* Patches from Cisco, uTorrent, Mandriva * Another Round of Peacomm Infections Under way * VMware CEO apologizes for virtual-server bug, and other interesting reading
endif; ?>With Microsoft’s monster Patch Tuesday now behind us, today’s alerts seem light by comparison. WebEx power users will want to make sure they’re using the latest update of WebEx Meeting Manager as previous versions contain a flaw that could result in malicious code running on the machine. Also, the peer-to-peer client uTorrent has a major update that fixes some serious flaws. And, VMWare’s CEO is apologizing for last week’s minor spot of bother with his company’s software that left customers unable to log in.
Cisco patches WebEx Meeting Manager
According to Cisco, “An ActiveX control (atucfobj.dll) that is used by the Cisco WebEx Meeting Manager contains a buffer overflow vulnerability that may result in a denial of service or remote code execution.” There’s a manual workaround available as well as an updated version of WebEx Meeting Manager.
**********
Peer-to-peer client uTorrent fixes serious vulnerability
One of the most popular programs used by some to illegally share files under copyright has patched a serious software vulnerability. The problem affects the peer-to-peer program uTorrent as well as BitTorrent Mainline, another program based on the uTorrent code. It has been classified as “highly critical,” the second most severe ranking of risk, by Secunia, a security vendor in Denmark. IDG News Service, 08/15/2008.
Secunia: uTorrent “created by” Buffer Overflow Vulnerability
**********
Three new patches from Mandriva:
cups (buffer overflow, code execution)
stunnel (authentication capture)
**********
Today’s malware news:
Another Round of Peacomm Infections Under way
The Peacomm network has definitely turned out to be a survivor. With infections dating back to January 2007 and a P2P structure largely unchanged in about a year, Peacomm continues to evolve and infect new hosts. In early August our honeypots began capturing a new version of Peacomm. Symantec Security Response, 08/14/2008.
Anti-Georgia spammers building new botnet
Hackers targeting Georgia in the midst of its conflict with Russia have started sending out a new batch of malicious spam messages, apparently with the aim of building a new botnet network of remote-controlled computers. IDG News Service, 08/15/2008.
**********
From the interesting reading department:
VMware CEO apologizes for virtual-server bug
VMware’s new CEO Paul Maritz has apologized to customers in a company blog posting after a major bug prevented VMware users from logging on to virtual servers this week. Network World, 08/14/2008.
Torvalds: Fed up with the ‘security circus’
Linus Torvalds, creator of the Linux kernel, says he’s fed up with what he sees as a “security circus” surrounding software vulnerabilities and how they’re hyped by security people. Torvalds explained his position in an e-mail exchange with Network World this week. He also expanded on critical comments he made last month that caused a stir in the IT industry. Network World , 08/14/2008
Wells Fargo codes used to access personal information
Wells Fargo Bank NA is notifying some 7,000 people that their Social Security numbers and other personal information may have been accessed by thieves using the financial services firm’s access codes. Computerworld, 08/18/2008.
As of this blog posting, exactly 900 days remain until the end of the Internet, or at least the exhaustion of IPv4 registry allocations. And you don’t have to take my word for it, even the normally staid London Times and Fox News proclaimed, “Internet meltdown: The world is heading for a digital doomsday”. Heady stuff. Security to the Core, 08/18/2008.
Drops, Dumps, CVVS, WMZ, WU, et cetera…
Underground forums are always full of chatter around various activities related to online crime. You keep reading about things like dumps (stolen credit card information), carding (using those cards), WU (Western Union), WMZ (Webmoney), CVVs (card verification value) and drops. So what’s a drop? F-Secure, 08/18/2008.




