phpbb and sql errors asp sqlserver odbc sql errors
click to see newsfeed

Newsfeed
(click to hide)

about this feed

Today´s Diary

If you have more information or corrections regarding our diary, please share.

Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html
Share |
Published: 2010-02-09,
Last Updated: 2010-02-09 00:23:31 UTC
by Adrien de Beaupre (Version: 1)
0 comment(s)

When is a 0day not a 0day? When the exploit ends up being just a poor default configuration issue. It can lead to files being read, that the user has permission to read. Like /etc/passwd for example. The solution? Set "wide links = no" in the [global] section of your smb.conf and restart smbd to eliminate this problem, from the Samba Symlink Attack posting here. Thanks Elazar!

Cheers,
Adrien de Beaupré
EWA-Canada.com

0 comment(s)

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2010-02-09Adrien de Beaupre When is a 0day not a 0day? Samba symlink bad default config
2010-02-08Adrien de Beaupre When is a 0day not a 0day? Fake OpenSSh exploit, again.
2010-02-06Guy Bruneau Oracle WebLogic Server Security Alert
2010-02-06Guy Bruneau LANDesk Management Gateway Vulnerability
2010-02-05Jim Clausing WordPress iframe injection?
2010-02-05Jim Clausing Memory Analysis - time to move beyond XP
2010-02-04Johannes Ullrich Microsoft Patch Tuesday Pre-Release
2010-02-04Mark Hofman Dealing with User 2.0
2010-02-03Rob VandenBrink APPLE-SA-2010-02-02-1 iPhone OS 3.1.3 and iPhone OS 3.1.3 for iPod touch
2010-02-03Rob VandenBrink Support for Legacy Browsers
Complete Archive
Search Diaries: