Not all perfect with iPhone 2.0

Opinion
Jul 24, 20084 mins

* Patches from Debian, Mandriva, Gentoo, others * Attack code released for new DNS attack * Open source software a security risk, and other interesting reading

Last month’s iPhone 2.0 software upgrade, in addition to adding new features, fixed a number of security problems in previous generations of the sofware. Looks like it didn’t fix enough. Security researcher Aviv Raff is reporting flaws in the iPhone’s e-mail and Safari browser applications that could be exploited to spam the affected device. No one wants spam on their iPhone. Also today, there are two new patches available for Asterisk IP PBX system.

Researcher warns of unpatched iPhone bugs

Security vulnerabilities in the iPhone’s e-mail application and Safari Web browser can be used by phishers to dupe users into visiting malicious sites or by spammers to flood the phone’s in-box with junk mail, a researcher warned today. Computerworld, 07/23/2008.

Aviv Raff: iPhone is Phishable and SPAMable

**********

Asterisks patches DoS vulnerability

A description of the flaw from Asterisk: “By flooding an Asterisk server with IAX2 ‘POKE’ requests, an attacker may eat up all call numbers associated with the IAX2 protocol on an Asterisk server and prevent other IAX2 calls from getting through.” A fix is available.

Patch for Asterisk’s traffic provisioning system

A flaw in a Asterisk’s traffic provisioning system could be exploited to flood a server with data, resulting in a denial of service. A fix is available.

**********

Four new patches from Debian:

xulrunner (multiple flaws)

iceweasel (multiple flaws)

libgd2 (multiple flaws)

Ruby 1.8 (multiple flaws)

**********

Five new updates from Mandriva:

emacs (code execution)

wireshark (denial of service)

libxslt (buffer overflow, code execution)

MySQL (unauthorized access)

Firefox (multiple flaws)

**********

Three new fixes from Gentoo:

BitchX (multiple flaws)

PeerCast (buffer overflow, code execution)

Bacula (information disclosure)

**********

Two new patches from Ubuntu:

PHP (multiple flaws)

Dnsmasq (cache poisoning)

**********

Today’s malware news:

Attack code released for new DNS attack

Hackers have released software that exploits a recently disclosed flaw in the Domain Name System (DNS) software used to route messages between computers on the Internet. The attack code was released Wednesday by developers of the Metasploit hacking toolkit. IDG News Service, 07/24/2008.

Also: Details of major Internet flaw posted by accident

**********

From the interesting reading department:

Podcast: Open source tools help secure city network

How does a fiscally constrained city department help get its network into compliance with PCI? Best of breed open source tools are a big help, explains Alan Boulanger, former director of Information Security for the City of Springfield, Mass. (7:52)

Open source software a security risk, study claims

Open source software is a significant security risk for corporations that use it because in many cases, the open source community fails to adhere to minimal security best practices, according a study released Monday. Network World, 07/21/2008.

Design flaws, besides vulnerabilities, hurt banking sites

Banking Web sites suffer from design flaws that undermine their security, exclusive of software vulnerabilities, according to a University of Michigan study to be released Friday. IDG News Service, 07/23/2008.

Stolen tape puts Bristol-Myers employee data at risk

Bristol-Myers Squibb Co. officials last week confirmed that a non-encrypted backup tape containing the personal data of current and former-employees and their dependents was stolen June 4 from a delivery truck carrying the device. Computerworld, 07/22/2008.

Questions abound as San Francisco tries to repair network

IT managers and analysts are expressing surprise at the amount of time it appears to be taking officials at the City of San Francisco to regain full control of the city’s FiberWAN network after a disgruntled network administrator allegedly locked access to it by resetting administrative passwords to its switches and routers. Computerworld, 07/22/2008.

Also: Why San Francisco’s network admin went rogue

Kaspersky Lab’s Malaysian Web site hacked

Russian security company Kaspersky Lab’s Web site for Malaysia was defaced on Saturday along with one of its online shopping sites, according to Zone-H, an organization that documents such attacks. IDG News Service, 07/21/2008.

Rg00dP@55Wrd53z?

Tell me if this sounds like a familiar scenario. You’ve come up with a brilliant password – it’s strong, easy to remember, and you’ve finally mastered the finger gymnastics required to type it in quickly – only to find that the usage window, mandated by IT password policy, is up. Symanted Security Response blog, 07/18.2008.