Posted by jkouns
Fri, 01 Aug 2008 03:35:00 GMT
The OSVDB team will definitely be in Vegas this year. If you would like to meet up then please drop a line to moderators@osvdb.org and let us know. Typically we organize an OSVDB dinner but we have been a little slack in organizing it this year! If you are interested let us know and we will see what we can make happen…………………..
Look forward to seeing everyone soon………
Posted in OSVDB News | 3 comments
Posted by jkouns
Tue, 15 Jul 2008 04:39:00 GMT
The Open Security Foundation (OSF) is pleased to announce that the DataLossDB (also known as the Data Loss Database - Open Source (DLDOS) currently run by Attrition.org) will be formally maintained as an ongoing project under the OSF umbrella organization as of July 15, 2008.
Attrition.org’s Data Loss project, which was originally conceptualized in 2001 and has been maintained since July 2005, introduced DLDOS to the public in September of 2006. The project’s core mission is to track the loss or theft of personally identifying information not just from the United States, but across the world. As of June 4, 2008, DataLossDB contains information on over 1,000 breaches of personal identifying information covering over 330 million records.
DataLossDB has become a recognized leader in the categorization of dataloss incidents over the past several years. In an effort to build off the current success and further enhance the project, the new relationship with OSF provides opportunities for growth, an improved data set, and expanded community involvement. "We’ve worked hard to research, gather, and make this data open to the public," says Kelly Todd, one of the project leaders for DataLossDB. "Hopefully, the migration to OSF will lead to more community participation, public awareness, and consumer advocacy by providing an open forum for submitting information."
The Open Security Foundation’s DataLossDB will be free for download and use in non-profit work and research. The new website launch (http://www.datalossdb.org/) builds off of the current data set and provides an extensive list of new features. DataLossDB has attained rapid success due to a core group of volunteers who have populated and maintained the database. However, the new system will provide an open framework that allows the community to get involved and enhance the project. "For a data set as dynamic as this, it made sense to build it into a more user-driven format.", states David Shettler, the lead developer for the Open Security Foundation. "With the release of this new site, the project can now be fed by anyone, from data loss victims to researchers".
The DataLossDB’s mail list will continue to be available to over 1,500 current subscribers and will accept new subscriptions under the Attrition.org banner until a migration to OSF has been completed. RSS feeds will also be available under the OSF banner for timely alerts about new and updated data loss events. We expect this transition to be completed in the coming months without impact to current subscribers.
Open Security Foundation’s DataLossDB is an open source community project that strives to provide a clear understanding of data loss issues and needs your support. Assistance can be provided through database updates, project leadership, word-of-mouth promotion, financial donations, and sponsorship to assist with the ongoing maintenance of the project. "The DataLossDB project provides a critical service that enables detailed analysis on the true impact of data loss.", says Jake Kouns. "The Open Security Foundation is in a perfect position to support the expansion of the DataLossDB project." Any entities interested in licensing the database for commercial ventures are encouraged to contact OSF.
Posted in OSVDB News | no comments
Posted by jericho
Tue, 08 Jul 2008 04:54:00 GMT
Reported Phishing/Vulnerable Site! The web site www.google.com has been reported as a vulnerable site that may pose a threat to your web browsing. Vulnerable sites do not prioritize security and don’t care about their users and customers. These sites may pose a risk to you, exploit the trust between you and their site and may cause your computer to perform actions you did not approve.
To carry on the scary wording in the style of others; Some web sites are high profile and may seem trustworthy, but you shouldn’t trust them at all. They are full of buggy code, don’t care about protecting their users (that’s you!) and generally suck. Despite using their site as a virtual crutch, you should clearly stay away from them unless it is to send nasty mails or mock them. Again, do not trust Google’s web sites or search engine, because they have been known to be vulnerable. What assholes!
On a more serious note, if anyone at Google is reading this, I hope you pass this on to the jackasses that develop Google Toolbar or whatever hook they use to integrate with Firefox. Not only is it worse than malware (every piece of software tries to get me to install it), it uses misleading wording to scare customers from visiting perfectly safe and innocent web sites (namely this blog). While it caters to morons, it doesn’t give users a real opportunity to learn why a site was ‘blocked’ other than vague wording.
My only guess as to why this warning occurs was an incident earlier this year, in which the OSVDB blog fell victim to a zero-day exploit in WordPress. I blogged about the incident to make our readers aware of the incident and clear up any confusion. I assume that Google’s crawl of the this blog noted the script code and subsequently declared us an "attack site", even though that is hardly the case.
The discouraging part is the "diagnostic page" says that Google visited ONE page in the last 90 days and 0 of those pages resulted in malicious software being downloaded. Google, if you are going to play Lord of the Browser, visit more than one page before you make that determination. To do anything less is a disservice to your users and a fast way to miss obvious malware. The third question mentions "intermediary" which is technically accurate as far as the script code that was injected in a few blog posts. However, the big red warning says nothing about ‘intermediary’ and explicitly labels us as some kind of malware hosting site with the intent of attacking people. That is libelous to say the least. Under ‘How did this happen’, Google mentions that sometimes third parties can inject such code, but doesn’t take the time to help clear this up. If the previous script injection issue is the cause of this, the fact that the script loaded content from a third party domain (in China no less) should be a good indication that WE did not host the malware. Sure, most users are dumb as a rock, but the few smart cookies that click for details should get just that.. details.
What Google Toolbar users may see when visiting this blog:

Finally, I opened the blog post calling Google’s search engine a threat, and I was serious. Google has a track record of vulnerabilities far worse than OSVDB does. Not only in their popular search engine, but their various products too. Besides, the mechanism for reporting potentially dangerous sites is a bit dubious to say the least.
Update: Ends up, we had another iframe injection into one of our posts (which is now removed), and the hunt for how this is happening now begins. That said, while Google’s warning that this site is "dangerous" may have been accurate, their mechanism for warning users in a vague manner (as shown in the image linked off ‘vague warning’) and not warning the site administrator is far from friendly. I can see that Google doesn’t care about warning sites of issues before warning the public, a far cry from ‘responsible disclosure’, something that Google pretends to care about:
This process of notifying a vendor before publicly releasing information is an industry-standard best practice known as responsible disclosure. Responsible disclosure is important to the ecology of the Internet. It allows companies like Google to keep users safe by fixing vulnerabilities and resolving security concerns before they are brought to the attention of the bad guys. We strongly encourage anyone who is interested in researching and reporting security issues to observe the simple courtesies and protocols of responsible disclosure.
Next time OSVDB is informed of a vulnerability that impacts Google products or services, I sure hope it doesn’t slip our mind to contact them. Perhaps the apparent race condition between the vague wording and the not-so-vague wording that users may see constitutes a bug. If they can read this blog, they can see the bug in action and then contact us if they have more questions.
Update 2: Google apparently tried to send mail to our domain: From: Google Search Quality
Posted in OSVDB News | no comments
Posted by jkouns
Sat, 21 Jun 2008 16:24:09 GMT
OSVDB is featured in the June issue of the Open Source Business Resource (OSBR) and is now available at the OSBR website. We were contacted and asked if we would like to include our original OSVDB Aims white paper in the issue. This was really the prompting that we needed to take the time to update the project’s successes since the launch and provide some additional information about the future of OSVDB.
We would like to thank Dru Lavigne and OSBR for their support and encourage you to take a look at the issue. The OSVDB article can be found at:
http://www.osbr.ca/ojs/index.php/osbr/article/view/607/568
OSBR’s editorial theme for June is “Security” and here is a listing from the table of contents:
Jake Kouns, president of the Open Security Foundation, introduces the Open
Source Vulnerability Database Project.
David Maxwell, Open Source Strategist at Coverity, discusses the findings
from Coverity’s analysis of over 55 million lines of open source code.
Robert Charpentier from Defence Research Establishment Valcartier and
Mourad Debbabi, Azzam Mourad and Marc-André Laverdière from Concordia
University present a summary of their research into providing security
hardening for the C programming language.
Frederic Michaud and Frederic Painchaud from Defence Research and
Development Canada describe their evaluation of automated tools that search
for security bugs.
Key messages from Carleton University’s Stoyan Tanev’s recent presentation
on technology marketing trends and the Eclipse Foundation’s Ian Skerrett’s
presentation on building successful communities.
Michael Geist, Canada’s Research Chair of Internet and E-commerce Law,
explains why the proposed Bill C-61 does not address the rights of
Canadians.
Alan Morewood from Bell Canada provides an example of open source meeting a
business need.
Next month’s editorial theme is “Accessibility”–contact the OSBR Editor if you
are interested in a submission.
Posted in OSVDB News, General Security | no comments
Posted by jkouns
Tue, 22 Apr 2008 04:04:45 GMT
We are pleased to report that OSVDB has been provided three projects for 2008. We would like to thank everyone that applied and encourage students that were not selected to still consider getting involved with the project. We had quite a few great applications but were unable to accept any more due to our limited mentoring resources this summer and the large number of new organizations taking part in SoC this year.
Here are the projects that were selected:
Patch Management Portal by Ronny Yabar Aizcorbe, mentored by David Shettler
The system will provide a way to define when a patch should be in development, testing or production status. And will allow users the ability to select vulnerabilities and patches based on the OSVDB watch list. The main components of the tool will be: Prioritization and scheduling, Testing, Implementation and Compliance.
OSVDB Widgets and Gadgets by Marc Augustin, mentored by Chris Newby
This project is intended to utilize the OSVDB as the main data source but should be a security dashboard for professionals via Gadgets and Widgets.
OSVDB Training Portal Framework by Sergios Pericleous, mentored by Jake Kouns
This project will create a training framework which will aim to integrate as much as possible with the existing OSVDB portal. The portal will allow specific admin users to create training material and quizzes for end-users, and it will also allow end-users to read this training material and make comments on it, take the quizzes and receive a score, and to track their progress using a progress report and graphs.
Congrats Ronny, Marc and Sergios and we look forward to another successful summer!
Posted in OSVDB News | 3 comments
Posted by jericho
Tue, 15 Apr 2008 05:16:20 GMT
Dave pushed a new set of code changes today! Here is a very brief summary of some of the highlights:
Public Enhancements:
- Browse now has: Browse by Top Creditee, Browse by Creditee Name [Remember, we need more entries at 100% to make this more accurate and complete. Mangle your own vulnerabilities and fill in the missing creditee!]
- Three new dates added to schema (Screenshot) [The new date fields won’t appear on the front end yet, as more changes are required, but we now have the capability to track a more thorough history of the vulnerability]
- Menu Changes and new pages in support of that.
- More diverse “Donation” options [Come on, donate 5 bucks and skip that fourth Latte!]
- General bug fixes/tweaks
- Vendor dictionary - change e-mail addresses to stop automatic harvesting
- New template for CSRF vulnerabilities
Behind the Scenes:
- Improved matching system for moderators to ensure we’re 100% matched with CVE
- Stream line NDM process for splitting vulnerabilities
- Better system for auto-importing references to milw0rm
- Better system for approving and cataloging relevant blog posts associated with vulnerabilities
Posted in OSVDB News | 1 comment
Posted by jkouns
Sat, 29 Mar 2008 02:43:31 GMT
Google will continue to accept student applications until Monday, March 31,
2008! Please help spread the word and encourage all eligible students to
apply to OSVDB or one of the other security related projects!
OSVDB: The Open Source Vulnerability Database:
http://osvdb.org/blog/?p=231
OSSIM: Open Source Security Information Management:
http://www.ossim.net/dokuwiki/doku.php?id=ideas
Nmap Security Scanner:
http://nmap.org/GoogleGrants.html
The Electronic Frontier Foundation/Tor Project:
https://www.torproject.org/volunteer.html.en#Projects
Umit: A Nmap Frontend:
http://www.umitproject.org/?active=gsoc&mode=ideas
Freenet Project Inc
http://wiki.freenetproject.org/SummerOfCode2008
Organizations by programming language:
http://eflow.org/wiki/index.php?Mentors_by_language
Organizations by category::
http://genmapp.org/gsoc/mentors_by_category.htm
SoC Timeline:
http://code.google.com/opensource/gsoc/2008/faqs.html#0.1_timeline
Posted in OSVDB News | no comments
Posted by jericho
Tue, 25 Mar 2008 05:16:20 GMT
Public Enhancements:
- Titles now prominently display “myth/fake” to help users mentally filter those when reading search results
- New users signing up are subjected to a CAPTCHA to prevent abuse
- Small re-design of vulnerability editing pages to improve screen real estate use
- Front end now shows who is online
Behind the Scenes:
- Bulk search enhancements, ultimately to better handle CVE matching
- Remove some error conditions that could occur during vendor management
Posted in OSVDB News | no comments
Posted by jkouns
Tue, 18 Mar 2008 01:06:41 GMT
OSVDB has been accepted for Google’s Summer of Code for 2008. Please help spread the word and encourage all eligible students to apply for an OSVDB project! Google will begin accepting student applications on Monday, March 24, 2008!
If you have any questions or would like some more details about our project ideas please get in touch with us!
Posted in OSVDB News | no comments
Posted by jericho
Wed, 05 Mar 2008 06:21:37 GMT
Public Enhancements:
- New reference type: milw0rm
- Vulnerability editing - several fields now bigger to better use screen real estate
Behind the Scenes:
- Internal tool to better track advisory pages
- Improvements to the reference migrator
Posted in OSVDB News | no comments