January 27th, 2010 . by DarkFiber Consulting
Microsoft has released Security Advisory 979352 to alert users of a vulnerability in Microsoft Internet Explorer. The advisory indicates that exploitation of this vulnerability may allow an attacker to execute arbitrary code. Microsoft also indicates that it is aware of public, active exploitation of this vulnerability.
DarkFiber Consulting encourages users and administrators to review Microsoft Security Advisory 979352 and apply the suggested workaround of setting the Internet zone security setting to High to help mitigate the risks.
Additional information about this vulnerability can be found in Vulnerability Note VU#492515.
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Code • Attacker • Code Microsoft • Internet Explorer • Internet Security • Internet Zone • Microsoft • Microsoft Explorer • Microsoft Internet • Microsoft Releases Security Advisory • Microsoft Security Advisory • Vulnerability Note • Workaround • Zone Security
July 2nd, 2009 . by DarkFiber Consulting
Foxit Reader has released updates for multiple vulnerabilities. By convincing a user to open a malicious PDF file, an attacker may be able to execute code or cause a vulnerable PDF viewer to crash. The PDF could be emailed as an attachment or hosted on a website.
DarkFiber Consulting encourages users to review the Foxit Security Bulletin and Vulnerability Note VU#251793 and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Attacker • Nbsp • Necessary Updates • Pdf Viewer • Security Bulletin • Vulnerability Note
October 27th, 2008 . by DarkFiber Consulting
Microsoft has released Security Advisory 958963 to alert users that exploit code is publicly available for the Windows Server Service vulnerability addressed in Microsoft Security Bulletin MS08-067. The advisory states that this exploit code has demonstrated arbitrary code execution on Windows 2000, XP and Server 2003.
DarkFiber Consulting encourages users and administrators to review Microsoft Security Advisory 958963 and apply the update or workarounds listed in Microsoft Security Bulletin MS08-067 to help mitigate the risks.
Additional information regarding the Windows Server Service vulnerability is available in:
Posted in Security Alerts | No Comments »
Tagged With: Arbitrary Code Execution • Current • Microsoft • Microsoft Releases Security Advisory • Microsoft Security Advisory • Microsoft Security Bulletin • Server Service • Service Vulnerability • Vulnerability Note • Windows 2000 • Windows 2000 Xp • Windows Server • Workarounds
September 9th, 2008 . by DarkFiber Consulting
In June, DarkFiber Consulting published Vulnerability Note VU#476345 to alert users of a vulnerability affecting Citect CitectSCADA. This vulnerability is due to a buffer overflow condition in the handling of ODBC requests from clients. Exploit code for this vulnerability is publicly available and exploitation may allow an attacker to execute arbitrary code.
DarkFiber Consulting encourages users to review Vulnerability Note VU#476345 and apply the patch as described in the document.
Posted in Security Alerts | 1 Comment »
Tagged With: Arbitrary Code • Attacker • Buffer Overflow Condition • Citect • Vulnerability Note
August 6th, 2008 . by DarkFiber Consulting
Oracle has released a patch to address a previously disclosed vulnerability in the WebLogic plug-in for Apache. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition.
DarkFiber Consulting encourages users to consider applying the patch and workarounds referenced in the Oracle Security Advisory and in Vulnerability Note VU#716387.
Posted in Security Alerts | No Comments »
Tagged With: Address • Apache • Arbitrary Code • Attacker • Denial Of Service • Oracle • Oracle Security • Security Advisory • Vulnerability Note • Weblogic
August 1st, 2008 . by DarkFiber Consulting
Apple has released Security Update 2008-005 to address multiple vulnerabilities that affect a number of applications. These vulnerabilities may allow an attacker to conduct DNS cache poisoning attacks, execute arbitrary code, cause a denial-of-service condition, or access the affected system with elevated privileges. Please note that this update addresses recent issues with weaknesses in common DNS implementations; see Vulnerability Note VU#800113 for additional information.
DarkFiber Consulting encourages users to review Apple Article HT2647 and apply any necessary updates as soon as possible to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Address • Addresses • Apple Article • Arbitrary Code • Attacker • Denial Of Service • Necessary Updates • Privileges • Vulnerabilities • Vulnerability Note
July 25th, 2008 . by DarkFiber Consulting
DarkFiber Consulting is aware of publicly available exploit code for a cache poisoning vulnerability in common DNS implementations. Exploitation of this vulnerability may allow an attacker to cause a nameserver’s clients to contact the incorrect, and possibly malicious hosts for particular services. As a result, web traffic, email and other important network data could be redirected to systems under the attacker’s control.
DarkFiber Consulting strongly urges administrators to patch affected systems immediately. Please review the following DarkFiber Consulting documents for further details:
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Affected Systems • Attacker • Current • Cyber Security • Dns Cache • Email • Important Network • Malicious Hosts • Mitigation • Nameserver • Nat Pat • Vulnerability Note • Web Traffic
July 23rd, 2008 . by DarkFiber Consulting
DarkFiber Consulting released a Current Activity entry and a Vulnerability Note on July 8, 2008 regarding deficiencies in DNS implementations. These deficiencies could leave an affected system vulnerable to cache poisoning. Technical details regarding this vulnerability have been posted to public websites. Attackers could use these details to construct exploit code. Users are encouraged to patch systems or apply workarounds immediately.
A number of patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks. Administrators should be aware that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated. This may weaken the protection offered by source port randomization in the nameserver.
DarkFiber Consulting encourages users to consider one of the following workarounds:
- Place the nameserver outside of the NAT/PAT device in the network infrastructure.
- Configure the NAT/PAT device to perform source port randomization.
- Configure the NAT/PAT device to preserve the source port assigned by the nameserver.
Additional information can be found in DarkFiber Consulting Vulnerability Note VU#800113.
More information will be provided as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Attackers • Code Users • Deficiencies • Dns Cache • Infrastructures • Mitigation • Name Server • Nameserver • Nat Pat • Network Address Translation • Network Infrastructure • Patches • Port Address Translation • Practicality • Randomization • Source Port • Technical Details • Vulnerability Note