New User, Welcome!     Login

<< Previous Next >>

security policies

Cisco Security Advisory: Cisco IOS Software TCP Denial of Service Vulnerability

to the affected device. Cisco IOS Software Releases 12.0S, 12.2SX,
12.2S, 12.3T, 12.4, and 12.4T support the CoPP feature. CoPP may be
configured on a device to protect the management and control planes
and minimize the risk and effectiveness of direct infrastructure
attacks by explicitly permitting only authorized traffic sent to
infrastructure devices in accordance with existing security policies and
configurations. The following example can be adapted to specific network
configurations:

    !
    !-- The 192.168.1.0/24 network and the 172.16.1.1 host are trusted.

Cisco Security Advisory: Cisco IOS Software Internet Group Management Protocol Denial of Service Vulnerability

CoPP may be configured on a device to protect the management and
control planes, and minimize the risk and effectiveness of direct
infrastructure attacks by explicitly permitting only authorized
traffic sent to infrastructure devices in accordance with existing
security policies and configurations. The following example can be
adapted to your network. Drop of IGMP packets with unicast IP
destination addresses can also be implemented with CoPP if the
network is using all multicast applications that utilize only
multicast group destination addresses for IGMP packets.


[ELEYTT] Public Advisory 05-12-2007

Eleytt offers Eleytt Business Continuity Program. What is it?

- Long-term continous security audits
- Security consulting and training
- Security policy compliance issues

For more information, please refer to eleytt.com, http://www.eleytt.com




Re: [Full-disclosure] 3rd party patch for XP for MS09-048?

>>>>>>>
>>>>>>>
>>>>>>>               
>>>>> --
>>>>> Eric C. Lukens
>>>>> IT Security Policy and Risk Assessment Analyst
>>>>> ITS-Network Services
>>>>> Curris Business Building 15
>>>>> University of Northern Iowa
>>>>> Cedar Falls, IA 50614-0121
>>>>> 319-273-7434

RE: [Full-disclosure] 3rd party patch for XP for MS09-048?

> > >>
> > >>
> >
> > --
> > Eric C. Lukens
> > IT Security Policy and Risk Assessment Analyst
> > ITS-Network Services
> > Curris Business Building 15
> > University of Northern Iowa
> > Cedar Falls, IA 50614-0121
> > 319-273-7434

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

untrusted sources. Cisco IOS Releases 12.0S, 12.2SX, 12.2S, 12.3T,
12.4, and 12.4T support the CoPP feature. CoPP may be configured on a
device to protect the management and control planes to minimize the
risk and effectiveness of direct infrastructure attacks by explicitly
permitting only authorized traffic sent to infrastructure devices in
accordance with existing security policies and configurations. The
following example can be adapted to specific network configurations:

    !-- The 192.168.1.0/24 network and the 172.16.1.1 host are trusted.
    !-- Everything else is not trusted. The following access list is used
    !-- to determine what traffic needs to be dropped by a control plane

Re: [Full-disclosure] 3rd party patch for XP for MS09-048?

>>>>>>>>
>>>>>>>>               
>>>>>>>>                 
>>>>>> --
>>>>>> Eric C. Lukens
>>>>>> IT Security Policy and Risk Assessment Analyst
>>>>>> ITS-Network Services
>>>>>> Curris Business Building 15
>>>>>> University of Northern Iowa
>>>>>> Cedar Falls, IA 50614-0121
>>>>>> 319-273-7434

RE: [Full-disclosure] 3rd party patch for XP for MS09-048?

> > >>
> > >>
> >
> > --
> > Eric C. Lukens
> > IT Security Policy and Risk Assessment Analyst
> > ITS-Network Services
> > Curris Business Building 15
> > University of Northern Iowa
> > Cedar Falls, IA 50614-0121
> > 319-273-7434

EC2ND 2009 CFP - 5th European Conference on Computer Network Defence

Topics include but are not limited to:

      * Intrusion Detection
      * Denial-of-Service
      * Privacy Protection
      * Security Policy
      * Peer-to-Peer and Grid Security
      * Network Monitoring
      * Web Security
      * Vulnerability Management and Tracking
      * Network Forensics

Re: Secunia Research: Adobe Reader JBIG2 Symbol Dictionary Buffer Overflow

> the Authenticode signature.
>   

-- 
Eric C. Lukens
IT Security Policy and Risk Assessment Analyst
ITS-Network Services
Curris Business Building 15
University of Northern Iowa
Cedar Falls, IA 50614-0121
319-273-7434

[USN-653-1] D-Bus vulnerabilities

effect the necessary changes.

Details follow:

Havoc Pennington discovered that the D-Bus daemon did not correctly
validate certain security policies.  If a local user sent a specially
crafted D-Bus request, they could bypass security policies that had a
"send_interface" defined. (CVE-2008-0595)

It was discovered that the D-Bus library did not correctly validate
certain corrupted signatures.  If a local user sent a specially crafted

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability

untrusted sources. Cisco IOS Releases 12.0S, 12.2SX, 12.2S, 12.3T,
12.4, and 12.4T support the CoPP feature. CoPP may be configured on a
device to protect the management and control planes to minimize the
risk and effectiveness of direct infrastructure attacks by explicitly
permitting only authorized traffic sent to infrastructure devices in
accordance with existing security policies and configurations. The
following example can be adapted to the network

    
    !-- The 192.168.1.0/24 network and the 172.16.1.1 host are trusted.
    !-- Everything else is not trusted. The following access list is used

Cisco Security Advisory: Cisco Content Services Gateway Denial of Service Vulnerability

other than applying infrastructure access control lists (iACLs) on
the Cisco 7600 router to block ICMP traffic destined to the IP
address of the Cisco CSG. Administrators can construct an iACL by
explicitly permitting only authorized traffic to enter the network at
ingress access points or permitting authorized traffic to transit the
network in accordance with existing security policies and
configurations. An iACL workaround cannot provide complete protection
against these vulnerabilities when the attack originates from a
trusted source address.

The iACL policy denies unauthorized ICMP packet types, including echo

RE: Windows Vista Power Management & Local Security Policy

-----Original Message-----
From: Abe Getchell [mailto:me@abegetchell.com] 
Sent: Friday, 18 July 2008 12:39 PM
To: bugtraq@securityfocus.com
Subject: Windows Vista Power Management & Local Security Policy

> When the security option "Shutdown: Allow system to be shutdown without
having to log on" (in the local security policy) is set to "Disable", and
> the power management setting "When I press the power button" is set to
"Shut Down", it is possible for an unauthenticated user to press the power 

Re: [Full-disclosure] 3rd party patch for XP for MS09-048?

>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>> --
>>>>>> Eric C. Lukens
>>>>>> IT Security Policy and Risk Assessment Analyst
>>>>>> ITS-Network Services
>>>>>> Curris Business Building 15
>>>>>> University of Northern Iowa
>>>>>> Cedar Falls, IA 50614-0121
>>>>>> 319-273-7434

Call for Papers: EC2ND 2010

  for submission include but are not limited to:

      * Intrusion Detection
      * Malicious Software
      * Web Security
      * Security Policy
      * Peer-to-Peer and Grid Security
      * Wireless and Mobile Security 
      * Network Forensics
      * Network Discovery and Mapping
      * Incident Response and Management

RE: Windows Vista Power Management & Local Security Policy

Correct. Power management in Windows Vista is apparently given a pass to
bypass local security policy, which is a bad thing, and sets a bad
precedence. I will leave it to others to exploit this security issue, given
that I know little about the programmatic aspect of power management in
Windows. There are people out there much more capable than me who, if they
feel it warranted, can research the issue further. I don't consider it, as
Jim Harrison would say, "wasting your time chasing things that 'might lead
to cats & dogs living together in sin'", but rather "security research" and
"sharing information". I don't consider Jim's reaction surprising at all,
though, as he works for Microsoft.

CORE-2008-0826 - Internet Explorer Security Zone restrictions bypass

information can be obtained by an attacker including but not limited to
user authentication credentials for any web application domain, HTTP
cookies, session management data, cached content of web applications in
different domains and any files stored on local filesystems.

The bug is related to a lack of enforcement of security policies
assigned to URL Security Zones [2] when content from the corresponding
zone is loaded and rendered from a local file. These issues have been
found in the way that security policies are applied when a URI is
specified in the UNC form (i.e., '\\MACHINE_NAME_OR_IP\PATH_TO_RESOURCE'):


RE: [Full-disclosure] 3rd party patch for XP for MS09-048?

>>>>>>>
>>>>>>>
>>>>>>>               
>>>>> --
>>>>> Eric C. Lukens
>>>>> IT Security Policy and Risk Assessment Analyst
>>>>> ITS-Network Services
>>>>> Curris Business Building 15
>>>>> University of Northern Iowa
>>>>> Cedar Falls, IA 50614-0121
>>>>> 319-273-7434

Cisco Security Advisory: Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities

untrusted sources. Cisco IOS software releases 12.0S, 12.2SX, 12.2S,
12.3T, 12.4, and 12.4T support the CoPP feature. CoPP may be
configured on a device to protect the management and control planes
to minimize the risk and effectiveness of direct infrastructure
attacks by explicitly permitting only authorized traffic sent to
infrastructure devices in accordance with existing security policies
and configurations. The following example can be adapted to your
network:


    !-- The 192.168.1.0/24 network and the 172.16.1.1 host are trusted.

Cisco Security Advisory: Multiple Multicast Vulnerabilities in Cisco IOS Software

effectiveness of direct infrastructure attacks, administrators are
advised to deploy ACLs to perform policy enforcement of traffic sent
to core infrastructure equipment. PIM is IP protocol 103. As an
additional workaround, administrators can explicitly permit only
authorized PIM (IP protocol 103) traffic sent to infrastructure
devices in accordance with existing security policies and
configurations. An ACL can be deployed as shown in the following
example:

    ip access-list extended Infrastructure-ACL-Policy


Checkpoint VPN-1 UTM Edge cross-site scripting

     and manageability. VPN-1 UTM Edge appliances consolidate proven
     enterprise-class technology into a single branch office solution
     that does not compromise the corporate network and eliminates the
     branch office as your weakest link. As part of Check Point's Unified
     Security Architecture, VPN-1 UTM Edge can enforce a global security
     policy and allows administrators to manage and update thousands of
     appliances as easily as managing one."

    Insufficient input validation and output encoding on the login page
    allows attacker to perform html-injection by posting suitable string
    to the login form handler. The injection leads to reflected

=?WINDOWS-1252?Q?Call_For_Papers_=96_ACM_CCS_2009_Workshops?=

The SWS workshop explores many topics related to Web Services
Security, ranging from the advancement and best practices of building
block technologies such as XML and Web services security protocols to
higher level issues such as advanced metadata, general security
policies, trust establishment, risk management, and service
assurance. The workshop provides a forum for presenting research
results, practical experiences, and innovative ideas in web services
security.

= 

CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation

*Report Timeline*

. *2007-10-16*:  Initial contact email sent to the VMware Security Team
notifying discovery of a Priority 1 vulnerability in accordance to the
vendor's security policy [9]. A draft security advisory describing the
problem is available. Public disclosure of the vulnerability is scheduled
on November 5th, 2007.
. *2007-10-17*:  Vendor acknowledges notification, provides public key and
requests a draft of the security advisory .
. *2007-10-17*:  Core sends the draft advisory.

Call for Papers - you Sh0t the Sheriff 4 - Security Conference, Brazil

   * Operating Systems
   * Career and Management topics
   * Mobile Devices/Embedded Systems
   * Information Security Audit and Control
   * Social Networking
   * Information Security Policies
   * Messing with Protocols
   * Networking/Telecommunication
   * Wireless and all RF related stuff
   * Incident Response & other applicable (and useful) Infosec Policies
   * Information Warfare

Paranoia 2011: Call for papers

•       Cyber Warfare
•       Information Assurance
•       Security Data Collection and Analysis
•       Internet-based Terrorism and Espionage
•       Reverse Engineering of Viruses and Worms
•       Security Policy Implementation & Compliance
•       Botnet Detection and Prevention
•       Information Security Risk Management
•       Economics of Information Security
•       Computer & Network Forensics
•       Network Security and Intrusion Detection

Cyber Warfare Conference: Agenda

CYBER WARS: A paradigm shift from Means to End

Michael Ruiz, CTO, Net-Enabled Operations (NEOS), BearingPoint
Cyber Command and Control: A Current Concept for Future Doctrine

Andrew Cutts, Director, Cybersecurity Policy, U.S. Department of
Homeland Security
Cyber Risk from a Homeland Security Perspective

David Sulek and Ned Moran, Booz Allen Hamilton
What Historical Analogies can tell us about the Future of Cybersecurity

Directory traversal in MicroWorld eScan Server 9.0.742.98

From vendor's website:
"The Powerful Management Console of eScan provides options for system
administrators to remotely administer a vast network of clients. It
also allows them to remotely install eScan, deploy upgrades and updates
and enforce an Integrated Security Policy for the entire Enterprise."


#######################################################################

======

[ MDVSA-2011:054 ] java-1.6.0-openjdk

 
 The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7,
 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from
 the checkPermission method instead of throwing an exception in certain
 circumstances, which might allow context-dependent attackers to bypass
 the intended security policy by creating instances of ClassLoader
 (CVE-2010-4351).
 
 Unspecified vulnerability in the Java Runtime Environment (JRE)
 in Oracle Java SE and Java for Business 6 Update 23 and earlier,
 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote

[CVE-2007-5342] Apache Tomcat's default security policy is too open

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

CVE-2007-5342: Tomcat's default security policy is too open

Severity:
Low

Vendor:
The Apache Software Foundation

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!