Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/3506.mp3
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
Cisco ACS Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130828-acs
Tor Usage Increases
https://metrics.torproject.org/users.html?graph=direct-users&start=2013-05-30&end=2013-08-28&country=all&events=off#direct-users
Java 6 Vulnerability Exploited
https://twitter.com/TimoHirvonen/status/371954767838208001
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130828-acs
Tor Usage Increases
https://metrics.torproject.org/users.html?graph=direct-users&start=2013-05-30&end=2013-08-28&country=all&events=off#direct-users
Java 6 Vulnerability Exploited
https://twitter.com/TimoHirvonen/status/371954767838208001
Discussion
We are using a log and event manager software which incorporates its own installation of Java 6. Towards the end of the year they will be issuing a software update which will use whatever the latest version of Java 7 is, but there will not be a feature for software subscribers to keep that version up to date. Since this installation of Java is not in the default install location for Java, and since the nodes on which the log and event manager agent is being installed are not used to browse the web, are we really secure from future vulnerabilities found in Java? In other words, would updating the default installation of Java be enough to keep these nodes secure from Java vulnerabilities? The vendor says their installation is sandboxed.
Posted by LawsonPoling on Thu Aug 29 2013, 13:32
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Network Monitoring and Threat Detection In-Depth | Baltimore | Mar 3rd - Mar 8th 2025 |
Application Security: Securing Web Apps, APIs, and Microservices | Orlando | Apr 13th - Apr 18th 2025 |