Wednesday, September 01, 2004
Distribute This Denial of Service Checklist
"The important thing to realize about DDoS attacks is that they aren't going to go away, and there's no way of preventing them. They have been around for a very long time, and they are getting easier to carry out. That's because there are increasing numbers of poorly secured home PCs with always-on Internet connections just waiting to be discovered and taken over by hackers. These compromised PCs are incorporated into attack networks, where they remain dormant until a short burst of command and control traffic activates them and turns them into crazed attack zombies, firing off data at a target host until -- the hacker hopes -- it disappears under a deluge of unwanted packets.…"
http://www.esecurityplanet.com/prevention/print.php/3400861
Monday, August 30, 2004
Order Windows XP Service Pack 2 on CD Now!
System Requirements
To install Windows XP Service Pack 2 via CD, you need:
A PC with Windows XP Home Edition, Professional, Media Center Edition, or Tablet PC Edition installed
233-megahertz or higher processor
64 megabytes (MB) of RAM or higher
1.6 GB of available hard disk space during installation
CD-ROM drive
Share This CD with a Friend
After you have installed Service Pack 2, Microsoft encourages you to give this CD to a friend or family member using Windows XP.
Friday, August 27, 2004
Security Watch Special: Windows XP SP2 Has a Dangerous Hole — WMI
"Microsoft will make Windows XP Service Pack 2 available to the general public this week, but the enthusiasm for the first significant OS update in almost two years is now competing with worries over discoveries and claims of new holes and vulnerabilities. Through an anonymous tip, we confirmed a core vulnerability that could lead to spoofing in the Windows Security Center, the new control panel for a PC's security status. Another unpatched hole has been found in Internet Explorer that affects Version 5.01 and later, as well as on an SP2 updated system. The hole allows an attacker to download a malicious executable to the user's system without their knowledge. For more on this IE flaw, see our Windows Update and vulnerabilities.
This week's tip also deals with the new SP2 security; we show you how to open ports to allow products like PCAnywhere to work correctly. For more on the potential spoofing of the Windows Security Center, see our Top Threat. "
WMI may not only be a security hole, but a crater in the wrong hands. Due to the nature of WMI, the WSC could potentially allow attackers to spoof the state of security on a user's system while accessing data, infecting the system, or turning the PC into a zombie for spam or other purposes.
According to Microsoft, WMI is the Microsoft implementation of Web-Based Enterprise Management (WBEM), an industry standard for accessing management information on a system. For Windows XP Service Pack 2, Microsoft added new fields or records to keep track of the Firewall and Antivirus information in the WMI database. Unfortunately, the WMI database is designed to be accessible via the WBEM API (application program interface) and is available to any program that wants to access the WMI. These programs can be desktop applications written in desktop- or web-based scripting or ActiveX modules.
This open door to the security status of a system can be exploited several ways. First, a malicious site could download a file (possibly with the drag and drop exploit discussed in our Windows updates and vulnerabilities section), which could run and access the WMI, monitoring the status of the firewall and antivirus protection.
http://www.pcmag.com/print_article/0,1761,a=133959,00.asp
Application Compatibility Guide for Windows XP SP 2
"Windows® XP SP2 introduces new security technologies to better enable Windows XP computers to withstand viruses, worms and other kinds of attacks. This guide will assist IT Professionals to test and mitigate application compatibility issues arising from these more stringent security technologies."
| ||||||||||
This is approximately 100 pages
This guidance discusses the security technologies, an application testing process, incompatibility symptoms, mitigation techniques, and deployment scenarios. It makes no assumption about the size or complexity of the network, and is as relevant to peer-to-peer environments as it is to Active Directory environments.
http://www.microsoft.com/downloads/details.aspx?FamilyId=9300BECF-2DEE-4772-ADD9-AD0EAF89C4A7&displaylang=en
Thursday, August 26, 2004
Microsoft offers SP2 compatibility guide - News - ZDNet
"Microsoft has launched a do-it-yourself kit to help IT professionals assess their software's compatibility with Windows XP Service Pack 2.
Fears among system administrators and IT managers that SP2 may break homegrown applications have already led to delays in corporate launches. To get users back on track and keep developers' blood pressure down, Microsoft is offering the application compatibility testing guide.
The guide, which can be retrieved from Microsoft's Download Center, is designed to help administrators 'test and mitigate application compatibility issues.' Microsoft adds that the guide is meant for a network of any size and is 'as relevant to peer-to-peer environments as it is to Active Directory environments.'… "
http://www.microsoft.com/downloads/details.aspx?FamilyId=9300BECF-2DEE-4772-ADD9-AD0EAF89C4A7&displaylang=en
http://zdnet.com.com/2100-1104-5323378.html
Wednesday, August 25, 2004
Between the Lines � Bush in 30 seconds. Your privacy in 2. - ZDNet.com
"When Web developer Shawn Smith used Google to find some of Moveon.org’s well-known "Bush in 30 seconds" anti-Bush video spots, he got more than he bargained for. Google’s search results also revealed a significant amount of confidential personal information about the Web site’s subscribers including names, e-mail addresses, newsletter subscription information, and areas of political interest. The exposure exemplifies the power and maturity of search engines like Google and begs the question "Have you Googled your own Web site recently?"… "
http://blogs.zdnet.com/index.php?p=376
Tuesday, August 24, 2004
Vulnerability could turn drag-and-drop into drag-and-infect- News - ZDNet
"An independent researcher warned that an Internet Explorer vulnerability could turn drag-and-drop into drag-and-infect, even on computers updated with Microsoft's latest security patch.
The flaw affects the latest version of Internet Explorer running on Windows XP, even after the latest major update--known as Service Pack 2--is applied. An attacker using the flaw could install a program on a victim's computer after convincing the person to visit a malicious Web site and click on a graphic.
The attacker's program would be placed in the Windows startup folder and would run the next time the user restarted the computer. The security researcher who discovered the flaw, known by the online nickname 'http-equiv,' posted an example to show the power of the flaw."
"If you look at the Web page, all you see are two red lines and an image; drag the image across the two lines and drop it," he said. "What you have actually done is drop (a program) into your startup folder. Next time you switch the computer on it runs the program."
Security information company Secunia believes the program that takes advantage of the issue could be simplified to only require a single click from the user. Secunia rated the flaw as "highly critical," its second-highest rating of vulnerability threats.
Microsoft said the issue did not pose a serious risk to users because it requires an attacker to trick people into visiting a Web site and taking some action at the site.…
http://zdnet.com.com/2100-1105_2-5318358.html
Friday, August 20, 2004
New Attack Pierces Fully Patched XP Machines, but SP2 not vulnerable
"Security researchers have identified a new version of the Download.Ject attack that is now being used on the Internet and can compromise fully patched Windows XP machines.
The new version of the attack just appeared Thursday afternoon, and while details are still sketchy, experts say its main purpose is to install a back door on compromised PCs. Users victimized by the attack receive an e-mail or an instant message containing a link directing them to a malicious Web page. "
The page is being hosted by a number of different sites, all of which share common "whois" information and appear to be deliberately serving the page, according to Thor Larholm, senior security researcher at PivX Solutions LLC, based in Newport Beach, Calif. The Trojan also will change the start page of the infected PC.
Once a user clicks on the link, the Web server attempts to download the back door. Larholm said a PC running a fully patched copy of Windows XP and Internet Explorer 6 will be compromised by the new version of Download.Ject, as will machines running older version of Windows and IE.
But machines running SP2 (Service Pack 2) for XP are not vulnerable to the new attack. Larholm added that the vulnerabilities exploited in this attack have been known for some time.…
http://www.eweek.com/article2/0,1759,1638037,00.asp?kc=ewnws082004dtx1k0000599
Judges rule file-sharing software legal - News - ZDNet
"Like the lower court, the Ninth Circuit implied that any ability to hold software developers liable for copyright infringement might have to come from Congress rather than from the courts. Indeed, the RIAA is already pursuing that goal, with a bill sponsored by Sen. Orrin Hatch, a Republican from Utah, that would put legal responsibility for copyright infringement back on the peer-to-peer developers.
But the Appeals Court closed its decision with words that some technology lawyers are interpreting as a cautionary note to Congress, as it debates that bill.
'The introduction of new technology is always disruptive to old markets and particularly to those copyright owners whose works are sold through well-established distribution mechanisms,' the court wrote. 'Yet history has shown that time and market forces often provide equilibrium in balancing interests, whether the new technology be a player piano, a copier, a tape recorder, a video recorder, a personal computer, a karaoke machine or an MP3 player. Thus, it is prudent for courts to exercise caution before restructuring liability theories for the purpose of addressing specific market abuses, despite their apparent present magnitude.' "
http://zdnet.com.com/2100-1104_2-5316570.html?tag=adnews
Thursday, August 19, 2004
Security Watch Letter: New MyDoom Piggybacks More Dangerous Worm
"… MyDoom is back with W32/MyDoom.S-mm. This variation, also known as MyDoom.Q@mm, Worm_Ratos.A, and I-worm.Win32.Ratos, was discovered on August 15th, and jumped to a medium-level threat very quickly. While MyDoom.S doesn't really do much, it downloads a particulary nasty trojan called Backdoor.Ratos.A. …"
http://www.pcmag.com/article2/0,1759,1637560,00.asp
http://www.pcmag.com/print_article/0,1761,a=133647,00.asp
Study: Unpatched PCs compromised in 20 minutes - News - ZDNet
"Don't connect that new PC to the Internet before taking security precautions, researchers at the Internet Storm Center warned Tuesday.
According to the researchers, an unpatched Windows PC connected to the Internet will last for only about 20 minutes before it's compromised by malware, on average. That figure is down from around 40 minutes, the group's estimate in 2003.
The Internet Storm Center, which is part of the SANS Institute, calculated the 20-minute 'survival time' by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.… "
The drop from 40 minutes to 20 minutes is worrisome because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from Internet threats.
Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the center's data believeable.
"It's a tough problem, and it's getting tougher," Conti said.
One of Conti's administrators tested the center's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.
The school is now checking the status of computers before letting them connect to the Internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.…
http://zdnet.com.com/2100-1105_2-5313402.html
Wednesday, August 18, 2004
MyDoom.s prevention and cure
"This mass-mailing virus appears to contain photos but actually attempts to install a backdoor Trojan horse."
http://reviews-zdnet.com.com/4520-6600_16-5428414.html
News: Special Reports: XP update: Windows XP SP2 on the hot seat
"As Microsoft releases its major update for Windows XP, Service Pack 2, companies are examining the software to see how it will fit into their systems. IBM, for one, wants to hold off until it has been further tested. Companies will also want to consider options to replace or enhance some of the new security features."
http://zdnet.com.com/2251-1110-5302605.html
Tuesday, August 17, 2004
TechNet Support WebCast: Understanding Microsoft Windows XP Service Pack 2 - 883733
"Thursday, August 19, 2004: 10:00 AM Pacific time (Greenwich mean time - 7 hours)
The changes to Microsoft Windows Firewall, Automatic Updates, and the Windows kernel help provide a better environment for Microsoft Windows customers. These changes may require modifications to be fully deployed in an enterprise computing environment. This Support WebCast discusses the changes in Microsoft Windows XP Service Pack 2 (SP2). The session also talks about how customers in enterprise computing environments can prepare to deploy the service pack. It discusses the details of buffer overflow prevention, network protection, and patching technologies in Windows XP SP2, and the deployment mechanisms to control each."
http://support.microsoft.com/default.aspx?scid=kb;en-us;883733&Product=winxp
Windows XP Service Pack 2 on CD Available Later this Summer. Order Here.
"You will be able to order this CD when it becomes available later this summer. "
The best way to ensure you get SP2 when it is released is by turning on the Automatic Updates feature in Windows XP. Visit the Protect Your PC site to let us turn it on for you or follow these manual steps—either way you'll get SP2 automatically as Microsoft releases it.
http://protect.microsoft.com/security/protect/WSA/en/default.asp
http://www.microsoft.com/athome/security/protect/windowsxp/updates.aspx
http://www.microsoft.com/windowsxp/downloads/updates/sp2/cdorder/en_us/default.mspx
Microsoft Takes New Development Track
"In addition to efforts to recruit developers through its many high-school and college programs, Microsoft is looking to its recently announced Express tools to bring in a new class of developers. Microsoft announced the Express versions of its Visual Studio tools at Tech Ed Europe last month, saying the tools are aimed at casual developers, hobbyists and students.
At the conference, Microsoft announced Express versions of its popular tools, including Visual Web Developer 2005 Express Edition, for building Web sites and Web services; Visual Basic 2005 Express Edition, which is aimed at helping beginners learn to program; and SQL Server 2005 Express Edition, a lightweight version of SQL Server, also for students and hobbyists, among others.…"
Two developers said they were impressed with the Express tools but put off by Microsoft's marketing plans. Tim Huckaby, CEO of InterKnowlogy LLC, in Carlsbad, Calif., said Microsoft is "selling itself short and doing a small disservice to the Express tools when they proclaim them to be 'for hobbyists, enthusiasts and students.' To me, that type of statement implies that the Express line is a set of toys.
"Those who have seen or used them know this is far from the case. There is no reason in the world that highly scalable enterprise software cannot be built in the Express tools," Huckaby said.
Huckaby said he can envision business analysts and nontechnical users using the Express tools to prototype applications. "How perfect is a world where part of the design is a prototype built by the business owner of the project itself?" he asked. "Then they throw it over the wall to the developers to build."
Stephen Forte, chief technology officer of New York-based Corzen Inc., agreed. Forte said he began programming using macros because he found using professional tools "intimidating." But after working with the program for a while, he moved on to master other tools and languages, he said. Forte said the Express tools are quite capable. "What's great about the Express products is that they use the full-blown .Net Framework," he said.…
http://www.eweek.com/article2/0,1759,1636268,00.asp
Monday, August 16, 2004
InfoWorld: New tool identifies 'phishy' Web sites: August 16, 2004: By : SECURITY
"The new product, called Web Caller-ID, can detect Web pages dressed up to look like legitimate e-commerce sites. WholeSecurity is marketing the technology to banks, credit card companies and online retailers as a way to prevent unwitting customers from accessing false sites, to reduce fraud and increase confidence in online commerce, the company said.
Phishing scams are online crimes that use unsolicited commercial, or 'spam,' e-mail to direct Internet users to Web sites controlled by thieves, but are designed to look like legitimate e-commerce sites. Users are asked to provide sensitive information such as a password, Social Security number, bank account or credit card number, often under the guise of updating account information.… "
http://www.infoworld.com/article/04/08/16/HNphishywebsites_1.html
Programs seem to stop working after you install Windows XP Service Pack 2 - 842242
"After you install Microsoft Windows XP Service Pack 2 (SP2), some programs may seem not to work. By default, Windows Firewall is enabled and blocks unsolicited connections to your computer. This article discusses how to make an exception and enable a program to run by adding it to the list of exceptions. This procedure permits the program to work as it did before the service pack was installed. "
To help provide security for your Windows XP SP2-based computer, Windows Firewall blocks unsolicited connections to your computer. However, sometimes you might want to make an exception and permit someone to connect to your computer.
After you install Windows XP SP2, client applications may not successfully receive data from a server.
Alternatively, server applications that are running on a Windows XP SP2-based computer may not respond to client requests.…
http://support.microsoft.com/default.aspx?kbid=842242
Internet's 'white pages' allow data attacks | CNET News.com
"The same technology that allows Web surfers to locate and connect to computers on the Internet can be used to create covert communications channels, bypass security measures and store distributed content, a security researcher said.
The security hack essentially uses data transferred by domain name service (DNS) servers to hide additional information in the network communications. DNS servers act as the white pages of the Internet, invisibly transforming easy-to-remember domain names--such as www.cnet.com--into the numerical network addresses used by computers. Moreover, corporate security measures, such as firewalls, tend to ignore DNS data because they assume it's harmless, said Dan Kaminsky, a security researcher for telecommunications firm Avaya and a speaker at the Defcon hacking conference here.
'DNS is everywhere--you cannot communicate over the global Internet without knowing where to go,' he said. 'No one notices DNS. No one monitors it.…'"
http://news.com.com/2100-1002_3-5291874.html
Saturday, August 14, 2004
Toolkits to Unblock/Block Delivery of Windows XP SP2
"While recognizing the security benefits of Windows XP SP2, some organizations have requested the ability to temporarily disable delivery of this update via Automatic Updates (AU) and Windows Update (WU). These organizations have populations of PCs, upon which they have enabled AU. This is done to ensure that these PCs receive all critical security updates. Since SP2 will start to be delivered to PCs running Windows XP or Windows XP with SP1 via AU starting on August 16, these customers would like to temporarily block the delivery of SP2 in order to provide additional time for validation and testing of the update. In response to these requests, Microsoft is providing this set of tools."
Un-block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=b2300c7b-f3d7-48d6-b86c-1256c0321727&DisplayLang=en" target="_blank
Temporarily Block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=871e8b42-c6d7-4402-a5a9-9d52a9cd2500&DisplayLang=en" target="_blank
Toolkit to Temporarily Block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows
http://www.microsoft.com/downloads/details.aspx?FamilyID=8bce6bba-ea5d-4425-89c1-c1cb1ccd463c&DisplayLang=en" target="_blank
http://reviews.cnet.com/5208-6132-0.html?forumID=32&threadID=32676&messageID=375942
Friday, August 13, 2004
AIM Beta Fixes Security Hole
"America Online Inc. has released a beta version of AOL Instant Messenger that fixes a critical security hole that could open users to remote attack.
As previously reported, AOL had promised to fix the vulnerability in an upgraded version of AIM. On Tuesday, it made a test version of AIM 5.9 available for download.
http://www.eweek.com/article2/0,,1634224,00.asp?kc=ewnws081104dtx1k0000599"
Security researchers had found that AIM 5.5 for Windows, and possibly earlier versions, was vulnerable to an attacker executing arbitrary code.
An attacker could initiate a buffer overflow through AIM's "Away" feature if a user were to click on a malicious link sent in an instant message. The "Away" features allows AIM users to send automatic messages about their presence status.
AOL spokesman Andrew Weinstein said the Dulles, Va., company knew of no active exploits of the vulnerability. Security research company iDEFENSE Inc., which put out an advisory this week, had informed AOL of the issue about a month ago, giving AOL an opportunity to plug the hole, Weinstein said.
The fix also will be incorporated into the full release of AIM 5.9, which a spokeswoman said is expected in early fall.…
http://www.eweek.com/article2/0,,1634224,00.asp?kc=ewnws081104dtx1k0000599
Wednesday, August 11, 2004
Between the Lines : Opera not exactly the safe alternative - ZDNet.com
"Opera not exactly the safe alternative"
In the wake of several critical flaws in Internet Explorer that surfaced in July (and that were subsequently patched by Microsoft), some security pros were recommending abstinence from using IE. Mozilla’s Firefox and Opera’s namesake browser were cited as alternatives. Even I heeded the advice and switched to Opera. But, in addition to some usability problems I encountered, Opera isn’t exactly turning out to be the safe haven I hoped it was. According to a recently updated security advisory from GreyMagic Software, a vulnerability in Opera has not only left Windows systems exposed, but assumed-to-be impenetrable Mac and Linux systems as well. The vulnerability exists in Opera versions up to and including version 7.53. While an update (version 7.54) is available from Opera’s Web site, the vulnerability calls into question whether Opera needs some better security talent on its development team. GreyMagic’s advisory notes that Opera overlooked the vulnerability when it addressed a previously issued advisory. This isn’t the first bad news for alternative browsers. Just last week, researchers identified a non-IE-specific buffer-overflow vulnerability in the Portable Network Graphics (PNG) image file format.…
http://blogs.zdnet.com/index.php?p=312
Windows XP Service Pack 2
"The package was released on August 6, but it will not appear immediately on www.windowsupdate.com. Turning on Automatic Updates is the best way to upgrade. Microsoft will use metered downloads to update users steadily without bogging down the entire Internet."
SP2 is dedicated to enhancing security in a variety of ways. Microsoft had originally planned for SP2 to turn on automatic updates by default to ensure that as many users as possible installed important patches. But this turned out to be illegal in some countries. Instead, users will be forced to choose "on" or "off" (see Figure 1 ) during installation (or, we assume, on first boot for machines that come with SP2 preinstalled).
Automatic updates currently install only critical patches for Windows; in SP2, they'll install both critical and security patches for Windows as well as some other Microsoft applications. If a download is interrupted, Windows Update will restart at the point where the interruption occurred. At shutdown, if updates have been downloaded but not installed, Windows will offer to install them and then shut down.…
http://www.pcmag.com/print_article/0,1761,a=132722,00.asp
Download details: Windows XP Service Pack 2 for IT Professionals and Developers
"This installation package is intended for IT professionals and developers downloading and installing on multiple computers on a network. If you're updating just one computer, please visit http://www.microsoft.com/protect."
There are a few people who will upgrade their nets one computer at a time. This post is for small nonprofits, community centers, and home networks.
http://www.microsoft.com/downloads/details.aspx?FamilyID=049c9dbe-3b8e-4f30-8245-9e368d3cdb5a&DisplayLang=en
Tuesday, August 10, 2004
AIM Security Hole Opens Users to Remote Attack
"…oversized values passed to the 'goaway' function of AIM's 'aim:' URI handler may be used to overwrite the pointer to the Structured Exception Handler, which could then be used to execute code written by the attacker."
The attack would appear as a link in the instant messaging window, and the user would have to click on the link in order to be subject to the vulnerability.
America Online Inc.'s AIM 5.5 has been tested and shown to be vulnerable, but iDEFENSE suspects that previous versions are also vulnerable. The iDEFENSE advisory says that AOL "recommends that Windows users of AIM upgrade to the latest beta version to be released on Aug. 9.
"This new version of AIM addresses the vulnerability described herein and can be obtained via the AOL Instant Messenger portal.…"
http://www.eweek.com/article2/0,1759,1633779,00.asp?kc=ewnws081004dtx1k0000599
Bagle Worm Variant Slips Through Defenses
"Another variant of the ubiquitous Bagle worm is now making its way across the Internet, flooding in-boxes with infected Zip files. The newest member of the Bagle family, named Bagle.AQ, arrives via an e-mail message with a spoofed sending address and no subject line. The only text in the message body is typically one or two words, either 'price' or 'new price.'
The name of the infected Zip file that accompanies the message is some variation on that theme as well. The files often are named Price.zip or New_price.zip, and may have a number appended to the end of the file name. "
Bagle.AQ first appeared Monday and began circulating in earnest in the early afternoon Eastern time. Some users reported getting as many as 100 infected messages in an hour. Virus researchers said they first began seeing Bagle.AQ at about 8 a.m. Monday and have been seeing thousands of copies an hour.
If a user opens the Zip file with an application such as Windows Internet Explorer that is not a standalone Zip file handler, the user will see an HTML file that contains exploit code. The file will then execute an included .exe file, which is a Trojan, according to McAfee Inc.'s analysis. The Trojan then connects to a number of remote sites to download the actual viral code.
This new variant is one of the few worms or viruses known to download its viral payload remotely after it is already resident on a PC. It is not until the code is actually pulled down by the Trojan that Bagle.AQ begins trying to replicate itself by sending out e-mails.…
http://www.eweek.com/article2/0,1759,1633740,00.asp?kc=ewnws081004dtx1k0000599
eWEEK.com's Special Report on Windows XP Evolution
"Windows XP Evolution"
Monday, August 09, 2004
Image flaw pierces PC security - News - ZDNet
"Six vulnerabilities in a common code that handles an open-source image format could allow intruders to compromise computers running Linux and may allow attacks against Windows PCs as well as Macs running OS X.
The security issues appear in a library supporting the portable network graphics (PNG) format, used widely by programs such as the Mozilla and Opera browsers and various e-mail clients. The most critical issue, a memory problem known as a buffer overflow, could allow specially created PNG graphics to execute a malicious program when the application loads the image.
Among the programs that use libPNG and are likely to be affected by the flaws are the Mail application on Apple Computer's Mac OS X, the Opera and Internet Explorer browsers on Windows, and the Mozilla and Netscape browsers on Solaris, according to independent security researcher Chris Evans, who discovered the issues. Apple and Microsoft could not immediately be reached for comment. Evans did not test every platform to check which vulnerabilities work, he said.…"
http://zdnet.com.com/2100-1105_2-5298999.html?tag=adnews
Friday, August 06, 2004
Malicious program aims for Pocket PCs - News - ZDNet
"A malicious Trojan horse program has emerged for Pocket PCs, antivirus companies said Thursday, but they characterized the threat as relatively low.
The program, known alternately as Backdoor.Bardor.A and WinCE.Brador.a, lets an attacker gain full control of the handheld and is the first such 'backdoor Trojan' program to emerge for Pocket PCs. However, such backdoor programs are not capable of propagating on their own and instead must be sent as e-mail attachments or through similar means, making them less dangerous.
Symantec rated the bug a '1,' the lowest on its five-point scale. In a statement, the company offered the standard warning not to open or execute files from unknown sources.… "
Last month, researchers identified the first Windows CE virus, which researchers said was mostly a "proof-of-concept" bug, or one designed to demonstrate its own feasibility.
"We were certain that a viable malicious program for PDAs would appear soon after the first proof-of-concept viruses emerged for mobile phones and Windows Mobile," Eugene Kaspersky, head of Anti-Virus Research at Kaspersky Labs, said in a statement. "WinCE.Brador.a is a full-scale malicious program ready to go: unlike proof-of-concept malware (malicious software), Brador has a complete set of destructive functions typical for back doors.…"
http://zdnet.com.com/2100-1105_2-5298781.html?tag=adnews
Flaws in Graphics Library Could Bring Attacks
"A researcher performing a source-code audit on a popular graphics library has found multiple security vulnerabilities in it that could be used to crash programs or execute attack code.
The PNG library (libpng) is a collection of graphics routines to manipulate PNG (portable network graphics) files. PNG (Portable Networks Graphic) is a graphics format that was designed many years ago as an alternative to the still more popular GIF format. "
…full story
http://www.extremetech.com/article2/0,1558,1632761,00.asp
Mozilla, Opera Plug Security Holes
"The Mozilla Foundation and Opera Software ASA have released updates to their Web browsers to fix a series of security vulnerabilities.
Mozilla on Wednesday posted new versions of its Firefox browser, Thunderbird e-mail client and Mozilla suite that provide fixes to three issues. They include a newly reported critical vulnerability affecting multiple vendors' software that uses the library for the Portable Networks Graphic (PNG) image format. "
The other two issues, as previously reported, were related to the handling of security certificates in the Mozilla browsers that, among other things, could allow an attacker to lull users into a false sense of security on a site. …full story
http://www.extremetech.com/article2/0,1558,1632752,00.asp
Wednesday, August 04, 2004
New MyDoom Variant Uses Yahoo People Search
Another new version of MyDoom is worming its way through the Internet, and this variant—like the last one—uses Yahoo as part of its infection routine.
MyDoom.P is similar to most of the other MyDoom variants in that it arrives via e-mail, with a spoofed sending address and a subject line designed to make it look like the message is related to one that the recipient sent. Among the subject lines in the e-mails are "SN: New secure mail," "Secure delivery," "Re: Extended mail," "Delivery Status (Secure)," "Re: Server Reply" and "SN: Server Status."
The body of the e-mail contains any of a number of sentences, some of which refer to the included Zip file. Many of the messages reference security or refer to the attached file as a "secure Zip file."
Once opened, the executable file copies itself to the Windows system directory as "winlibs.exe." The executable contains a list of dozens of common first and surnames that it puts through Yahoo's People Search in an attempt to find more e-mail addresses to mail itself to, according to a preliminary analysis of the worm done by the staff of the Internet Storm Center at The SANS Institute in Bethesda, Md.…
http://www.eweek.com/article2/0,1759,1630965,00.asp?kc=ewnws080404dtx1k0000599
Free .NET and Native Windows Dev Tools
"Everyone likes having something for free, and Microsoft has some software development tools that you can have for nothing more than the cost of the download."
VC++ Toolkit
http://www.microsoft.com/downloads/details.aspx?FamilyID=272be09d-40bb-49fd-9cb0-4bfa122fa91b&displaylang=en
.NET SDK
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B3A2CA6-3647-4070-9F41-A333C6B9181D&displaylang=en
Platform SDK
http://www.microsoft.com/msdownload/platformsdk/sdkupdate/
May Community edition of Visual Studio .NET 2005
http://lab.msdn.microsoft.com/vs2005/get/default.aspx
Express version of Visual C++
http://lab.msdn.microsoft.com/express/visualc/default.aspx
http://www.ddj.com/documents/s=9204/ddj040801dnn/
Tuesday, August 03, 2004
Build Your Own ASP.NET Website Using C# and VB.NET. Pt. 4. - WebReference.com-
"Web Forms and Web Controls"
At the heart of ASP.NET is its ability to create dynamic form content. Whether you’re creating a complex shopping cart application, or a simple page to collect user information and send the results out via email, Web Forms have a solution. They allow you to use HTML controls and Web controls to create dynamic pages with which users can interact. In this chapter, you will learn how Web Forms, HTML controls, and Web controls, in conjunction with VB.NET and C# code, should change the way you look at, and develop for, the Web.
http://www.webreference.com/programming/asp_net4/
Sasser (A-F) Worm Removal Tool (KB841720)
"This tool will help to remove the Sasser (A-F) worm from infected systems.… it automatically checks for infection and removes any of the targeted worms that are found."
After running, the tool displays a message describing the outcome of the detection and removal process. The tool can be safely deleted after it has run. Also, the tool creates a log file named sasscln.log in the %WINDIR%\debug folder.…
http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en
What You Should Know About the Mydoom and Doomjuice Worms
"The Mydoom worm leaves a program, known as a back door, that could potentially allow an attacker to gain access to infected computers. Several variants of the worm are currently circulating, and malicious programs related to Mydoom have been released under the names Doomjuice and Zindos. Microsoft urges you to take action to remove these worms and help keep your computer safe from malicious intrusions."
Download and install the tool from the Download Center.
http://www.microsoft.com/downloads/details.aspx?familyid=c14bfbe4-3d50-464d-a26c-9c287f8a08c5&displaylang
http://www.microsoft.com/security/incident/mydoom.mspx
Monday, August 02, 2004
The Search Engine Report - Number 93
Threats to Windows, IIS, and Outlook Express
"Get the details on Microsoft Security Bulletins MS04-018, MS04-019, MS04-020, MS04-021, MS04-024. "
MS04-018, “Cumulative Security Update for Outlook Express,” is caused by a failure of Outlook express to properly handle some specifically malformed e-mail headers. This is a DoS threat and Microsoft reports having seen published exploits but hasn't received any reports from customers that have been compromised by the exploit. This threat is covered by CAN-2004-0215
MS04-019, “Vulnerability in Utility Manager Could Allow Code Execution,” is a local elevation of privilege threat that can’t be exploited remotely. MSBA will report if your system needs this update and Systems Management Server (SMS) can help deploy it.
MS04-020, “Vulnerability in POSIX Could Allow Code Execution,” is an unchecked buffer vulnerability in the Portable Operating System Interface for UNIX. MSBA will report if your system needs this update and SMS can help deploy it. This threat is covered by CAN-2004-0210.
MS04-021, “Security Update for IIS 4.0,” is a buffer overrun vulnerability in the redirect function that can allow remote execution. MSBA will report if your system needs this update and SMS can help deploy it. This threat is covered by CAN-2004-0205.
MS04-024, “Vulnerability in Windows Shell Could Allow Remote Code Execution,” replaces MS03-027 for Windows XP (but not for the other affected operating systems). This threat is covered by CAN-2004-0420.
…
http://www.microsoft.com/technet/security/bulletin/ms04-018.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-019.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-020.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-024.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-027.mspx
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0215
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0210
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0205
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0420
http://techrepublic.com.com/5102-6264-5284223.html
Saturday, July 31, 2004
MyDoom Attacks Microsoft.com Through Back Door
"As many security researchers feared after analyzing the code for MyDoom.O, a second, related attack began in earnest Tuesday with a new piece of code using the back door installed by MyDoom.O to spread itself and launch a DDoS (distributed denial of service) attack against Microsoft.com.
MyDoom.O, also known as MyDoom.M or MyDoom.M@mm, installs a Trojan known as Zincite.A on every PC that it infects. The Trojan opens TCP port 1034 and listens for further commands. Zindos spreads itself by scanning for machines listening on port 1034. When it finds one, Zindos copies itself to the infected PC and then Zincite executes the copy. "
Analysts at Symantec Corp., based in Cupertino, Calif., said Tuesday that they had discovered a previously unknown function in MyDoom.O that keeps track of every system the worm infects.
After finding this, the analysts went back over the code from MyDoom.L and found that that variant contains the same feature. This led the team to conclude that the worms' author may have used the machines infected by the L variant as a seeding ground for the latest version.…
http://www.eweek.com/article2/0,1759,1628180,00.asp
Unscheduled Security Update Fixes Critical IE Flaws
"The security bulletin accompanying the updates, numbered MS04-025, addresses three vulnerabilities rated 'critical' that could result in an attacker executing code in the context of a logged-on user. If the user is logged on as Administrator, the attack would have free reign over the system."
The first vulnerability, titled "Navigation Method Cross-Domain Vulnerability," could allow an attacker to execute arbitrary code in the Local Machine security zone. Microsoft reports that many factors can make this vulnerability more difficult to execute, including installing certain previous updates. Nevertheless, Symantec reports this as the most critical of the three vulnerabilities and that they have already seen exploits of it in the wild.
The other two vulnerabilities are related to the browser's handling of image files. Both are buffer overflows in Internet Explorer's handling of these files, one for BMP files and one for GIF files. Internet Explorer 6 Service Pack 1 and Windows Server 2003, both 32-bit and 64-bit editions, are not affected by the BMP file vulnerability.
The GIF buffer overrun affects all versions of Windows and Internet Explorer and results when the attacker attempts to free memory that has already been freed. The bulletin indicates that this is most likely a denial-of-service attack, but the potential exists for it to be used to execute arbitrary code.
The update replaces a previous update, MS04-004. If users have applied that patch and subsequently applied non-public hotfixes they may have to reapply them after applying the new cumulative update. Users should consult the bulletin and Microsoft support.
http://www.microsoft.com/technet/security/bulletin/MS04-025.mspx
http://www.eweek.com/article2/0,1759,1629584,00.asp
Friday, July 30, 2004
Open-Source Exploit Tool: 'Point, Click, Root'
"It's as easy as 'point, click, root.'
At a heavily attended panel Wednesday at the Black Hat security conference here, HD Moore and 'spoonm' unveiled the latest release of the Metasploit Framework, an exploit tool designed to quickly take over a variety of target platforms."
Although the framework was developed several months ago, the "preview release" of Version 2.2 offers users the opportunity to develop their own custom modules. The tool, written in Perl for Unix environments, also includes a Cygwin shell to enable it to run under Windows. The official Version 2.2 will be available in a week or so.
Both researchers demonstrated the tool "owning," or taking over, Mac OS X, Windows 2000 Server and Windows XP systems, although the duo used a VMWare virtual machine to speed the process. Metasploit even runs on a Sharp Zaurus PDA, which when equipped with a Wi-Fi card can be used to attack while mobile.
The authors described the tool as the open-source, cheap alternative to Immunity's Canvas and Core Security Technology's Impact tools, designed for commercial applications and requiring the latest exploits almost as quickly as possible. Metasploit currently contains 35 exploits and 40 payloads; the tool was designed to point the user to the exploit appropriate for the operating system.
Although available for several months, the tool is apparently still relatively unknown even in security circles, judging from the reaction of attendees. Patrick Chambet, a senior consultant at French IT security firm Edelweb SA, said he found the presentation the most interesting of the day. Another researcher said he worried that Metasploit would be used by "script kiddies" as a means to quickly own other boxes.…
http://www.eweek.com/article2/0,1759,1628707,00.asp?kc=ewnws072904dtx1k0000599
Monday, July 26, 2004
Researchers Wonder Why Bagle Virus is a Success
"Several new variants of the venerable Bagle virus visited themselves upon corporate networks last week, frustrating administrators and virus researchers who continue to wonder why these worms can still infect thousands of machines after months of warnings.
None of the most recent variants is particularly innovative or clever in its social engineering efforts or infection methods. Many versions of the Bagle virus actually make it difficult for users to infect machines by requiring them not only to open an attachment but also to enter a password to launch the malware. "
http://www.eweek.com/article2/0,1759,1626686,00.asp?kc=ewnws072604dtx1k0000599
VeriSign: Be Wary Online. Be Very Wary.
"Internet commerce grew 13.2 percent in the past 12 months, according to a new report. Not bad.
But fraud grew faster.
The report, to be released Monday, said phishing attacks, in which fraudsters lure people to sites that mimic those of top retailers in order to steal personal information, have become more acute and global in nature. "
http://www.internetnews.com/ec-news/article.php/3385681
iPaq handheld can easily switch between cellular and Wi-Fi
"Hewlett-Packard is introducing its first iPaq handheld that can easily switch between traditional cellular and Wi-Fi networks.
The h6315, which was co-developed with T-Mobile, operates on a traditional cellular network but can automatically hop over onto a faster Wi-Fi connection when one is available. The device also has a built-in camera and a detachable keyboard and can also act as a cell phone using the GSM cellular network. "
http://zdnet.com.com/2100-1103_2-5282083.html
Windows Security Updates for July 2004
"The Microsoft Windows security updates for July 2004 address newly discovered issues in Windows, including Microsoft Internet Explorer and Microsoft Outlook Express, both components of Windows. If you have any of the software listed on this page installed on your computer, you should visit the Windows Update Web site to install related updates."
http://www.microsoft.com/security/bulletins/200407_windows.mspx
Windows XP Home and Professional Service Configurations by Black Viper
"This section on Windows XP Service Configurations has complete explanations of each service and advice and which ones you can safely disable."
http://www.blackviper.com/WinXP/servicecfg.htm
Friday, July 23, 2004
Gmail Vulnerability Reported
"A vulnerability in Google's Gmail may give remote users access to Gmail user information. The culprit is the Gmail CheckAvailability script. Remote users can apply the '/accounts/CheckAvailability' script repeatedly until the system returns another user's information.
The only information that seems to be revealed are the user's first and last name and desired Gmail account. Also, in order to access this information, the remote user must have a valid Gmail invite. While this may not be as much of a security caution as, say, revealing credit card information, it still causes a worry for users wishing to remain anonymous.… "
http://www.webpronews.com/news/ebusinessnews/wpn-45-20040720GmailVulnerabilityReported.html
Thursday, July 22, 2004
What's Next: For Doctored Photos, a New Flavor of Digital Truth Serum
"'It used to be that you had a photograph, and that was the end of it - that was truth,' said Hany Farid, an associate professor of computer science at Dartmouth College who is a leader in the field. 'We're trying to bring some of that back. To put some measure of guarantee back in photography.'
At stake is more than the fate of possible child pornographers. The United States military has become increasingly reliant on digital images from drones and satellites to give soldiers a sense of the battlefield. Law enforcement officers routinely use digital cameras to photograph crime scenes. Newspapers and magazines are now dependent on digital photographs that can be easily doctored.
Over the last three years, Professor Farid and his students have become experts at forgery, making hundreds of images that look authentic but have in fact been digitally tweaked. License plate numbers are changed. A single stool standing on a checkerboard floor is suddenly a pair of stools. Dents on a car are wiped away with a few mouse clicks.
The skillful tampering disturbed the images in ways that the human eye could not detect. But Professor Farid says his algorithms can spot them and sound the alarm."
For example, when two images are spliced together - like the picture of a shark attacking a helicopter that has circulated around the Internet in the past few years - one or both of the original pictures usually has to be shrunk, enlarged or rotated to make the pieces fit together. And those changes, no matter how artful, leave clues behind.
Take a picture that is 10 pixels by 10 pixels, for a total of 100. Stretch it to 10 by 20 pixels, and image-editing software like Adobe Photoshop will assign the picture's original pixels to every other slot in the new picture. That leaves 100 pixels "blank," or without values. Image-editing software fills in the gaps by examining what their neighbors look like, and then applying an average. To oversimplify, if pixel A is blue, and pixel C is red, the blank pixel B will become purple.
This kind of averaging becomes "pretty obvious" after some analysis of the image, Professor Farid said.
In tests on several hundred doctored photos, this technique for detecting changes proved to be virtually foolproof if the picture quality was high enough. Uncompressed TIFF image files, which contain enormous amounts of data, were like an open book to Professor Farid's team.
But Professor Farid said that for now the technique does not work as well with files created in JPEG, the compressed picture format most commonly used online.…
http://www.nytimes.com/2004/07/22/technology/circuits/22next.html
ASP.NET Web Matrix Guided Tour
"What Level of Expertise Is Assumed in the Guided Tour?
You should be fluent in HTML and general Web development terminology. You do not need previous ASP.NET experience for most of the walkthroughs, although you should be familiar with the general web concepts behind interactive Web pages, including forms, XML, and data access.
For a walkthrough of ASP.NET itself, please review the ASP.NET QuickStart Tutorial at: http://www.asp.net/Tutorials/quickstart.aspx"
http://www.asp.net/webmatrix/tour/getstarted/intro.aspx
Bagle.ag and Bagle.ai - ZDNet: Reviews
"The most recent variations of the Bagle worm family appear to be based on code similar to the Bagle.af variation. Bagle.ag (w32.bagle.ag@mm, also known as Beagle.ac and Bagle.ah) and Bagle.ai (w32.bagle.ai@mm, also known as Bagle.ae, Beagle.ag, and Bagle.ah) are mass-mailing worms that vary in length and are packed with the UPX file compressor. They use various subject lines and attached files to spread via e-mail. They also attempt to spread via shared network files. They both try to terminate security apps that may be running on the infected machine and install a backdoor Trojan horse. Additionally, Bagle.ai will attempt to terminate any Netsky virus that may be running on the infected machine. This worm does not affect Linux, Unix, or Mac OS systems. Because Bagle.ag and Bagle.ai spread via e-mail and open a backdoor Trojan, they rate a 6 on the CNET/ZDNet Virus Meter. "
How it works
Both versions of Bagle use a different set of subject and body texts, contain their own SMTP engine to send copies of themselves. They also harvest e-mail addresses from infected machines, spoof the e-mail sender's address, and password-protect the attached file. These worms contain a remote access Trojan horse, copy themselves to folders that use the string "shar" in the name, and will attempt to terminate security programs and other computer viruses and worms.
Additionally, Bagle.ai will use mutex names already used by the Netsky in order to prevent further Netsky infections. Bagle.ai will also delete the registry entries for security apps and other viruses such as Netsky.
Bagle.ag creates the following in the Win/System32 folder
sys_xp.exe
sys_xp.exeopen
sys_xp.exeopenopen
Bagle.ai creates the following in the Win/System32 folder:
WinXP.exe
WinXP.exeopen
WinXP.exeopenopen
WinXP.exeopenopenopen
WinXP.exeopenopenopenopen
Bagle.ag opens TCP port 1080 while Bagle.ai opens ports 1080 (TCP) and 1040 (UDP).…
http://reviews-zdnet.com.com/4520-6600_16-5144521.html
Wednesday, July 21, 2004
eMachine Shop, a bridge between the real world and computers.
"At eMachineShop, you can download a powerful yet straightforward CAD program to design objects. You then specify the material and submit your design to the site, and eMachineShop will price it according to the materials and machining or forming difficulty, along with the number of steps involved in manufacturing and finishing. The available materials range from every imaginable kind of plastic to metals such as aluminum, brass, and steel. You can specify bending, drilling, milling, turning, and various other operations. You can also specify finishes, including plating and powder coating.
The eMachineShop software prices your job on the spot, while the 3D rendering is on your screen. You find out what your part or run of parts will cost you in minutes, not days. When you give the okay, eMachineShop makes your parts and ships them to you. It's a full-capability fabrication facility that you pay for on an as-needed basis. Customers have created both simple and complex parts; you can see some photos on the site."
Lewis wasn't content to stop at mechanical fabrication. His goal is to be a one-stop product development facility. "As Amazon is to books I want to be to manufacturing," he says. Since more and more devices contain electronics, it made sense to offer circuit board fabrication too. You can go to sites like www.pcbexpress.com and order up a run of single-layer or multilayer circuit boards, but you have to be sufficiently knowledgeable to generate files that will control their drilling and routing equipment.
So Lewis created the Web site Pad2Pad, where you can design your board with simple downloadable software, place parts, run traces, spot holes, and connect layers. Like eMachineShop, Pad2Pad prices your work in advance and actually assembles the boards from a large inventory of parts instead of delivering solder-ready boards.
Of course, Pad2Pad can't stock all of the millions of electronic components, especially the more esoteric integrated circuits, but it can leave holes or surface-mount pads on the board for you to stuff or solder to. Pad2Pad is still in launch mode, and Lewis is expanding the parts inventory. He plans to connect with a major parts distributor, thus gaining access to just about anything you can put on a circuit board.…
http://www.pcmag.com/article2/0,1759,1619713,00.asp
Keep Your Kids Safe
"In September 2003, 53-year-old John Zuccarini was arrested at a Florida hotel and, after admitting to his crimes in a plea bargain, became the first person convicted under the national Truth in Domain Names Act. The crime: According to the United States Attorney's office for the Southern District of New York, Zuccarini registered and used more than 3,000 misleading domain names, many of which directed children to hard-core porn sites and graphic depictions of young people engaged in sex acts. The domains included www .teltubbies.com and www.bobthebiulder.com—both misspellings of the addresses for popular children's TV shows.
Porn is just one of many issues parents should be concerned about when their kids go online. Problems could be as dangerous as encountering a predator in a chat room, as common as sharing music and software illegally via peer-to-peer file-sharing services, or as simple as spending far too much time playing games and chatting with friends.
Recent market research suggests that many parents consider online chatting more dangerous than Web surfing. Last year, Microsoft's MSN service shut down its chat rooms in 28 countries partly because of concerns about sexual predators preying on minors. And in a study published by Harris Interactive in November 2003, 24 percent of 550 U.S. teens surveyed said they had been contacted online by a stranger who tried to arrange an off-line meeting.
Meanwhile, the amount of time kids spend online is just as important an issue. A November study performed by the Pew Internet & American Life Project found that almost 70 percent of young users say they would find it "very hard to give up" the Internet, compared with only 48 percent who said the same about television. Computers have become a hub for social activity. And for the most part, it is an unsupervised environment. Many parents go to sleep every night convinced that their kids are sleeping too, while some of the kids are actually chatting online with friends and strangers. And not surprisingly, some kids are also chatting when they should be doing homework.
The Internet has so much good to offer, however, that you can't just take your kids' access away permanently. It's a great educational resource and an essential form of communication today. And the more your kids learn about using the Internet now, the better prepared they'll be for using it in the future.
Parents need to protect their kids online. Just as they want some control over where their kids go and whom they talk to in real life, parents need to establish some rules on where they go and whom they talk to online. Which strategy is best for your needs is your decision. The good news is that the products on the market offer a variety of approaches, so finding the right solution shouldn't be too difficult.…"
http://www.pcmag.com/article2/0,1759,1620643,00.asp
Tuesday, July 20, 2004
Picasa: Automated Digital Photo Organizer software: Download
"Picasa is now part of Google. Download version 1.6 for Free!
Picasa works with the digital photo files on your PC to create a better, more organized viewing and editing experience. Picasa will not delete or move the location of pictures saved on your PC. "
http://www.picasa.com/google/
Zend Updates PHP Scripting Language
"Zend 5 includes a new version of the Zend engine, known as Zend Engine II. It also features object orientation, enhanced XML processing and Web services support.
Gutmans said the previous release, PHP 4, came out four years ago and the installed base of users has grown from 1.5 million then to 16 million now.
'The Zend II engine is a complete rewrite of all the object-oriented capabilities in the language,' Gutmans said. The new version features exception handling."
"The reason why object-oriented development gets such a big focus is that the more critical the application becomes the more structured the development becomes," Gutmans said. And as PHP becomes more a part of the enterprise, interoperability becomes important, he said.
The XML extensions in PHP 5 were rewritten to use the GNOME Project's XML and Extensible Stylesheet Language Transformations libraries. The new version includes a new module, MySQLi, for database support, as well as SQLite, an embedded database.…
http://www.eweek.com/article2/0,1759,1624753,00.asp
Monday, July 19, 2004
ZDNet AnchorDesk: Is another MSBlast attack on its way?
"The Eschelbeck Theory, named after Gerhard Eschelbeck, a security researcher at Qualys.
The theory states that only half of the vulnerable systems in the world are patched within the first 30 days of a patch's existence, and that within that same 30-day period, someone invariably releases a virus or a worm to take advantage of the still-vulnerable systems. Given that, the clock is already ticking on these new Microsoft vulnerabilities. Of course, several of the newly announced flaws also involve Internet Explorer in some way.… "
http://reviews-zdnet.com.com/AnchorDesk/4520-7297_16-5144057.html?tag=ns
Saturday, July 17, 2004
Crypto-Gram: July 15, 2004
"
- Due Process and Security
- Security Notes from All Over: X-Ray Machines and Building Security
- Cryptographers and U.S. Immigration
- Crypto-Gram Reprints
- Security and Portable Storage Devices
- News
- Counterpane News
- Security Notes from All Over: Coca-Cola and the NSA
- The Doghouse: ICS
- The CLEAR Act Does Not Help Fight Terror
http://www.schneier.com/crypto-gram-0407.html
Latest Bagle succeeds by sheer numbers, contacts one of 141 Web sites - News - ZDNet
"Bagle.AF arrives in e-mail as an attached file and infects computers running the Windows operating system if the user opens the file. The program attempts to halt more than 250 security applications from running on the computer, mails itself to any e-mail address it can find on the computer, and contacts one of 141 German Web sites, twice the number that a previous version of the virus contacted. The diverse Web sites have likely been compromised by online vandals, leaving behind software to record which computers have been infected by the Bagle worm.
With that information, the vandals can use the compromised computers to spread spam, or sell the information to spammers, Friedrichs said. The virus leaves open a backdoor specifically for that purpose."
http://zdnet.com.com/2100-1105_2-5271930.html
Spam grows as spammers mature - News - ZDNet
"It's been 12 months since spam really burst into the public consciousness. Before then it had certainly been a well-publicized problem, but often only with the more tech-savvy while the wider public had far more questions than answers about strange mail appearing in their inbox.
Then last summer the level of spam passed the important watershed of the 50 percent mark--meaning more e-mail traffic was unsolicited than not. For every 100 e-mails the average user was receiving more than 50 that were offering everything from pornographic content to college diplomas.
Since shattering that 50 percent mark the level of global spam e-mail has continued to skyrocket. By most measures that figure is now somewhere around 75 percent. "
But perhaps the biggest change in the spam world has been in the types of e-mails users are seeing. According to the latest figures from Clearswift, the traditional mainstays of the inbox menace--namely pornography and more frivolous offers--are being replaced by financial services, scams and pharmaceuticals which despite the best advice of the 'don't buy from spammers' lobby still seem to have some traction in the marketplace.…
http://zdnet.com.com/2100-1105_2-5270764.html?tag=adnews
Friday, July 16, 2004
Google Toolbar Can Browse By Name
"The Google Toolbar's new Browse by Name feature, introduced on Wednesday, takes the concept of searching from the browser address bar and kicks it up a notch. Now, to search, you simply type the name or description of the site you're looking for. If there's a strong match, Google will go straight to that page. For example, 'new york times', 'ben and jerry', 'john kerry' and 'strong bad' all zoom directly to the appropriate page. "
When there's no single obvious match, you haven't lost anything—you still get a standard Google search results page. Browse by Name is especially useful when the URL you're searching for is not obvious. For example, Browse by Name on "Muir Woods" brings up the National Park Service's site, www.nps.gov/muwo.…
http://www.eweek.com/article2/0,1759,1623934,00.asp?kc=ewnws071504dtx1k0000599
'Important' Windows flaw could turn critical - News - ZDNet
"Security experts are bracing themselves for a spate of new worms and viruses designed to exploit of the seven new vulnerabilities announced by Microsoft on Tuesday as part of its monthly patch cycle.
Of the new vulnerabilities, Windows Shell (MS04-024)--has been picked out by security experts as a potential target for future worms and viruses.
Ben Nagy, senior security engineer at security researcher firm eEye, said he expects the Windows Shell bug to be the most serious threat--despite Microsoft rating the problem as 'important' rather than 'critical'."
According to Microsoft, if a user is vulnerable to MS04-024 and has administrator privileges, an attacker could "take complete control of the affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges."
However, the flaw is not rated as critical because it would require "significant user interaction" to work. This means that a user would need to open an e-mail attachment, or download a file from a malicious Web site.
Richard Starnes, president of security industry group ISSA UK, said that malware writers usually reverse-engineer Microsoft's patches in order to produce exploits. Based on his on experience of previous threats, he expects the first batch of new exploit codes to be available as early as next week. These would probably be used to create a worm delivered as an email attachment.…
http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx
http://zdnet.com.com/2100-1105-5268989.html
Wednesday, July 14, 2004
MS Security Bulletin MS04-022: Vulnerability in Task Scheduler Could Allow Code Execution
"This update resolves a newly-discovered, privately reported vulnerability. A remote code execution vulnerability exists in the Task Scheduler because of an unchecked buffer. The vulnerability is documented in the Vulnerability Details section of this bulletin.
If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. However, user interaction is required to exploit this vulnerability. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.…"
http://www.microsoft.com/technet/security/bulletin/MS04-022.mspx
MS Security Bulletin MS04-023: Vulnerability in HTML Help Could Allow Code Execution
"This update resolves two newly-discovered vulnerabilities. The HTML Help vulnerability was privately reported and the showHelp vulnerability is public. Each vulnerability is documented in this bulletin in its own Vulnerability Details section.
If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts that have full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.…"
http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx
Defensive Perimeter, The Top 10 Best Security Tools:
"You may not don battle gear, but switch on an Internet-connected PC, and you've stepped into a war zone where countless insurgents relentlessly pound your system, looking for ways in. 'Keep Your PC Safe', part of the comprehensive new Security Special on our Security Watch page, provides the Special Forces training you need to prevail. As backup, in this roundup we've stockpiled reviews of the products recommended in that PC combat manual."
http://www.pcmag.com/article2/0,1759,1618645,00.asp
http://www.pcmag.com/category2/0,1738,12,00.asp
http://www.pcmag.com/article2/0,1759,1621759,00.asp
Tuesday, July 13, 2004
Troubleshooting Windows XP, Tweaks and Fixes for Windows XP
"To use the Regedits: Save the REG File to your hard disk. Double click it and answer yes to the import prompt. REG files can be viewed in Notepad by right clicking on the file and selecting Edit.…"
http://www.kellys-korner-xp.com/xp_tweaks.htm
Anti-Phishing Working Group
"What is Phishing?
Phishing attacks use 'spoofed' e-mails and fraudulent websites designed to fool recipients into divulging personal financial data such as credit card numbers, account usernames and passwords, social security numbers, etc. By hijacking the trusted brands of well-known banks, online retailers and credit card companies, phishers are able to convince up to 5% of recipients to respond to them."
http://www.antiphishing.org/
Atak, The latest mass-mailing Worm sleeps to avoid detection - News - ZDNet
"The latest mass-mailing worm, Atak, hides by going to sleep when it suspects that antivirus software is trying to detect it.
Atak was first discovered Monday. Although antivirus companies do not expect it to cause much damage, they say it will be a nuisance because it can generate a large amount of spam.…"
"Atak tries to tell when someone is stepping through the code to analyze whether it is a virus or not. Often, a virus will contain lots of code that is designed to make it more complicated for (antivirus) companies to write the detections,"Graham Cluley, senior technology consultant for antivirus company Sophos said.…
http://zdnet.com.com/2100-1105-5267258.html
Lovgate.ad prevention and cure - ZDNet: Reviews
"Lovgate.ad is the latest variation of a known mass-mailing worm family that includes a backdoor Trojan horse and, this time, overwrites several key Windows files, including executables files ending with .exe. While Lovgate.ad (w32.Lovgate.ad@mm, also known by some antivirus software vendors as Lovgate.ab, Lovgate.ae, Lovgate.ah, Lovgate.ao) doesn't destroy personal data, it will destroy access to the applications that run the data. Restoration from a backup utility after removal of the worm is required. Mac, Linux, and Unix users are not affected. At this time, Lovgate.ad is spreading slowly via e-mail, network-shared files, and network connections still vulnerable to the flaw that allowed the MSBlast worm to spread last summer. Because Lovgate.ad contains a variety of ways in which to spread and could damage system files, this worm rates a 6 on the CNET/ZDNet Virus Meter.…"
http://reviews-zdnet.com.com/4520-6600_16-5143031.html
FCC chief blogs to tech industry - News - ZDNet
"WASHINGTON--U.S. Federal Communications Commission Chairman Michael Powell has started his own Web log, or blog, to reach out to the high-tech community and bypass the scores of Washington lobbyists who typically skulk around his office.
Powell, who wants to avoid regulating new technologies like Web-based telephone service for fear of stifling innovation, said he started the blog to encourage the high-tech industry to get involved because its past practice of flying under the radar to avoid regulations would no longer work.
'Regulated interests have about an 80-year head start on the entrepreneurial tech community when it comes to informing regulators what they want and need, but if anyone can make up for that, Silicon Valley can,' he said in his first blog comments posted Thursday morning.…"
http://www.alwayson-network.com/comments.php?id=4860_0_3_0_C
http://zdnet.com.com/2100-1103_2-5264405.html