Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

SecureNinja BootCamps


Rated #1 Training

Best hacking and penetration testing  magazine in the world

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes 1827

Who's Online

There are currently, 76 guest(s) and 12 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

Security News: CERT Hacking Information
Posted on Wednesday, 30 May 2001 @ 14:57:27 EDT
Contributed by cdupuis | Topic: Vulnerabilities

Thanks to Chuck Bianco for forwarding to me the CERT information below.

The information below is published by the CERT team. I have been reading Tipton and Krause?s latest security handbook. The new handbook contains articles on hacking and virus detection in the Operations Chapter. The information below on Internet attacks compliments the new security handbook as its changes focus from traditional operations security issues to Internet based security issues.

Click on Read More below for full story.

?

-----BEGIN PGP SIGNED

?

CERT Summary CS-2001-02

?

May 29, 2001

?

Each quarter, the CERT Coordination Center (CERT/CC) issues the CERT Summary to draw attention to the types of attacks reported to our incident response team, as well as other noteworthy incident and vulnerability information. The summary includes pointers to sources of

information for dealing with the problems.

?

Past CERT summaries are available from:

?

CERT Summaries

http://www.cert.org/summaries/

?? ______________________________________________________________________

?

Recent Activity

?

Since the last regularly scheduled CERT summary, issued in February 2001 (CS-2001-01), we have seen a significant increase in reconnaissance activity, a number of self-propagating worms, and active exploitation of vulnerabilities in snmpxdmid, BIND and IIS by intruders

?

For more current information on activity being reported to the CERT/CC, please visit the CERT/CC Current Activity page. The Current Activity page is a regularly updated summary of the most frequent, high-impact types of security incidents and vulnerabilities being reported to the CERT/CC. The information on the Current Activity page is reviewed and updated as reporting trends change.

?

CERT/CC Current Activity

http://www.cert.org/current/current_activity.html

?

?

sadmind/IIS Worm

?

The CERT/CC has received reports from more than 400 sites affected by a piece of self-propagating malicious code (referred to here as the sadmind/IIS worm). This worm uses two well-known vulnerabilities to compromise Solaris systems and deface web pages running on IIS servers. Reports indicate more than 500 Solaris machines have been compromised by the sadmind/IIS worm and more than 6000 IIS servers have been defaced. Sites running either Solaris or IIS are strongly encouraged to review CA-2001-11 and those running IIS should review the advisories listed below in the "Other Recent IIS Security Issues" section as well.

?

CERT Advisory CA-2001-11: sadmind/IIS Worm

http://www.cert.org/advisories/CA-2001-11.html

?

?

Other Recent IIS Security Issues

?

The CERT/CC has recently published information on two new vulnerabilities in IIS. Given the current level of exploitation of IIS by intruders and the sadmind/IIS worm, the CERT/CC strongly encourages sites to review the following advisories and take appropriate steps to protect IIS servers.

?

Superfluous Decoding Vulnerability in IIS

?

A serious vulnerability in Microsoft IIS may allow remote intruders to execute commands on an IIS web server. This vulnerability closely resembles a previous vulnerability in IIS that was widely exploited. The CERT/CC urges IIS administrators to take action to correct this vulnerability.

?

CERT Advisory CA-2001-12: Superfluous Decoding Vulnerability in IIS

http://www.cert.org/advisories/CA-2001-12.html

?

?

Buffer Overflow Vulnerability in Microsoft IIS 5.0

?

A vulnerability exists in Microsoft IIS 5.0 running on Windows 2000 that allows a remote intruder to run arbitrary code on the victim machine, allowing them to gain complete administrative control of the machine. A proof-of-concept exploit is publicly available for this vulnerability, which increases the urgency that system administrators apply the patch.

?

CERT Advisory CA-2001-10: Buffer Overflow Vulnerability in Microsoft IIS 5.0

http://www.cert.org/advisories/CA-2001-10.html

?

Additional advice on securing IIS web servers is available from:

?

Microsoft Technet Security Tools

http://www.microsoft.com/technet/security/tools.asp

?

?

Exploitation of snmpXdmid

?

The CERT/CC has received dozens of reports indicating that a vulnerability in snmpXdmid is being actively exploited Exploitation of this vulnerability allows an intruder to gain privileged (root) access to the system.

?

CERT Advisory CA-2001-05: Exploitation of snmpXdmid

http://www.cert.org/advisories/CA-2001-05.html

?

?

Exploitation of BIND Vulnerabilities

?

On January 29, 2001, the CERT/CC published CERT Advisory CA-2001-02, detailing multiple vulnerabilities in multiple versions of ISC BIND nameserver software. Two of the vulnerabilities described in the advisory are still being actively exploited by the intruder community to compromise systems.

?

CERT Incident Note IN-2001-03: Exploitation of BIND Vulnerabilities

http://www.cert.org/incident_notes/IN-2001-03.html

?

CERT Advisory CA-2001-02: Multiple Vulnerabilities in BIND

http://www.cert.org/advisories/CA-2001-02.html

?

The "cheese" Worm

?

The CERT/CC has observed in public and private reports a recent pattern of activity surrounding probes to TCP port 10008. We have obtained an artifact called the "cheese" worm which may contribute to this pattern.

?

CERT Incident Note IN-2001-05: The "cheese" Worm

http://www.cert.org/incident_notes/IN-2001-05.html

?

Increase in Reconnaissance Activity

?

Over the past several weeks, the CERT/CC has observed a significant increase in network reconnaissance activity. While some of this traffic may be attributed to the sadmind/IIS worm or the "cheese" worm, reports indicate active scanning for known vulnerabilities in other network services as well. In addition, we have seen a significant increase in the number of generalized port scans of hosts.

?

In order to minimize exposure to this activity, the CERT/CC recommends that sites review and apply vendor-supplied security patches, disable non-critical network services, and actively monitor system and network logs for unusual activity.

?

?

Statistical Weaknesses in TCP/IP Initial Sequence Numbers

?

A new vulnerability has been identified which is present when using random increments to constantly increase TCP ISN values over time. Systems are vulnerable if they have not incorporated RFC 1948 or equivalent improvements, or do not use cryptographically secure network protocols like IPsec.

?

CERT Advisory CA-2001-09: Statistical Weaknesses in CP/IP Initial Sequence Numbers

http://www.cert.org/advisories/CA-2001-09.html

_________________________________________________________________

?

Collaboration between the CERT Coordination Center and the Internet Security Alliance

?

Using its standard process for collaborating with industry organizations, the CERT/CC, as part of the SEI, has entered into an agreement with the Electronic Industries Alliance, a not-for-profit organization in Virginia, to support the activity of the Internet Security Alliance (ISA). ISA is a member organization that is focused on the overall improvement of Internet security.

?

Internet Security Alliance

http://www.isalliance.org/

?

Frequently Asked Questions (FAQ) about the collaboration between CERT Coordination Center and the Internet Security Alliance

http://www.cert.org/faq/certcc_ISA.html

_________________________________________________________________

?

What's New and Updated

?

Since the last CERT Summary, we have published new and updated

?

Advisories

http://www.cert.org/advisories/

Incident Notes

http://www.cert.org/incident_notes/

CERT/CC Statistics

http://www.cert.org/stats/cert_stats.html

Annual Reports

http://www.cert.org/annual_rpts/

______________________________________________________________________

?

This document is available from:

http://www.cert.org/summaries/CS-2001-02.html

______________________________________________________________________

?

CERT/CC Contact Information

?

Email:?? cert@cert.org

Phone: ? +1 412-268-7090 (24-hour hotline)

Fax: ?????? +1 412-268-6989

Postal address:

CERT Coordination Center

Software Engineering Institute

Carnegie Mellon University

Pittsburgh PA 15213-3890 U.S.A.

?

CERT personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends.

?

Using encryption

?

We strongly urge you to encrypt sensitive information sent by email.

Our public PGP key is available from

?

http://www.cert.org/CERT_PGP.key

?

If you prefer to use DES, please call the CERT hotline for more information.

?

Getting security information

?

CERT publications and other security information are available from our web site

?

http://www.cert.org/

?

To subscribe to the CERT mailing list for advisories and bulletins, send email to majordomo@cert.org. Please include in the body of your message

?

subscribe cert-advisory

?

"CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.

______________________________________________________________________

?

NO WARRANTY

Any material furnished by Carnegie Mellon University and the Software Engineering Institute is furnished on an "as is" basis. Carnegie Mellon University makes no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results btained from use of the material. Carnegie Mellon University does not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement.

_________________________________________________________________

?

Conditions for use, disclaimers, and sponsorship information

?

Copyright ?2001 Carnegie Mellon University.

?

-----BEGIN PGP SIGNATURE-----

Version: PGPfreeware 5.0i for non-commercial use

Charset: noconv

?

iQCVAwUBOxQFvgYcfu8gsZJZAQGhBwQAnOGWyK2i3snaTskm3SvFycSFQCIhatKI

0+UrWPAX4oR5dYcygJwg23/QSuN2deQuLatfJSRKHW+hYKVgJlHxoBED0CPspkhx

ezU47UcqLFKk2QI3Bt3cG22i28qxjpEOZNn325MfrxJg/q2XdUFZcpqkdian5otJ

Lv+z0JyeV/M=

=I/U5

-----END PGP SIGNATURE-----

?


Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links

Article Rating

Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options


Re: (Score: 1)
by econom25 on Thursday, 03 July 2008 @ 10:03:34 EDT
(User Info | Send a Message)
fotos de bragas bombachas lenceria erotica [groups.google.nl] lace lingerie [groups.google.nl] tattoo de diablos en caricaturas [groups.google.nl] tetas gigantescas [groups.google.nl] morenas sensuales [groups.google.nl] ver desnuda a mariela zaneti [groups.google.nl] venezolanas chupando [groups.google.nl] galeria de desnudos en el df [groups.google.nl] novias infieles vids [groups.google.nl] gif animados de osos [groups.google.nl] africanas calients [groups.google.nl] los picapiedra pornos [groups.google.nl] novias infieles vids [groups.google.nl] latex sexy mpgs [groups.google.nl] 0123famosas [groups.google.nl] ww juegocom [groups.google.nl] nenas chiquitas atrevidas [groups.google.nl] nenas chiquitas atrevidas [groups.google.nl] paja cubana video gratis [groups.google.nl] video comicos de comiquitasgratis [groups.google.nl] videos vivo [groups.google.nl] fotos de chicxas sexy [groups.google.nl] gifs de eroticos [groups.google.nl] espaniola webcam pajina [groups.google.nl] escolares hot corridas [groups.google.nl] 0123famosas [groups.google.nl] paja cubana video gratis [groups.google.nl] videos vivo [groups.google.nl]



Re: (Score: 1)
by econom25 on Thursday, 03 July 2008 @ 10:39:09 EDT
(User Info | Send a Message)
videos de cexo [groups.google.nom.es] livejazmin porno video [groups.google.nom.es] descuidos de lolitas [groups.google.nom.es] club barcelona travesti [groups.google.nom.es] videos harcode [groups.google.nom.es] super braguitas dvd [groups.google.nom.es] por chat sexoo [groups.google.nom.es] petardasexso [groups.google.nom.es] ciolegialas ticas} [groups.google.nom.es] rubias bronceadas pics [groups.google.nom.es] esposa chupadora foto [groups.google.nom.es] logo sadomasoquismo [groups.google.nom.es] super culos blancos [groups.google.nom.es] fotos de bucaramanga [groups.google.nom.es] ancianos follando con [groups.google.nom.es] webcams de mujeres [groups.google.nom.es] pezones mas largos fotos [groups.google.nom.es] marihuana dibujos [groups.google.nom.es] tetas grandes rubias macizas sexooolia mamadas [groups.google.nom.es] bideos de chiapas [groups.google.nom.es] cojiendo con perros [groups.google.nom.es] descuidos de lolitas [groups.google.nom.es] fotos follando con penes pequeaos [groups.google.nom.es] fotosde jovensitas [groups.google.nom.es] videos gratis de stripti [groups.google.nom.es] porno britni [groups.google.nom.es] fotosde jovensitas [groups.google.nom.es] amateur porn sex [groups.google.nom.es]



Re: CERT Hacking Information (Score: 1)
by nikeshox on Tuesday, 04 May 2010 @ 23:19:36 EDT
(User Info | Send a Message)

  Nike shox [www.nikeshoxsales.com] [www.nikeshoxsales.com] shoe has always been the favourite of so many people, because it looks so powerful, high quality, and noblest and so on.We offer all kinds of Branded Nike shox Shoes. Everyone is different. Nike shox sale [www.nikeshoxsales.com] [www.nikeshoxsales.com] online store,We are an honest and serious supplier with many years experience.Our product is direct from company,so you can buy  cheap nike shox [www.nikeshoxsales.com] [www.nikeshoxsales.com] shoe with free shipping no tax and more discount.In my opinion, nike shox shoe is widely popular and is suitable for all kinds of people. You can find your any style from nike shox sale store such as  cheap nike shox r4 [www.nikeshoxsales.com] [www.nikeshoxsales.com] shoe. this is a good chance for you, as they are super sale off,you will save much more.




Re: CERT Hacking Information (Score: 1)
by webplu9 on Thursday, 03 June 2010 @ 20:47:32 EDT
(User Info | Send a Message)

منتديات لمسة دفا [lmst-d.com] دليل لمسة دفا [dir.lmst-d.com] عرب [arabtoc.com] دليل مواقع [max4arab.net] التحلية [a77a.com] دليل مواقع [max4arab.net] منتديات ويانا [wyana.net] شات [wll3.com] ترفيه [k-ala7sas.com] حواء [k-ala7sas.com] ولد حائل برمجه [wldhail.com] ولد حائل تسليه [wldhail.com] منتدى الود طبعي [x090x.com] توبيكات الود طبعي [x090x.com] فيديو الود طبعي [x090x.com] خواطر الود طبعي [x090x.com] موقع الود طبعي [x090x.com] الجلسة الدعوية [al-jalsa.com] منتديات الجلسة الدعوية [al-jalsa.com] بحر الشوق [b7r5.com] منتديات بحر الشوق [vb.b7r5.com] مدونات [vb.b7r5.com] دليل منتديات [b7r5.net] توبيكات ملونه [vb.b7r5.com] دردشة [chat.b7r5.com] منتديات [forums.jraaa7.com] دليل مواقع [max4arab.net] صور [pic.jraaa7.com] عنب [a3np.com] زفات [afra7.net] عالم حواء [afra7.net] زفات اسلاميه [zffat.com] دليل الافراح [dir.afra7.net] عالم المراه [fff7.com] عاشق

Read the rest of this comment...




Re: CERT Hacking Information (Score: 1)
by webplu9 on Wednesday, 23 June 2010 @ 09:05:47 EDT
(User Info | Send a Message)

<a href="http://ruoof.net/vb">منتديات ريوف</a>
<a href="http://ruoof.net/vb">ريوف</a>
<a href="http://ruoof.net/vb">موقع ريوف</a>
<a href="http://ruoof.net/vb/forumdisplay.php?f=53">أخبار عاجلة</a>
<a href="http://ruoof.net/albom">صور ريوف</a>
<a href="http://ruoof.net/albom/cat5.htm">اختصارات ماسنجر</a>
<a href="http://ruoof.net/albom/cat18.htm">وسائط</a>
<a href="http://up.ruoof.net">مركز تحميل ريوف</a>
<a href="http://up.ruoof.net">تحميل صور</a>
<a href="http://dir.ruoof.net">دليل مواقع ريوف</a>
<a href="http://ruoof.net/vb">منتدى ريوف</a>
<a href="http://ruoof.net/vb/forumdisplay.php?f=48">يوتيوب</a>
<a href="http://ruoof.net/vb/forumdisplay.php?f=48">YouTube</a>
<a href="http://ruoof.net/vb">ريوف</a>
<a href="http://ruoof.net/vb">منتديات ريوف</a>
-
<a href="http://forum.miss44.com">بنات سدير</a>
<a href="http://forum.miss44.com">بنات جلاجل </a>
<a href="http://forum.miss44.com"> بنات الحوطه</a>
<a href="http://forum.miss44.com">بنات تمير</a>
<a href="http://forum.miss44.com">بنات الروضه</a>
<a href="http://forum.miss44.com">ازياء سدير</a>
<a href="http://forum.miss44.com">ملابس سدير</a>
<a href="http://forum.miss44.com">مكياج سدير</a>
<a href="http://forum.miss44.com">وظائف نسائيه</a>
<a href="http://forum.miss44.com">موقع سدير</a>
<a href="http://forum.miss44.com">سدير نت</a>
<a href="http://forum.miss44.com">مكشات سدير</a>
<a href="http://forum.miss44.com">دردشة سدير</a>
<a href="http://forum.miss44.com">شات سدير</a>
<a href="http://forum.miss44.com">منتدى سدير</a>
<a href="http://forum.miss44.com">شبكة سدير</a>
<a href="http://forum.miss44.com">خريطة سدير</a>
<a href="http://forum.miss44.com">مدينة سدير</a>
<a href="http://forum.miss44.com">منطقة سدير</a>
<a href="http://forum.miss44.com">سيدات سدير</a>
<a href="http://forum.miss44.com"

Read the rest of this comment...




Re: CERT Hacking Information (Score: 1)
by webplu9 on Thursday, 24 June 2010 @ 09:40:33 EDT
(User Info | Send a Message)

منتديات ريوف [ruoof.net] ريوف [ruoof.net] موقع ريوف [ruoof.net] أخبار عاجلة [ruoof.net] صور ريوف [ruoof.net] اختصارات ماسنجر [ruoof.net] وسائط [ruoof.net] مركز تحميل ريوف [up.ruoof.net] تحميل صور [up.ruoof.net] دليل مواقع ريوف [dir.ruoof.net] منتدى ريوف [ruoof.net] يوتيوب [ruoof.net] YouTube [ruoof.net] ريوف [ruoof.net] منتديات ريوف [ruoof.net] - بنات سدير [forum.miss44.com] بنات جلاجل [forum.miss44.com] بنات الحوطه [forum.miss44.com] بنات تمير [forum.miss44.com] بنات الروضه [forum.miss44.com] ازياء سدير [forum.miss44.com] ملابس سدير [forum.miss44.com] مكياج سدير [forum.miss44.com] وظائف نسائيه [forum.miss44.com] موقع سدير [forum.miss44.com] سدير نت [forum.miss44.com] مكشات سدير [forum.miss44.com] دردشة سدير [forum.miss44.com] شات سدير [forum.miss44.com] منتدى سدير [forum.miss44.com] شبكة سدير [forum.miss44.com] خريطة سدير [forum.miss44.com] مدينة سدير [forum.miss44.com] منطقة سدير [forum.miss44.com] سيد&#1

Read the rest of this comment...




replica watches (Score: 1)
by replicahandbag on Friday, 23 July 2010 @ 22:58:23 EDT
(User Info | Send a Message)

That is one point valentino bags [www.mylacebags.com] that really hamstrings a lot of replica dooney and bourke [www.mylacebags.com] entrepreneurs. Pressing forward with our burberry handbags [www.mylacebags.com]discussion on affiliate marketer burberry handbags [www.mylacebags.com] advertising, we’d fendi replica handbags [www.thetotebag4u.com]like for you personally cartier handbags [www.marisabags.com] to discover a few strategies and Mulberry handbags [www.marisabags.com]ideas that really can make a d&g handbags [www.thelacebags.com]good difference in your own advertising.High quality dooney & bourke handbags [www.thelacebags.com]of content has been an issue celine replica handbags [www.thetotebag4u.com]and debate with entrepreneurs, but in DeWitt watches [www.qualityfirstwatch.com]general you always ought to try to chopard watches [www.qualityfirstwatch.com]create the highest quality content Alain Silberstein for sale [www.standardwatch.com]as feasible. Nevertheless it is not Panerai for sale [www.standardwatch.com]doubted that higher quality content Breitling for sale [www.thefirstwatches.com] will out-perform low quality ebel for sale [www.thefirstwatches.com]content in many ways. You will get the Concord replica [www.poperwatches.com]worst outcomes in terms of swiss watches [www.poperwatches.com] readership and conversions Christian Dior watches [www.poperwatches.com]from low quality or even outdated content.




Re: CERT Hacking Information (Score: 1)
by webplu9 on Monday, 23 August 2010 @ 16:47:41 EDT
(User Info | Send a Message)

href="http://www.eg-girl.com">بنت مصر
دردشة بنت مصر [www.eg-girl.com]
شات بنت مصر [www.eg-girl.com]
دردشة مصرية [www.eg-girl.com]
شات مصرى [www.eg-girl.com]
شات بنات مصر [www.eg-girl.com]
دردشة بنات مصر [www.eg-girl.com]
شات مصر [www.eg-girl.com]
دردشة مصر [www.eg-girl.com]
بنات مصر [www.eg-girl.com]
دردشة [www.eg-girl.com]
شات [www.eg-girl.com]
دردشه مصريه [www.eg-girl.com]
شات مصري [www.eg-girl.com]
اغانى مصرية [links.eg-girl.com]
منتدى بنت مصر [vb.eg-girl.com]
منتديات بنت مصر [vb.eg-girl.com]
شات بنت مصر الكتابى [chat.eg-girl.com]
دردشة بنت مصر الكتابية [chat.eg-girl.com]
شات بنت مصر الصوتى [voice.eg-girl.com]
دردشة بنت مصر الصوتية [voice.eg-girl.com]
العاب بنت مصر [games.eg-girl.com]
يوتيوب بنت مصر [video.eg-girl.com]
جوال بنت مصر [mob.eg-girl.com]
مطبخ بنت مصر [kitchen.eg-girl.com]
الازياء والموضة بنت مصر [azya.eg-girl.com]
ماسنجر بنت مصر [pic.eg-girl.com]
توبيكات بنت مصر [topics.eg-girl.com]
شات اسوان [chat.eg-girl.com]
شات الاسكن

Read the rest of this comment...




All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 1.08 Seconds