* Patches from Sun, VMware, Gentoo, others * Intego finds new variant of RSPlug Trojan Horse * Apple removes antivirus support page, and other interesting reading
endif; ?>While Sun and VMWare top our list of patches this week, it’s Apple that seems to be making the most news. Reports earlier in the week said that Apple was urging users to add an antivirus application to their Mac OS X systems. But, later in the week, Apple took down the warning page saying it was outdated. So, do Macs need antivirus? They are less of a target than Windows obviously, but still a target. Does it hurt to run antivirus and add that extra layer of security?
Sun patches at least 14 bugs in Java
Sun patched at least 14 vulnerabilities in Java Tuesday as it updated the popular software to version 6.0, build 11. The release notes for Java 1.6.0_11 , as Sun dubbed the update, skimped on details about the security flaws that were patched, but listed a total of 14 alerts, each of which will presumably provide information about at least one vulnerability.
Sun’s Release Notes on the new update
**********
VMWare patches Hosted Products
According to the VMWare advisory, “Updated VMware Hosted products and patches for ESX and ESXi resolve two security issues. The first is a critical memory corruption vulnerability in virtual device hardware. The second is an updated bzip2 package for the Service Console.’
**********
Eight new patches from Gentoo:
libsamplerate (buffer overflow, code execution)
IPsec-Tools (denial of service)
enscript (buffer overflows, code execution)
OptiPNG (buffer overflow, code execution)
**********
Seven new updates from Debian:
awstats (cross scripting flaw)
perl (arbitrary file deletion)
cupsys (integer overflow, code execution)
flamethrower (symlink, denial of service)
phpmyadmin (input santization)
jailer (symlink attack, denial of service)
**********
Five new fixes from Ubuntu:
Imlib2 (denial of service, code execution)
libvorbis (denial of service, code execution)
ImageMagick (denial of service, code execution)
**********
Today’s malware news:
Intego finds new variant of RSPlug Trojan Horse
Mac security company, Intego, warned on Wednesday of a new variant of the RSPlug Trojan Horse. The original RSPlug trojan was found last October. The new variant has been found on pornographic Web sites and presents itself when a users tries to view a video. When attempting to view the video an error message comes up saying “Video ActiveX Object Error,” and then gives a link for a download. Macworld, 12/03/2008.
As the use of removable drives has increased, they have become a successful vehicle to enter a network and compromise computers. The ease of infection is facilitated by a feature within Windows called AutoPlay. Meant as a feature of convenience, AutoPlay allows programs to automatically launch when CDs, DVDs, removable drives, or any other form of storage is inserted into a computer. Symantec Security Response, 12/03/2008.
Experts douse Sinowal Trojan hype
Security experts have poured cold water on media reports that claim some 20,000 Australian bank accounts have been compromised by the Sinowal Trojan. Computerworld, 12/01/2008.
This is a particular favourite of Phishers – a page claiming to give you free Microsoft Points for XBox Live, only to take your login and do what they want with it (which could range from using the credit card stored against your account to buy lots of games you don’t actually want to just trashing your gamer profile). The SpywareGuide Greynets Blog, 12/02/2008.
**********
From the interesting reading department:
Apple removes antivirus support page
A support page on Apple’s Web site recommending users purchase antivirus software for their Macs received a lot of attention over the past couple of days, but on Tuesday Apple removed the page from its Web site. Macworld, 12/03/2008.
Previously: Apple says users should install antivirus software
Virtually every Windows PC at risk, says Secunia
More than 98% of Windows computers harbor at least one unpatched application, and nearly half contain 11 or more programs at risk from attack, a Danish security company said Wednesday. Computerworld, 12/03/2008.
License server glitch exposes SonicWall users to threats
A technical problem in a license management server at SonicWall created havoc Tuesday for users of the company’s e-mail security products, leaving many customers temporarily unprotected against spam, phishing and malware threats while others were unable to log into their own systems. Computerworld, 12/03/2008.
Criminals take control of CheckFree Web site
Online criminals took control of the Domain Name System (DNS) record for payment processor CheckFree and briefly redirected the site’s visitors to a their own server. The site was redirected at around 12:30 a.m. Eastern Time on Tuesday after someone logged into CheckFree’s Network Solutions account and changed the domain’s DNS settings, said Susan Wade, a Network Solutions spokeswoman. “Somebody got hold of the customer’s login information,” she said. “I don’t know how they got access.” {Sounds a lot like the Kaminski Hack to me.}
Botnet master sees himself as next Bill GatesOwen Walker’s future seems brighter today than it did a year ago when New Zealand police came knocking on his door to arrest him on computer hacking charges. IDG News Service, 12/02/2008.Exercise Caution When Using Public ComputersOver Thanksgiving I was reminded how scary public computers are and why you should avoid them. Publicly available computers are popping everywhere and increasingly ubiquitous with our daily lives. A few of the computers I ran into this weekend include: while waiting for an oil change at Mobile 1, a café for breakfast and the hotel I stayed at. CA Security Advisor Research Blog, 12/02/2008.‘Tis the Season to be Extra Aware of MalwareUsing the happy subject line “You have recieved [sic] A Hallmark E-Card”, Win32/Mytob variants attached to spam emails have been getting around lately. The team at CA ISBU labs has monitored Mytob’s increased activity especially towards the end of Q3 2008, and you can read more by visiting the Win32/Mytob.OM and Win32/Mytob.ON malware analyses in our encyclopedia. CA Security Advisor Research Blog, 12/02/2008.Hackers’ posting forces Tweeter to shut down Web site“Hackers apparently broke into Tweeter’s website yesterday morning and posted a picture of President Bush on the home page with a message about the bankrupt chain’s owner and chief restructuring officer. “Don’t trust either of them!!!”” Boston.com, 12/04/2008.




