Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Sunday, June 27, 2004
 


11:28:52 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Father of DVD Gets Bitter Reward
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Rplr msg() Buffer Overflow (Exploit)

9:28:12 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Ukiyo-e remix art. A BoingBoing art exclusive: the latest watercolor from Moira Hahn, whose illustration work has appeared in Time, the New Yorker, and elsewhere. About this remix of classic ukiyo-e art -- which depicts a backyard conflict between cats and birds -- Moira says "Kuniyoshi was an influence, the primary Edo period ukiyo-e artist who regularly depicted cats... [but] most of this composition has been changed from various Edo and Meiji sources. The original figures were human, patterns were different, and there was no owl." [Ed. note: Dude, is that Waldo from Hatebeak on the far left?]

Link to full-size jpeg image (about 500k)

2.  Coffee Geeks: brewing gadgetry, DIY roasters, Cuban contraband. Responding to a previous post about current guestblogger Christopher Coppola's favorite road trip espresso maker, several readers point us to CoffeeGeek. The site lists reviews for such a mindbogglingly vast array of coffee-related gadgets, I get a contact buzz just clicking on it. Link. (Thanks, Josh, and everyone else!)

Reader Bill says, "If you're talking coffee, you should check out this website, from a tiny California company that supports do-it-yourselfers that roast their own beans. While there are some hazards - like smoking the place out, you can use 1970's air popcorn poppers, woks, or actual home roasters. Apparently, coffee goes stale in 4-6 days, so most of us have been drinking stale coffee without even knowing it." Link

X-NAS-Bayes: #0: 3.36962E-151; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2290 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

And reader Simon Fodden in Canada says, "For those closer to the middle of the landmass, the Merchants of Green Coffee offer similar products, plus (oh, the forbidden fruit!) really good coffee from Cuba."

3.  PopSci design competition: "personal occupation kits". Among the finalists in the 2004 Popular Science design competition:

"The horrendous situation in Iraq highlights the thorny challenge of liberation by a superpower: The liberated don't necessarily buy into the program...In this concept, autonomous surveillance systems watch foreign news broadcasts for any foment of anti-American sentiment to identify areas in need of intervention. The geographical coordinates are beamed to airplanes carrying the smart bombs; the bombs explode and shower, not explosives, but small, flower-like packages containing assorted bits of Americana."
Link (Thanks, Brian Wong!)
4.  Congress looks out for Hollywood. A piece by my Wired News colleague Katie Dean about a slew of legislation passed on Capitol Hill this week that could outlaw a range of devices and software, and impose severe penalties on anyone caught trading files. Link. And Andrew Orlowski offers an astute analysis in The Register, which begins: "It may soon be possible to carry around an AK-47 assault rifle and an iPod with you down the street - and be arrested for carrying the iPod." Link
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  Cut-Rate Windows 'XP Starter Edition' in Thailand
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
6.  Vulns: ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability. Newsletter ZWS is a web based news content and mailing list management script created by ZaireWeb Solutions.

Newsletter ZWS is reported prone to an administrative interf...


8:27:52 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Iraq torture memo primer. A helpful timeline and overview of government memoranda related to the mistreatment and torture of wartime detainees, from the New York Times . Link bypassing NYT's dumb-as-a-stump site registration
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: LibPNG Incorrect Offset Calculation Buffer Overflow Vulnerability. The libpng graphics library may incorrectly calculate some offsets when creating or modifying PNG files. This vulnerability has been reported when manipulating 16-bit sam...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  TROJ_RANKY.D
4.  TROJ_SDOT.A

7:27:33 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  WA Bans Gift-Card Expirations, Fees
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability. giFT-FastTrack is a module for the giFT filesharing daemon. giFT provides a framework for interfacing with multiple peer-to-peer networks. giFT-FastTrack is a module desi...
3.  Vulns: Rlpr msg() Function Multiple Vulnerabilities. rlpr is a utility to print files on remote sites to your local printer. The package includes BSD-compatible replacements for `lpr', `lpq', and `lprm'. X-NAS-Bayes: #0: 1.18573E-017; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2288 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

It is reported th...

----------------------------------------------------------------------
Help Net Security
----------------------------------------------------------------------
4.  Cookie path best practice
5.  NewsIsFree: Your own Advanced News Reader and Feed Publisher. Read news from thousands of news sources updated every 15 minutes on the most powerful news aggregator.
Create custom feeds with more items, descriptions, select your version of RSS...
Check out NewsIsFree's services!
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Vulns: GNU gzexe Temporary File Command Execution Vulnerability
7.  Ethical Hacking Is No Oxymoron

6:27:13 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Should Companies Expense Stock Options?

5:26:53 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  2004 U.S. Puzzle Championship Winners
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: GNU gzexe Temporary File Command Execution Vulnerability. GNU gzexe is a component of the gzip set of file compression utilities. gzexe is a shell script that allows for executable files to be compressed in their existing file s...

4:26:32 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  EU suspends Microsoft sanctions. Order requiring Microsoft to sell Windows without media player software gets put on hold.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
2.  Russian website spreading 'malicious' program shut down: Microsoft (AFP). AFP - A Russian website that spread a "malicious" Internet program has been shut down, software giant Microsoft said, adding that users of Internet Explorer are no longer at risk.
3.  Program Lets Users Share Slices of Web (AP). AP - Trolling the Internet often yields cool tidbits, but they aren't easy to share. If you're planning a trip with friends, for example, and find six good hotel deals, you're probably just going to e-mail them six separate links to check out.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  Vulns: Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability
5.  Vulns: HP-UX DCE Unspecified Remote Denial Of Service Vulnerability
6.  Vulns: Microsoft Internet Explorer Non-FQDN URI Address Zone Bypass Vulnerability

3:26:13 PM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Microsoft gets temporary stay in EU Windows Media Player ruling. Today news from Brussels indicates that the EU has put a temporary hold on these sanctions just the day before they were slated to take effect. By Ken "Caesar" Fisher.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  EC Suspends Microsoft Sanctions Due to Appeal
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  Vulns: Microsoft Internet Explorer Non-FQDN URI Address Zone Bypass Vulnerability. Microsoft Internet Explorer is prone to a zone bypass vulnerability. A remote attacker may execute code in the Intranet zone. X-NAS-Bayes: #0: 2.06175E-036; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2281 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The Intranet Zone contains all sites withi...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  Drcatd Multiple Vulnerabilities
5.  Artmedic_links5 File Include Vulnerability
6.  Gnats Format String Vulnerability
7.  FreeBSD Local Denial of Service Vulnerability

2:25:53 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  EU suspends anti-trust measures against Microsoft (AFP). AFP - Microsoft won a reprieve from a hard-hitting anti-trust ruling by the European Union after the EU executive said it had suspended its punishment against the US software giant.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  CERT Recommends Mozilla, Firefox
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  Vulns: Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability. The DCE (Distributed Computer Environment) is a set of distributed computing standards maintained by Open Software Foundation. Numerous vendors provide DCE client and se...
4.  Vulns: HP-UX DCE Unspecified Remote Denial Of Service Vulnerability. HP-UX is a UNIX Operating System variant distributed and maintained by HP. X-NAS-Bayes: #0: 4.59554E-036; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2278 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A problem has been identified in the Distributed Computing Environment (DCE) that may allow at...


1:25:32 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  EU Temporarily Lifts Microsoft Ruling (AP). AP - The European Union on Sunday temporarily lifted its order to Microsoft Corp. to change the way it sells software in Europe until the EU high court has heard the company's request for a final appeal of the landmark antitrust decision,
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  HP Recall on 900,000 Notebooks
3.  A How-Not-To Guide to Cyber-Extortion
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
4.  Vulns: VBulletin Multiple Module HTML Injection Vulnerability. VBulletin is a commercially available web based bulletin board application. It is implemented in PHP and may be run on Unix and Unix like operating systems as well as Mic...
5.  Vulns: 3Com SuperStack Switch Web Interface Denial Of Service Vulnerability. 3Com SuperStack network switches are fully configurable and include a web configuration interface to facilitate remote configuration. X-NAS-Bayes: #0: 1.64256E-079; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2277 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

It is reported that 3Com SuperStack...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  HackNotes Network Security Portable Reference
7.  Web infection may be aimed at stealing financial data
8.  Wi-fi hopper guilty of cyber-extortion
9.  Experts studying Internet attack
10.  FBI antiterror computer system delayed
11.  Trojan virus attacks popular Web sites
12.  Network admins get peek at Microsoft's security
13.  Researchers warn of infectious Web sites
14.  Now We Need To Worry About VoIP Spam
15.  Novell tools manage Linux and Windows desktops
16.  Al Qaida websites blocked
17.  Infected websites exploit Microsoft browser flaws

12:25:14 PM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  EU Temporarily Suspends Microsoft Sanctions (Reuters). Reuters - The European Commission has temporarily suspended an order requiring Microsoft to sell a version of its Windows operating system without a media player software, just before the order would have taken effect, it announced Sunday.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Red Hat announces GFS

11:24:53 AM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  Week ahead: Tigers on the loose. Comdex is off, but the Vegas glitz lives on, as both Apple and Sun get ready to unleash separate products code-named "Tiger" in San Francisco.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Fahrenheit 9/11 Discussion

10:24:33 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  iPod Alternatives Shaking Up Market (Reuters). Reuters - Fitness buff Dr. Mark Hawkins bought his first iPod a year ago when the clunky CD player he used in morning workouts started giving Robert Plant, the singer of Led Zeppelin's blues-y "Babe I'm Gonna Leave You," a bad stutter.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Smart Systems Threaten More Jobs Than Outsourcing

9:24:13 AM    comment []


8:23:52 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  The Future of Free Weather Data on the Internet

7:23:34 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  EU Temporarily Suspends Microsoft Sanctions-Source (Reuters). Reuters - The European Commission has temporarily suspended an order demanding that Microsoft change the way it sells Windows software, pending an EU judicial decision on the firm's request for a longer-term suspension, a source familiar with the situation said Sunday.

6:23:12 AM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Three-year-old commentator on pre-movie (c) warnings. James took his three-year-old to see Shrek 2 yesterday and when the copyright warning came on at the start of the picture, his son responded appropriately. X-NAS-Bayes: #0: 6.6764E-076; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2268 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

I went to see Shrek 2 today with my son Edward who is 3 next week. He was very excited, he loves going to the cinema. However when the copyright warning about taking pictures and video appeared (the one that Cory Doctorow takes pictures of) he said in a very loud voice "blah blah blah blah", which had me in hysterics if no one else.

Link

(Thanks,< a href="http://thebloomers.blogspot.com">James!)

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
2.  Budding DJs mixing on mobiles. Festival-goers at Glastonbury 2004 have been getting a taste of making their own music with a new service.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  NetBSD Multi-homed Host Arbitrary ARP Packet Modification
4.  NetBSD Static ARP Entry Arbitrary Overwrite
5.  Evidence awaited in Iraqi death
6.  Memos: Abuse rife in Iraq
7.  Bush calls for NATO to aid Iraq

5:22:52 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 27 Jun 2004.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  The Open Source Paradigm Shift
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Experts Warn That 'Scob' Virus Could Lead To Keyboard Logging
4.  Militants threaten to behead 3 Turks

4:22:32 AM    comment []


3:22:13 AM    comment []

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
1.  More Hacking News...
2.  Web attack aims to steal surfers' financial details

2:21:52 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Java3D Source Code Released

1:21:33 AM    comment []

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
1.  NetBSD sendmsg msg_controllen DoS
2.  NetBSD ftpchroot Broken Parsing Arbitrary File Access
3.  Openswan X.509 Validation Error Lets Remote Users Authenticated to Protected Networks
4.  strongSwan X.509 Validation Error Lets Remote Users Authenticated to Protected Networks

12:15:44 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 7/1/2004; 2:25:01 AM.
This theme is based on the SoundWaves (blue) Manila theme.
June 2004
Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      
May   Jul