Tipper2010

[20161201] – Core – Elevated Privileges

  • Project: Joomla!
  • SubProject: CMS
  • Severity: High
  • Versions: 1.6.0 through 3.6.4
  • Exploit type: Elevated Privileges
  • Reported Date: 2016-November-04
  • Fixed Date: 2016-December-06
  • CVE Number: CVE-2016-9838

Description

Incorrect use of unfiltered data stored to the session on a form validation failure allows for existing user accounts to be modified; to include resetting their username, password, and user group assignments.

Affected Installs

Joomla! CMS versions 1.6.0 through 3.6.4

Solution

Upgrade to version 3.6.5

Contact

The JSST at the Joomla! Security Centre.

Reported By: @iamsecurity

[20161201] – Core – Elevated Privileges Read More »

5 parent tips for picking the right video games

(BPT) – With new game consoles, mobile devices and interactive experiences arriving just in time for the holidays, video games are certain to make the “most wanted” list for gamers of all ages. With so many choices, parents can sometimes feel a little overwhelmed trying to decide which games are appropriate for their children to play.

The Entertainment Software Rating Board (ESRB), the non-profit organization that assigns age and content ratings for video games, is an excellent resource for helping parents navigate both the real and virtual game aisles. The familiar ESRB ratings including E (Everyone), T (Teen) or M (Mature) are now also assigned to downloadable games and apps in Google Play, Microsoft’s Xbox Live store, Nintendo eShop and the PlayStation Store.

ESRB offers the following tips for parents looking for the console games or mobile apps that are perfectly suited to their family:

1. Check the rating. Start with the recommended age rating. ESRB assigns E (Everyone), E10+ (Everyone 10 and older), T (Teen), M (Mature) and AO (Adults Only), which are clearly labeled on video game boxes or on the game’s page prior to downloading from an online or mobile storefront.

2. Review the content descriptors. ESRB uses about 30 different content descriptors for depictions involving violence, suggestive or sexual themes, language, controlled substances and other types of content to help parents understand what may have triggered a particular age rating.

3. Look for interactive elements. Interactive elements describe certain aspects of a game or app that may be of interest to many parents and consumers, and can be assigned to downloadable games and apps. These include the sharing of the user’s location, if the game or app enables the purchase of digital goods, if users can interact and/or if unrestricted internet access is provided.

4. Set parental controls. Today’s gaming devices have parental controls built in, which allow parents to block titles by age rating, ensuring children can access only age-appropriate games and apps. Depending on the device, parents can also control specific features like with whom their children can play online and whether in-game purchases can be made. Just make sure you never reveal your password or PIN!

5. Do your research. Check ESRB rating summaries at ESRB.org, which provide a more detailed explanation of content in many packaged games. Forget to check the rating summary before you set out on a gift-getting expedition? No problem — you can find rating summaries for packaged games on the ESRB app as well! If you still want more information, online reviews are another great resource. These often include screenshots, videos and other details that parents may find helpful in making a final purchase decision. You can also always talk to your local video game retailers — they’re often staffed with experienced gamers who can help guide parents toward the right games for their family. For downloadable games and apps, parents may want to review the details on the product’s page and some of the user reviews before downloading.

Perhaps most importantly, have fun! If you’re not already a gamer, try it — you might like it! Not only is it a great way to bond with your children, it allows you to share and better understand one of their passions. Never underestimate the value of playing as a family; enjoying games together enables you to engage in an ongoing conversation with your children about the games they want and love to play.

5 parent tips for picking the right video games Read More »

5 parent tips for picking the right video games

(BPT) – With new game consoles, mobile devices and interactive experiences arriving just in time for the holidays, video games are certain to make the “most wanted” list for gamers of all ages. With so many choices, parents can sometimes feel a little overwhelmed trying to decide which games are appropriate for their children to play.

The Entertainment Software Rating Board (ESRB), the non-profit organization that assigns age and content ratings for video games, is an excellent resource for helping parents navigate both the real and virtual game aisles. The familiar ESRB ratings including E (Everyone), T (Teen) or M (Mature) are now also assigned to downloadable games and apps in Google Play, Microsoft’s Xbox Live store, Nintendo eShop and the PlayStation Store.

ESRB offers the following tips for parents looking for the console games or mobile apps that are perfectly suited to their family:

1. Check the rating. Start with the recommended age rating. ESRB assigns E (Everyone), E10+ (Everyone 10 and older), T (Teen), M (Mature) and AO (Adults Only), which are clearly labeled on video game boxes or on the game’s page prior to downloading from an online or mobile storefront.

2. Review the content descriptors. ESRB uses about 30 different content descriptors for depictions involving violence, suggestive or sexual themes, language, controlled substances and other types of content to help parents understand what may have triggered a particular age rating.

3. Look for interactive elements. Interactive elements describe certain aspects of a game or app that may be of interest to many parents and consumers, and can be assigned to downloadable games and apps. These include the sharing of the user’s location, if the game or app enables the purchase of digital goods, if users can interact and/or if unrestricted internet access is provided.

4. Set parental controls. Today’s gaming devices have parental controls built in, which allow parents to block titles by age rating, ensuring children can access only age-appropriate games and apps. Depending on the device, parents can also control specific features like with whom their children can play online and whether in-game purchases can be made. Just make sure you never reveal your password or PIN!

5. Do your research. Check ESRB rating summaries at ESRB.org, which provide a more detailed explanation of content in many packaged games. Forget to check the rating summary before you set out on a gift-getting expedition? No problem — you can find rating summaries for packaged games on the ESRB app as well! If you still want more information, online reviews are another great resource. These often include screenshots, videos and other details that parents may find helpful in making a final purchase decision. You can also always talk to your local video game retailers — they’re often staffed with experienced gamers who can help guide parents toward the right games for their family. For downloadable games and apps, parents may want to review the details on the product’s page and some of the user reviews before downloading.

Perhaps most importantly, have fun! If you’re not already a gamer, try it — you might like it! Not only is it a great way to bond with your children, it allows you to share and better understand one of their passions. Never underestimate the value of playing as a family; enjoying games together enables you to engage in an ongoing conversation with your children about the games they want and love to play.

5 parent tips for picking the right video games Read More »

How technology can save your love life

(BPT) – It’s a common refrain: technology is killing our relationships. Couples have swapped date night for Netflix binging. They Candy Crush their way through an intimate conversation. They’ve replaced long walks on the beach with an all-out Facebook investigation into their friend’s cute new puppy.

We can blame a lot of our relationship woes on today’s tech — it’s true – but when technology’s power is harnessed the right way, it can actually become the very thing that saves us from love’s most common pitfalls.

So before powering down all of your electronics, consider the following three scenarios where technology might be the only thing that can help you save an untimely end to your relationship:

1. Your loved one is having a tech meltdown.

Admit it: there is no greater frustration known to mankind than when you’ve been working on a document for hours and the program crashes. Or when the printer isn’t printing. Or when you can’t access the baby pictures that you’re trying to show to your grandma.

The urge to pick up the computer/phone/tablet and throw it against the wall becomes a dark force within you. Your tech-savvy partner is out for the whole day and now the dog is even starting to judge you.

So what do you do? You call your partner — wherever he or she may be — and rant about the problem.

If you’ve been on the receiving end of one of these calls, you know how they all end. The few troubleshooting suggestions you can rationally muster without being able to see the problem at hand are all met with an “It’s still not working!” The frustration flows on both sides of the call with no resolution in sight.

But by adding a “remote control” application into the mix you can now virtually (and safely) access a computer and solve any problems from anywhere with an internet connection.

A number of companies produce this kind of software. TeamViewer offers a free version for personal use and their latest version has improved security features and, for the first time ever, offers mobile-to-mobile remote control so you can even help your loved one with their phone faux pas.

2. You’ve left the tickets to the big show at home.

It has happened to all of us. You’re finally at the check-in for the sold-out Beyoncé concert — where Jay Z is expected to make an on-stage appearance — and where he will rap-battle with a hologram of himself.

The security guard calls for “tickets, please!” You reach into your pockets, and your heart drops as the realization sets in: the tickets have been left at home, saved on the computer.

You start calculating the damage — both emotional and fiscal. Your partner begins to glow red with rage.

But you need not fret! Remote control software lets you log in to your home computer, even when it’s unattended, from your phone, your partner’s phone or that tablet in your carry-on.

It’s the perfect opportunity to prevent such a moment from spiraling into an all-out “incident” that will be held against you for years to come.

For added bonus points, use your smartphone’s built-in personal assistant and ask her to remind you to bring the tickets before you ever leave the house.

Admitting you’re forgetful is the first step. Stepping up your tech savviness is the second.

3. That special getaway you’ve planned is about to be ruined by work

One of the quickest buzzkills to any vacation is the unexpected work assignment from the boss or client who doesn’t care that this is the first time you and your partner are getting away together — without the kids/dogs/cats/ferrets — in over a year.

Enter virtual meeting applications.

They let you present documents, share files and even speak to your attendees all through the app with no need to long distance dial-in. You can tell your boss you’ll handle the presentation and still plan that special vacation without worrying that a big project might flare up. And your partner can still take in all the R&R she or he has been longing for.

You see? With a little help from technology, you can bring out the relationship champ you always knew was within you.

How technology can save your love life Read More »

How technology can save your love life

(BPT) – It’s a common refrain: technology is killing our relationships. Couples have swapped date night for Netflix binging. They Candy Crush their way through an intimate conversation. They’ve replaced long walks on the beach with an all-out Facebook investigation into their friend’s cute new puppy.

We can blame a lot of our relationship woes on today’s tech — it’s true – but when technology’s power is harnessed the right way, it can actually become the very thing that saves us from love’s most common pitfalls.

So before powering down all of your electronics, consider the following three scenarios where technology might be the only thing that can help you save an untimely end to your relationship:

1. Your loved one is having a tech meltdown.

Admit it: there is no greater frustration known to mankind than when you’ve been working on a document for hours and the program crashes. Or when the printer isn’t printing. Or when you can’t access the baby pictures that you’re trying to show to your grandma.

The urge to pick up the computer/phone/tablet and throw it against the wall becomes a dark force within you. Your tech-savvy partner is out for the whole day and now the dog is even starting to judge you.

So what do you do? You call your partner — wherever he or she may be — and rant about the problem.

If you’ve been on the receiving end of one of these calls, you know how they all end. The few troubleshooting suggestions you can rationally muster without being able to see the problem at hand are all met with an “It’s still not working!” The frustration flows on both sides of the call with no resolution in sight.

But by adding a “remote control” application into the mix you can now virtually (and safely) access a computer and solve any problems from anywhere with an internet connection.

A number of companies produce this kind of software. TeamViewer offers a free version for personal use and their latest version has improved security features and, for the first time ever, offers mobile-to-mobile remote control so you can even help your loved one with their phone faux pas.

2. You’ve left the tickets to the big show at home.

It has happened to all of us. You’re finally at the check-in for the sold-out Beyoncé concert — where Jay Z is expected to make an on-stage appearance — and where he will rap-battle with a hologram of himself.

The security guard calls for “tickets, please!” You reach into your pockets, and your heart drops as the realization sets in: the tickets have been left at home, saved on the computer.

You start calculating the damage — both emotional and fiscal. Your partner begins to glow red with rage.

But you need not fret! Remote control software lets you log in to your home computer, even when it’s unattended, from your phone, your partner’s phone or that tablet in your carry-on.

It’s the perfect opportunity to prevent such a moment from spiraling into an all-out “incident” that will be held against you for years to come.

For added bonus points, use your smartphone’s built-in personal assistant and ask her to remind you to bring the tickets before you ever leave the house.

Admitting you’re forgetful is the first step. Stepping up your tech savviness is the second.

3. That special getaway you’ve planned is about to be ruined by work

One of the quickest buzzkills to any vacation is the unexpected work assignment from the boss or client who doesn’t care that this is the first time you and your partner are getting away together — without the kids/dogs/cats/ferrets — in over a year.

Enter virtual meeting applications.

They let you present documents, share files and even speak to your attendees all through the app with no need to long distance dial-in. You can tell your boss you’ll handle the presentation and still plan that special vacation without worrying that a big project might flare up. And your partner can still take in all the R&R she or he has been longing for.

You see? With a little help from technology, you can bring out the relationship champ you always knew was within you.

How technology can save your love life Read More »

A digital safe vault to protect your information

(BPT) – Whether you’re paying for a meal, signing up to play a game on your smartphone or withdrawing money from your bank, your information is at risk. In 2016 alone, 873 data breaches exposed more than 29.8 million records containing potentially sensitive information, according to the Identity Theft Resource Center.

Clearly, stronger measures must be taken.

While more people are turning to digital solutions to store important information, the threat of cyber security remains a concern for many businesses, governments and individuals. The modern reality when it comes to safely protecting valuables, documents and digital assets, is that both physical and digital secure storage solutions are needed.

Security in a changing world

In The Wall Street Journal, Sue Shellenbarger says people need a way to securely store both digital and physical copies of important documents. They should “wrap the documents in plastic and store them in a safe or safe-deposit box. Other paper items to keep in both paper and digital form include wills, diplomas, deeds, titles, licenses and trust and retirement-plan documents.”

Jerry Pluard of Safe Deposit Box Insurance Coverage (SDBIC) agrees, and recommends using a combination of physical and “digital” safe deposit boxes to protect valuables and digital identity.

“A digital safe deposit box can be used to maintain an inventory and store images of the valuable items in your physical box. You can also specify in your digital box the location of physical box and where the keys can be found,” Pluard says.

Digital vaults for consumers

While highly secured digital safe deposit boxes have been used by consumers and banking institutions in Europe for several years, the technology has not been embraced to the same degree in the United States.

With the digital vault options now available, American consumers need to be educated on what features are essential to ensuring their security. The top features are:

1. Password manager: Keeping passwords in a highly secure location might be the feature you access the most in your digital safe deposit box. Look for a password generator and the ability to link directly to the login screen to copy and paste the password in. Also, make sure you can access the password vault even when offline.

2. Encrypted email: Your digital box should have an encrypted email so you can send and receive sensitive documents.

3. Accessibly: Your digital box should have an easy to use mobile app, allowing you to access your passwords, documents and to download and receive encrypted information form a number of devices.

4. Digital inheritance: You should be able to designate several loved ones as beneficiaries who will have access to your digital files and documents in case of a life-changing event.

5. Security: Zero Knowledge technology is a must. This means only you and those you authorize can access your box. Also, you want something known as double encryption. This assures you that even if there is a breach, the hacker cannot access documents or data.

An Integrated Solution

Recently, SDBIC formed a partnership with DSwiss AG to bring such a digital vault solution to the US.

In addition to providing people with the needed features mentioned above, all the data is stored in a military command bunker in the Swiss mountains. This same service, which is used by large European financial firms to store highly sensitive information, is available to the consumer for just $40 a year.

This means there is now double-pronged security solution available. With an insured safe deposit box and a Digital Fortress digital vault, consumers can enjoy the peace of mind that comes with knowing their valuables are protected. It’s a digital and physical security solution for every generation.

A digital safe vault to protect your information Read More »

6 Gig Economy Values Parents Need to Teach Their Children

It is every parent’s responsibility to educate their children about money. Some adults may think talking to kids about money is inappropriate, but starting them young ensures that they will grow up to be financially stable and independent. So, if … Read More

The post 6 Gig Economy Values Parents Need to Teach Their Children appeared first on Official Fiverr Blog.

6 Gig Economy Values Parents Need to Teach Their Children Read More »

Your moments at the gas pump are about to get more entertaining

Play Video

(BPT) – The next time you find yourself pumping gas, don’t be surprised if Miles offers to keep you company. He’s not an attendant and he isn’t a friendly good Samaritan.

Miles is the name given to the first ever BP Personality Pump, an interactive smart pump that will first start appearing at BP stations this year. Miles uses proprietary technology allowing him to “speak” with consumers as they are filling their tanks. Miles receives responses in real-time through a touchscreen tablet allowing consumers to interact with him via an array of entertainment options.

“We know that most people don’t enjoy pumping gas. So we asked ourselves, how can we make those moments spent at the pump more fun,” said Donna Sanker, chief marketing officer of BP Fuels North America. “With the BP Personality Pump, we hope to redefine perceptions of the routine fill-up and build a meaningful relationship with our consumers, giving them a fulfilling and entertaining experience during the time they spend with us.”

Miles is programmed to interact with consumers in several different ways. During their visit, consumers will have the opportunity to engage Miles by playing music trivia, selecting songs to play through Pandora or even by recording a video e-card that they can then share on their social media channels. And, upon finishing filling up their tank, consumers will also have the opportunity to send themselves a text message with the content they created during their interaction with Miles. This message will include a link to the Pandora station they chose as well as a special return offer.

The goal, according to BP, is to make the otherwise routine task of filling a gas tank more fun and memorable.

Miles will first appear in November, 2016 in the Chicago and New York Metro areas.

To showcase more of Miles’ capabilities, BP has teamed up with The Onion Inc.’s creative services agency, Onion Labs, to develop a series of videos capturing customers’ interactions with Miles. You can watch this video, titled Laura & Miles, to learn more about the first-ever Personality Pump. You can find more videos at www.theonion.com/special/innovation.

Your moments at the gas pump are about to get more entertaining Read More »