Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: Virus

» Topic:  Yet Another eBay Phish

» Added by:  Era

» Date:  3.11.2005

  A new kind of eBay phishing attempt is going around. It's only going to fool people who have something for sale on eBay, because it's disguised as a question from another eBay member about shipping costs for "your item".

It even includes the boilerplate from a genuine eBay message which says "Your registered name is included to show this message originated from eBay", although it does not in fact contain your registered eBay screen name, for obvious reasons. The phishers only have your email address, not your eBay screen name. (Of course, they might be the same, or at least similar. One more reason to invent a truly unique screen name for all the on-line services you subscribe to.)

Because the message contains a number of fingerprints which are typical for forged messages, both spam and phish, it's already detected by our existing phishing rules.

This brings up another point, though. The majority of these fingerprints are based on header analysis. But when we get a spam or phishing sample, we frequently only get the body of the message (and sometimes only something like a copy-paste of what the user actually sees, or even just a screen shot).

In fact, a number of "modern" email clients make it very very hard indeed to forward a message with the full original headers intact. If you are connected to an Exchange server, it's not even possible. (Fortunately, we hear Microsoft is finally working on this.)

An example of what takes in Outlook to send a proper sample is at http://www.umkc.edu/is/cs/abuse/headers_outlook.htm, but see your own ISP's abuse pages, they probably have something quite similar ... and similary complex.

If you want to send us a proper spam or phishing sample, it would actually be a farily good idea to install a third-party plug-in to help extract the full headers. We are aware of such plug-ins for Outlook and Eudora.

Ironically, those of us who still live in the "stone age" don't have such problems. In classical email clients such as Mutt and Gnus (and, ${dmr} bless you, Pine, if you configure it correctly) this is not a problem at all.

Source : www.f-secure.com



Alert

Microsoft VISTA TCP/IP stack buffer overflow

high- 2008-11-27

Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 dba_replace()
   destroying file

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.