Four ‘important’ Microsoft patches due Tuesday

Friday, July 4th, 2008

Microsoft will release four security patches for its Windows, Exchange, and SQL products next Tuesday, all rated "important."The Exchange and SQL flaws are "Elevation of Privilege" bugs, meaning that an attacker could theoretically exploit them to get administrative access to a PC. One of the Windows flaws is labeled a ...

New Opera v9.51 fixes couple of security issues

Thursday, July 3rd, 2008

A new version of Opera (v9.51) has been released. It fixes couple of security vulnerabilities and some stability issues. One of the fixed issues includes arbitrary code execution but the exploit has not been published yet.Source:http://isc.sans.org/diary.html?storyid=4666&rss

Ratproxy – Passive Web Application Security Assessment Tool

Wednesday, July 2nd, 2008

Ratproxy is a semi-automated, largely passive web application security audit tool. It is meant to complement active crawlers and manual proxies more commonly used for this task, and is optimized specifically for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the ...

Firefox 2.0.0.15 is out

Wednesday, July 2nd, 2008

For those of you that haven't yet made the move to Firefox 3.0, the Mozilla folks have released Firefox 2.0.0.15 which according to the release notes link (see below) fixes a security vulnerability. However, the "known vulnerabilities" page (linked from the release notes page) doesn't include any info (yet) ...

Secure SQL Server from SQL injection attacks

Wednesday, July 2nd, 2008

SQL injection attacks are probably the most common way for hackers to strike Internet-facing SQL Server databases. No matter how secure your network is or how many firewalls you have in place, any application that uses dynamic SQL and allows for unchecked user input to be passed to the database ...