PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 
Site Navigation

Home:

 
Donate o Meter
Help Keep Our Servers Online AND Our Services Free!
Make donations with PayPal!
Donations
 
Please Link To Me!
 
Quality Web Hosting For All PHP Applications
Quality PHP Web Host!

Great Reviews!
Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?
Need help customizing or designing scripts?
Please contact us via the Contact Us option for further details and pricing.

Link to Me

RavenPHPScripts

RavenPHPScripts

There are more Link To Me icons here.
 
Site Info v2.2.2 ©
Your IP: 38.107.191.99

 Welcome, Anonymous
Nickname
Password
Security Code:
Security Code
Type Security Code:

· Register
· Lost Password
Server Date/Time
6 September 2010 20:25:08 EDT (GMT -4)
 
Ravens PHP Scripts And Web Hosting: Security

Search on This Topic:   
[ Go to Home | Select a New Topic ]

Google Chrome Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA40479

VERIFY ADVISORY: Secunia.com: http://secunia.com/advisories/40479/

RELEASE DATE: 2010-07-06

CRITICAL: Highly Critical!

DESCRIPTION: Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can potentially be exploited by malicious people to compromise a vulnerable system.
Posted by Raven on Monday, July 05, 2010 @ 22:49:12 EDT (588 reads)
(Read More... | 2250 bytes more | Score: 0)
TortoiseSVN Spoofing Vulnerability 
Security SECUNIA ADVISORY ID: SA40355

VERIFY ADVISORY: http://secunia.com/advisories/40355/

RELEASE DATE: 2010-07-01

DISCUSS ADVISORY: http://secunia.com/advisories/40355/#comments

DESCRIPTION: A vulnerability has been reported in TortoiseSVN, which can be exploited by malicious people to conduct spoofing attacks. The vulnerability is caused due to the use of a vulnerable version of the neon library.

For more information: SA36371. Note: This also fixes a Denial of Service when processing certain XML entities.
Posted by Raven on Saturday, July 03, 2010 @ 18:05:02 EDT (581 reads)
(Read More... | 1001 bytes more | Score: 0)
HTML 5 Comes With SQL Injection Risks  
Securitynb1 writes "
Internet Explorer 9 and Firefox 4 will support it, and Microsoft recently touted its advantages. But the upcoming version of HTML, which builds rich Internet application features into the Web programming language and shifts more Web functions to the client machine, also could open up new Web attack vectors.
Read the full article
"
Posted by Raven on Thursday, May 13, 2010 @ 09:18:05 EDT (649 reads)
( | Score: 0)
MySQL Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA39792

VERIFY ADVISORY: http://secunia.com/advisories/39792/

DESCRIPTION: Some vulnerabilities have been reported in MySQL, which can be exploited by malicious users to bypass certain security restrictions or potentially compromise a vulnerable system and by malicious people to cause a DoS (Denial of Service). Successful exploitation of this vulnerability may allow execution of arbitrary code. The vulnerabilities are reported in versions prior to 5.1.47.
Posted by Raven on Wednesday, May 12, 2010 @ 19:56:02 EDT (760 reads)
(Read More... | 1532 bytes more | Score: 0)
phpnuke.org has been compromised 
Security"From Snype @ www.phpnuke-install.com: Posted on Saturday, May 08, 2010 @ 07:06:19 CDT"

Snype writes:

PHP-Nuke is a popular Web content management system (CMS), based on PHP and a database such as MySQL, PostgreSQL, Sybase, or Adabas. Earlier versions were open source and free software protected by GNU Public License, but since then it has become commercial software. As it is still very popular in the Internet community, it is not surprising that it has become a target [yet again] of blackhat attacks.

WARNING: At the time of writing the front page of phpnuke.org still contains the malicious iframe, so we advise users to stay away from the site until it has been fixed.

Read Snype's entire article @ phpnuke-install.com
Posted by Raven on Monday, May 10, 2010 @ 08:44:46 EDT (797 reads)
( | Score: 0)
Apache.org hit by targeted XSS attack, passwords compromised 
SecurityCombining a cross-site scripting (XSS) vulnerability with a TinyURL redirect, hackers successfully broke into the infrastructure for the open-source Apache Foundation in what is being described as a “direct, targeted attack.”

The hackers hit the server hosting the software that Apache.org uses to it to track issues and requests and stole passwords from all users. The software was hosted on brutus.apache.org, a machine running Ubuntu Linux 8.04 LTS, the group said.

The passwords were encrypted on the compromised servers (SHA-512 hash) but Apache said the risk to simple passwords based on dictionary words “is quite high” and urged users to immediately rotate their passwords. ”In addition, if you logged into the Apache JIRA instance between April 6th and April 9th, you should consider the password as compromised, because the attackers changed the login form to log them,” Apache said.

Read Apache.org hit by targeted XSS attack, passwords compromised
Posted by Raven on Tuesday, April 13, 2010 @ 15:42:01 EDT (1613 reads)
( | Score: 0)
Google releases web security scanner 
Securitynb1 writes "Google has released an open source scanner that allows web application developers to test their applications for security holes. The application, called Skipfish, offers a similar functionality to that of tools such as Nmap or Nessus, but it's said to be much faster. Using fully automated heuristics, it detects code that is vulnerable to cross-site scripting attacks (XSS), SQL and XML injection attacks and many other attack types. The tool's comprehensive post-processing of the individual test results is designed to help with the interpretation of the final report.

Skipfish is a pure C implementation and according to Google, can easily process 2,000 HTTP requests per second – provided the tested server can handle such a high load. In individual tests across local networks, 7,000+ requests per second have reportedly been sent with a modest CPU load and memory footprint.

Google achieves this high performance via a serial I/O model which processes responses asynchronously and is said to offer much better scalability than traditional multi-threaded approaches with synchronous request processing. Optimised HTTP connection handling via features such as HTTP 1.1 range requests, keep-alive connections and data compression are designed to keep Skipfish's network bandwidth requirements in check.

Google says that it uses the scanner to test its own web applications for insecure interfaces. However, Google also points out that the security checks are far from comprehensive and do not satisfy most of the Web Application Security Consortium's (WASC) Web Application Security Scanner Evaluation Criteria criteria.

The latest release of Skipfish is version 1.10 Beta and a list of known issues is available on the project's Google Code page. Skipfish is released under version 2 of the Apache License.
"
Posted by Raven on Monday, March 22, 2010 @ 18:21:37 EDT (924 reads)
( | Score: 0)
Google Chrome Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA39029

VERIFY ADVISORY: http://secunia.com/advisories/39029/

CRITICALITY: Highly Critical

DESCRIPTION: Some vulnerabilities have been reported in Google Chrome, where some have unknown impacts and others can be exploited by malicious people to conduct spoofing attacks and bypass certain security restrictions.
Posted by Raven on Thursday, March 18, 2010 @ 20:28:35 EDT (998 reads)
(Read More... | 1790 bytes more | Score: 0)
SecurityFocus to partially shut down  
Securitynb1 writes "Symantec has announced that it plans to shut down part of its SecurityFocus security information portal. The company says that only the Mailing Lists, including Bugtraq, and its Vulnerability Database will remain online Starting on the 15th of March, SecurityFocus will begin transitioning its content to the Symantec Connect site.

Founded in 1999, SecurityFocus was acquired in 2002 by Symantec, the company behind another acquisition the popular Norton range of security products. In addition to its various mailing lists and vulnerability database, SecurityFocus maintains a comprehensive collection of articles and papers on a number of security issues. The site has also served as a reliable source for news from security experts on the latest security threats and problems.

Change in Focus, a SecurityFocus news post.
"
Posted by Raven on Friday, March 12, 2010 @ 22:56:26 EST (703 reads)
( | Score: 0)
Apache HTTP Server *mod_isapi* Module Unloading Vulnerability 
Security SECUNIA ADVISORY ID: SA38852

VERIFY ADVISORY: http://secunia.com/advisories/38852/

CRITICALITY: Highly Critical

DESCRIPTION: A vulnerability has been reported in Apache HTTP Server, which can be exploited by malicious people to potentially compromise a vulnerable system. For more information see vulnerability #2 in: SA38776

SOLUTION: Fixed in the SVN repository: http://svn.apache.org/viewvc?view=revision&revision=920961

ORIGINAL ADVISORY: http://httpd.apache.org/security/vulnerabilities_20.html

OTHER REFERENCES: SA38776: http://secunia.com/advisories/38776/
Posted by Raven on Wednesday, March 10, 2010 @ 21:14:10 EST (640 reads)
( | Score: 0)
Partners

NuSphere PhpED
IDE for PHP, HTML, CSS, XML, SMARTY, XHTML and other
Clan-Themes
Making clans look good!
CSE HTML Validator
ip address masquerading
CoffeeCup Software
Just Great Software
Code Authors
Home of Spam Blocker
Montego Scripts
phpDesigner
PHP Editor/IDE for all PHP/Web development

 
Recommended Sites
Montego Scripts - Home of HTML Newsletter

Code-Authors.com

nukeSEO.com

RavenNuke(tm) Test site

Totally Nuked Mods

Codezwiz Your #1 Help Resource

CSE HTML Validator Helped Clean up This Page!

PC Sympathy - Your Source for PC News and Technical Support

Mantis Bugtracker

Nuke-Evolution

TrickedOutNews.com - Home of Tricked Out News Mod, FaceBox and SlimBox RavenNuke(tm) mods

FLASH-FOR-NUKE

 
Old Articles

Monday, March 08
· Update For Two Vulnerabilities In gzip (0)
Saturday, March 06
· Critical Security Release Announcement From PHPBB Group (0)
Wednesday, February 24
· Google Picasa JPEG Processing Integer Overflow Vulnerability (0)
Thursday, February 18
· Internet Security 10 or IS2010 (0)
Thursday, February 11
· Google Chrome Multiple Vulnerabilities (0)
Monday, February 01
· Firefox-based attack wreaks havoc on IRC users (0)
Thursday, January 28
· IE vulnerability offers your files to hackers (0)
Tuesday, January 26
· Google Chrome Multiple Vulnerabilities (0)
Monday, December 07
· Patch Tuesday heads-up: MS to fix *critical* IE, Office security holes (0)
Sunday, November 22
· PHP Multiple Vulnerabilities (0)
Thursday, November 19
· Thousands of web sites compromised, redirect to scareware (0)
Sunday, November 08
· Adobe Reader Multiple Vulnerabilities (0)
Monday, October 19
· Microsoft exposes Firefox users to drive-by malware downloads (0)
Friday, October 09
· New Adobe PDF flaw under attack; Patch coming Tuesday (0)
Tuesday, September 22
· Microsoft unveils shield for critical Windows flaw as attack code looms (0)
Saturday, September 12
· Mozilla Firefox Multiple Vulnerabilities (0)
Wednesday, September 09
· Windows 7, Vista exposed to *teardrop attack* (0)
Tuesday, September 08
· Microsoft Windows DHTML Editing ActiveX Control Vulnerability (0)
Friday, September 04
· Sun Java System Active Server Pages Multiple Vulnerabilities (0)
· LiteSpeed Web Server Two Unspecified Vulnerabilities (0)

Older Articles
 
Verse of the Day
 
Daily Inspiration
 
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2010 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum