| IBM patents technique for killing fraud, using click patterns | The U.S. state of cybercrime takes another step back | |||||||||
| Network World Security | |||||||||
| TrueCrypt's abrupt demise 'puzzling, bizarre' WHITE PAPER: Silver Peak Systems Inc 2014 Gartner Magic Quadrant for WAN Optimization According to Gartner, Leaders exhibit an ability to shape the market by introducing additional capabilities in their product offerings and by raising awareness of the importance of these features. Gartner expects a Leader to grow the market as a whole and to have solutions that resonate with an increasing number of enterprises. Learn more >> In this Issue
WHITE PAPER: Fortinet Who does NSS Labs "Recommend" for NGFW? In 2012, NSS Labs found that most available NGFW solutions "fell short in performance and security effectiveness." In 2013 NSS Labs noted "marked improvement" and bestowed their "recommended" rating on 6 vendors. Click here to find out who they were. Learn more >> IBM patents technique for killing fraud, using click patterns The U.S. state of cybercrime takes another step back WHITE PAPER: Akamai Technologies, Inc. 10 Key Considerations for a Successful Online Video Strategy As video technology has become more ubiquitous, it has also become more complex. The key considerations in this guide will help you to develop a successful online video strategy with advice to deliver high-quality video, scale instantly, and ensure real-time optimizations specific to each device, operating system and user connection. Learn More New attack methods can 'brick' systems, defeat Secure Boot, researchers say Google starts accepting 'right to be forgotten' requests in Europe WHITE PAPER: HP Why you need a next-generation firewall This white paper explores the reasons for implementing NG firewalls and lays out a path to success for overburdened IT organizations. Learn More How to avoid cyberspies on Facebook, LinkedIn Companies should already know how to protect data, FTC argues Google pulls trigger, cripples some Chrome add-ons | |||||||||
SLIDESHOWS Which tech leaders received the most generous pay hikes in 2013? JOIN THE NETWORK WORLD COMMUNITIES As network pros you understand that the value of connections increase as the number of connections increase, the so called network effect, and no where is this more evident than in professional relationships. Join Network World's LinkedIn and Facebook communities to share ideas, post questions, see what your peers are working on and scout out job applicants (or maybe find your next opportunity). MOST-READ STORIES 1. How MIT and Caltech's coding breakthrough could accelerate mobile network speeds 2. Encryption canary or insecure app? TrueCrypt warning says use Microsoft's BitLocker 3. 15 hot Kickstarter tech campaigns 4. Gartner: Amazon runs away with IaaS cloud Magic Quadrant; Microsoft catching up 5. 10 things M.I.T. computer scientists have given the world 6. Hacking Windows XP to get security patches is a really bad idea 7. Microsoft baffled by fact one of its products keeps getting better 8. Sprint union with T-Mobile reportedly a done deal 9. Ballmer wins LA Clippers basketball team for $2 billion 10. The Top 11 Cities for Technology Careers | |||||||||
| Do You Tweet? You are currently subscribed to networkworld_security_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2014 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | |||||||||
Everything related to Computer Security - Security Audits, Security Vulnerabilities, Intrusion Detection, Incident Handling, Forensics and Investigation, Information Security Policies, and a whole lot more.
Search This Blog
Monday, June 02, 2014
TrueCrypt's abrupt demise 'puzzling, bizarre'
Sunday, June 01, 2014
Update Back.
Groupon Indonesia Deals Kategori Nasional Senin 02 June 2014
| Groupon harian untuk Kategori Nasional | Buka di website | Mobile version | Start your deal Tambahkan noreply@indogroupon.com ke dalam address book supaya email dapat diterima dengan baik |
| | |
| Customer Care: konsumen@indogroupon.com, SMS: 0878-0840-5008, Senin - Jumat pukul 09.00-16.00 wib Anda menerima email penawaran diskon harian dari Indogroupon karena telah mendaftar di website http://indogroupon.com. Groupon Indonesia | Penyedia Diskon Setiap Hari | Deal Kategori Nasional |
ITworld cartoons 2014: The year in geek humor
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Voicemail to UC – 10 Considerations for ROI
| If you have trouble viewing this email, read the online version. |
|
[SECURITY] [DSA 2943-1] php5 security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2943-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
June 01, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : php5
CVE ID : CVE-2014-0185 CVE-2014-0237 CVE-2014-0238 CVE-2014-2270
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development:
CVE-2014-0185
The default PHP FPM socket permission has been changed from 0666
to 0660 to mitigate a security vulnerability (CVE-2014-0185) in PHP
FPM that allowed any local user to run a PHP code under the active
user of FPM process via crafted FastCGI client.
The default Debian setup now correctly sets the listen.owner and
listen.group to www-data:www-data in default php-fpm.conf. If you
have more FPM instances or a webserver not running under www-data
user you need to adjust the configuration of FPM pools in
/etc/php5/fpm/pool.d/ so the accessing process has rights to
access the socket.
CVE-2014-0237 / CVE-2014-0238:
Denial of service in the CDF parser of the fileinfo module.
CVE-2014-2270
Denial of service in the fileinfo module.
For the stable distribution (wheezy), these problems have been fixed in
version 5.4.4-14+deb7u10.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you upgrade your php5 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJTiuQVAAoJEBDCk7bDfE42gBAQAJ3ENaQ//rk0bMIQEZmZTWpN
dKJ5MoDiA+H2nWtwbnzrYbr0xGlmDn0BX7OCJJ7orXMbmsSsrD5Ff0/C5rgjr6uy
8Ll5g1y1jab0JuHJrjf1NLnAUXp93EGFGoTGGSvKirz4vG/qVFAwCba6/GYz51+r
9bh3MiGy1x7BiO3CFrCcDMZ1MKuztwE5n0BDacqKTjDaTrsF+QO15G5ddWbnRLYi
TnN8Sv68A10ar8Zs3uj1fTPEwL7LqsXWqmZG1MYMdHElVLJOo7Xs3KVVO7xmyANE
tm5P6O9SwJl6MesjS6cxIGjIlgVMcjaRlulNavC5YnOlZ9apoAwPnrjzgo5DFrKl
OJzUm2nproMXkR2vi9DDBVOxF4awbq1FGJ9WRD58lm7L+SZC+aO8AgIth6+pqmTG
DrVaCPBZ0HfSBCGxiSXGvWiTeBhcQ2du8HsLCv+dbddDdqXJiqaeQ448Z6BDLPdv
yGcqsDiAY8hunuht+YdXqfCeDd0pJzuf/XSROHzv0PcF8JM5bGK8aKDSbjGLfVrP
yD7I/wU60zQkc896z0mQy18SSg3YmCqdi1vWQ+LMORMGIeQmlXdizkvRMHTosM5u
4Rlf5h1JBX2PanIl4oDwLICctUQh5h42w59IG7Z4DTFuDFjmFfz+1vDJIK8uOgLw
NAMfkKFHzD3pco8De480
=WobB
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20140601083803.GC5008@pisco.westfalen.local
[SECURITY] [DSA 2944-1] gnutls26 security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2944-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
June 01, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : gnutls26
CVE ID : CVE-2014-3466
Joonas Kuorilehto discovered that GNU TLS performed insufficient
validation of session IDs during TLS/SSL handshakes. A malicious server
could use this to execute arbitrary code or perform denial or service.
For the stable distribution (wheezy), this problem has been fixed in
version 2.12.20-8+deb7u2.
For the unstable distribution (sid), this problem has been fixed in
version 2.12.23-16.
We recommend that you upgrade your gnutls26 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJTiuVvAAoJEBDCk7bDfE42qk8P/3vu4mGXhGNJwK9+E1rVlJ7b
bL9M2qAo9PiNO3Saw8reZYjFhpXy4iq5E2kTpUDHhDvWWvIAzme4N4/nXgAlQGQL
umMAG9vLl33vIhllcTlGy0RqI1bx/qXqzTsuFv/3lwArWdY3T2UzeYceGfcbFNqY
H5RSP8UAN7rFWEMiqSuTNpRdmwhEPrGqLatIZ8r8Q5/jWcCAat+MNP+KERouksBT
u5U5WkImDwpiPuxWBsJdkfLhbWCazmul+dVIerNm+9FA73W85HwkMb88Xit7rVgv
0d/Obd4qP0QiyDMfAnRDwVci3H/tzYyifAwutLf+zSPRBpy84lFKorMIAKA3mO8W
4ezBtP9D8v9FHxfKGi28RV779ZLDlWY1I8yL6FTAQk0m1QFpvgiy7IclKnmfN7Ew
DOFp5KIntqL+5AnVs8aBaTByEphKHlxt6jGi142VKESz7oB/io6umtECTWfLXI9D
8sZpTqXMhCQMK4ydmgJmado+oKzH/fq21Y5PagJIntGErCRIoe45wviamJXUjGHW
ol/rhGNqrZYTsVBnqUmTURQvQc1/pHT4ZH8tEc9Cxv9ndlWkaZ7QJMY3zbNWaVf8
XcOBu9/GxuNeq32xAM0Kq4e94WtU3WB8wrDzTUl/wWwzJfV2I+nczRyL/uSCfZLk
RmrvS8guUXe3SXS0h9VX
=PIu6
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20140601083852.GD5008@pisco.westfalen.local
[SECURITY] [DSA 2942-1] typo3-src security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2942-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
Jun 01, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : typo3-src
CVE ID : not available yet
Debian Bug : 749215
Multiple security issues have been discovered in the Typo3 CMS. More
information can be found in the upstream advisory:
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
For the stable distribution (wheezy), this problem has been fixed in
version 4.5.19+dfsg1-5+wheezy3.
For the testing distribution (jessie), this problem has been fixed in
version 4.5.34+dfsg1-1.
For the unstable distribution (sid), this problem has been fixed in
version 4.5.34+dfsg1-1.
We recommend that you upgrade your typo3-src packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJTiuF5AAoJEBDCk7bDfE42MIoQAL5SSqX1aYQiokeqB11UBUMH
yWq0r6N84KjG023sNfuERimUZKEgIGWi5rZjcqAnP8OPyebizpOyJyiN5L0Lia4d
aiAvaODKJWw1YTbBDdAnXTXMr2H22AcdH/JC61mIYeg0CKVWVQepvDuxaLoS1A37
iib5dFXe34aCx0cw0PQmYMZIoBaygrKwtqMWvW9wjCbiUx0XGtkKhkXeRNjHFDYg
qYsyYyofOeHTq7qFso1kC0Kq70YDXyBaF6mXql8LU9BijyPbicPZDuwD8VwKXXhE
458kk5GUUxTLp5JBbdO6+3RWfaBHjTqm5WhMSjsPASH3fYYiFMryuTJBVnc3Rmr/
oTW2omRufDOcYeI1pfpPc3dLOfrzfxR18a5kA7HItTMZ94EzXpDFEQ7ILeWBJwtc
Vn29IFFfZ9TIbeqw9GliqS15IKD35LpcNrEvtC5A8aJd1GcqusZeI2sRz2cV6Myf
STpgcjPjVbcwuSsCqU0RIpNbnZ8mncJmSDRJXskTOlT2eR9OkWw5Iz8HEgi5UsZA
k5H1VvEwKXmFEraKAo14Fhlmxz1CdAo2Q7erE/gZMeytLWgJGkttZwTnaoABgcBj
O15ldHOOxnf+1fWQBPYwmFcdHdb2tCvSCKXNZo6FcHelLuDS9g7XMx1MSM3Fa53G
Z8Wp558yFSFCGIzVXgB/
=UWdd
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20140601083710.GB5008@pisco.westfalen.local
[SECURITY] [DSA 2941-1] lxml security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2941-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
Jun 01, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : lxml
CVE ID : CVE-2014-3146
It was discovered that clean_html() function of lxml (pythonic bindings
for the libxml2 and libxslt libraries) performed insufficient
sanitisation for some non-printable characters. This could lead to
cross-site scripting.
For the stable distribution (wheezy), this problem has been fixed in
version 2.3.2-1+deb7u1.
For the testing distribution (jessie), this problem has been fixed in
version 3.3.5-1.
For the unstable distribution (sid), this problem has been fixed in
version 3.3.5-1.
We recommend that you upgrade your lxml packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJTiuFIAAoJEBDCk7bDfE4206YP/R4EpBfyFfsdt0HMpiL06QSy
mkJLPSXcBd9WjamraFKLbF1BOuL130pljlM9gko129MXhM0lvCWcWInDjX2oRsGL
gJq+NZEUWc4nvEh4ZpxrrLMMkie8mqE6UrLJ6tu0m7wd8j7NQNX7mpsVnBOv5evr
xnoLefTI0UwaZzuEBrB6MEDwh/Yvc7vEH/47dDCHJyKhna6HpkKoiAFH7ZFLobjZ
jFcXJv+rIJjcX1qaM0n7bsrjybU7MaCAzH+RrRnZslAgGfbE5KL4PEscXtfrt70p
pK2KtQ3hCc4ErxHxWORobteij6N5S4fDi754nOEpvKAkUJS6QliochfnmGKKtn58
GafXfqkFAkftvPPfm4BMXqaN2tCvCXkNdCAH3nks+BApsL0EfIuTsu+u1F3T74K+
ih/i69uZr/bmFcDD9p2ocHgJab1JKkn1l84bgDu1QLm8xem86OGQXrczw4DdO4BI
+6IX8bqSlQ+Okcl7Y2X1wiVQ1ItkFvKQOS/4nQc/MouhubBce93VdKy24xCHAKt+
LPKRSN9788yk00P0OdnCPVuAV1Ex+C5GxPoQ9anDqsU/mdV+v4B1O2Xyw/9z61Vc
c9hMqtXjwOvJkVUPoCDn1MMurFavSo+1K/EEKv8AeZvfqnB5TMuA6sBH1eB+2NJ9
ydKRN9LmvrfDM+DV4IeM
=nIOs
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20140601083618.GA5008@pisco.westfalen.local
Thanks -- this is a major undertaking
Thanks for adding your name in support of the EPA's new carbon pollution standards. OFA will make sure every name is counted as part of the EPA's public comment period.
No matter how much climate change deniers in Congress drag their feet, the science behind climate change is conclusive -- it's already happening, and it's on all of us to fight back.
President Obama's proposed new carbon pollution standards are a huge step in the right direction -- they've been called "the strongest action ever taken by an American president to tackle climate change" -- and we've got to fight for them, because dirty special interests are going to be pushing back hard.
Everybody who cares about climate change should stand up in support of the President's aggressive action today.
You can help right now -- send this link to three friends, and ask them to add their names in support, too:
http://my.barackobama.com/Fight-Climate-Change-Now
Thanks -- more soon,
Organizing for Action
