Updates for Java eliminate many security holes

Thursday, July 10th, 2008

Sun Microsystems has issued updates for Java to eliminate many errors and vulnerabilities in the Java Development Kit (JDK) and the Java Runtime Environment (JRE). These include DoS vulnerabilities, buffer overflows and other errors that could cause a crash or allow a crafted applet to access certain resources, the filing ...

DNSenum – Domain Information Gathering Tool

Thursday, July 10th, 2008

The first stage of penetration testing is usually passive information gathering and enumeration (active information gathering). This is where tools like dnsenum come in, the purpose of DNSenum is to gather as much information as possible about a domain. The program currently performs the following operations: 1. Get the host’s addresse (A ...

Gmail now blocking fake eBay, PayPal e-mails

Wednesday, July 9th, 2008

Google on Tuesday said it is now using an e-mail authentication technology to keep phishers from luring Gmail users to fake eBay and PayPal Web pages in order to steal usernames and passwords.Source:http://news.cnet.com/8301-10784_3-9985605-7.html?hhTest∂=rss&tag=feed&subj=NewsBlog

Zero day Word flaw exploited by Trojan

Wednesday, July 9th, 2008

Microsoft warns that an unpatched Word vulnerability has become the subject of targeted attacks.The flaw - which is restricted to Microsoft Office Word 2002 Service Pack 3 - creates a mechanism for hackers to inject hostile code onto vulnerable systems. Redmond has published workarounds as a stop-gap measure while its ...

Microsoft DNS Security Fix Knocks ZoneAlarm Users Offline

Wednesday, July 9th, 2008

The problem began when Microsoft on Tuesday sent patch number KB951748 to Windows users. The patch is designed to plug a security vulnerability that leaves computers vulnerable to so-called DNS attacks.The vulnerability is widespread and affects products made by numerous networking and software vendors beyond Microsoft. It was discovered by ...