CRA Maldoc Analysis, (Sun, Feb 26th) SANS Internet Storm Center, InfoCON: green(cached at February 26, 2017, 11:30 pm)

I took a look at Guy font-family:Helvetica Neue width:1267px" />

tevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Google Discloses Yet Another New Unpatched Microsoft Vulnerability In Edge/IE Slashdotby EditorDavid on bug at January 1, 1970, 1:00 am (cached at February 26, 2017, 11:03 pm)

An anonymous reader quotes BleepingComputer: Google has gone public with details of a second unpatched vulnerability in Microsoft products, this time in Edge and Internet Explorer, after last week they've published details about a bug in the Windows GDI (Graphics Device Interface) component... The bug, discovered by Google Project Zero researcher Ivan Fratric, is tracked by the CVE-2017-0037 identifier and is a type confusion, a kind of security flaw that can allow an attacker to execute code on the affected machine, and take over a device. Details about CVE-2017-0037 are available in Google's bug report, along with proof-of-concept code. The PoC code causes a crash of the exploited browser, but depending on the attacker's skill level, more dangerous exploits could be built... Besides the Edge and IE bug, Microsoft products are also plagued by two other severe security flaws, one affecting the Windows GDI component and one the SMB file sharing protocol shipped with all Windows OS versions... Google's team notified Microsoft of the bug 90 days ago, only disclosing it publicly on Friday.

Read more of this story at Slashdot.

Do talks on Syria serve any purpose? AL JAZEERA ENGLISH (AJE)(cached at February 26, 2017, 10:30 pm)

Another round of talks on Syria get under way as an attack in Homs claims the lives of senior military officers.
Do talks on Syria serve any purpose? AL JAZEERA ENGLISH (AJE)(cached at February 26, 2017, 10:30 pm)

Another round of talks on Syria get under way as an attack in Homs claims the lives of senior military officers.
The Kool Desktop Environment (IT Toolbox Blogs) SANS ISC SecNewsFeed(cached at February 26, 2017, 10:30 pm)

The memory lane continues (IT Toolbox Blogs) SANS ISC SecNewsFeed(cached at February 26, 2017, 10:30 pm)

Git lt;codegt;fscklt;/codegt;ed by SHA-1 collision? Not so fast, says Linus Torvalds SANS ISC SecNewsFeed(cached at February 26, 2017, 10:30 pm)

Apache Subversion Fails SHA-1 Collision Test, Exploit Moves Into The Wild Slashdotby EditorDavid on security at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:04 pm)

WebKit's bug-tracker now includes a comment from Friday noting "the bots all are red" on their git-svn mirror site, reporting an error message about a checksum mismatch for shattered-2.pdf. "In some cases, due to the corruption, further commits are blocked," reports the official "Shattered" web site. Slashdot reader Artem Tashkinov explains its significance: A WebKit developer who tried to upload "bad" PDF files generated from the first successful SHA-1 attack broke WebKit's SVN repository because Subversion uses SHA-1 hash to differentiate commits. The reason to upload the files was to create a test for checking cache poisoning in WebKit. Another news story is that based on the theoretical incomplete description of the SHA-1 collision attack published by Google just two days ago, people have managed to recreate the attack in practice and now you can download a Python script which can create a new PDF file with the same SHA-1 hashsum using your input PDF. The attack is also implemented as a website which can prepare two PDF files with different JPEG images which will result in the same hash sum.

Read more of this story at Slashdot.

POE-Component-Server-Discard-1.16 search.cpan.orgby Chris Williams at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

A POE component that implements an RFC 863 Discard server.
POE-Component-Server-Daytime-1.16 search.cpan.orgby Chris Williams at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

A POE component that implements an RFC 867 Daytime server.
POE-Component-Server-Qotd-1.16 search.cpan.orgby Chris Williams at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

A POE component that implements an RFC 865 QotD server.
Config-Model-2.098 search.cpan.orgby Dominique Dumont at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

Create tools to validate, migrate and edit configuration files
POE-Component-Server-Time-1.16 search.cpan.orgby Chris Williams at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

A POE component that implements an RFC 868 Time server.
X-Tiny-0.01-TRIAL search.cpan.orgby Felipe Gasper at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

Super-lightweight exception framework
Bot-ChatBots-Telegram-0.005-TRIAL search.cpan.orgby Flavio Poletti at January 1, 1970, 1:00 am (cached at February 26, 2017, 10:03 pm)

Telegram adapter for Bot::ChatBots