David Ansermot Web Developer / TYPO3 Integrator

26oct/100

Security issue in Powermail for TYPO3

A security issue has been discovered in the third party TYPO3 extension powermail.

Read full post

26oct/100

Security flaw discovered iOS 4.1

A new security flaw was discovered in iOS 4.1, this flaw allows access to the directory of an iPhone protected by a password.

Handling is fairly simple, just to have an iPhone on iOS 4.1 Protecting a password and :

  • Click "Emergency Call"
  • Type a number at random, ex: 1234
  • Tap on "Call" followed immediately:
  • Pressing the power button on the top right.

If you were fast enough, you should find yourself in the application "Phone" of the iPhone and can see the different contacts and even call them!
Namely, this flaw does not appear to be present in the beta iOS 4.2 but there is no fix to date for version 4.1, either by Apple or Cydia.

25oct/100

RDS security flaw in Linux Kernel 2.6.30 and higher

A flaw affecting the RDS for Linux allows a user to afford the status of "super user", a fix is luckily available.

A security flaw in Linux issue very recently discovered by a team of researchers. The scientists point the finger and a vulnerability that appeared in version 2.6.30 of the kernel of the operating system free, and that continues to this day.

It is situated in the RDS (Reliable Datagram Sockets) that came with this version of the kernel.

Download the patch

Source : VSR Security

25oct/100

A 12 years old hacker found a critical flaw in Firefox

In the series' value does not expect the number of years "after the young girl of 16 who is developing a site for the British government, this is the hacker of 12 years is a critical flaw in Firefox.

And pocketing $ 3,000 in the passage provided by the Mozilla Foundation for any contributor who help significantly to improve the security of its browser.

Alex Miller is a young boy from San Jose (Calif.) computer enthusiast. Passionate but not insensitive to the gains.

When Mozilla has decided to multiply by six the reward for the discovery of a significant vulnerability, the young prodigy has made up his mind to win the award.

His initial analysis led him to find some flaws, minor, insufficient to receive the jackpot.

Stubborn, Alex Miller continues his research for 10 days at an hour and a half per day, until he uncovers a flaw in the use of application memory.

Tracking down bugs is not easy. Very technical, it concerns only a small community of developers, says essentially Brandon Sterne, head of security at Mozilla, about Alex Miller.

An annoying boy ?

Source : Mercury News

24oct/100

Apple FaceTime “security flaw” fixed

Apple has fixed the security flaw on the server-side.

But you can fix the flaw for your already logged account like this :
Go to your User Folder / Library / Preferences and delete com.apple.FaceTime.plist