<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-400</id>
	<title>Nabble - Info Security News (ISN)</title>
	<updated>2008-09-05T02:42:59Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/Info-Security-News-(ISN)-f400.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Info-Security-News-%28ISN%29-f400.html" />
	<subtitle type="html">Carries news items (generally from mainstream sources) that relate to security. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-19328234</id>
	<title>Infamous Israeli hacker linked to $1.8M heist</title>
	<published>2008-09-05T02:42:59Z</published>
	<updated>2008-09-05T02:42:59Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.canada.com/windsorstar/news/business/story.html?id=df98c776-bbb9-4987-8526-6649e56c0574&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.canada.com/windsorstar/news/business/story.html?id=df98c776-bbb9-4987-8526-6649e56c0574&lt;/a&gt;&lt;br&gt;&lt;br&gt;Star News Services
&lt;br&gt;September 05, 2008
&lt;br&gt;&lt;br&gt;CALGARY - Investigators spent nine months using technology and 
&lt;br&gt;old-fashioned sleuthing to find four suspects who allegedly stole $1.8 
&lt;br&gt;million from a Calgary company.
&lt;br&gt;&lt;br&gt;The operation involved the U.S. Secret Service and municipal police in 
&lt;br&gt;Calgary and Vancouver -- as well as in Montreal, where investigators 
&lt;br&gt;arrested four Quebec-based suspects.
&lt;br&gt;&lt;br&gt;Among those charged with theft of credit-card data and fraud is Ehud 
&lt;br&gt;Tenenbaum, an Israeli national living in Montreal. In 1998, a 
&lt;br&gt;19-year-old Israeli named Ehud Tenenbaum -- known online as &amp;quot;the 
&lt;br&gt;Analyzer&amp;quot; -- accessed computers belonging to the Pentagon.
&lt;br&gt;&lt;br&gt;After his conviction, Tenenbaum used his expertise to help Israeli 
&lt;br&gt;organizations protect their computer networks against cyber attacks.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Infamous-Israeli-hacker-linked-to-%241.8M-heist-tp19328234p19328234.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328209</id>
	<title>TIGTA: The IRS lacks secure Web servers</title>
	<published>2008-09-05T02:42:47Z</published>
	<updated>2008-09-05T02:42:47Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.fcw.com/online/news/153690-1.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.fcw.com/online/news/153690-1.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Mary Mosquera
&lt;br&gt;FCW.com
&lt;br&gt;September 4, 2008
&lt;br&gt;&lt;br&gt;Unauthorized and insecure Web servers connect to the Internal Revenue 
&lt;br&gt;Service’s network, which puts the agency’s computers and entire network 
&lt;br&gt;at risk of unauthorized access to taxpayer and personally identifiable 
&lt;br&gt;information, the Treasury Inspector General for Tax Administration said 
&lt;br&gt;in a recent report [1].
&lt;br&gt;&lt;br&gt;The IRS has 1,811 unapproved internal Web servers on the network and 
&lt;br&gt;2,093 internal Web servers that have some security weaknesses, the TIGTA 
&lt;br&gt;report, released Sept. 3, states.
&lt;br&gt;&lt;br&gt;The IRS requires that business units register all internal Web sites and 
&lt;br&gt;Web servers with the Modernization and Information Technology Services 
&lt;br&gt;organization, but some fail to register their servers, the report 
&lt;br&gt;states. The IRS might block unregistered servers from sharing 
&lt;br&gt;information with the network.
&lt;br&gt;&lt;br&gt;Because no office had responsibility for the Web registration program, 
&lt;br&gt;the IRS has not enforced the requirement, allowing Web servers to 
&lt;br&gt;connect to the network without proper authorization and accountability, 
&lt;br&gt;the report states.
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.ustreas.gov/tigta/auditreports/2008reports/200820159fr.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ustreas.gov/tigta/auditreports/2008reports/200820159fr.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br /&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/TIGTA%3A-The-IRS-lacks-secure-Web-servers-tp19328209p19328209.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328178</id>
	<title>Re: ICANN cast as online scam enabler</title>
	<published>2008-09-05T02:42:35Z</published>
	<updated>2008-09-05T02:42:35Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">Forwarded from: Directi &amp;lt;shridhar.l (at) directi.com&amp;gt;
&lt;br&gt;&lt;br&gt;Directi's official response to inaccurate reports which falsely 
&lt;br&gt;implicate the Directi Group
&lt;br&gt;&lt;br&gt;&amp;nbsp;From Bhavin Turakhia’s Desk:
&lt;br&gt;&lt;br&gt;There have been some articles and reports recently published by Garth 
&lt;br&gt;Bruen at Knujon and by Jart Armin and James Mcquad at Hostexploit, that 
&lt;br&gt;somehow link Directi with groups that support organized internet crime. 
&lt;br&gt;The motives behind these reports are still unknown, but as an 
&lt;br&gt;organization that prides itself in setting industry benchmarks in ethics 
&lt;br&gt;and best practices, we are extremely shocked by these allegations. While 
&lt;br&gt;I applaud the efforts of volunteers such as Knujon and Hostexploit who 
&lt;br&gt;spend their personal time to try and combat spam, I am personally quite 
&lt;br&gt;saddened when the very individuals who we trust to combat fraud engage 
&lt;br&gt;in publicity moves without consideration for the reputation of 
&lt;br&gt;legitimate businesses.
&lt;br&gt;&lt;br&gt;Neither Knujon nor Hostexploit extended a basic courtesy of even 
&lt;br&gt;contacting us to verify any of the facts in their report before 
&lt;br&gt;publishing the same. Directi is not even remotely related to the 
&lt;br&gt;organizations or activities listed in those reports. The arguments 
&lt;br&gt;presented in these reports are either downright baseless, or based on 
&lt;br&gt;complete fabrication of facts.
&lt;br&gt;&lt;br&gt;Various other news agencies and blogs have further referenced these 
&lt;br&gt;reports in the form of a story or post, once again without any attempt 
&lt;br&gt;to verify or validate the facts in these reports. Given the amount of 
&lt;br&gt;noise this has created - it is imperative that we clarify our stand and 
&lt;br&gt;rectify the factual inaccuracies in those reports.
&lt;br&gt;&lt;br&gt;The first false and inaccurate report in question is one published by 
&lt;br&gt;Garth Bruen of Knujon. Find below each of the factual inaccuracy or 
&lt;br&gt;misstatement in his report and our response to the same -
&lt;br&gt;&lt;br&gt;1. The report claims that “48 ICANN-accredited Registrars (affiliated 
&lt;br&gt;&amp;nbsp; &amp;nbsp;with Directi) … do not seem to exist and are phantom.” This statement 
&lt;br&gt;&amp;nbsp; &amp;nbsp;is factually incorrect, and was completely unverified by Knujon. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Knujon did not even bother to contact ICANN in this regards to get 
&lt;br&gt;&amp;nbsp; &amp;nbsp;the right facts. The truth of the matter is that all 48 companies 
&lt;br&gt;&amp;nbsp; &amp;nbsp;which belong to Directi and its clients, are in existence and are 
&lt;br&gt;&amp;nbsp; &amp;nbsp;duly incorporated and validly existing under law.
&lt;br&gt;&lt;br&gt;2. Other Online reports further claim that these 48 registrars are 
&lt;br&gt;&amp;nbsp; &amp;nbsp;involved in illicit activities. This allegation is made without 
&lt;br&gt;&amp;nbsp; &amp;nbsp;providing ANY evidence to corroborate the same. This statement is 
&lt;br&gt;&amp;nbsp; &amp;nbsp;grossly inaccurate. The reporters did not bother to support such 
&lt;br&gt;&amp;nbsp; &amp;nbsp;claims with any factual evidence, nor contacted us for clarification. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;All 48 companies combined have under a few thousand customers who 
&lt;br&gt;&amp;nbsp; &amp;nbsp;have registered legitimate domains with these registrars and have not 
&lt;br&gt;&amp;nbsp; &amp;nbsp;received any abuse complaints. Yet these companies have been dragged 
&lt;br&gt;&amp;nbsp; &amp;nbsp;in, without evidence, into an issue that is unrelated to them.
&lt;br&gt;&lt;br&gt;3. Garth of Knujon further claims that the Directi Group owns a company 
&lt;br&gt;&amp;nbsp; &amp;nbsp;by the name of ESTDomains. This is another blatantly false 
&lt;br&gt;&amp;nbsp; &amp;nbsp;insinuation. Directi has never owned ESTDomains. Garth has no 
&lt;br&gt;&amp;nbsp; &amp;nbsp;documentation that shows Directi owning ESTDomains. We have 
&lt;br&gt;&amp;nbsp; &amp;nbsp;challenged Knujon to produce any evidence with respect to this. In 
&lt;br&gt;&amp;nbsp; &amp;nbsp;fact the only relationship between Directi and ESTDomains is that 
&lt;br&gt;&amp;nbsp; &amp;nbsp;ESTDomains has purchased certain software from Logicboxes a few years 
&lt;br&gt;&amp;nbsp; &amp;nbsp;ago to power their Registrar operations. They are otherwise an 
&lt;br&gt;&amp;nbsp; &amp;nbsp;independent company and we do not control their actions or their 
&lt;br&gt;&amp;nbsp; &amp;nbsp;behavior.
&lt;br&gt;&lt;br&gt;4. Another claim in the reports is that Directi sponsors illegal 
&lt;br&gt;&amp;nbsp; &amp;nbsp;pharmacy related domain names and that If and when the site content 
&lt;br&gt;&amp;nbsp; &amp;nbsp;is closed by the ISP host, Directi/PublicDomainsRegistry (sic) just 
&lt;br&gt;&amp;nbsp; &amp;nbsp;helps them set up at a new IP This accusation is once again baseless 
&lt;br&gt;&amp;nbsp; &amp;nbsp;- we certainly do not condone any abusive behavior, much less 
&lt;br&gt;&amp;nbsp; &amp;nbsp;facilitate it. Despite the fact that policing the Internet does not 
&lt;br&gt;&amp;nbsp; &amp;nbsp;fall under the purview of a domain name Registrars’ responsibility, 
&lt;br&gt;&amp;nbsp; &amp;nbsp;we work hard to clamp down abuse, from a moral standpoint. Infact the 
&lt;br&gt;&amp;nbsp; &amp;nbsp;report again contains no evidence of a single domain name where WE 
&lt;br&gt;&amp;nbsp; &amp;nbsp;have explicitly assisted a miscreant in migrating from one IP address 
&lt;br&gt;&amp;nbsp; &amp;nbsp;to another. Quite the contrary, despite not having any legal 
&lt;br&gt;&amp;nbsp; &amp;nbsp;obligation to do so as a Registar, we still takedown over 95% of the 
&lt;br&gt;&amp;nbsp; &amp;nbsp;domains for which we receive abuse complaints within 24 hours of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;receiving these complaints. We invest significant resources towards 
&lt;br&gt;&amp;nbsp; &amp;nbsp;ensuring that all abuse complaints are thoroughly investigated and 
&lt;br&gt;&amp;nbsp; &amp;nbsp;swiftly acted upon.
&lt;br&gt;&lt;br&gt;5. The reports state that the privacy protection service that we provide 
&lt;br&gt;&amp;nbsp; &amp;nbsp;intentionally harbors abusive domain names and should not be offered 
&lt;br&gt;&amp;nbsp; &amp;nbsp;for domain names. PrivacyProtect.org was created to safeguard genuine 
&lt;br&gt;&amp;nbsp; &amp;nbsp;domain owners from the very threats that KnujOn perceives it to 
&lt;br&gt;&amp;nbsp; &amp;nbsp;protect. Millions of genuine domain registrants and customers of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Directi are using the privacy protection services we offer and are 
&lt;br&gt;&amp;nbsp; &amp;nbsp;very happy that we provide the same since it protects their email 
&lt;br&gt;&amp;nbsp; &amp;nbsp;addresses from being harvested and protects their identity from 
&lt;br&gt;&amp;nbsp; &amp;nbsp;spammers and miscreants. We also maintain a strict zero-tolerance 
&lt;br&gt;&amp;nbsp; &amp;nbsp;policy w.r.t. abuse of our privacy protection services, and any 
&lt;br&gt;&amp;nbsp; &amp;nbsp;domain name proven to indulge in illegal activities has its 
&lt;br&gt;&amp;nbsp; &amp;nbsp;protection immediately revoked. We challenge Knujon to find an 
&lt;br&gt;&amp;nbsp; &amp;nbsp;example wherein a complaint was made to our privacy protection 
&lt;br&gt;&amp;nbsp; &amp;nbsp;service and was not actioned upon.
&lt;br&gt;&lt;br&gt;6. The report claims “EstDomains is a Registrar that also makes heavy 
&lt;br&gt;&amp;nbsp; &amp;nbsp;use of the PrivacyProtect.org service for masking the ownership of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;fake pharmacy domains.” Long before this report was ever published, 
&lt;br&gt;&amp;nbsp; &amp;nbsp;we had already discontinued our privacy protection services to 
&lt;br&gt;&amp;nbsp; &amp;nbsp;ESTDomains as per our zero tolerance policy. Knujon again choose not 
&lt;br&gt;&amp;nbsp; &amp;nbsp;to verify their facts before publishing such assertions.
&lt;br&gt;&lt;br&gt;7. Further updates from Garth and other sites state that we are in the 
&lt;br&gt;&amp;nbsp; &amp;nbsp;process of severing our relationship with ESTDomains making it sound 
&lt;br&gt;&amp;nbsp; &amp;nbsp;as if we were harboring ESTDomains all this while and are now 
&lt;br&gt;&amp;nbsp; &amp;nbsp;canceling their services This assertion is incorrect. The only 
&lt;br&gt;&amp;nbsp; &amp;nbsp;relationship Directi has had with ESTDomains is that of a software 
&lt;br&gt;&amp;nbsp; &amp;nbsp;vendor. We have discontinued providing privacy protection services to 
&lt;br&gt;&amp;nbsp; &amp;nbsp;them a few months ago. However ESTDomains continues to use software 
&lt;br&gt;&amp;nbsp; &amp;nbsp;that they purchased from Directi since several years. We do not 
&lt;br&gt;&amp;nbsp; &amp;nbsp;control their actions in this respect. None of our steps in terms of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;abuse prevention are knee jerk reactions to these reports because 
&lt;br&gt;&amp;nbsp; &amp;nbsp;these reports do not carry any factual data. We are not responsible 
&lt;br&gt;&amp;nbsp; &amp;nbsp;for domains registered through ESTDomains in any manner and cannot 
&lt;br&gt;&amp;nbsp; &amp;nbsp;suspend them or prevent abuse on them.
&lt;br&gt;&lt;br&gt;The second false and inaccurate report in question is one published by 
&lt;br&gt;Jart Armin and James Mcquad at Hostexploit. Here are our responses to 
&lt;br&gt;the claims in that report -
&lt;br&gt;&lt;br&gt;1. This report deals with the purported abusive and illegal activities 
&lt;br&gt;&amp;nbsp; &amp;nbsp;of a company called Atrivo, goes on to associate the Directi group 
&lt;br&gt;&amp;nbsp; &amp;nbsp;with Atrivo. Most of the accusations in this report are based on the 
&lt;br&gt;&amp;nbsp; &amp;nbsp;notion that the Directi Group has some association with Atrivo. In 
&lt;br&gt;&amp;nbsp; &amp;nbsp;fact, the report states one of “the most important of these (cyber 
&lt;br&gt;&amp;nbsp; &amp;nbsp;crime) Atrivo associations” as “PrivacyProtect (anonymous 
&lt;br&gt;&amp;nbsp; &amp;nbsp;registrant), LogicBoxes (hosting servers)”.This statement is 
&lt;br&gt;&amp;nbsp; &amp;nbsp;completely incorrect. Neither is Atrivo associated with LogicBoxes, 
&lt;br&gt;&amp;nbsp; &amp;nbsp;nor is it being hosted by LogicBoxes, nor have they registered their 
&lt;br&gt;&amp;nbsp; &amp;nbsp;domain name through LogicBoxes. In fact there is no link between 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Atrivo and LogicBoxes, except the fact that Atrivo is a customer of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;ESTDomains and ESTDomains is a customer of LogicBoxes. The Directi 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Group does not have, and has NEVER had, any association with either 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Atrivo or their business practices. Directi and Logicboxes are 
&lt;br&gt;&amp;nbsp; &amp;nbsp;neither a vendor nor a customer nor a business associate of Atrivo. 
&lt;br&gt;&amp;nbsp; &amp;nbsp;Directi received no courtesy information request from the authors of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;this report to verify this claim. The report shows no evidence of any 
&lt;br&gt;&amp;nbsp; &amp;nbsp;such association.
&lt;br&gt;&lt;br&gt;2. This report, in its investigations of our privacy protection service, 
&lt;br&gt;&amp;nbsp; &amp;nbsp;goes on to detail the name server and whois information of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;privacyprotect.com (which is not affiliated with us) instead of 
&lt;br&gt;&amp;nbsp; &amp;nbsp;privacyprotect.org, which perhaps epitomizes the quality of research 
&lt;br&gt;&amp;nbsp; &amp;nbsp;on which the report is based. From a simple whois query, and a quick 
&lt;br&gt;&amp;nbsp; &amp;nbsp;visit to these websites, it is amply clear that these two entities 
&lt;br&gt;&amp;nbsp; &amp;nbsp;are in no way connected with each other.
&lt;br&gt;&lt;br&gt;3. Like the previous report, this report also claims that ESTDomains 
&lt;br&gt;&amp;nbsp; &amp;nbsp;provides use of Directi’s privacy protection services - which, as 
&lt;br&gt;&amp;nbsp; &amp;nbsp;clarified above, is absolutely false and inaccurate at the time the 
&lt;br&gt;&amp;nbsp; &amp;nbsp;report was published.
&lt;br&gt;&lt;br&gt;If you are a news agency or a blog or a news site that has quoted any of 
&lt;br&gt;the above mentioned reports with false allegations about Directi and 
&lt;br&gt;LogicBoxes, we request you to post this update in its entirety in a 
&lt;br&gt;visible manner with a link from the existing article’s headline with a 
&lt;br&gt;byline that can state “Update: Directi disclaims all allegations in the 
&lt;br&gt;knujon / hostexploit reports as baseless and factually incorrect“, since 
&lt;br&gt;you are currently carrying false and defamatory statements without 
&lt;br&gt;verification or evidence on the same and have caused considerable 
&lt;br&gt;reputation loss to our organization. Several of you who have already 
&lt;br&gt;updated your respective websites, and confirmed the same to us - we 
&lt;br&gt;thank you for your cooperation and urge you to ensure that in the future 
&lt;br&gt;when referencing reports of this nature, you at least extend the 
&lt;br&gt;subject, a basic courtesy of confirming the facts. The reputation damage 
&lt;br&gt;that has been caused as a result of this incident is considerable.
&lt;br&gt;&lt;br&gt;Today, Directi continues to be one of the most proactive Registrars in 
&lt;br&gt;combating abuse and implementing strict AUPs. We have a significant 
&lt;br&gt;investment in terms of manpower and processes to achieve just this. We 
&lt;br&gt;do so, not because we’re contractually obligated, or to protect our own 
&lt;br&gt;business interests, but because we sincerely believe in the ideology of 
&lt;br&gt;making the internet a safer and more secure medium for conducting 
&lt;br&gt;business.
&lt;br&gt;&lt;br&gt;However it is reports and claims like these that are disappointing to 
&lt;br&gt;any white hat, genuinely conscientious Registrar, wherein despite our 
&lt;br&gt;continuous efforts, organizations such as Knujon and HostExploit, 
&lt;br&gt;without attempting to verify facts, publish libelous and false 
&lt;br&gt;allegations. Even a basic common courtesy of contacting us was not 
&lt;br&gt;extended prior to publishing these reports.
&lt;br&gt;&lt;br&gt;While Directi will take all steps necessary to protect its interests, we 
&lt;br&gt;hope that this type of an incident is not repeated in the future and 
&lt;br&gt;that online press and media take some basic steps to verify their 
&lt;br&gt;stories before maligning someone falsely on the Internet at large.
&lt;br&gt;&lt;br&gt;&lt;br&gt;--
&lt;br&gt;View this message in context: 
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/ICANN-cast-as-online-scam-enabler-tp19283495p19313470.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/ICANN-cast-as-online-scam-enabler-tp19283495p19313470.html&lt;/a&gt;&lt;br&gt;Sent from the Info Security News (ISN) mailing list archive at Nabble.com.
&lt;br&gt;&lt;br&gt;&lt;br /&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ICANN-cast-as-online-scam-enabler-tp19283495p19328178.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328148</id>
	<title>Obama alma mater gets an education in 'net security</title>
	<published>2008-09-05T02:42:15Z</published>
	<updated>2008-09-05T02:42:15Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.networkworld.com/news/2008/090308-punahou-sudents-laptop.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.networkworld.com/news/2008/090308-punahou-sudents-laptop.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Ellen Messmer 
&lt;br&gt;Network World
&lt;br&gt;09/03/2008
&lt;br&gt;&lt;br&gt;Punahou School in Honolulu has moved into the networking vanguard since 
&lt;br&gt;presidential candidate Barack Obama graduated from the K-12 school in 
&lt;br&gt;1979.
&lt;br&gt;&lt;br&gt;The private school's 45 buildings are now connected via a fiber backbone 
&lt;br&gt;and point-to-point laser system for short-range wireless communications, 
&lt;br&gt;with Cisco switches and a voice-over-IP system for 500 phones, all 
&lt;br&gt;installed in just the last two years. The 76-acre campus also is Wi-Fi 
&lt;br&gt;enabled.
&lt;br&gt;&lt;br&gt;Except for the very youngest of Punahou's 3,700 students, most attending 
&lt;br&gt;the school have a laptop assigned to them at the start of the school 
&lt;br&gt;year, and are given strict instructions that it's intended for academic 
&lt;br&gt;purposes, not fun and games.
&lt;br&gt;&lt;br&gt;&amp;quot;We have an acceptable-use policy and students have to sign it, and 
&lt;br&gt;sometimes parents do, too,&amp;quot; says David Parrish, chief architect of the 
&lt;br&gt;IT network at Punahou. (Yes, if Barack Obama were in high school there 
&lt;br&gt;now, he'd have to sign it, too, to use the school computer and network.)
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Obama-alma-mater-gets-an-education-in-%27net-security-tp19328148p19328148.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328127</id>
	<title>Microsoft tackles remote code execution with updates</title>
	<published>2008-09-05T02:42:00Z</published>
	<updated>2008-09-05T02:42:00Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.techworld.com/security/news/index.cfm?newsID=103984&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.techworld.com/security/news/index.cfm?newsID=103984&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Grant Gross
&lt;br&gt;IDG news service
&lt;br&gt;05 September 2008
&lt;br&gt;&lt;br&gt;Microsoft is to release four critical updates next Tuesday.
&lt;br&gt;&lt;br&gt;The patches to be released on so-called Patch Tuesday include fixes for 
&lt;br&gt;a vulnerability that allows remote code execution in Windows Media 
&lt;br&gt;Player 11 on various Microsoft operating systems and for a vulnerability 
&lt;br&gt;that allows remote code execution in various versions of the Windows OS 
&lt;br&gt;and related products, including 2003 Server, Vista, XP, Office, .Net 
&lt;br&gt;Framework, Works, Visual Studio, Visual FoxPro and other software.
&lt;br&gt;&lt;br&gt;The two other patches will address remote code execution in Windows 
&lt;br&gt;Media Encoder 9 and in Office and Office OneNote 2007.
&lt;br&gt;&lt;br&gt;More information is available at Microsoft's site [1].
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-sep.mspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms08-sep.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Microsoft-tackles-remote-code-execution-with-updates-tp19328127p19328127.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328102</id>
	<title>Lessons Learned: This Time, New Orleans VARs Were Ready</title>
	<published>2008-09-05T02:41:44Z</published>
	<updated>2008-09-05T02:41:44Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.crn.com/it-channel/210500009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.crn.com/it-channel/210500009&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Scott Campbell
&lt;br&gt;ChannelWeb
&lt;br&gt;Sept. 04, 2008
&lt;br&gt;&lt;br&gt;The power is still out, cell phones calls still fail and businesses will 
&lt;br&gt;remain closed today. But New Orleans is breathing a lot easier.
&lt;br&gt;&lt;br&gt;The city took a big hit over the Labor Day weekend from Hurricane 
&lt;br&gt;Gustav, but it was spared the devastation wrought three years earlier by 
&lt;br&gt;Katrina. And this time, local solution providers were ready.
&lt;br&gt;&lt;br&gt;Overall, the evacuation of New Orleans was a more efficient operation 
&lt;br&gt;compared to Katrina. Emergency officials improved their response plan 
&lt;br&gt;following the chaos that ensued during Hurricane Katrina and the same 
&lt;br&gt;can be said for solution providers too. This time, they were better able 
&lt;br&gt;to help customers backup systems and prepare their businesses for the 
&lt;br&gt;possibility of an emergency.
&lt;br&gt;&lt;br&gt;Solution providers along the Gulf Coast developed new strategies after 
&lt;br&gt;Katrina, and Gustav was the first big test to see if the changes would 
&lt;br&gt;prove successful. Several VARs said all their hard work paid off.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Lessons-Learned%3A-This-Time%2C-New-Orleans-VARs-Were-Ready-tp19328102p19328102.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328074</id>
	<title>Secunia Weekly Summary - Issue: 2008-36</title>
	<published>2008-09-05T02:41:28Z</published>
	<updated>2008-09-05T02:41:28Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">========================================================================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The Secunia Weekly Advisory Summary &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-08-28 - 2008-09-04 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This week: 61 advisories &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;Table of Contents:
&lt;br&gt;&lt;br&gt;1.....................................................Word From Secunia
&lt;br&gt;2....................................................This Week In Brief
&lt;br&gt;3...............................This Weeks Top Ten Most Read Advisories
&lt;br&gt;4.......................................Vulnerabilities Summary Listing
&lt;br&gt;5.......................................Vulnerabilities Content Listing
&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;1) Word From Secunia:
&lt;br&gt;&lt;br&gt;Try the Secunia Network Software Inspector (NSI) 2.0 for free! The
&lt;br&gt;Secunia NSI 2.0 is available as a 7-day trial download and can be used
&lt;br&gt;to scan up to 3 hosts within your network.
&lt;br&gt;&lt;br&gt;Download the Secunia NSI trial version from:
&lt;br&gt;&lt;a href=&quot;https://psi.secunia.com/NSISetup.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://psi.secunia.com/NSISetup.exe&lt;/a&gt;&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;2) This Week in Brief:
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware Workstation,
&lt;br&gt;which can be exploited by malicious, local users to gain escalated
&lt;br&gt;privileges and by malicious people to cause a DoS (Denial of Service)
&lt;br&gt;and potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;For more information, refer to:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31707/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31707/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;Secunia Research has discovered a vulnerability in Novell iPrint
&lt;br&gt;Client, which can be exploited by malicious people to compromise a
&lt;br&gt;user's system.
&lt;br&gt;&lt;br&gt;For more information, refer to:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31370/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31370/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;VIRUS ALERTS:
&lt;br&gt;&lt;br&gt;During the past week Secunia collected 232 virus descriptions from the
&lt;br&gt;Antivirus vendors. However, none were deemed MEDIUM risk or higher
&lt;br&gt;according to the Secunia assessment scale.
&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;3) This Weeks Top Ten Most Read Advisories:
&lt;br&gt;&lt;br&gt;1. &amp;nbsp;[SA31549] Opera Multiple Vulnerabilities
&lt;br&gt;2. &amp;nbsp;[SA31684] Novell eDirectory Multiple Vulnerabilities
&lt;br&gt;3. &amp;nbsp;[SA31708] VMware Server Multiple Vulnerabilities
&lt;br&gt;4. &amp;nbsp;[SA31707] VMware Workstation Multiple Vulnerabilities
&lt;br&gt;5. &amp;nbsp;[SA31667] Sun Solaris Kernel Covert Channel Security Bypass
&lt;br&gt;6. &amp;nbsp;[SA31587] HP TCP/IP Services for OpenVMS Finger Format String
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vulnerability
&lt;br&gt;7. &amp;nbsp;[SA31640] OpenOffice &amp;quot;rtl_allocateMemory()&amp;quot; Truncation
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vulnerability
&lt;br&gt;8. &amp;nbsp;[SA31681] dotProject SQL Injection and Cross-Site Scripting
&lt;br&gt;9. &amp;nbsp;[SA14652] Subdreamer Light Global Variables SQL Injection
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vulnerability
&lt;br&gt;10. [SA31651] HP-UX update for Apache
&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;4) Vulnerabilities Summary Listing
&lt;br&gt;&lt;br&gt;Windows:
&lt;br&gt;[SA31710] VMware ACE Multiple Vulnerabilities
&lt;br&gt;[SA31666] Acoustica MP3 CD Burner ASX Playlist Buffer Overflow
&lt;br&gt;[SA31660] Acoustica Beatcraft Project File Buffer Overflow
&lt;br&gt;Vulnerability
&lt;br&gt;[SA31727] @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;[SA31715] Softalk Mail Server IMAP Denial of Service Vulnerability
&lt;br&gt;[SA31693] PageR Enterprise Directory Traversal Vulnerability
&lt;br&gt;&lt;br&gt;UNIX/Linux:
&lt;br&gt;[SA31736] SUSE update for IBMJava5-JRE and java-1_5_0-ibm 
&lt;br&gt;[SA31711] VMware Fusion Multiple Vulnerabilities
&lt;br&gt;[SA31687] SUSE Update for Multiple Packages
&lt;br&gt;[SA31671] Najdi.si Toolbar Buffer Overflow Vulnerability
&lt;br&gt;[SA31745] FreeBSD ICMPv6 &amp;quot;Packet Too Big&amp;quot; MTU Denial of Service
&lt;br&gt;Vulnerability
&lt;br&gt;[SA31742] Astaro Security Gateway DNS Cache Poisoning
&lt;br&gt;[SA31738] Slackware update for php
&lt;br&gt;[SA31728] Ubuntu update for libxml2
&lt;br&gt;[SA31725] ClamAV CHM Processing Denial of Service
&lt;br&gt;[SA31722] eliteCMS &amp;quot;page&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31712] VMware ESX Server Multiple Vulnerabilities
&lt;br&gt;[SA31702] HP-UX update for Netscape / Red Hat Directory Server
&lt;br&gt;[SA31699] PHP Coupon Script &amp;quot;id&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31698] Ubuntu update for tiff
&lt;br&gt;[SA31697] rPath update for ruby
&lt;br&gt;[SA31676] Newsbeuter URL Processing Shell Command Execution
&lt;br&gt;[SA31670] Red Hat update for libtiff
&lt;br&gt;[SA31668] Red Hat update for libtiff
&lt;br&gt;[SA31720] @Mail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;[SA31713] VMware ESX / ESXi Server Multiple Vulnerabilities
&lt;br&gt;[SA31691] Debian update for slash
&lt;br&gt;[SA31743] FreeBSD AMD64 General Protection Fault Privilege Escalation
&lt;br&gt;[SA31685] Avaya Products Linux Kernel Multiple Vulnerabilities
&lt;br&gt;[SA31663] Slackware update for amarok
&lt;br&gt;[SA31739] IBM AIX &amp;quot;swcons&amp;quot; Command Privilege Escalation Vulnerability
&lt;br&gt;[SA31716] Postfix epoll File Descriptor Leak Security Issue
&lt;br&gt;[SA31694] GpsDrive &amp;quot;geo-code&amp;quot; Insecure Temporary Files
&lt;br&gt;[SA31689] Avaya Products Linux Kernel Local Denial of Service
&lt;br&gt;[SA31667] Sun Solaris Kernel Covert Channel Security Bypass
&lt;br&gt;&lt;br&gt;Other:
&lt;br&gt;[SA31730] Cisco ASA and PIX Security Appliances Multiple
&lt;br&gt;Vulnerabilities
&lt;br&gt;[SA31673] IBM WebSphere Application Server for z/OS HTTP Server
&lt;br&gt;mod_proxy_ftp Vulnerability
&lt;br&gt;[SA31680] Kyocera FS-118MFP Command Center Directory Traversal
&lt;br&gt;Vulnerability
&lt;br&gt;[SA31665] Belkin Wireless G Router Web Interface Authentication Bypass
&lt;br&gt;&lt;br&gt;Cross Platform:
&lt;br&gt;[SA31709] VMware Player Multiple Vulnerabilities
&lt;br&gt;[SA31708] VMware Server Multiple Vulnerabilities
&lt;br&gt;[SA31707] VMware Workstation Multiple Vulnerabilities
&lt;br&gt;[SA31723] Ruby on Rails REXML Denial of Service Vulnerability
&lt;br&gt;[SA31703] Reciprocal Links Manager &amp;quot;site&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31696] Living Local Website &amp;quot;r&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31683] Invision Power Board Multiple Vulnerabilities
&lt;br&gt;[SA31682] EasyClassifields &amp;quot;go&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31678] Novell IDM Cross-Site Scripting and Script Insertion
&lt;br&gt;[SA31674] Wireshark Denial of Service Vulnerabilities
&lt;br&gt;[SA31669] CMSbright &amp;quot;id_rub_page&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31664] Spice Classifieds &amp;quot;cat_path&amp;quot; SQL Injection Vulnerability
&lt;br&gt;[SA31684] Novell eDirectory Multiple Vulnerabilities
&lt;br&gt;[SA31735] Celerondude Uploader &amp;quot;username&amp;quot; Cross-Site Scripting
&lt;br&gt;Vulnerability
&lt;br&gt;[SA31729] Django Authentication Cross-Site Request Forgery
&lt;br&gt;[SA31719] Open Media Collectors Database Cross-Site Scripting and
&lt;br&gt;Request Forgery
&lt;br&gt;[SA31681] dotProject SQL Injection and Cross-Site Scripting
&lt;br&gt;[SA31679] vtiger CRM Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;[SA31662] Blogn Cross-Site Scripting and Cross-Site Request Forgery
&lt;br&gt;[SA31661] Brim SQL Injection and Script Insertion Vulnerabilities
&lt;br&gt;[SA31731] Cisco Secure ACS EAP Packet Denial of Service
&lt;br&gt;[SA31688] HP OpenView Network Node Manager Denial of Service
&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;5) Vulnerabilities Content Listing
&lt;br&gt;&lt;br&gt;Windows:--
&lt;br&gt;&lt;br&gt;[SA31710] VMware ACE Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware ACE, which can
&lt;br&gt;be exploited by malicious, local users to gain escalated privileges and
&lt;br&gt;by malicious people to potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31710/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31710/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31666] Acoustica MP3 CD Burner ASX Playlist Buffer Overflow
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;n00b has discovered a vulnerability in Acoustica MP3 CD Burner, which
&lt;br&gt;can be exploited by malicious people to compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31666/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31666/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31660] Acoustica Beatcraft Project File Buffer Overflow
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;Koshi has discovered a vulnerability in Acoustica Beatcraft, which can
&lt;br&gt;be exploited by malicious people to compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31660/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31660/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31727] @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;C1c4Tr1Z has discovered some vulnerabilities in @Mail WebMail, which
&lt;br&gt;can be exploited by malicious people to conduct cross-site scripting
&lt;br&gt;attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31727/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31727/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31715] Softalk Mail Server IMAP Denial of Service Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Joo Antunes has discovered a vulnerability in Softalk Mail Server,
&lt;br&gt;which can be exploited by malicious users to cause a DoS (Denial of
&lt;br&gt;Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31715/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31715/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31693] PageR Enterprise Directory Traversal Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Exposure of system information, Exposure of sensitive
&lt;br&gt;information
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in PageR Enterprise, which can be
&lt;br&gt;exploited by malicious users to disclose potentially sensitive
&lt;br&gt;information.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31693/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31693/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;UNIX/Linux:--
&lt;br&gt;&lt;br&gt;[SA31736] SUSE update for IBMJava5-JRE and java-1_5_0-ibm 
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Bypass, Exposure of system information, Exposure
&lt;br&gt;of sensitive information, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;SUSE has issued an update for IBMJava5-JRE and java-1_5_0-ibm. This
&lt;br&gt;fixes some vulnerabilities, which can be exploited by malicious people
&lt;br&gt;to bypass certain security restrictions, disclose system information or
&lt;br&gt;potentially sensitive information, cause a DoS (Denial of Service), or
&lt;br&gt;compromise a vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31736/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31736/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31711] VMware Fusion Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware Fusion, which
&lt;br&gt;can be exploited by malicious people to cause a DoS (Denial of Service)
&lt;br&gt;and potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31711/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31711/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31687] SUSE Update for Multiple Packages
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Bypass, Cross Site Scripting, Spoofing, Exposure
&lt;br&gt;of system information, Exposure of sensitive information, Privilege
&lt;br&gt;escalation, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;SUSE has issued an update for multiple packages. This fixes some
&lt;br&gt;vulnerabilities, which can be exploited by malicious, local users to
&lt;br&gt;disclose potentially sensitive information, gain escalated privileges,
&lt;br&gt;and bypass certain security restrictions, by malicious users to conduct
&lt;br&gt;script insertion attacks and cause a DoS (Denial of Service), and by
&lt;br&gt;malicious people to disclose potentially sensitive information, conduct
&lt;br&gt;cross-site scripting attacks, cause a DoS, poison the DNS cache, and
&lt;br&gt;potentially compromise a vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31687/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31687/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31671] Najdi.si Toolbar Buffer Overflow Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;shinnai has discovered a vulnerability in Najdi.si Toolbar, which can
&lt;br&gt;be exploited by malicious people to compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31671/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31671/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31745] FreeBSD ICMPv6 &amp;quot;Packet Too Big&amp;quot; MTU Denial of Service
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;FreeBSD has acknowledged a vulnerability, which can be exploited by
&lt;br&gt;malicious people to cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31745/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31745/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31742] Astaro Security Gateway DNS Cache Poisoning
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Spoofing
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Astaro has acknowledged a vulnerability in Astaro Security Gateway,
&lt;br&gt;which can be exploited by malicious people to poison the DNS cache.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31742/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31742/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31738] Slackware update for php
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Unknown, Exposure of sensitive information, DoS, System
&lt;br&gt;access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Slackware has issued an update for php. This fixes some
&lt;br&gt;vulnerabilities, where some have an unknown impact and others can
&lt;br&gt;potentially be exploited by malicious people to disclose sensitive
&lt;br&gt;information, cause a DoS (Denial of Service), or compromise a
&lt;br&gt;vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31738/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31738/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31728] Ubuntu update for libxml2
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Ubuntu has issued an update for libxml2. This fixes a vulnerability,
&lt;br&gt;which can be exploited by malicious people to cause a DoS (Denial of
&lt;br&gt;Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31728/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31728/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31725] ClamAV CHM Processing Denial of Service
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in ClamAV, which can be exploited by
&lt;br&gt;malicious people to cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31725/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31725/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31722] eliteCMS &amp;quot;page&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data, Exposure of sensitive information
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;e.wiZz! has discovered a vulnerability in eliteCMS, which can be
&lt;br&gt;exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31722/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31722/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31712] VMware ESX Server Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware ESX Server,
&lt;br&gt;which can be exploited by malicious people to cause a DoS (Denial of
&lt;br&gt;Service) and potentially compromise a vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31712/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31712/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31702] HP-UX update for Netscape / Red Hat Directory Server
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;HP has issued an update for Netscape / Red Hat Directory Server. This
&lt;br&gt;fixes some vulnerabilities, which can be exploited by malicious people
&lt;br&gt;to conduct cross-site scripting attacks, cause a DoS (Denial of
&lt;br&gt;Service), and potentially compromise a vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31702/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31702/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31699] PHP Coupon Script &amp;quot;id&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Hussin X has reported a vulnerability in PHP Coupon Script, which can
&lt;br&gt;be exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31699/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31699/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31698] Ubuntu update for tiff
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Ubuntu has issued an update for tiff. This fixes a vulnerability, which
&lt;br&gt;can be exploited by malicious people to cause a DoS (Denial of Service)
&lt;br&gt;or to potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31698/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31698/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31697] rPath update for ruby
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Bypass, Spoofing, DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;rPath has issued an update for ruby. This fixes some vulnerabilities,
&lt;br&gt;which can be exploited by malicious people to bypass certain security
&lt;br&gt;restrictions, cause a DoS (Denial of Service), and conduct spoofing
&lt;br&gt;attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31697/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31697/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31676] Newsbeuter URL Processing Shell Command Execution
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in Newsbeuter, which can be exploited
&lt;br&gt;by malicious people to compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31676/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31676/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31670] Red Hat update for libtiff
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;Red Hat has issued an update for libtiff. This fixes some
&lt;br&gt;vulnerabilities, which can be exploited by malicious people to cause a
&lt;br&gt;DoS (Denial of Service) and potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31670/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31670/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31668] Red Hat update for libtiff
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;Red Hat has issued an update for libtiff. This fixes a vulnerability,
&lt;br&gt;which can be exploited by malicious people to cause a DoS (Denial of
&lt;br&gt;Service) and potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31668/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31668/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31720] @Mail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;C1c4Tr1Z has discovered some vulnerabilities in @Mail, which can be
&lt;br&gt;exploited by malicious people to conduct cross-site scripting attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31720/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31720/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31713] VMware ESX / ESXi Server Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged a weakness and a vulnerability in VMware ESX
&lt;br&gt;Server, which can be exploited by malicious users to disclose
&lt;br&gt;potentially sensitive information and by malicious people to cause a
&lt;br&gt;DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31713/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31713/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31691] Debian update for slash
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting, Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;Debian has issued an update for slash. This fixes some vulnerabilities,
&lt;br&gt;which can be exploited by malicious users to conduct SQL injection
&lt;br&gt;attacks and by malicious people to conduct cross-site scripting
&lt;br&gt;attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31691/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31691/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31743] FreeBSD AMD64 General Protection Fault Privilege Escalation
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;FreeBSD has acknowledged a vulnerability, which can be exploited by
&lt;br&gt;malicious, local users to gain escalated privileges.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31743/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31743/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31685] Avaya Products Linux Kernel Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation, DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;Avaya has acknowledged some vulnerabilities in various Avaya products,
&lt;br&gt;which can be exploited by malicious, local users to cause a DoS (Denial
&lt;br&gt;of Service) and potentially gain escalated privileges.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31685/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31685/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31663] Slackware update for amarok
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;Slackware has issued an update for amarok. This fixes a security issue,
&lt;br&gt;which can be exploited by malicious, local users to perform certain
&lt;br&gt;actions with escalated privileges.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31663/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31663/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31739] IBM AIX &amp;quot;swcons&amp;quot; Command Privilege Escalation Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Not critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in IBM AIX, which can be exploited by
&lt;br&gt;malicious, local users to gain escalated privileges.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31739/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31739/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31716] Postfix epoll File Descriptor Leak Security Issue
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Not critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;A security issue has been reported in Postfix, which can be exploited
&lt;br&gt;by malicious, local users to cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31716/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31716/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31694] GpsDrive &amp;quot;geo-code&amp;quot; Insecure Temporary Files
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Not critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;A security issue has been reported in GpsDrive, which can be exploited
&lt;br&gt;by malicious, local users to perform certain actions with escalated
&lt;br&gt;privileges.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31694/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31694/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31689] Avaya Products Linux Kernel Local Denial of Service
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Not critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;Avaya has acknowledged a vulnerability in various Avaya products, which
&lt;br&gt;can be exploited by malicious, local users to cause a DoS (Denial of
&lt;br&gt;Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31689/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31689/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31667] Sun Solaris Kernel Covert Channel Security Bypass
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Not critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; Local system
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Bypass
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in Sun Solaris, which can be
&lt;br&gt;exploited by malicious, local users to bypass certain security
&lt;br&gt;restrictions.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31667/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31667/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Other:--
&lt;br&gt;&lt;br&gt;[SA31730] Cisco ASA and PIX Security Appliances Multiple
&lt;br&gt;Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Exposure of sensitive information, DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Some vulnerabilities have been reported in Cisco ASA and PIX
&lt;br&gt;appliances, which can be exploited by malicious people to disclose
&lt;br&gt;sensitive information, and by malicious users and malicious people to
&lt;br&gt;cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31730/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31730/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31673] IBM WebSphere Application Server for z/OS HTTP Server
&lt;br&gt;mod_proxy_ftp Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;IBM has acknowledged a vulnerability in IBM WebSphere Application
&lt;br&gt;Server for z/OS, which can be exploited by malicious people to conduct
&lt;br&gt;cross-site scripting attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31673/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31673/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31680] Kyocera FS-118MFP Command Center Directory Traversal
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From local network
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Exposure of sensitive information
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;Francesco Tornieri has reported a vulnerability in Kyocera FS-118MFP,
&lt;br&gt;which can be exploited by malicious people to disclose potentially
&lt;br&gt;sensitive information.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31680/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31680/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31665] Belkin Wireless G Router Web Interface Authentication Bypass
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From local network
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Bypass
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;noensr has reported a vulnerability in Belkin Wireless G F5D7632-4V6,
&lt;br&gt;which can be exploited by malicious people to bypass certain security
&lt;br&gt;restrictions.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31665/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31665/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Cross Platform:--
&lt;br&gt;&lt;br&gt;[SA31709] VMware Player Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware Player, which
&lt;br&gt;can be exploited by malicious, local users to gain escalated privileges
&lt;br&gt;and by malicious people to cause a DoS (Denial of Service) and
&lt;br&gt;potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31709/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31709/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31708] VMware Server Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware Server, which
&lt;br&gt;can be exploited by malicious, local users to gain escalated privileges
&lt;br&gt;and by malicious people to cause a DoS (Denial of Service) and
&lt;br&gt;potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31708/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31708/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31707] VMware Workstation Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Highly critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Privilege escalation, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;VMware has acknowledged some vulnerabilities in VMware Workstation,
&lt;br&gt;which can be exploited by malicious, local users to gain escalated
&lt;br&gt;privileges and by malicious people to cause a DoS (Denial of Service)
&lt;br&gt;and potentially compromise a user's system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31707/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31707/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31723] Ruby on Rails REXML Denial of Service Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in Ruby on Rails, which can be
&lt;br&gt;exploited by malicious people to cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31723/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31723/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31703] Reciprocal Links Manager &amp;quot;site&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;Hussin X has discovered a vulnerability in Reciprocal Links Manager,
&lt;br&gt;which can be exploited by malicious people to conduct SQL injection
&lt;br&gt;attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31703/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31703/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31696] Living Local Website &amp;quot;r&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Hussin X has reported a vulnerability in Living Local Website, which
&lt;br&gt;can be exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31696/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31696/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31683] Invision Power Board Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Hijacking, Manipulation of data, Exposure of sensitive
&lt;br&gt;information, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;DarkFig has reported some vulnerabilities in Invision Power Board
&lt;br&gt;(IP.Board), which can be exploited by malicious users to disclose
&lt;br&gt;sensitive information and compromise a vulnerable system, and by
&lt;br&gt;malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31683/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31683/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31682] EasyClassifields &amp;quot;go&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;e.wiZz! has discovered a vulnerability in EasyClassifields, which can
&lt;br&gt;be exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31682/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31682/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31678] Novell IDM Cross-Site Scripting and Script Insertion
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;Some vulnerabilities have been reported in Novell User Application and
&lt;br&gt;Novell Identity Manager Roles Based Provisioning Module, which can be
&lt;br&gt;exploited by malicious people to conduct script insertion and
&lt;br&gt;cross-site scripting attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31678/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31678/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31674] Wireshark Denial of Service Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;Some vulnerabilities have been reported in Wireshark, which can be
&lt;br&gt;exploited by malicious people to cause a DoS (Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31674/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31674/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31669] CMSbright &amp;quot;id_rub_page&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;BorN To K!LL has reported a vulnerability in CMSbright, which can be
&lt;br&gt;exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31669/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31669/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31664] Spice Classifieds &amp;quot;cat_path&amp;quot; SQL Injection Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Cyb3r-1sT has reported a vulnerability in Spice Classifieds, which can
&lt;br&gt;be exploited by malicious people to conduct SQL injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31664/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31664/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31684] Novell eDirectory Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Moderately critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From local network
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Unknown, Cross Site Scripting, DoS, System access
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;Multiple vulnerabilities have been reported in Novell eDirectory, where
&lt;br&gt;some have an unknown impact and others can be exploited by malicious
&lt;br&gt;people to conduct cross-site scripting attacks or to potentially
&lt;br&gt;compromise a vulnerable system.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31684/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31684/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31735] Celerondude Uploader &amp;quot;username&amp;quot; Cross-Site Scripting
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;A vulnerability has been discovered in Celerondude Uploader, which can
&lt;br&gt;be exploited by malicious people to conduct cross-site scripting
&lt;br&gt;attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31735/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31735/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31729] Django Authentication Cross-Site Request Forgery
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting, Manipulation of data
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in Django, which can be exploited by
&lt;br&gt;malicious people to conduct cross-site request forgery attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31729/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31729/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31719] Open Media Collectors Database Cross-Site Scripting and
&lt;br&gt;Request Forgery
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Some vulnerabilities have been discovered in Open Media Collectors
&lt;br&gt;Database (OpenDb), which can be exploited by malicious people to
&lt;br&gt;conduct cross-site scripting and cross-site request forgery attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31719/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31719/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31681] dotProject SQL Injection and Cross-Site Scripting
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting, Manipulation of data, Exposure of
&lt;br&gt;sensitive information
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;C1c4Tr1Z has discovered some vulnerabilities in dotProject, which can
&lt;br&gt;be exploited by malicious users to conduct SQL injection attacks, and
&lt;br&gt;by malicious people to conduct cross-site scripting attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31681/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31681/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31679] vtiger CRM Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-02
&lt;br&gt;&lt;br&gt;Fabian Fingerle has discovered some vulnerabilities in vtiger CRM,
&lt;br&gt;which can be exploited by malicious people to conduct cross-site
&lt;br&gt;scripting attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31679/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31679/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31662] Blogn Cross-Site Scripting and Cross-Site Request Forgery
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-08-29
&lt;br&gt;&lt;br&gt;Two vulnerabilities have been reported in Blogn, which can be exploited
&lt;br&gt;by malicious people to conduct cross-site scripting and cross-site
&lt;br&gt;request forgery attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31662/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31662/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31661] Brim SQL Injection and Script Insertion Vulnerabilities
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From remote
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross Site Scripting, Manipulation of data, Exposure of
&lt;br&gt;sensitive information
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-01
&lt;br&gt;&lt;br&gt;Fisher762 has discovered two vulnerabilities in Brim, which can be
&lt;br&gt;exploited by malicious users to conduct script insertion and SQL
&lt;br&gt;injection attacks.
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31661/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31661/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31731] Cisco Secure ACS EAP Packet Denial of Service
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From local network
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-04
&lt;br&gt;&lt;br&gt;A vulnerability has been reported in Cisco Secure Access Control Server
&lt;br&gt;(ACS), which can be exploited by malicious people to cause a DoS (Denial
&lt;br&gt;of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31731/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31731/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;--
&lt;br&gt;&lt;br&gt;[SA31688] HP OpenView Network Node Manager Denial of Service
&lt;br&gt;&lt;br&gt;Critical: &amp;nbsp; &amp;nbsp;Less critical
&lt;br&gt;Where: &amp;nbsp; &amp;nbsp; &amp;nbsp; From local network
&lt;br&gt;Impact: &amp;nbsp; &amp;nbsp; &amp;nbsp;DoS
&lt;br&gt;Released: &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;&lt;br&gt;Some vulnerabilities have been reported in HP OpenView Network Node
&lt;br&gt;Manager, which can be exploited by malicious people to cause a DoS
&lt;br&gt;(Denial of Service).
&lt;br&gt;&lt;br&gt;Full Advisory:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/31688/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/31688/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;========================================================================
&lt;br&gt;&lt;br&gt;Secunia recommends that you verify all advisories you receive,
&lt;br&gt;by clicking the link.
&lt;br&gt;Secunia NEVER sends attached files with advisories.
&lt;br&gt;Secunia does not advise people to install third party patches, only use
&lt;br&gt;those supplied by the vendor.
&lt;br&gt;&lt;br&gt;Definitions: (Criticality, Where etc.)
&lt;br&gt;&lt;a href=&quot;http://secunia.com/about_secunia_advisories/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/about_secunia_advisories/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Subscribe:
&lt;br&gt;&lt;a href=&quot;http://secunia.com/secunia_weekly_summary/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/secunia_weekly_summary/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Contact details:
&lt;br&gt;Web	: &lt;a href=&quot;http://secunia.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/&lt;/a&gt;&lt;br&gt;E-mail	: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19328074&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;support@...&lt;/a&gt;
&lt;br&gt;Tel	: +45 70 20 51 44
&lt;br&gt;Fax	: +45 70 20 51 45
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Secunia-Weekly-Summary---Issue%3A-2008-36-tp19328074p19328074.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19328041</id>
	<title>Detroit's Mayor Will Leave Office and Go to Jail</title>
	<published>2008-09-05T02:41:13Z</published>
	<updated>2008-09-05T02:41:13Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.nytimes.com/2008/09/05/us/05detroit.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.nytimes.com/2008/09/05/us/05detroit.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;[Backround: &lt;a href=&quot;http://www.infosecnews.org/hypermail/0801/14318.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.infosecnews.org/hypermail/0801/14318.html&lt;/a&gt;&amp;nbsp; - WK]
&lt;br&gt;&lt;br&gt;By SUSAN SAULNY and NICK BUNKLEY
&lt;br&gt;The New York Times
&lt;br&gt;September 4, 2008
&lt;br&gt;&lt;br&gt;DETROIT - Mayor Kwame M. Kilpatrick pleaded guilty to felony charges 
&lt;br&gt;here on Thursday and agreed to resign from office and serve 120 days in 
&lt;br&gt;jail, ending eight months of political turmoil but also opening a new 
&lt;br&gt;era of uncertainty for the city.
&lt;br&gt;&lt;br&gt;After the agreement, Gov. Jennifer M. Granholm of Michigan suspended her 
&lt;br&gt;hearing on whether to remove Mr. Kilpatrick for misconduct, relieving 
&lt;br&gt;her of being in the awkward position of possibly ousting the mayor, a 
&lt;br&gt;fellow Democrat, from office.
&lt;br&gt;&lt;br&gt;&amp;quot;It is my profound hope that we can now write a new history for this 
&lt;br&gt;great but embattled city and that the citizens of Detroit begin the 
&lt;br&gt;healing process to move forward,&amp;quot; she said. But even as the fate of Mr. 
&lt;br&gt;Kilpatrick became clear on Thursday, a new layer of potential pitfalls 
&lt;br&gt;came into view.
&lt;br&gt;&lt;br&gt;The City Council that will now try to bring stability to the nation's 
&lt;br&gt;11th largest city is known for its volatility. Its two top leaders, 
&lt;br&gt;Kenneth V. Cockrel Jr., the council president who will now be interim 
&lt;br&gt;mayor, and Monica Conyers, who will become president of the Council, 
&lt;br&gt;were recently involved in a public shouting match that has become a 
&lt;br&gt;running joke.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Detroit%27s-Mayor-Will-Leave-Office-and-Go-to-Jail-tp19328041p19328041.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19313470</id>
	<title>Re: ICANN cast as online scam enabler</title>
	<published>2008-09-04T08:44:02Z</published>
	<updated>2008-09-04T08:44:02Z</updated>
	<author>
		<name>Directi</name>
	</author>
	<content type="html">&lt;b&gt;Directi's official response to inaccurate reports which falsely implicate the Directi Group&lt;/b&gt;&lt;br&gt;&lt;br&gt;&lt;b&gt;From Bhavin Turakhia’s Desk:&lt;/b&gt;&lt;br&gt;&lt;br&gt;There have been some articles and reports recently published by Garth Bruen at Knujon and by Jart Armin and James Mcquad at Hostexploit, that somehow link Directi with groups that support organized internet crime. The motives behind these reports are still unknown, but as an organization that prides itself in setting industry benchmarks in ethics and best practices, we are extremely shocked by these allegations. While I applaud the efforts of volunteers such as Knujon and Hostexploit who spend their personal time to try and combat spam, I am personally quite saddened when the very individuals who we trust to combat fraud engage in publicity moves without consideration for the reputation of legitimate businesses.
&lt;br&gt;&lt;br&gt;Neither Knujon nor Hostexploit extended a basic courtesy of even contacting us to verify any of the facts in their report before publishing the same. Directi is not even remotely related to the organizations or activities listed in those reports. The arguments presented in these reports are either downright baseless, or based on complete fabrication of facts.
&lt;br&gt;&lt;br&gt;Various other news agencies and blogs have further referenced these reports in the form of a story or post, once again without any attempt to verify or validate the facts in these reports. Given the amount of noise this has created - it is imperative that we clarify our stand and rectify the factual inaccuracies in those reports.
&lt;br&gt;&lt;br&gt;&lt;b&gt;The first false and inaccurate report in question is one published by Garth Bruen of Knujon. Find below each of the factual inaccuracy or misstatement in his report and our response to the same -&lt;/b&gt;&lt;br&gt;&lt;br&gt;1. The report claims that “48 ICANN-accredited Registrars (affiliated with Directi) … do not seem to exist and are phantom.”
&lt;br&gt;This statement is factually incorrect, and was completely unverified by Knujon. Knujon did not even bother to contact ICANN in this regards to get the right facts. The truth of the matter is that all 48 companies which belong to Directi and its clients, are in existence and are duly incorporated and validly existing under law. 
&lt;br&gt;&lt;br&gt;2. Other Online reports further claim that these 48 registrars are involved in illicit activities.
&lt;br&gt;This allegation is made without providing ANY evidence to corroborate the same. This statement is grossly inaccurate. The reporters did not bother to support such claims with any factual evidence, nor contacted us for clarification. All 48 companies combined have under a few thousand customers who have registered legitimate domains with these registrars and have not received any abuse complaints. Yet these companies have been dragged in, without evidence, into an issue that is unrelated to them. 
&lt;br&gt;&lt;br&gt;3. Garth of Knujon further claims that the Directi Group owns a company by the name of ESTDomains.
&lt;br&gt;This is another blatantly false insinuation. Directi has never owned ESTDomains. Garth has no documentation that shows Directi owning ESTDomains. We have challenged Knujon to produce any evidence with respect to this. In fact the only relationship between Directi and ESTDomains is that ESTDomains has purchased certain software from Logicboxes a few years ago to power their Registrar operations. They are otherwise an independent company and we do not control their actions or their behavior. 
&lt;br&gt;&lt;br&gt;4. Another claim in the reports is that Directi sponsors illegal pharmacy related domain names and that If and when the site content is closed by the ISP host, Directi/PublicDomainsRegistry (sic) just helps them set up at a new IP
&lt;br&gt;This accusation is once again baseless - we certainly do not condone any abusive behavior, much less facilitate it. Despite the fact that policing the Internet does not fall under the purview of a domain name Registrars’ responsibility, we work hard to clamp down abuse, from a moral standpoint. Infact the report again contains no evidence of a single domain name where WE have explicitly assisted a miscreant in migrating from one IP address to another. Quite the contrary, despite not having any legal obligation to do so as a Registar, we still takedown over 95% of the domains for which we receive abuse complaints within 24 hours of receiving these complaints. We invest significant resources towards ensuring that all abuse complaints are thoroughly investigated and swiftly acted upon. 
&lt;br&gt;&lt;br&gt;5. The reports state that the privacy protection service that we provide intentionally harbors abusive domain names and should not be offered for domain names.
&lt;br&gt;PrivacyProtect.org was created to safeguard genuine domain owners from the very threats that KnujOn perceives it to protect. Millions of genuine domain registrants and customers of Directi are using the privacy protection services we offer and are very happy that we provide the same since it protects their email addresses from being harvested and protects their identity from spammers and miscreants. We also maintain a strict zero-tolerance policy w.r.t. abuse of our privacy protection services, and any domain name proven to indulge in illegal activities has its protection immediately revoked. We challenge Knujon to find an example wherein a complaint was made to our privacy protection service and was not actioned upon. 
&lt;br&gt;&lt;br&gt;6. The report claims “EstDomains is a Registrar that also makes heavy use of the PrivacyProtect.org service for masking the ownership of fake pharmacy domains.”
&lt;br&gt;Long before this report was ever published, we had already discontinued our privacy protection services to ESTDomains as per our zero tolerance policy. Knujon again choose not to verify their facts before publishing such assertions. 
&lt;br&gt;&lt;br&gt;7. Further updates from Garth and other sites state that we are in the process of severing our relationship with ESTDomains making it sound as if we were harboring ESTDomains all this while and are now canceling their services
&lt;br&gt;This assertion is incorrect. The only relationship Directi has had with ESTDomains is that of a software vendor. We have discontinued providing privacy protection services to them a few months ago. However ESTDomains continues to use software that they purchased from Directi since several years. We do not control their actions in this respect. None of our steps in terms of abuse prevention are knee jerk reactions to these reports because these reports do not carry any factual data. We are not responsible for domains registered through ESTDomains in any manner and cannot suspend them or prevent abuse on them. 
&lt;br&gt;&lt;br&gt;&lt;b&gt;The second false and inaccurate report in question is one published by Jart Armin and James Mcquad at Hostexploit. Here are our responses to the claims in that report -&lt;/b&gt;&lt;br&gt;&lt;br&gt;1. This report deals with the purported abusive and illegal activities of a company called Atrivo, goes on to associate the Directi group with Atrivo. Most of the accusations in this report are based on the notion that the Directi Group has some association with Atrivo. In fact, the report states one of “the most important of these (cyber crime) Atrivo associations” as “PrivacyProtect (anonymous registrant), LogicBoxes (hosting servers)”.This statement is completely incorrect. Neither is Atrivo associated with LogicBoxes, nor is it being hosted by LogicBoxes, nor have they registered their domain name through LogicBoxes. In fact there is no link between Atrivo and LogicBoxes, except the fact that Atrivo is a customer of ESTDomains and ESTDomains is a customer of LogicBoxes. The Directi Group does not have, and has NEVER had, any association with either Atrivo or their business practices. Directi and Logicboxes are neither a vendor nor a customer nor a business associate of Atrivo. Directi received no courtesy information request from the authors of this report to verify this claim. The report shows no evidence of any such association. 
&lt;br&gt;&lt;br&gt;2. This report, in its investigations of our privacy protection service, goes on to detail the name server and whois information of privacyprotect.com (which is not affiliated with us) instead of privacyprotect.org, which perhaps epitomizes the quality of research on which the report is based. From a simple whois query, and a quick visit to these websites, it is amply clear that these two entities are in no way connected with each other. 
&lt;br&gt;&lt;br&gt;3. Like the previous report, this report also claims that ESTDomains provides use of Directi’s privacy protection services - which, as clarified above, is absolutely false and inaccurate at the time the report was published. 
&lt;br&gt;&lt;br&gt;If you are a news agency or a blog or a news site that has quoted any of the above mentioned reports with false allegations about Directi and LogicBoxes, we request you to post this update in its entirety in a visible manner with a link from the existing article’s headline with a byline that can state “Update: Directi disclaims all allegations in the knujon / hostexploit reports as baseless and factually incorrect“, since you are currently carrying false and defamatory statements without verification or evidence on the same and have caused considerable reputation loss to our organization. Several of you who have already updated your respective websites, and confirmed the same to us - we thank you for your cooperation and urge you to ensure that in the future when referencing reports of this nature, you at least extend the subject, a basic courtesy of confirming the facts. The reputation damage that has been caused as a result of this incident is considerable.
&lt;br&gt;&lt;br&gt;Today, Directi continues to be one of the most proactive Registrars in combating abuse and implementing strict AUPs. We have a significant investment in terms of manpower and processes to achieve just this. We do so, not because we’re contractually obligated, or to protect our own business interests, but because we sincerely believe in the ideology of making the internet a safer and more secure medium for conducting business.
&lt;br&gt;&lt;br&gt;However it is reports and claims like these that are disappointing to any white hat, genuinely conscientious Registrar, wherein despite our continuous efforts, organizations such as Knujon and HostExploit, without attempting to verify facts, publish libelous and false allegations. Even a basic common courtesy of contacting us was not extended prior to publishing these reports.
&lt;br&gt;&lt;br&gt;While Directi will take all steps necessary to protect its interests, we hope that this type of an incident is not repeated in the future and that online press and media take some basic steps to verify their stories before maligning someone falsely on the Internet at large.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ICANN-cast-as-online-scam-enabler-tp19283495p19313470.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304980</id>
	<title>'MythBusters' co-host backpedals on RFID kerfuffle</title>
	<published>2008-09-04T00:18:58Z</published>
	<updated>2008-09-04T00:18:58Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://news.cnet.com/8301-13772_3-10031601-52.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://news.cnet.com/8301-13772_3-10031601-52.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Daniel Terdiman
&lt;br&gt;Gaming and Culture 
&lt;br&gt;CNET News
&lt;br&gt;September 3, 2008
&lt;br&gt;&lt;br&gt;MythBusters co-host Adam Savage is stepping back from public comments 
&lt;br&gt;suggesting that legal counsel from several credit card companies led the 
&lt;br&gt;Discovery Channel to pull the plug on an episode dedicated to security 
&lt;br&gt;holes in RFID.
&lt;br&gt;&lt;br&gt;At the Last HOPE conference in New York in July, Savage told a crowd of 
&lt;br&gt;several thousand people that his theory on why MythBusters had not gone 
&lt;br&gt;forward with a planned episode on RFID (radio frequency identification) 
&lt;br&gt;hackability was that on a conference call to discuss the matter with 
&lt;br&gt;technicians from Texas Instruments, the lawyers for the credit cards 
&lt;br&gt;companies had put the hammer down on the show.
&lt;br&gt;&lt;br&gt;&amp;quot;Texas Instruments comes on along with chief legal counsel for American 
&lt;br&gt;Express, Visa, Discover, and everybody else (co-host Tory Belleci and a 
&lt;br&gt;MythBusters producer) were way, way out-gunned,&amp;quot; Savage told the crowd, 
&lt;br&gt;&amp;quot;and (the lawyers) absolutely made it really clear to Discovery that 
&lt;br&gt;they were not going to air this episode talking about how hackable this 
&lt;br&gt;stuff was, and Discovery backed way down, being a large corporation that 
&lt;br&gt;depends upon the revenue of the advertisers. Now it's on Discovery's 
&lt;br&gt;radar and they won't let us go near it.&amp;quot;
&lt;br&gt;&lt;br&gt;But Texas Instruments spokeswoman Cindy Huff told CNET News on Tuesday 
&lt;br&gt;that things had gone a bit different than Savage had said.
&lt;br&gt;&lt;br&gt;&amp;quot;In June 2007, MythBusters was interested in pursuing some great 
&lt;br&gt;myth-busting ideas for RFID. While in pursuit, they contacted Texas 
&lt;br&gt;Instruments' RFID Systems, who is a pioneer of RFID and contactless 
&lt;br&gt;technology, for technical help and understanding of RFID in the 
&lt;br&gt;contactless payments space,&amp;quot; Huff said. &amp;quot;Some of the information that 
&lt;br&gt;was needed to pursue the program required further support from the 
&lt;br&gt;contactless payment companies as they construct their own proprietary 
&lt;br&gt;systems for security to protect their customers. To move the process 
&lt;br&gt;along, Texas Instruments coordinated a conversation with Smart Card 
&lt;br&gt;Alliance (SCA) who invited MasterCard and Visa, on contactless payments 
&lt;br&gt;to help MythBusters get the right information. Of the handful of people 
&lt;br&gt;on the call, there were mostly product managers and only one contactless 
&lt;br&gt;payment company's legal counsel member. Technical questions were asked 
&lt;br&gt;and answered and we were to wait for MythBusters to let us know when 
&lt;br&gt;they were planning on showing the segment. A few weeks later, Texas 
&lt;br&gt;Instruments was told by MythBusters that the storyline had changed and 
&lt;br&gt;they were pursuing a different angle which did not require our help.&amp;quot;
&lt;br&gt;&lt;br&gt;And now, even Savage is saying that he got his facts wrong.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/%27MythBusters%27-co-host-backpedals-on-RFID-kerfuffle-tp19304980p19304980.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304928</id>
	<title>Zombie network explosion</title>
	<published>2008-09-04T00:18:44Z</published>
	<updated>2008-09-04T00:18:44Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.theregister.co.uk/2008/09/02/zombie_surge/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.theregister.co.uk/2008/09/02/zombie_surge/&lt;/a&gt;&lt;br&gt;&lt;br&gt;By John Leyden
&lt;br&gt;The Register
&lt;br&gt;2nd September 2008
&lt;br&gt;&lt;br&gt;The number of compromised zombie PCs in botnet networks has quadrupled 
&lt;br&gt;over the last three months, according to figures from the Shadowserver 
&lt;br&gt;Foundation.
&lt;br&gt;&lt;br&gt;Shadowserver tracks botnet activity and the number of command and 
&lt;br&gt;control servers. It uses a variety of metrics to slice and dice its 
&lt;br&gt;figures based in part on the entropy of botnet infections. The clear 
&lt;br&gt;trend within these figures is upwards, with a rise in botnet numbers of 
&lt;br&gt;100,000 to 400,000 (if 30 day entropy is factored into equations) or 
&lt;br&gt;from 20,000 to 60,000 (for five day entropy).
&lt;br&gt;&lt;br&gt;Entropy of botnets is calculated on the basis that if no activity is 
&lt;br&gt;seen from a specific IP for a number of days - either 30, 10 or five - 
&lt;br&gt;then it is removed from the botnet count.
&lt;br&gt;&lt;br&gt;Shadowserver figures suggest the number of command and control servers 
&lt;br&gt;has actually decreased over the last month, following a spike in 
&lt;br&gt;activity back in July.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Zombie-network-explosion-tp19304928p19304928.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304901</id>
	<title>Google's Chrome Browser Not Yet Secure</title>
	<published>2008-09-04T00:18:32Z</published>
	<updated>2008-09-04T00:18:32Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.informationweek.com/news/internet/google/showArticle.jhtml?articleID=210300297&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.informationweek.com/news/internet/google/showArticle.jhtml?articleID=210300297&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Thomas Claburn
&lt;br&gt;InformationWeek
&lt;br&gt;September 3, 2008
&lt;br&gt;&lt;br&gt;Google (NSDQ: GOOG)'s Chrome browser is only a day old, but security 
&lt;br&gt;researchers already have found vulnerabilities that can be exploited.
&lt;br&gt;&lt;br&gt;According to a report published by ZDNet, security researcher Aviv Raff 
&lt;br&gt;has found that he can combine a flaw in the open source WebKit engine 
&lt;br&gt;with a Java bug to dupe Chrome users into downloading executable files.
&lt;br&gt;&lt;br&gt;Apple, which uses WebKit in its Safari browser, fixed this flaw with its 
&lt;br&gt;Safari 3.1.2 browser patch. Chrome uses an older version of WebKit that 
&lt;br&gt;has not been repaired.
&lt;br&gt;&lt;br&gt;Another security researcher, Rishi Narang, claimed to have found a way 
&lt;br&gt;to crash Chrome with a malicious link.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Google%27s-Chrome-Browser-Not-Yet-Secure-tp19304901p19304901.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304866</id>
	<title>'Defense Ministry's Cyber Network Is Hacker-Proof'</title>
	<published>2008-09-04T00:18:17Z</published>
	<updated>2008-09-04T00:18:17Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.koreatimes.co.kr/www/news/nation/2008/09/116_30464.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.koreatimes.co.kr/www/news/nation/2008/09/116_30464.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Michael Ha
&lt;br&gt;Staff Reporter
&lt;br&gt;09-02-2008
&lt;br&gt;&lt;br&gt;A Defense Ministry spokesman assured Tuesday that the department's 
&lt;br&gt;cyber-security system is &amp;quot;hacker-proof,&amp;quot; adding that its intra-net 
&lt;br&gt;computer data network is detached from the external Internet.
&lt;br&gt;&lt;br&gt;The ministry's announcement was designed to address new security 
&lt;br&gt;concerns in wake of the arrest of a North Korean defector who was 
&lt;br&gt;allegedly working for North Korean intelligence.
&lt;br&gt;&lt;br&gt;Local media have reported that Won Jung-hwa, 34, had allegedly collected 
&lt;br&gt;e-mail addresses of a number of South Korean military officials. The 
&lt;br&gt;reports said these e-mail addresses may have been used by hackers to 
&lt;br&gt;break into the Defense Ministry's computer network. In fact, the Korean 
&lt;br&gt;military officials issued a security warning to its personnel last month 
&lt;br&gt;when some staff began receiving e-mails with attachments containing 
&lt;br&gt;hacking programs.
&lt;br&gt;&lt;br&gt;But Defense Ministry spokesman Won Tae-jae told local reporters during a 
&lt;br&gt;press briefing Tuesday that the ministry's intra-net network is not 
&lt;br&gt;connected to the external Web, &amp;quot;so that outsiders can't approach the 
&lt;br&gt;internal network through the Internet.&amp;quot;
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/%27Defense-Ministry%27s-Cyber-Network-Is-Hacker-Proof%27-tp19304866p19304866.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304833</id>
	<title>UK crime fighters grapple with iPhone wipe threat</title>
	<published>2008-09-04T00:17:48Z</published>
	<updated>2008-09-04T00:17:48Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://networks.silicon.com/mobile/0,39024665,39282266,00.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://networks.silicon.com/mobile/0,39024665,39282266,00.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Nick Heath
&lt;br&gt;Silicon.com
&lt;br&gt;2 September 2008
&lt;br&gt;&lt;br&gt;Criminals can remotely destroy incriminating evidence by exploiting 
&lt;br&gt;security features on the Apple iPhone, a leading digital forensics 
&lt;br&gt;expert has warned.
&lt;br&gt;&lt;br&gt;The head of the Serious Fraud Office digital forensics unit Keith Foggon 
&lt;br&gt;cautioned that the ability to remotely wipe the iPhone and other smart 
&lt;br&gt;phones used by enterprises could be exploited by lawbreakers.
&lt;br&gt;&lt;br&gt;Foggon said: &amp;quot;The 3G iPhone is brand new, there are not many tools for 
&lt;br&gt;dealing with it and it can be remotely wiped. It's a bit like the 
&lt;br&gt;BlackBerrys where users can carry out remote deletion.&amp;quot;
&lt;br&gt;&lt;br&gt;He added the unit took precautions to guard against the feature being 
&lt;br&gt;exploited. &amp;quot;Because we isolate the devices immediately, and never 
&lt;br&gt;reconnect them to their network, the remote wiping capability does not 
&lt;br&gt;present us with much of a problem,&amp;quot; he noted.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/UK-crime-fighters-grapple-with-iPhone-wipe-threat-tp19304833p19304833.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304802</id>
	<title>'Lack of Cyber laws makes it impossible to fight Net crimes'</title>
	<published>2008-09-04T00:17:34Z</published>
	<updated>2008-09-04T00:17:34Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.arabtimesonline.com/kuwaitnews/pagesdetails.asp?nid=21784&amp;ccid=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.arabtimesonline.com/kuwaitnews/pagesdetails.asp?nid=21784&amp;ccid=9&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Francis A. Clifford Cardozo
&lt;br&gt;Arab Times Staff
&lt;br&gt;September 04, 2008 
&lt;br&gt;&lt;br&gt;KUWAIT CITY - Internet-related crimes are on the rise in Kuwait and the 
&lt;br&gt;lack of Cyber laws makes it impossible to tackle such fraudulent 
&lt;br&gt;practices, says a Kuwaiti lawyer. Speaking to the Arab Times on 
&lt;br&gt;Wednesday, Labeed Abdal added that hackers are increasingly targeting 
&lt;br&gt;Kuwait and many other countries, knowing full well that they can get 
&lt;br&gt;away with their crimes. He went on to explain that some people send 
&lt;br&gt;abusive emails to settle personal scores and that the law enforcement 
&lt;br&gt;agencies are unable to act on such matters due to non-existence of Cyber 
&lt;br&gt;laws, “which must be in tune with the latest changes in the Internet 
&lt;br&gt;domain.”
&lt;br&gt;&lt;br&gt;Citing an example, he said, recently a woman approached a police station 
&lt;br&gt;to file complaint with regards to a derogatory email but the police 
&lt;br&gt;refused to entertain her complaint. “In such a scenario, we cannot blame 
&lt;br&gt;the security authorities. There is an exigent need to establish what can 
&lt;br&gt;be called as Cyber Police which will enable to monitor online 
&lt;br&gt;activities, besides tracking down the source of abusive emails. In other 
&lt;br&gt;words, the police will only register a complaint provided a person 
&lt;br&gt;admits to his or her crime, thereby referring the case to prosecution.”
&lt;br&gt;&lt;br&gt;&lt;br&gt;Confess
&lt;br&gt;&lt;br&gt;“Supposing a person refuses to confess to his crime, then it becomes 
&lt;br&gt;impossible for the authorities to register a complaint for the simple 
&lt;br&gt;reason that they do not posses the required know-how and equipment to 
&lt;br&gt;track down the source of an email, especially if the sender uses only 
&lt;br&gt;his initials or if the mail is anonymous,” he added. Asked to comment on 
&lt;br&gt;the decision of some prosecutors to draft a law with regards to Internet 
&lt;br&gt;crimes, Abdal said he was unable to comment on the issue as he was yet 
&lt;br&gt;to see the contents of the draft, which must be submitted to the 
&lt;br&gt;parliament before being reviewed by the legislative committee.
&lt;br&gt;&lt;br&gt;Stressing that many unsolicited emails were originating from Africa, 
&lt;br&gt;particularly from Nigeria, Abdal noted that one Kuwaiti lady was 
&lt;br&gt;recently duped by some unscrupulous elements after she fell prey to a 
&lt;br&gt;fraudulent email.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br /&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/%27Lack-of-Cyber-laws-makes-it-impossible-to-fight-Net-crimes%27-tp19304802p19304802.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19304759</id>
	<title>Vice chief of Cyber Command is reassigned</title>
	<published>2008-09-04T00:17:17Z</published>
	<updated>2008-09-04T00:17:17Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://www.airforcetimes.com/news/2008/09/airforce_general_moves_090208w/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.airforcetimes.com/news/2008/09/airforce_general_moves_090208w/&lt;/a&gt;&lt;br&gt;&lt;br&gt;By Bruce Rolfsen 
&lt;br&gt;Staff writer
&lt;br&gt;Air Force Times
&lt;br&gt;Sept. 3, 2008
&lt;br&gt;&lt;br&gt;The Air Force’s latest reassignment list for general officers reflects 
&lt;br&gt;the service’s move away from an independent cyber command.
&lt;br&gt;&lt;br&gt;The provisional command's vice commander, who has been on the job for 
&lt;br&gt;one month, is being reassigned to the Pentagon, the Air Force said in an 
&lt;br&gt;Aug. 29 statement. No replacement was named.
&lt;br&gt;&lt;br&gt;Maj. Gen. Randal D. Fullhart, who assumed the vice commander post in 
&lt;br&gt;August, is moving to the Air Staff to join the Office of the Assistant 
&lt;br&gt;Secretary of the Air Force for Acquisition as director of global reach 
&lt;br&gt;programs. Fullhart is a career mobility pilot, but he served with the 
&lt;br&gt;National Security Agency as the deputy chief for the Central Security 
&lt;br&gt;Service for two years before moving to the cyber post.
&lt;br&gt;&lt;br&gt;The service’s plans to establish a cyber command were put on hold in 
&lt;br&gt;August as newly appointed Chief of Staff Gen. Norton Schwartz and acting 
&lt;br&gt;Secretary of the Air Force Michael Donley began a wide-ranging review of 
&lt;br&gt;projects advocated by the leaders they replaced, now-retired Gen. T. 
&lt;br&gt;Michael Moseley and former secretary Michael Wynne.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br /&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Vice-chief-of-Cyber-Command-is-reassigned-tp19304759p19304759.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19283543</id>
	<title>North Korea spyware targets South's army</title>
	<published>2008-09-02T23:06:32Z</published>
	<updated>2008-09-02T23:06:32Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://news.theage.com.au/world/north-korea-spyware-targets-souths-army-20080902-47wp.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://news.theage.com.au/world/north-korea-spyware-targets-souths-army-20080902-47wp.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Age
&lt;br&gt;September 2, 2008
&lt;br&gt;&lt;br&gt;North Korea has tried to hack into the computers of South Korean army 
&lt;br&gt;officers, officials said, one week after disclosing an espionage case 
&lt;br&gt;involving a woman posing as a defector.
&lt;br&gt;&lt;br&gt;An email sent to &amp;quot;many&amp;quot; officers contained a hacking program designed 
&lt;br&gt;automatically to steal stored files if the recipient opens it, a South 
&lt;br&gt;Korean defence ministry spokesman said.
&lt;br&gt;&lt;br&gt;A colonel was among those who have received the email virus since June.
&lt;br&gt;&lt;br&gt;The ministry said no classified information had been leaked.
&lt;br&gt;&lt;br&gt;&amp;quot;It is impossible for hackers to break into the computer system of our 
&lt;br&gt;military which operates a separate intra network,&amp;quot; a spokesman told AFP.
&lt;br&gt;&lt;br&gt;But the North's cyber attack prompted the army to update its 
&lt;br&gt;anti-hacking software and officers had been asked not to store sensitive 
&lt;br&gt;data on their personal computers, he said.
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;__________________________________________________ &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;Register now for HITBSecConf2008 - Malaysia! With 
&lt;br&gt;a new triple-track conference featuring 4 keynote 
&lt;br&gt;speakers and over 35 international experts, this 
&lt;br&gt;is the largest network security event in Asia and 
&lt;br&gt;the Middle East! 
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2008kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2008kl/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/North-Korea-spyware-targets-South%27s-army-tp19283543p19283543.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19283527</id>
	<title>Love of Cats Was Six Flags Hacker's Downfall</title>
	<published>2008-09-02T23:06:23Z</published>
	<updated>2008-09-02T23:06:23Z</updated>
	<author>
		<name>InfoSec News-2</name>
	</author>
	<content type="html">&lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/09/love-of-cats-he.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blog.wired.com/27bstroke6/2008/09/love-of-cats-he.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;By David Kravets 
&lt;br&gt;Threat Level
&lt;br&gt;Wired.com
&lt;br&gt;September 02, 2008 
&lt;br&gt;&lt;br&gt;A San Francisco hacker faces up to 10 years imprisonment for intruding 
&lt;br&gt;into the computers of theme park giant Six Flags, posting a message of 
&lt;br&gt;love for his girlfriend and inundating the company with bot-produced job 
&lt;br&gt;applications reading &amp;quot;THIS SITE WAS HACKED.&amp;quot;
&lt;br&gt;&lt;br&gt;Over a five-day period in 2004, Mark Kahn, 27, left messages in the 
&lt;br&gt;amusement park company's network to his girlfriend: &amp;quot;I Love you, Laura,&amp;quot; 
&lt;br&gt;the authorities said.
&lt;br&gt;&lt;br&gt;The IP address from where the hacking originated were traced to web 
&lt;br&gt;sites used by Kahn, including his personal web site where he posted 
&lt;br&gt;blogs, pictures of his girlfriend Laura and pictures of cats, according 
&lt;br&gt;to South Carolina U.S. Attorney W. Walter Wilkins, South Carolina's U.S. 
&lt;br&gt;attorney.
&lt;br&gt;&lt;br&gt;One picture of a cat helped the authorities nab Kahn, who pleaded (.pdf) 
&lt;br&gt;[1] guilty last week to one count of hacking (.pdf) [2]. Authorities 
&lt;br&gt;enlarged one picture with a cat on a keyboard and saw a web address to a 
&lt;br&gt;site in which the hacker described the intrusion.
&lt;br&gt;&lt;br&