Stop Fixing All The Things – Our BSidesLV Talk | The Risk I/O Blog

http://blog.risk.io/2013/08/stop-fixing-all-the-things-bsideslv/ Recent parer shows that it make sense to focus only on vulns that have ready exploits in metasploit and exploitdb

Stop Fixing All The Things – Our BSidesLV Talk | The Risk I/O Blog

http://blog.risk.io/2013/08/stop-fixing-all-the-things-bsideslv/ Recent parer shows that it make sense to focus only on vulns that have ready exploits in metasploit and exploitdb

Microsoft Security Advisory (2876146): Wireless PEAP-MS-CHAPv2 Authentication Could Allow Information Disclosure

http://technet.microsoft.com/en-us/security/advisory/2876146 Recent security hole in wifi authentication – fix requires a roll-out of PKI (i.e. certificate-based auth ) for all devices . (Great ?! )

Microsoft Security Advisory (2876146): Wireless PEAP-MS-CHAPv2 Authentication Could Allow Information Disclosure

http://technet.microsoft.com/en-us/security/advisory/2876146 Recent security hole in wifi authentication – fix requires a roll-out of PKI (i.e. certificate-based auth ) for all devices . (Great ?! )

Reverse Proxy Bypass - Bug in Apache mod_proxy

http://www.contextis.com/research/blog/reverseproxybypass/ It is possible for an attacker to reach internal resources in a DMZ if RewriteRule or ProxyPassMatch directives are used in mod_proxy config

Reverse Proxy Bypass - Bug in Apache mod_proxy

http://www.contextis.com/research/blog/reverseproxybypass/ It is possible for an attacker to reach internal resources in a DMZ if RewriteRule or ProxyPassMatch directives are used in mod_proxy config

Not a Guessing Game -- Paul Vixie [from ISC/Bind] on recenet DNS hole

http://www.circleid.com/posts/87143_dns_not_a_guessing_game/ do a ‘dig TXT porttest.dns-oarc.net’ . || w.out disclosing details Pau confirms that the hole exists, and that !IMPORTANT! NAT/PAT effectively netrualize UDP port randomization fix

Matasano Chargen » This New Vulnerability: Dowd’s Inhuman Flash Exploit

http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/ detalied description about Flash vuln that was used to vin a recent hack contest (where vista and mac were hacked )

D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability

http://www.securityfocus.com/bid/24560