Friday, August 1, 2008

Laptops and Airline Travel

When the TSA (Transportation Security Administration) banned laptops from being carried on to airplanes in the wake of an attempted terrorist attack, I wrote an article detailing steps to enable... Read More

Read More

Over the past few months, IBM X-Force has seen an escalation of SQL injection and other web-related attacks.  In the past few weeks, these attacks have culminated into  automated SQL injection attacks that, in some cases, have systematically defaced websites. As of July 24, IBM MSS has continued to monitor escalating attack attempts. Although most exploitation had been focused on ASP (primarily fueled by the Asprox botnet and Chinese sources), recent exploitation has turned to attacks specific to ColdFusion from sources that appear to be mostly Russian. Read More

The Microsoft MJPEG codec is vulnerable to multiple stack-based buffer overflows when parsing specially crafted files. A remote attacker could overflow the buffer and execute arbitary code within the context of the user viewing the malicious file. Read More

At some point, the United States Customs and Border Patrol decided that the current administration's blatant disregard for the Constitution of the United States trickles down to them as well... Read More

The Microsoft Dynamics GP is vulnerable to four heap and stack-based buffer overflows. A remote attacker could overflow the buffer and execute arbitrary code or gain control of the affected system by sending malicious queries to the Distributed Process Server or Distributed Process Manager. Read More

No comments: