Tageszusammenfassung - Montag 17-12-2012

End-of-Shift report

Timeframe: Freitag 14-12-2012 18:00 − Montag 17-12-2012 18:00 Handler: Stephan Richter Co-Handler: Robert Waldner

Vuln: MyBB DyMy User Agent Plugin SQL Injection Vulnerability

MyBB DyMy User Agent Plugin SQL Injection Vulnerability

http://www.securityfocus.com/bid/56931


Bugtraq: Wordpress Pingback Port Scanner

Wordpress Pingback Port Scanner

http://www.securityfocus.com/archive/1/525045


Bugtraq: DDIVRT-2012-48 VMware View Connection Server Directory Traversal (CVE-2012-5978)

DDIVRT-2012-48 VMware View Connection Server Directory Traversal (CVE-2012-5978)

http://www.securityfocus.com/archive/1/525044


ENISA - Introduction to Return on Security Investment

"As for any organization, CERTs need to measure their cost-effectiveness, to justify their budget usage and provide supportive arguments for their next budget claim. But organizations often have difficulties to accurately measure the effectiveness and the cost of their information security activities. The reason for that is that security is not usually an investment that provides profit but loss prevention...."

http://www.enisa.europa.eu/activities/cert/other-work/introduction-to-return-on-security-investment


Foswiki Remote code execution and other vulnerabilities in MAKETEXT

Topic: Foswiki Remote code execution and other vulnerabilities in MAKETEXT Risk: High Text: + Security Alert: Code injection vulnerability in MAKETEXT macro, Denial of Service vulnerability in MAKETEXT macro. This ...

http://feedproxy.google.com/~r/securityalert_database/~3/8WkKh9Nz_ZM/WLB-2012120126


Eurograbber: A Smart Trojan Attack - Hackers Methods Reveal Banking Know-How

"The Eurograbber banking Trojan is an all-in-one hit, researchers say. It successfully compromises desktops and mobile devices, and has gotten around commonly used two-factor authentication practices in Europe. How can banking institutions defend themselves and their customers against this super-Trojan attack?..."

http://www.bankinfosecurity.com/eurograbber-smart-trojan-attack-a-5359?rf=2012-12-17-eb&elq=86d5df3bc3674754ab10f0c99eb6172a&elqCampaignId=5352