napredna pretraga
[ naslovna ] | [ za webmastere ] zastita feeds

02-09-2010 1:43

Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html, (Tue,





News ::  ISC



Povezani zapisi:

09-03-2010 10:09

The correct CV(or malware)

Today we have observed some messages which at first glance appeared to be somebody trying to correct their mistakes on the CV they sent out.

All messages had the same body text that read as follows:

Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential opportunity.

I have just spotted a mistake on the CV I sent in which my email was incorrect.

Apologies for any inconvenience caused if you have already sent me any information on anything we discussed.

My CV is an updated!
CV with the correct email on this link: http://<censored>/mycv.doc.exe

The link was broken.

It was obvious that somebody was trying to trick people into downloading executable files disguised as CV documents but had made some mistakes in the course of doing so.

Then at a later time during the day, this was observed in quantity:


Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential opportunity.

I have just spotted a mistake on the CV I sent in which my email was incorrect.

Apologies for any inconvenience caused if you have already sent me any information on anything we discussed.

My CV is an updated!
CV with the correct email on this link: http://<censored>/mycv.docx


It is exactly the same text body except the last line.

The link is now live, and the linked file is detected by Sophos as Mal/Zbot-U.

 

Sophos

09-03-2010 8:49

cloudprotection.pandasecurity.com XSS

SeeMe has discovered a vulnerability in cloudprotection.pandasecurity.com, which could be exploited by malicious people to conduct XSS attacks. 

XSSed

09-03-2010 8:47

searchsecuritychannel.techtarget.com XSS

d3v1l has discovered a vulnerability in searchsecuritychannel.techtarget.com, which could be exploited by malicious people to conduct XSS attacks. 

XSSed

09-03-2010 8:45

securitycenter.verisign.com XSS

d3v1l has discovered a vulnerability in securitycenter.verisign.com, which could be exploited by malicious people to conduct XSS attacks. 

XSSed








Brza pretraga:

xss
antivirus
security
vulnerability
avast
SPAM
attacks
pentesting
microsoft
kasper
zastita


Sponzorisani linkovi:

Grcki stubovi
Torte