* Patches from Debian, Mandriva, Gentoo, others * Hunt for the elusive rootkit 'Rustock.C' revealed * Insider threat looms large as San Francisco's network crisis plays out , and other interesting reading
It’s an IT shops worst nightmare: All your systems are patched, intrusions are monitored and quarantined, virus-ladden e-mails are turned away before they hit the mail server, but an insider wreaks havoc on your systems. The City of San Francisco is living that nightmare as a system admin changed all the passwords to key systems and refused to divulge the key. See all the dirty details in our related links area.
FreeBSD catches up with BIND update
After last week’s disclosure of a major DNS vulnerability, many vendors began rolling out patches for their various implementations. FreeBSD has finally loosed a patch for its version of BIND, which closes up the hole that would allow an attacker to poison a DNS cache.
**********
Four new patches from Debian:
gaim (integer overflow, code execution)
mysql-dfsg-5.0 (authorization bypass)
**********
Three new updates from Mandriva:
pcre (buffer overflow, code execution)
bluez (input validation, denial of service)
**********
Two new fixes from Gentoo:
Mercurial (directory traversal)
OpenOffice.org (integer overflow, code execution)
**********
Two new patches from rPath:
**********
Today’s malware news:
Hunt for the elusive rootkit ‘Rustock.C’ revealed
Rootkits are software code designed to hide from detection. So Kaspersky Lab’s hunt for the elusive Rustock.C rootkit, rumored to exist for almost two years, reads like a detective plot. Network World, 07/15/2008.
Symantec: Microsoft Access ActiveX attacks will intensify
An easy-to-use toolkit used to hack computers has now been updated to take advantage of an unpatched security vulnerability in Microsoft’s software, which could mean attacks will intensify, according to vendor Symantec. IDG News Service, 07/14/2008.
**********
From the interesting reading department:Insider threat looms large as San Francisco’s network crisis plays outReport: IT admin locks up San Francisco’s network
The unfolding cliffhanger in San Francisco this week — in which a city network administrator has been arrested for allegedly holding the network hostage — represents an extreme example of the insider threat that IT security vendors and others have been sounding the alarm about for years. Network World, 07/16/2008.
Also:
Data can leak from partially encrypted disks
If you’re using encryption software to keep part of your computer’s hard drive private, you may have a problem, according to researchers at the University of Washington and British Telecommunications. They’ve discovered that popular programs like Word and Google Desktop store data on unencrypted sections of a computer’s hard drive — even when the programs are working with encrypted files. IDG News Service, 07/16/2008.
The what, who, when, where, why and how of XSS
In 2005, a MySpace user named Samy discovered a unique way to expand his buddy list. Within 24 hours, the number of friends on his page grew from 73 to more than 1 million. He achieved this instant popularity by creating the first self-propagating cross-site scripting (XSS) worm and by exploiting the lax security in many Web browsers. Network World, 07/16/2008.
How CAPTCHA got trashed
CAPTCHA used to be an easy and useful way for Web administrators to authenticate users. Now it’s an easy and useful way for malware authors and spammers to do their dirty work. Computerworld, 07/16/2008.
Unpatched Windows PCs fall to hackers in under 5 minutes
It takes less than five minutes for hackers to find and compromise an unpatched Windows PC after it’s connected to the Internet, a security researcher said today. Computerworld, 07/16/2008.
Woman fired over death threat sent from work e-mail
An employee of 1-800-Flowers.com has been fired after an e-mailed death threat was linked to her account. The crudely worded e-mail was sent Sunday to Paul “PZ” Myers, an associate professor of biology at the University of Minnesota Morris, who is known for his criticism of religion and creationism. IDG News Service, 07/16/2008.
One in four businesses block access to Facebook, social networking sites
Nearly one in four businesses block employee access to social networking Web sites such as Facebook and MySpace,according to a survey of about 200 human resources professionals. Network World, 07/15/2008.
Researchers trace structure of cybercrime gangs
The chain of command of a cybercrime gang is not unlike the Mafia, an evolution that shows how online crime is becoming a broad, well-organized endeavor. IDG News Service, 07/15/2008.
Facebook bug leaks members’ birthday data
A glitch in a test version of Facebook’s Web site inadvertently exposed the birthdays of Facebook’s 80 million members this week. IDG News Service , 07/16/2008.
Researcher set to demo attack on Intel chips
The author of several security books is slated to demonstrate how he could take advantage of flaws in Intel Corp.’s chips to launch a remote attack against a computer — regardless of what software platform it’s running. Computerworld, 07/14/2008.




