PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 
Site Navigation

Home:

 
Donate o Meter
Help Keep Our Servers Online AND Our Services Free!
Make donations with PayPal!
Donations
 
Please Link To Me!
 
Quality Web Hosting For All PHP Applications
Quality PHP Web Host!

Great Reviews!
Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?
Need help customizing or designing scripts?
Please contact us via the Contact Us option for further details and pricing.

Link to Me

RavenPHPScripts

RavenPHPScripts

There are more Link To Me icons here.
 
Site Info v2.2.2 ©
Your IP: 38.107.179.230

 Welcome, Anonymous
Nickname
Password
Security Code:
Security Code
Type Security Code:

· Register
· Lost Password
Server Date/Time
9 February 2012 10:11:16 EST (GMT -5)
 
Ravens PHP Scripts And Web Hosting: Security

Search on This Topic:   
[ Go to Home | Select a New Topic ]

 
Security SECUNIA ADVISORY ID: SA47694

VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/47694/

RELEASE DATE: 2012-01-24

CRITICALITY: Highly Critical

DESCRIPTION: Some vulnerabilities have been reported in Google Chrome, which potentially can be exploited by malicious people to compromise a user's system.
Posted by Raven on Friday, January 27, 2012 @ 02:12:23 EST (121 reads)
(Read More... | 1191 bytes more | Score: 0)
Major Symantec breach highlights risks of running old software 
SecurityBy Ed Bott | January 25, 2012, 4:56pm PST

Summary: Symantec says it has fewer than 50,000 users of pcAnywhere, a remote-access program that has been around for decades. It now says, for safety’s sake, those users should pull the plug. Immediately.

At this time, Symantec recommends disabling the product until Symantec releases a final set of software updates that resolve currently known vulnerability risks.

Read entire story
Posted by Raven on Friday, January 27, 2012 @ 00:51:47 EST (45 reads)
( | Score: 0)
Security mandates aim to shore up shattered SSL system 
SecuritySouthern writes "Too little, too late

A consortium of companies has published a set of security practices they want all web authentication authorities to follow for their secure sockets layer certificates to be trusted by browsers and other software.

The baseline requirements (PDF), published this week by the Certification Authority/Browser Forum, are designed to prevent security breaches that compromise the tangled web of trust that forms the underpinning of the SSL certificate system. Its release follows years of mismanagement by individual certificate authorities permitted to issue credentials that are trusted by web browsers. Most notable is this year's breach of DigiNotar, which led to the issuance of a fraudulent certificate used to snoop on 300,000 Gmail users in Iran.

The four dozen or so members of the CAB Forum still have a way to go, since their requirements are meaningless unless they are mandated by the software makers who place their trust in the authorities.

more: Packet Storm Security
"
Posted by Raven on Friday, January 13, 2012 @ 16:27:09 EST (54 reads)
( | Score: 0)
SQL Injection Attacks by Example 
SecuritySouthern writes ""SQL Injection" is subset of the an unverified/unsanitized user input vulnerability ("buffer overflows" are a different subset), and the idea is to convince the application to run SQL code that was not intended. If the application is creating SQL strings naively on the fly and then running them, it's straightforward to create some real surprises.

We'll note that this was a somewhat winding road with more than one wrong turn, and others with more experience will certainly have different -- and better -- approaches. But the fact that we were successful does suggest that we were not entirely misguided.

There have been other papers on SQL injection, including some that are much more detailed, but this one shows the rationale of discovery as much as the process of exploitation.

more: UnixWiz
"
Posted by Raven on Friday, January 13, 2012 @ 16:26:03 EST (58 reads)
( | Score: 0)
Opera Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA47077

VERIFY ADVISORY: http://secunia.com/advisories/47077/

RELEASE DATE: 2011-12-06

DESCRIPTION: Multiple vulnerabilities have been reported in Opera, where one has an unknown impact and others can be exploited by malicious people to bypass certain security features, disclose potentially sensitive information, and hijack a user's session. The vulnerabilities are reported in versions prior to 11.60.
Posted by Raven on Wednesday, December 07, 2011 @ 17:10:48 EST (438 reads)
(Read More... | 1717 bytes more | Score: 0)
Download.Com Caught Adding Malware to Nmap & Other Software 
SecuritySouthern writes "CNET's Download.Com is one of the most popular (currently ranked #174 worldwide by Alexa) and longest-running (been around since 1996) major sites on the Internet. As a download repository, their key value ad was that they screened software to avoid malware, spyware, ad-ware, viruses and other harmful content that certain shady software contains. Even many security experts recommended them as a safe place to download software online. Download.Com is run by CNET, which is part of the 17-billion dollar CBS media empire. Many people assumed that a major site like this wouldn't resort to unethical monetization schemes like adding spyware and other malware to their downloads.

Unfortunately, those people were wrong.
"
Posted by Raven on Wednesday, December 07, 2011 @ 17:01:21 EST (458 reads)
(Read More... | 1748 bytes more | Score: 0)
SQL Injection Attack happening ATM, 4000+ sites infected 
SecurityCrypto writes "There have been several reports of sites being injected with a php-string. Typically code is inserted into several tables. From the information gathered so far it looks targeted at ASP, IIS and MSSQL backends, but that is just speculation at this time.

When discovered yesterday about 80 sites showed in Google, this morning about 200, by lunch 1000 and a few minutes ago 4000+.
"
Posted by Raven on Sunday, December 04, 2011 @ 10:24:11 EST (457 reads)
(Read More... | 676 bytes more | Score: 0)
Outsmarted: Captcha security not much of a gotcha 
SecuritySouthern writes "A team of Stanford University researchers has bad news to report about Captchas, those often unreadable, always annoying distorted letters that you're required to type in at many a Web site to prove that you're really a human.

Many Captchas don't work well at all. More precisely, the researchers invented a standard way to decode those irksome letters and numbers found in Captchas on many major Web sites, including Visa's Authorize.net, Blizzard, eBay, and Wikipedia. This chart shows how successful Decaptcha was in decoding each Web site's anti-bot mechanism. The column marked "precision" shows the success rate.

This chart shows how successful Decaptcha was in decoding each Web site's anti-bot mechanism. The column labeled "precision" shows the success rate.

Their decoding technique borrows concepts from the field of machine vision, which has developed techniques to control robots by removing noise from images and detecting shapes. The Stanford tool, called Decaptcha, uses these algorithms to clean up the image so it can be split into more readily recognized letters and numbers.

"Most Captchas are designed without proper testing and no usability testing," Elie Bursztein, 31, a postdoctoral researcher at the Stanford Security Laboratory, told CNET yesterday. "We hope our work will push people to be more rigorous in their approach in Captcha design." Captcha stands for Completely Automated Public Turing test to tell Computers and Humans Apart.

more: CNET
"
Posted by Raven on Thursday, November 10, 2011 @ 01:31:03 EST (211 reads)
( | Score: 0)
Race conditions in security dialogs 
SecuritySouthern writes "From www.squarefree.com
I discovered arbitrary code execution holes in Firefox, Internet Explorer, and Opera that involve human reaction time. One version of the attack works like this:

The secret word fills the blank in the sentence 'If ____ web developers would use alternate text correctly!' It is all lowercase.

The page contains a captcha displaying the word "only" and asks you to type the word to verify that you are a human. As soon as you type 'n', the site attempts to install software, resulting in a security dialog. When you type 'y' at the end of the word, you trigger the 'Yes' button in the dialog. I made a demo of this attack for Firefox and Mozilla.

Another form of the attack involves convincing the user to double-click a certain spot on the screen. This spot happens to be the location where the 'Yes' button will appear. The first click triggers the dialog; the second click lands on the 'Yes' button. I made a demo of this attack for Firefox and Mozilla.

more: squarefree
"
Posted by Raven on Sunday, October 16, 2011 @ 02:34:45 EDT (612 reads)
( | Score: 0)
phpMyAdmin Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA45365

VERIFY ADVISORY: http://secunia.com/advisories/45365/

CRITICALITY: Highly Critical

RELEASE DATE: 2011-07-29

DESCRIPTION: Multiple vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious users to conduct cross-site scripting attacks and potentially compromise a vulnerable system and by malicious people to disclose potentially sensitive information and potentially compromise a vulnerable system.
Posted by Raven on Friday, July 29, 2011 @ 23:19:12 EDT (1275 reads)
(Read More... | 2697 bytes more | Score: 0)
Partners

NuSphere PhpED
IDE for PHP, HTML, CSS, XML, SMARTY, XHTML
Special 10% off coupon! ALL-ACT-10-O-945A4
PHPRunner - PHP form builder
CSE HTML Validator
ip address masquerading
CoffeeCup Software
phpDesigner
PHP Editor/IDE for all PHP/Web development
Just Great Software
Clan-Themes
Making clans look good!
Code Authors
Home of Spam Blocker
Montego Scripts
HTML Newsletter Support

 
Recommended Sites
Montego Scripts - Home of HTML Newsletter

Code-Authors.com

nukeSEO.com

Totally Nuked Mods

EZ Communities - Custom PHP/MySQL Scripts and Solutions

RavenNuke(tm) Test site

Codezwiz Your #1 Help Resource

CSE HTML Validator Helped Clean up This Page!

PC Sympathy - Your Source for PC News and Technical Support

Mantis Bugtracker

Nuke-Evolution

TrickedOutNews.com - Home of Tricked Out News Mod, FaceBox and SlimBox RavenNuke(tm) mods

 
Old Articles

Sunday, June 21
· NukeC 3.7.3 Released (0)
Friday, June 19
· Spam IP Module for PHP-Nuke Check and Submit IP's! (0)
Tuesday, May 19
· New free downloads added at Tricked Out News (0)
Sunday, May 10
· phpBB3ToNuke - 3.0.4 RC 1 is ready to listen to nukers (0)
Monday, May 04
· Two new jQuery lightbox wysiwyg editor mods for download (0)
Wednesday, March 04
· TS Member 2.2 (0)
Thursday, December 25
· PHP-Nuke - PRO Nuke Forms Available: ++ 29 different admin controlled options (0)
Thursday, December 18
· Updated PHP Manual and MySQL Manual Module (0)
Sunday, December 14
· Many modules for you: see the many mods and get more code now! (0)
Wednesday, November 26
· Content Plus 2.2.1 Released Today, Update Your Copy Right Now (0)
· Great real live solutions: GoogleMaps, Map-Manager, NukeFace (0)
Friday, September 19
· Finally! Feedback Resecured 1.0.7 Hit the light, Go get it now! (0)
Friday, September 05
· PROWHS releases Pro Forms v2.0.0 (0)
Monday, August 18
· Who is Online Admin Module Version 2 (0)
Saturday, August 16
· GCalendar is an event calendar module for RavenNuke™ with lots of top-feat (0)
· HTML-Newsletter and many other great RavenNuke™ Solutions (0)
Tuesday, August 12
· NukeSigs v1.1 Released (0)
Monday, August 11
· LD Google Page Rank Checker (0)
Monday, August 04
· NukeFace: a social-utility-module that connects you with the people around you (0)
· kissoftware.org.uk: NukeQuiz and many blocks : get them and lots of support (0)

Older Articles
 
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum