<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; vulnerability</title> <atom:link href="http://m32consulting.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>phpMyAdmin Exploit Used To Launch New SSH Brute-Force Attack</title><link>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack</link> <comments>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/#comments</comments> <pubDate>Fri, 13 Aug 2010 01:55:13 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[dd.txt]]></category> <category><![CDATA[dd_ssh vmsplice.txt]]></category> <category><![CDATA[phpmyadmin]]></category> <category><![CDATA[ssh]]></category> <category><![CDATA[vm.c]]></category> <category><![CDATA[vmsplice]]></category> <category><![CDATA[vulnerability]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=160</guid> <description><![CDATA[An older vulnerability in phpMyAdmin (CVE-2009-1151) is now being exploited by a botnet known as dd_ssh. Details are still emerging, but it appears that this new bot originated from 91.193.157.206 according to SANS. If the exploit of CVE-2009-1151 is successful on vulnerable phpMyAdmin installs, the files vmsplice.txt, dd.txt, and, in some instances, vm.c are downloaded from the aforementioned IP. The last [...]]]></description> <content:encoded><![CDATA[<p>An <a
title="Debian security bulletin" href="http://www.debian.org/security/2010/dsa-2034" target="_blank">older vulnerability in phpMyAdmin</a> (<a
href="http://www.securityfocus.com/bid/34236/info" target="_blank">CVE-2009-1151</a>) is now being exploited by a botnet known as dd_ssh. Details are still emerging, but it appears that this new bot originated from 91.193.157.206 according to SANS. If the exploit of CVE-2009-1151 is successful on vulnerable phpMyAdmin installs, the files vmsplice.txt, dd.txt, and, in some instances, vm.c are downloaded from the aforementioned IP. The last of those files mentioned contains the vmsplice local root exploit (<a
title="NVD CVE2008-0600" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0600" target="_blank">CVE2008-0600</a>). After being compromised, the infected installations start making connections to multiple addresses on ports 54509 and 54510; most likely for command &amp; control. SANS ISC is actively monitoring this apparent new botnet and has noticed a notable up-tick in machines scanning SSH lately.</p><p><a
href="http://isc.sans.edu/diary.html?storyid=9370" target="_blank">More Info Over at SANS ISC</a> and thanks goes to <a
href="http://www.dslreports.com/forum/r24640843-Botnet-Trend-phpMyAdmin-SSH-Attacks" target="_blank">Briareos over at BroadBand Reports for the quick fact-finding</a> and possible discovery.</p><p><a
href="http://support.f5.com/kb/en-us/solutions/public/11000/700/sol11719.html" target="_blank">June Security Advisory posted by F5 on identifying any suspicious activity and mitigating the exploit</a></p>Tags: <a
href="http://m32consulting.com/tag/dd-txt/" title="dd.txt" rel="tag">dd.txt</a>, <a
href="http://m32consulting.com/tag/dd_ssh-vmsplice-txt/" title="dd_ssh vmsplice.txt" rel="tag">dd_ssh vmsplice.txt</a>, <a
href="http://m32consulting.com/tag/phpmyadmin/" title="phpmyadmin" rel="tag">phpmyadmin</a>, <a
href="http://m32consulting.com/tag/ssh/" title="ssh" rel="tag">ssh</a>, <a
href="http://m32consulting.com/tag/vm-c/" title="vm.c" rel="tag">vm.c</a>, <a
href="http://m32consulting.com/tag/vmsplice/" title="vmsplice" rel="tag">vmsplice</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Critical Microsoft Vista/2008/Windows 7 Zero-day Remote BSOD Found</title><link>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found</link> <comments>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/#comments</comments> <pubDate>Wed, 09 Sep 2009 00:24:06 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[ampersand]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[blue screen of death]]></category> <category><![CDATA[BSOD]]></category> <category><![CDATA[Laurent Gaffié]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft vista]]></category> <category><![CDATA[microsoft windows vista]]></category> <category><![CDATA[OOB]]></category> <category><![CDATA[process id]]></category> <category><![CDATA[proof of concept]]></category> <category><![CDATA[SMB]]></category> <category><![CDATA[throwback]]></category> <category><![CDATA[versions of windows vista]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[zero day]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=41</guid> <description><![CDATA[Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down [...]]]></description> <content:encoded><![CDATA[<p>Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down with a simple ampersand. Leave it up to Microsoft to do it all again more than a decade later.</p><p>The SMB 2.0 driver in x86 and x64 versions of Windows Vista, Server 2008, and Windows 7 are all one in the same. When sent the &#8220;&amp;&#8221; character in the &#8220;Process ID High&#8221; SMB header, the process pagefaults and brings us the beloved Blue Screen of Death we&#8217;ve all come to know and love.</p><p><a
href="http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html" target="_blank">Credit goes to Laurent Gaffié and you can find the Proof-of-Concept on his blog.</a></p>Tags: <a
href="http://m32consulting.com/tag/ampersand/" title="ampersand" rel="tag">ampersand</a>, <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a
href="http://m32consulting.com/tag/blue-screen-of-death/" title="blue screen of death" rel="tag">blue screen of death</a>, <a
href="http://m32consulting.com/tag/bsod/" title="BSOD" rel="tag">BSOD</a>, <a
href="http://m32consulting.com/tag/laurent-gaffie/" title="Laurent Gaffié" rel="tag">Laurent Gaffié</a>, <a
href="http://m32consulting.com/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a
href="http://m32consulting.com/tag/microsoft-vista/" title="microsoft vista" rel="tag">microsoft vista</a>, <a
href="http://m32consulting.com/tag/microsoft-windows-vista/" title="microsoft windows vista" rel="tag">microsoft windows vista</a>, <a
href="http://m32consulting.com/tag/oob/" title="OOB" rel="tag">OOB</a>, <a
href="http://m32consulting.com/tag/process-id/" title="process id" rel="tag">process id</a>, <a
href="http://m32consulting.com/tag/proof-of-concept/" title="proof of concept" rel="tag">proof of concept</a>, <a
href="http://m32consulting.com/tag/smb/" title="SMB" rel="tag">SMB</a>, <a
href="http://m32consulting.com/tag/throwback/" title="throwback" rel="tag">throwback</a>, <a
href="http://m32consulting.com/tag/versions-of-windows-vista/" title="versions of windows vista" rel="tag">versions of windows vista</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a
href="http://m32consulting.com/tag/zero-day/" title="zero day" rel="tag">zero day</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>About</title><link>http://m32consulting.com/about/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=about</link> <comments>http://m32consulting.com/about/#comments</comments> <pubDate>Fri, 11 Jul 2008 02:29:56 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[auditing]]></category> <category><![CDATA[consulting]]></category> <category><![CDATA[cryptology]]></category> <category><![CDATA[exploits]]></category> <category><![CDATA[firewall]]></category> <category><![CDATA[firewalls]]></category> <category><![CDATA[hacking]]></category> <category><![CDATA[infosec]]></category> <category><![CDATA[infosec news]]></category> <category><![CDATA[kyle jones]]></category> <category><![CDATA[m32]]></category> <category><![CDATA[netsec]]></category> <category><![CDATA[network security]]></category> <category><![CDATA[nist]]></category> <category><![CDATA[security news]]></category> <category><![CDATA[VPN]]></category> <category><![CDATA[vulnerability]]></category><guid
isPermaLink="false">http://m32consulting.com/?page_id=2</guid> <description><![CDATA[My name is Kyle Jones, M32 Security is my collection of noteworthy IT and Network Security news, links, resources, and various other NetSec tidbits. If you find something interesting, feel free to register and make a comment on it or contact me. Tags: auditing, consulting, cryptology, exploits, firewall, firewalls, hacking, infosec, infosec news, kyle jones, [...]]]></description> <content:encoded><![CDATA[<p>My name is Kyle Jones, M32 Security is my collection of noteworthy IT and Network Security news, links, resources, and various other NetSec tidbits. If you find something interesting, feel free to register and make a comment on it or contact me.</p> [contact-form-7]Tags: <a
href="http://m32consulting.com/tag/auditing/" title="auditing" rel="tag">auditing</a>, <a
href="http://m32consulting.com/tag/consulting/" title="consulting" rel="tag">consulting</a>, <a
href="http://m32consulting.com/tag/cryptology/" title="cryptology" rel="tag">cryptology</a>, <a
href="http://m32consulting.com/tag/exploits-2/" title="exploits" rel="tag">exploits</a>, <a
href="http://m32consulting.com/tag/firewall/" title="firewall" rel="tag">firewall</a>, <a
href="http://m32consulting.com/tag/firewalls-2/" title="firewalls" rel="tag">firewalls</a>, <a
href="http://m32consulting.com/tag/hacking-2/" title="hacking" rel="tag">hacking</a>, <a
href="http://m32consulting.com/tag/infosec/" title="infosec" rel="tag">infosec</a>, <a
href="http://m32consulting.com/tag/infosec-news/" title="infosec news" rel="tag">infosec news</a>, <a
href="http://m32consulting.com/tag/kyle-jones/" title="kyle jones" rel="tag">kyle jones</a>, <a
href="http://m32consulting.com/tag/m32/" title="m32" rel="tag">m32</a>, <a
href="http://m32consulting.com/tag/netsec/" title="netsec" rel="tag">netsec</a>, <a
href="http://m32consulting.com/tag/network-security/" title="network security" rel="tag">network security</a>, <a
href="http://m32consulting.com/tag/nist/" title="nist" rel="tag">nist</a>, <a
href="http://m32consulting.com/tag/security-news/" title="security news" rel="tag">security news</a>, <a
href="http://m32consulting.com/tag/vpn/" title="VPN" rel="tag">VPN</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/about/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 10/28 queries in 0.115 seconds using disk: basic
Object Caching 1781/1838 objects using disk: basic

Served from: m32consulting.com @ 2012-02-05 20:15:10 -->
