Inside the hacker underground

Opinion
Sep 25, 20084 mins

* Patches from Cisco, Firefox, Apple * Apple's patch process a mess, say researchers, and other interesting reading

Tom Rusin, President of Affinion Security Center, has me scared that hackers are trading my personal and credit card information all over the Web. His company uses monitoring of underground chat rooms and other sources to help keep customers credit safe and he recently gave me a live look at the hacker underground in action. Amazing how much of this information is being traded every minute.

Cisco releases bundle of router security patches

Cisco has issued a set of security patches for the Internet Operating System (IOS) software, used to power its routers and switches. The patches were published Wednesday, the date Cisco had previously set aside as the latest release date for its twice-yearly IOS patches. Cisco also published 12 security advisories describing the bugs, noting that many of these vulnerabilities could be exploited by attackers to crash an IOS device. IDG News Service, 09/25/2008.

All 12 advisories listed here

**********

Firefox update patches a dozen flaws

A new update for Mozilla’s Firefox browser (version 3.0.2) fixes a dozen different flaws from previous versions. The most serious of the vulnerabilities could be exploited to run malicious software on an affected machine. Firefox should automatically download the update, but you may need to manually restart the application, unlike with previous versions of Firefox where it asks you to restart as soon as the update is downloaded.

**********

Apple releases Java updates

Two new updates from Apple fix flaws in its Java implementation in Mac OS X 10.4 and 10.5. The most serious of the flaws could allow an applet to access local files and resources.

Java for Mac OS X 10.5 Update 2

Java for Mac OS X 10.4, Release 7

**********

Adobe slates patch for Flash clipboard poisoning attacks

Adobe Systems last week said it will soon quash a bug in Flash that has been used for more than a month by attackers to poison Mac and Windows users’ clipboards with URLs to malicious sites. Computerworld, 09/22/2008.

More info on the slated fix

**********

Seven new updates from Gentoo:

GNU ed (buffer overflow, code execution)

BitlBee (authentication bypass, account hijack)

R (symlink attack)

Newsbeuter (shell command execution)

HAVP (denial of service)

Mantis (multiple flaws)

Postfix (denial of service)**********

Six new patches from Mandriva:

blender (code execution)

awstats (cross scripting)

phpMyAdmin (multiple flaws)

pan (denial of service)

ed (heap overflow, code execution)

wireshark (multiple flaws)**********

Two new fixes from Ubuntu;

rdesktop (multiple flaws)

Firefox (multiple flaws)**********

From the interesting reading department:

Apple’s patch process a mess, say researchersApple’s patching process proves that the company isn’t serious about moving Macs into the enterprise, security researchers said Monday. Computerworld , 09/22/2008.Intrusion-prevention systems still not used full throttle: survey

Intrusion-prevention systems often aren’t used to actually block attack traffic, but instead act more like intrusion-detection systems, according to an Infonetics Research survey of 169 information professionals who offered a detailed look at how IPS equipment really gets used. Network World, 09/23/2008.

Computer users overeager to click popup ‘OKs’Web surfers have a standard reaction to error messages that pop up in their Web browsers, according to new research published this week: They click “OK” and hope it will disappear. IDG News Service, 09/25/2008.McAfee to acquire Secure Computing for $465MMcAfee Monday announced an agreement to acquire Secure Computing in a transaction valued at $465 million in a deal both companies say will help in winning customers in an era where broad product portfolios have an advantage. Network World, 09/22/2008.IBM’s AppScan now quashes bugs during developmentIBM on Monday introduced new source-code-scanning software designed to spot security bugs as programs are being written. IDG News Service, 09/22/2008.Palin hacker’s IP address linked to student’s apartmentThe man who traced the IP address of the hacker who accessed Alaska Gov. Sarah Palin’s e-mail account last week confirmed Monday that it belongs to an Illinois company that provides Internet service to the Knoxville, Tenn., apartment complex where the FBI served a search warrant early Sunday. Computerworld, 09/22/2008.