A Network Time Protocol (NTP) Amplification attack is an emerging form of Distributed Denial of Service (DDoS) that relies on the use of publicly accessible NTP servers to overwhelm a victim system with UDP traffic. The NTP service supports a monitoring service that allows administrators to query the server for traffic counts of connected clients. This information is provided via the “monlist” command. The basic attack technique consists of an attacker sending a “get monlist” request to a vulnerable NTP server, with the source address spoofed to be the victim’s address. This tool is a proof of concept that demonstrates this attack.
Monthly Archives: July 2015
Yet Another High Severity Bug Found In OpenSSL
Ransomware Campaign Alters Variants To Evade Detection
Manhattan DA: iPhone Crypto Locked Out Cops 74 Times
Adobe Tackles New Flash Threat After Hacking Team Leak
GLSA 201507-09: PyPAM: Arbitrary code execution
DSA-3306 pdns – security update
Toshifumi Sakaguchi discovered that the patch applied to pdns, an
authoritative DNS server, fixing
CVE-2015-1868, was insufficient in
some cases, allowing remote attackers to cause a denial of service
(service-affecting CPU spikes and in some cases a crash).
DSA-3307 pdns-recursor – security update
Toshifumi Sakaguchi discovered that the patch applied to pdns-recursor,
a recursive DNS server, fixing
CVE-2015-1868, was insufficient in some
cases, allowing remote attackers to cause a denial of service
(service-affecting CPU spikes and in some cases a crash).
FreeBSD Security Advisory – BIND Denial Of Service
FreeBSD Security Advisory – BIND 9 is an implementation of the Domain Name System (DNS) protocol. The named daemon is an Internet Domain Name Server. The libdns library is a library of DNS protocol support functions. Due to a software defect, specially constructed zone data could cause named to crash with an assertion failure and rejecting the malformed query when DNSSEC validation is enabled. An attacker who can cause specific queries to be sent to a nameserver could cause named to crash, resulting in a denial of service.
WordPress Easy2Map-Photos 1.09 SQL Injection
WordPress Easy2Map-Photos plugin version 1.09 suffers from a remote SQL injection vulnerability.