 07 Apr 2016 14:01:52 GMT Full Article headline hacker government privacy data loss philippines
ot Philippines Elections Hack 'Leaks Voter Data' By packetstormsecurity.com Published On :: Tue, 12 Apr 2016 00:24:50 GMT Full Article headline hacker data loss philippines
ot FCKEditor 2.6.8 ASP File Upload Protection Bypass By packetstormsecurity.com Published On :: Wed, 28 Nov 2012 01:33:11 GMT FCKEditor version 2.6.8 ASP version suffers from a file upload protection bypass. Full Article
ot LW-N605R Remote Code Execution By packetstormsecurity.com Published On :: Mon, 10 Sep 2018 20:22:22 GMT LW-N605R devices allow remote code execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases. Full Article
ot Telerik UI Remote Code Execution By packetstormsecurity.com Published On :: Wed, 18 Dec 2019 14:03:55 GMT The Telerik UI for ASP.NET AJAX insecurely deserializes JSON objects in a manner that results in arbitrary remote code execution on the software's underlying host. Full Article
ot Dutch Police Use Unusual Tactics In Botnet Battle By packetstormsecurity.com Published On :: Wed, 27 Oct 2010 09:59:39 GMT Full Article government botnet netherlands
ot Dutch Courts: Wi-Fi Hacking Is Not A Crime By packetstormsecurity.com Published On :: Mon, 21 Mar 2011 15:27:12 GMT Full Article headline hacker wireless netherlands
ot Microsoft And Mozilla Ban Dutch Government Root Certificate By packetstormsecurity.com Published On :: Wed, 07 Sep 2011 14:37:21 GMT Full Article headline microsoft ssl mozilla netherlands
ot Fortezza Pleads Not Guilty To Mass Credit Card Theft By packetstormsecurity.com Published On :: Tue, 12 Jun 2012 15:36:23 GMT Full Article headline hacker bank usa cybercrime scam netherlands
ot Grum Botnet Loses Dutch Servers By packetstormsecurity.com Published On :: Wed, 18 Jul 2012 15:28:08 GMT Full Article headline cybercrime botnet netherlands
ot Netherlands Reverts To Hand-Counted Votes To Quell Security Fears By packetstormsecurity.com Published On :: Thu, 02 Feb 2017 13:54:57 GMT Full Article headline government fraud cyberwar netherlands
ot Dutch Vote To Grant Intel Agencies New Surveillance Powers By packetstormsecurity.com Published On :: Thu, 13 Jul 2017 13:49:11 GMT Full Article headline government privacy spyware netherlands
ot Police Swoop On Suspected Darknet Fake Banknote Buyers By packetstormsecurity.com Published On :: Mon, 16 Dec 2019 15:18:09 GMT Full Article headline bank cybercrime fraud
ot TrickBot Banking Trojan Introduces RDP Brute Forcing Module By packetstormsecurity.com Published On :: Fri, 20 Mar 2020 15:11:58 GMT Full Article headline hacker malware bank cybercrime fraud
ot New Mirai Botnet Lurks In The Tor Network By packetstormsecurity.com Published On :: Thu, 01 Aug 2019 16:47:50 GMT Full Article headline malware botnet
ot Author Of Multiple IoT Botnets Pleads Guilty By packetstormsecurity.com Published On :: Wed, 04 Sep 2019 13:52:53 GMT Full Article headline hacker government botnet
ot IoT Malware Forces Wi-Fi Routers To Join Botnet Army By packetstormsecurity.com Published On :: Thu, 31 Oct 2019 14:20:33 GMT Full Article headline malware botnet
ot Naive IoT Botnet Wastes Its Time Mining Cryptocurrency By packetstormsecurity.com Published On :: Wed, 08 Jan 2020 16:25:55 GMT Full Article headline malware botnet cryptography
ot New Mirai Botnet Variant Targets NAS Devices By packetstormsecurity.com Published On :: Fri, 20 Mar 2020 15:11:55 GMT Full Article headline malware botnet
ot New Dexphot Malware Infected More Than 80,000 Computers By packetstormsecurity.com Published On :: Tue, 26 Nov 2019 17:33:37 GMT Full Article headline malware microsoft
ot Microsoft Takes Down Global Zombie Bot Network By packetstormsecurity.com Published On :: Wed, 11 Mar 2020 13:51:19 GMT Full Article headline microsoft botnet
ot Telnet Backdoor Opens More Than 1M IoT Radios To Hijack By packetstormsecurity.com Published On :: Mon, 09 Sep 2019 23:41:20 GMT Full Article headline flaw backdoor
ot Hotel Booking Sites Come Under Fire From Magecart By packetstormsecurity.com Published On :: Fri, 20 Sep 2019 14:43:51 GMT Full Article headline privacy bank cybercrime data loss fraud backdoor
ot TrickBot Hackers Create New Stealthy Backdoor By packetstormsecurity.com Published On :: Fri, 10 Jan 2020 15:30:56 GMT Full Article headline malware backdoor
ot IBM Scientists Unveil Racetrack Memory Chip Prototype By packetstormsecurity.com Published On :: Tue, 06 Dec 2011 15:58:38 GMT Full Article headline ibm science
ot Cisco And Others Take A Hit In China Due To Spy Scandal By packetstormsecurity.com Published On :: Fri, 15 Nov 2013 03:12:09 GMT Full Article headline government microsoft ibm usa china cisco spyware nsa
ot IBM: We Gave NOTHING To The NSA, Stateside Or Elsewhere By packetstormsecurity.com Published On :: Mon, 17 Mar 2014 15:03:30 GMT Full Article headline government privacy ibm usa nsa
ot FBI Program Offers Companies Data Protection Via Deception By packetstormsecurity.com Published On :: Sat, 21 Dec 2019 06:48:46 GMT Full Article headline government usa fraud fbi
ot Vietnamese Dissidents Targeted By Botnet Attacks By packetstormsecurity.com Published On :: Wed, 31 Mar 2010 16:53:50 GMT Full Article botnet vietnam
ot TrickBot Gang Is Now Supplying North Korea By packetstormsecurity.com Published On :: Wed, 11 Dec 2019 16:43:58 GMT Full Article headline government malware cyberwar korea
ot Apache Shiro 1.2.4 Remote Code Execution By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:05:16 GMT This Metasploit module exploits a vulnerability that allows remote attackers to execute arbitrary code on vulnerable installations of Apache Shiro version 1.2.4. Full Article
ot Half Dozen Security Experts Boycott RSA Over NSA Deal By packetstormsecurity.com Published On :: Wed, 08 Jan 2014 16:05:36 GMT Full Article headline privacy nsa conference cryptography rsa
ot RSA Bans Booth Babes By packetstormsecurity.com Published On :: Fri, 27 Mar 2015 14:11:24 GMT Full Article headline conference rsa
ot When Big Data Becomes Big Brother By packetstormsecurity.com Published On :: Fri, 05 Jun 2015 13:38:04 GMT Full Article headline government privacy spyware mcafee nsa
ot John McAfee Offers To Crack San Bernardino Shooter's iPhone By packetstormsecurity.com Published On :: Fri, 19 Feb 2016 01:27:07 GMT Full Article headline phone password apple mcafee fbi
ot Ubuntu Security Notice USN-4184-2 By packetstormsecurity.com Published On :: Thu, 14 Nov 2019 15:55:13 GMT Ubuntu Security Notice 4184-2 - USN-4184-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 was incomplete on 64-bit Intel x86 systems. Also, the update introduced a regression that broke KVM guests where extended page tables are disabled or not supported. This update addresses both issues. Various other issues were also addressed. Full Article
ot Ubuntu Security Notice USN-4183-2 By packetstormsecurity.com Published On :: Thu, 14 Nov 2019 15:55:18 GMT Ubuntu Security Notice 4183-2 - USN-4183-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 was incomplete on 64-bit Intel x86 systems. This update addresses the issue. Various other issues were also addressed. Full Article
ot Ubuntu Security Notice USN-4185-3 By packetstormsecurity.com Published On :: Thu, 14 Nov 2019 15:55:24 GMT Ubuntu Security Notice 4185-3 - USN-4185-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 was incomplete on 64-bit Intel x86 systems. Also, the update introduced a regression that broke KVM guests where extended page tables are disabled or not supported. This update addresses both issues. Various other issues were also addressed. Full Article
ot Ubuntu Security Notice USN-4186-3 By packetstormsecurity.com Published On :: Thu, 14 Nov 2019 15:56:10 GMT Ubuntu Security Notice 4186-3 - USN-4186-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 was incomplete on 64-bit Intel x86 systems. This update addresses the issue. Various other issues were also addressed. Full Article
ot Ubuntu Security Notice USN-3199-3 By packetstormsecurity.com Published On :: Mon, 28 Aug 2017 21:11:00 GMT Ubuntu Security Notice 3199-3 - USN-3199-1 fixed a vulnerability in Python Crypto. This update provides the corresponding update for Ubuntu 12.04 ESM. A It was discovered that the ALGnew function in block_templace.c in the A Python Cryptography Toolkit contained a heap-based buffer overflow A vulnerability. A remote attacker could use this flaw to execute A arbitrary code by using a crafted initialization vector parameter. Various other issues were also addressed. Full Article
ot Primefaces 5.x Remote Code Execution By packetstormsecurity.com Published On :: Thu, 18 Jan 2018 20:56:41 GMT This Metasploit module exploits an expression language remote code execution flaw in the Primefaces JSF framework. Primefaces versions prior to 5.2.21, 5.3.8 or 6.0 are vulnerable to a padding oracle attack, due to the use of weak crypto and default encryption password and salt. Full Article
ot Ubuntu Security Notice USN-3616-1 By packetstormsecurity.com Published On :: Tue, 03 Apr 2018 18:19:00 GMT Ubuntu Security Notice 3616-1 - It was discovered that Python Crypto incorrectly generated ElGamal key parameters. A remote attacker could possibly use this issue to obtain sensitive information. Full Article
ot Ubuntu Security Notice USN-3616-2 By packetstormsecurity.com Published On :: Mon, 09 Apr 2018 16:41:45 GMT Ubuntu Security Notice 3616-2 - USN-3616-1 fixed a vulnerability in Python Crypto. This update provides the corresponding update for Ubuntu 12.04 ESM. It was discovered that Python Crypto incorrectly generated ElGamal key parameters. A remote attacker could possibly use this issue to obtain sensitive information. Various other issues were also addressed. Full Article
ot Ubuntu Security Notice USN-3727-1 By packetstormsecurity.com Published On :: Wed, 01 Aug 2018 18:32:00 GMT Ubuntu Security Notice 3727-1 - It was discovered that Bouncy Castle incorrectly handled certain crypto algorithms. A remote attacker could possibly use these issues to obtain sensitive information, including private keys. Full Article
ot Ubuntu Security Notice USN-3901-1 By packetstormsecurity.com Published On :: Wed, 06 Mar 2019 18:08:40 GMT Ubuntu Security Notice 3901-1 - Jann Horn discovered that the userfaultd implementation in the Linux kernel did not properly restrict access to certain ioctls. A local attacker could use this possibly to modify files. It was discovered that the crypto subsystem of the Linux kernel leaked uninitialized memory to user space in some situations. A local attacker could use this to expose sensitive information. Various other issues were also addressed. Full Article
ot RootedCON 2020 Call For Papers By packetstormsecurity.com Published On :: Fri, 01 Nov 2019 16:55:55 GMT RootedCON is a technology congress that will be held in Madrid (Spain) March 5th through the 7th, 2020. With an estimated seating from 2,000 and 2,500 people, is the most relevant specialized congress that is held in the country, and one of the most relevant in Europe, with attendee profiles ranging from students, Law Enforcement Agencies to professionals in the technology and information security market and, even, just passionate people. Full Article
ot Facebook To Notify Users Of Third-Party App Logins By packetstormsecurity.com Published On :: Wed, 15 Jan 2020 17:03:35 GMT Full Article headline privacy password facebook social