Tampilkan postingan dengan label Zero Day Vulnerability. Tampilkan semua postingan
It is recommended that users should disable the Java program in their Web browsers, because it remains vulnerable to attacks that could result in identity theft and other cyber crimes. Some browsers by default have disabled the JAVA Program. On Sunday, Oracle released a security update that addresses two critical zero-day vulnerabilities in Java that are being actively exploited by attackers, an online vulnerability seller began offering a brand-new Java bug for sale.
According to a report, a Java exploits was being advertised for $5,000 a piece in an underground Internet forum and the new zero-day vulnerability was apparently already in at least one attacker's hands.
The thread has since been deleted from the forum indicating a sale has been made, something sure to bring more concern to Oracle.Oracle can�t predict the future, and its engineers obviously can�t predict what exploits are going to be found in its software.
The most recent hold Java fixed to allow hackers to enter a computer by using compromised websites as the entry-point into Java. Once in the system, they could steal any information, or hook up the computer to a botnet or a string of infected computers that can be used to launch attacks against other computers.
The exploit is valuable because not only is it usable on the most up-to-date version of Java, which could remain vulnerable for weeks, if not months.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Java Zero Day sells on Black market for $5000
Facebook password reset vulnerability found by a security researcher
Rabu, 09 Januari 2013
Posted by Unknown
An independent vulnerability researcher, Sow Ching Shiong, found a way to change the password of any facebook username without knowing his last password. Facebook have fixed this very critical vulnerability. This flaw allow an attacker to change any facebook user's password easily.
Facebook have a recovery page for compromised accounts "https://www.facebook.com/hacked". when clicked, it redirected to another page
"https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"
the parameter f equals to the user id, if any user id is given, password can be changed without any proper authentication.
The vulnerability was very simple to execute. This vulnerability has been confirmed and patched by Facebook Security Team.
Facebook have a recovery page for compromised accounts "https://www.facebook.com/hacked". when clicked, it redirected to another page
"https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"
the parameter f equals to the user id, if any user id is given, password can be changed without any proper authentication.
The vulnerability was very simple to execute. This vulnerability has been confirmed and patched by Facebook Security Team.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Facebook password reset vulnerability found by a security researcher
Symantec product PGP Whole Disk Encryption which is used to encrypt all the contents on the disk on a block-by-block basis having Zero-Day Vulnerability, Exploitation of this issue allows an attacker to execute arbitrary code within the kernel. An attacker would need local access to a vulnerable computer to exploit
this vulnerability.according to a pastebin note.
Note was posted on 25th Dec by Nikita Tarakanov, claiming that pgpwded.sys kernel driver distributed with Symantec PGP Desktop contains an arbitrary memory overwrite vulnerability. Affected version of software is Symantec PGP Desktop 10.2.0 Build 2599 (up-to date).
Symantec confirmed Through a blog post that its a potential issue, but it cannot easily be exploited. Vulnerability is limited to systems running Windows XP and Windows 2003 only. An attacker would need local access to a vulnerable computer to exploit this vulnerability.
Note posted by Nikita also provide technical details on the issue, that help Symantec encryption engineering team to understand the issue.
"However, the exploit would be very difficult to trigger as it relies on the system entering an error condition first. Once in this error condition, the exploit could allow an attacker with lower privileges to run some arbitrary code with higher privileges." Kelvin Kwan said.
Vendor is planning a fix in an upcoming maintenance pack in February.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Symantec PGP Desktop Zero Day Vulnerability



