Última actualització: 01/11/2006; 11:44:30
Quands.cat Quands.cat
 
Notes sobre seguretat informàtica.
Publicitat

dimarts, 31 / octubre / 2006


[NetworkWorld] New Windows attack can kill firewall
Hackers have published code that could let an attacker disable the Windows Firewall on certain Windows XP machines.

The code, which was posted on the Internet early Sunday morning, could be used to disable the Windows Firewall on a fully patched Windows XP PC that was running Windows' Internet Connection Service (ICS). This service allows Windows users to essentially turn their PC into a router and share their Internet connection with other computers on the local area network (LAN.) It is typically used by home and small-business users.

The attacker could send a malicious data packet to another PC using ICS that would cause the service to terminate. Because this service is connected to the Windows firewall, this packet would also cause the firewall to stop working, said Tyler Reguly, a research engineer at nCircle Network Security Inc., who has blogged about the issue.
 
De la FAQ sobre aquesta vulnerabilitat:
Am I vulnerable Checklist:
1) Are you running Windows XP
2) Are you sharing your internet connection?

If the answer is yes to both of those, then you are vulnerable.

Mitigation:
1) Disable Internet Connection Sharing.
2) Block UDP port 53 (DNS) on the computer that is sharing the internet, manually set the DNS Server to your ISPs DNS address.
 


18:03 (# Enllaç permanent) | Comentaris: | Trackback:


[SecurityFocus] Metasploit targets wireless drivers
The Metasploit project, which aims to allow plug-and-play exploiting for penetration testers and researchers, will add the ability to target the wireless functionality of Windows and Linux operating systems, a member of the project said on the Metasploit blog this week.

The project has completed a major initiative that allows the framework to exploit flaws in kernel components, including wireless drivers.
 


10:57 (# Enllaç permanent) | Comentaris: | Trackback:


FirefoxUna d'aquelles coses que, de vegades, costa d'entendre: una vulnerabilitat, coneguda des de juny, però sense pegat específic públic; els desenvolupadors de Mozilla van dir que la versió 1.5.0.5 soluciona el problema.

Però, vés per on,  la versió 2.0 no inclou la solució per a aquest problema.

Hi ha una prova de concepte de la vulnerabilitat, suficient per demostrar com el Firefox es mor.

La bona notícia és que aquest bug sembla no explotable al nivell de comprometre l'ordinador de l'usuari de Firefox. Només produeix un DoS.


10:00 (# Enllaç permanent) | Comentaris: | Trackback:


[zmanda] How to setup and verify a backup solution for MySQL in 15 minutes - all using open source software. Zmanda Recovery Manager és un sistema per a la realització de còpies de seguretat de bases de dades MySQL de codi obert. Una característica ben destacable és la capacitat de realitzar còpies de seguretat en calent de la base de dades (no cal aturar el motor).
We have a fairly representative MySQL database being managed by a DBA. The DBA doesn't have the time to write backup/recovery scripts nor does the DBA want to manually backup the database every 12 hours. We are running one MySQL database using the InnoDB Storage Engine. We will be performing a logical backup of our database. A logical backup 1) contains SQL statements that can reconstruct the database table schema and contents, 2) can be performed while the database is still running (hot backup), and 3) can be restored to another platform or another database.
 


09:52 (# Enllaç permanent) | Comentaris: | Trackback:


Una imatge anomenada Eina.gif
RFIDIOt is an open source python library for exploring RFID devices.
 


09:37 (# Enllaç permanent) | Comentaris: | Trackback:

© Copyright 2003-2006 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
Wishlist
Octubre 2006
Diu Dil Dim Dim Dij Div Dis
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        
Set   Nov

Click to see the XML version of this web page.






Una imatge anomenada a_wiccac-logo.gif Creative Commons License

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter