December 30th, 2008 . by DarkFiber Consulting
DarkFiber Consulting is aware of a public report describing how MD5 collisions can be leveraged to generate rogue SSL CA certificates. A rogue CA certificate could be used by an attacker to generate valid SSL certificates for arbitrary web sites. Using these certificates in DNS redirection attacks, an attacker could spoof an SSL protected web site and obtain sensitive information.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Web • Attacker • Ca Certificate • Ca Certificates • Collisions • Md5 • Redirection • Rogue • Spoof • Ssl Certificate • Ssl Certificates • Vulnerability
December 23rd, 2008 . by DarkFiber Consulting
Trend Micro has released a patch to address a vulnerability in HouseCall 6.6. This vulnerability may allow an attacker to execute arbitrary code. Visitors to the publicly available HouseCall application may receive an older, vulnerable version of the control.
DarkFiber Consulting encourages users to review Hot Fix B1285 and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Code • Attacker • Micro Trend • Necessary Updates • Trend Housecall • Trend Micro • Vulnerability • Vulnerable Version
December 23rd, 2008 . by DarkFiber Consulting
Microsoft has released Security Advisory 961040 to address reports of attacks against a new vulnerability in Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine, Microsoft SQL Server 2000 Desktop Engine, and Windows Internal Database. The vulnerability occurs in the extended stored procedure “sp_replwriteovarbin.” Exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary code. Additionally, if a web application is vulnerable to SQL injection, an unauthenticated, remote attacker may be able to execute arbitrary code.
DarkFiber Consulting encourages users to review the Microsoft Security Advisory 961040 and implement any Suggested Actions to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Code • Attacker • Internal Database • Microsoft 2000 • Microsoft Releases Security Advisory • Microsoft Security Advisory • Microsoft Sql Server • Microsoft Sql Server 2000 • Microsoft Sql Server 2000 Desktop Engine • Microsoft Sql Server 2005 • Microsoft Sql Server 2005 Express • Microsoft Sql Server 2005 Express Edition • Sql 2000 • Sql Server 2000 • Sql Server 2000 Desktop Engine • Sql Server 2005 • Sql Server 2005 Express • Sql Server 2005 Express Edition • Vulnerability • Web Application
December 17th, 2008 . by DarkFiber Consulting
Mozilla has released Firefox 3.0.5 to address multiple vulnerabilities. The impacts of these vulnerabilities include cross-site scripting and information disclosure. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect Thunderbird.
DarkFiber Consulting encourages users to do the following to help mitigate the risks:
Posted in Security Alerts | No Comments »
Tagged With: Address • Cross Site Scripting • Information Disclosure • Mozilla Foundation Security Advisories • Mozilla Foundation Security Advisory • Thunderbird
December 17th, 2008 . by DarkFiber Consulting
Opera Software has released Opera Version 9.63 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, conduct cross-site scripting, or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review Opera advisories: 920, 921, 922, 923, and 924 and upgrade to version 9.63 to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Cross Site Scripting • Denial Of Service • Opera Software • Opera Version
December 17th, 2008 . by DarkFiber Consulting
Microsoft has released Security Bulletin MS08-078 to address a vulnerability in Internet Explorer. This vulnerability is due to an invalid pointer reference in the data binding function. By convincing a user to view a specially crafted document that performs data binding (e.g., a web page, email message, or attachment), a remote, unauthenticated attacker may be able to execute arbitrary code.
DarkFiber Consulting encourages users to review Microsoft Security Bulletin MS08-078 and apply the update or workarounds listed in the bulletin to help mitigate the risks. Users may also want to consider implementing the best security practices listed in the Securing Your Web Browser document to strengthen their web browsers against future vulnerabilities.
Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Best Security • Internet Explorer • Invalid Pointer • Microsoft • Microsoft Security Bulletin • Security Practices • Vulnerability Notes Database • Web Browser • Web Browsers • Web Page • Workarounds
December 16th, 2008 . by DarkFiber Consulting
Microsoft has released a Security Bulletin Advance Notification indicating that an out-of-band Security Bulletin will be released. This bulletin will address a remote code execution vulnerability in Microsoft Internet Explorer. Release of this Bulletin is scheduled for Wednesday, December 17.
DarkFiber Consulting encourages users to review the Security Bulletin Advance Notification and apply any necessary updates when they become available. Additional information about this vulnerability can be found in the Vulnerability Notes Database.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Advance Notification • Code Execution • December 17 • Internet Explorer Release • Microsoft • Microsoft Explorer • Microsoft Internet • Necessary Updates • Security Bulletin • Vulnerability Notes Database
December 15th, 2008 . by DarkFiber Consulting
Apple has released Security Update 2008-008 and Mac OS X v10.5.6 to address multiple vulnerabilities in Mac OS X and related products. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, denial of service, or information disclosure.
DarkFiber Consulting encourages users to review Apple article HT3338 and apply the appropriate updates.
Posted in Security Alerts | No Comments »
Tagged With: Address • Apple Article • Apple Updates • Arbitrary Code Execution • Denial Of Service • Escalation • Information Disclosure • Mac Os X • Os X • Privilege • Related Products • Security Updates
December 11th, 2008 . by DarkFiber Consulting
Microsoft has released Security Advisory 961051 to address reports of attacks against a new vulnerability in Internet Explorer 7. By convincing a user to view a specially crafted XML document, an attacker may be able to execute arbitrary code with the privileges of the user. Additionally, Microsoft indicates that it is aware of limited and targeted attacks using this vulnerability.
DarkFiber Consulting encourages users to review the Microsoft Security Advisory 961051 and implement any Suggested Actions to help mitigate the risks.
Additional information is available in the Vulnerability Notes database. DarkFiber Consulting will provide further details as they become available.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Internet Explorer 7 • Microsoft • Microsoft Releases Security Advisory • Microsoft Security Advisory • Nbsp • Privileges • Vulnerability Notes Database
December 11th, 2008 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of an email scam circulating that is targeting holiday travelers. The email messages related to this scam appear to come from legitimate major airlines and contain a .zip attachment. This .zip attachment appears to contain a purchase invoice and flight ticket. If a user opens this attachment, malicious code may be installed on the system.
DarkFiber Consulting encourages users to do the following to help mitigate the risks:
Posted in Security Alerts | No Comments »
Tagged With: Airline Ticket • Caution • Email Messages • Email Scam • Email Scams • Flight Ticket • Holiday Travelers • Invoice • Major Airlines • Malicious Code • Opening Attachments • Phishing Attacks • Social Engineering • Virus Signatures