Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
lippylion writes "We have added a password strength meter converted for Nuke from The Meter Man. This module will assist users to help strengthen their passwords and gives and incite in how and what to use to help make your password stronger, in terms of making it more difficult to guess or hack.
For more information and try it out visit us @ Kissoftware"
Posted by Raven on Monday, May 05, 2008 @ 12:18:34 EDT (731 reads) (Read More... | 741 bytes more | Score: 0)
550 Themes update...
papamike writes "I had a problem with new member registrations which 'southern' brought to my attention. It has been corrected. I am going to leave the link active for a longer period of time.
I'm sure that there are a lot of good themes in the batch, I just never seemed to find the time to work on them.
Enjoy! :)"
Posted by Raven on Sunday, May 04, 2008 @ 11:49:42 EDT (571 reads) ( | Score: 0)
550 Php-Nuke Themes
papamike writes "I have a 40mb zip file which contains 550 nuke themes from various sources. I downloaded these from a source (can't remember where) in a zip file and I just want to get rid of them, so instead of simply deleting them I decided to let 10 people download them.
When the download count gets to 10 I am going to delete the category. Go to http://www.papamikecreations.net and click the Products link. You will see the download link from there. You will have to be a member to get this zip file.
I can't tell you anything about them because I did not try to do anything with them."
Posted by Raven on Saturday, May 03, 2008 @ 17:02:40 EDT (554 reads) ( | Score: 0)
PHP 5.2.6 Released
[01-May-2008] The PHP development team would like to announce the immediate availability of PHP 5.2.6. This release focuses on improving the stability ofthe PHP 5.2.x branch with over 120 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.6:
* Fixed possible stack buffer overflow in the FastCGI SAPI identified by Andrei Nigmatulin.
* Fixed integer overflow in printf() identified by Maksymilian Aciemowicz.
* Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh.
* Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz.
* Properly address incomplete multibyte chars inside escapeshellcmd() identified by Stefan Esser.
* Upgraded bundled PCRE to version 7.6
Posted by Raven on Friday, May 02, 2008 @ 12:57:49 EDT (830 reads) ( | Score: 0)
Strength In Passwords
papamike writes "I spent a whole bunch of years as a Network Engineer (retired PhD). And in all of that time one thing I pushed was strong passwords.
I violated my own goldplated rule and allowed one of the people I host to have a 'weak' password because of his physical condition.
Now today I'm paying the price for violating my rule in the number of hours spent weeding out implanted code within php and html files scattered all over the site in question.
Please, for your own sake, keep the passwords strong and don't give them out to anyone. Your friend today just could be your enemy tomorrow."
Posted by Raven on Friday, May 02, 2008 @ 00:09:28 EDT (455 reads) ( | Score: 0)
BackTrack
southern writes "BackTrack is a Live Linux distribution based on SLAX that is focused purely on penetration testing. Distributed by remote-exploit.org, BackTrack is the successor to Auditor. It comes prepackaged with security tools including network analyzers, password crackers, wireless tools and fuzzers. Although originally designed to Boot from a CD or DVD, BackTrack contains USB installation scripts that make portable installation to a USB device a snap.
Posted by Raven on Wednesday, April 30, 2008 @ 18:23:02 EDT (545 reads) ( | Score: 0)
Clan Roster 2.0 Released!
floppydrivez writes "Clan Themes has finally released a new version of Clan Roster.
Whats New?
Multiple Games Added
Multiple Member Images (4 total)
Simplified User Interface
Added a Division system
Added a Clan Tag system
Switched to a template system for ease of use and customization.
Per-Domain Licensing System
Auto-Status Mod
Ribbon / Award Forum Intergration
Scrolling-side block
Fixed all the errors from 1.7
Tested on the latest versions of RavenNuke, Evolution, and Platinum."
Posted by Raven on Thursday, April 24, 2008 @ 02:54:21 EDT (1129 reads) (Read More... | 1050 bytes more | Score: 0)
Mass Attack JavaScript injection - hundreds of thousands affected
Websense® Security Labs has been tracking a recent development of the malicious JavaScript injection that compromised thousands of domains at the start of this month, just 2-3 weeks ago. The attackers have now switched over to a new domain as their hub for hosting the malicious payload in this attack. We have no doubt that the two attacks are related as our brief analysis in our blog will detail. In the last few hours we have seen the number of compromised sites increase by a factor of ten.
This mass injection is remarkably similar to the attack we saw earlier this month. When a user browses to a compromised site, the injected JavaScript loads a file named 1.js which is hosted on http://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing.
There are further similarities too between the two mass attacks. Resident on the latest malicious domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here. Mentioned in that diary entry is http://www.2117[removed].net. Our blog on that attack can be found here. It appears that same tool was used to orchestrate this attack too.
The number of sites affected is in the hundreds of thousands. Casualties of the previous attack include various US news web sites, a major Israeli shopping portal, and numerous travel sites.
Websense® security customers are protected from this attack.
Posted by Raven on Tuesday, April 22, 2008 @ 17:26:32 EDT (577 reads) ( | Score: 0)
DESCRIPTION: Some vulnerabilities have been reported in OpenOffice, which can be exploited by malicious people to potentially compromise a user's system. Successful exploitation of the vulnerabilities may allow execution of arbitrary code. The vulnerabilities are reported in versions prior to 2.4.
Posted by Raven on Thursday, April 17, 2008 @ 22:32:39 EDT (794 reads) (Read More... | 1810 bytes more | Score: 0)
SOFTWARE:
Safari 3.x http://secunia.com/product/17989/
Safari for Windows 3.x http://secunia.com/product/17978/
DESCRIPTION: Some vulnerabilities have been reported in Safari, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially to compromise a user's system. Successful exploitation may allow execution of arbitrary code e.g. when a user visits a malicious web page. The vulnerabilities are reported in versions prior to 3.1.1.
Posted by Raven on Thursday, April 17, 2008 @ 21:55:11 EDT (792 reads) (Read More... | 1867 bytes more | Score: 0)