... neuere Einträge
Tuesday, 19. July 2011
Microsoft offers $250,000 of Rustock Botnet
Am Tuesday, 19. Jul 2011 im Topic 'News'
Microsoft Declares "Today, we take our pursuit a step further. After publishing notices in two Russian newspapers last month to notify the Rustock operators of the civil lawsuit, we decided to augment our civil discovery efforts to identify those responsible for controlling the notorious Rustock botnet by issuing a monetary reward in the amount of $250,000 for new information.
Source
http://www.zdnet.com/blog/hardware/microsoft-offering-250000-reward-for-rustock-botnet-info/13741
Source
http://www.zdnet.com/blog/hardware/microsoft-offering-250000-reward-for-rustock-botnet-info/13741
NetSecL v.3.2
Am Tuesday, 19. Jul 2011 im Topic 'Pentest'
NetSecL is a hardened,live and installable OS based on OpenSuse suitable for Desktop/Server and Penetration testing. Once installed you can fully enjoy the features of GrSecurity hardened kernel and penetration tools OR use the penetration tools directly from your live DVD.
Installation PDF:
http://rsync.netsecl.com/netsecl_3.2.pdf
Download:
http://susegallery.com/a/EmL6GN/netsecltoolset
Installation PDF:
http://rsync.netsecl.com/netsecl_3.2.pdf
Download:
http://susegallery.com/a/EmL6GN/netsecltoolset
WP e-Commerce <= 3.8.4 - SQL
Am Tuesday, 19. Jul 2011 im Topic 'Vulnerabilities'
Download link:
http://wordpress.org/extend/plugins/wp-e-commerce
Google Dork:
inurl:page_id= "Your billing/contact details"
Bugged code (wpsc-theme/functions/wpsc-user_log_functions.php):
foreach ( (array)$_POST['collected_data'] as $value_id => $value ) {
$form_sql = "SELECT * FROM `" . WPSC_TABLE_CHECKOUT_FORMS . "` WHERE
`id` = '$value_id' LIMIT 1?;
$form_data = $wpdb->get_row( $form_sql, ARRAY_A );
FIX:
Upgrade to new version
http://wordpress.org/extend/plugins/wp-e-commerce
Google Dork:
inurl:page_id= "Your billing/contact details"
Bugged code (wpsc-theme/functions/wpsc-user_log_functions.php):
foreach ( (array)$_POST['collected_data'] as $value_id => $value ) {
$form_sql = "SELECT * FROM `" . WPSC_TABLE_CHECKOUT_FORMS . "` WHERE
`id` = '$value_id' LIMIT 1?;
$form_data = $wpdb->get_row( $form_sql, ARRAY_A );
FIX:
Upgrade to new version
PHP/HTML Redirection
Am Tuesday, 19. Jul 2011 im Topic 'Source Code'
Source
http://pastebin.com/t5Y79711
http://pastebin.com/t5Y79711
... ältere Einträge