* Patches from Apple, Debian, Gentoo, others * Safe Summer Travels on the Information Superhighway, and other intersting reading
endif; ?>Apple has gotten off the sidelines and patched its version of DNS, nearly a month after a researcher disclosed major issues with the naming system. The DNS update for Mac OS X is part of a broader security update from Apple. There are some reports from another researcher that the patch does not work, so be on the lookout for a potential follow-up patch from Apple.
Apple finally patches dangerous DNS flaw
Apple has at last issued a patch for the DNS (Domain Name System) flaw considered one of the most dangerous vulnerabilities ever to affect the Internet. On Friday, Apple posted a security advisory saying that the patch will fix Apple’s implementation of the Berkeley Internet Name Domain (BIND) DNS server in Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.4 and Mac OS X Server v10.5.4. Apple has also wrapped a dozen other fixes in the security update. The fixes can be downloaded individually or the “software update” feature can be used in OS X to download the whole batch. IDG News Service, 08/01/2008.
Also: Apple’s patch fails to fix DNS flaw, researchers claim
**********
Researcher reveals Twitter ‘follow’ bug
Attackers can exploit a bug in Twitter to force victims to follow the hacker’s account, a security researcher said Thursday. According to Aviv Raff, the Twitter vulnerably could expose users to malware-hosting Web sites. Computerworld, 07/31/2008.
**********
Five new updates from Debian:
httrack (buffer overflow, code execution)
libxslt (buffer overflows, code execution)
newsx (buffer overflow, code execution)
**********
Four new patches from Gentoo:
Pan (buffer overflow, code execution)
Linux Audit (buffer overflow, code execution)
**********
Three new fixes from Ununtu:
libxslt (buffer overflows, code execution)
**********
Two new patches from Mandriva:
libxslt (buffer overflows, code execution)
**********
From the interesting reading department:
Safe Summer Travels on the Information Superhighway
With the Olympics right around the corner and being that we are in the heart of the summer, I’m sure many of you will find yourselves travelling quite extensively. Nowadays, it’s almost impossible to go cold turkey from the Internet. Symantec Security Response, 08/01/2008.
Busch alerts N.H. residents: Stolen laptop had personal data
About 2,250 New Hampshire residents have been notified that their personal information was stored on a laptop computer taken by thieves that burgled an Anheuser-Busch Co. office in Missouri in June. Computerworld, 08/02/2008.
Busch alerts N.H. residents: Stolen laptop had personal data
Customers of small ISPs may be at risk of online fraud, following the industry’s lax response to securing against the recently discovered Domain Name System (DNS) cache poisoning flaw. Computerworld, 08/02/2008.
Black Hat Talk on Apple Encryption Flaw Pulled
A security researcher who was set to speak at the Black Hat hacker convention in Las Vegas next week on a previously undiscovered flaw in Apple’s FileVault encryption system has canceled his talk, citing confidentiality agreements with the Cupertino computer maker. Security Fix blog, 07/31/2008.
Hunting Unicorns: Myths and Realities of the Net Neutrality Debate
In many ways, the emotionally charged debate on Network Neutrality (NN) has been a lot like hunting Unicorns. While hunting the mythical horse could be filled with adrenalin, emotion, and likely be quite entertaining, the prize would ultimately prove to be elusive. Security to the Core blog, 08/01/2008.
FBI: Flash drive used to steal Countrywide data
Struggling home mortgage lender Countrywide, already hit hard by the lending crisis and an investigation into potential fraud at the company, now faces another crisis: One of its employees has been charged for allegedly stealing personal information about customers. IDG News Service, 08/01/2008.




