<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ClubHack &#187; Vulnerabilities</title>
	<atom:link href="http://www.clubhack.com/category/news/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clubhack.com</link>
	<description>Empowering innovation &#38; leadership in security</description>
	<lastBuildDate>Thu, 16 May 2013 08:58:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Oracle released out of cycle patch for Apache &#8220;HTTP Killer&#8221; bug</title>
		<link>http://www.clubhack.com/oracle-released-out-of-cycle-patch/</link>
		<comments>http://www.clubhack.com/oracle-released-out-of-cycle-patch/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 08:37:32 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Apache HTTP Server]]></category>
		<category><![CDATA[National Vulnerability Database]]></category>
		<category><![CDATA[Oracle HTTP Server]]></category>
		<category><![CDATA[Patch]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1411</guid>
		<description><![CDATA[Oracle issued an emergency patch to fix a denial of service(DoS) vulnerability in Oracle HTTP server products that are based on the Apache Web server 2.0 and 2.2. Attack Details &#8212;&#8212;&#8212;&#8212;&#8212;&#8211; With this attack any exploiter can remotely send large chunk of data in the header without any authentication or requiring  any username and password. [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em">
<div class="wp-caption alignright" style="width: 250px"><a href="http://www.flickr.com/photos/43394187@N00/125245043"><img src="http://farm1.static.flickr.com/45/125245043_0080575160_m.jpg" alt="Denial of Service Attack" width="240" height="160" /></a><p class="wp-caption-text">Image by kryptyk via Flickr</p></div>
</div>
<p>Oracle issued an <a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html">emergency patch</a> to fix a denial of service(DoS) vulnerability in Oracle HTTP server products that are based on the <a class="zem_slink" title="Apache HTTP Server" href="http://en.wikipedia.org/wiki/Apache_HTTP_Server" rel="wikipedia">Apache Web server</a> 2.0 and 2.2.</p>
<p>Attack Details<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
With this attack any exploiter can remotely send large chunk of data in the header without any authentication or requiring  any username and password. When the server tries to process the data, memory and CPU resources are exhausted, resulting in a <a class="zem_slink" title="Denial-of-service attack" href="http://en.wikipedia.org/wiki/Denial-of-service_attack" rel="wikipedia">DoS attack</a>. This bug is known since long but a  security researcher [kingscope] posted an &#8220;<a href="http://seclists.org/fulldisclosure/2011/Aug/175">Apache Killer</a>&#8221; Perl script on <a class="zem_slink" title="Full disclosure" href="http://en.wikipedia.org/wiki/Full_disclosure" rel="wikipedia">Full Disclosure mailing list</a> in August; which made it easier to launch such attacks.</p>
<p>National Vulnerability Database (NVD) has assigned a <a class="zem_slink" title="CVSS" href="http://en.wikipedia.org/wiki/CVSS" rel="wikipedia">Common Vulnerability Scoring System</a> (CVSS) score of 7.8 to this vulnerability &#8211; <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3192">Common Vulnerability and Exposures -2011-3192</a>.</p>
<p>Oracle strongly recommended customers to apply Security patch as soon as possible since this patch is released out of the regular quarterly cycle of updates.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/oracle-released-out-of-cycle-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patchy Tuesday: August 9</title>
		<link>http://www.clubhack.com/patchy-tuesday-august-9/</link>
		<comments>http://www.clubhack.com/patchy-tuesday-august-9/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:06:34 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[advance notification]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Patch Tuesday]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1361</guid>
		<description><![CDATA[Microsoft has announced advance notification for 13 security bulletins to address 22 vulnerabilities in Windows XP/7/Vista/Server 2008, Office, Internet Explorer, .NET and Visual Studio for August 9, 2011. Two among 13 bulletins are rated as critical [highest severity] to prevent attacks related to remote code execution. Check the bulletin summary below Full version of Microsoft [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em">
<div class="wp-caption alignright" style="width: 96px"><a href="http://en.wikipedia.org/wiki/File:Internet_Explorer_7_Logo.png"><img src="http://upload.wikimedia.org/wikipedia/en/1/10/Internet_Explorer_7_Logo.png" alt="Internet Explorer Mobile Logo" width="86" height="76" /></a><p class="wp-caption-text">via Wikipedia</p></div>
</div>
<p><a class="zem_slink" title="Microsoft" href="http://en.wikipedia.org/wiki/Microsoft" rel="wikipedia">Microsoft</a> has announced advance notification for 13 security bulletins to address 22 vulnerabilities in <a class="zem_slink" title="Microsoft Windows" href="http://en.wikipedia.org/wiki/Microsoft_Windows" rel="wikipedia">Windows</a> XP/7/Vista/Server 2008, <a class="zem_slink" title="Microsoft Office" href="http://office.microsoft.com/en-us/default.aspx" rel="homepage">Office</a>, <a class="zem_slink" title="Internet Explorer" href="http://www.microsoft.com/windows/internet-explorer/default.aspx" rel="homepage">Internet Explorer</a>, <a class="zem_slink" title=".NET Framework" href="http://en.wikipedia.org/wiki/.NET_Framework" rel="wikipedia">.NET</a> and Visual Studio for August 9, 2011.</p>
<p>Two among 13 bulletins are rated as critical [highest severity] to prevent attacks related to remote code execution. Check the bulletin summary below</p>
<div id="attachment_1362" class="wp-caption alignleft" style="width: 585px"><a href="http://clubhack.com/wp-content/uploads/2011/08/ScreenShot00119.png"><img class="size-full wp-image-1362 " src="http://clubhack.com/wp-content/uploads/2011/08/ScreenShot00119.png" alt="" width="575" height="754" /></a><p class="wp-caption-text">Security Bulletin Summary</p></div>
<p>Full version of Microsoft Security Bulletin Advance Notification for August: <a title="Microsoft August Sec. Bulletin" href="http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx.">http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/patchy-tuesday-august-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TDL-4 botnet traps 4.5 million PC&#8217;s</title>
		<link>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/</link>
		<comments>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 13:32:46 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tdl-4]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1326</guid>
		<description><![CDATA[Security researchers [Sergey Golovnoav &#38; Igor Soumenkov] at Kaspersky Lab have posted a detailed analysis of new botnet called TDL-4 and calling it as &#8211;&#62;  the one that might just be &#8220;indestructible&#8221;. TDL-4 compared to previous versions is an updated algorithm encrypting the protocol used for communication between infected computers and botnet command and control [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em">
<div class="wp-caption alignright" style="width: 138px"><a href="http://commons.wikipedia.org/wiki/File:Malware_logo.png"><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Malware_logo.png" alt="I constructed this image using :image:Computer..." width="128" height="128" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p><a href="http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot">Security researchers [Sergey Golovnoav &amp; Igor Soumenkov] at Kaspersky Lab</a> have posted a detailed analysis of new <a class="zem_slink" title="Botnet" rel="wikipedia" href="http://en.wikipedia.org/wiki/Botnet">botnet</a> called  TDL-4 and calling it as &#8211;&gt;  the one that might just be &#8220;indestructible&#8221;. TDL-4 compared to previous versions is an  updated algorithm encrypting the protocol used for communication between  infected computers and botnet command and control servers.</p>
<p>TDL-4 is distributed via adult sites, bootleg websites, and video and file storage  services where affiliates receive between $20 to $200 for every 1,000 installations of  TDL. The [TDL-4] botnet have already infected  more than 4.5 million computers and is    used by hackers to manipulate adware, search engines, to provide    anonymous internet access and acts as a launch pad for other malware&#8217;s.</p>
<p>TDL loads into the MBR and messes with Windows memory even before the OS loads, injecting malware right into Windows right from the start when there is no security at place. [MBR: <a class="zem_slink" title="Master boot record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Master_boot_record">Master Boot Record</a> is responsible for bootstrapping/loading  the OS].</p>
<p>As per Kaspersky Labs &#8220;key threat&#8221; from TDL-4 type botnet is that even if the    control servers are seized and shut down, botnet owners will not loose complete control because    of its <a class="zem_slink" title="Peer-to-peer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Peer-to-peer">peer to peer networking</a> capabilities.</p>
<p>TDL seems to be dodgy, well planned and smartly implemented and can be a tough analysis problem for security researchers. But History tells us its the ethical guys or investigators/security researchers have taken down all malware&#8217;s sooner or later and the challenge is open again for them.</p>
<p>Note:</p>
<ul>
<li> <a class="zem_slink" title="Conficker" rel="wikipedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> was taken down  last year.</li>
<li><a href="http://clubhack.com/rustock-botnet-goes-silent-2/">Rustock botnet</a> [world's biggest source  of <a class="zem_slink" title="E-mail spam" rel="wikipedia" href="http://en.wikipedia.org/wiki/E-mail_spam">SPAM</a>] was    shut down after <a class="zem_slink" title="Microsoft" rel="geolocation" href="http://maps.google.com/maps?ll=47.6395972222,-122.12845&amp;spn=1.0,1.0&amp;q=47.6395972222,-122.12845%20%28Microsoft%29&amp;t=h">Microsoft</a> and US authorities  located and seized its control    servers.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony PSN hit by new exploit</title>
		<link>http://www.clubhack.com/sony-psn-hit-by-new-exploit/</link>
		<comments>http://www.clubhack.com/sony-psn-hit-by-new-exploit/#comments</comments>
		<pubDate>Thu, 19 May 2011 10:21:04 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[PlayStation Network]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1227</guid>
		<description><![CDATA[Yesterday Nyleveia revealed a new vulnerability in Sony PSN password reset page. The hack involves PSN web-based password reset page, where it’s said anyone can change someone else’s password using their PSN account email and date of birth (details possibly collected by hackers in April breach). Eurogamer’s also claiming to have seen actual video footage [...]]]></description>
				<content:encoded><![CDATA[<div class="mceTemp">
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em">
<div class="wp-caption alignright" style="width: 158px"><a href="http://en.wikipedia.org/wiki/File:PSN_logo_color_trans.png"><img src="http://upload.wikimedia.org/wikipedia/en/thumb/b/bc/PSN_logo_color_trans.png/300px-PSN_logo_color_trans.png" alt="Logo of the PlayStation Network" width="148" height="127" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
</div>
<p>Yesterday <a href="http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-your-accounts-are-still-not-safe/">Nyleveia</a> revealed a new vulnerability in <a class="zem_slink" title="PlayStation Network" rel="wikipedia" href="http://en.wikipedia.org/wiki/PlayStation_Network">Sony PSN</a> password reset page. The  hack involves PSN web-based password reset page, where it’s said   anyone can change someone else’s password using their PSN account email   and date of birth (details possibly collected by hackers in <a href="http://clubhack.com/sony-playstation-network-breached/">April breach</a>). Eurogamer’s  also <a href="http://www.eurogamer.net/articles/2011-05-18-sonys-psn-password-page-hacked">claiming</a> to have seen actual video footage of PSN password exploit/hack in action.</p>
<p>Whatever the case maybe when I tried to login through <a href="http://us.playstation.com/psn/">PSN site</a> &#8211;&gt; following maintenance page is displayed</p>
<p class="mceTemp mceIEcenter" style="text-align: center">&nbsp;</p>
<dl>
<dt><a href="http://clubhack.com/wp-content/uploads/2011/05/2011-05-19_124924.png"><img class="size-full wp-image-1228  " src="http://clubhack.com/wp-content/uploads/2011/05/2011-05-19_124924.png" alt="" width="472" height="321" /></a></dt>
</dl>
<p>Sony started <a href="http://twitter.com/#!/sorabhk5/status/70369895912718336">phased relaunch</a> of PlayStation Network last week with <a href="http://us.playstation.com/support/answer/index.htm?a_id=2360">updated software</a> , customer appreciation program (free games) and promise of higher standards  for security.</p>
<p>Sony also <a href="http://blog.eu.playstation.com/2011/05/18/update-on-psn-password-reset-process/">confirmed the hack</a> or to be precise the &#8220;URL exploit&#8221;  and has taken the PSN  login and password reset page down for maintenance. Even though Sony says PSN login page is down for maintenance   to improve the password reset process. Nyleveia says “system went down approximately 15 minutes after I received a response from SCEE [Sony Computer Entertainment Europe] on the matter.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/sony-psn-hit-by-new-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability in Android has put 99% android handsets at Risk</title>
		<link>http://www.clubhack.com/vulnerability-in-android-has-put-99-android-handsets-at-risk/</link>
		<comments>http://www.clubhack.com/vulnerability-in-android-has-put-99-android-handsets-at-risk/#comments</comments>
		<pubDate>Thu, 19 May 2011 06:07:41 +0000</pubDate>
		<dc:creator>Amey Anekar</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[FireSheep]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Session hijacking]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1219</guid>
		<description><![CDATA[This risk pertains to using your Android to connect to Facebook, Twitter and some Google services over unencrypted wireless networks. The apps for this services communicate over clear text which can intercepted by an eavesdropper. Google services which are vulnerable to eavesdropping are Google Calendar and Google Contacts. The attack is possible to all Google [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 155px"><a href="http://en.wikipedia.org/wiki/File:Android-logo.jpg"><img title="Android robot logo." src="http://upload.wikimedia.org/wikipedia/en/a/a5/Android-logo.jpg" alt="Android robot logo." width="145" height="160" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>This risk pertains to using your Android to connect to Facebook, Twitter  and some <a class="zem_slink" title="List of Google products" rel="wikipedia" href="http://en.wikipedia.org/wiki/List_of_Google_products">Google services</a> over unencrypted wireless networks. The apps  for this services communicate over clear text which can intercepted by  an eavesdropper. Google services which are vulnerable to eavesdropping  are <a class="zem_slink" title="Google Calendar" rel="homepage" href="http://google.com/calendar">Google Calendar</a> and Google Contacts. The attack is possible to all  Google services using the ClientLogin authentication protocol for access  to its data APIs.</p>
<p><a href="http://code.google.com/apis/accounts/docs/AuthForInstalledApps.html">ClientLogin</a> is meant to be used for authentication by installed applications and  <a class="zem_slink" title="Android" rel="homepage" href="http://code.google.com/android/">Android apps</a>. Basically, to use ClientLogin, an application needs to  request an authentication token (authToken) from the Google service by  passing an account name and password via a https connection. The  returned authToken can be used for any subsequent request to the service  API and is valid for a maximum duration of 2 weeks. However, if this  authToken is used in requests send over unencrypted http, an adversary  can easily sniff the authToken (e.g. with <a class="zem_slink" title="Wireshark" rel="homepage" href="http://www.wireshark.org/">Wireshark</a>). Because the authToken is not bound to any session or device  specific information the adversary  can subsequently use the captured  authToken to access any personal data which is made available through  the service API. For instance, the adversary can gain full access to the  calendar, contacts information, or private web albums of the respective  Google user. This means that the adversary can view, modify or delete  any contacts, calendar events, or private pictures.<br />
What can the attacker do?<br />
The attack is similar to session stealing(<a class="zem_slink" title="Session hijacking" rel="wikipedia" href="http://en.wikipedia.org/wiki/Session_hijacking">Sidejacking</a>). It is similar to what <a class="zem_slink" title="Firesheep" rel="homepage" href="http://codebutler.com/firesheep?c=1">FireSheep</a> had done.<br />
The attacker can setup a rogue access point and get the victims to  connect through his access point. The attacker can then attempt to  impersonate the users and modify the information stored in their  accounts</p>
<p>Google has released a patch to solve the ClientLogin protocol problem, but the patch only works for Android 2.3.4 and Android 3.0, meaning that about 99 percent of Android phones don’t have access to the updated code !!!!</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=cd32208f-4f50-4a67-9b43-466a2a34ba68" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/vulnerability-in-android-has-put-99-android-handsets-at-risk/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Facebook Scam:WTF I can&#8217;t believe you&#8217;re in this vid</title>
		<link>http://www.clubhack.com/facebook-scamwtf-i-cant-believe-youre-in-this-vid/</link>
		<comments>http://www.clubhack.com/facebook-scamwtf-i-cant-believe-youre-in-this-vid/#comments</comments>
		<pubDate>Mon, 16 May 2011 09:14:46 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[online scams]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1195</guid>
		<description><![CDATA[If you happen to get a new wall post from your friend saying &#8220;WTF &#60;yourname&#62; I can&#8217;t believe you&#8217;re in this vid&#8221; or &#8220;ROFL &#60;yourname&#62; i cant believe youre tagged in this video&#8221; Its a new scam spreading on Facebook. Don&#8217;t open or click on this link else it will be posted to all your [...]]]></description>
				<content:encoded><![CDATA[<p>If you happen to get a new wall post from your friend saying</p>
<p>&#8220;WTF &lt;yourname&gt; I can&#8217;t believe you&#8217;re in this vid&#8221; or<br />
&#8220;ROFL &lt;yourname&gt; i cant believe youre tagged in this video&#8221;</p>
<div id="attachment_1196" class="wp-caption aligncenter" style="width: 310px"><a href="http://clubhack.com/wp-content/uploads/2011/05/FB_videoscam.png"><img class="size-medium wp-image-1196 " src="http://clubhack.com/wp-content/uploads/2011/05/FB_videoscam-300x157.png" alt="" width="300" height="157" /></a><p class="wp-caption-text">Sample Wall Post</p></div>
<div class="mceTemp mceIEcenter">
<dl> </dl>
</div>
<p>Its a new scam spreading on <a class="zem_slink" title="Facebook" rel="wikipedia" href="http://en.wikipedia.org/wiki/Facebook">Facebook</a>. Don&#8217;t open or click on this link else it will be posted to all your friends wall, esp. copy any URL [java-script code]  and paste in your browser navigation/location bar to help spread the message to all your friends.</p>
<p>Most importantly for the user who fall into such <a class="zem_slink" title="Confidence trick" rel="wikipedia" href="http://en.wikipedia.org/wiki/Confidence_trick">scams</a> by clicking the link in impulse. Remember Facebook <a class="zem_slink" title="Application programming interface" rel="wikipedia" href="http://en.wikipedia.org/wiki/Application_programming_interface">API</a> doesn’t provide data about  if your friend are present in a video or which user has  been visiting your profile.</p>
<p>If you are  already hit by this scam, delete all related wall posts  from your profile, change your password and update your  friends about the scam or share this link on Facebook.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/facebook-scamwtf-i-cant-believe-youre-in-this-vid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony PlayStation Network Breached</title>
		<link>http://www.clubhack.com/sony-playstation-network-breached/</link>
		<comments>http://www.clubhack.com/sony-playstation-network-breached/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 13:20:44 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[PlayStation 3]]></category>
		<category><![CDATA[PlayStation Network]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1159</guid>
		<description><![CDATA[After a week&#8217;s shut down of PlayStation Network (PSN); Sony has publicly admitted that its 77 million users data has been compromised which includes names addresses date of birth email passwords or possibly users credit card details. If you are a PSN user check your account statement, monitor credit reports and if you still have [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em;">
<div class="wp-caption alignright" style="width: 196px"><a href="http://en.wikipedia.org/wiki/File:Ps_store_logo.png"><img src="http://upload.wikimedia.org/wikipedia/en/e/e2/Ps_store_logo.png" alt="PlayStation Store" width="186" height="213" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>After a week&#8217;s shut down of PlayStation Network (PSN); <a class="zem_slink" title="Sony" rel="homepage" href="http://www.sony.com">Sony</a> has publicly admitted that its 77 million users data  has been compromised which includes</p>
<ul>
<li>names</li>
<li>addresses</li>
<li>date of birth</li>
<li>email</li>
<li>passwords</li>
<li>or possibly users credit card details.</li>
</ul>
<p style="text-align: justify;">If you are a PSN user check your account statement, monitor credit reports and if you still have queries read the SONY <a href="http://faq.en.playstation.com/cgi-bin/scee_gb.cfg/php/enduser/std_adp.php?locale=en_GB&amp;p_faqid=5593">outage FAQ</a> for more details.</p>
<p style="text-align: justify;">PSN is  online network that connects <a class="zem_slink" title="PlayStation 3" rel="wikipedia" href="http://en.wikipedia.org/wiki/PlayStation_3">PlayStation 3</a> devices to the   Internet and Sony <span class="zem_slink">cloud services</span>. PS3 owners use  PSN to  download  games, buy/rent movies from the PlayStation  Store, and to relish  multilayer  gaming across the world with PS3 users. Since <a class="zem_slink" title="PlayStation Network" rel="wikipedia" href="http://en.wikipedia.org/wiki/PlayStation_Network">PSN network</a> is  down users have no option except playing single-player mode. Sony says it expects to restore some services within a week.</p>
<p style="text-align: justify;">As quoted in <a href="http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/">Sony Playstation Blog</a>:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p style="padding-left: 30px;">We have discovered that between April 17 and April 19, 2011, certain  PlayStation Network and Qriocity service user account information was  compromised in connection with an illegal and unauthorized intrusion  into our network. In response to this intrusion, we have:</p>
<blockquote>
<ol>
<li>Temporarily turned off PlayStation Network and Qriocity services;</li>
<li>Engaged an outside, recognized security firm to conduct a full and complete investigation into what happened; and</li>
<li>Quickly taken steps to enhance security and strengthen our network  infrastructure by re-building our system to provide you with greater  protection of your personal information.</li>
</ol>
</blockquote>
<p style="padding-left: 30px;">We greatly appreciate your patience, understanding and goodwill as we  do whatever it takes to resolve these issues as quickly and efficiently  as practicable.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>[UPDATE]</p>
<p>@hdmoore tweeted the link to actual mail sent to Playstation customers affected by the recent Sony breach</p>
<p><a href="http://pastie.org/1842067">http://pastie.org/1842067</a><br />
<script src="http://pastie.org/1842067.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/sony-playstation-network-breached/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Top10 Tools and Tactics</title>
		<link>http://www.clubhack.com/owasp-top10-tools-and-tactics/</link>
		<comments>http://www.clubhack.com/owasp-top10-tools-and-tactics/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 16:43:46 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1121</guid>
		<description><![CDATA[Around a month back Infosec Resources compiled a post with nice set of tools and tactics to exploit OWASP top 10 vulnerabilities Following is a risk and tool matrix. RISK TOOL A1: Injection SQL Inject Me A2: Cross-Site Scripting (XSS) ZAP A3: Broken Authentication and Session Management HackBar A4: Insecure Direct Object References Burp A5: Cross-Site [...]]]></description>
				<content:encoded><![CDATA[<p>Around a month back <a href="http://infosecinstitute.com">Infosec Resources</a> compiled a post with nice set of tools and tactics to exploit <a class="zem_slink" title="OWASP" rel="wikipedia" href="http://en.wikipedia.org/wiki/OWASP">OWASP</a> top 10 vulnerabilities</p>
<hr />
<p>Following is a risk and tool matrix.</p>
<table border="0" cellpadding="2" width="600">
<tbody>
<tr>
<td bgcolor="#009933"><strong>RISK</strong></td>
<td bgcolor="#009933"><strong>TOOL</strong></td>
</tr>
<tr>
<td width="382"><strong>A1: Injection</strong></td>
<td width="204"><strong>SQL Inject Me</strong></td>
</tr>
<tr>
<td><strong>A2: <a class="zem_slink" title="Cross-site scripting" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">Cross-Site Scripting</a> (XSS)</strong></td>
<td><strong>ZAP</strong></td>
</tr>
<tr>
<td><strong>A3: Broken Authentication and Session Management</strong></td>
<td><strong>HackBar</strong></td>
</tr>
<tr>
<td><strong>A4: Insecure Direct Object References</strong></td>
<td><strong>Burp</strong></td>
</tr>
<tr>
<td><strong>A5: <a class="zem_slink" title="Cross-site request forgery" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_request_forgery">Cross-Site Request Forgery</a> (CSRF)</strong></td>
<td><strong>Tamper Data</strong></td>
</tr>
<tr>
<td><strong>A6: Security Misconfiguration</strong></td>
<td><strong>Watobo</strong></td>
</tr>
<tr>
<td><strong>A7: Insecure Cryptographic Storage</strong></td>
<td><strong>N/A</strong></td>
</tr>
<tr>
<td><strong>A8: Failure to Restrict URL Access</strong></td>
<td><strong>Nikto/Wikto</strong></td>
</tr>
<tr>
<td><strong>A9: Insufficient Transport Layer Protection</strong></td>
<td><strong>Calomel</strong></td>
</tr>
<tr>
<td><strong>A10: Unvalidated Redirects and Forwards</strong></td>
<td><strong>Watcher</strong></td>
</tr>
</tbody>
</table>
<hr />
<p>&nbsp;</p>
<p>The article is a good reference point for someone looking forward for <a class="zem_slink" title="Web application testing" rel="wikipedia" href="http://en.wikipedia.org/wiki/Web_application_testing">web application testing</a> on the lines of OWASP</p>
<p>Full article can be found here:</p>
<p><a href="http://resources.infosecinstitute.com/owasp-top-10-tools-and-tactics/">http://resources.infosecinstitute.com/owasp-top-10-tools-and-tactics/</a></p>
<p>&nbsp;</p>
<p>There&#8217;s another interesting article by Rakkhi Samarasekera which deals with mitigating OWASP top 10 without touching any code.</p>
<p>This might be useful for many legacy apps</p>
<p><a href="http://www.rakkhis.com/2011/03/mitigating-owasp-top-10-without-any.html">http://www.rakkhis.com/2011/03/mitigating-owasp-top-10-without-any.html</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=b1f89aed-2591-47b2-9bfd-b74e7e4156e9" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/owasp-top10-tools-and-tactics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New flash 0-day uncovered by Armorize</title>
		<link>http://www.clubhack.com/new-flash-0-day-uncovered-by-armorize/</link>
		<comments>http://www.clubhack.com/new-flash-0-day-uncovered-by-armorize/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 10:25:08 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Zero-day attack]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1111</guid>
		<description><![CDATA[Armorize, which runs cloud-based Web malware scanning service blogged about a newest Adobe flash 0-day which is being used in new drive-by download variations such as drive-by cache. &#160; WARNING:- the blog of Armorize also contains the full exploit codes to the drive-by cache example.]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 164px"><a href="http://en.wikipedia.org/wiki/File:Adobe_Flash_Player_icon.png"><img class=" " title="Adobe Flash Player Icon" src="http://upload.wikimedia.org/wikipedia/en/2/28/Adobe_Flash_Player_icon.png" alt="Adobe Flash Player Icon" width="154" height="154" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>Armorize, which runs cloud-based Web malware scanning service <a href="http://blog.armorize.com/2011/04/newest-adobe-flash-0-day-used-in-new.html">blogged </a>about a newest Adobe flash 0-day which is being used in new drive-by download variations such as drive-by cache.</p>
<p>&nbsp;</p>
<p><span style="color: #ff0000;">WARNING</span>:- the blog of Armorize also contains the full exploit codes to the drive-by cache example.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=347eaca6-496d-4597-a9dd-74cde25ed8b9" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/new-flash-0-day-uncovered-by-armorize/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patchy Tuesday</title>
		<link>http://www.clubhack.com/patchy-tuesday/</link>
		<comments>http://www.clubhack.com/patchy-tuesday/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 05:26:29 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1064</guid>
		<description><![CDATA[As Microsoft April Advance Security Bulletin Today Microsoft will be pushing huge updates and patches for multiple vulnerabilities across different versions of Microsoft Windows, Microsoft Office and Developer tools like .NET etc Total of 64 vulnerabilities will be fixed across 17 bulletins from which 9  bulletins are rated as critical. So get ready to install [...]]]></description>
				<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em;">
<div class="wp-caption alignright" style="width: 200px"><a href="http://www.crunchbase.com/product/windows"><img src="http://www.crunchbase.com/assets/images/resized/0002/1545/21545v2-max-450x450.png" alt="Image representing Windows as depicted in Crun..." width="190" height="66" /></a><p class="wp-caption-text">Image via CrunchBase</p></div>
</div>
<p>As Microsoft <a href="http://www.microsoft.com/technet/security/Bulletin/MS11-apr.mspx">April Advance Security</a> Bulletin</p>
<p>Today Microsoft will be pushing huge updates and patches for multiple vulnerabilities across different versions of Microsoft Windows, Microsoft Office and Developer tools like <a class="zem_slink" title=".NET Framework" rel="homepage" href="http://msdn.microsoft.com/netframework">.NET</a> etc</p>
<p>Total of 64 vulnerabilities will be fixed across 17 bulletins from which 9  bulletins are rated as critical.</p>
<p>So get ready to install or plan for deploying the updates and another round of reboot to secure your machines from already disclosed <a href="http://www.microsoft.com/technet/security/advisory/2501696.mspx">vulnerabilities</a></p>
<p>Hey &amp; who said <a class="zem_slink" title="Internet Explorer 6" rel="homepage" href="http://www.microsoft.com/windows/ie/ie6/default.mspx">IE6</a> is dead? I still see updates for IE6 in this Microsoft bulletin&#8230;.. <img src='http://www.clubhack.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=085ef3e5-cd51-4fd0-b6cf-544e6ab29af9" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/patchy-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
