Microsoft better-late-than-never with 7-year-old patch

Opinion
Nov 13, 20085 mins

* Patches from Microsoft, Gentoo, rPath, others * Facebook hit by Nigerian 419 scam * One in four DNS servers still vulnerable to Kaminsky flaw, survey says, and other interesting reading

From the better-late-than-never department: One of the two patches Microsoft released this week is for a 7-year-old bug in Windows, one that a founding member of the Trustworthy Computing team had warned about from the beginning. You might think there wasn’t an exploit until now, so no need to patch. But, Cult of the Dead Cow (what a great name) released an exploit back in March Of 2001. Not sure what took so long for Microsoft to catch up, but they finally have. Also today, we’ve got some karping going on between rivals IBM and TrendMicro over flaws in the latters’ products. Always good fodder when security companies snipe at each other.

Microsoft fixes critical Web bugs with security updates

Microsoft released two security updates for its Windows operating system Tuesday to patch flaws that could give attackers new ways to install malicious software on a victim’s computer. IDG News Service , 11/11/2008.

Microsoft advisory

Also:

Microsoft patch closes 7-year-old OS hole, expert saysA former Microsoft employee who’s now CTO for a patch management firm says an update issued by Microsoft on Tuesday closes a vulnerability that has been exploited for almost seven years and that he first identified while working for the company. Network World, 11/12/2008.

**********

Flawed AVG antivirus update cripples Windows XP PCsA flawed signature update to AVG Technologies’ antivirus software over the weekend crippled some Windows XP PCs by mistakenly deleting a critical system file, the company has confirmed. Computerworld, 11/11/2008.AVG’s FAQ on how to fix the issue**********IBM’s ISS blasts security rival Trend Micro over bugsIn an unusual move, a security company owned by IBM has publicly blasted a rival for not patching reported bugs in its enterprise-grade, server-side antivirus software. On Monday, David Dewey, a researcher with IBM’s Internet Security Systems, explained why his company had released several advisories that covered multiple vulnerabilities in Trend Micro’s ServerProtect software, even though according to IBM, Trend has not fixed the flaws. Computerworld, 11/12/2008.IBM Frequency X blog: The Scoop on the X-Force TrendMicro Advisories**********Apple releases iLife Support 8.3.1 to fix flawsAn image handling flaw in Apple’s iLife Support module, which is used by Aperture and other imaging applications, could be exploited to run malicious code on an unpatched machine. The new update repairs the bug.

**********

Four new updates for rPath:

initscripts (denial of service)

kernel (multiple flaws)

net-snmp (denial of service)

postfix (denial of service)**********

Three new patches from Gentoo:

Graphviz (buffer overflow, code execution)

FAAD2 (buffer overflow, code execution)

Gallery (multiple flaws)**********

Two new fixes from Debian:

libcdaudio (heap overflow, code execution)

ekg (denial of service)**********

Today’s malware news:

Facebook hit by Nigerian 419 scamScammers are trawling Facebook for victims using a convincing twist on the notorious ‘Nigerian 419’ scam. TechWorld, 11/10/2008Mobile Malware: What Happens Next?

Four years ago, F-Secure Chief Research Officer Mikko Hypponen was talking about malware infections on mobile phones while few others were paying attention. With the growing use of Internet-enabled phones, particularly Apple’s iPhone and RIM’s Blackberry, he sees more opportunities than ever for malicious activity. But, surprisingly, he sees a quiet mobile malware landscape at the moment. CSO, 11/12/2008.

**********

From the interesting reading department:

One in four DNS servers still vulnerable to Kaminsky flaw, survey saysDespite industry efforts to lock down DNS servers, one in four remain vulnerable to cache poisoning due to the well-documented Kaminsky flaw identified earlier this year and another 40% could be considered a danger to themselves and others, recent research shows. Network World, 11/10/2008.Most data security risks internal, Cisco study findsMost enterprise IT officials believe their company’s employees pose a greater threat to data security than any outside source. Network World, 11/12/2008.Whit Diffie on Encryption and PKIIn the 1970s, Whitfield Diffie co-wrote the recipe for one of today’s most widely used security algorithms in a paper called “New Directions in Cryptography.” The paper was a blueprint of what came to be known the Diffie-Hellman key exchange, a seismic advancement in Public Key Infrastructure (PKI) technology that makes secure online transactions possible. It’s part of such popular protocols as the Secure Sockets Layer (SSL) and Secure Shell (SSH). But much has happened in the world of security since then, which begs the question: Does the old recipe hold up in today’s environment? CSO, 11/10/2008.2008 Worldwide Infrastructure Security ReportGrowing financial pressures, unforeseen threats, and a volatile and rapidly changing business landscape — apt descriptions for both the world economy and this years Worldwide Infrastructure Security Survey. Arbor’s Security to the Core blog, 11/11/08.Former inmate arrested for breaking into prison’s IT systemsIt isn’t uncommon for people to go to prison for breaking into corporate computers and stealing data. It’s rare, though, for someone to be sent back to jail for breaking into a prison computer system while already serving time for another crime. Computerworld, 11/11/2008.Spam plummets after hosting service shutteredSpam volumes plunged by more than 40% after a major bot hosting network was shut down, researchers at IronPort Systems Inc. said Wednesday. Computerworld, 11/12/2008.Express Scripts offers $1 million award to nab extortionist in data breach caseExpress Scripts, the pharmacy benefits management company which recently disclosed an extortionist is demanding money by threatening to expose millions of patient records the company holds, Wednesday said it has decided to offer $1 million to nab the perpetrator. Network World, 11/12/2008.How IT Helped Catch the Jewelry Thief

It used to be that after a robbery, the police would review a surveillance tape for clues into who broke in, at what time and what the bad guys looked like. Since the thieves would be long gone by the time the tape was reviewed, there would often be little the authorities could do about it. CSO, 11/12/2008.