We are proud that we finally can present you the one and
only, the best, the always right and never wrong
dmca-ignoring and bush-bashing PHRACK magazine NUMBER 60!
Having now reached this milestone we hope to be able to keep
you satisfied with both quality and quantity. . . .see
yourself at
http://www.phrack.org/
Php
Vendor: PHP Group
A buffer overflow vulnerability was reported in PHP. A
remote user could cause the web service to crash or possibly
execute arbitrary code.
Impact: Denial of service via network
Alert:
http://securitytracker.com/alerts/2002/Dec/1005863.html
Windows File Protection
Vendor: Microsoft
A weakness was reported in Microsoft's Windows File
Protection mechanism. A remote user can sign binaries using
certificates that will cause the target user's Windows
operating system to trust the signature on the code.
Impact: Modification of system information
Alert:
http://securitytracker.com/alerts/2002/Dec/1005859.html
Windows File Protection
Vendor: Microsoft
A vulnerability was reported in the Microsoft Windows
File Protection mechanism in several Windows operating
systems. A local user could install older vulnerable
versions of signed software without detection.
Impact: Modification of system information
Alert:
http://securitytracker.com/alerts/2002/Dec/1005858.html
Microsoft Internet Explorer (IE)
Vendor: Microsoft
An input validation vulnerability was reported in
Microsoft Internet Explorer (IE). A remote user can create
HTML that, when loaded by a target user, will cause
arbitrary scripting code to be executed in another domain.
Impact: Disclosure of authentication information
Alert:
http://securitytracker.com/alerts/2002/Dec/1005857.html
CUPS (Common UNIX Printing System)
Vendor: Easy Software Products
An integer overflow was reported in the 'pdftops' filter
in the Common UNIX Printing System (CUPS) packages. A remote
user may be able to cause arbitrary code to be executed by
the target user.
Impact: User access via network
Alert:
http://securitytracker.com/alerts/2002/Dec/1005853.html
PHP-Nuke
Vendor: Phpnuke.org
An information disclosure vulnerability was reported in
PHP-Nuke. A remote user can determine the installation path.
Impact: Disclosure of system information
Alert:
http://securitytracker.com/alerts/2002/Dec/1005850.html
KDE
Vendor: KDE.org
Several vulnerabilities were reported in KDE. A remote
user may be able to execute arbitrary commands on a target
user's system.
Impact: Execution of arbitrary code via network
Alert:
http://securitytracker.com/alerts/2002/Dec/1005845.html
From: "Georgi Guninski" <guninski@guninski.com>
emacs users are advised to disable local variables by: (setq
enable-local-variables nil) in .emacs Execution of shell
commands is possible. It is claimed that emacs CVS fixes the
problems.
WHO'S GOT ROOT? FIND OUT WITH TRIPWIRE
Your network groans under the weight of monitors and
alarms. If an intruder slides through all the barriers and
successfully cozies into a snug corner, how will you know?
>>
http://www.net-security.org/news.php?id=1700
SECURING OUTLOOK, PART TWO: MANY CHOICES TO MAKE
The first article offered a brief overview of Outlook, as
well as some of the threats that undermine its security.
This article will look at some more things that Outlook
users can do to improve their e-mail security.
>>
http://www.net-security.org/news.php?id=1704
"Open source anche per windows: GNUWin II"
Disponibile iso di software open source anche per
windows: GNUWin II. GNUWin II è una collezione di software
liberi per Windows. Vi troverete tre tipi di
funzionalità: Applicazioni, Articoli, Aiuto in linea e
spiegazioni di GNUWin. Non esitate a percorrere il glossario
o la F.A.Q.!
http://www.ziobudda.net/news/see_comments.php?id_notizia=9850
** ANCHE GLI MP3 SONO A RISCHIO VIRUS **
Windows XP, il gioiello di casa Microsoft, si conferma un
colabrodo. E' disponibile la patch. [Pubblicato su
http://www.zeusnews.it
il 03-01-2003] >> di Paolo Attivissimo
http://www.zeusnews.it/news.php?cod=1814 |