Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Sunday, May 30, 2004
 

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Studios Sue Retailer for Piracy (AP). AP - Two Hollywood movie studios have sued an online retailer, accusing Technology One of defiantly selling DVD-copying software previously barred by two federal courts.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  The 3Com Saga
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Boy Uses Chatroom Spy Plot To Order His Own Murder

11:26:21 PM    comment []


10:26:02 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Many Wireless Networks Lack Security (AP). AP - With a laptop perched in the passenger seat of his Toyota 4Runner and a special antenna on the roof, Mike Outmesguine ventured off to sniff out wireless networks between Los Angeles and San Francisco. He got a big whiff of insecurity.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Report: FDIC Data Vulnerable

9:25:41 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The Urban Geek As A Mugger Magnet?
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  OpenBSD XFree86 xdm Unintended Query Listening Security Issue
3.  Mac OS X Multiple Unspecified Vulnerabilities
4.  jftpgw Logging Format String Vulnerability
5.  Debian update for jftpgw

8:25:22 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  NYT: E-Voting will only work if it's open source. A thought-provoking piece on cures for e-voting woes, from today's New York Times
Electronic voting has much to offer, but will we ever be able to trust these buggy machines? Yes, we will -- but only if we adopt the techniques of the ''open source'' geeks.

One reason it's difficult to trust the voting software of companies like Diebold is that the source code remains a trade secret. A few federally approved software experts are allowed to examine the code and verify that it works as intended, and in some cases, states are allowed to keep a copy in escrow. But the public has no access, and this is troublesome. When the Diebold source code was accidentally posted online last year, a computer-science professor looked at it and found it was dangerously hackable. Diebold may have fixed its bugs, but since the firm won't share the code publicly, there's no way of knowing. Just trust us, the company says.

Link
2.  Bollywood Vanilla Coke ad which kicks ass. BoingBoing reader Vishal points us to a spectacularly cheesy Indian TV ad starring yet another one of my future husbands (look, any fella who eschews SMS for pigeon as preferred love-note carrier is alright by me).

Vishal says, "This Ad is really popular in India, and I was surprised to find that the good people at Coke have it online too (RealPlayer). It features one of the hottest young actors in Bollywood, Vivek Oberoi, and features many in-jokes to '70s Bollywood films (note, especially, the lightbulb dress in the 3rd segment, a direct lift from a classic 70's movie)."

Footnote to menswear trendwatchers: take a tip from Vivek, at left -- pink vomit prints are the new black.
Link

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  FCC Move Could Shut Down High School Radio Station
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
4.  Vulns: PHP Input/Ouput Wrapper Remote Include Function Command Execution Weakness. PHP includes various file input/output wrappers to facilitate efficient read and write operations; php://input is one of these wrappers that facilitates reading POST data...
5.  Vulns: Subversion Pre-Commit-Hook Template Undisclosed Vulnerability. Subversion is a freely available, open source software version control system for the Unix, Linux, and Microsoft Windows platforms. X-NAS-Bayes: #0: 1.78664E-114; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1199 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Subversion is reported prone to an un...


6:24:42 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Mo' Beta Testing Blues
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Media Archive - New page added to site featuring hacking related audio / video for download, inc...

4:24:02 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Online Plagiarist Sues University
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: Canon ImageRUNNER Remote Port Scan Denial of Service Vulnerability. imageRUNNER is a laser printer offered by Canon. imageRUNNER offers a web interface over TCP port 80. X-NAS-Bayes: #0: 1.47202E-005; #1: 0.999985 X-NAS-Classification: 0 X-NAS-MessageID: 1191 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

imageRUNNER is prone to a remote denial of service vulnerability. ...

3.  Vulns: 3Com OfficeConnect Remote 812 ADSL Router Web Interface Authentication Bypass Vulnerability. 3Com OfficeConnect Remote 812 ADSL Router is an Internet gateway device. The device provides a web configuration interface to allow for remote administration.

3Com Offi...


3:23:42 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Japanese Internet Star Pushes Blogs (AP). AP - Snapshots of his pet dog, thoughts on democracy and a recipe for bamboo shoots clutter Joichi Ito's Web journal, a lively peek into the tireless mind of one of Japan's biggest Internet stars.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: XFree86 XDM RequestPort Random Open TCP Socket Vulnerability. xdm is the X Display Manager with support for XDMCP. X-NAS-Bayes: #0: 4.66809E-065; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1190 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

xdm is reported prone to a potential security vulnerability that may lead to a false sense of security. Normally xdm...

3.  Vulns: IsoqLog Remote Buffer Overflow Vulnerability. IsoqLog is an MTA log analysis application implemented using the C language. It is freely available for Unix and Unix variant operating systems.

IsoqLog is reportedly a...

4.  Vulns: Sun Java System Application Server Remote Installation Path Disclosure Vulnerability. It is reported that Java System Application Server is prone to a remote installation path disclosure vulnerability. This issue is due to a failure of the application to p...

2:23:22 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Parliamentary panel nods to Kuwait's third mobile operator (AFP). AFP - Kuwait parliament's financial affairs committee has approved draft legislation calling for a third mobile telecommunications company in the oil-rich emirate, the committee chair said.
2.  Many Wireless Networks Lack Security (AP). AP - With a laptop perched in the passenger seat of his Toyota 4Runner and a special antenna on the roof, Mike Outmesguine ventured off to sniff out wireless networks between Los Angeles and San Francisco. He got a big whiff of insecurity.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Periodic Table of the Operators
4.  Fedora Core 2 Dud or Dodo?
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  FreeBSD sliplogin Privilege Escalation
6.  FreeBSD comsat Arbitrary Mail Read
7.  FreeBSD msync MS_INVALIDATE File Write Restriction
8.  SSH .shosts Authentication
9.  SSH .rhosts Authentication
10.  Sun Cluster in.mond Arbitrary File Read
11.  Bugzilla Reverse DNS Failure IP Check Bypass

1:23:02 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Touchscreen BoomboxPC
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities. LHA is a utility that can compress and decompress LHarc/LH7 format archives. X-NAS-Bayes: #0: 1.36522E-038; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1185 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive t...

3.  Vulns: Apache Mod_SSL SSL_Util_UUEncode_Binary Stack Buffer Overflow Vulnerability. mod_ssl provides an interface for accessing the OpenSSL libraries from within Apache.

A stack-based buffer overflow has been reported in the Apache mod_ssl module.

Th...


12:22:41 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  More Blackholes Discovered...
2.  Big Screen for NYPD
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  Vulns: WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability. WildTangent WebDriver is a multimedia gaming browser plugin that is compatible with Internet Explorer and Netscape on Windows operating systems. X-NAS-Bayes: #0: 6.98598E-016; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1182 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A remotely exploitable s...

4.  Vulns: Heimdal K5AdminD Remote Heap Buffer Overflow. Heimdal implements the Kerberos 5 network authentication protocols. The k5admind daemon provides the administrative interface to the Kerberos Key Distribution Center (KDC...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Massale poging tot diefstal via nog onbekend lek in IE

11:22:22 AM    comment []


10:22:02 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Week ahead: Conferences aplenty
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Future of Visual Gadgets Rolled Out (AP). AP - A television sewn into your shirt sleeve. A dashboard screen to monitor the kids in the back seat. A 3-D computer monitor sharp enough to make a hardcore gamer's heart stop — or help a surgeon start one. The gizmo-packed exhibition hall at the Society for Information Display's international symposium offers a tantalizing vision of what's to come.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  NEC Admits To Ripping Off Schools Through E-Rate Program
----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
4.  Microsoft workers bemoan cutbacks. Microsoft's plan to save $80m by cutting back benefits upsets many of its staff, an internal poll obtained by Reuters reveals.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  Apple Mac OS X Has Unspecified Flaw in NFS
6.  Apple Mac OS X Has Unspecified Flaw in LoginWindow
7.  Apple Mac OS X Has Unspecified Flaw in Package Installation
8.  AppleFileServer Has Unspecified Flaw in Reporting Errors

9:21:41 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The Single Man's Guide To TV Dinners

8:21:21 AM    comment []


7:21:01 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  What 'Network Games' Could Have Looked Like

6:20:42 AM    comment []

----------------------------------------------------------------------
Digital Identity World
----------------------------------------------------------------------
1.  The Digital ID World Newsletter - March 11, 2004 Issue
2.  The Digital ID World Newsletter - March 18, 2004 Issue
3.  The Digital ID World Newsletter - March 25, 2004 Issue
4.  The Digital ID World Newsletter - April 1, 2004 Issue
5.  Digital ID World Announces 2004 Conference
6.  The Digital ID World Newsletter - April 8, 2004 Issue
7.  The Digital ID World Newsletter - April 15, 2004 Issue
8.  The Digital ID World Newsletter - April 22, 2004 Issue
9.  The Digital ID World Newsletter - April 29, 2004 Issue
10.  The Digital ID World Newsletter - May 6, 2004 Issue
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Mollensoft FTP Server Can Be Crashed By Remote Authenticated Users With a CD Command
12.  Penetraion-testing.com - Penetration Testing Guide from
13.  Tuning out wartime's complex face
14.  Clashes persist despite truce
15.  Abuse alleged at other prisons

5:20:23 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 30 May 2004.

4:20:01 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Spotcode. Along the lines of Semacode, another "use your phonecam as a meatspace remote control" project -- Spotcode. Developer Anil Madhavapeddy says: X-NAS-Bayes: #0: 4.09753E-066; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1169 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

I've been working on some software that lets you use your existing camera phone as a virtual mouse by locking onto tags and physically rotating it around and so on. It's most easily explained by checking out the videos. In particular, the volume control one (MPEG) is fun.

Link (Also spotted on Warren Ellis' blog)

2.  Porn art-remixes part deux: Safe For Work.

Those French "pornotuning" remixes aren't the first time someone with a pinch of snark and a penchant for pr0n got jiggy with Photoshop. For instance, this somethingawful riff from a couple of years back: "Make Porn Work-Safe." Results included the bizarre goatse-esque mashup shown here, which suggests a rollicking three-way between Man Ray, Terry Richardson, and Betty Crocker. BoingBoing reader Phil points us to the archived gallery and says, "Basically, they hacked pornopix just enough to make them (at least theoretically) safe for work."
Link

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
3.  Instant messaging grows up. The hugely popular practice of instant messaging is evolving beyond just text.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  Boy Poses As Internet Spy To Plot His Own Murder

3:19:42 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Porn art-remixes part deux: Safe For Work. X-NAS-Bayes: #0: 6.02177E-048; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 1168 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Those French "pornotuning" remixes were preceded by a similar somethingawful riff a couple of years ago: "Make Porn Work-Safe." The results included the bizarre goatse-esque mashup shown here which suggests, oh, a rollicking three-way betwen Marcel Duchamp, Terry Richardson, and Betty Crocker. BoingBoing reader Phil points us to the archived photoshoppery and says, "Basically, they hacked pornopix just enough to make them (at least theoretically) safe for work."
Link

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  PlayStation Portable wows consumers, retailers; analysts cautious (AFP). AFP - The planned launch of a portable edition of Sony's hugely popular PlayStation game console series is eagerly awaited by game fans and retailers here, but analysts are more cautious about a product claimed by Sony to be as revolutionary as its Walkman.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  Cassini Alters Path. Phoebe Now In Sight!
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  [SECURITY] [DSA 509-1] New gatos packages fix privilege escalation
5.  [SECURITY] [DSA 510-1] New jftpgw packages fix format string vulnerability
6.  Fastest Rising: 445 microsoft-ds
7.  WORM_LAMUD.A
8.  FastCGI mod_fastcgi FastCgiSuexec Vhosts Privilege Escalation
9.  FastCGI mod_fastcgi subprocess_env Password Disclosure
10.  FastCGI mod_fastcgi fopen Append Error Log Corruption
11.  FastCGI mod_fastcgi Socket Permission Weakness
12.  LHA get_header Directory Name Overflow
13.  LHA get_header File Name Overflow
14.  LHA Directory Traversal

2:19:21 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Shuttle XPC Packs a Lot Into a Small -- and Imperfect -- Package (washingtonpost.com). washingtonpost.com - Compared with the tower-case computers that squat under desks in millions of homes and offices, the tidy black box I have set up at home is a midget of a machine. Not only does this desktop actually fit on top of a desk, at roughly 7 1/4 inches tall by 7 7/8 inches wide by 12 inches long, it takes up no more room than many shoeboxes.
2.  Yahoo Tries To Keep Spies Out (washingtonpost.com). washingtonpost.com - Yahoo rolled out a test version of a browser add-on that can help Web users shield their surfing habits from spyware.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  BugTraq: [SECURITY] [DSA 510-1] New jftpgw packages fix format string vulnerability. Sender: Matt Zimmerman [mdz at debian dot org]

12:22:10 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 6/1/2004; 12:33:06 AM.
This theme is based on the SoundWaves (blue) Manila theme.
May 2004
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Apr   Jun