Book Mark

Ike.ninja

Linux Fun
  • Home
  • How to
  • Reference Links
  • Categories
    • Releases
    • Plesk
    • Community
    • CMS
    • security
    • MYSQL
    • cPanel
  • Tools
    • IP Checker
    • Byte Converter
RSS

Debian: 2768-1: icedtea-web: heap-based buffer overflow

Oct08
by Ike on October 8, 2013 at 3:36 am
Posted In: Other

(Oct 4) A heap-based buffer overflow vulnerability was found in icedtea-web, a web browser plugin for running applets written in the Java programming language. If a user were tricked into opening a malicious website, an attacker could cause the plugin to crash or possibly execute arbitrary [More…]

└ Tags: vulnerability, website
 Comment 

Phishers using CloudFlare for SSL

Oct07
by Ike on October 7, 2013 at 1:05 pm
Posted In: security

Some Content Delivery Networks (CDNs) enable fraudsters to deploy phishing attacks with valid SSL certificates. Not only does this make the fraudulent sites appear more credible, but they also benefit from the fast response times provided by the CDN.

A Turkish phishing site using CloudFlare (site has since been taken down)

The phishing site on odemerkezi.com is targeted at Turkcell customers — visitors to the phishing site are asked for their phone number, bank name, credit card details, and password. As CloudFlare’s SSL feature is only available on paid accounts (which start at $20/month), the fraudster may have used an early victim’s credit card to purchase the Pro plan.

Netcraft is currently blocking hundreds of phishing attacks which use CloudFlare’s content delivery network, including some which use CloudFlare-provided SSL certificates. So far this year, Netcraft has blocked more than 2,000 phishing attacks using Cloudflare’s infrastructure, of which approaching 200 used SSL.

CloudFlare’s SSL certificates make use of the Subject Alternative Name (SAN) extension, which allows an edge node to use a single certificate for multiple domains. In the case of www.odemerkezi.com, the edge node presented a certificate which had a common name (CN) of “ssl2796.cloudflare.com”, but also included the odemerkezi.com domain along with the domains of many other CloudFlare customers.


An SSL certificate used by a CloudFlare edge node server. It is valid for multiple domains belonging to its customers.

The multi-domain SSL certificates used by CloudFlare edge nodes are issued by GlobalSign. Rather than using Server Name Identification (SNI) — which would allow an individual certificate to be used for each website on a single IP address — CloudFlare uses GlobalSign’s Cloud product to work around a lack of support for SNI in Internet Explorer on Windows XP and some mobile browsers. The two companies announced their partnership less than a year ago, and GlobalSign’s own website uses CloudFlare, as do its
OCSP and CRL services.

Some of the SSL phishing sites on CloudFlare that have been blocked by Netcraft have used deceptive domain names, such as paypal-germany.de.com, paypal-kundensicherheit.net and paypal-verifikation.com. Last month, a similarly deceptive domain name and SSL certificate issued by Network Solutions was

used in a phishing attack
against customers of Chase Bank.

Domain registrars and certificate authorities can reduce the likelihood of new domains and certificates being used for fraudulent activities. Netcraft’s Domain Registration Risk service identifies domains which are deceptively similar to legitimate websites run by banks and other institutions that are commonly targeted by phishing attackers.

└ Tags: edge, security, site, SSL, website
 Comment 

Ubuntu: 1978-1: libKDcraw vulnerabilities

Oct05
by Ike on October 5, 2013 at 3:59 am
Posted In: Other

(Sep 30) libKDcraw could be made to crash if it opened a specially crafted file.

 Comment 

Ubuntu: 1984-1: Python 3.2 vulnerabilities

Oct05
by Ike on October 5, 2013 at 3:59 am
Posted In: Other

(Oct 1) Several security issues were fixed in Python.

 Comment 

Ubuntu: 1982-1: Python 2.6 vulnerability

Oct04
by Ike on October 4, 2013 at 3:57 am
Posted In: Other

(Oct 1) Fraudulent security certificates could allow sensitive information tobe exposed when accessing the Internet.

└ Tags: sensitive
 Comment 
  • Page 2,566 of 2,967
  • « First
  • «
  • 2,564
  • 2,565
  • 2,566
  • 2,567
  • 2,568
  • »
  • Last »

What’s New?

  • Fedora 42: tinygltf Update 2.9.7 Advisory FEDORA-2025-ac8ed4a110
  • Fedora 43: webkitgtk Critical Update for CVE-2025-13947, 43458, 66287
  • Fedora 42: abrt Critical Command Injection Vulnerability CVE-2025-12744
  • Fedora 42: Chromium High CVE-2025-13630, 13631, 13632 Advisory
  • Ubuntu 22.04: Linux Kernel Azure Important Security Flaws USN-7910-2
  • Ubuntu 22.04: Important Linux Kernel Updates Addressing Security Flaws
  • Ubuntu 22.04 LTS: Linux Kernel Critical Security Vulnerability USN-7889-5
  • Ubuntu 25.10: Linux GCP Kernel Critical Security Issues USN-7906-2
  • Debian: Chromium Critical Exec Abuse DoS Info Disclosure DSA-6072-1
  • Debian: Unbound Critical Cache Poisoning Fix DSA-6071-1 CVE-2025-11411
  • Ubuntu 20.04 LTS: Important CUPS Denial of Service Advisory USN-7912-2
  • Ubuntu 25.10: MAME Critical Heap Overflow Attacks USN-7913-1
  • Fedora 42: usd Important Security Update for 3D Format 2025-073e4f7991
  • Ubuntu 23.04: xyz Enhanced Security Vulnerabilities Update 2025-4bd12a45g3
  • Debian: WebKitGTK Critical CVE-2025-43392 Exfiltration and Crash DSA-6070-1
  • Debian: OpenVPN Critical HMAC Flaw Bypass CVE-2025-13086 DSA-6069-1
  • State of the Word 2025: Innovation Shaped by Community
  • Ubuntu 20.04: Ghostscript Important DoS Vulnerability USN-7904-1
  • Ubuntu 25.10: PostgreSQL Critical Denial of Service Fix USN-7908-1
  • Fedora 41: openbao 2.4.4 Important Security Issues DoS 2025-45a7dd8f10
  • Fedora 41: restic 0.18.1 Advisory – Urgent Security Concerns Identified
  • Debian: Critical Denial of Service & Privilege Escalation DSA-6067-1
  • Debian 11: Xen Critical Privilege Escalation DSA-6068-1 CVE-2024-28956
  • WordPress 6.9 “Gene”
  • Ubuntu 25.10: Django Important SQL Exec DoS Vulnerabilities 2025:7903-1

Search

Translator

Tags

Business and industry code Community cPanel CVE Debian Debian Linux Distribution - Security Advisories Development Events Fedora Fedora Linux Distribution - Security Advisories General Hosting Important Advisory Linux Moderate Advisory Month in WordPress news Parallels Plesk Parallels Plesk Panel Performance PHP Plesk news and announcements Plesk Panel Podcast ProdDevSec Product and technology Products Project Release News Red Hat Red Hat Linux Distribution - Security Advisories Releases security Security Centre sensitive site Ubuntu Ubuntu Linux Distribution - Security Advisories update updates Various vulnerability Web Server Survey Wordpress wp-briefing

Posts

Helpful Links

  • Liquidweb.com
  • MYSQL Dev Documentation
  • Plugins
  • Source forge SED command
  • Themes
  • WordPress Documentation
  • You Tube
December 2025
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  
  • Google
  • Yahoo
  • Liquid Web
  • Storm
  • YouTube

©1999-2025 Ike.ninja | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑

52 queries. 8.5 mb Memory usage. 0.278 seconds.