* Patches from Debian, Mandriva, Gentoo, others * Attack code released for new DNS attack * Open source software a security risk, and other interesting reading
endif; ?>Last month’s iPhone 2.0 software upgrade, in addition to adding new features, fixed a number of security problems in previous generations of the sofware. Looks like it didn’t fix enough. Security researcher Aviv Raff is reporting flaws in the iPhone’s e-mail and Safari browser applications that could be exploited to spam the affected device. No one wants spam on their iPhone. Also today, there are two new patches available for Asterisk IP PBX system.
Researcher warns of unpatched iPhone bugs
Security vulnerabilities in the iPhone’s e-mail application and Safari Web browser can be used by phishers to dupe users into visiting malicious sites or by spammers to flood the phone’s in-box with junk mail, a researcher warned today. Computerworld, 07/23/2008.
Aviv Raff: iPhone is Phishable and SPAMable
**********
Asterisks patches DoS vulnerability
A description of the flaw from Asterisk: “By flooding an Asterisk server with IAX2 ‘POKE’ requests, an attacker may eat up all call numbers associated with the IAX2 protocol on an Asterisk server and prevent other IAX2 calls from getting through.” A fix is available.
Patch for Asterisk’s traffic provisioning system
A flaw in a Asterisk’s traffic provisioning system could be exploited to flood a server with data, resulting in a denial of service. A fix is available.
**********
Four new patches from Debian:
**********
Five new updates from Mandriva:
libxslt (buffer overflow, code execution)
**********
Three new fixes from Gentoo:
PeerCast (buffer overflow, code execution)
Bacula (information disclosure)
**********
Two new patches from Ubuntu:
**********
Today’s malware news:
Attack code released for new DNS attack
Hackers have released software that exploits a recently disclosed flaw in the Domain Name System (DNS) software used to route messages between computers on the Internet. The attack code was released Wednesday by developers of the Metasploit hacking toolkit. IDG News Service, 07/24/2008.
Also: Details of major Internet flaw posted by accident
**********
From the interesting reading department:
Podcast: Open source tools help secure city network
How does a fiscally constrained city department help get its network into compliance with PCI? Best of breed open source tools are a big help, explains Alan Boulanger, former director of Information Security for the City of Springfield, Mass. (7:52)
Open source software a security risk, study claims
Open source software is a significant security risk for corporations that use it because in many cases, the open source community fails to adhere to minimal security best practices, according a study released Monday. Network World, 07/21/2008.
Design flaws, besides vulnerabilities, hurt banking sites
Banking Web sites suffer from design flaws that undermine their security, exclusive of software vulnerabilities, according to a University of Michigan study to be released Friday. IDG News Service, 07/23/2008.
Stolen tape puts Bristol-Myers employee data at risk
Bristol-Myers Squibb Co. officials last week confirmed that a non-encrypted backup tape containing the personal data of current and former-employees and their dependents was stolen June 4 from a delivery truck carrying the device. Computerworld, 07/22/2008.
Questions abound as San Francisco tries to repair network
IT managers and analysts are expressing surprise at the amount of time it appears to be taking officials at the City of San Francisco to regain full control of the city’s FiberWAN network after a disgruntled network administrator allegedly locked access to it by resetting administrative passwords to its switches and routers. Computerworld, 07/22/2008.
Also: Why San Francisco’s network admin went rogue
Kaspersky Lab’s Malaysian Web site hacked
Russian security company Kaspersky Lab’s Web site for Malaysia was defaced on Saturday along with one of its online shopping sites, according to Zone-H, an organization that documents such attacks. IDG News Service, 07/21/2008.
Tell me if this sounds like a familiar scenario. You’ve come up with a brilliant password – it’s strong, easy to remember, and you’ve finally mastered the finger gymnastics required to type it in quickly – only to find that the usage window, mandated by IT password policy, is up. Symanted Security Response blog, 07/18.2008.




