Showing posts with label Critical. Show all posts
Showing posts with label Critical. Show all posts

Sunday, September 29, 2013

Declassified Documents show NSA spied on Martin Luther King Jr., Muhammad Ali and Art Buchwald to be critical of the war


A declassified NSA document reveals that the Agency spied on communications of Muhammad Ali, Art Buchwald and MLK.


During the middle of the protest against the Viet Nam war, NSA has done some spying activities. Some classified NSA documents have been show this Wednesday declassified as they revealed that the NSA agents tapped communications overseas who were current among some critics of the war. The names include Muhammad Ali, Senator Frank Church and Martin Luther King Jr. It also includes the name of the Washington Post humor columnist i.e. Art Buchwald.


During the middle of the protest against the Viet Nam war, NSA has done some spying activities. Some of the declassified NSA classified documents as they were revealed Wednesday show that officials of the NSA on interception of communications that were underway overseas between critics of the war. The names include Muhammad Ali, Senator Frank Church and Martin Luther King Jr. It also includes the name of the Washington Post humor columnist i.e. Art Buchwald


According to the documents, Howard Baker, another Senator, who was among the supporter of the war was also included in the list of targets to be subjected to monitoring. Surveillance includes communications overseas through telephone calls, traffic of cable and telex. The list, which includes almost 1600 names remained active in the period from 1967 to 1973.


Is no hidden fact that the Government was spying on the obvious war protesters and proponents of civil rights since the 1960s and 1970s. However, this last revelation of the secret history of the NSA, which has been released by the national security Archives has opened new chapters of NSA respect the communications of Americans. Well it really happened for some time.


Is no hidden fact that the Government was spying on the obvious war protesters and proponents of civil rights since the 1960s and 1970s. However, this last revelation of the secret history of the NSA, which has been released by the national security Archives has opened new chapters of NSA respect the communications of Americans. Well it really happened for some time.


The country burned in flames in 1967 as written in the notes of the internal history of the NSA. Johnson was taking steps to make sure if the nationwide protest that raged against the war was financed by an external force. The army and the CIA initially showed concerns about reservations expressed by the President and the FBI has prepared a list of names for this purpose. Listen job has been given to the NSA and he nicknamed the Minaret of the program in 1969.


Documents that have been revealed this Wednesday gave 7 names that includes Larry King and his compatriot Whitney Young who was a civil rights leader, Muhammad Ali, boxing legislators Baker champion and the Church, a columnist for the New York Times Tom Wicker and Buchwald.


Matthew M. Aid, who is a historian of the analyst and deals with the study of the history of NSA intelligence has said that "it has no knowledge on why Artie Buchwald and Tom Wicker were there in the list."


According to documents, counsel of the NSA, who later went on to examine the program says that people who have been involved in the list appear to have an idea that the program was disreputable.


According to William Burr and aid, Buchwald, at that time wrote some very scathing columns in the Viet Nam war-related. One of the columns by Buchwald suggested it had cost about 332,000 US dollars for killing a single soldier. He argued in the column that he would have been less expensive and effective if the Government would have offered Cong defectors, a House with a value of $ 25000, a television and education of children.


The aid is of the column was not sufficient to give NSA the right to Buchwald on the list.


 

Thursday, September 19, 2013

Critical vulnerability: buy any product on eBay to only 0.01 USD

Have you thought about buying an iPhone or a free Play Station? Well, you could, but it's too late now, as an Indian security researcher goes with the handful of Ishwar Prasad Bilodeau had found a vulnerability criticizes largest online shopping site eBay in the world which allowed users to buy any product in only 1 equivalent of Indian rupee at 0.01 USD.


The vulnerability has been discovered on designated Indian domain for eBay (www.ebay.in), which was set yesterday  Ishwar reported it to authorities eBay on August 6, 2013.


In a conversation by email, security researcher told me about the vulnerability that, with the help of this bug, he was able to buy the most expensive product on eBay in just 1 Indian rupee.


However, Ishwar won't be paid to save eBay of loose millions of dollars that the company does not any program of premiums for bug like Facebook and Microsoft. As a reward, eBay said its name on their official website in the list of security researchers who helped the company in determining critical vulnerabilities.


Here is the link where eBay acknowledged 122 researchers including Ishwar Prasad Bhat services.


Ishwar is a first year student of 18 years of collage Veltechmulti Tech Engineering to Avadi, Chennai city, India.

Friday, September 13, 2013

Blog: Microsoft Updates September 2013 - Critical Server and Client Side RCE Vulnerabilities in IE, Outlook, Built-in Windows Components and Sharepoint

Microsoft releases a long list of security bulletins this month on the server and client side, patching a longer list of vulnerabilities in this month's array of technologies. Only four of the bulletins are rated "critical" this month: Internet Explorer, a variety of built-in Windows components, and Sharepoint and Office Web Services. Thirteen security bulletins are released in total, patching almost fifty vulnerabilities. Mostly every one of this month's vulnerabilities were reported privately, other than the XSS vulnerability in Sharepoint, which Microsoft claims would be difficult to exploit. In all likelihood, at some point Windows folks will have to reboot following download and install of around 100Mb of system updates this month.


For mass exploitation purposes, the most problematic issues have to do with Internet Explorer, with working exploits likely being developed in the near future to attack these memory corruption vulnerabilities. These are the sort of things that can happen to anyone online, so all Windows users should address them asap. These ten vulnerabilities enable remote code execution across all supported versions of IE across all Windows clients and servers, so most likely, they will receive immediate attention from the offensive security global peanut gallery.

Follow me on Twitter

On the targeted attack side, Sharepoint and Web Office Service administrators need to be aware of the critical vulnerabilities addressed with the large cumulative update MS013-067. Flaws in this code base enable RCE that could be exploited with the spear phishing techniques very commonly and effectively in use.


Also problematic from both perspectives is this interesting Outlook update, which patches a flaw in Outlook 2007 and 2010 S/MIME handling. It can be triggered in preview mode, which seems to make this the first severe, potentially wormable issue seen in Outlook in years. Patch immediately.


The long list of important updates are presented at Microsoft's Technet site here.

Friday, September 6, 2013

Blog: Microsoft Updates August 2013 - Critical Internet Explorer across All Windows Clients, OpenType Font Parsing, Exchange OWA Vulnerabilities Fixed

Today, Microsoft released a set of eight security Bulletins (MS13-059 through MS13-066) for a broad variety of vulnerable technologies and exploit categories. The critical vulnerabilities are not known to be exploited publicly at the time of Bulletin release. The more interesting Bulletins this month address RCE and EoP vulnerabilities in Internet Explorer, Windows components, and yet again Exchange/OWA components licensed from Oracle. Also included in this month's release are fixes for RPC, kernel drivers, Active Directory, and the networking stack.


MS13-059 is the priority update to roll out across Windows clients, as it fixes nine critical memory corruption vulnerabilities (that look like use-after-free to me) in IE6, IE7, IE8, IE9, IE10 and even IE11 preview on Windows 8.1 preview, along with XSS due to flawed Kanji font handling and flawed code in the "Windows Integrity Mechanism", which is used for sandboxing apps like Internet Explorer, Adobe Reader and Google Chrome. On Windows server, the maximum severity is "Moderate" and doesn't effect "Server Core" installations at all. Admins need to refer to the severity ratings and maximum impact table to prioritize server patch deployments, but those that need to prioritize patch deployments probably shouldn't surf the web from these types of systems anyway.

Follow me on Twitter

MS13-060 corrects code in the Unicode Scripts Processor implementing OpenType font handling, a format developed by Microsoft and Adobe over the past decade built on top of the TrueType format, in USB10.dll. This dll is used by Windows and all sorts of third party applications to handle right-to-left scripts like Arabic and Hebrew, and other complex fonts like Indian and Thai scripts too. The vulnerability is a user mode vulnerability that effects only Windows XP SP 2 and 3 (64 bit too) and Windows 2003 versions. These types of systems continue to be widely deployed, especially in government and critical infrastructure systems around the world. Exploits may be delivered via spearphish, as in the Duqu incident, or via a web page for a browser like Internet Explorer, as in Duqu copycat malcode like the Blackhole exploit pack that continues to be widely distributed and highly active.


Another interesting update includes MS13-061 that patches code in third party components built by Oracle and licensed by Microsoft for Outlook Web Access on Exchange Server 2007, 2010, and 2013. Applying the patch will not require a system reboot, but it will restart related Exchange services. The interesting thing about this critical set of issues is that they enable exploitation of the WebReady Document Viewing and Data Loss Prevention features on OWA for code execution not on the client system, but on the server itself with LocalService credentials. So a client system browsing code sent to their email account can remotely execute code on the server in the service's context, which is very problematic.


Please review the set and update ASAP. While most of the vulnerabilities this month were privately reported, these present high risk opportunities and the Exchange issues and exploitation are publicly known.

Popular Posts