Not so random encryption keys a hackers dream

Opinion
May 19, 20084 mins

* Patches from Linux * SQL injection attack in 'third wave,' says IBM * Non-tech criminals can now rent-a-botnet, and other interesting reading

Last week came word that the randomly generated crytographic keys used by certain Linux flavors were not so random. Now there’s a tool in circulation that can make it easier for attackers to crack the less-than-random keys. Debian, Ubuntu and others have released updates for the key generator. Plus, the SQL injection attack is entering its “third wave,” according to IBM.

Tools circulate that crack Debian, Ubuntu keys

A recently disclosed vulnerability in widely used Linux distributions can be exploited by attackers to guess cryptographic keys, possibly leading to the forgery of digital signatures and theft of confidential information, a noted security researcher said Thursday. Computerworld, 05/16/2008.

US-CERT advisory

F-Secure: Debian OpenSSL Vulnerability

Debian re-updates OpenSSH patch

**********

Two new updates from Mandriva:

libvorbis (multiple flaws)

rdesktop (multiple flaws)

**********

Today’s malware news:

SQL injection attack in ‘third wave,’ says IBM

A SQL injection attack that has affected at least a half-million Web sites has entered a “third wave” that’s more resistant than previous versions to traditional security measures, according to IBM security researchers. Network World, 05/15/2008.

After ‘treasure hunt,’ hacker releases IE attack code

One week after hiding Internet Explorer attack code on his Web site, security researcher Aviv Raff has posted details on how to launch the attack. The bug lies in the “Print Table of Links” feature, which lets IE users print out a Web page along with a list of all the links on the page tacked onto the end. Raff discovered that if an attacker added special scripting code to a Web page, he could then run unauthorized software on the PCs of IE users who printed using this feature. IDG News Service, 05/15/2008.

Aviv Raff: Happy Birthday Israel!

OKOK.exe is not okay – okay?

Recently I came across a worm that has the potential to send the internal infrastructure of a network to the attacker by using a service related to Backdoor.CVM. The infection begins like it usually does. Someone clicks something they shouldn’t. Regardless of how it happens, the results are the same. The SpywareGuide Greynets Blog, 05/13/2008.

More Fake Instant Messaging Scams

Here’s another fake Instant Messaging application from the creator of the fake Google Talk program currently in circulation. This time round, the victim is MSN Messenger. The SpywareGuide Greynets Blog, 05/09/2008.

Non-tech criminals can now rent-a-botnet

**********

From the interesting reading department:

Apple dismisses Safari download issue

A security researcher has published a demonstration exploit that takes advantage of the download mechanism in Apple’s Safari browser to automatically download files onto a user’s system. Nevertheless, Apple said it does not consider the issue a security vulnerability, according to Nitesh Dhanjani, a researcher who currently leads application security efforts at professional services company Ernst & Young. TechWorld, 05/16/2008.

Non-tech criminals can now rent-a-botnet

Online fraudsters that aren’t highly skilled in the arts of cybercrime can now rent a service that offers an all-in-one hosting server with a built-in Zeus trojan administration panel and infecting tools, allowing them to create their own botnet. Computerworld, 05/15/2008.

Oklahoma State breach points to higher-ed security problems

A seemingly neverending string of data breaches at various colleges around the U.S. highlights precisely why university systems and networks continue to have a reputation for being notoriously insecure. Computerworld, 05/15/2008.

Quickly Identifying And Solving Software Bugs

Nearly every IT project manager, designer, DBA and developer wants to build the perfect software application: the seamless union of hardware and software, intuitive and robust, with eye-popping performance and rock-solid logic. While this pinnacle is difficult to reach, and flaws will be found-there are steps you can take to resolve them more quickly. CIO, 05/14/2008.

Bring me a password. Now bring me another and another …

Chew on this statistic: Worldwide spending on identity and access management reached almost $3 billion in 2006, according to a 2007 IDC study of the authentication technology market. That’s $3 billion to bridge the Internet Age moats around our castles, but it does not include the cost of aspirin for headaches that password issues cause network administrators and users alike every year. Network World, 05/19/2008.

DNS trouble knocks NSA off Internet

A server problem at the U.S. National Security Agency has knocked the secretive intelligence agency off the Internet. The agency’s Web site was unresponsive at 7 a.m. Pacific time Thursday and continued to be unavailable throughout the morning for Internet users. IDG News Service, 05/15/2008.

Fujitsu security system targets employee tailgating

A new security system from Fujitsu aims to improve security in facilities like datacenters by catching attempts to tailgate authorized employees into secure areas. IDG News Service, 05/19/2008.

Microsoft ballyhoos Vista’s lower patch count

Microsoft touted Windows Vista’s lower patch count Wednesday, saying it required about 20% fewer fixes in 2007 than the four-year-old Windows XP Service Pack 2. Computerworld, 05/17/2008.