PREVIOUS GNEWS "This is Gary Gnu... and the no gnews is good gnews show. The ONLY tv gnews show guar-an-TEED-- to contain NO gnews what-so-ever."

Slides:



Advertisements
Similar presentations
Creating Stronger, Safer, Web Facing Code JPL IT Security Mary Rivera June 17, 2011.
Advertisements

PREVIOUS GNEWS "This is Gary Gnu... and the no gnews is good gnews show. The ONLY tv gnews show guar-an-TEED-- to contain NO gnews what-so-ever."
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
PREVIOUS GNEWS. 4 Patches – 9 bugs addressed Affecting Windows, SQL, Exchange (OWA) Other updates, MSRT, Defender Definitions, Junk Mail Filter 8 Security.
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
Advanced Security Center Overview Northern Illinois University.
Lesson 9-Securing a Network. Overview Identifying threats to the network security. Planning a secure network.
“Today over 70% of attacks against a company’s network come at the ‘Application Layer’ not the Network or System layer.” - Gartner Is Your Web Application.
Vulnerabilities. flaws in systems that allow them to be exploited provide means for attackers to compromise hosts, servers and networks.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Word, Outlook, Publisher, Jet DB Engine, IE, Windows Other updates, MSRT, Defender Definitions,
1 Infrastructure Hardening. 2 Objectives Why hardening infrastructure is important? Hardening Operating Systems, Network and Applications.
Ladd Van Tol Senior Software Engineer Security on the Web Part One - Vulnerabilities.
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. 7 Patches – x bugs addressed Affecting Word, Outlook, Publisher, Jet DB Engine, IE, Windows Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
WEBSENSE ® SECURITY LABS™ 2006 Semi-Annual Web Security Trends Report OWASP Presentation November 9, 2006 Jim Young (301)
3-Protecting Systems Dr. John P. Abraham Professor UTPA.
PREVIOUS GNEWS. 8 Patches – 10 bugs addressed Affecting Project, Visio, DNS, GDI, Scripting, Activex, IE, Windows Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 2 Patches / 3 Vulns – 1 Critical Affecting Windows XP, Vista, 7, 2003, 2008 Other updates, MSRT, Defender Definitions, Junk Mail Filter.
1 Internet Browsing Vulnerabilities and Security ECE4112 Final Lab Ye Yan Frank Park Scott Kim Neil Joshi.
PREVIOUS GNEWS. 4 Patches – 12 bugs addressed Affecting Office, Visual Studio, BizTalk Other updates, MSRT, Defender Definitions, Junk Mail Filter 4 Security.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
I-Hack’08 International Hacking Competition “Details”
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Windows, SQL, Office, Visual Studio,.Net Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. 6 Patches, 15 bug – 3 Critical, Affects 2000, XP, Srv 2003 / 8, Vista, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. Advanced Notification on Thursday Patch Tuesday.
. Next Week Yo! Patch Tuesday Java Multiple advisories and updates Openssl DoS in ASN1_STRING_print_ex() cisco ios DoS in Cisco Tunneling.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
Web Security Group 5 Adam Swett Brian Marco. Why Web Security? Web sites and web applications constantly growing Complex business applications are now.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
Previous Gnews. Patch Tuesday April – 8 Patches (5 high/critical), Windows, Excel, ISA, IE, HTTP Services MS thru MS May – 1 Patch (critical)
PREVIOUS GNEWS. 2 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
Mark Shtern.  Our life depends on computer systems  Traffic control  Banking  Medical equipment  Internet  Social networks  Growing number of.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter Out of Band Patchs –MS – IE Cumulative Security Update / Activex –MS
Vulnerabilities in Operating Systems Michael Gaydeski COSC December 2008.
PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Implementing Client Security on Windows 2000 and Windows XP Level 150
All images scavenged without permission
Presentation transcript:

PREVIOUS GNEWS "This is Gary Gnu... and the no gnews is good gnews show. The ONLY tv gnews show guar-an-TEED-- to contain NO gnews what-so-ever."

Patch Tuesday 1 Out of Cycle Patch, 7 bugs addressed –MS07-017, Vulnerabiities in GDI could allow remote executioin (925902) 10 Patches originally expected –5 Security, 4 Non-Security related updates, Malicious Software Removal Tool Update 5 Security Patches, 8 bugs addressed –MS Microsoft Content Management Server Could Allow Remote Code Execution (925939) –MS Universal Plug and Play Could Allow Remote Code Execution (931261) –MS Microsoft Agent Could Allow Remote Code Execution (932168) –MS CSRSS Could Allow Remote Code Execution (930178) –MS Windows Kernel Could Allow Elevation of Privilege (931784)

Holes Month of PHP Bugs (March), 45 Bugs released –14 do not require PoC/Exploit code –7 PoC/Exploit code coming soon –3 Bonus bugs, not in PHP (1 mod_security, 2 Zend Platform) –PHP expected April 5 th (late) –Stefan eludes to repeat perfromance “Yeah “The Return of the MOPB” will be better prepared…” Week of Vista Bugs (First Week of April), Hoax / bad social experiment Month of MySpace Bugs (April), –Mondo Armando and Müstaschio –Not limited to one sploit per day –Bug submissions must include PoC code –self admitted XSS lame-ness PoC Virus for iPod with Linux

DATA LOSS RadioShack, Corpus Christi –CC #s and Personal Information found in the trash California Secretary of State web site, selling ID’s since 2004 Attrition.org lists 14 other Data Loss incidents TrustedID.com lists 2 other Data Loss incidents TJX update, information now found in circulation and use IRS, 500 Stolen laptops, 2,300 records Japan, 8.6 milion records

Holes 2 Open BSD IPv6, - patch available –Remote kernel buffer overflow, improper mbuf handling in ICMP6 Telnet Redux / MIT krb5, - patch available –RedHat McAfee ePolicy Orchestrator / ProtectionPilot ActiveX Control Buffer Overflows, - patch available –boundary errors within the SITEMANAGER.DLL ActiveX Control when processing arguments passed to the "ExportSiteList()" and "VerifyPackageCatalog()" methods. Trend Micro UPX Processing DoS, patch available –Divide by zero error in the anti-virus engine RFID + SQL Injection = ACCESS, PoC to be released –Joshua Perrymon of PacketFocus Security Solutions –SQL inject code written to RFID tag

Games Sony RootKit hacks WOW –Hides cheat processes from Blizzard’s process monitor Xbox Live account hi-jacking Xbox 360 Elite Upgrade –120 GB HD, wireless headset, HiDef port Wii Helm –Good-Bye carpal tunnel, Hello whiplash

Holes 3 IE 7 XSS –navcancl.htm local resource Vista, Windows Mail – with a link, code execution with no warning 0-day, Windows Animated Cursor Handling, - patch availableI –Out of cycle patch released –Reported 113,000 malicious sites via a Google Query Shady Blogger Flamed for posting a speculative view of SP1 –Vista hotfix tracking blog was misrepresented as an SP1 leak Vulnerabilities in Vista implementation of Symbolic Links

Corp. Hell ICANN may seek to be a Private International Organization FCC rules to keep cell phone ban for aircraft Microsoft sued for deceptive Vista advertising, “Vista Capable” DHS Opens National Computer Forensic Institute Oracle sues SAP, claiming documents and software were pilfered from the customer’s only support site

Papers Mark Russinovich wraps up Vista Kernel Series NSA releases Mac Security Guide A new radio spectrum? –A "metamaterial" that selectively filters terahertz radiation could perhaps be used for short-range wireless communications. WEP busted in 1 minute

Film Apple TV –Kernel mod allows full OS X on Apple TV Apple + EMI = AAC standard –DRM-Free deal suggests a shift in the de-facto format

WTF!? Washington State OK’s RFID driver’s license XXX Domain voted down, again Carder Community Releases Private IM Service, CarderIM WiFi Proof Paint Discotequezone, Italian P2P site raided FBI launches “raids” of Second Life casinos Hackers profiled, 8 distinct profiles Air Car Car Navigation Hacking, Radio Data System-Traffic Message Channel (RDS-TMC)

Apollo by Adobe, runtime environment TrueCrypt 4.3 MetaSploit 3 THC Hydra 5.4 Nessus Beta Snortalog Snort 3.0 Beta Python on Planes Windows Change Analysis Tool for XP

Legal 3 rd attempt for Tougher anti-spyware bill –Securely Protect Yourself Against Cyber Trespass Act Potential changes for internet radio based on ruling by the Copyright Royalty Board –Rather than the previous fee based on estimation of plays new rules state fees are based per play NFL Violates DMCA McCain Myspace page ‘goatsed’ Court upholds use of counter hack, generates questions regarding the use of warrantless seizures

CON Results Con Archive - Jikto, Java Script based scanner and more, Shmoocon –Billy Hoffman of SpiDynamics, Choose not to release code but exposed the url with a subsequent leak Cisco NAC bypassed with Credentials Spoofing, Black Hat Europe –Michael Thurmann and Dror-John Roecher of ERNW GmbH Vbootkit, a Vista RooKit,Black Hat Europe –Nitin and Vipin Kumar of NV Labs Flaws in ARM and XScale microprocessors will be demo’ed at CanSec West –Barnaby Jack of Juniper, porcessors used in cell phones and routers

CON Events Completed Cons –ShmooCon, 23 – 25 March Washington D.C –Black Hat Europe, 27 – 30 March - Amsterdam –Hack In The Box, 2 – 5 April - Dubai Future Cons –CanSecWest, 18 – 20 April 2007 – Vancouver –Infosec Europe, 24 – 26 April London –NOTACON, 27 – 29 April Chapel Hill NC –Layerone, 5 – 6 May Pasadena CA –DallasCon, 11 – 12 May 2007 – Dallas, TX –H2K2, 7 – 12 April New York NY –BlackHat, 28 July thru 2 Aug 2007 – Las Vegas, NV –DefCon, 3 – 5 August 2007 – Las Vegas, NV –Hack In The Box, 3 – 6 Sept. – Kuala Lumpur CanSecWest hosts Apple Hacking Competition

All images scavenged without permission