The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015

Open source hardware can protect against NSA spying

Open source hardware can protect against NSA spying

Eli Dourado from George Mason University suggested to use an open source hardware in order to protect the companies against NSA spying. It will more effectively detect backdoors and vulnerabilities that are built by NSA or other government agencies in the companies' system.

"To make the Internet less susceptible to mass surveillance, we need to recreate the physical layer of its infrastructure on the basis of open-source principles," stated Dourado.

According to the researcher, the use of hardware with open source will succeed, since everyone will be able to modify it, and then provide a modified version to the others. This policy had positive results with the open source software, including Linux and Apache web-servers.

The information about the NSA and U.S. intelligence agencies surveillance became available thanks to the former NSA employee Edward Snowden. At the moment we know that the NSA was gaining access to confidential data on users of services and products provided by Microsoft, Apple and Google.

The documents revealed by Snowden also stated that NSA could intercept Internet traffic through routers and switches. The open source hardware will be really difficult to tap.

Opponents of Dourado’s policies say that, in practice, it will be very difficult for companies to keep track of all hardware upgrades , especially to continuously examine updates of low-level code in hardware.

(c) Naked Security


Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015