Security requires a little common sense

Opinion
Oct 23, 20085 mins

* Patches from Microsoft, Cisco, Google, others * Web Attacks Using Microsoft Help and Support Center Viewer * Dentist loses patient records out the back of garbage truck, and other interesting reading

Sometimes its the simple things that can lead to a data leak. Like not shredding paper data. A dentist’s office near my house is in hot water for letting paperwork containing sixty patients infomation to get loose. The Aspen Dental office in Nashua, NH says it didn’t have to shred the data before throwing it away and that its the garbage contractor’s fault for losing it. Haven’t they heard of dumpster diving? All the network security in the world wouldn’t have prevented this leak, but a little common sense would have.

Microsoft to rush out emergency Windows patch

The company offered few details on why it was releasing the software update, which is rated critical for users of Windows 2000, Windows XP, and Windows Server 2003. A critical flaw is worrisome, however, because it can be exploited by online attackers to seize control of the PC. The update will be released at 10:00 am, Pacific time, said Microsoft spokesman Christopher Budd in a blog posting published late Wednesday.

Microsoft advisory**********Cisco warns of ASA, PIX vulnerabilities; acknowledges DoS vulnerablities in TCP

Cisco is warning of multiple security holes in its ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. It also issued a security response that acknowledges multiple vulnerabilities involving the manipulation of TCP state table information. Cisco Subnet, 10/22/2008.

Cisco advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA

**********

Google patches Chrome ‘carpet bomb’ bugGoogle has patched its Chrome browser to block a months-old bug that can be used to trick people into downloading and launching malicious code. Computerworld, 10/21/2008.Google Chrom release highlights**********

Four new patches from Debian:

dbus (denial of service)

qemu (symlink attack, denial of service)

cupsys (multiple flaws)

linux-2.6.24 (multiple flaws)**********

Two new updates from Mandriva:

mon (denial of service, file overwrite)

pam_mount (restrictions bypass)**********

Today’s malware news:

Web Attacks Using Microsoft Help and Support Center ViewerThe Symantec DeepSight Threat Analysis team recently observed an interesting attack development related to a known vulnerability type. This seemingly new technique allows attackers to execute a malicious payload immediately on a victim’s system, where in the past they weren’t able to achieve instant code execution by exploiting such vulnerabilities. Symantec Security Response, 10/22/2008.Virus.VBS.ConfiOne of our Web Security Analysts, Chu Kian, came across a relatively old threat this week. It was during his day-to-day work that he encountered a VBS malware, Virus.VBS.Confi. It’s not something new, detection was added in 2005, but it still works and it can still infect some unpatched systems if they browse websites with the malware code present. F-Secure, 10/22/2008.Hackers renew airline-ticket scam spamIn a reprise of a summer tactic, hackers are trying to trick people into infecting their PCs with malware by sending them e-mail that poses as bogus airline-ticket invoices and boarding passes, a security company said today. Computerworld, 10/20/2008.

**********

From the interesting reading department:

Dentist loses patient records out the back of garbage truckWhoops, a dentist office down the street from my house seems to have lost the personal data of 60 or so patients. Faulty data security? Open wireless access point exploited? Nope, something a little more simple: A failure to shred paper records. SecurityBlog.Voices from IT Roadmap podcast: Security compliance about protecting your own dataAt MultiCare Health System in Washington, the key to getting into compliance with HIPPA and other regulations is to think about how you want to protect your data in general then align those steps with the individual regulations impacting you, says Paul VanAmerongen, Manager, Information Security Services. Network World.SanDisk puts antivirus on flash driveSanDisk has stepped up its efforts to convince corporates that USB sticks are a secure medium, adding built-in antivirus capability to its latest Cruzer drive. TechWorld, 10/22/2008.A Guide for Beating Phishing AttacksPhishing is a way for individuals who are known as “phishers” to obtain your private information such as bank account details and passwords. Phishing messages come in the form of an email message that is directed to you and appears to be from a reputable company or business-often one that you have an association with and trust. But, it is not. Symantec Security Response, 10/21/2008.Reshipping scam: a new cyber-criminal trend?“Are you looking for a new job? What about getting $2000 monthly working at home? You just only need to follow some of our directions and a good compensation is waiting for you…” Attractive job? Yes probably, but what is behind it? It seems cyber-criminals use modern technology to resurrect traditional fraudulent schemes. CA Security Advisor Research Blog, 10/22/2008.French President Sarkozy’s bank account hacked

Cyberthieves have stolen money from the personal bank account of France’s president, Nicolas Sarkozy. The criminals reportedly managed to obtain Sarkozy’s online username and password, and removed several small sums of money from the account. Computerworld UK, 10/21/2008.

Big changes ahead for the Internet, says Vint CerfThe Internet will get support for IPv6, a more secure domain name system and international characters, during the next couple of years, according to Vint Cerf, vice president and chief Internet evangelist at Google. IDG News Service, 10/21/2008.Security breaches: 3 tools for preventing data lossWhen it comes to protecting data, there isn’t one end-all, be-all solution. That’s more true now than ever, when your most likely threat is your own employees. As more workers blur the line that surrounds the workday and bring their laptops, smartphones and other devices home, they are potentially putting their companies’ data at risk. CIO, 10/21/2008.Breach cripples Ohio Secretary of State’s siteThe Web site of Ohio’s secretary of state was shut down after it was hacked Monday, according to the site and local media reports. The site was later restored, but with only limited functionality. Computerworld, 10/21/2008.