Open Source Security: Still a Myth:
“by John Viega
Does the open source process guarantee better security than proprietary development methods do? Not necessarily, warns John Viega. There are several security challenges facing open source software that many developers have so far failed to recognize.”
“In the real world, it's rare that someone reviewing code for security will perform a thorough audit. Line-by-line review is often not feasible, simply because the human mind can't retain a detailed understanding of a large code base. Generally, people have tools to support them. Those tools are a starting point for manual inspection, which focuses on the findings of the tool and looks to see whether there's actually anything to the problem.
"Real" analysis tools are just starting to hit the market. The tools people use tend to be simple ones that don't do sophisticated analysis--grep-like tools such as RATS and flawfinder. A few commercial companies offer "web scanners" that look for common vulnerabilities in an application using a fuzz-like approach (you pick the inputs you think might exercise a common problem, give it a go, and see what happens). The problem with black-box testing for security is that most programs are complex and have states that an automated crawler isn't likely to find. Security problems are often buried in complex systems. Finding them with such an approach would require heavy user interaction to put the system into a large number of different states.
With both the grep-like tools and the black-box testing tools, you will almost always have a large number of false positives to sift through. Most potential auditors throw up their hands in frustration pretty quickly. Those who don't will usually focus on only a few of the reported issues. Even research tools such as BOON tend to have incredibly high false-positive rates.”
The Myth of Open Source Security , http://www.developer.com/tech/article.php/626641
Why Open Source Software/Free Software? Look at the Numbers! , http://www.dwheeler.com/oss_fs_why.html
http://www.onlamp.com/pub/a/security/2004/09/16/open_source_security_myths.html
Tuesday, September 21, 2004
Open Source Security: Still a Myth
Download details: Application Compatibility Guide for Windows XP SP 2
"Windows® XP SP2 introduces new security technologies to better enable Windows XP computers to withstand viruses, worms and other kinds of attacks. This guide will assist IT Professionals to test and mitigate application compatibility issues arising from these more stringent security technologies."
Microsoft® Windows® XP Service Pack 2 (SP2) introduces a set of security technologies that improve the ability of Windows XP systems to withstand malicious attacks, and provides the IT administrator with system wide security configuration capabilities.
SP2 is more secure by default, and thus automatically provides Windows XP systems with improved protection. However, because system security becomes more restrictive upon initial installation, SP2 may also expose application compatibility issues. It is important that an investigation into possible application compatibility issues takes place prior to full deployment.
This guidance discusses the security technologies, an application testing process, incompatibility symptoms, mitigation techniques, and deployment scenarios. It makes no assumption about the size or complexity of the network, and is as relevant to peer-to-peer environments as it is to Active Directory environments.
File Name: | AppCompat-XPSP2.msi |
Download Size: | 2956 KB |
Date Published: | 8/25/2004 |
Version: | 1.0 |
http://www.microsoft.com/downloads/details.aspx?familyid=9300becf-2dee-4772-add9-ad0eaf89c4a7&displaylang=en
Visual Web Developer 2005 Express Edition Beta
"Visual Web Developer 2005 Express Edition is a lightweight, easy-to-use and easy-to-learn development tool focused exclusively on Web development. Inside, you will find everything you need to begin building exciting, dynamic Web applications with ASP.NET 2.0. "
Visual Web Developer 2005 Express Edition provides everything you need to begin building Web applications with ASP.NET 2.0. It provides:
- Visual designers that make creating Web applications easy via an easy-to-use drag-and-drop interface
- Powerful code editor with rich functionality such as IntelliSense that makes writing code and HTML faster
- Quickly create data-driven Web applications using the built-in data controls and integrated access to Microsoft SQL Server 2005 Express
- Support for multiple languages, including Visual Basic, C#, and J#
- Get started using the built-in, fully functional starter kits like the Personal Web Starter Kit
Simple management
Create your applications in Visual Web Developer 2005 Express Edition, and then easily deploy using the built-in Copy Web tool that streamlines the process. Visual Web Developer 2005 Express Edition includes support for creating and consuming Web services, validating applications across multiple browsers, and easily running and debugging your code using the built-in test Web server, without having to have access to IIS.
Personal Web Starter Kit
Inside Visual Web Developer 2005 Express Edition is the Personal Web Starter Kit , a fully functional sample application that will help you get up and running quickly. This Starter Kit provides all the basic functionality you need to build your own personal Web site, including a balanced and customizable look and feel, a Web-based administration system, rich photo gallery, membership, role management, and more.
http://lab.msdn.microsoft.com/express/vwd/starterkit/default.aspx
http://lab.msdn.microsoft.com/express/vwd/default.aspx
Saturday, September 18, 2004
How to Handle Copyright Infringement Found by the Search Engines
"
- Take screen captures of the pages
- Download Google/Yahoo/SE cache as proof (if available)
- Document whois information and figure out who the ISP is
- Call or Email the number (if any) listed on the contact us page
- If no response in a few days, send an email to the ISP with the subject Digital Millennium Copyright Act Copyright Infringement with the proof listed above. I ask them to take down the pages that were stolen, providing the file names and paths.
- Send email/fax to the search engines
- Google's DMCA
- Yahoo's Copyright Infringement & Yahoo's Page Deletion Process
- Ask Jeeves TOS, scroll down and you will see 'Copyrights and Copyright Agent' section with a form."
Serious Kerberos flaws affect Cisco and Mac, but not Windows
"MIT's Kerberos authentication utility has been found to have some serious vulnerabilities. Windows is not affected, but other widely used products from Cisco and Apple are definitely vulnerable, as are many third-party applications that rely on Kerberos 5."
http://techrepublic.com.com/5100-6264-5366280.html
Friday, September 17, 2004
Don't get phished again: Check trustwatch.com | Tech News on ZDNet
"Noting that businesses lost close to $50 billion in 2003 as a result of covering the costs of identity theft, GeoTrust on Monday made available a free domain-verification service that consumers can use to check the security and trustworthiness of Web sites.
Before providing a credit card number, personal identification information or other confidential data to a Web site, a consumer can use the TrustWatch service to check that the site has been verified by a trusted third party and is using appropriate safeguarding measures.
Typing a Web site address or domain name into a search box on the TrustWatch site will return a confidence rating based on GeoTrust's data about that site. "
http://news.zdnet.com/2110-3513_22-5367650.html
Thursday, September 16, 2004
Add clickable icons to your links
"When you're working with CSS, sometimes the obvious technique doesn't produce the effect you might expect or desire. Fortunately, there's a good chance that you can achieve the effect you want if you're willing to look beyond the obvious and try other methods. "
http://builder.com.com/5100-6371_14-5354381.html?tag=e601
Major graphics flaw threatens non XP SP2 Windows PCs | Tech News on ZDNet
"The critical flaw has to do with how Microsoft's operating systems and other software process the widely used JPEG image format and could let attackers create an image file that would run a malicious program on a victim's computer as soon as the file is viewed. Because the software giant's Internet Explorer browser is vulnerable, Windows users could fall prey to an attack just by visiting a Web site that has affected images.…"
"The potential is very high for an attack," said Craig Schmugar, virus research manager for security software company McAfee. "But that said, we haven't seen any proof-of-concept code yet." Such code illustrates how to abuse flaws and generally appears soon after a software maker publishes a patch for one of its products.
The flaw affects various versions of at least a dozen Microsoft software applications and operating systems, including Windows XP, Windows Server 2003, Office XP, Office 2003, Internet Explorer 6 Service Pack 1, Project, Visio, Picture It and Digital Image Pro. The software giant has a full list of affected applications in the advisory on its Web site. Windows XP Service Pack 2, which is still being distributed to many customers' computers, is not vulnerable to the flaw.…
http://news.zdnet.com/2100-1009_22-5366314.html
Windows XP Security Guide Overview
"The Windows® XP Security Guide v2.0 describes the features and recommended settings for Microsoft Windows XP Service Pack 2 (SP2). The Guide includes thoroughly tested templates for security settings for Windows Firewall, which replaces Internet Connection Firewall (ICF). Information is provided about closing ports, Remote Procedure Call (RPC) communications, memory protection, e-mail handling, Web download controls, spyware controls, and much more."
In addition to describing the features and recommended settings for Windows XP
SP2, this guide includes thoroughly tested templates for security settings for
Windows Firewall, which replaces Internet Connection Firewall.
http://www.microsoft.com/technet/security/prodtech/winclnt/secwinxp/default.mspx
The Great Debates: Pass Phrases vs. Passwords. Part 1 of 3
"Information security fosters some interesting debates. The issues range in importance, but they all demonstrate that the field is still growing and exciting. I would like to summarize some of these debates, and offer my own partial entries. For the first set of these articles, I will enter the passwords fray and address the issue of pass phrases versus passwords."
OK, maybe “pass phrases versus passwords” is really “the other great debate” or the “kind of boring and few people care” debate. In any case, which is more secure, pass phrases or passwords? The answer is not as clear-cut as it may seem.…
http://www.microsoft.com/technet/security/secnews/articles/itproviewpoint091004.mspx
Download details: Visual Basic and C# Code Samples
"This download includes a master set of Visual Basic and Visual C# code samples demonstrating various aspects of the language in the following areas: syntax, data access, Windows Forms, Web development and Web services, XML, security, the .NET Framework, file system and file I/O, interop and migration issues, COM , ADO.NET, and advanced topics including graphics with GDI , remoting, serialization, MSMQ, and Windows services."
Download Size: 6578 KB - 13400 KB
Date Published: 3/11/2004
Version: 7.1
CSharp.msi 6578KB
http://download.microsoft.com/download/6/4/7/6474467e-b2b7-40ea-a478-1d3296e78adf/CSharp.msi
VisualBasic.msi 6822KB
http://download.microsoft.com/download/6/4/7/6474467e-b2b7-40ea-a478-1d3296e78adf/VisualBasic.msi
http://www.microsoft.com/downloads/details.aspx?FamilyId=08E3D5F8-033D-420B-A3B1-3074505C03F3&displaylang=en
Wednesday, September 15, 2004
Deploying Windows Firewall Settings for Microsoft Windows XP with Service Pack 2
"Windows XP Service Pack 2 (SP2) includes the Windows Firewall, a replacement for the Internet Connection Firewall (ICF) in previous versions of Windows XP. Windows Firewall is a stateful host-based firewall that discards unsolicited incoming traffic, providing a level of protection for computers against malicious users or programs. To provide better protection for computers connected to any kind of network (such as the Internet, a home network, or an organization network), Windows XP SP2 enables Windows Firewall on all network connections by default. This new behavior can impair some types of communications. This article describes how to deploy the appropriate configuration settings for Windows Firewall on an organization network so that it is enabled and providing protection, and so that communications are not impaired."
File Name: | WF_XPSP2.doc |
Download Size: | 942 KB |
Date Published: | 8/12/2004 |
Version: | 2.4 |
Manually Configuring Windows Firewall in Windows XP Service Pack 2
http://go.microsoft.com/?linkid=664515
http://www.microsoft.com/downloads/details.aspx?FamilyID=4454e0e1-61fa-447a-bdcd-499f73a637d1&displaylang=en
Saturday, September 11, 2004
Windows XP Service Pack 2 Resources for IT Professionals
Explore the new features of Windows XP SP2 and find out what makes it a worthwhile update.
Get information on planning, testing, installing, application compatibility, and configuring your network.
Get details on managing Windows Firewall, controlling users’ access to the Internet, and using Group Policy.
Download and Install Service Pack 2 on a Single Computer
Order the Service Pack on CD
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/winxpsp2.mspx
New MyDoom Variants Could Forewarn Major Attack
"The arrival of four new variants of the MyDoom worm within the last 24 hours has anti-virus experts worried that the virus creator may be preparing to release a major onslaught."
On Thursday afternoon, MyDoom.U, V, W and X all appeared within a couple of hours of one another. None of the variants is particularly worrisome or innovative on its own, but taken as a whole, the release of four versions so close together is of some concern, experts said. The last time so many variants of one virus were released in such a short period of time was in July when four minor versions of the Bagle virus emerged, followed by a major new strain. http://www.eweek.com/article2/0,1759,1624970,00.asp
Anti-virus researchers say the MyDoom author could be following a similar pattern.
"The last time this happened was with Bagle, and the next one was a big one," said Sam Curry, vice president of the eTrust Security division at Computer Associates International Inc., in Islandia, N.Y. "Plus, we're getting close to the end of the alphabet and a lot of times the Z and AA variants have some extra impact."
Curry also noted that with the third anniversary of the Sept. 11 terrorist attacks coming up Saturday, virus writers may be looking to make a splash.
http://www.eweek.com/article2/0,1759,1644713,00.asp
Friday, September 10, 2004
Using special characters as typographic niceties
"Using special characters on Web pages
Generally speaking, you can use any of the characters that appear on the standard computer keyboard in the text of your Web page. The only exceptions are the ampersand (&), less than (<), and greater than (>) symbols, which have special meaning in HTML/XHTML code and are reserved for that use.
The standard keyboard characters are only a limited subset of the characters available. There are many other special-purpose characters available in the extended character set of most fonts, including accented letters, math symbols, and an assortment of punctuation characters and symbols.
In order to use one of the reserved symbols (&, <, >) or an extended character in a Web page, you must use an escape sequence, which is a sequence of characters that forms a special code instructing the browser to render the character identified by the code instead of the individual characters that make up the code. "
http://builder.com.com/5100-6371_14-5341208.html?tag=e601
Thursday, September 09, 2004
The Search Engine Report - Number 94
"In This Issue
- Search Engine Watch News
- Search Engine Strategies Set For Stockholm, Chicago
- Search Engine Watch Articles
- Search Engine Articles
- Search Engine Resources
- About The Newsletter"
SearchDay, Sept. 1, 2004
http://www.searchenginewatch.com/searchday/article.php/3402251
Everything You Ever Wanted to Know About URL
SearchDay, Aug. 24, 2004
http://www.searchenginewatch.com/searchday/article.php/3398511
http://searchenginewatch.com/sereport/article.php/3405411
Microsoft Sets a New Deadline for XP Service Pack 2
"On Tuesday, Microsoft began notifying customers that it has established new deadlines regarding how long they will be able to block Windows XP Service Pack 2 (SP2) from downloading automatically to their systems.
Microsoft made available to customers in August a couple of different tools to temporarily disable the delivery of SP21 to users machines via its Windows Update/Automatic Update patching services. A number of customers had requested these tools, claiming they were not ready to take delivery of SP2, as they had not tested SP2 adequately to make sure it did not break their applications."
this deadline to 240 days, or eight months, from August 16. As a result, Microsoft will now begin pushing SP2 to all Windows XP and Windows XP Service Pack 1 customers automatically via Windows Update and Automatic Update as of April 12, 2005.
Microsoft noted the change in its patch-blocking dates2 on its TechNet IT portal Web site, as well as in a note it sent to corporate customers via e-mail.
Microsoft released SP2 to manufacturing on August 6 and has been rolling it out in stages to its various XP customer bases over the past month.
Even though Microsoft has deemed SP2 a "critical" update, some corporate and home users have been leery to install it. Microsoft has acknowledged that a number of applications, including several of its own3, do not work properly with SP2 unless certain settings are changed. And a number of third-party hardware and software vendors still have yet to provide patches and updates to their products that will allow them to work with SP2.
1. http://www.microsoft-watch.com/article2/0,1995,1639208,00.asp
2. http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx
3. http://www.microsoft-watch.com/article2/0,1995,1636071,00.asp
http://www.microsoft-watch.com/article2/0,1995,1643925,00.asp
Wednesday, September 08, 2004
Building a Wi-Fi Antenna Out of a Tin Can
"While there are many commercial antennas available on the market today, they can be expensive. And hey, let's face it, attaching a commercial antenna to your Wi-Fi network will not turn heads like making your own will.
There are several different types of antennas that you can build. The most famous Wi-Fi antennas are made from either a coffee can or a Pringles potato chip can. In this chapter you learn how to build your own antenna from a regular, metal coffee can. You will be able to build it quickly and cheaply. As an added bonus, you will have lots of coffee which will come in handy in staying awake for the other projects in this book."
http://www.extremetech.com/print_article/0,1583,a=134389,00.asp
PC Magazine Feature: External Storage: Little Big Drives
"Backup has gotten personal: Small drives that match your lifestyle have changed the face of storage and backup. Add-in drives are out of the question now that notebooks are steadily replacing desktops. Fast interfaces such as USB 2.0 and FireWire have made plug-and-play external drives practical, and skyrocketing capacity and plummeting costs have made them affordable.
The files you're storing have changed, too. You're more likely to need room for your digital photos, gigabytes of music, Web site backup, or video-editing projects. IDE drives have become orders of magnitude more reliable in recent years, so the emphasis in backup has moved from generational data sets and disaster recovery to a clean working copy of your hard drive.…"
http://www.pcmag.com/article2/0,1759,1639442,00.asp
Tuesday, September 07, 2004
Saturday, September 04, 2004
Register for the Microsoft Security Newsletter for Home Users
"This newsletter provides practical security tips, topical security guidance, useful resources and links, pointers to helpful community resources, and a forum for you to provide feedback and ask security-related questions.
Available in text and HTML formats, the newsletter is a convenient way for you to stay up-to-date on the latest issues, insights, and events surrounding Microsoft"
http://www.microsoft.com/athome/security/secnews/default.mspx
Friday, September 03, 2004
Windows XP won't boot after installing SP2 – a BIOS update may be necessary
"Installing Microsoft Windows XP Service Pack 2 on a PC with a 'Prescott' CPU and certain chip sets can cause it to fail to reboot completely. The problem can be solved with a workaround or a BIOS update. "
Depending on the chipset, motherboard manufacturer, BIOS version, and CPU, installing Microsoft Windows XP Service Pack 2 can result in an unbootable computer system. The problem is generally associated with Intel "Prescott" CPUs and its chipsets, but not every such combination will cause a problem. As of this writing, motherboards exhibiting the behavior include:
Albatron PX865 PE Pro
Shuttle SB61G2
Jetway i875P
Soyo P4I865P
Aopen AX4SG Max
Asus P4P800-E deluxe
Abit IS7-V
Foxconn 865A01-G-6EKRS
Technically speaking, the problem revolves around the machine's BIOS not installing a production level microcode update. To check whether the BIOS is at the correct level, download the Intel Processor Frequency ID utility. The microcode version is identified by this utility as CPU Revision, which should equal at least 8.…
http://techrepublic.com.com/5100-6268_11-5330486.html?tag=fdnew
Thursday, September 02, 2004
Kerberos Flaws Allow Access to Protected Networks
"The Massachusetts Institute of Technology has disclosed a number of serious security flaws in the Kerberos v5 authentication system, the worst of which could give unauthorized users access to protected corporate networks.… "
http://www.eweek.com/article2/0,1759,1641644,00.asp?kc=ewnws090104dtx1k0000599
Wednesday, September 01, 2004
Distribute This Denial of Service Checklist
"The important thing to realize about DDoS attacks is that they aren't going to go away, and there's no way of preventing them. They have been around for a very long time, and they are getting easier to carry out. That's because there are increasing numbers of poorly secured home PCs with always-on Internet connections just waiting to be discovered and taken over by hackers. These compromised PCs are incorporated into attack networks, where they remain dormant until a short burst of command and control traffic activates them and turns them into crazed attack zombies, firing off data at a target host until -- the hacker hopes -- it disappears under a deluge of unwanted packets.…"
http://www.esecurityplanet.com/prevention/print.php/3400861
Monday, August 30, 2004
Order Windows XP Service Pack 2 on CD Now!
System Requirements
To install Windows XP Service Pack 2 via CD, you need:
A PC with Windows XP Home Edition, Professional, Media Center Edition, or Tablet PC Edition installed
233-megahertz or higher processor
64 megabytes (MB) of RAM or higher
1.6 GB of available hard disk space during installation
CD-ROM drive
Share This CD with a Friend
After you have installed Service Pack 2, Microsoft encourages you to give this CD to a friend or family member using Windows XP.
Friday, August 27, 2004
Security Watch Special: Windows XP SP2 Has a Dangerous Hole — WMI
"Microsoft will make Windows XP Service Pack 2 available to the general public this week, but the enthusiasm for the first significant OS update in almost two years is now competing with worries over discoveries and claims of new holes and vulnerabilities. Through an anonymous tip, we confirmed a core vulnerability that could lead to spoofing in the Windows Security Center, the new control panel for a PC's security status. Another unpatched hole has been found in Internet Explorer that affects Version 5.01 and later, as well as on an SP2 updated system. The hole allows an attacker to download a malicious executable to the user's system without their knowledge. For more on this IE flaw, see our Windows Update and vulnerabilities.
This week's tip also deals with the new SP2 security; we show you how to open ports to allow products like PCAnywhere to work correctly. For more on the potential spoofing of the Windows Security Center, see our Top Threat. "
WMI may not only be a security hole, but a crater in the wrong hands. Due to the nature of WMI, the WSC could potentially allow attackers to spoof the state of security on a user's system while accessing data, infecting the system, or turning the PC into a zombie for spam or other purposes.
According to Microsoft, WMI is the Microsoft implementation of Web-Based Enterprise Management (WBEM), an industry standard for accessing management information on a system. For Windows XP Service Pack 2, Microsoft added new fields or records to keep track of the Firewall and Antivirus information in the WMI database. Unfortunately, the WMI database is designed to be accessible via the WBEM API (application program interface) and is available to any program that wants to access the WMI. These programs can be desktop applications written in desktop- or web-based scripting or ActiveX modules.
This open door to the security status of a system can be exploited several ways. First, a malicious site could download a file (possibly with the drag and drop exploit discussed in our Windows updates and vulnerabilities section), which could run and access the WMI, monitoring the status of the firewall and antivirus protection.
http://www.pcmag.com/print_article/0,1761,a=133959,00.asp
Application Compatibility Guide for Windows XP SP 2
"Windows® XP SP2 introduces new security technologies to better enable Windows XP computers to withstand viruses, worms and other kinds of attacks. This guide will assist IT Professionals to test and mitigate application compatibility issues arising from these more stringent security technologies."
| ||||||||||
This is approximately 100 pages
This guidance discusses the security technologies, an application testing process, incompatibility symptoms, mitigation techniques, and deployment scenarios. It makes no assumption about the size or complexity of the network, and is as relevant to peer-to-peer environments as it is to Active Directory environments.
http://www.microsoft.com/downloads/details.aspx?FamilyId=9300BECF-2DEE-4772-ADD9-AD0EAF89C4A7&displaylang=en
Thursday, August 26, 2004
Microsoft offers SP2 compatibility guide - News - ZDNet
"Microsoft has launched a do-it-yourself kit to help IT professionals assess their software's compatibility with Windows XP Service Pack 2.
Fears among system administrators and IT managers that SP2 may break homegrown applications have already led to delays in corporate launches. To get users back on track and keep developers' blood pressure down, Microsoft is offering the application compatibility testing guide.
The guide, which can be retrieved from Microsoft's Download Center, is designed to help administrators 'test and mitigate application compatibility issues.' Microsoft adds that the guide is meant for a network of any size and is 'as relevant to peer-to-peer environments as it is to Active Directory environments.'… "
http://www.microsoft.com/downloads/details.aspx?FamilyId=9300BECF-2DEE-4772-ADD9-AD0EAF89C4A7&displaylang=en
http://zdnet.com.com/2100-1104-5323378.html
Wednesday, August 25, 2004
Between the Lines � Bush in 30 seconds. Your privacy in 2. - ZDNet.com
"When Web developer Shawn Smith used Google to find some of Moveon.org’s well-known "Bush in 30 seconds" anti-Bush video spots, he got more than he bargained for. Google’s search results also revealed a significant amount of confidential personal information about the Web site’s subscribers including names, e-mail addresses, newsletter subscription information, and areas of political interest. The exposure exemplifies the power and maturity of search engines like Google and begs the question "Have you Googled your own Web site recently?"… "
http://blogs.zdnet.com/index.php?p=376
Tuesday, August 24, 2004
Vulnerability could turn drag-and-drop into drag-and-infect- News - ZDNet
"An independent researcher warned that an Internet Explorer vulnerability could turn drag-and-drop into drag-and-infect, even on computers updated with Microsoft's latest security patch.
The flaw affects the latest version of Internet Explorer running on Windows XP, even after the latest major update--known as Service Pack 2--is applied. An attacker using the flaw could install a program on a victim's computer after convincing the person to visit a malicious Web site and click on a graphic.
The attacker's program would be placed in the Windows startup folder and would run the next time the user restarted the computer. The security researcher who discovered the flaw, known by the online nickname 'http-equiv,' posted an example to show the power of the flaw."
"If you look at the Web page, all you see are two red lines and an image; drag the image across the two lines and drop it," he said. "What you have actually done is drop (a program) into your startup folder. Next time you switch the computer on it runs the program."
Security information company Secunia believes the program that takes advantage of the issue could be simplified to only require a single click from the user. Secunia rated the flaw as "highly critical," its second-highest rating of vulnerability threats.
Microsoft said the issue did not pose a serious risk to users because it requires an attacker to trick people into visiting a Web site and taking some action at the site.…
http://zdnet.com.com/2100-1105_2-5318358.html
Friday, August 20, 2004
New Attack Pierces Fully Patched XP Machines, but SP2 not vulnerable
"Security researchers have identified a new version of the Download.Ject attack that is now being used on the Internet and can compromise fully patched Windows XP machines.
The new version of the attack just appeared Thursday afternoon, and while details are still sketchy, experts say its main purpose is to install a back door on compromised PCs. Users victimized by the attack receive an e-mail or an instant message containing a link directing them to a malicious Web page. "
The page is being hosted by a number of different sites, all of which share common "whois" information and appear to be deliberately serving the page, according to Thor Larholm, senior security researcher at PivX Solutions LLC, based in Newport Beach, Calif. The Trojan also will change the start page of the infected PC.
Once a user clicks on the link, the Web server attempts to download the back door. Larholm said a PC running a fully patched copy of Windows XP and Internet Explorer 6 will be compromised by the new version of Download.Ject, as will machines running older version of Windows and IE.
But machines running SP2 (Service Pack 2) for XP are not vulnerable to the new attack. Larholm added that the vulnerabilities exploited in this attack have been known for some time.…
http://www.eweek.com/article2/0,1759,1638037,00.asp?kc=ewnws082004dtx1k0000599
Judges rule file-sharing software legal - News - ZDNet
"Like the lower court, the Ninth Circuit implied that any ability to hold software developers liable for copyright infringement might have to come from Congress rather than from the courts. Indeed, the RIAA is already pursuing that goal, with a bill sponsored by Sen. Orrin Hatch, a Republican from Utah, that would put legal responsibility for copyright infringement back on the peer-to-peer developers.
But the Appeals Court closed its decision with words that some technology lawyers are interpreting as a cautionary note to Congress, as it debates that bill.
'The introduction of new technology is always disruptive to old markets and particularly to those copyright owners whose works are sold through well-established distribution mechanisms,' the court wrote. 'Yet history has shown that time and market forces often provide equilibrium in balancing interests, whether the new technology be a player piano, a copier, a tape recorder, a video recorder, a personal computer, a karaoke machine or an MP3 player. Thus, it is prudent for courts to exercise caution before restructuring liability theories for the purpose of addressing specific market abuses, despite their apparent present magnitude.' "
http://zdnet.com.com/2100-1104_2-5316570.html?tag=adnews
Thursday, August 19, 2004
Security Watch Letter: New MyDoom Piggybacks More Dangerous Worm
"… MyDoom is back with W32/MyDoom.S-mm. This variation, also known as MyDoom.Q@mm, Worm_Ratos.A, and I-worm.Win32.Ratos, was discovered on August 15th, and jumped to a medium-level threat very quickly. While MyDoom.S doesn't really do much, it downloads a particulary nasty trojan called Backdoor.Ratos.A. …"
http://www.pcmag.com/article2/0,1759,1637560,00.asp
http://www.pcmag.com/print_article/0,1761,a=133647,00.asp
Study: Unpatched PCs compromised in 20 minutes - News - ZDNet
"Don't connect that new PC to the Internet before taking security precautions, researchers at the Internet Storm Center warned Tuesday.
According to the researchers, an unpatched Windows PC connected to the Internet will last for only about 20 minutes before it's compromised by malware, on average. That figure is down from around 40 minutes, the group's estimate in 2003.
The Internet Storm Center, which is part of the SANS Institute, calculated the 20-minute 'survival time' by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.… "
The drop from 40 minutes to 20 minutes is worrisome because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from Internet threats.
Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the center's data believeable.
"It's a tough problem, and it's getting tougher," Conti said.
One of Conti's administrators tested the center's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.
The school is now checking the status of computers before letting them connect to the Internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.…
http://zdnet.com.com/2100-1105_2-5313402.html
Wednesday, August 18, 2004
MyDoom.s prevention and cure
"This mass-mailing virus appears to contain photos but actually attempts to install a backdoor Trojan horse."
http://reviews-zdnet.com.com/4520-6600_16-5428414.html
News: Special Reports: XP update: Windows XP SP2 on the hot seat
"As Microsoft releases its major update for Windows XP, Service Pack 2, companies are examining the software to see how it will fit into their systems. IBM, for one, wants to hold off until it has been further tested. Companies will also want to consider options to replace or enhance some of the new security features."
http://zdnet.com.com/2251-1110-5302605.html
Tuesday, August 17, 2004
TechNet Support WebCast: Understanding Microsoft Windows XP Service Pack 2 - 883733
"Thursday, August 19, 2004: 10:00 AM Pacific time (Greenwich mean time - 7 hours)
The changes to Microsoft Windows Firewall, Automatic Updates, and the Windows kernel help provide a better environment for Microsoft Windows customers. These changes may require modifications to be fully deployed in an enterprise computing environment. This Support WebCast discusses the changes in Microsoft Windows XP Service Pack 2 (SP2). The session also talks about how customers in enterprise computing environments can prepare to deploy the service pack. It discusses the details of buffer overflow prevention, network protection, and patching technologies in Windows XP SP2, and the deployment mechanisms to control each."
http://support.microsoft.com/default.aspx?scid=kb;en-us;883733&Product=winxp
Windows XP Service Pack 2 on CD Available Later this Summer. Order Here.
"You will be able to order this CD when it becomes available later this summer. "
The best way to ensure you get SP2 when it is released is by turning on the Automatic Updates feature in Windows XP. Visit the Protect Your PC site to let us turn it on for you or follow these manual steps—either way you'll get SP2 automatically as Microsoft releases it.
http://protect.microsoft.com/security/protect/WSA/en/default.asp
http://www.microsoft.com/athome/security/protect/windowsxp/updates.aspx
http://www.microsoft.com/windowsxp/downloads/updates/sp2/cdorder/en_us/default.mspx
Microsoft Takes New Development Track
"In addition to efforts to recruit developers through its many high-school and college programs, Microsoft is looking to its recently announced Express tools to bring in a new class of developers. Microsoft announced the Express versions of its Visual Studio tools at Tech Ed Europe last month, saying the tools are aimed at casual developers, hobbyists and students.
At the conference, Microsoft announced Express versions of its popular tools, including Visual Web Developer 2005 Express Edition, for building Web sites and Web services; Visual Basic 2005 Express Edition, which is aimed at helping beginners learn to program; and SQL Server 2005 Express Edition, a lightweight version of SQL Server, also for students and hobbyists, among others.…"
Two developers said they were impressed with the Express tools but put off by Microsoft's marketing plans. Tim Huckaby, CEO of InterKnowlogy LLC, in Carlsbad, Calif., said Microsoft is "selling itself short and doing a small disservice to the Express tools when they proclaim them to be 'for hobbyists, enthusiasts and students.' To me, that type of statement implies that the Express line is a set of toys.
"Those who have seen or used them know this is far from the case. There is no reason in the world that highly scalable enterprise software cannot be built in the Express tools," Huckaby said.
Huckaby said he can envision business analysts and nontechnical users using the Express tools to prototype applications. "How perfect is a world where part of the design is a prototype built by the business owner of the project itself?" he asked. "Then they throw it over the wall to the developers to build."
Stephen Forte, chief technology officer of New York-based Corzen Inc., agreed. Forte said he began programming using macros because he found using professional tools "intimidating." But after working with the program for a while, he moved on to master other tools and languages, he said. Forte said the Express tools are quite capable. "What's great about the Express products is that they use the full-blown .Net Framework," he said.…
http://www.eweek.com/article2/0,1759,1636268,00.asp
Monday, August 16, 2004
InfoWorld: New tool identifies 'phishy' Web sites: August 16, 2004: By : SECURITY
"The new product, called Web Caller-ID, can detect Web pages dressed up to look like legitimate e-commerce sites. WholeSecurity is marketing the technology to banks, credit card companies and online retailers as a way to prevent unwitting customers from accessing false sites, to reduce fraud and increase confidence in online commerce, the company said.
Phishing scams are online crimes that use unsolicited commercial, or 'spam,' e-mail to direct Internet users to Web sites controlled by thieves, but are designed to look like legitimate e-commerce sites. Users are asked to provide sensitive information such as a password, Social Security number, bank account or credit card number, often under the guise of updating account information.… "
http://www.infoworld.com/article/04/08/16/HNphishywebsites_1.html
Programs seem to stop working after you install Windows XP Service Pack 2 - 842242
"After you install Microsoft Windows XP Service Pack 2 (SP2), some programs may seem not to work. By default, Windows Firewall is enabled and blocks unsolicited connections to your computer. This article discusses how to make an exception and enable a program to run by adding it to the list of exceptions. This procedure permits the program to work as it did before the service pack was installed. "
To help provide security for your Windows XP SP2-based computer, Windows Firewall blocks unsolicited connections to your computer. However, sometimes you might want to make an exception and permit someone to connect to your computer.
After you install Windows XP SP2, client applications may not successfully receive data from a server.
Alternatively, server applications that are running on a Windows XP SP2-based computer may not respond to client requests.…
http://support.microsoft.com/default.aspx?kbid=842242
Internet's 'white pages' allow data attacks | CNET News.com
"The same technology that allows Web surfers to locate and connect to computers on the Internet can be used to create covert communications channels, bypass security measures and store distributed content, a security researcher said.
The security hack essentially uses data transferred by domain name service (DNS) servers to hide additional information in the network communications. DNS servers act as the white pages of the Internet, invisibly transforming easy-to-remember domain names--such as www.cnet.com--into the numerical network addresses used by computers. Moreover, corporate security measures, such as firewalls, tend to ignore DNS data because they assume it's harmless, said Dan Kaminsky, a security researcher for telecommunications firm Avaya and a speaker at the Defcon hacking conference here.
'DNS is everywhere--you cannot communicate over the global Internet without knowing where to go,' he said. 'No one notices DNS. No one monitors it.…'"
http://news.com.com/2100-1002_3-5291874.html
Saturday, August 14, 2004
Toolkits to Unblock/Block Delivery of Windows XP SP2
"While recognizing the security benefits of Windows XP SP2, some organizations have requested the ability to temporarily disable delivery of this update via Automatic Updates (AU) and Windows Update (WU). These organizations have populations of PCs, upon which they have enabled AU. This is done to ensure that these PCs receive all critical security updates. Since SP2 will start to be delivered to PCs running Windows XP or Windows XP with SP1 via AU starting on August 16, these customers would like to temporarily block the delivery of SP2 in order to provide additional time for validation and testing of the update. In response to these requests, Microsoft is providing this set of tools."
Un-block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=b2300c7b-f3d7-48d6-b86c-1256c0321727&DisplayLang=en" target="_blank
Temporarily Block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=871e8b42-c6d7-4402-a5a9-9d52a9cd2500&DisplayLang=en" target="_blank
Toolkit to Temporarily Block Delivery of Windows XP SP2 to a PC Through Automatic Updates and Windows
http://www.microsoft.com/downloads/details.aspx?FamilyID=8bce6bba-ea5d-4425-89c1-c1cb1ccd463c&DisplayLang=en" target="_blank
http://reviews.cnet.com/5208-6132-0.html?forumID=32&threadID=32676&messageID=375942
Friday, August 13, 2004
AIM Beta Fixes Security Hole
"America Online Inc. has released a beta version of AOL Instant Messenger that fixes a critical security hole that could open users to remote attack.
As previously reported, AOL had promised to fix the vulnerability in an upgraded version of AIM. On Tuesday, it made a test version of AIM 5.9 available for download.
http://www.eweek.com/article2/0,,1634224,00.asp?kc=ewnws081104dtx1k0000599"
Security researchers had found that AIM 5.5 for Windows, and possibly earlier versions, was vulnerable to an attacker executing arbitrary code.
An attacker could initiate a buffer overflow through AIM's "Away" feature if a user were to click on a malicious link sent in an instant message. The "Away" features allows AIM users to send automatic messages about their presence status.
AOL spokesman Andrew Weinstein said the Dulles, Va., company knew of no active exploits of the vulnerability. Security research company iDEFENSE Inc., which put out an advisory this week, had informed AOL of the issue about a month ago, giving AOL an opportunity to plug the hole, Weinstein said.
The fix also will be incorporated into the full release of AIM 5.9, which a spokeswoman said is expected in early fall.…
http://www.eweek.com/article2/0,,1634224,00.asp?kc=ewnws081104dtx1k0000599
Wednesday, August 11, 2004
Between the Lines : Opera not exactly the safe alternative - ZDNet.com
"Opera not exactly the safe alternative"
In the wake of several critical flaws in Internet Explorer that surfaced in July (and that were subsequently patched by Microsoft), some security pros were recommending abstinence from using IE. Mozilla’s Firefox and Opera’s namesake browser were cited as alternatives. Even I heeded the advice and switched to Opera. But, in addition to some usability problems I encountered, Opera isn’t exactly turning out to be the safe haven I hoped it was. According to a recently updated security advisory from GreyMagic Software, a vulnerability in Opera has not only left Windows systems exposed, but assumed-to-be impenetrable Mac and Linux systems as well. The vulnerability exists in Opera versions up to and including version 7.53. While an update (version 7.54) is available from Opera’s Web site, the vulnerability calls into question whether Opera needs some better security talent on its development team. GreyMagic’s advisory notes that Opera overlooked the vulnerability when it addressed a previously issued advisory. This isn’t the first bad news for alternative browsers. Just last week, researchers identified a non-IE-specific buffer-overflow vulnerability in the Portable Network Graphics (PNG) image file format.…
http://blogs.zdnet.com/index.php?p=312
Windows XP Service Pack 2
"The package was released on August 6, but it will not appear immediately on www.windowsupdate.com. Turning on Automatic Updates is the best way to upgrade. Microsoft will use metered downloads to update users steadily without bogging down the entire Internet."
SP2 is dedicated to enhancing security in a variety of ways. Microsoft had originally planned for SP2 to turn on automatic updates by default to ensure that as many users as possible installed important patches. But this turned out to be illegal in some countries. Instead, users will be forced to choose "on" or "off" (see Figure 1 ) during installation (or, we assume, on first boot for machines that come with SP2 preinstalled).
Automatic updates currently install only critical patches for Windows; in SP2, they'll install both critical and security patches for Windows as well as some other Microsoft applications. If a download is interrupted, Windows Update will restart at the point where the interruption occurred. At shutdown, if updates have been downloaded but not installed, Windows will offer to install them and then shut down.…
http://www.pcmag.com/print_article/0,1761,a=132722,00.asp
Download details: Windows XP Service Pack 2 for IT Professionals and Developers
"This installation package is intended for IT professionals and developers downloading and installing on multiple computers on a network. If you're updating just one computer, please visit http://www.microsoft.com/protect."
There are a few people who will upgrade their nets one computer at a time. This post is for small nonprofits, community centers, and home networks.
http://www.microsoft.com/downloads/details.aspx?FamilyID=049c9dbe-3b8e-4f30-8245-9e368d3cdb5a&DisplayLang=en
Tuesday, August 10, 2004
AIM Security Hole Opens Users to Remote Attack
"…oversized values passed to the 'goaway' function of AIM's 'aim:' URI handler may be used to overwrite the pointer to the Structured Exception Handler, which could then be used to execute code written by the attacker."
The attack would appear as a link in the instant messaging window, and the user would have to click on the link in order to be subject to the vulnerability.
America Online Inc.'s AIM 5.5 has been tested and shown to be vulnerable, but iDEFENSE suspects that previous versions are also vulnerable. The iDEFENSE advisory says that AOL "recommends that Windows users of AIM upgrade to the latest beta version to be released on Aug. 9.
"This new version of AIM addresses the vulnerability described herein and can be obtained via the AOL Instant Messenger portal.…"
http://www.eweek.com/article2/0,1759,1633779,00.asp?kc=ewnws081004dtx1k0000599
Bagle Worm Variant Slips Through Defenses
"Another variant of the ubiquitous Bagle worm is now making its way across the Internet, flooding in-boxes with infected Zip files. The newest member of the Bagle family, named Bagle.AQ, arrives via an e-mail message with a spoofed sending address and no subject line. The only text in the message body is typically one or two words, either 'price' or 'new price.'
The name of the infected Zip file that accompanies the message is some variation on that theme as well. The files often are named Price.zip or New_price.zip, and may have a number appended to the end of the file name. "
Bagle.AQ first appeared Monday and began circulating in earnest in the early afternoon Eastern time. Some users reported getting as many as 100 infected messages in an hour. Virus researchers said they first began seeing Bagle.AQ at about 8 a.m. Monday and have been seeing thousands of copies an hour.
If a user opens the Zip file with an application such as Windows Internet Explorer that is not a standalone Zip file handler, the user will see an HTML file that contains exploit code. The file will then execute an included .exe file, which is a Trojan, according to McAfee Inc.'s analysis. The Trojan then connects to a number of remote sites to download the actual viral code.
This new variant is one of the few worms or viruses known to download its viral payload remotely after it is already resident on a PC. It is not until the code is actually pulled down by the Trojan that Bagle.AQ begins trying to replicate itself by sending out e-mails.…
http://www.eweek.com/article2/0,1759,1633740,00.asp?kc=ewnws081004dtx1k0000599
eWEEK.com's Special Report on Windows XP Evolution
"Windows XP Evolution"
Monday, August 09, 2004
Image flaw pierces PC security - News - ZDNet
"Six vulnerabilities in a common code that handles an open-source image format could allow intruders to compromise computers running Linux and may allow attacks against Windows PCs as well as Macs running OS X.
The security issues appear in a library supporting the portable network graphics (PNG) format, used widely by programs such as the Mozilla and Opera browsers and various e-mail clients. The most critical issue, a memory problem known as a buffer overflow, could allow specially created PNG graphics to execute a malicious program when the application loads the image.
Among the programs that use libPNG and are likely to be affected by the flaws are the Mail application on Apple Computer's Mac OS X, the Opera and Internet Explorer browsers on Windows, and the Mozilla and Netscape browsers on Solaris, according to independent security researcher Chris Evans, who discovered the issues. Apple and Microsoft could not immediately be reached for comment. Evans did not test every platform to check which vulnerabilities work, he said.…"
http://zdnet.com.com/2100-1105_2-5298999.html?tag=adnews
Friday, August 06, 2004
Malicious program aims for Pocket PCs - News - ZDNet
"A malicious Trojan horse program has emerged for Pocket PCs, antivirus companies said Thursday, but they characterized the threat as relatively low.
The program, known alternately as Backdoor.Bardor.A and WinCE.Brador.a, lets an attacker gain full control of the handheld and is the first such 'backdoor Trojan' program to emerge for Pocket PCs. However, such backdoor programs are not capable of propagating on their own and instead must be sent as e-mail attachments or through similar means, making them less dangerous.
Symantec rated the bug a '1,' the lowest on its five-point scale. In a statement, the company offered the standard warning not to open or execute files from unknown sources.… "
Last month, researchers identified the first Windows CE virus, which researchers said was mostly a "proof-of-concept" bug, or one designed to demonstrate its own feasibility.
"We were certain that a viable malicious program for PDAs would appear soon after the first proof-of-concept viruses emerged for mobile phones and Windows Mobile," Eugene Kaspersky, head of Anti-Virus Research at Kaspersky Labs, said in a statement. "WinCE.Brador.a is a full-scale malicious program ready to go: unlike proof-of-concept malware (malicious software), Brador has a complete set of destructive functions typical for back doors.…"
http://zdnet.com.com/2100-1105_2-5298781.html?tag=adnews
Flaws in Graphics Library Could Bring Attacks
"A researcher performing a source-code audit on a popular graphics library has found multiple security vulnerabilities in it that could be used to crash programs or execute attack code.
The PNG library (libpng) is a collection of graphics routines to manipulate PNG (portable network graphics) files. PNG (Portable Networks Graphic) is a graphics format that was designed many years ago as an alternative to the still more popular GIF format. "
…full story
http://www.extremetech.com/article2/0,1558,1632761,00.asp
Mozilla, Opera Plug Security Holes
"The Mozilla Foundation and Opera Software ASA have released updates to their Web browsers to fix a series of security vulnerabilities.
Mozilla on Wednesday posted new versions of its Firefox browser, Thunderbird e-mail client and Mozilla suite that provide fixes to three issues. They include a newly reported critical vulnerability affecting multiple vendors' software that uses the library for the Portable Networks Graphic (PNG) image format. "
The other two issues, as previously reported, were related to the handling of security certificates in the Mozilla browsers that, among other things, could allow an attacker to lull users into a false sense of security on a site. …full story
http://www.extremetech.com/article2/0,1558,1632752,00.asp
Wednesday, August 04, 2004
New MyDoom Variant Uses Yahoo People Search
Another new version of MyDoom is worming its way through the Internet, and this variant—like the last one—uses Yahoo as part of its infection routine.
MyDoom.P is similar to most of the other MyDoom variants in that it arrives via e-mail, with a spoofed sending address and a subject line designed to make it look like the message is related to one that the recipient sent. Among the subject lines in the e-mails are "SN: New secure mail," "Secure delivery," "Re: Extended mail," "Delivery Status (Secure)," "Re: Server Reply" and "SN: Server Status."
The body of the e-mail contains any of a number of sentences, some of which refer to the included Zip file. Many of the messages reference security or refer to the attached file as a "secure Zip file."
Once opened, the executable file copies itself to the Windows system directory as "winlibs.exe." The executable contains a list of dozens of common first and surnames that it puts through Yahoo's People Search in an attempt to find more e-mail addresses to mail itself to, according to a preliminary analysis of the worm done by the staff of the Internet Storm Center at The SANS Institute in Bethesda, Md.…
http://www.eweek.com/article2/0,1759,1630965,00.asp?kc=ewnws080404dtx1k0000599
Free .NET and Native Windows Dev Tools
"Everyone likes having something for free, and Microsoft has some software development tools that you can have for nothing more than the cost of the download."
VC++ Toolkit
http://www.microsoft.com/downloads/details.aspx?FamilyID=272be09d-40bb-49fd-9cb0-4bfa122fa91b&displaylang=en
.NET SDK
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B3A2CA6-3647-4070-9F41-A333C6B9181D&displaylang=en
Platform SDK
http://www.microsoft.com/msdownload/platformsdk/sdkupdate/
May Community edition of Visual Studio .NET 2005
http://lab.msdn.microsoft.com/vs2005/get/default.aspx
Express version of Visual C++
http://lab.msdn.microsoft.com/express/visualc/default.aspx
http://www.ddj.com/documents/s=9204/ddj040801dnn/
Tuesday, August 03, 2004
Build Your Own ASP.NET Website Using C# and VB.NET. Pt. 4. - WebReference.com-
"Web Forms and Web Controls"
At the heart of ASP.NET is its ability to create dynamic form content. Whether you’re creating a complex shopping cart application, or a simple page to collect user information and send the results out via email, Web Forms have a solution. They allow you to use HTML controls and Web controls to create dynamic pages with which users can interact. In this chapter, you will learn how Web Forms, HTML controls, and Web controls, in conjunction with VB.NET and C# code, should change the way you look at, and develop for, the Web.
http://www.webreference.com/programming/asp_net4/
Sasser (A-F) Worm Removal Tool (KB841720)
"This tool will help to remove the Sasser (A-F) worm from infected systems.… it automatically checks for infection and removes any of the targeted worms that are found."
After running, the tool displays a message describing the outcome of the detection and removal process. The tool can be safely deleted after it has run. Also, the tool creates a log file named sasscln.log in the %WINDIR%\debug folder.…
http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en
What You Should Know About the Mydoom and Doomjuice Worms
"The Mydoom worm leaves a program, known as a back door, that could potentially allow an attacker to gain access to infected computers. Several variants of the worm are currently circulating, and malicious programs related to Mydoom have been released under the names Doomjuice and Zindos. Microsoft urges you to take action to remove these worms and help keep your computer safe from malicious intrusions."
Download and install the tool from the Download Center.
http://www.microsoft.com/downloads/details.aspx?familyid=c14bfbe4-3d50-464d-a26c-9c287f8a08c5&displaylang
http://www.microsoft.com/security/incident/mydoom.mspx
Monday, August 02, 2004
The Search Engine Report - Number 93
Threats to Windows, IIS, and Outlook Express
"Get the details on Microsoft Security Bulletins MS04-018, MS04-019, MS04-020, MS04-021, MS04-024. "
MS04-018, “Cumulative Security Update for Outlook Express,” is caused by a failure of Outlook express to properly handle some specifically malformed e-mail headers. This is a DoS threat and Microsoft reports having seen published exploits but hasn't received any reports from customers that have been compromised by the exploit. This threat is covered by CAN-2004-0215
MS04-019, “Vulnerability in Utility Manager Could Allow Code Execution,” is a local elevation of privilege threat that can’t be exploited remotely. MSBA will report if your system needs this update and Systems Management Server (SMS) can help deploy it.
MS04-020, “Vulnerability in POSIX Could Allow Code Execution,” is an unchecked buffer vulnerability in the Portable Operating System Interface for UNIX. MSBA will report if your system needs this update and SMS can help deploy it. This threat is covered by CAN-2004-0210.
MS04-021, “Security Update for IIS 4.0,” is a buffer overrun vulnerability in the redirect function that can allow remote execution. MSBA will report if your system needs this update and SMS can help deploy it. This threat is covered by CAN-2004-0205.
MS04-024, “Vulnerability in Windows Shell Could Allow Remote Code Execution,” replaces MS03-027 for Windows XP (but not for the other affected operating systems). This threat is covered by CAN-2004-0420.
…
http://www.microsoft.com/technet/security/bulletin/ms04-018.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-019.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-020.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-024.mspx
http://www.microsoft.com/technet/security/bulletin/ms04-027.mspx
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0215
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0210
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0205
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0420
http://techrepublic.com.com/5102-6264-5284223.html
Saturday, July 31, 2004
MyDoom Attacks Microsoft.com Through Back Door
"As many security researchers feared after analyzing the code for MyDoom.O, a second, related attack began in earnest Tuesday with a new piece of code using the back door installed by MyDoom.O to spread itself and launch a DDoS (distributed denial of service) attack against Microsoft.com.
MyDoom.O, also known as MyDoom.M or MyDoom.M@mm, installs a Trojan known as Zincite.A on every PC that it infects. The Trojan opens TCP port 1034 and listens for further commands. Zindos spreads itself by scanning for machines listening on port 1034. When it finds one, Zindos copies itself to the infected PC and then Zincite executes the copy. "
Analysts at Symantec Corp., based in Cupertino, Calif., said Tuesday that they had discovered a previously unknown function in MyDoom.O that keeps track of every system the worm infects.
After finding this, the analysts went back over the code from MyDoom.L and found that that variant contains the same feature. This led the team to conclude that the worms' author may have used the machines infected by the L variant as a seeding ground for the latest version.…
http://www.eweek.com/article2/0,1759,1628180,00.asp
Unscheduled Security Update Fixes Critical IE Flaws
"The security bulletin accompanying the updates, numbered MS04-025, addresses three vulnerabilities rated 'critical' that could result in an attacker executing code in the context of a logged-on user. If the user is logged on as Administrator, the attack would have free reign over the system."
The first vulnerability, titled "Navigation Method Cross-Domain Vulnerability," could allow an attacker to execute arbitrary code in the Local Machine security zone. Microsoft reports that many factors can make this vulnerability more difficult to execute, including installing certain previous updates. Nevertheless, Symantec reports this as the most critical of the three vulnerabilities and that they have already seen exploits of it in the wild.
The other two vulnerabilities are related to the browser's handling of image files. Both are buffer overflows in Internet Explorer's handling of these files, one for BMP files and one for GIF files. Internet Explorer 6 Service Pack 1 and Windows Server 2003, both 32-bit and 64-bit editions, are not affected by the BMP file vulnerability.
The GIF buffer overrun affects all versions of Windows and Internet Explorer and results when the attacker attempts to free memory that has already been freed. The bulletin indicates that this is most likely a denial-of-service attack, but the potential exists for it to be used to execute arbitrary code.
The update replaces a previous update, MS04-004. If users have applied that patch and subsequently applied non-public hotfixes they may have to reapply them after applying the new cumulative update. Users should consult the bulletin and Microsoft support.
http://www.microsoft.com/technet/security/bulletin/MS04-025.mspx
http://www.eweek.com/article2/0,1759,1629584,00.asp
Friday, July 30, 2004
Open-Source Exploit Tool: 'Point, Click, Root'
"It's as easy as 'point, click, root.'
At a heavily attended panel Wednesday at the Black Hat security conference here, HD Moore and 'spoonm' unveiled the latest release of the Metasploit Framework, an exploit tool designed to quickly take over a variety of target platforms."
Although the framework was developed several months ago, the "preview release" of Version 2.2 offers users the opportunity to develop their own custom modules. The tool, written in Perl for Unix environments, also includes a Cygwin shell to enable it to run under Windows. The official Version 2.2 will be available in a week or so.
Both researchers demonstrated the tool "owning," or taking over, Mac OS X, Windows 2000 Server and Windows XP systems, although the duo used a VMWare virtual machine to speed the process. Metasploit even runs on a Sharp Zaurus PDA, which when equipped with a Wi-Fi card can be used to attack while mobile.
The authors described the tool as the open-source, cheap alternative to Immunity's Canvas and Core Security Technology's Impact tools, designed for commercial applications and requiring the latest exploits almost as quickly as possible. Metasploit currently contains 35 exploits and 40 payloads; the tool was designed to point the user to the exploit appropriate for the operating system.
Although available for several months, the tool is apparently still relatively unknown even in security circles, judging from the reaction of attendees. Patrick Chambet, a senior consultant at French IT security firm Edelweb SA, said he found the presentation the most interesting of the day. Another researcher said he worried that Metasploit would be used by "script kiddies" as a means to quickly own other boxes.…
http://www.eweek.com/article2/0,1759,1628707,00.asp?kc=ewnws072904dtx1k0000599
Monday, July 26, 2004
Researchers Wonder Why Bagle Virus is a Success
"Several new variants of the venerable Bagle virus visited themselves upon corporate networks last week, frustrating administrators and virus researchers who continue to wonder why these worms can still infect thousands of machines after months of warnings.
None of the most recent variants is particularly innovative or clever in its social engineering efforts or infection methods. Many versions of the Bagle virus actually make it difficult for users to infect machines by requiring them not only to open an attachment but also to enter a password to launch the malware. "
http://www.eweek.com/article2/0,1759,1626686,00.asp?kc=ewnws072604dtx1k0000599
VeriSign: Be Wary Online. Be Very Wary.
"Internet commerce grew 13.2 percent in the past 12 months, according to a new report. Not bad.
But fraud grew faster.
The report, to be released Monday, said phishing attacks, in which fraudsters lure people to sites that mimic those of top retailers in order to steal personal information, have become more acute and global in nature. "
http://www.internetnews.com/ec-news/article.php/3385681
iPaq handheld can easily switch between cellular and Wi-Fi
"Hewlett-Packard is introducing its first iPaq handheld that can easily switch between traditional cellular and Wi-Fi networks.
The h6315, which was co-developed with T-Mobile, operates on a traditional cellular network but can automatically hop over onto a faster Wi-Fi connection when one is available. The device also has a built-in camera and a detachable keyboard and can also act as a cell phone using the GSM cellular network. "
http://zdnet.com.com/2100-1103_2-5282083.html
Windows Security Updates for July 2004
"The Microsoft Windows security updates for July 2004 address newly discovered issues in Windows, including Microsoft Internet Explorer and Microsoft Outlook Express, both components of Windows. If you have any of the software listed on this page installed on your computer, you should visit the Windows Update Web site to install related updates."
http://www.microsoft.com/security/bulletins/200407_windows.mspx
Windows XP Home and Professional Service Configurations by Black Viper
"This section on Windows XP Service Configurations has complete explanations of each service and advice and which ones you can safely disable."
http://www.blackviper.com/WinXP/servicecfg.htm