New User, Welcome!     Login

Software Developers

Call for papers and trainers - SeacureIT 2009

is possible to put together the brightest minds from the university,
goverment, industry and hacking community to provide the audience with
cutting-edge research in the field.
Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall-Admins, and Software Developers.

== Speakers/Trainers ==

Until February 10th, 23:59 CET, we'll be accepting speech proposals.
Please note we are a non-product, non-vendor biased security conference,

CFP: International workshop on Secure Software Engineering - Deadline extended!

In conjunction with ARES 2008
Barcelona, Catalonia, March 4th-7th 2008 

Suggested topics include, but are not limited to:
- Secure architecture and design
- Security in agile software development
- Aspect-oriented software development for secure software
- Security requirements
- Risk management in software projects
- Secure implementation
- Secure deployment

CFP: International workshop on Secure Software Engineering

Topics
======
Suggested topics include, but are not limited to:
-    Secure architecture and design
-    Security in agile software development
-    Aspect-oriented software development for secure software
-    Security requirements
-    Risk management in software projects
-    Secure implementation
-    Secure deployment

Announcement - DeepSec Conference 2008, Nov 11-14 2008

present the best research and experience from the fields' leading experts.

Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall Administrators, Teachers, Academic Researchers and Software
Developers.

The last conference has been attended by: Ericsson, Commerzbank, Philips,
RBT, GRZ IT, IERN Sierra Leone, SAP, Improware, Telekom Austria, Microsoft,
BAWAG, T-Systems, Iphos, Sektion Eins, T-Mobile, Red Hat, SWITCH, Austrian
National Bank, Daimler, Sentrigo, University of Vienna, SEC Consult, Tech

Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack

of the three lower bits are unset, as is the case with the required cs pair).

- Assumption 2: ring3 code cannot forge a trap frame.

Returning to usermode with iret is a complicated operation, the pseudocode for
the iret instruction alone spans several pages of Intel's Software Developers
Manual. The operation occurs in two stages, a pre-commit stage and a
post-commit stage. Using the VdmContext installed using NtVdmControl(), an
invalid context can be created that causes iret to fail pre-commit, thus
forging a trap frame.


[HITB-Announce] HITBSecConf2009 - Malaysia Videos Released!

9.) Deviant Olam (TOOOL USA)

10.) Dimitrios Petropoulos (Managing Director, ENCODE Middle East)

11.) Frdric Raynal (Head of Research & Software Development,
Sogeti/Cap Gemini)

12.) Guillaume Delugr (Sogeti)

13.) Haroon Meer (Technical Director, Sensepost)

SECOBJADV-2008-01: Lenovo SystemUpdate SSL Certificate Issuer Spoofing Vulnerability

20-May-2008 Released Patch
25-May-2008 Published Advisory

ABOUT SECURITY OBJECTIVES

Security Objectives is a security centric consultancy and software development 
corporation which operates in the area of application assurance software. 
Security Objectives employs methods that are centered on software 
comprehension, therefore a more in-depth contextual understanding of the 
application is developed.


SECOBJADV-2008-03.2: PartyGaming PartyPoker Malicious Update Vulnerability

18-Aug-2008 Coordinated Second Version of Advisory with Vendor
25-Aug-2008 Released New Advisory

ABOUT SECURITY OBJECTIVES

Security Objectives is a security centric consultancy and software development
corporation which operates in the area of application assurance software. 
Security Objectives employs methods that are centered on software 
comprehension, therefore a more in-depth contextual understanding of the 
application is developed.


Multiple integer overflows in Borland StarTeam server 10.0.0.57

From vendor's website:
"Borland® StarTeam® is a fully integrated, cost-effective software
change and configuration management tool, designed for both centralized
and geographically distributed software development environments."


#######################################################################

=======

{PRL} Novell Netware CIFS And AFP Remote Memory Consumption DoS

1) Introduction
===============

Novell,Inc. is a global software and services company based in Waltham, Massachusetts. The company specializes in enterprise operating systems, such as SUSE Linux Enterprise and Novell NetWare; identity, security, and systems management solutions; and collaboration solutions, such as Novell Groupwise and Novell Pulse.

Novell was instrumental in making the Utah Valley a focus for technology and software development. Novell technology contributed to the emergence of local area networks, which displaced the dominant mainframe computing model and changed computing worldwide. Today, a primary focus of the company is on developing open source software for enterprise clients.

(http://en.wikipedia.org/wiki/Novell)

#####################################################################################


Reminder: DeepSec 2009 Call for Papers is open

 - Incident Response
 - Malware Research
 - Messaging Technologies
 - Network Protocols
 - Operating Systems
 - Secure Software Development
 - Security Management
 - Social Engineering
 - Virtualisation
 - VoIP Technology
 - Web Security

DeepSec 2010 - Call for Papers and Experts

- Malware Research
- Messaging Technologies
- Network Protocols
- Operating Systems
- Patch & Upgrade Management
- Secure Software Development
- Security Management
- Social Engineering
- Virtualisation
- VoIP Technology
- Web Security

FRHACK List of Talks and Speakers released

FRHACK is not commercial - but - highly technical.

Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall Administrators, Teachers, Academic Researchers and Software
Developers.

Conference will be held in Besançon - EU, East of France, closer to
Switzerland, and aims to get together industry, government, academia and
underground hackers to share knowledge and leading-edge ideas about
information security and everything related to it.

[CFP] FRHACK 01 Call For Papers (save the dates!)

FRHACK is not commercial - but - highly technical.

Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall Administrators, Teachers, Academic Researchers and Software
Developers.

The FRHACK Team (TFT) encourages speakers to present new and interesting
projects for FRHACK 01 and will give preferential treatment to
submissions that have not been presented at other conferences.
Further, TFT invites any individual who has not spoken at a conference

DeepSec 2009 - Call for Papers is open

 - Incident Response
 - Malware Research
 - Messaging Technologies
 - Network Protocols
 - Operating Systems
 - Secure Software Development
 - Security Management
 - Social Engineering
 - Virtualisation

Please note, that we are a non-product, non-vendor biased security

n.runs, Sophos, German laws, and customer safety

  "Signatory states passing legislation to implement the treaty may
  endanger the security of their computer systems, because computer
  users in those countries will not be able to adequately protect
  their computer systems... legislation that criminalizes security
  software development, distribution, and use is counter to that goal,
  as it would adversely impact security practitioners, researchers,
  and educators."

If I recall correctly, we were assured by representatives that such an
outcome would not occur.

DeepSec 2010 - Call for Papers - REMINDER

- Malware Research
- Messaging Technologies
- Network Protocols
- Operating Systems
- Patch & Upgrade Management
- Secure Software Development
- Security Management
- Social Engineering
- Virtualisation
- VoIP Technology
- Web Security

Re: n.runs, Sophos, German laws, and customer safety

> 
>   "Signatory states passing legislation to implement the treaty may
>   endanger the security of their computer systems, because computer
>   users in those countries will not be able to adequately protect
>   their computer systems... legislation that criminalizes security
>   software development, distribution, and use is counter to that goal,
>   as it would adversely impact security practitioners, researchers,
>   and educators."
> 
> If I recall correctly, we were assured by representatives that such an
> outcome would not occur.

[CFP] FRHACK 2nd Call For Papers

FRHACK is not commercial - but - highly technical.

Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall Administrators, Teachers, Academic Researchers and Software
Developers.

The FRHACK Team (TFT) encourages speakers to present new and interesting
projects for FRHACK 01 and will give preferential treatment to
submissions that have not been presented at other conferences.
Further, TFT invites any individual who has not spoken at a conference

SECOBJADV-2008-05: Symantec Veritas Storage Foundation Arbitrary File Read Vulnerability

20-Oct-2008 Maintenance Release
22-Oct-2008 Published Advisory

ABOUT SECURITY OBJECTIVES

Security Objectives is a security centric consultancy and software development 
corporation which operates in the area of application assurance software. 
Security Objectives employs methods that are centered on software 
comprehension, therefore a more in-depth contextual understanding of the 
application is developed.


SECOBJADV-2008-04: Symantec Veritas Storage Foundation Memory Disclosure Vulnerability

20-Oct-2008 Maintenance Release
21-Oct-2008 Published Advisory

ABOUT SECURITY OBJECTIVES

Security Objectives is a security centric consultancy and software development 
corporation which operates in the area of application assurance software. 
Security Objectives employs methods that are centered on software 
comprehension, therefore a more in-depth contextual understanding of the 
application is developed.


[ GLSA 200709-08 ] id3lib: Insecure temporary file creation

overwrite arbitrary files via a symlink attack.

Background
==========

id3lib is an open-source, cross-platform software development library
for reading, writing, and manipulating ID3v1 and ID3v2 tags.

Affected packages
=================


Cisco Security Advisory: Active Template Library (ATL) Vulnerability

Details
=======

Microsoft has identified vulnerabilities in the Active Template
Library (ATL) headers that are shipped with the Software Development
Kit (SDK) for Microsoft Windows systems and used in Cisco products.
In general, this vulnerability, if exposed by an ActiveX control,
could lead to remote code execution on a client's system.

For complete details, please review the Microsoft Security Bulletin

Re: n.runs, Sophos, German laws, and customer safety

>
>   "Signatory states passing legislation to implement the treaty may
>   endanger the security of their computer systems, because computer
>   users in those countries will not be able to adequately protect
>   their computer systems... legislation that criminalizes security
>   software development, distribution, and use is counter to that goal,
>   as it would adversely impact security practitioners, researchers,
>   and educators."
>
> If I recall correctly, we were assured by representatives that such an
> outcome would not occur.

SECOBJADV-2008-02: Cygwin Installation and Update Process can be Subverted Vulnerability

22-Jul-2008 New Setup Program Tested and Verified
25-Jul-2008 Published Advisory

ABOUT SECURITY OBJECTIVES

Security Objectives is a security centric consultancy and software development 
corporation which operates in the area of application assurance software. 
Security Objectives employs methods that are centered on software 
comprehension, therefore a more in-depth contextual understanding of the 
application is developed.


DeepSec 2009 - Preliminary Schedule is online

present the best research and experience from the fields' leading experts.

Target Audience: Security Officers, Security Professionals and Product
Vendors, IT Decision Makers, Policy Makers, Security-, Network-, and
Firewall Administrators, Teachers, Academic Researchers and Software
Developers.

The last conference has been attended by: Ericsson, Commerzbank, Philips,
RBT, GRZ IT, IERN Sierra Leone, SAP, Improware, Telekom Austria, Microsoft,
BAWAG, T-Systems, Iphos, Sektion Eins, T-Mobile, Red Hat, SWITCH, Austrian
National Bank, Daimler, Sentrigo, University of Vienna, SEC Consult, Tech

Re: n.runs, Sophos, German laws, and customer safety

>>
>>   "Signatory states passing legislation to implement the treaty may
>>   endanger the security of their computer systems, because computer
>>   users in those countries will not be able to adequately protect
>>   their computer systems... legislation that criminalizes security
>>   software development, distribution, and use is counter to that goal,
>>   as it would adversely impact security practitioners, researchers,
>>   and educators."
>> 
>> If I recall correctly, we were assured by representatives that such an
>> outcome would not occur.

[ GLSA 200709-18 ] Bugzilla: Multiple vulnerabilities

Background
==========

Bugzilla is a web application designed to help with managing software
development.

Affected packages
=================

    -------------------------------------------------------------------

{PRL} Novell Netware FTP Remote Stack Overflow

Groupwise and Novell

Pulse.

Novell was instrumental in making the Utah Valley a focus for
technology and software development. Novell technology contributed to
the emergence of local

area networks, which displaced the dominant mainframe computing model
and changed computing worldwide. Today, a primary focus of the company
is on developing



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!