* Patches from Microsoft, Cisco, Linux * Hacker writes rootkit for Cisco's routers * The case of the tampered USBs, and other interesting reading
As we reported earlier this week, Microsoft came out with four patches (three critical) for its various systems, including Word, Publisher, and the Jet database engine. Cisco also had four patches of its own, all focused around the company’s unified communications platform. Also, Linux vendors Debian, Mandriva, Gentoo and Ubuntu all have handfuls of new patches available for users.
Microsoft Patch Tuesday: Four patches fix mostly Office vulnerabilities
Microsoft Tuesday released four patches to fix six vulnerabilities, three of which were rated critical for Microsoft Word, Publisher and the Jet Database Engine 4.0. Experts say the fourth patch, rated important, could also be viewed as critical because it affects security software that could be shut down in an attack. Network World, 05/13/2008.
Microsoft advisories:
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
Vulnerability in Microsoft Publisher Could Allow Remote Code Execution
Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution
Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service
Related:
Determining Microsoft Jet Database Engine vulnerability
Do we need to worry about the recently disclosed vulnerability in the Microsoft Jet Database Engine if we have Windows XP Service Pack 3 installed? Network World, 05/14/2008.
US-CERT: Microsoft Updates for Multiple Vulnerabilities
**********
Four vulnerabilities found in Cisco Unified Communications Manager
On May 14 Cisco issued a security advisory for Cisco Unified Communications Manager (formerly Cisco CallManager). Patches are now available to fix four denial of service (DoS) vulnerabilities all of which were discovered internally by Cisco. Cisco Subnet, 05/14/08.
Cisco advisories:
Cisco Unified Presence Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Content Switching Module Memory Leak Vulnerability
**********
Seven new patches from Debian:
gforge (non-secure temp files, file overwrite)
openssh (predictable random key generation)
openssl (predictable random key generation)
**********
Two new fixes from Mandriva:
ImageMagick (heap overflows, code execution)
**********
Eight new updates from Gentoo:
OpenOffice.org (multiple flaws)
Common Data Format library (user-assisted code execution)
Pngcrush (user-assisted code execution)
MoinMoin (privilege escalation)
**********
Six new patches from Ubuntu (all OpenSSL related):
**********
Today’s malware news:
SQL Injection Attacks Becoming More Intense
The mass SQL injection attacks we’ve mentioned here and here are increasing in number and we’re seeing more domains being injected and used to host the attack files. We believe that there is now more than one group using a set of different automated tools to inject the code. F-Secure blog, 05/13/2008.
Phishing botnet expands by hacking legit sites
A botnet is now using a SQL injection attack tool designed to hack legitimate Web sites, a move meant to add more hijacked PCs to its collection, according to a security researcher. Computerworld, 05/14/2008.
Hacker writes rootkit for Cisco’s routers
A security researcher has developed malicious rootkit software for Cisco’s routers, a development that has placed increasing scrutiny on the routers that carry the majority of the Internet’s traffic. IDG News Service, 05/14/2008.
Fake Windows Update Popup: It’s Back (Again)
The fake Windows Update popup has been doing the rounds on Myspace for a long time (we’re talking at least June 2007). Every now and again it returns, usually varying the payload. Well, here we have an example where Phishing is involved and a sneaky imitation of a well known security program is thrown in for good measure. The SpywareGuide Greynets Blog, 05/14/2008.
Phishers scamming IRS rebates
Scammers want your IRS refund checks and have devised at least one phishing scheme to get it, according to the FBI. The e-mail, which purports to be from the IRS advises recipients that the best way to get their economic stimulus rebate money is by direct deposit. It then directs them to a Web site that asks them to enter bank account information and other personal data. Network World, 05/12/2008.
**********
From the interesting reading department:
Debian predictable PRNG fiasco
I am a big fan of Debian and Ubuntu- but not a big fan of gaping, ginormous security holes. The largely under-reported “predictable Pseudo Random Number Generator” OpenSSL vulnerability in Debian (and Ubuntu, and other Debian variants) leaves a gaping hole not only in those systems, but systems which are using keys from vulnerable systems. Uncommon Sense Security, 05/14/2008.
The case of the tampered USBs
How does a company keep up? Can anyone know all the ways in which data can leave a company? Can they know who should see what? The challenge now exists in using an organization’s traffic to determine what is normal, to investigate unusual activities or to validate the rules they have in place. Network World, 05/12/2008.
Three charged in Dave & Buster’s hacking job
It may not have been the greatest hack ever, but police say the malicious software sneaked onto restaurant chain Dave & Buster’s corporate network was good enough to earn criminals hundreds of thousands of dollars. IDG News Service, 05/12/2008.
Hackers create their own social network
Hackers now have their own social network, backed by GnuCitizen, a high-profile “ethical hacking” group. The network, called House of Hackers, has signed up more than 1,000 members since its launch earlier this week, according to the site. TechWorld, 05/12/2008.
Installing Windows XP SP3? Read This First
Take your hands off that mouse. I know, you’re ready to grab XP SP3. But slow down a sec and read my quick tutorial. It could save you some time and make your life with the new Service Pack less harrowing. PC World, 05/13/2008.
Hacker posts Chilean government data on 6 million
An anonymous hacker has posted personal data about 6 million Chilean residents on the Internet, highlighting wider privacy problems in the country. IDG News Service, 05/13/2008.
Icy encryption tool protects laptops from “cold boot” attack, vendor says
The vendor HyBlue says it can prevent the “cold boot” encryption hack discovered by Princeton researchers with a laptop security product announced Tuesday. Network World, 05/13/2008.




