<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>(-) HatSecurity.com &#187; vulnerability</title>
	<atom:link href="http://hatsecurity.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://hatsecurity.com</link>
	<description>../something for all Hats</description>
	<lastBuildDate>Sat, 07 Mar 2009 15:33:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Oracle to issue patch for 41 security issues</title>
		<link>http://hatsecurity.com/2009/01/12/oracle-to-issue-patch-for-41-security-issues/</link>
		<comments>http://hatsecurity.com/2009/01/12/oracle-to-issue-patch-for-41-security-issues/#comments</comments>
		<pubDate>Mon, 12 Jan 2009 16:07:27 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=250</guid>
		<description><![CDATA[Oracle is to release a patch tomorrow that fixes 41 security vulnerabilities across hundreds of its products. According to the announcement, the affected supported products are: • Oracle Database 11g, version 11.1.0.6 • Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3, 10.2.0.4 • Oracle Database 10g, version 10.1.0.5 • Oracle Database 9i Release 2, versions [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2009/01/oracle_healthcare.jpg"><img class="alignright size-full wp-image-251" title="oracle_healthcare" src="http://hatsecurity.com/wp-content/uploads/2009/01/oracle_healthcare.jpg" alt="" width="112" height="83" /></a>Oracle is to release a patch tomorrow that fixes 41 security vulnerabilities across hundreds of its products. According to the <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html" target="_blank">announcement</a>, the affected supported products are:</p>
<table class="texta" style="margin-left: 0.25in;" border="0" summary="Category I">
<tbody>
<tr>
<td>• Oracle Database 11<em>g</em>, version 11.1.0.6</td>
</tr>
<tr>
<td>• Oracle Database 10<em>g</em> Release 2, versions 10.2.0.2, 10.2.0.3,  	10.2.0.4</td>
</tr>
<tr>
<td>• Oracle Database 10<em>g</em>, version 10.1.0.5</td>
</tr>
<tr>
<td>• Oracle Database 9<em>i</em> Release 2, versions 9.2.0.8, 9.2.0.8DV</td>
</tr>
<tr>
<td>• Oracle Secure Backup version 10.2.0.2, 10.2.0.3</td>
</tr>
<tr>
<td>• Oracle Secure Backup version 10.1.0.1, 10.1.0.2, 10.1.0.3</td>
</tr>
<tr>
<td>• Oracle TimesTen In-Memory Database version 7.0.5.1.0, 7.0.5.2.0,  	7.0.5.3.0, 7.0.5.4.0</td>
</tr>
<tr>
<td>• Oracle Application Server 10<em>g</em> Release 3 (10.1.3), version  	10.1.3.3.0</td>
</tr>
<tr>
<td>• Oracle Application Server 10<em>g</em> Release 2 (10.1.2), versions  	10.1.2.2.0, 10.1.2.3.0</td>
</tr>
<tr>
<td>• Oracle Collaboration Suite 10<em>g</em>, version 10.1.2</td>
</tr>
<tr>
<td>• Oracle E-Business Suite Release 12, version 12.0.6</td>
</tr>
<tr>
<td>• Oracle E-Business Suite Release 11<em>i</em>, version 11.5.10.2</td>
</tr>
<tr>
<td>• Oracle Enterprise Manager Grid Control 10<em>g</em> Release 4, version  	10.2.0.4</td>
</tr>
<tr>
<td>• PeopleSoft Enterprise HRMS versions 8.9, 9.0 and 9.1</td>
</tr>
<tr>
<td>• JD Edwards Tools version 8.97</td>
</tr>
<tr>
<td>• Oracle WebLogic Server (formerly BEA WebLogic Server) 10.0 released  	through MP1, 10.3 GA</td>
</tr>
<tr>
<td>• Oracle WebLogic Server (formerly BEA WebLogic Server) 9.0 GA, 9.1 GA,  	9.2 released through MP3</td>
</tr>
<tr>
<td>• Oracle WebLogic Server (formerly BEA WebLogic Server) 8.1 released  	through SP6</td>
</tr>
<tr>
<td>• Oracle WebLogic Server (formerly BEA WebLogic Server) 7.0 released  	through SP7</td>
</tr>
<tr>
<td>• Oracle WebLogic Portal (formerly BEA WebLogic Portal) 10.0 released  	through MP1, 10.2 GA, 10.3 GA</td>
</tr>
<tr>
<td>• Oracle WebLogic Portal (formerly BEA WebLogic Portal) 9.2 released  	through MP3</td>
</tr>
<tr>
<td>• Oracle WebLogic Portal (formerly BEA WebLogic Portal) 8.1 released  	through SP6</td>
</tr>
</tbody>
</table>
<p>This release dwarfs <a href="http://www.vnunet.com/vnunet/news/2233696/microsoft-cuts-patches" target="_blank">Microsoft&#8217;s one-patch fix</a> that affects Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2009/01/12/oracle-to-issue-patch-for-41-security-issues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogue Certification Authority certificates a reality</title>
		<link>http://hatsecurity.com/2008/12/31/rogue-certification-authority-certificates-a-reality/</link>
		<comments>http://hatsecurity.com/2008/12/31/rogue-certification-authority-certificates-a-reality/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 19:21:58 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=243</guid>
		<description><![CDATA[A team of researchers presenting yesterday at the 25th Annual Chaos Communication Congress held in Berlin,  have successfully demonstrated an attack against X.509 digital certificates signed by a trusted Certification Authority (CA) using the MD5 hashing algorithm. The attack method makes use of MD5 collision techniques which were known to exist since 2004 but demonstrated [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/12/securelock.jpg"><img class="alignright size-full wp-image-244" title="securelock" src="http://hatsecurity.com/wp-content/uploads/2008/12/securelock.jpg" alt="" width="162" height="180" /></a>A <a href="http://www.win.tue.nl/hashclash/rogue-ca/" target="_blank">team of researchers</a> presenting yesterday at the <a href="http://events.ccc.de/congress/2008/" target="_blank">25th Annual Chaos Communication Congress</a> held in Berlin,  have successfully demonstrated an attack against X.509 digital certificates signed by a trusted Certification Authority (CA) using the MD5 hashing algorithm. The attack method makes use of MD5 collision techniques which were known to exist since 2004 but demonstrated in practice for the first time.</p>
<p>Read more about the details <a href="http://www.win.tue.nl/hashclash/rogue-ca/" target="_blank">here. </a></p>
<p>The discovery, however, does not post a serious security risk as the technique has not been disclosed. Furthermore, most CAs are already using at least SHA-1 for the hashing function instead of MD5. The slow mover, VeriSign, <a href="https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php" target="_blank">acknowledged</a> the attack today and confirms that all certificates issued are not vulnerable to the new attack.</p>
<p>If you are still paranoid, get hold of an <a href="http://en.wikipedia.org/wiki/Extended_Validation_Certificate" target="_blank">Extended Validation Certificate</a>.</p>
<p>Happy New Year 2009! <img src='http://hatsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><span id="more-243"></span></p>
<p>Update (January 2 &#8211; 10:30PM +4GMT) &#8211; A <a href="http://www.codefromthe70s.org/sslblacklist.aspx" target="_blank">Firefox plugin</a> has been released that warns users about certificate chains that utilize MD5 hash algorithm for the RSA signature.</p>
<p><a href="http://hatsecurity.com/wp-content/uploads/2009/01/ssl-md5-block.jpg"><img class="aligncenter size-full wp-image-248" title="ssl-md5-block" src="http://hatsecurity.com/wp-content/uploads/2009/01/ssl-md5-block.jpg" alt="" width="429" height="413" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/12/31/rogue-certification-authority-certificates-a-reality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo! fixes cross-site scripting vulnerability</title>
		<link>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/</link>
		<comments>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 23:13:28 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[cross-site scripting]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=202</guid>
		<description><![CDATA[Yahoo! has fixed a cross-site scripting vulnerability affecting the HotJobs website. The vulnerability, first reported by Netcraft allowed injection of malicious code that stole session authentication cookie of Yahoo! users and submitting them to a US-based webserver. Yahoo!&#8217;s statement found on Netcraft states: The team was made aware of this particular Cross-Site Scripting issue yesterday [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-203" title="yahoo" src="http://hatsecurity.com/wp-content/uploads/2008/10/yahoo.jpg" alt="" width="141" height="33" />Yahoo! has fixed a cross-site scripting vulnerability affecting the <a href="http://hotjobs.yahoo.com/" target="_blank">HotJobs</a> website. The vulnerability, <a href="http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html" target="_blank">first reported by Netcraft</a> allowed injection of malicious code that stole session authentication cookie of Yahoo! users and submitting them to a US-based webserver. Yahoo!&#8217;s <a href="http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html" target="_blank">statement</a> found on Netcraft states:</p>
<blockquote><p><em> The team was made aware of this particular Cross-Site Scripting issue yesterday morning (Sunday, Oct. 26) and a fix was deployed within a matter of hours. Yahoo! appreciates Netcraft&#8217;s assistance in identifying this issue.</em></p>
<p><em> As a safety precaution, we recommend users change their passwords, should they still be concerned. Users should always verify via their Sign-in Seal that they are giving their passwords to Yahoo.com.</em></p></blockquote>
<p>The session authentication cookies could have been used for accessing Yahoo! services such as Yahoo! Mail and Yahoo! HotJobs amongst others.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google&#8217;s Chrome under fire</title>
		<link>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/</link>
		<comments>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 07:30:46 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=156</guid>
		<description><![CDATA[The new JavaScript speed king, Google Chrome web browser is getting hammered by security researchers over security vulnerabilities ranging from crashing the browser to potentially running malicious code on the user&#8217;s computer.  Here&#8217;s a quick round-up of what I have come across so far: 1. &#8220;Carpet bomb&#8221; &#8211; September 3, 2008. Security researcher Aviv Raff [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/09/google-chrome.jpg"><img class="alignright size-full wp-image-157" title="google-chrome" src="http://hatsecurity.com/wp-content/uploads/2008/09/google-chrome.jpg" alt="" width="150" height="55" /></a>The new JavaScript <a href="http://news.cnet.com/8301-1001_3-10030888-92.html" target="_blank">speed king</a>, Google Chrome web browser is getting hammered by security researchers over security vulnerabilities ranging from crashing the browser to potentially running malicious code on the user&#8217;s computer.  Here&#8217;s a quick round-up of what I have come across so far:</p>
<p>1. <strong>&#8220;Carpet bomb&#8221; &#8211; September 3, 2008</strong>. Security researcher <a href="http://aviv.raffon.net/" target="_blank">Aviv Raff</a> managed to discover this vulnerability hours after the browser was released. The vulnerability, when exploited could litter the user&#8217;s download directory with numerous irrelevant files or could potentially be used to exploit other vulnerabilities that may exist on the user&#8217;s machine.</p>
<p><span id="articleBody">Raff describes on his <a href="http://aviv.raffon.net/2008/09/03/GoogleMule.aspx" target="_blank">site</a> how a specially-crafted java archive file (JAR), combined with a social engineering ploy could trick a user in to downloading and executing the file without any warning from the browser.</span></p>
<p>The vulnerability comes from Google&#8217;s use of an outdated version of <a href="http://webkit.org/" target="_blank">WebKit</a>, the open source browser engine toolkit used also by Apple&#8217;s Safari browser. The WebKit version used in Chrome is the same used in Safari 3.1, which had its own set of vulnerabilities.</p>
<p><strong>2. URL Handler Crash &#8211; September 3, 2008. </strong><a href="http://evilfingers.com/advisory/google_chrome_poc.php" target="_blank">Rishi Narang</a> discovered an issue in Chrome that can crash Chrome altogether when the user visits a specially-crafted URL, throwing the following (<strong>G</strong>)message:</p>
<blockquote><p>Whoa! Google Chrome has crashed. Restart now?</p></blockquote>
<p><span id="more-156"></span></p>
<p><strong>3. &#8216;SaveAs&#8217; Buffer Overflow &#8211; September 5, 2008. </strong><a href="http://security.bkis.vn/?p=119" target="_blank">SVRT-Bkis</a>, a security team from Vietnam discovered this vulnerability that can allow an attacker to take control of the user&#8217;s computer.</p>
<p>The vulnerability lies in the &#8220;Save page as&#8230;&#8221; function which causes a buffer overflow when saving pages with very long page titles.  This aids the attackers to execute arbitrary code on users’ systems.</p>
<p>As of this writing, Google has patched this vulnerability.</p>
<p><strong>4. &#8220;Tool tip&#8221; DoS &#8211; September 8, 2008. </strong><em>Exodus</em><strong> </strong>of BlackHat Security (Israel) has <a href="http://www.blackhat.org.il/index.php/ready-set-chrome/" target="_blank">discovered</a> that a large object title can crash Chrome. This works on the current version of Chrome (0.2.149.29 Built 1798). The PoC is <a href="http://www.blackhat.org.il/exploits/chrome-freeze-exploit.html" target="_blank">here.</a></p>
<p><em>Update: Click <a href="http://code.google.com/p/chromium/issues/list" target="_blank">here</a> for an updated list of all publicly tracked Chrome issues.<br />
</em></p>
<pre><em>Article updated - October 01 - 3PM +4GMT</em></pre>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
