Monthly Archives: August 2016
Dropbox Email Warns Users That Old Passwords Must Be Reset
Apple Tackles iPhone One-Tap Spyware Flaws
Htcap Analysis Tool 1.0.1
Htcap is a web application analysis tool for detecting communications between javascript and the server. It crawls the target application and maps ajax calls, dynamically inserted scripts, websockets calls, dynamically loaded resources and some interesting elements. The generated report is meant to be a good starting point for a manual web application security audit. Htcap is written in python and uses phantomjs to load pages injecting a probe that analyzes javascript behaviour. Once injected, the probe, overrides native javascript methods in order to intercept communications and DOM changes. It also simulates user interaction by firing all attached events and by filling html inputs.
Debian Security Advisory 3654-1
Debian Linux Security Advisory 3654-1 – Two vulnerabilities were discovered in quagga, a BGP/OSPF/RIP routing daemon.
Debian Security Advisory 3652-1
Debian Linux Security Advisory 3652-1 – handling problems and cases of missing or incomplete input sanitising may result in denial of service or the execution of arbitrary code if malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum, PDB, DDS, DCM, EXIF, RGF or BMP files are processed.
KV Site Admin CMS 3.0 SQL Injection
KV Site Admin CMS version 3.0 suffers from a remote SQL injection vulnerability.
Threatpost News Wrap, August 26, 2016
Mike Mimoso and Chris Brook discuss the news of the week, including the latest on ShadowBrokers and Cisco, Sweet32, decryptors for the Wildfire ransomware, and some gaming forum breaches.
Apple libc incomplete fix of Security Update for OS X El Capitan 10.11.2
Posted by [CXSEC] on Aug 26
——————————————————————————–
Apple libc incomplete fix of Security Update for OS X El Capitan 10.11.2
Credit: Maksymilian Arciemowicz from CXSECURITY.COM
URL: https://cxsecurity.com/issue/WLB-2016080232
——————————————————————————–
Apple tried to fix security issue in file system (FTS) libc implementation
but doesn’t patch it completely….
Tales from Ransomwhere: Shadow Copies
It is difficult to recover files that were kidnapped by ransomware without paying the criminals. In this new chapter we will clue you in on some tricks.