ot

jQuery Impacted By Prototype Pollution Flaw




ot

Surveillance Footage And Code Clues Indicate Stuxnet Hit Iran





ot

Windows 2000/XP/2003 win32k.sys SfnLOGONNOTIFY Denial Of Service

win32k.sys in Microsoft Windows 2000 / XP / 2003 suffers from a local kernel denial of service vulnerability related to SfnLOGONNOTIFY.







ot

vthrottle-0.60.tar.gz

vthrottle is an implementation of an SMTP throttling engine for Sendmail servers, based upon M. Williamson's mechanisms, as described in his 2003 Usenix Security paper. It allows the administrator to control how much email users and hosts may send, hindering the rapid spread of viruses, worms, and spam. Exceptions can be made using a whitelist mechanism, which can be generated manually or with the included tool vmeasure.




ot

LPRng use_syslog Remote Format String Vulnerability

This Metasploit module exploits a format string vulnerability in the LPRng print server. This vulnerability was discovered by Chris Evans. There was a publicly circulating worm targeting this vulnerability, which prompted RedHat to pull their 7.0 release. They consequently re-released it as "7.0-respin".




ot

PHP-Nuke 7.0 / 8.1 / 8.1.35 Wormable Remote Code Execution

PHP-Nuke versions 7.0, 8.1 and 8.1.35 wormable remote code execution exploit.




ot

Linksys E-Series Remote Code Execution

Linksys E-Series unauthenticated remote command execution exploit that leverages the same vulnerability as used in the "Moon" worm.




ot

Linksys Worm Remote Root

Proof of concept exploit used by the recent Linksys worm (known as "Moon"). Exploits blind command injection in tmUnblock.cgi.




ot

Linksys E-Series TheMoon Remote Command Injection

Some Linksys E-Series Routers are vulnerable to an unauthenticated OS command injection. This vulnerability was used from the so called "TheMoon" worm. There are many Linksys systems that might be vulnerable including E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900. This Metasploit module was tested successfully against an E1500 v1.0.5.




ot

Ubuntu Security Notice 715-1

Ubuntu Security Notice USN-715-1 - Hugo Dias discovered that the ATM subsystem did not correctly manage socket counts. It was discovered that the inotify subsystem contained watch removal race conditions. Dann Frazier discovered that in certain situations sendmsg did not correctly release allocated memory. Helge Deller discovered that PA-RISC stack unwinding was not handled correctly. It was discovered that the ATA subsystem did not correctly set timeouts. It was discovered that the ib700 watchdog timer did not correctly check buffer sizes.




ot

Anonymous Takes Down Greek Sites In Support Of Athens Protests




ot

Opera CEO - Unite Not A Security Risk







ot

Xenotix Python Keylogger For Windows

Xenotix is a keylogger for windows that is written in Python. It has the ability to send logs remotely.




ot

Notorious eBay Hacker Gets 3-Year Suspended Sentence







ot

Novell ZENworks Configuration Management Remote Execution

This Metasploit module exploits a code execution flaw in Novell ZENworks Configuration Management 10 SP3 and 11 SP2. The vulnerability exists in the ZEnworks Control Center application, allowing an unauthenticated attacker to upload a malicious file outside of the TEMP directory and then make a second request that allows for arbitrary code execution. This Metasploit module has been tested successfully on Novell ZENworks Configuration Management 10 SP3 and 11 SP2 on Windows 2003 SP2 and SUSE Linux Enterprise Server 10 SP3.




ot

DMCA Strikes Again - First Amendment Does Not Apply




ot

Diebold Uses DMCA to Conceal E-Voting Machine Flaws




ot

E-Voting Vendor Sued For DMCA Takedown




ot

Hackers, Others Seek DMCA Exemptions





ot

The Robot War Over Libya Has Begun




ot

Satellite Photos Take You Inside Gadhafi's Compound




ot

Hackers Plan Attacks To Protest Iraq War






ot

prott_packV01A.zip

Protty is a ring 3 library developed to protect against shellcode execution on Windows NT based systems.




ot

Scotland Rejects Independence, But Concerns Linger for a Renewables Future

Scotland’s decision to vote no to independence from the United Kingdom of Great Britain and Northern Ireland has elicited a collective sigh of relief from energy sector players. Those companies with significant investments in Scottish renewable energy assets had understandably been anxious over the uncertainty that an independent Scotland would engender, for example potentially changing the rules on support measures for renewable energy investment north of the border.




ot

Increased Study Requirements, Loss of DOE Backing End Admiralty Inlet Tidal Pilot Project

Snohomish County Public Utility District announced it is abandoning plans to develop the 600-kW Admiralty Inlet Pilot tidal project in Washington's Puget Sound.




ot

IEA World Forecast: Stresses on Energy System Must Not Be Ignored

The world’s decision-makers must not let current events distract them from recognizing and addressing the longer-term signs of stress that are emerging in the global energy system, the International Energy Agency (IEA) warned today at the launch of its annual World Energy Outlook 2014 report in London.




ot

Marine Energy Making Waves on Both Sides of the Pond

In recent months, a number of initiatives aimed at speeding up the development of the wave energy sector have been launched in the U.S. and Europe. As part of the ongoing work to establish a viable United States wave energy industry, the National Renewable Energy Laboratory (NREL) and Sandia National Laboratories (SANDIA) are working on the creation of a sophisticated open-source modeling tool known as WEC-Sim — and the U.S. Department of Energy is also enlisting the coding community to help in its development. Meanwhile, the European WavePOD project is an industry-wide initiative that aims to solve the problem of converting captured wave energy into electricity by creating a "standardised self-contained offshore electricity generator for the wave industry."




ot

India Plans Renewables Splurge, But Will Not Commit to Carbon Plan

India, the world’s third-largest polluter, will spend at least $100 billion on climate-related projects but isn’t ready to follow China and the U.S., the top two emitters, in promising to limit its fossil-fuel emissions.




ot

Solar Tariffs: Throttling America's Biggest Job Creation Machine

The U.S. Department of Commerce just announced that it will add high tariffs for solar modules imported from China. The Canadian government is also investigating the adoption of similar measures, following recent complaints filed by Ontario-based solar manufacturers. With the solar industry in hypergrowth, it’s not a surprise that these governments are interested in boosting new jobs, protecting their economies, and fostering the solar sector. The problem is that tariffs are a short-sighted approach that actually attack the future of North American solar on its home soil, and likely destroy more jobs than they create.




ot

We Should be Looking to CEOs, Not Politicians, for Climate Change Action

In May of 2014, Speaker of the House John Boehner responded to a climate change question with, “listen, I’m not qualified to debate the science over climate change. I am astute to understand that every proposal that has come out of this administration to deal with climate change involves hurting our economy and killing American jobs. That can’t be the prescription for dealing with changes to our climate.” Speaker Boehner is not the only one reluctant to enter into the debate on climate change. In a March interview Mitch McConnell responded to a climate change remark with, “For everybody who thinks it's warming, I can find somebody who thinks it isn't…”




ot

Demand Response: A Valuable Tool that Can Help California Realize its Clean Energy Potential

A tool only has value if it’s used. For example, you could be the sort of person who’s set a goal of wanting to exercise more. If someone gives you a nifty little Fitbit to help you do that, and you never open the box, how useful, then, is this little device? The same is true about smart energy management solutions: good tools exist, but whether it’s calories or energy use that you want to cut, at some point those helpful devices need to be unpacked.




ot

Protecting Workers and Communities During the Clean Energy Transition

When I worked at the New York Attorney General's Office, we sued coal-fired power plants because their air pollution was making people sick. But in some towns, I saw that the reliance on coal really had people in a bind. The coal plant was making them sick, but it was also a major tax generator for the town. If the plant closed, the town might have to lay off teachers and cops, in addition to losing the plant jobs.




ot

Harvard’s Star Alumni Urge Week of Fossil Fuel Protests

Actress Natalie Portman, environmentalist Robert F. Kennedy, Jr., and other high-profile Harvard University alumni are calling for demonstrations to urge divestment from fossil fuels.




ot

The Big Question: Where Do You See Renewable Energy Growth Potential in 2015?

The annual outlook issue of Renewable Energy World magazine is our attempt to predict what will happen within the renewable energy industry over the course of the year. To do this, we went straight to the top of major renewable energy companies, asking CEOs and presidents to tell us where they are devoting their company resources in order to capitalize on some of the market growth that they expect to see in 2015.





ot

US Climate Commitment Should Spur Other Countries to Act

The proposed U.S. commitment to tackling climate change in support of a new international climate agreement is a serious and achievable plan that demonstrates the United States is ready to take significant action. Coming today, eight months before the UNFCCC Conference of the Parties in Paris this December, known as COP 21, the U.S. submission adds momentum toglobal climate negotiations and should help spur other countries to act.