Security Newsbites for 7/17
Some recent security-related news:
- Offsensive Security announces Free “Metasploit Unleashed – Mastering the Framework” Class The Offensive Security team (makers of BackTrack) announced a new free online course yesterday. The course materials and labs will be available online for free, and the videos will require a small fee with all proceeds going to benefit Hackers for Charity.
- Nmap 5.0 Released Big release of Nmap with the “Top 5 Improvements” being the addition of the ncat (Nmap’s written from scratch version of netcat with new features), ndiff scan comparison tool, better performance, release of the Nmap Network Scanning book, and the Nmap Scripting Engine.
- Firefox 3.5 0-day released, now patched Critical bug in Firefox 3.5 that was exploitable on Mac, Linux, and Windows. Carlos “Dark0perator” Perez posted an article about how to use Metasploit to test your susceptibility to the bug.
- milw0rm, the famed exploit posting portal, almost closes due to a lack of str0ke’s time to process all the incoming exploits. Some of his friends stepped forward and offered to help with the posting of exploits and the site was saved.
- Linux kernel 2.6.30 Critical Bug This is supposed to be exploitable on both 32- and 64-bit systems but there appears to be some debate in the comments about how vulnerable an SMP or preemptible system may be to it.
- ISC DHCP dhclient has a critical bug