Main Menu
Utilities
NQ HTTP Request

Symantec Alert Box
Security : RealVNC Password Authentication Bypass Vulnerability
Posted by digitalTR on 2006/5/17 14:50:00 (143 reads)

The RealVNC Server fails to properly authenticate clients.
This may allow a remote attacker to bypass authentication and gain access to the VNC server


The RealVNC Server fails to properly authenticate clients. When a RealVNC client connects to a RealVNC server, the server provides a list of supported authentication methods. By design, the client then selects a method from the list. Due to an implementation flaw, if the client specifies that no (null) authentication should be used, the server accepts this method and authenticates the client, whether or not null authentication was offered by the server.

Note that exploit code for this vulnerability is publicly available.

Read More... | 1922 bytes more
Security : Check Point Introduces New Safe@Office Unified Threat Management Appliances with Integrated ADSL Modems
Posted by digitalTR on 2006/5/16 18:40:00 (77 reads)
Security

Easy-to-manage appliances allow Internet Service Providers to provide security protection and connectivity in a single solution
Check Point® Software Technologies Ltd., the worldwide leader in securing the Internet, today announced the availability of new Check Point "Safe @ Office 500/500W ADSL" appliances, providing complete network security and a choice of wired or wireless Internet connectivity in a single, all-in-one solution for small businesses worldwide.

Read More... | 3923 bytes more
Security : Microsoft Security Bulletin Summary for January, 2006
Posted by digitalTR on 2006/1/11 4:40:00 (85 reads)

Maximum Severity Rating: Critical

* A vulnerability exists in the Graphics Rendering Engine that could allow remote code execution.
* A vulnerability exists when viewing Embedded Web Fonts that could lead to remote code execution.
* A vulnerability exists in TNEF messages that could allow remote code execution.

Read More... | 3640 bytes more