CERT

Recently in Analysis Category

Safely Using Package Managers

Hi, it's Ryan. Package managers partially automate the process of installing and removing software packages. Most package managers use cryptographic signatures to verify the integrity of packages. In the article Attacks on Package Managers, the authors describe how an attacker can abuse package managers that use digital signatures.




Continue reading Safely Using Package Managers.

Signed Java Applet Security: Worse than ActiveX?

Hi, it's Will again. ActiveX vulnerabilities seem to be getting a lot of attention lately. However, Java applets are also a concern.


Continue reading Signed Java Applet Security: Worse than ActiveX?.

Is Your Adobe Flash Player Updated?

Hey, it's Will. As you may already be aware, there is active exploitation of a vulnerability in Adobe Flash. So, it's a good idea to make sure that you have the latest version of Flash Player, which, at the time of this writing, is 9.0.124.0. Even if you think that you are up to date, can you be sure?


Continue reading Is Your Adobe Flash Player Updated?.

Who has my cookies?

Hi, Ryan Giobbi from the Vulnerability Analysis team making this post. The CERT/CC has been tracking cross-site scripting vulnerabilities for a long time, and the actual vulnerabilities haven't changed much over the years. However, some technology that was developed to make life easier can actually be exploited to expand the impact of a cross-site scripting attack.


Continue reading Who has my cookies?.

The Dangers of Windows AutoRun

Hi, this is Will Dormann of the CERT/CC Vulnerability Analysis team. A few months ago, reports of infected digital picture frames hit the media. I was curious about how the malicious code was being executed, so I began investigating the Microsoft AutoRun and AutoPlay features.


Continue reading The Dangers of Windows AutoRun.

Vulnerability Analysis at the CERT/CC

Hi, this is Art Manion, the Vulnerability Analysis team lead at the CERT Coordination Center (CERT/CC). For our first blog entry, I'd like to briefly explain our efforts to reduce software vulnerabilities.




Continue reading Vulnerability Analysis at the CERT/CC.