
Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- Apple plugs gaping QuickTime security holes
- Apple plugs gaping QuickTime security holesThis is clearly Microsofts problemThey should never have bailed out Apple.Good thing....OSX is not Susceptible. Only Windows users should update. No one in the world could ever use these against a Mac, its just impossible. RE: Apple plugs gaping QuickTime security holesWhere's...
- Tags: Apple Mac OS X, Digital music, Digital media, Java, security, OSX, Apple Inc., Apple QuickTime
- Discussion threads 2009-06-01
- Apple plugs gaping QuickTime security holes
- Apple today released QuickTime 7.6.2 with fixes for a variety of security vulnerabilities, some of which could lead to arbitrary code execution attacks. The update, available for Mac OS X, Windows XP and Windows Vista, covers a total of 10 documented vulnerabilities that could be exploited via...
- Tags: Security, Apple QuickTime, Movie, Apple Inc., Arbitrary Code Execution, Buffer-overflow, Application Termination, Digital Music, Digital Media, Personal Technology, Consumer Electronics, Ryan Naraine
- Blog posts 2009-06-01
- Steps Involved in Exploiting a Buffer Overflow Vulnerability Using a SEH Handler
- This paper uses buffer overflow vulnerability in an application to overwrite the SEH handler. This paper will outline all the steps necessary to exploit such vulnerability, from detecting the point of buffer overflow in the application, to writing an exploit. The exploit uses an Activex control (XXXXX.dll) having buffer overflow...
- Tags: Buffer-overflow Vulnerability, Buffer-overflow, Viruses And Worms, Security
- White papers 2009-03-17
- Competitors for the next hash standard found to have security-related coding flaws
- As further proof that no one is immune to making mistakes, two of the algorithms competing to be the next hash standard were found to contain buffer overflows. The government board in charge of nominating standard cryptographic algorithms, NIST, has been holding a competition to choose the...
- Tags: Algorithm, Flaw, Buffer-overflow, Engineering, Security, Viruses And Worms, Adam O'Donnell
- Blog posts 2009-02-23
- Firefox tops list of 12 most vulnerable apps
- Mozilla's flagship Firefox browser has earned the dubious title of the most vulnerable software program running on the Windows platform. According to application whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed...
- Tags: Mozilla Firefox, Attacker, Vulnerability, JRE, Arbitrary Code Execution, Buffer-overflow, Security, Viruses And Worms, Ryan Naraine
- Blog posts 2008-12-15
- Apple fixes 12 Safari security flaws
- Apple has release Safari 3.2 to fix at least a dozen security flaws, some very serious. The update, available for Windows XP, Windows Vista and Mac OS X Tiger and Leopard, address vulnerabilities that could be exploited to take full control of a compromised machine. ...
- Tags: Apple Safari, Apple Inc., Arbitrary Code Execution, Buffer-overflow, TIFF, Application Termination, Security, Viruses And Worms, Ryan Naraine
- Blog posts 2008-11-13
- 'Highly critical' vulnerabilities in VLC media player
- A pair of "highly critical" vulnerabilities in the cross-platform VLC Media Player could put millions of users at risk of remote code execution attacks, according to a warning from security researchers. The issues, reported in versions 0.5.0 through 0.9.5, could let hackers take complete control of compromised...
- Tags: Vulnerability, Buffer-overflow, Media Player, Media Players, Security, Digital Music, Digital Media, Viruses And Worms, Consumer Electronics, Personal Technology, Ryan Naraine
- Blog posts 2008-11-07
- Remote buffer overflow bug bites Linux Kernel
- Remote buffer overflow bug bites Linux KernelSo it ISN'T a kernel bugit's a kernel DRIVER bug. That's akin to a bad video driver in Windows.This is not a Linux problem, it's an NDISWRAPPER problem.You should correct the first line of this article, which reads: "A remote buffer overflow vulnerability...
- Tags: OPEN SOURCE, UNIX, Operating systems, LOL!!, Linux, Linux kernel, buffer-overflow bug, buffer-overflow
- Discussion threads 2008-11-05
- Remote buffer overflow bug bites Linux Kernel
- A remote buffer overflow vulnerability in the Linux Kernel could be exploited by attackers to execute code or cripple affected systems, according to a Gentoo bug report that just became public. The flaw could allow malicious hackers to launch arbitrary code with kernel-level privileges. This could lead...
- Tags: Linux Kernel, Buffer-overflow, Wireless Network, Linux, Wi-Fi, Wireless, Security, Open Source, Operating Systems, Software, Ryan Naraine
- Blog posts 2008-11-05
- Heap-based buffer overflow reported in RealNetworks RealPlayer
- Heap-based buffer overflow reported in RealNetworks RealPlayerDefinition of PoC?Forgive my ignorance when using vulnerability speak, but what does PoC stand for? I thought at first it might mean Point of Contact, but I figured I might as well ask.RE: Black Hat webcastThe Black Hat conference organisers really should know...
- Tags: Digital music, Digital media, SECURITY, PoC, RealNetworks RealPlayer, buffer-overflow, RealNetworks Inc.
- Discussion threads 2008-07-25
- Heap-based buffer overflow reported in RealNetworks RealPlayer
- Update 07/25/2008: Aaron Portnoy of TippingPoint's security research group was kind enough to point out that I'm actually not affected by this, since I've installed the newest version of RealPlayer. From Aaron's email: Notice the Secunia advisory states it affects RealPlayer 10.5... the latest is 11.x, which now uses...
- Tags: Vulnerability, RealNetworks Inc., Buffer-overflow, RealNetworks RealPlayer, Secunia Research, Vendor, Digital Music, Digital Media, Personal Technology, Consumer Electronics, Nathan McFeters
- Blog posts 2008-07-25
- Novell GroupWise 'mailto' URI handler buffer overflow vulnerability
- Researcher Juan Pablo Lopez Yacubian has reported another URI abuse exploit. From Security Focus: Novell GroupWise is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Successfully exploiting this issue will allow an attacker to execute...
- Tags: Novell Inc., Researcher, Vulnerability, Buffer-overflow, Novell GroupWise, E-mail Servers, E-mail Clients, Groupware, Viruses And Worms, Security, Enterprise Software, Software, Nathan McFeters
- Blog posts 2008-04-29
- Black Hat Europe, Day 2: The day that wasn't and Black Hat Europe, Day 3: Begin the presentations
- If you haven't seen it yet, you can check out Day 1 of my coverage of Black Hat Europe 2008 here. So, for those of you looking forward to a Black Hat Day 2 update with some more from the training sessions... I'm afraid it didn't happen. I had...
- Tags: Black Hat, Antivirus, Buffer-overflow, Attack, Breese, Security, Viruses And Worms, Nathan McFeters
- Blog posts 2008-03-29
- Cisco patches multiple vulnerabilities in IP phones
- Cisco on Wednesday delivered patches to plug multiple overflow and denial of service vulnerabilities. In an advisory Cisco said multiple IP phone devices running the Skinny Client Control Protocol SCCP firmware were impacted. The vulnerabilities range from arbitrary code executions on a phone to forced phone reboots....
- Tags: Phone, IP Phone, Vulnerability, Patch Management, IP, Cisco Systems Inc., Firmware, Buffer-overflow, Security, Larry Dignan
- Blog posts 2008-02-14
- DefencePlus SERVER EDITION 2.20 (Windows)
- This version is made to protect your server (Apache, IIS, etc.) from being hacked or infected by buffer overflow exploitations or vulnerabilities ("exploits"). Program doesn't work under VMWare/VirtualPC emulators. Program doesn't work with Kaspersky Antivirus 5.x under WindowsNT/2000.
- Tags: Microsoft Windows, Buffer-overflow, SoftSphere Technologies, Viruses And Worms, Security
- Software downloads 2008-02-05
- DefencePlus 2.20 (Windows)
- DefencePlus (previously known as Anti-Cracker Shield) is a powerful proactive multi-level defense for an old-styled processors without NX/XD-bit on-board against hackers, viruses and Internet worms which may try to attack your computer with buffer overflow exploits. It provides a level of defense that is not covered by anti-virus or firewall...
- Tags: Microsoft Windows, Buffer-overflow, Exploit, Computer, SoftSphere Technologies, DefencePlus 2.20, Security, Viruses And Worms, Internet, Productivity, Firewalls, Networking
- Software downloads 2008-02-05
- After the hello, goodbye and thanks
- After the hello, goodbye and thanksBest of Luck!ntA modified traditional Irish blessingMay the information superhighway rise up to meet youMay the ACL be always at your backThe powerboost shine warm upon your wiresThe load balancers fall soft upon your last mileAnd until we ping againMay QoS hold your packets in...
- Tags: SECURITY, Ryan, buffer-overflow
- Discussion threads 2007-12-14
- Apple nukes QuickTime for Java, plugs more code execution holes
- Less than a week after its QuickTime media player made the top-ten list of most vulnerable Windows applications, Apple shipped QuickTime 7.3 to patch a total of at least seven vulnerabilities that could lead to code execution attacks. The update, available for both Mac and Windows (XP...
- Tags: Attacker, Apple QuickTime, Java, Movie, Apple Inc., Buffer-overflow, Application Termination, Digital Music, Digital Media, Security, Personal Technology, Consumer Electronics, Ryan Naraine
- Blog posts 2007-11-05
- Apple plugs gaping iTunes hole, doesn't tell everyone
- Apple today shipped an iTunes software refresh to add support for all its shiny new toys but, unless you're following security announcements closely, you'd never know that iTunes 7.4 contains a fix for a pretty nasty code execution vulnerability. Here's what Mac users see: ...
- Tags: Security, Apple Macintosh, Apple Inc., Buffer-overflow, Apple iTunes, Ryan Naraine
- Blog posts 2007-09-06
- Defend against format string attacks
- Printf functions and the bugs due to the misuse of them have been around for years, but in 2000, the security world became aware of a new type of security vulnerability in software that became known as format string bugs, a completely new method for exploiting programming bugs...
- Tags: String, Bug, Buffer-overflow, Attack, Syngress, Chapter Coverage, Security, Viruses And Worms, Development Tools, Software Development, Software/Web Development
- Book chapters 2007-07-06
White Papers and Webcasts