Posted by . in Computer, Event.
Another security seminar in town! Opened for all people who interest in Security computer area. This is a FREE seminar, but since the seats are limited, please do the RSVP immediately by June 26th (the latest) to dian@securityfirst.or.id with the complete data below:
Name :
Name of Company :
Title :
Mobile No :
Email :
For information contact:
Dian Novita Elfrida
Email: dian@securityfirst.or.id
08129528451/02193887474
Source: http://think.securityfirst.web.id/?page_id=1215
Posted by . in Computer, News, Social Life.

Description:
Some vulnerabilities have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), disclose sensitive information, conduct cross-site scripting and cross-site request forgery attacks, or compromise a user’s system.
- Multiple vulnerabilities in CoreGraphics can be exploited by malicious people to compromise a user’s system.
- An error in the handling of untrusted Exchange server certificates can lead to the disclosure of credentials or application data due to the certificate being accepted with no prompt and validation.
- A vulnerability in ImageIO can be exploited by malicious people to compromise a user’s system.
- A vulnerability in International Components for Unicode can be exploited by malicious people to bypass certain security restrictions.
- Some vulnerabilities in IPSec can be exploited by malicious people to cause a DoS (Denial of Service).
- Some vulnerabilities in libxml2 can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
- A weakness in Mail can result in a phone call being initiated without user interaction if an application causes an alert during the call approval dialog.
- An input validation error in the handling of MPEG-4 video files can lead to an unexpected device reset.
- Clearing Safari’s history via the Settings application can lead to disclosure of the search history.
- An assertion error in the handling of ICMP echo request packets can be exploited to cause a device reset via a specially crafted ICMP echo request.
- Some vulnerabilities in WebKit can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to compromise a user’s system.
- An error in the separation of JavaScript contexts can be exploited to overwrite the “document.implementation” of an embedded or parent document served from a different security zone.
- A type conversion error exists in the JavaScript exception handling in WebKit. This can be exploited to corrupt memory when assigning the exception to a variable that is declared as a constant and may allow execution of arbitrary code when a user visits a specially crafted web site.
- An error in the JavaScript garbage collector implementation can potentially be exploited to corrupt memory and execute arbitrary code.
- Multiple unspecified errors in the handling of javascript objects can potentially be exploited to conduct cross-site scripting attacks.
- An error in WebKit can be exploited to alter standard JavaScript prototypes of websites served from a different domain.
- An error in WebKit in the handling of HTMLSelectElement objects can be exploited to cause a device reset.
- An error in WebKit can be exploited to load and capture an image from another website by using a canvas and a redirect.
- An error in WebKit allows frames to be accessed by an HTML document after a page transition, which can be exploited to conduct cross-site scripting attacks.
- An error in the handling of XMLHttpRequest headers in WebKit can be exploited to bypass the same-origin policy.
- Use-After-Free error exists in WebKit within the handling of the JavaScript DOM, which can potentially be exploited to execute arbitrary code.
- An error in WebKit within the handling of Location and History objects can be exploited to conduct cross-site scripting attacks.
Solution:
Update to iPhone OS 3.0 or iPhone OS for iPod touch 3.0 (downloadable and installable via iTunes).
For more details: http://secunia.com/advisories/35449/
Posted by . in Computer, Event.

ID-SEC-CONF atau juga Indonesian security conference adalah salah satu ajang silaturahmi nasional bagi para peminat keamanan teknologi informasi dari seluruh penjuru nusantara. Salah satu tujuan dari di adakannya acara ini adalah agar terjadinya knowledge sharing khususnya masalah keamanan teknologi informasi, yang akhirnya akan menghindarkan kita semua dari keterpurukan dan kesenjangan pengetahuan *huahaha*. Menurut gue pribadi, acara ini bagus karena event seperti ini agak jarang di adakan, terlebih acara ini fokus terhadap network security. Untuk itu, marilah bersama-sama kita dukung acara ini agar dapat terwujud, karena insya allah dapat memberikan manfaat yang lebih baki para pelaku IT Security.
Info lebih lanjut, lihat: http://idsecconf.echo.or.id/