Tampilkan postingan dengan label Vulnerability. Tampilkan semua postingan
FileHippo Vulnerable to XSS flaw found by Security researcher
Kamis, 21 Februari 2013
Posted by Unknown
A Pakistani Security Researcher Ali Hasan Ghauri - founder of AHPT has discovered XSS Vulnerability on Filehippo.com main site. Vulnerability still exists
Last time we published news of W3Schools vulnerable to same XSS flaw reported by the security researcher.
[#] - Website:
http://www.sify.com
[#] - Vulnerable link (POC):
http://www.filehippo.com/it/download_ccleaner/%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%28%22XSS%20By%20Ali%20Hasan%20Ghauri%22%29%3C/script%3E
[#] - Vulnerability Type:
XSS (Cross Site Scripting)
[#] - Status:
Not Fixed [Critical]
[#] - Tested on:
Firefox 18.0.1
The Youngest Pakistani Security Researcher "Ali Hasan Ghauri" (AHPT) also Found Vulnerabilities on Big Tech Sites on Skype , Adobe, Asia Cnet, Yellowpages, visualstudiomagazine ,Filehippo ,CnetDownloads, US.Acer, W3Schools, Hamariweb & Many More.
About Filehippo:
FileHippo is an Internet download website that offers open source, freeware, and shareware programs for Windows. It does not accept user uploaded files.The website also offers its own software, FileHippo Update Checker, a free program that scans a computer and then reports out-dated software in a web-page, offering links to updated versions.
According to Quantcast, FileHippo receives more than three million US visitors each month and Alexa lists FileHippo among the 700 most visited websites worldwide.
More News of XSS flaw can be found here.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: FileHippo Vulnerable to XSS flaw found by Security researcher
BSRT-2013-003 advisory released for Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution. In order to address the issues, RIM has released BlackBerry Enterprise Server 5.0.4 MR2, according to Blackberry.
According to the advisory published by the company, the security holes affect the components that process TIFF images for rendering on BlackBerry smartphones.
In some cases, the security holes could also be leveraged to allow the attacker to extend access to other parts of the network.
In order to exploit the vulnerabilities that affect the Mobile Data System�s Connection Service component, the attacker would have to create a malicious webpage and convince the victim to access it.
The flaws that affect the BlackBerry Messaging Agent or the BlackBerry Collaboration Service components are more dangerous because there�s no user interaction required for the attack to be successful. The attacker must simply attach a specially-crafted TIFF image to an email or an instant message and send it to a BlackBerry smartphone.
�The user does not need to click a link or an image, or view the email message or instant message for the attack to succeed in this scenario,� the company explained.
RIM is not aware of any attacks that have leveraged these vulnerabilities, but taking into account the fact that they are considered to be of high severity, the company advises customers to update to the latest version to ensure they�re fully protected.
In addition to BlackBerry Enterprise Server 5.0.4 MR2, which can be applied to all supported versions of the product, RIM has also released an interim security update.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: RIM Fixes Remote Code Execution Flaws in BlackBerry
Indian Ethical Hackers found a SQL injection flaw at Sify( sify.com). SQLi Vulnerability still exist in the site.
Ethical Hackers from India found a SQL Injection vulnerability at the high profile website sify.com. According to Ethical Hackers, they reported bug to site administration but they didnot respond to the vulnerability.
Website:
About Sify:
Sify is an Internet service provider in India. Seventy five per cent of the 1.6 million visitors in 2008 to the web site sify.com hail from India. It was rated as one of "The ten top technology companies world-wide recommended for investment" by Fortune in 1999.
Sify was one of the first private sector player to offer internet access, when internet access was opened to private sector (until then the state run VSNL had a monopoly in providing internet access). It leased international bandwidth from global vendors, domestic connectivity from telecom players and set up last mile connectivity by multiple methods: wi-fi connections using roof top antennae, copper connections using phone lines or cable TV connections. Sify also started providing internet network connectivity for business enterprises in India. Sify set up a chain of franchised internet cafes (today a network of over 3,300+ cybercafes).
Ethical Hackers from India found a SQL Injection vulnerability at the high profile website sify.com. According to Ethical Hackers, they reported bug to site administration but they didnot respond to the vulnerability.
Website:
http://www.sify.comVulnerable link:
http://www.sify.com/imagegallery/gallery/img_view_sentcard.php?card_number=ssVulnerability Type:
SQL InjectionStatus:
Not Fixed [Critical]
About Sify:
Sify is an Internet service provider in India. Seventy five per cent of the 1.6 million visitors in 2008 to the web site sify.com hail from India. It was rated as one of "The ten top technology companies world-wide recommended for investment" by Fortune in 1999.
Sify was one of the first private sector player to offer internet access, when internet access was opened to private sector (until then the state run VSNL had a monopoly in providing internet access). It leased international bandwidth from global vendors, domestic connectivity from telecom players and set up last mile connectivity by multiple methods: wi-fi connections using roof top antennae, copper connections using phone lines or cable TV connections. Sify also started providing internet network connectivity for business enterprises in India. Sify set up a chain of franchised internet cafes (today a network of over 3,300+ cybercafes).
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Sify.com vulnerable to SQL Injection

