PREVIOUS GNEWS. 6 Patches – 9 bugs addressed Affecting Windows, Outlook Express / Windows Mail, Office, IE Other updates, MSRT, Defender Definitions,

Slides:



Advertisements
Similar presentations
Computing Fundamentals
Advertisements

WebGoat & WebScarab “What is computer security for $1000 Alex?”
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
PREVIOUS GNEWS. 4 Patches – 9 bugs addressed Affecting Windows, SQL, Exchange (OWA) Other updates, MSRT, Defender Definitions, Junk Mail Filter 8 Security.
Chapter 7 HARDENING SERVERS.
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
To receive our video stream in Live Meeting: - Click on “Voice & Video” - Click the drop down next to the camera icon - Select “Show Main Video” Dial-in.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Word, Outlook, Publisher, Jet DB Engine, IE, Windows Other updates, MSRT, Defender Definitions,
Copyright © 2012 Certification Partners, LLC -- All Rights Reserved Lesson 5: Multimedia on the Web.
PREVIOUS GNEWS. 11 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter 11 Security Patches.
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. 7 Patches – x bugs addressed Affecting Word, Outlook, Publisher, Jet DB Engine, IE, Windows Other updates, MSRT, Defender Definitions,
Is Your Mobile App Secure. DEF CON 23 Wall of Sheep Sat
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
Unit 5- Computer Software.  Identify how hardware & software interact  Explain how a software program works  Describe the difference between application.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 4 Patches – 2 bugs addressed Affecting Windows, Windows Servers, Other updates, MSRT, Defender Definitions, Junk Mail Filter, RootCert.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 2 Patches / 3 Vulns – 1 Critical Affecting Windows XP, Vista, 7, 2003, 2008 Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. 4 Patches – 12 bugs addressed Affecting Office, Visual Studio, BizTalk Other updates, MSRT, Defender Definitions, Junk Mail Filter 4 Security.
Where is Askja [äs'kyä] ? In Iceland, elevation 4,954 feet The crater lake was formed after Askja’s most devastating eruption in 1875 The crater itself.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. 7 Patches – 11 bugs addressed Affecting Windows, Windows Servers, Vista, Media Player, DirectX, Macrovision (DRM) Other updates, MSRT,
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
Client-based Application Attacks Adli Abdul Wahid Dept. of Comp. Science, IIUM
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Windows, SQL, Office, Visual Studio,.Net Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. 6 Patches, 15 bug – 3 Critical, Affects 2000, XP, Srv 2003 / 8, Vista, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. Advanced Notification on Thursday Patch Tuesday.
. Next Week Yo! Patch Tuesday Java Multiple advisories and updates Openssl DoS in ASN1_STRING_print_ex() cisco ios DoS in Cisco Tunneling.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
Slides and projects at samsclass.info. Adding Trojans to Apps Slides and projects at samsclass.info.
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
Previous Gnews. Patch Tuesday April – 8 Patches (5 high/critical), Windows, Excel, ISA, IE, HTTP Services MS thru MS May – 1 Patch (critical)
PREVIOUS GNEWS. 2 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
0wning the koobface botnet. intro web 2.0 botnet spreads through social networks –facebook –myspace –twitter, etc.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter Out of Band Patchs –MS – IE Cumulative Security Update / Activex –MS
Vulnerabilities in Operating Systems Michael Gaydeski COSC December 2008.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
Computing Fundamentals
MICROSOFT OUTLOOK and Outlook service Provider
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Presentation transcript:

PREVIOUS GNEWS

6 Patches – 9 bugs addressed Affecting Windows, Outlook Express / Windows Mail, Office, IE Other updates, MSRT, Defender Definitions, Junk Mail Filter, RootCert ** Aug, MS pushed silent patches including devices with auto-update disabled Patch Tuesday 6 Security Patches - 4 Critical, 2 Important –MS – Kodak Image Viewer (win2k) - Remote Code Execution –MS – Outlook Express / Windows Mail - Remote Code Execution (NNTP) –MS – IE Cumulative –MS – RPC – DoS (NTLM) –MS – SharePoint Services 3.0 / Office SharePoint Server 2007 – Privilege Escalation (XSS, in SP) –MS – Word – Remote Code Execution

Books Security Data Visualization: Graphical Techniques for Network Analysis –by Greg Conti Essential Silverlight –by Christian Wenz Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research –by David Maynor, James C. Foster, KK Mookhey, Kevin Harriford –HD PS. In case it wasn't clear, the Metasploit team was not involved with this book in any shape or form. - eBook was very briefly leaked to the metasploit mail list.

Holes / Patches Pwnpress Exploitation Toolkit –code posted to milw0rm Open Office, Tiff document handling (patch available) VMware ESX Server, multiple vulns (patch available) Tor ControlPort torrc Rewrite (patch available) –code posted to milw0rm, ControlPort must be enabled Ruby Net::HTTPS insufficient Validation of Server Certificate CN (patch available) Java JRE, Multiple Vulns (patch available) XEN, privilege escalation (patch available)

DATA LOSS 21 + reported incidents TD Ameritrade –6 million Records, Database compromise ABN Amro –5,000 Records on BearShare Western Oregon University –Student Reporter on file, Paper Advisor fired

Holes / Patches (more) QuickTime –JavaScript on Firefox Apple Patches MOAB #3 for Windows –Command injection via.qtl Automated Solutions Modbus TCP Slave Activex –Arbitrary code on SCADA devices AOL AIM –IE controls, victim must be logged on Gmail XSS

Hacking Multi-Core attacks, Cambridge Professor leverages concurrency New iPod linux-ized Apple WiFi hack details finally released AirRaid2, Thailand WiFi Completion Dec personalwireless.org launches RFID mail list Are botnets are splintering to evade detection?

Holes / Patches (again) Microsoft SQL Server Distributed Management Objects Buffer Overflow –code posted to milw0rm Excel 2007 Multiplication bug –any formula that should evaluate to 65,535 will act strangely Undisclosed 0-day in.pdf files DHS mail list misconfig exposes member s Citrix.ica file harvesting

Corp. Hell Intel buys Havok (physics / animation) Yahoo buys Zimbra (office suite) McAfee buys SafeBoot (encryption) Nokia Buys Navteq (mapping) MS to increase stake in FaceBook One Laptop PerChild announces limited commercial sale in November –$400, you get one, child gets one Google to launch Gphone in 2008 Google StreetView to blur Canada Google drafts an open source license Symantec DeepSight issues false ThreatCon4 alert Wal-Mart RFID venture reported as not meeting expectations

Games All versions PSP Hack Halo3 Games for Grades –Oak Cliff GameStop manager suspended

Film / Music FCC requires analog TV until 2012 Class action suit filed for ala cart TV packaging Trent Reznor condones theft China creates it’s own hi-def format, CH-DVD Virgin Digital closes store Amazon launches DRM-Free store AT&T planning to filter MPAA content Canadian copyright official sacked after MPAA lobbyist relationship exposed BluRay copy protection, BD+, not 100% compatible

Papers Blog - XP Process Throttling Michael G. Kaplan - Receiver Initiated Authentication: A Practical Method to Authenticate Incoming Stanford, CMU, VMware, Xen -Compatibility is Not Transparency: VMM Detection Myths and Realities Web Application Common Criteria scoring drafted Berkeley posting full lectures to YouTube University of Waterloo, Ann Cavoukian – Privacy By Design

Updates iPhone firmware update Apple Leopard may not support 800Mhz G4 Metasploit iPhone payloads FireFox FireFox 3 Anti-Phishing uses Google FireCat 1.2 Gnome 2.2 WordPress 2.3 Flare (flash decompiler) rkhunter aircrak-ptw thc-orkelcracker11g IE7 installer drops WGA checking XP SP3 Beta released

Legal N.runs reposts btcrack code Isp tax ban ends Nov 1 st Two Patriot Act provisions ruled unconstitutional 17 year old with a copy of ‘The Anarchist’s Cookbook’ charged in U.K. under the Terrorism Act 2000 New U.K. laws criminalize refusal to surrender encryption keys TJX ringleader gets 5 years Police recover data on erased CD-RW by writing to disc iPhone law suits

CON Results Simple Nomad discusses IDS / IPS at Security World MS Blue Hat, Blog posts by RFP, Halvar Flake and more MS Blue Hat, Closed WabiSabiLabi exploit auction

CON Events Completed Cons –Security World - - San Francisco CA –MS Blue Hat – Sept 27 – – Redmond WA –ToorCon, 29 Sept - 1 Oct San Diego CA Future Cons –Phreaknic, Oct Nashville TN –LISA, Nov Dallas TX –OWASP + WASC, Nov - San Jose CA –BreakPoint, Nov - Mexico –Chaos Communication Congress, Dec Berlin –InfowarCon 2008 – 2-4 Mar Bethesda MD

All images scavenged without permission