Bookmark and Share

Microsoft’s fuzzing botnet finds 1,800 Office bugs

News | Wednesday 31 March 2010 7:42 pm

Microsoft uncovered more than 1,800 bugs in Office 2010 by tapping into the unused computing horsepower of idling PCs, a company security engineer said today.

Office developers found the bugs by running millions of “fuzzing” tests, said Tom Gallagher, senior security test lead with Microsoft’s Trustworthy Computing group.

View full post on Security Central – Infoworld

The Real MCTS/MCITP Exam 70-620 Prep Kit

Internet Security Books | Wednesday 31 March 2010 6:04 pm

The Real MCTS/MCITP Exam 70-620 Prep Kit

Officials: 29 arrested in cybercrime operation (The Tampa Tribune)

News | Wednesday 31 March 2010 6:04 pm

The 29 Central Florida men arrested in a seven-week cybercrime investigation include a military police officer, a hospital administrator and a Tampa man authorities say was abusing the two young daughters of a woman he molested when she was a child.

Linksys by Cisco SFE2010P 48-port 10/100 Ethernet Switch – PoE

Internet Security Hardware | Wednesday 31 March 2010 5:59 pm

  • Former Linksys Business Series
  • Power over Ethernet connects up to 48 network devices PCs, printers, access points, and servers¿to share and transfer files and videos
  • Tap into your network’s existing high speeds using a flexible high-speed uplink connection
  • Resilient stacking technology lets you manage multiple switches from a single configuration menu

Product Description
48PORT 10/100 SWITCH 2GIG PERP2SFP LAYER 3 STACKABLE POE… More >>

Linksys by Cisco SFE2010P 48-port 10/100 Ethernet Switch – PoE

PDF Arbitrary Code Execution – vulnerable by design., (Wed, Mar 31st)

News | Wednesday 31 March 2010 5:08 pm

Didier Stevens, who probably knows the PDF format better then most and has written some great PDF analysis tools, published a very interesting and concerning blog post [1].
In this post, he outlines how PDFs can be used to execute code. Nothing new you may say… plenty of exploits have done this in the past. This is different: He is not using a vulnerability, but a feature. Evidently, PDFs have the ability to execute code by design. Since this is not an implementation, but a design problem, various PDF readers are vulnerable. In his blog, Didier show a video of the exploit using Adobe’s PDF reader. Adobe’s reader will show a warning and ask the user for permission. However, the wording of this warning may be changed by the attacker. Foxit, a popular alternative to Adobe’s reader, will show no warning.
At this point, Didier does not provide a public PoC exploit. However, he says he is in contact with vendors.

[1] http://blog.didierstevens.com
——

Johannes B. Ullrich, Ph.D.

SANS Technology Institute

Twitter

(c) SANS Internet Storm Center. http://isc.sans.org Creative Commons Attribution-Noncommercial 3.0 United States License.

View full post on SANS Internet Storm Center, InfoCON: green



Some Content may originate from third party websites(i.e. Amazon, Yahoo Answers, Youtube)
Internet SecuritT Group LLC is not responsible or liable for the content of any third party affiliate
All third party content is property of the respective owners.