sprawl - intelstream https://thesprawl.org/intelstream Wireless car hacking due to poor security http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 04:38:42 PDT Research from the University of California San Diego and the University of Washington - and which concludes that modern cars are susceptible to wireless hacking - is the result of a security issues be... Every week 57,000 fake Web addresses try to infect users http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 04:30:24 PDT Every week, hackers are creating 57,000 new Web addresses which they position and index on leading search engines in the hope that unwary users will click them by mistake. Those who do, will see ... iPad scammers hack Kirstie Allsopp's Twitter http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 04:06:46 PDT Posh property presenter pwned iPad scammers managed to reach a huge potential audience last weekend after they took over a Twitter profile maintained by British TV presenter Kirstie Allsopp. Browser security warning lookalike pushes malware http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:42:40 PDT Zeven deadly sins Scareware peddlers have developed a new ruse that relies on mimicking browser warning pages. Flash player as the spy system http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:41:00 PDT The Flash player can grant access to sites webcam and microphone. With a man-in-the-middle attack can remotely change the settings so that every website has access to it. Using the HAVP anti-virus proxy to protect from web attacks http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:29:28 PDT The free HAVP proxy, combined with free virus scanners for Linux, reduces the risk of falling prey to attacks when browsing the internet on a Windows PC. Its installation is anything but rocket science SECURITY DSA-2103-1 New smbind packages fix sql injection http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:16:09 PDT Posted by Giuseppe Iuculano on Sep 06------------------------------------------------------------------------ Debian Security Advisory DSA-2103-1 security () debian org http://www.debian.org/security/ Giuseppe Iuculano September 05, 2010 http://www.debian.org/security/faq ------------------------------------------------------------------------ Package : smbind Vulnerability : sql injection Problem type : remote... nmap = 5.21 is vulnerable to Windows DLL Hijacking Vulnerability. http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:14:51 PDT Posted by Nikhil Mittal on Sep 061. Overview nmap = 5.21 is vulnerable to Windows DLL Hijacking Vulnerability. 2. Vulnerability Description nmap passes insufficiently qualified path for the dll airpcap.dll while opening a file using nmap Timeline 27-08-2010 - Discovered Vulnerability 31-08-2010 - Disclosed at nmap-dev mailing list 04-09-2010 - Response and fix from developers 05-09-2010 - Disclosure 3. Exploitability A file extension needs to be registered... eNYeSec Monitor v1.0 http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:11:53 PDT Utility to capture all traffic from net card as a sniffer (promiscuous mode). It is configurable with filters, and captures TCP, UDP, ICMP and ARP protocols. It can export data, and has a login plain text detection mode (ftp, pop3, etc.). It uses winpcap library, and is multilanguage (english spanish). BlindSQL v1.0 http://thesprawl.org/intelstream/ Mon, 06 Sep 2010 03:00:48 PDT Bash script to make blind attacks SQL inject again databases, usually MySQL. It attacks with bruteforce gaining configuration data, tables, fields and data from DB. It uses lynx navigator for http requests.