Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: World

» Topic:  E-mail bomber to face retrial

» Added by:  Jeremy Kirk, IDG news service

» Date:  15.5.2006

  A teenager who crashed a former employer's server by sending a torrent of junk e-mail, a practice known as mail bombing, could still face up to five years in prison after the case was sent back to trial.

On Thursday, a British appeals court rejected a lower court's ruling that David Lennon didn't violate the UK's Computer Misuse Act of 1990. Lennon is charged with one count of unauthorised modification of a computer.

The case goes to the core of calls to revise the Computer Misuse Act with more specific language to address denial-of-service attacks. The U.K. Parliament is considering revising the act to increase the maximum penalty for unauthorised modification of a computer from five years' imprisonment to 10 years, among other changes.

Prosecutors must prove that the defendant's actions modified a computer, and that the action was unauthorised. Lennon allegedly launched a denial-of-service attack using a program called Avalanche in early 2004 that crashed the e-mail server of Domestic and General Group, a company that provides warranties for domestic appliances.

But a district judge at Wimbledon Magistrates' Court ruled in November that the excess e-mail was authorised since the company's website invited responses, and Lennon was therefore not in violation. Prosecutors appealed, sending the case to the Royal Courts of Justice.

Updated interpretations of the Computer Misuse Act are needed to deal with high-tech crime, Senior Crown Prosecutor Russell Tyner said in a statement.

Last Thursday, the Royal Courts of Justice sent the case back to the magistrates' court, saying the high volume of e-mail constituted a crime. No date has been set for Lennon's continuing trial.

Lennon could face six months in prison if sentenced in magistrates' court. However, prosecutors could ask for a referral to the crown courts, where he could face up to five years in prison, a Crown Prosecution Service official said.



Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.