* Patches from Ubuntu * Encrypted image backups open to new attack * CAN-SPAM: What went wrong?, and other interesting reading
Yikes. Newly discovered (but yet to be disclosed) flaws in the TCP/IP protocol – the backbone of the Internet – could be exploited to launch denial-of-service attacks against virtually any device running any operating system, including firewalls and other security measures. According to reports, the researchers that discovered the flaws are working with vendors to repair the issue before releasing their findings to the general public. iPhone users weren’t so lucky: A frustrated security researcher detailed two flaws he found in the popular Apple device after not hearing back from Cupertino on his July discovery.
Vendors fixing bug that could crash Internet systems
Internet infrastructure vendors are working on patches for a set of security flaws that could help hackers knock servers offline with very little effort. IDG News Service, 10/03/2008.
Robert Hanson: New DOS Attack Is a Killer
**********
Security researcher reveals iPhone design flaws
Apple’s iPhone has two design flaws that could pose potential security problems, according to a researcher. The first one concerns the iPhone’s e-mail application, which automatically downloads images within an e-mail. The second design flaw is how the iPhone’s e-mail application displays URLs. IDG News Service, 10/02/2008.
**********
Apple releases Apple TV 2.2 update
A new software update for Apple TV (version 2.2) fixes numerous flaws in previous versions that could be exploited to run malicious code on the device. Most of the vulnerabilities are related to how certain files are handled by the OS. Apple TV users should see the new update downloaded automatically.
**********
Two new updates from Ubuntu:
cpio (buffer overflow, code execution)
OpenSSH (denial of service, authentication bypass)
**********
Today’s malware news:
Encrypted image backups open to new attackBitmaps stored inside encrypted backup files could be vulnerable to a sophisticated ‘comparison’ attack, a German security researcher has discovered. TechWorld, 10/03/2008.Researcher finds evidence of massive site compromiseSeveral criminal gangs have acquired administrative log-in credentials for more than 200,000 Web sites — including the one used by the U.S. Postal Service — and have used the compromised domains to attack unsuspecting users’ PCs with a notorious hacker exploit kit, a researcher said today. Computerworld, 10/03/2008.Read the Verizon report (PDF)**********
From the interesting reading department:
CAN-SPAM: What went wrong?Five years ago, the U.S. tech industry, politicians and Internet users were wringing their hands over the escalating problem of spam. Network World, 10/06/2008.Prevalence of Exploited PDFsWhile the threat landscape has changed dramatically over the past years, attackers are becoming increasingly aggressive in exploring ways to get into users’ system. A spammed email with an EXE attachment no longer penetrates the wider network or users, now that most home users and enterprise networks have a certain level of awareness on information security. But, how about spamming an exploited file like a PDF? CA Security Advisor Research Blog, 10/05/2008.Does patch management need patching?According to a recent estimate from Verizon, 90% of successful exploits these days involve vulnerabilities for which a patch has been available for six months or longer. CSO, 10/01/2008.It’s All About ReputationIn a nutshell, Symantec’s new approach to detecting threats automatically derives reputation ratings (e.g. safe, unknown, unsafe) for every executable file available on the Internet. The reputation ratings are derived automatically using algorithms, not unlike Google’s Page Rank algorithm, from literally billions of Norton Community Watch file reports from our tens of millions of participating users. Symantec Security Response blog, 10/02/2008.Survey: Many computer users lack basic security precautionsCybersecurity efforts in the U.S. government and many businesses are improving, but many individual computer users still don’t take basic precautions against cyberattacks, cybersecurity experts said Thursday. IDG News Service, 10/02/2008.Sysadmin admits stealing computers, office equipment from NavyMost often when systems administrators abuse their access to corporate networks and systems, the end result is either data theft or network sabotage on a massive scale. Computerworld, 10/02/2008.




