Inguma 0.0.7.2 Released for Download – Penetration Testing Toolkit

Monday, March 17th, 2008

For those that don’t know, Inguma is an open source penetration testing and vulnerability research toolkit written completely in Python. The environment is mainly oriented to attack Oracle related systems but, anyway, it can be used against any other kind of systems. It’s becoming a mature and useful package! I’m glad ...

Cisco product shipped with backdoor

Monday, March 17th, 2008

Cisco has reported a critical security hole in CiscoWorks Internetwork Performance Monitor (IPM), the network availability monitoring component of the CiscoWorks LAN Management Solution (LMS). According to the advisory, commands can be executed remotely on the underlying Solaris or Windows operating system without authentication. Cisco reports that the problem is due ...

Malware Analysis for Administrators

Saturday, March 8th, 2008

http://www.securityfocus.com/infocus/1780   1. Introduction The threat of malicious software can easily be considered as the greatest threat to Internet security. Earlier, viruses were, more or less, the only form of malware. Nowadays, the threat has grown to include network-aware worms, trojans, DDoS agents, IRC Controlled bots, spyware, and so on. The infection vectors ...

Unpatched Machines Seen As Major Security Threat

Saturday, March 8th, 2008

Hackers will keep cranking out exploits that take advantage of known software vulnerabilities because, although patches are available, a minority of machines are fixed, security vendor McAfee said Monday. In releasing its quarterly security analysis, McAfee's "AVERT" virus research team noted that exploited vulnerabilities are becoming a dominant threat to ...

Password Stealing Browser Hijacker Discovered

Saturday, March 8th, 2008

The Internet Storm Center has announced a very scary discovery. They have found a browser hijacker, installed as a Browser Helper Object (BHO), that will monitor what are supposed to be secure, encrypted browsing sessions and steal passwords. These passwords then are forwarded to a web based script at www.refestltd.com. ...