<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog Life &#187; Security Findings</title>
	<atom:link href="http://www.ridhzuanharun.com/category/security-findings/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ridhzuanharun.com</link>
	<description>Ridhzuan&#039;s Other Half</description>
	<lastBuildDate>Wed, 17 Aug 2011 23:25:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Adobe Reader and Acrobat Vulnerabilities</title>
		<link>http://www.ridhzuanharun.com/adobe-reader-and-acrobat-vulnerabilities/</link>
		<comments>http://www.ridhzuanharun.com/adobe-reader-and-acrobat-vulnerabilities/#comments</comments>
		<pubDate>Sun, 17 Feb 2008 16:05:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Public Announcement]]></category>
		<category><![CDATA[Security Findings]]></category>

		<guid isPermaLink="false">http://ridhzuanharun.com/?p=38</guid>
		<description><![CDATA[This is the latest vulnerabilities findings and was found by US-CERT (United States Computer Emergency Readiness Team). Hopefully it will helps us from possible virus or expoit
National Cyber Alert System
Technical Cyber Security Alert TA08-043A 		
Adobe Reader and Acrobat Vulnerabilities
Original release [...]]]></description>
			<content:encoded><![CDATA[<p>This is the latest vulnerabilities findings and was found by US-CERT (United States Computer Emergency Readiness Team). Hopefully it will helps us from possible virus or expoit</p>
<p><span class="cas_title">National Cyber Alert System</span><br />
<span class="cas_alert_info">Technical Cyber Security Alert TA08-043A</span> 		<span id="cas_archiveLink"><a href="http://www.us-cert.gov/cas/techalerts/index.html" title="Current Activity Archive"><img src="http://www.us-cert.gov/images/archive.gif" alt="archive" border="0" /></a></span></p>
<h2>Adobe Reader and Acrobat Vulnerabilities</h2>
<p>Original release date: February 12, 2008<br />
Last <a href="http://www.us-cert.gov/cas/techalerts/TA08-043A.html#revisions">revised</a>: &#8211;<br />
Source: US-CERT</p>
<p><a name="affected"></a></p>
<h3>Systems Affected</h3>
<ul>
<li>Adobe Reader version 8.1.1 and earlier</li>
<li>Adobe Acrobat Professional, 3D, and Standard versions 8.1.1 and earlier</li>
</ul>
<p><a name="overview"></a></p>
<h2>Overview</h2>
<p>Adobe has released Security advisory  <a href="http://www.adobe.com/support/security/advisories/apsa08-01.html">APSA08-01</a> to address multiple vulnerabilities affecting Adobe Reader and Acrobat. The most severe of these vulnerabilities could allow a remote attacker to execute arbitrary code.<br />
<a name="description"></a></p>
<h2>I. Description</h2>
<p>Adobe Security advisory <a href="http://www.adobe.com/support/security/advisories/apsa08-01.html">APSA08-01</a> addresses a number of vulnerabilities affecting the Adobe Acrobat family of products, including Adobe Reader. Acrobat versions 8.1.1 and earlier are affected. Further details are available in the US-CERT <a href="http://www.kb.cert.org/vuls/byid?searchview&amp;query=APSA08-01">Vulnerability Notes Database</a>.</p>
<p>An attacker could exploit these vulnerabilities by convincing a user to load a specially crafted Adobe Portable Document Format (PDF) file. Acrobat integrates with popular web browsers, and visiting a web site is usually sufficient to cause Acrobat to load PDF content.</p>
<p>At least one of these vulnerabilities is being actively exploited.  The SANS Internet Storm Center <a href="http://isc.sans.org/diary.html?storyid=3958">Handler&#8217;s Diary</a> contains more information.<br />
<a name="impact"></a></p>
<h2>II. Impact</h2>
<p>The impacts of these vulnerabilities vary. The most severe of these vulnerabilities allows a remote attacker to execute arbitrary code.<br />
<a name="solution"></a></p>
<h2>III. Solution</h2>
<h4>Upgrade</h4>
<p>Upgrade Adobe Reader or Acrobat to version 8.1.2 according to the information in Adobe Security advisory <a href="http://www.adobe.com/support/security/advisories/apsa08-01.html">APSA08-01</a>.</p>
<h4>Disable web browser display for PDF documents</h4>
<p>Preventing PDF documents from opening inside a web browser may mitigate this vulnerability. Applying the following workaround in conjunction with upgrading may prevent similar vulnerabilities from being automatically exploited.</p>
<p>To prevent PDF documents from automatically being opened in a web browser with Acrobat or Reader:</p>
<ol>
<li>Open Adobe Acrobat or Adobe Reader.</li>
<li>Open the <em>Edit</em> menu.</li>
<li>Choose the <em>Preferences</em> option.</li>
<li>Choose the <em>Internet</em> section.</li>
<li>De-select the <em>&#8220;Display PDF in browser&#8221;</em> check box.</li>
</ol>
<h4>Disable automatic opening of PDF documents in Microsoft Internet Explorer</h4>
<p>To disable automatic opening of PDF files in Microsoft Internet Explorer (IE), a second step is required. To configure IE to prompt before opening a PDF file, disable the &#8220;Display PDF in browser&#8221; feature (as described above) and then make the following changes to the Windows registry:</p>
<ul><font face="courier"> Windows Registry Editor Version 5.00</p>
<p>[HKEY_CLASSES_ROOT\AcroExch.Document.7]<br />
&#8220;EditFlags&#8221;=hex:00,00,00,00<br />
</font></ul>
<h4>Disable JavaScript in Adobe Reader and Acrobat</h4>
<p>Disabling JavaScript in Adobe Reader and Acrobat may prevent this vulnerability from being exploited. In Acrobat Reader, JavaScript can be disabled in the General preferences dialog (<em>Edit</em> &#8211;&gt; <em>Preferences</em> &#8211;&gt; <em>JavaScript</em>, de-select <em>Enable Acrobat JavaScript</em>).</p>
<h2>IV. References</h2>
<ul>
<li>US-CERT Vulnerability Notes for Adobe Security advisory APSA08-01 &#8211; &lt;<a href="http://www.kb.cert.org/vuls/byid?searchview&amp;query=APSA08-01">http://www.kb.cert.org/vuls/byid?searchview&amp;query=APSA08-01</a>&gt;</li>
<li> Securing Your Web Browser &#8211; &lt;<a href="http://www.us-cert.gov/reading_room/securing_browser/">http://www.us-cert.gov/reading_room/securing_browser/</a>&gt;</li>
<li>Adobe Security Advisory APSA08-01 &#8211; &lt;<a href="http://www.adobe.com/support/security/advisories/apsa08-01.html">http://www.adobe.com/support/security/advisories/apsa08-01.html</a>&gt;</li>
<li>Adobe Reader 8.1.2 Release Notes &#8211; &lt;<a href="http://www.adobe.com/go/kb403079">http://www.adobe.com/go/kb403079</a>&gt;</li>
<li>SANS Internet Storm Center Handler&#8217;s Diary &#8211; &lt;<a href="http://isc.sans.org/diary.html?storyid=3958">http://isc.sans.org/diary.html?storyid=3958</a>&gt;</li>
<li>Configuring Windows Explorer &#8211; Registry EditFlags &#8211; &lt;<a href="http://mc-computing.com/WinExplorer/WinExplorerEditFlags.htm">http://mc-computing.com/WinExplorer/WinExplorerEditFlags.htm</a>&gt;</li>
<li>Internet Explorer Opens .exe Files Instead of Downloading Them &#8211; &lt;<a href="http://support.microsoft.com/kb/140991">http://support.microsoft.com/kb/140991</a>&gt;</li>
<li>Office Documents opening in IE &#8211; &lt;<a href="http://blogs.msdn.com/omars/archive/2004/04/29/123181.aspx">http://blogs.msdn.com/omars/archive/2004/04/29/123181.aspx</a>&gt;</li>
</ul>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=257004110992506&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.ridhzuanharun.com/adobe-reader-and-acrobat-vulnerabilities/" send="true" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div>]]></content:encoded>
			<wfw:commentRss>http://www.ridhzuanharun.com/adobe-reader-and-acrobat-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MA-119.102007: MyCERT Special Alert &#8211; Festive Season and Long Holiday Alert</title>
		<link>http://www.ridhzuanharun.com/ma-119102007-mycert-special-alert-festive-season-and-long-holiday-alert/</link>
		<comments>http://www.ridhzuanharun.com/ma-119102007-mycert-special-alert-festive-season-and-long-holiday-alert/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 00:02:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Public Announcement]]></category>
		<category><![CDATA[Security Findings]]></category>

		<guid isPermaLink="false">http://ridhzuanharun.com/?p=30</guid>
		<description><![CDATA[A public service announcement by MyCert for Malaysian
Original Issue Date: 10th October 2007
With the coming festive season and long holiday break, MyCERT would like to alert all System Administrators, Network Administrators, IT Personnel and Internet users to properly secure/harden their [...]]]></description>
			<content:encoded><![CDATA[<p><em>A public service announcement by <a href="http://www.mycert.org.my/" target="_blank">MyCert</a> for Malaysian</em></p>
<p>Original Issue Date: 10th October 2007</p>
<p>With the coming festive season and long holiday break, MyCERT would like to alert all System Administrators, Network Administrators, IT Personnel and Internet users to properly secure/harden their systems and networks before they leave for their long holidays.</p>
<p>Based on our experience, we had security incidents with servers compromised and websites defaced during festive seasons/long holiday break. Thus, with the release of the alert, we hope such incidents could be prevented.</p>
<p>System Administrators, Network Administrators should take extra precautions against any possibilities of web defacements and malicious code activities during the festive and long holiday season, by implementing proper preventive measures against the above threats. However, other threats such as Denial of Service and Hack threats should not be overlooked. Data Center Administrators should also take extra precautions against any possibilities of mass defacements involving virtual hosting servers. We have been seeing the trend of mass defacements involving virtual hosting servers belonging to data centers.</p>
<p>Financial Institutions must also be vigilant against any possibilities of phishing activities that target the internet bankings. Customers must be advised adequately on avoiding themselves becoming victims of phishing activities by applying safe browsing and safe internet banking practice.</p>
<p>Make sure contact information of your system, network or security administrator is available in the event of a security incident occurring at or originating from your site/network.</p>
<p>Attached below are some useful guidelines and measures that you may follow to ensure that your systems and networks are properly secured, thus preventing them from being compromised:</p>
<p>1.Make sure all your systems are installed with latest service packs and patches.</p>
<p>If you&#8217;re running older versions of operating systems or softwares, make sure you have upgraded them to the latest versions as older versions may have some vulnerabilities that can be manipulated by intruders Aside from that, please make sure that your web based applications and network based appliances are patched accordingly.</p>
<p>You may refer to your respective vendors for the latest patches, service packs and upgrades.<br />
2.If you&#8217;re running services, make sure you close unneeded services/ports and other required services should be filtered and patched accordingly.<br />
3.Make sure anti-virus softwares that are running on your hosts and email gateways are updated with latest signature files and are enabled to scan all files.</p>
<p>You may refer to the AV sites at: http://www.mycert.org.my/anti-virus.htm<br />
4.Please check that your systems and networks are configured properly in order to avoid any unnecessary incidents caused by system misconfiguration.<br />
5.Make sure loggings of your systems and servers are properly enabled.<br />
6.Make sure you back up important and relevant data from all your systems.<br />
7.Organizations are recommended to apply defense in depth strategy in protecting their networks. Firewalls, intrusion prevention systems (IPS), network and host based intrusion detection systems (IDS) can prevent and log most of the generic attacks.</p>
<p>List of several Intrusion Detection Systems</p>
<p>http://www.mycert.org.my/resource/ids.htm</p>
<p>8.Home Users who are using PCs/computers at home are advised to:<br />
1.Make sure your PCs, browsers are installed with latest service packs or patches.<br />
2.Install an Anti-Virus software on your PCs which scans and blocks any worms /viruses/malware to the PC. The Anti-virus should be regularly updated with latest signature files in order to detect new worms/viruses.</p>
<p>You may refer to the following AV sites to download anti-virus software.</p>
<p>http://www.mycert.org.my/anti-virus.htm</p>
<p>3.It is recommended for home users to install personal firewalls on their PCs. A personal firewall is capable of blocking and alerting the owner of malicious and suspicious activities.</p>
<p>More information on home user PC security is available at:</p>
<p>http://www.mycert.org.my/homepcsecurity.html</p>
<p>4.Implement safe email-practices.</p>
<p>Safe-email practices document is available at:</p>
<p>http://www.mycert.org.my/faq-safe_email_practices.htm</p>
<p>Please take note that MyCERT is available 24&#215;7 during the festive season/long holiday break for incident reporting and users/organizations may contact us for assistance.</p>
<p>MyCERT can be reached at:</p>
<p>E-mail : mycert@mycert.org.my<br />
Phone : +603 89926969 (monitored during business hours)<br />
Fax : +603 89453442 (monitored during business hours)<br />
Handphone : +60 19 2665850 (24&#215;7 call incident reporting)<br />
SMS : +60 19 2813801 (24&#215;7 SMS reporting)<br />
Business Hours : Mon &#8211; Fri 08:30 -17:30 MYT<br />
Web: http://www.mycert.org.my</p>
<p>Postal : Malaysian Computer Emergency Response Team (MyCERT)<br />
CyberSecurity Malaysia<br />
Level 7, SAPURA@MINES<br />
7, Jalan Tasik, The Mines Resort City<br />
43300 Seri Kembangan<br />
Selangor Darul Ehsan<br />
MALAYSIA</p>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=257004110992506&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.ridhzuanharun.com/ma-119102007-mycert-special-alert-festive-season-and-long-holiday-alert/" send="true" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div>]]></content:encoded>
			<wfw:commentRss>http://www.ridhzuanharun.com/ma-119102007-mycert-special-alert-festive-season-and-long-holiday-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Updates for Multiple Vulnerabilities</title>
		<link>http://www.ridhzuanharun.com/microsoft-updates-for-multiple-vulnerabilities/</link>
		<comments>http://www.ridhzuanharun.com/microsoft-updates-for-multiple-vulnerabilities/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 23:53:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Findings]]></category>

		<guid isPermaLink="false">http://ridhzuanharun.com/?p=29</guid>
		<description><![CDATA[Written by Administrator
Wednesday, 10 October 2007
Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Microsoft Internet Explorer, Microsoft Outlook Express and Windows Mail, Microsoft Office, Microsoft Office for Mac, and Microsoft SharePoint. Exploitation of these vulnerabilities could allow [...]]]></description>
			<content:encoded><![CDATA[<p>Written by Administrator<br />
Wednesday, 10 October 2007</p>
<p>Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Microsoft Internet Explorer, Microsoft Outlook Express and Windows Mail, Microsoft Office, Microsoft Office for Mac, and Microsoft SharePoint. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.<br />
Systems Affected</p>
<p>* Microsoft Windows<br />
* Microsoft Internet Explorer<br />
* Microsoft Outlook Express and Windows Mail<br />
* Microsoft Office<br />
* Microsoft Office for Mac<br />
* Microsoft SharePoint</p>
<p>I. Description</p>
<p>Microsoft has released updates to address vulnerabilities that affect Microsoft Windows, Microsoft Internet Explorer, Microsoft Outlook Express and Windows Mail, Microsoft Office, Microsoft Office for Mac, and Microsoft SharePoint as part of the Microsoft Security Bulletin Summary for October 2007. The most severe vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.</p>
<p>Further information about the vulnerabilities addressed by these updates is available in the Vulnerability Notes Database.<br />
II. Impact</p>
<p>A remote, unauthenticated attacker could execute arbitrary code on a vulnerable system. An attacker may also be able to cause a denial of service.<br />
III. Solution<br />
Apply updates from Microsoft</p>
<p>Microsoft has provided updates for these vulnerabilities in the October 2007 security bulletins. The security bulletins describe any known issues related to the updates. Administrators are encouraged to note any known issues that are described in the bulletins and test for any potentially adverse effects.</p>
<p>System administrators should consider using an automated patch distribution system such as Windows Server Update Services (WSUS).<br />
IV. References</p>
<p>* US-CERT Vulnerability Notes for Microsoft October 2007 updates &#8211; http://www.kb.cert.org/vuls/byid?searchview&amp;query=ms07-oct<br />
* Microsoft Security Bulletin Summary for October 2007 &#8211; http://www.microsoft.com/technet/security/bulletin/ms07-oct.mspx<br />
* Microsoft Update &#8211; https://update.microsoft.com/microsoftupdate/<br />
* Windows Server Update Services &#8211; http://www.microsoft.com/windowsserversystem/updateservices/default.mspx<br />
* Securing Your Web Browser &#8211; http://www.cert.org/tech_tips/securing_browser/<br />
* Mactopia &#8211; http://www.microsoft.com/mac/</p>
<p>Original Article : http://www.us-cert.gov/cas/techalerts/TA07-282A.html</p>
<p>Last Updated ( Monday, 05 November 2007 )</p>
<p>* original resources from <a href="http://gcert.mampu.gov.my/" target="_blank">Government Computer Emergency Response Team</a></p>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=257004110992506&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.ridhzuanharun.com/microsoft-updates-for-multiple-vulnerabilities/" send="true" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div>]]></content:encoded>
			<wfw:commentRss>http://www.ridhzuanharun.com/microsoft-updates-for-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eTicket &#8220;open.php&#8221; Cross-Site Scripting</title>
		<link>http://www.ridhzuanharun.com/eticket-openphp-cross-site-scripting/</link>
		<comments>http://www.ridhzuanharun.com/eticket-openphp-cross-site-scripting/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 23:50:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Findings]]></category>

		<guid isPermaLink="false">http://ridhzuanharun.com/?p=28</guid>
		<description><![CDATA[Jesper Jurcenoks has discovered two vulnerabilities in eTicket, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed to the &#8220;err&#8221; and &#8220;warn&#8221; parameters in open.php is not properly sanitised before being returned to the user. [...]]]></description>
			<content:encoded><![CDATA[<p>Jesper Jurcenoks has discovered two vulnerabilities in eTicket, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed to the &#8220;err&#8221; and &#8220;warn&#8221; parameters in open.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site.</p>
<p>Successful exploitation requires that &#8220;register_globals&#8221; is enabled&#8230;<br />
The vulnerabilities are confirmed in versions 1.5.5 and 1.5.5.1. Other versions may also be affected.</p>
<p><strong>Solution</strong>:<br />
Edit the source code to ensure that input is properly sanitised.</p>
<p><strong>Provided and/or discovered by</strong>:<br />
Jesper Jurcenoks</p>
<p><strong>Original Article:<br />
<a href="http://secunia.com/advisories/25871/" target="_blank"><u><font color="#0000ff">http://secunia.com/advisories/25871/</font></u></a></strong></p>
<p>* original resources from <a href="http://gcert.mampu.gov.my/" target="_blank">Government Computer Emergency Response Team</a></p>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=257004110992506&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.ridhzuanharun.com/eticket-openphp-cross-site-scripting/" send="true" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div>]]></content:encoded>
			<wfw:commentRss>http://www.ridhzuanharun.com/eticket-openphp-cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

