Should Kids Be Using Facebook?

Kids can put a lot of pressure on parents to let them use Facebook. However there are several important things that parents should know before making a decision either way.

Did you know?

  • Facebook has a minimum required age to create an account, and for good reason – children can be exposed to inappropriate content.
    For example: Kids may have older Facebook friends or family (perhaps friends of their friends) that post content to their timeline that isn’t appropriate for them to see.
  • Kids themselves may be unknowingly posting inappropriate content or giving away too much of their families private information.
  • When a Facebook account is created for an underage child using a fake date of birth, this gives Facebook a false impression of the child’s real age. This can result in young children being incorrectly targeted by Facebook advertisers and exposed to inappropriate products and services.
  • Kids could also lose all of their Facebook data at any time. Facebook has a whistleblower policy that allows anyone to nominate an account that they think is being used by someone under the required age. If that happens, the account will be shut down and become inaccessible.

 

So do you still think kids should be using Facebook?

My Little Forum Multiple XSS Security Vulnerabilities

Posted by Jing Wang on Feb 03

*My Little Forum Multiple XSS Security Vulnerabilities*

Exploit Title: My Little Forum Multiple XSS Security Vulnerabilities
Vendor: My Little Forum
Product: My Little Forum
Vulnerable Versions: 2.3.3 2.2 1.7
Tested Version: 2.3.3 2.2 1.7
Advisory Publication: Feb 2, 2015
Latest Update: Feb 2, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: *
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM)…

Maldrone for drones.

Posted by Rahul Sasi on Feb 03

I wrote a blog post last week regarding a small project I was working on my
free time “Learning about Drones and security issues” . And a youtube demo
video titled “Maldrone first malware for drones”. The blog is a preview of
few things I would be presenting at my upcoming talk at Nullcon
<http://nullcon.net/website/goa-15/about-speakers.php> .

Video: https://www.youtube.com/watch?v=5SlWdl4ZuAI
Blog:…

RHSA-2015:0113-1: Moderate: libvncserver security update

Red Hat Enterprise Linux: Updated libvncserver packages that fix two security issues are now
available for Red Hat Enterprise Linux 6.5 Extended Update Support.

Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2014-6051, CVE-2014-6055

RHSA-2015:0112-1: Moderate: libyaml security update

Red Hat Enterprise Linux: Updated libyaml packages that fix one security issue are now available for
Red Hat Software Collections 1.

Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2014-9130

USN-2488-1: ClamAV vulnerability

Ubuntu Security Notice USN-2488-1

2nd February, 2015

clamav vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 14.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

ClamAV could be made to crash or run programs if it processed a specially
crafted file.

Software description

  • clamav
    – Anti-virus utility for Unix

Details

Sebastian Andrzej Siewior discovered that ClamAV incorrectly handled
certain upack packer files. An attacker could possibly use this issue to
cause ClamAV to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 14.10:
clamav

0.98.6+dfsg-0ubuntu0.14.10.1
Ubuntu 14.04 LTS:
clamav

0.98.6+dfsg-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
clamav

0.98.6+dfsg-0ubuntu0.12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

CVE-2014-9328