* Patches from Debian * Hacked Texas National Guard site serves up malware * , and other interesting reading
endif; ?>Much attention is being brought to the Web-based mail security (or lack of), after last week’s hack in to vice presidential candidate Sarah Palin’s Yahoo e-mail account. It seems all the major services are vulnerable to the same sort of password recovery hack used in the Palin case, so vendors are coming out with ways you can protect yourself and tips for the providers to offer better security for end users. The good news is, authorities seem to be hot on the trail of the Palin hacker.
VMWare releases critical fix for ESXi and ESX 3.5The Openwsman system management platform inside VMWare’s ESXi and ESX 3.5 applications is vulnerable to two buffer overflows that could be exploited by remote attackers. A patch is available.
**********
Hacker posts QuickTime zero-day attack codeA hacker has released attack code that exploits an unpatched vulnerability in Apple’s QuickTime, just a week after the company updated the media player to plug nine other serious vulnerabilities, a security researcher said last week. Computerworld, 09/18/2008.
**********
Four new updates from Debian:
Python Django (cross site request forgery)
twiki (information leak, code execution)**********
Today’s malware news:
Fake Paypal BruteforcerI see a lot of programs designed to hack the wannabe hacker. It’s been a trend for some time now for professional Phishers to offer up Trojaned Phishing kits to newbies (so they can watch the newcomer do all the hard work then snatch the booty at the last second), and the practice of hackers placing bait for wannabes such as this has probably been going on for a lot longer. The SpywareGuide Greynets Blog, 09/21/2008.Hacked Texas National Guard site serves up malwareAttackers have hacked the Web site of the Texas National Guard and are using it to serve up offers of fake security software and plant rootkits on unpatched PCs, a security researcher said Thursday. Computerworld, 09/19/2008.
**********
From the interesting reading department:
Legislator’s son at center of Palin hack talkA Tennessee state legislator has confirmed that his son, a 20-year-old student at the University of Tennessee-Knoxville, is the person being named on blogs and message boards in connection with the hacking of Gov. Sarah Palin’s e-mail account, a Nashville paper reported late Thursday. Computerworld, 09/21/2008.
Also: FBI searches Tenn. student’s apartment in Palin hacking case
Also: Anon Delivers?
Protecting your WebmailIs there was any way to tell if someone had broken into your Webmail account? IBM’s Frequency X blog, 09/19/2008.Yahoo, Hotmail, Gmail all vulnerable to password reset hackYahoo Mail isn’t the only Web-based mail service that could be duped into giving up someone else’s account password, the tactic that some have argued was used to break into Gov. Sarah Palin’s e-mail earlier this week. Computerworld, 09/20/2008.Cybercrime toll mounts for businessesCybercrime is more than a buzzword, it’s a critical business concern, say 1,387 IT professionals surveyed by security firm Finjan. Network World, 09/22/2008.Wikileaks posts Bill O’Reilly Web site dataJust days after publishing U.S. vice presidential candidate Sarah Palin’s personal e-mail messages, the Wikileaks Web site has published data about members who signed up for a section of Fox Television host Bill O’Reilly’s Web site. IDG News Service, 09/20/2008.Retail security: ‘Knee-jerk’standards compliance isn’t enoughBusinesses certified to be compliant with the Payment Card Industry Data Security Standards (PCI DSS) keep suffering data breaches, but the problem may be more with the way businesses address the requirements than with the PCI standard, experts told an Interop gathering. Network World, 09/18/2008.




