90 likes | 432 Views
Groove Virtual Office, vulnerable activex control. Lotus Domino, vulnerable activex ... followed by 2007-009 v1.1 (safari) Apple Safari Beta 3 patches released. Apple QuickTime, ...
E N D
Patch Tuesday • 2 Patches – bugs addressed • Affecting Windows (all versions) • Other updates, MSRT, Defender Definitions, Junk Mail Filter • 2 Security Patches - 1 Critical, 1 Important • MS08-001 – IGMP - Remote Code Execution • MS08-002 – LSASS – Local Privilege Escalation • Vista Advisory 943411 – Vulnerable Sidebar Gadgets
Holes / Patches • Vmware, 2 rounds of patch releases for ESX Server • Realplayer • Mambo, multiple vulns and XSS • Groove Virtual Office, vulnerable activex control • Lotus Domino, vulnerable activex control • Thunderbird, multiple vulns • Cisco Firewall Services, DoS • Opera, multiple vulns • Adobe Flash Player, multiple vulns
Hacking • L0pht “reunion” at SOURCE Boston, Mar 2008 • Too Much Media Corp., Data Loss
Holes / Patches (more) • Clam AV, multiple vulns • Apple Patch Release 2007-009, 41 fixes • followed by 2007-009 v1.1 (safari) • Apple Safari Beta 3 patches released • Apple QuickTime, multiple vulns • Apple Java, multiple vulns (10.4) • HP Activex, brick my laptop • Paper posted to milw0rm • g
Film / Music • TruTV – Tiger Team • Chris Nickerson, Luke McOmie, and Ryan Jones
Updates • Openstego 0.3.0 • Iptables 1.4.0 • PWDumpX 14 • Chkrootkit 0.48 • Netspoc 3.1.tar.gz • BTScan • Seat 0.2 • Bluediving 0.9 • Nmbscan 1.2.5 • Paterva
CON Events • Future Cons • Shmoocon, 15 - 18 Feb / Washington DC • Black Hat DC, 18 - 21 Feb / Washington DC • InfowarCon 2008, 2 - 4 Mar / Bethesda MD • Infosec World, 10 - 12 Mar / Orlando FL • SOURCE Boston, 12 - 14 Mar / Boston MA • Black Hat Europe, 25 - 28 Mar / Amsterdam • CanSecWest 2008, 26 - 28 Mar / Vancouver BC • CarolinaCon 4, 28 - 29 Mar / Chapel Hill NC
All images scavenged without permission All images scavenged without permission