Monday, July 13, 2009

Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution

Microsoft is investigating a privately reported vulnerability in Microsoft Video ActiveX Control. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.

We are aware of attacks attempting to exploit the vulnerability.

Our investigation has shown that there are no by-design uses for this ActiveX Control in Internet Explorer which includes all of the Class Identifiers within the msvidctl.dll that hosts this ActiveX Control. For Windows XP and Windows Server 2003 customers, Microsoft is recommending removing support for this ActiveX Control within Internet Explorer using all the Class Identifiers listed in the Workaround section. Though unaffected by this vulnerability, Microsoft is recommending that Windows Vista and Windows Server 2008 customers remove support for this ActiveX Control within Internet Explorer using the same Class Identifiers as a defense-in-depth measure.

Read more...

Monday, July 6, 2009

Microsoft warns of hole in Video ActiveX control

"Microsoft on Monday warned of a vulnerability in its Video ActiveX Control that could allow an attacker to take control of a PC if the user visits a malicious Web site.

There have been limited attacks exploiting the hole, which affects Windows XP and Windows Server 2003, Microsoft said on its Security Response Center blog.

This is the second DirectShow security hole Microsoft has announced in the past few months. The company has yet to provide a security update for a vulnerability announced in May that involves the way DirectX handles QuickTime files."

Thursday, July 2, 2009

US job losses worse than expected

Totally not IT or security related but everyone is pretty much affected one way or another....

The number of jobs lost in the US last month came in at 467,000, which was much more than had been expected.The jobless rate rose to 9.5% in June, from 9.4% in May, as the US economy continued to struggle.

Since the start of the recession in December 2007, the number of jobless people has risen by 7.2 million, the Department of Labor said.

The unemployment rate was slightly lower than had been expected, but was still the highest since August 1983.

In its separate weekly jobs report, the Department of Labor said that the number of newly laid-off workers applying for employment benefits last week fell to 614,000, while the number of people continuing to claim benefits unexpectedly fell to 6.7 million.

Read more...

Wednesday, July 1, 2009

Kon-Boot

"Kon-Boot is an prototype piece of software which allows to change contents of a linux kernel (and now Windows kernel also!!!) on the fly (while booting). In the current compilation state it allows to log into a linux system as 'root' user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password. It was acctually started as silly project of mine, which was born from my never-ending memory problems :) Secondly it was mainly created for Ubuntu, later i have made few add-ons to cover some other linux distributions. Finally, please consider this is my first linux project so far :) Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0."

Read more...

Tuesday, June 30, 2009

Snort Setup Guide

A new set-up guide based on Nick Moore's June 12 webinar "Installing Snort on FC 10" is now available on Snort.org.
The document is posted at: http://www.snort.org/docs/setup-guides/

Saturday, June 6, 2009

Virginia patients warned about hacking of state drug Web site

By Bill Sizemore
The Virginian-Pilot
© June 4, 2009

State officials are notifying more than a half-million Virginians that their Social Security numbers may have been contained in a prescription drug database that was targeted by a computer hacker April 30.

The hacker gained access to the Prescription Monitoring Program computer system, which is designed to deter prescription drug abuse, and demanded a $10 million ransom. The hacker has not been identified.

A criminal investigation has not yet determined what, if any, personal information was put at risk in the incident, said Sandra Whitley Ryals, director of the Virginia Department of Health Professions, on Wednesday.

Nevertheless, the state is mailing individual notifications to 530,000 people whose prescription records may have contained Social Security numbers, in order to alert them to the potential for identity theft, Ryals said.

Read more...

Monday, June 1, 2009

Tory MP hacked on Facebook

IT security and control firm Sophos is reminding computer users to be on their guard against phishing attacks following news that the Facebook account of Conservative MP for Lichfield, Michael Fabricant, has been hacked.

According to reports, the MP fell foul of a phishing campaign that stole his username and password, and hackers then sent messages to Fabricant's 1,500 friends saying "Look at this!" and pointing recipients to a malicious webpage. Facebook has now suspended the politician's page.

Read more...

Hack the Box Blue

https://arcy24.medium.com/hack-the-box-blue-f5ae5b602a5c