SecurityTeam.usLatest HeadlinesMass TCP Port Attack Could Be Imminent, Analyst Warns- June 23, 2005 An ominous increase in sniffing activity on TCP Port 445 could signal an impending mass malicious code attack targeting a recently patched Microsoft vulnerability, according to a warning from security researchers. Researchers at Symantec Corp.'s DeepSight Network have detected a surge in scans on Port 445, an indication that malicious hackers may have already created exploits for a flaw in Microsoft Corp.'s implementation of the SMB (Server Message Block) protocol. In Windows 2000, Windows XP..http://www.securityteam.us/article.php/20050623161321985 Mozilla Firefox Camino Dialog Origin Spoofing Vulnerability- June 21, 2005 Secunia Research has discovered a vulnerability in Mozilla, Firefox, and Camino, which can be exploited by malicious web sites to spoof dialog boxes. The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.Successful exploitation normally requires that a user is tricked into opening a link from a malicious web site to a trusted web site.Secunia has constructed a test,..http://www.securityteam.us/article.php/20050621080203222 Microsoft Internet Explorer Dialog Origin Spoofing Vulnerability- June 21, 2005 Secunia Research has discovered a vulnerability in Internet Explorer, which can be exploited by malicious web sites to spoof dialog boxes. The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.Successful exploitation normally requires that a user is tricked into opening a link from a malicious web site to a trusted web site.Secunia has constructed a test, which can...http://www.securityteam.us/article.php/20050621080035623 Opera Dialog Origin Spoofing Vulnerability- June 21, 2005 Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious web sites to spoof dialog boxes. The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.Successful exploitation normally requires that a user is tricked into opening a link from a malicious web site to a trusted web site.Secunia has constructed a test, which can be used to...http://www.securityteam.us/article.php/20050621080429322 Microsoft Outlook Express News Reading Buffer Overflow- June 15, 2005 A vulnerability has been reported in Microsoft Outlook Express, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the parsing of NNTP responses when using Outlook Express as a newsgroup reader. This can be exploited to cause a buffer overflow via a malicious newsgroup server.Successful exploitation requires that a user queries a malicious newsgroup server for news.SOFTWARE:Microsoft Outlook Express 6Microsoft...http://www.securityteam.us/article.php/20050615073711975 |