Latest YouTube Video

Wednesday, January 11, 2017

Microsoft Releases 4 Security Updates — Smallest Patch Tuesday Ever!

In Brief Microsoft has issued its first Patch Tuesday for 2017, and it's one of the smallest ever monthly patch releases for the company, with only four security updates to address vulnerabilities in its Windows operating system as well as Adobe Flash Player. Meanwhile, Adobe has also released patches for more than three dozen security vulnerabilities in its Flash Player and Acrobat/Reader


from The Hacker News http://ift.tt/2if5Fj3
via IFTTT

I have a new follower on Twitter


Michal Davídek
| Software Engineer & Developer | Clean code Enthusiast | #Java | #Groovy | #SpringFramework | Football player | Father of two |
Sedlec-Prčice, Česká republika
https://t.co/jZ54sQbh51
Following: 5234 - Followers: 5715

January 11, 2017 at 02:15AM via Twitter http://twitter.com/mikealdo007

Re: [FD] [oss-security] Docker 1.12.6 - Security Advisory

[FD] CSRF/XSS in Responsive Poll allows unauthenticated attackers to do almost anything an admin can (WordPress plugin)

Details ================ Software: Responsive Poll Version: 1.6.4,1.7.4 Homepage: http://ift.tt/1lBBtLp Advisory report: http://ift.tt/2j6d0G3 CVE: Awaiting assignment CVSS: 5.8 (Medium; AV:N/AC:M/Au:N/C:P/I:P/A:N) Description ================ CSRF/XSS in Responsive Poll allows unauthenticated attackers to do almost anything an admin can Vulnerability ================ This plugin lacks CSRF checks when updating polls meaning an unauthenticated attacker can cause anything to be modified in a poll. The plugin also fails to escape values put into HTML. The combination of these two means that an unauthenticated attacker can put arbitrary JavaScript into a page in /wp-admin/. Proof of concept ================ Create a poll. We assume that the ID of this poll will be 1. Visit the following page and click submit (in a real attack the form can be submitted without user interaction):
Then visit http://localhost/wp-admin/admin.php?page=polls&action=edit&edit_poll=1 and focus the Question field (either via clicking on it or tabbing to it). Mitigations ================ Disable the plugin until a new version is released that fixes this bug. Disclosure policy ================ dxw believes in responsible disclosure. Your attention is drawn to our disclosure policy: http://ift.tt/1B6NWzd Please contact us on security@dxw.com to acknowledge this report if you received it via a third party (for example, plugins@wordpress.org) as they generally cannot communicate with us on your behalf. This vulnerability will be published if we do not receive a response to this report with 14 days. Timeline ================ 2015-09-15: Discovered 2016-12-07: Reported to vendor via http://ift.tt/2j6l4Xj 2016-12-07: Requested CVE 2016-12-15: Vendor first replied 2017-01-10: It’s been over 30 days and the vendor has not reported the bug fixed or indicated when they expect it to be fixed 2017-01-10: Advisory published Discovered by dxw: ================ Tom Adams Please visit security.dxw.com for more information.

Source: Gmail -> IFTTT-> Blogger

Tuesday, January 10, 2017

I have a new follower on Twitter


Renascence
Music to help you Relax, 🌺 Refocus and Reset. I create custom music for your Yoga, Meditation & Wellness needs. 🎶 Spas, studios, guidance. Free downloads.
Round Rock, TX
https://t.co/mYfnMInucW
Following: 1507 - Followers: 1488

January 10, 2017 at 11:15PM via Twitter http://twitter.com/kreative66