Patch Tuesday and a full moon: A bad combo?

Opinion
Oct 13, 20084 mins

* Patches from Microsoft, Apple, Gentoo * Trojan.Silentbanker Decryption * World Bank denies report of massive data breaches, and other interesting reading

October’s Patch Tuesday is upon us with 11 new updates for various Microsoft products including Active Directory, Internet Explorer and Excel. Tuesday is also a full moon, so should be an interesting day. Apple users too have some patching to do as the company released a new wide-ranging Mac OS X update last week. Finally, with the downturn in the economy comes opportunity for spammers, phishers and malcode authors. If the deal looks too good to be true, it probably is.

Exploit code loose for six-month-old Windows bug

Microsoft Thursday acknowledged that exploit code is circulating for a vulnerability it acknowledged six months ago, but has yet to patch. It’s not clear whether Microsoft intends to fix the flaw next week. On Thursday, Microsoft revised a security advisory it first posted April 19 about a bug in Windows XP, Vista, Server 2003 and Server 2008 that could be exploited to gain additional privileges on vulnerable machines. Computerworld, 10/11/2008.

11 Microsoft security updates due next week

Next week will be a busy one for system administrators as Microsoft is planning to ship 11 security updates — four of them rated critical — for its products. The patches will include fixes for critical security bugs in Windows Active Directory, Internet Explorer, Excel and the Microsoft Host Integration Server, which integrates Windows computers with IBM mainframes, Microsoft said Thursday in a note on the patches. IDG News Service, 10/09/2008.

Microsft advance advisory

**********

Apple releases new wide-ranging security update

Apple on Thursday posted Security Update 2008-007, a new security patch for client and server versions of Mac OS X 10.5 “Leopard” and Mac OS X 10.4.11. The update is available for download from the Software Update system preference or from Apple’s Web site. Multiple vulnerabilities have been address in the Apache 2.2.9 release, the most serious of which may lead to cross site request forgery. Root certificates have been updated, added to the list of system roots. ClamAV — the open-source anti-virus software included on Mac OS X Server — was updated to 0.94, addressing problems that could lead to arbitrary code execution. Macworld, 10/09/2008.

Apple advisory**********

Two new patches from Gentoo:

Portage (root privileges, code execution)

WordNet (multiple flaws)**********

Today’s malware news:

Trojan.Silentbanker DecryptionOn Monday we saw that Trojan.Silentbanker had added rootkit functionality in order to hide its own files. Today we’ll look at another change that the new version of the Trojan has introduced, namely, the new configuration file format that the Trojan uses. Symantec Security Response, 10/10/2008.

**********

From the interesting reading department:

Economic Crisis: A Phishing and Malcode OpportunityIn the past few weeks as a flurry of global financial institutions have suffered, a lot of names have been bandied about. Some banks have merged, some banks have faltered, and some government programs have been highlighted. It turns out that this is giving some enterprising phishers and malcode authors an opportunity. They’re preying on fears and name recognition. Security to the Core blog, 10/09/2008.World Bank denies report of massive data breachesCount the World Bank Group among the high profile organizations suffering major data breaches – maybe. Word of the possible breaches just adds to a weeks-long series of bad news related to the economy and financial industry, turmoil that appears to be starting to take its toll on the tech industry as well. Network World, 10/12/2008.Google in curious alliance with click-fraud detection firmIn a development that would have seemed impossible two years ago, Google is cooperating publicly with Click Forensics, a click-fraud detection company with which it has had a rocky relationship. IDG News Service, 10/10/2008.Targeted ScamsIn the last couple of months the trend seems to have shifted towards cybercriminals employing a great number of resources to commit financial fraud through targeted scams. The latest attempt surfaced around the recent launch of the Apple iPhone. Panda Security, 10/11/2008.