Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: Virus

» Topic:  First Symbian trojan that tries to attack PC

» Added by:  sp3x

» Date:  24.9.2005

  Now as the Bagle situation has calmed down we have time to blog about other interesting case we got yesterday.

SymbOS/Cardtrap.A is otherwise unremarkable Symbian trojan, except that it also tries to infect users PC if user inserts the phone memory card to PC.

When infecting Symbian phone the Cardtrap.A copies two Windows worms (Win32/Padobot.Z and Win32/Rays) to the memory card of the phone. Padobot.Z is copied with autorun.inf file in attempt to start automatically if the card is inserted to PC using windows. Rays is copied with filename SYSTEM.EXE and same icon as the System folder, this is done as social engineering attempt so that user would click on Rays instead of System folder.

To our knowledge, no Windows version supports autorun from a memory card, but it still might work with some Windows version and third party driver combination.

The goal of the trojan is most likely to cause user to infect his PC when he is trying disinfect his phone. A typical reaction of more advanced user who would encounter trojan like Cardtrap, would be to insert the phone memory card to PC to copy file manager or disinfection tool to the card. Only this time a careless user might to get his PC infected in process.

Source : f-secure.com



Alert

Microsoft VISTA TCP/IP stack buffer overflow

high- 2008-11-27

Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 dba_replace()
   destroying file

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.