Crypto-Gram: June 15, 2004:
"A Must Read! Newsletter
Breaking Iranian Codes
Biometric IDs for Airport Employees
Crypto-Gram Reprints
Microsoft and SP2
News
Cell Phone Jamming and Terrorist Attacks
Photographing Subways and Terrorist Attacks
Counterpane News
The Witty Worm
Comments from Readers "
http://www.schneier.com/crypto-gram-0406.html
Friday, June 18, 2004
Antipiracy bill targets tech. ReplayTV, peer-to-peer, even the VCR could be outlawed.
Antipiracy bill targets technology - News - ZDNet:
"A forthcoming bill in the U.S. Senate would, if passed, dramatically reshape copyright law by prohibiting file-trading networks and some consumer electronics devices on the grounds that they could be used for unlawful purposes.
The proposal, called the Induce Act, says 'whoever intentionally induces any violation' of copyright law would be legally liable for those violations, a prohibition that would effectively ban file-swapping networks like Kazaa and Morpheus. In the draft bill seen by CNET News.com, inducement is defined as 'aids, abets, induces, counsels, or procures' and can be punished with civil fines and, in some circumstances, lengthy prison terms.
The bill represents the latest legislative attempt by influential copyright holders to address what they view as the growing threat of peer-to-peer networks rife with pirated music, movies and software. As file-swapping networks grow in popularity, copyright lobbyists are becoming increasingly creative in their legal responses, which include proposals for Justice Department lawsuits against infringers and action at the state level. "
Originally, the Induce Act was scheduled to be introduced Thursday by Sen. Orrin Hatch, R-Utah, but the Senate Judiciary Committee confirmed at the end of the day that the bill had been delayed. A representative of Senate Majority Leader Bill Frist, a probable co-sponsor of the legislation, said the Induce Act would be introduced "sometime next week," a delay that one technology lobbyist attributed to opposition to the measure.
Though the Induce Act is not yet public, critics are already attacking it as an unjustified expansion of copyright law that seeks to regulate new technologies out of existence.
"They're trying to make it legally risky to introduce technologies that could be used for copyright infringement," said Jessica Litman, a professor at Wayne State University who specializes in copyright law. "That's why it's worded so broadly."
Litman said that under the Induce Act, products like ReplayTV, peer-to-peer networks and even the humble VCR could be outlawed because they can potentially be used to infringe copyrights. Web sites such as Tucows that host peer-to-peer clients like the Morpheus software are also at risk for "inducing" infringement, Litman warned.…
http://zdnet.com.com/2100-1104_2-5238140.html
"A forthcoming bill in the U.S. Senate would, if passed, dramatically reshape copyright law by prohibiting file-trading networks and some consumer electronics devices on the grounds that they could be used for unlawful purposes.
The proposal, called the Induce Act, says 'whoever intentionally induces any violation' of copyright law would be legally liable for those violations, a prohibition that would effectively ban file-swapping networks like Kazaa and Morpheus. In the draft bill seen by CNET News.com, inducement is defined as 'aids, abets, induces, counsels, or procures' and can be punished with civil fines and, in some circumstances, lengthy prison terms.
The bill represents the latest legislative attempt by influential copyright holders to address what they view as the growing threat of peer-to-peer networks rife with pirated music, movies and software. As file-swapping networks grow in popularity, copyright lobbyists are becoming increasingly creative in their legal responses, which include proposals for Justice Department lawsuits against infringers and action at the state level. "
Originally, the Induce Act was scheduled to be introduced Thursday by Sen. Orrin Hatch, R-Utah, but the Senate Judiciary Committee confirmed at the end of the day that the bill had been delayed. A representative of Senate Majority Leader Bill Frist, a probable co-sponsor of the legislation, said the Induce Act would be introduced "sometime next week," a delay that one technology lobbyist attributed to opposition to the measure.
Though the Induce Act is not yet public, critics are already attacking it as an unjustified expansion of copyright law that seeks to regulate new technologies out of existence.
"They're trying to make it legally risky to introduce technologies that could be used for copyright infringement," said Jessica Litman, a professor at Wayne State University who specializes in copyright law. "That's why it's worded so broadly."
Litman said that under the Induce Act, products like ReplayTV, peer-to-peer networks and even the humble VCR could be outlawed because they can potentially be used to infringe copyrights. Web sites such as Tucows that host peer-to-peer clients like the Morpheus software are also at risk for "inducing" infringement, Litman warned.…
http://zdnet.com.com/2100-1104_2-5238140.html
New worm terminates antivirus apps - News - ZDNet
New worm terminates antivirus apps - News - ZDNet:
"A new worm variant that can terminate antivirus applications was discovered last Friday, prompting Internet security vendor F-Secure to issue a level two warning.
The variant, called Zafi.B, is spread through e-mail attachments in PIF, EXE or Com attachments, and according to F-Secure, the worm 'terminates all applications that have 'firewall' or 'virus' in their file-name'.
The worm is capable of transmitting in several languages, including English, Italian, Spanish, Russian, Swedish, German or Finnish, said F-Secure, and spreads itself by collecting e-mail addresses from the recipient's address book.… "
http://zdnet.com.com/2100-1105_2-5236264.html
"A new worm variant that can terminate antivirus applications was discovered last Friday, prompting Internet security vendor F-Secure to issue a level two warning.
The variant, called Zafi.B, is spread through e-mail attachments in PIF, EXE or Com attachments, and according to F-Secure, the worm 'terminates all applications that have 'firewall' or 'virus' in their file-name'.
The worm is capable of transmitting in several languages, including English, Italian, Spanish, Russian, Swedish, German or Finnish, said F-Secure, and spreads itself by collecting e-mail addresses from the recipient's address book.… "
http://zdnet.com.com/2100-1105_2-5236264.html
Judge tosses online privacy case - News - ZDNet
Judge tosses online privacy case - News - ZDNet:
"In a decision dated June 6, U.S. District Court Judge Paul Magnuson ruled that seven consolidated class action lawsuits against Northwest had no merit--in part because the privacy policy posted on the airline's Web site was unenforceable unless plaintiffs claimed to have read it. The plaintiffs had contended that the airline, in giving passenger information to the government in the wake of the Sept. 11, 2001, terrorist attacks, violated laws and its own privacy policy.
'Although Northwest had a privacy policy for information included on the Web site, plaintiffs do not contend that they actually read the privacy policy prior to providing Northwest with their personal information,' Magnuson noted. 'Thus, plaintiffs' expectation of privacy was low.'"
Privacy advocates assailed that part of the decision, saying it rendered Web site privacy policies all but unenforceable.
"I don't think it's relevant whether or not they actually read the privacy policy first," said Lee Tien, senior staff attorney for the Electronic Frontier Foundation (EFF) in San Francisco. "Think of all the 'fine print' we run into every day--warranties and the like. Rather than focus on what the plaintiffs actually read, we should focus on what Northwest said it would do."
"The rationale the court uses calls into question the assurances of any policy posted on any Web site," said David Sobel, general counsel for the Electronic Privacy Information Center (EPIC) in Washington, D.C.…
http://zdnet.com.com/2100-1104_2-5234971.html
"In a decision dated June 6, U.S. District Court Judge Paul Magnuson ruled that seven consolidated class action lawsuits against Northwest had no merit--in part because the privacy policy posted on the airline's Web site was unenforceable unless plaintiffs claimed to have read it. The plaintiffs had contended that the airline, in giving passenger information to the government in the wake of the Sept. 11, 2001, terrorist attacks, violated laws and its own privacy policy.
'Although Northwest had a privacy policy for information included on the Web site, plaintiffs do not contend that they actually read the privacy policy prior to providing Northwest with their personal information,' Magnuson noted. 'Thus, plaintiffs' expectation of privacy was low.'"
Privacy advocates assailed that part of the decision, saying it rendered Web site privacy policies all but unenforceable.
"I don't think it's relevant whether or not they actually read the privacy policy first," said Lee Tien, senior staff attorney for the Electronic Frontier Foundation (EFF) in San Francisco. "Think of all the 'fine print' we run into every day--warranties and the like. Rather than focus on what the plaintiffs actually read, we should focus on what Northwest said it would do."
"The rationale the court uses calls into question the assurances of any policy posted on any Web site," said David Sobel, general counsel for the Electronic Privacy Information Center (EPIC) in Washington, D.C.…
http://zdnet.com.com/2100-1104_2-5234971.html
'Zombie' PCs caused Web outage, Akamai says - News - ZDNet
'Zombie' PCs caused Web outage, Akamai says - News - ZDNet:
"The attack that blacked out Google, Yahoo and other major Web sites earlier this week involved the use of a 'bot net'--a large network of zombified home PCs--Internet infrastructure provider Akamai Technologies said Wednesday.
The attack, which blocked nearly all access to Apple Computer, Google, Microsoft and Yahoo's Web sites for two hours on Tuesday, took aim at the key domain name system (DNS) servers run by Akamai. These servers translate word-based URLs, such as www.microsoft.com, into the numerical addresses used by the Internet. Using compromised home computers, the attackers sent a flood of data to the DNS servers, preventing them from providing that translation and effectively shutting surfers out of the four companies' pages, according to Akamai.
The deluge of data that hit the infrastructure provider was 'so large that it (couldn't have) come from a couple of servers,' said Tom Leighton, chief scientist and co-founder of Akamai. 'Working with our network partners, we were able to identify a bot network that appeared to be operating and managed to shut it down, which resulted in stopping the attack.' "
Bot networks are collections of computers that have been compromised by software specifically designed to create a network of systems for attack. A bot--also known as remote-access Trojan horse program, or RAT--seeks out and places itself on vulnerable PCs. It then runs silently in the background, letting an attacker send commands to the system while its owner works, oblivious. The computers are essentially turned into zombies, controllable from afar.…
http://zdnet.com.com/2100-1105_2-5236403.html
"The attack that blacked out Google, Yahoo and other major Web sites earlier this week involved the use of a 'bot net'--a large network of zombified home PCs--Internet infrastructure provider Akamai Technologies said Wednesday.
The attack, which blocked nearly all access to Apple Computer, Google, Microsoft and Yahoo's Web sites for two hours on Tuesday, took aim at the key domain name system (DNS) servers run by Akamai. These servers translate word-based URLs, such as www.microsoft.com, into the numerical addresses used by the Internet. Using compromised home computers, the attackers sent a flood of data to the DNS servers, preventing them from providing that translation and effectively shutting surfers out of the four companies' pages, according to Akamai.
The deluge of data that hit the infrastructure provider was 'so large that it (couldn't have) come from a couple of servers,' said Tom Leighton, chief scientist and co-founder of Akamai. 'Working with our network partners, we were able to identify a bot network that appeared to be operating and managed to shut it down, which resulted in stopping the attack.' "
Bot networks are collections of computers that have been compromised by software specifically designed to create a network of systems for attack. A bot--also known as remote-access Trojan horse program, or RAT--seeks out and places itself on vulnerable PCs. It then runs silently in the background, letting an attacker send commands to the system while its owner works, oblivious. The computers are essentially turned into zombies, controllable from afar.…
http://zdnet.com.com/2100-1105_2-5236403.html
Spying on spyware - News - ZDNet - one of every three computers scanned was infected.
Spying on spyware - News - ZDNet:
"EarthLink and Webroot Software released a report Wednesday, revealing that nearly one of every three computers scanned in April for Trojan horse programs or system monitor spyware was infected.
Internet access provider EarthLink and security software maker Webroot scanned nearly 421,000 computers for their April Spy Audit report. Trojan horses and system monitors accounted for 133,715 pieces of the spyware found on those computers--representing almost one in three machines.
System monitors track users' computer activity, capturing virtually everything they do online. Trojan horses appear to be software programs a user has requested but actually aid hackers in stealing computer data. That information is then used to gain unrestricted access to users' computers while they are online.…"
http://zdnet.com.com/2100-1104_2-5236735.html
"EarthLink and Webroot Software released a report Wednesday, revealing that nearly one of every three computers scanned in April for Trojan horse programs or system monitor spyware was infected.
Internet access provider EarthLink and security software maker Webroot scanned nearly 421,000 computers for their April Spy Audit report. Trojan horses and system monitors accounted for 133,715 pieces of the spyware found on those computers--representing almost one in three machines.
System monitors track users' computer activity, capturing virtually everything they do online. Trojan horses appear to be software programs a user has requested but actually aid hackers in stealing computer data. That information is then used to gain unrestricted access to users' computers while they are online.…"
http://zdnet.com.com/2100-1104_2-5236735.html
Thursday, June 17, 2004
Flaw pops up in the core component of Linux kernel
Flaw pops up in Linux kernel - News - ZDNet:
"Linux users have been urged to fix a flaw in the core component of the open-source operating system, following the public release of code that could be used to crash Linux systems.
The flaw, found by two software programmers, could give a user with access to a Linux system the ability to crash the system using two dozen lines of code written in the C programming language, said an advisory posted over the weekend on linuxreviews."
"Assume your kernel is (vulnerable) unless you have good reason to believe it is safe," Oyvind Saether, one of the discoverers of the flaw, said in the advisory.
The program, dubbed "evil.c," causes problems with the code sent to the floating-point unit, the part of the processor that handles noninteger calculations, according to a note in a source code patch published by Linux founder Linus Torvalds.
The open-source Linux operating system has fallen prey to its share of flaws and attacks this year. Several flaws were found in the Concurrent Versions System, CVS, a commonly used application for managing open-source code under development. In March and April, online attackers targeted Linux and Solaris systems at many academic high-performance computing centers.…
http://zdnet.com.com/2100-1105_2-5235028.html
"Linux users have been urged to fix a flaw in the core component of the open-source operating system, following the public release of code that could be used to crash Linux systems.
The flaw, found by two software programmers, could give a user with access to a Linux system the ability to crash the system using two dozen lines of code written in the C programming language, said an advisory posted over the weekend on linuxreviews."
"Assume your kernel is (vulnerable) unless you have good reason to believe it is safe," Oyvind Saether, one of the discoverers of the flaw, said in the advisory.
The program, dubbed "evil.c," causes problems with the code sent to the floating-point unit, the part of the processor that handles noninteger calculations, according to a note in a source code patch published by Linux founder Linus Torvalds.
The open-source Linux operating system has fallen prey to its share of flaws and attacks this year. Several flaws were found in the Concurrent Versions System, CVS, a commonly used application for managing open-source code under development. In March and April, online attackers targeted Linux and Solaris systems at many academic high-performance computing centers.…
http://zdnet.com.com/2100-1105_2-5235028.html
Wednesday, June 16, 2004
Yahoo Mail Popped Instead of Pumped.
Yahoo Chokes Upon Offering Additional User Storage:
"Yahoo Inc., which on Tuesday meant to pump up users' free e-mail accounts to 100MB, popped instead.
On the morning of its splashy debut, Yahoo users were greeted with notices of the upgrade, which boosted standard accounts from 4MB of e-mail storage to 100MB.
However, the vastly popular e-mail service was sluggish, if it worked at all. Starting Tuesday morning, users began complaining about the site's groggy response time—if, in fact, they could even get the www.yahoo.com site to load at all.
Predictably enough, postings on Slashdot show that Yahoo users are looking the gift horse in the mouth.…"
http://www.eweek.com/article2/0,1759,1612683,00.asp?kc=ewnws061504dtx1k0000599
"Yahoo Inc., which on Tuesday meant to pump up users' free e-mail accounts to 100MB, popped instead.
On the morning of its splashy debut, Yahoo users were greeted with notices of the upgrade, which boosted standard accounts from 4MB of e-mail storage to 100MB.
However, the vastly popular e-mail service was sluggish, if it worked at all. Starting Tuesday morning, users began complaining about the site's groggy response time—if, in fact, they could even get the www.yahoo.com site to load at all.
Predictably enough, postings on Slashdot show that Yahoo users are looking the gift horse in the mouth.…"
http://www.eweek.com/article2/0,1759,1612683,00.asp?kc=ewnws061504dtx1k0000599
Tuesday, June 15, 2004
Yahoo Expands E-Mail Storage
Yahoo Expands E-Mail Storage, in Nod to Google:
"Starting today, Yahoo will offer users of its free e-mail service 100 megabytes of storage. That is one-tenth of what Google offers but is still far more than the four megabytes Yahoo previously offered. It will also introduce a premium e-mail service, called Yahoo Mail Plus, with two gigabytes of storage for $19.99 a year.…"
http://www.nytimes.com/2004/06/15/technology/15mail.html
"Starting today, Yahoo will offer users of its free e-mail service 100 megabytes of storage. That is one-tenth of what Google offers but is still far more than the four megabytes Yahoo previously offered. It will also introduce a premium e-mail service, called Yahoo Mail Plus, with two gigabytes of storage for $19.99 a year.…"
http://www.nytimes.com/2004/06/15/technology/15mail.html
A bug in fully patched versions of Microsoft's Internet Explorer Invites Phishing Attacks
URL Parsing Bug in IE Invites Phishing Attacks:
"A bug in fully patched versions of Microsoft's Internet Explorer Web browser allows violations of the browser's security zones, with the result that an unknown malicious site could assume the privileges of more trusted zones.
Researchers on several security mailing lists have been discussing the bug since yesterday and appear still to be learning about it.… "
http://www.eweek.com/article2/0,1759,1611102,00.asp?kc=ewnws061404dtx1k0000599
"A bug in fully patched versions of Microsoft's Internet Explorer Web browser allows violations of the browser's security zones, with the result that an unknown malicious site could assume the privileges of more trusted zones.
Researchers on several security mailing lists have been discussing the bug since yesterday and appear still to be learning about it.… "
http://www.eweek.com/article2/0,1759,1611102,00.asp?kc=ewnws061404dtx1k0000599
ZDNet AnchorDesk: Is your antivirus app working? Are you sure?
Is your antivirus app working? Are you sure?:
"You have a desktop antivirus app installed now, and you know the signature file subscription is current with the vendor, but still you're seeing viruslike symptoms or perhaps you actually know that you have a virus. Since the first of this year, many new viruses have been shutting down antivirus and firewall apps, or, in other cases, disabling the software's automatic update feature, leaving your system vulnerable to future attack.
It's actually an old trick. The virus MTX, for example, released in 2000, blocks access to antivirus software Web sites. But these recent antivirus-disabling attacks are more effective because of their sheer volume: with some 30-odd variations of Bagle appearing within a 10-week period, each one better than the last, you might have been hit and not even realized it."
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5138927.html?tag=adss
"You have a desktop antivirus app installed now, and you know the signature file subscription is current with the vendor, but still you're seeing viruslike symptoms or perhaps you actually know that you have a virus. Since the first of this year, many new viruses have been shutting down antivirus and firewall apps, or, in other cases, disabling the software's automatic update feature, leaving your system vulnerable to future attack.
It's actually an old trick. The virus MTX, for example, released in 2000, blocks access to antivirus software Web sites. But these recent antivirus-disabling attacks are more effective because of their sheer volume: with some 30-odd variations of Bagle appearing within a 10-week period, each one better than the last, you might have been hit and not even realized it."
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5138927.html?tag=adss
Friday, June 11, 2004
How Much Is Spam Costing Your Company?
How Much Is Spam Costing Your Company?:
"Two research firms' recent reports say spam is costing your company mucho bucks. Security Center Editor Larry Seltzer sees whether the numbers add up."
By now, you've probably seen the stories about the outrageous cost of spam to businesses. Most of it came from research firm Nucleus Research.
eWEEK's story also cited research from MessageLabs, a respected mail security service.
The report from Nucleus, here in PDF form, made some electrifying claims, the big one being that spam is costing an average of $1,934 per employee a year of lost productivity. The cost in July 2003 was $874 per employee a year.
My goodness, that's a lot of money. "What will we do?" some might ask. But I ask, "Where did they get that number?"
Fortunately, the report answers the question. It assumes that an employee makes $30 per hour and works 2,080 hours per year, stating that employees in May got 29 spam messages per day. The increase from July 2003 comes from the average number of spam messages increasing from 13 to 29.
I don't know where they get those last two numbers on the increase in messages; maybe they're accurate, maybe not. Seems like more of a jump than I've seen, but it could be right.
They also assume 30 seconds per spam message. This is where I have a real problem. It seems like an awful lot of time to me. The average spam message that gets through my filtering takes me a second at most to delete.
I'm probably also on the phone while I do this, further complicating the productivity calculation. Let's assume it takes three seconds to dispose of a spam message, quite a long time if you ask me; that cuts the cost per employee from $1,934 to $193.40, nothing to sneeze at but a whole lot less.…
http://www.eweek.com/article2/0,1759,1609427,00.asp
"Two research firms' recent reports say spam is costing your company mucho bucks. Security Center Editor Larry Seltzer sees whether the numbers add up."
By now, you've probably seen the stories about the outrageous cost of spam to businesses. Most of it came from research firm Nucleus Research.
eWEEK's story also cited research from MessageLabs, a respected mail security service.
The report from Nucleus, here in PDF form, made some electrifying claims, the big one being that spam is costing an average of $1,934 per employee a year of lost productivity. The cost in July 2003 was $874 per employee a year.
My goodness, that's a lot of money. "What will we do?" some might ask. But I ask, "Where did they get that number?"
Fortunately, the report answers the question. It assumes that an employee makes $30 per hour and works 2,080 hours per year, stating that employees in May got 29 spam messages per day. The increase from July 2003 comes from the average number of spam messages increasing from 13 to 29.
I don't know where they get those last two numbers on the increase in messages; maybe they're accurate, maybe not. Seems like more of a jump than I've seen, but it could be right.
They also assume 30 seconds per spam message. This is where I have a real problem. It seems like an awful lot of time to me. The average spam message that gets through my filtering takes me a second at most to delete.
I'm probably also on the phone while I do this, further complicating the productivity calculation. Let's assume it takes three seconds to dispose of a spam message, quite a long time if you ask me; that cuts the cost per employee from $1,934 to $193.40, nothing to sneeze at but a whole lot less.…
http://www.eweek.com/article2/0,1759,1609427,00.asp
Thursday, June 10, 2004
Adware purveyor used security flaws to install a toolbar on Internet Explorer
Pop-up toolbar spreads via IE flaws - News - ZDNet:
"An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.
One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to 'cross zones,' or run with privileges higher than normal. Together, the two issues allow for the creation of a Web site that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.… "
http://zdnet.com.com/2100-1105_2-5229707.html
"An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.
One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to 'cross zones,' or run with privileges higher than normal. Together, the two issues allow for the creation of a Web site that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.… "
http://zdnet.com.com/2100-1105_2-5229707.html
833786 - Identify and to protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks
833786 - Steps that you can take to help identify and to help protect yourself from deceptive (spoofed) Web sites and malicious hyperlinks:
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL.… "
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
"When you point to a hyperlink in Microsoft Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, the address of the Web site typically appears in the Status bar at the bottom of the window. After you click a link that opens in Internet Explorer, the address of the Web site typically appears in the Internet Explorer Address bar, and the title of the Web page typically appears in the Title bar of the window.
However, a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar. This article describes steps that you can take to help mitigate this issue and to help you to identify a deceptive (spoofed) Web site or URL.… "
http://support.microsoft.com/default.aspx?scid=kb;[ln];833786
Friday, June 04, 2004
Yahoo Anti-Spy Doesn't Default to Detect Adware
Yahoo Plays Favorites with Some Adware:
"When it comes to blocking intrusive Internet software, Yahoo Inc.'s new Anti-Spy gives adware the benefit of the doubt.
The beta version of the spyware-fighting toolbar add-on, which Yahoo released last week, doesn't default to detect adware—a category of software in which Yahoo's paid search division has a financial stake.
Instead, users who want to identify adware in their systems via Anti-Spy must check a box each time they conduct a scan.…"
http://www.eweek.com/article2/0,1759,1606054,00.asp
"When it comes to blocking intrusive Internet software, Yahoo Inc.'s new Anti-Spy gives adware the benefit of the doubt.
The beta version of the spyware-fighting toolbar add-on, which Yahoo released last week, doesn't default to detect adware—a category of software in which Yahoo's paid search division has a financial stake.
Instead, users who want to identify adware in their systems via Anti-Spy must check a box each time they conduct a scan.…"
http://www.eweek.com/article2/0,1759,1606054,00.asp
Thursday, June 03, 2004
New Windows Media DRM Announced!
Microsoft Windows Media - Digital Rights Management (DRM):
"Windows Media digital rights management (DRM) is a proven platform to protect and securely deliver content for playback on a computer, portable device, or network device. It's flexible to support a range of business models from single downloads or physical format delivery. The latest version of Windows Media DRM enables new scenarios and provides consumers even greater access to protected audio and video content."
http://www.microsoft.com/windows/windowsmedia/drm/default.aspx
"Windows Media digital rights management (DRM) is a proven platform to protect and securely deliver content for playback on a computer, portable device, or network device. It's flexible to support a range of business models from single downloads or physical format delivery. The latest version of Windows Media DRM enables new scenarios and provides consumers even greater access to protected audio and video content."
http://www.microsoft.com/windows/windowsmedia/drm/default.aspx
Wednesday, June 02, 2004
The Search Engine Report - Number 91 - May 27, 2004
A worm that uses seven mechanisms to spread itself.
Kibuv Worm, Bobax Trojan Try Many Methods:
"Security experts are tracking two new threats that have emerged in the past few days, including a worm that uses seven mechanisms to spread itself.
The worm is known as Kibuv, and researchers first noticed its presence Friday. Kibuv affects all versions of Windows from 98 through Windows Server 2003 and attempts to spread through a variety of methods, including exploiting five Windows vulnerabilities and connecting to the FTP server installed by the Sasser worms. "
Once it's installed on a PC, Kibuv starts its own FTP server that can be used to distribute copies of the worm. It also connects to a remote IRC chat server and listens for commands, according to an analysis done by Symantec Corp. Kibuv also listens on TCP port 420 for commands.
The worm has not spread too widely as of yet, but with its variety of infection methods, experts say the potential exists for it to infect a large number of machines.
The second piece of malware that has surfaced is a Trojan that is capable of spreading semi-automatically. Known as Bobax, the Trojan can only infect machines running Windows XP and seems to exist solely for the purpose of sending out large amounts of spam, according to an analysis by LURHQ Corp., a managed security services provider.
http://securityresponse.symantec.com/avcenter/venc/data/w32.kibuv.b.html
http://www.eweek.com/article2/0,1759,1594848,00.asp?kc=ewnws051904dtx1k0000599
"Security experts are tracking two new threats that have emerged in the past few days, including a worm that uses seven mechanisms to spread itself.
The worm is known as Kibuv, and researchers first noticed its presence Friday. Kibuv affects all versions of Windows from 98 through Windows Server 2003 and attempts to spread through a variety of methods, including exploiting five Windows vulnerabilities and connecting to the FTP server installed by the Sasser worms. "
Once it's installed on a PC, Kibuv starts its own FTP server that can be used to distribute copies of the worm. It also connects to a remote IRC chat server and listens for commands, according to an analysis done by Symantec Corp. Kibuv also listens on TCP port 420 for commands.
The worm has not spread too widely as of yet, but with its variety of infection methods, experts say the potential exists for it to infect a large number of machines.
The second piece of malware that has surfaced is a Trojan that is capable of spreading semi-automatically. Known as Bobax, the Trojan can only infect machines running Windows XP and seems to exist solely for the purpose of sending out large amounts of spam, according to an analysis by LURHQ Corp., a managed security services provider.
http://securityresponse.symantec.com/avcenter/venc/data/w32.kibuv.b.html
http://www.eweek.com/article2/0,1759,1594848,00.asp?kc=ewnws051904dtx1k0000599
unless they're shut down by the company that installed them, RFID tags can be read
Zombie RFID tags may never die - News - ZDNet:
"Item-level tagging is some way off yet, mainly due to cost rather than retailers' lack of enthusiasm but, when it does kick off in earnest, it's worth putting money on consumers being at loggerheads with retailers over when exactly to switch off and kill the chips.
RFID tags can be read--either by a store or by an unrelated third party--unless they're shut down by the company that installed them in the product. "
While a consumer might quite fancy the idea of walking up to the checkout and having his new $9,000 plasma-screen TV scanned instantaneously, he might not be so pleased that any passer-by with a reader can find out what he's got in the back of his car. He may also just not like the idea of a supermarket being able to scan his goods after he's left the store.
But when should the tag's tracking powers be turned off? Kill commands, as they're known, do exist. The idea is that when a shopper passes a certain point, any active RFID chip essentially shuts itself down (German supermarket Metro tried similar technology with its RFID rollout and was rather red-faced to find its kill commanders were more like a nasty-kick-in-the-shins commands).
The question remains: why would we want to keep the tags active once we've left our local Tesco and should retailers be allowed to?…
http://zdnet.com.com/2100-1103_2-5214648.html?tag=zdaresources
"Item-level tagging is some way off yet, mainly due to cost rather than retailers' lack of enthusiasm but, when it does kick off in earnest, it's worth putting money on consumers being at loggerheads with retailers over when exactly to switch off and kill the chips.
RFID tags can be read--either by a store or by an unrelated third party--unless they're shut down by the company that installed them in the product. "
While a consumer might quite fancy the idea of walking up to the checkout and having his new $9,000 plasma-screen TV scanned instantaneously, he might not be so pleased that any passer-by with a reader can find out what he's got in the back of his car. He may also just not like the idea of a supermarket being able to scan his goods after he's left the store.
But when should the tag's tracking powers be turned off? Kill commands, as they're known, do exist. The idea is that when a shopper passes a certain point, any active RFID chip essentially shuts itself down (German supermarket Metro tried similar technology with its RFID rollout and was rather red-faced to find its kill commanders were more like a nasty-kick-in-the-shins commands).
The question remains: why would we want to keep the tags active once we've left our local Tesco and should retailers be allowed to?…
http://zdnet.com.com/2100-1103_2-5214648.html?tag=zdaresources
Friday, May 28, 2004
Security Watch Letter: Dangerous Bobax Worm Hits System Files
Security Watch Letter: Dangerous Bobax Worm Hits System Files:
"Since Sasser opened the door, we've seen over a half a dozen new names, and several versions of each-- Cycle, Gaobot, Bobax, Korgo, Kibuv, and Sdbot. Gaobot and Wallon worms also attempt to exploit Windows vulnerabilities from earlier security bulletins. However, the most prolific threats are still the e-mail viruses Netsky.P, Bagel.X, and Dumaru. Sasser.B is also still at the top of the active infector lists, even though Microsoft reports that the number downloads of the MS04-011 update (which could block a Sasser infection) is four times the amount of previous ones. If you haven't updated and haven't gotten Sasser, you're lucky. Update now."
Our top threat of the week is the Bobax.D worm. The fourth in the family, Bobaxuses the same LSASS vulnerability that the Sasser family did. It hasn't had a Sasser-sized impact, but it has the potential (if Sasser doesn't infect the un-patched systems first). Bobax is a little more dangerous than Sasser, as it deletes and changes system files, and sets up an open e-mail relay to send spam from a victim's machine. It even checks the speed of the victim's connection, presumably to cherry-pick the best spam-sending systems.…
http://www.pcmag.com/article2/0,1759,1600125,00.asp
"Since Sasser opened the door, we've seen over a half a dozen new names, and several versions of each-- Cycle, Gaobot, Bobax, Korgo, Kibuv, and Sdbot. Gaobot and Wallon worms also attempt to exploit Windows vulnerabilities from earlier security bulletins. However, the most prolific threats are still the e-mail viruses Netsky.P, Bagel.X, and Dumaru. Sasser.B is also still at the top of the active infector lists, even though Microsoft reports that the number downloads of the MS04-011 update (which could block a Sasser infection) is four times the amount of previous ones. If you haven't updated and haven't gotten Sasser, you're lucky. Update now."
Our top threat of the week is the Bobax.D worm. The fourth in the family, Bobaxuses the same LSASS vulnerability that the Sasser family did. It hasn't had a Sasser-sized impact, but it has the potential (if Sasser doesn't infect the un-patched systems first). Bobax is a little more dangerous than Sasser, as it deletes and changes system files, and sets up an open e-mail relay to send spam from a victim's machine. It even checks the speed of the victim's connection, presumably to cherry-pick the best spam-sending systems.…
http://www.pcmag.com/article2/0,1759,1600125,00.asp
Subscribe to:
Posts (Atom)
