October 14th, 2009 . by DarkFiber Consulting
Microsoft has released an update to address vulnerabilities in Microsoft Windows, Silverlight, Internet Explorer, .NET Framework, Office, SQL Server, Developer Tools, and Forefront as part of the Microsoft Security Bulletin Summary for October 2009. These vulnerabilities may allow an attacker to execute arbitrary code, operate with escalated privileges, cause a denial-of-service condition, or spoof an end user or website.
DarkFiber Consulting encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Bulletins • Denial Of Service • Developer Tools • Forefront • Internet Explorer • Microsoft • Microsoft Internet • Microsoft Security Bulletin • Microsoft Windows • Privileges • Security Policies • Server Developer • Spoof • Vulnerabilities
December 30th, 2008 . by DarkFiber Consulting
DarkFiber Consulting is aware of a public report describing how MD5 collisions can be leveraged to generate rogue SSL CA certificates. A rogue CA certificate could be used by an attacker to generate valid SSL certificates for arbitrary web sites. Using these certificates in DNS redirection attacks, an attacker could spoof an SSL protected web site and obtain sensitive information.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Web • Attacker • Ca Certificate • Ca Certificates • Collisions • Md5 • Redirection • Rogue • Spoof • Ssl Certificate • Ssl Certificates • Vulnerability
November 24th, 2008 . by DarkFiber Consulting
Apple has released OS 2.2 for the iPhone and iPod touch to address multiple vulnerabilities. These vulnerabilities affect CoreGraphics, ImageIO, Networking, Office Viewer, Password Lock, Safari, and Webkit. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, place arbitrary calls, cause a denial-of-service condition, spoof user interface, and obtain sensitive information.
DarkFiber Consulting encourages users to review Apple Article HT3318 and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Address • Apple 2 • Apple Article • Apple Os • Arbitrary Code • Attacker • Denial Of Service • Iphone • Ipod • Nbsp • Necessary Updates • Networking • Os 2 • Safari • Spoof • User Interface
October 31st, 2008 . by DarkFiber Consulting
VMware has released a Security Advisory indicating it has updated the ESX packages to address vulnerabilities in libxml2, ucd-snmp, and libtiff. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, spoof authenticated SNMPv3 packets, or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review VMware Security Advisory VMSA-2008-0017 and apply any necessary updates to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Code • Attacker • Denial Of Service • Necessary Updates • Security Advisory • Spoof • Ucd Snmp • Vmware
September 12th, 2008 . by DarkFiber Consulting
Apple has released iPhone v2.1 to address multiple vulnerabilities in Application Sandbox, CoreGraphics, mDNSResponder, Networking, Passcode Lock, and Webkit. These vulnerabilities may allow an attacker to execute arbitrary code, conduct DNS cache poisoning attacks, spoof or hijack TCP sessions, bypass Passcode Lock, obtain sensitive information, or cause a denial-of-service condition.
DarkFiber Consulting encourages users to review Apple document HT3129 and upgrade to iPhone v2.1.
Posted in Security Alerts | No Comments »
Tagged With: Address • Apple 1 • Arbitrary Code • Attacker • Denial Of Service • Iphone • Networking • Spoof • Tcp Sessions • Vulnerabilities
September 10th, 2008 . by DarkFiber Consulting
Apple has released four security updates to address multiple vulnerabilities in iTunes, QuickTime, iPod touch, and Bonjour for Windows. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct DNS cache poisoning attacks, spoof or hijack TCP sessions, access the system with escalated privileges, or obtain sensitive information.
DarkFiber Consulting encourages users and administrators to review the following Apple Security Articles and apply any necessary updates:
Posted in Security Alerts | No Comments »
Tagged With: Address • Apple Updates • Arbitrary Code • Attacker • Bonjour For Windows • Denial Of Service • Itunes • Necessary Updates • Privileges • Quicktime • Security Articles • Security Updates • Spoof • Tcp Sessions • Vulnerabilities