The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
02/23/2015

Linux.Zorroten

Type:  Trojan
Discovered:  23.02.2015
Updated:  23.02.2015
Affected systems:  Linux
AV Vendor:  Symantec

Description:

When the Trojan is executed, it changes its process name to the following:
  • n1mWrb6l1t67Gvj

The Trojan then scans random IP addresses for Telnet services (TCP port 23) using the following user name/password combinations:
  • root/root
  • root/admin
  • root/[BLANK]
  • root/1234
  • root/12345
  • root/123456
  • root/1111
  • root/password
  • root/dreambox
  • root/vizxv
  • root/system
  • admin/admin
  • admin/[BLANK]
  • admin/password
  • admin/1234
  • admin/12345
  • admin/123456
  • admin/1111
  • admin/smcadmin
  • admin/4321
  • support/support

If the Trojan is able to gain access to a Telnet service, it then sends the IP address, user name, and password to the following remote location:
  • [http://]104.192.0.18/[REMOVED]

Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015