最近信箱收到一些垃圾郵件是有關新年快樂的訊息,但此信件中包含可下載風暴蠕蟲 (Storm Worm) 的連結,下載檔案名稱為 happy-2008.exe,可見此病毒的作者又開始利用「放年假的心態」,以散播新變種的風暴蠕蟲,請各位小心囉。

詳文請按此 rogerspeaking.blogspot.com/2007/12/blog-post_9976.html

昨天收到從一個朋友的MSN傳送過來的一個樣本,名為「christmas-2007.zip」,壓縮檔中包含一個名為 「img2007-12.JPEG.scr」的檔案,分析後,它具有惡意行為,請各位小心囉。


北軟股份有限公司網站被植入惡意連結,此惡意程式為 TROJ_SMALL.DXW,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒。(Credit: 匿名網友)

相關資訊 http://www.blackhat.com/html/bh-dc-08/bh-dc-08-main.html

Secunia Advisory: SA28196  
Release Date: 2007-12-21

Less critical
Impact: Cross Site Scripting

Secunia Advisory: SA28186  
Release Date: 2007-12-21

Less critical
Impact: Cross Site Scripting

ecunia Advisory: SA28166  
Release Date: 2007-12-21

Less critical
Impact: Spoofing

Published: 2007-12-24,
Last Updated: 2007-12-24 03:41:39 UTC
by Kevin Liston (Version: 2)

December 19, 2007
By  Ryan Naraine

Adobe Flash player における複数の脆弱性に対するアップデート


Adobe から、Flash player の複数の脆弱性に対するアップデートが公開されました。

December 21, 2007
By  Ryan Naraine

December 21, 2007
By  Paul A. Strassmann
Access to Web applications is typically the most frequent use of a personal computer. Whether this should be done by means of a "fat" computer or by the increasingly available "thin" client is a question on many enterprises' agendas.

1. 1433端口入侵
scanport.exe 查有1433的機器
SQLScanPass.exe 進行字典暴破(字典是關鍵)

