* Patches from Gentoo, Debian * Inside a Malicious Flash File * Google Earth with Worms, Spam and Malware, and other interesting reading
endif; ?>An early flaw in Apple’s Safari browser for Windows might have deeper consequences, particularly when exploited along with an unpatched bug in Internet Explorer. Microsoft is saying users should avoid Safari all together at this point. (Firefox seems to be the winner here.) Also, Gentoo and Debian have patches out for a heap overflow in Samba, the popular networking protocol.
Safari flaw worse than first thought, Microsoft warns
Microsoft is warning that a previously disclosed flaw in Apple’s Safari browser could have dire consequences for Windows users. The Safari bug, originally disclosed on May 15 by security researcher Nitesh Dhanjani, allows attackers to litter a victim’s desktop with executable files, an attack known as “carpet bombing.” It turns out that if this flaw is exploited in combination with a second unpatched bug in Internet Explorer, attackers can run unauthorized software on a victim’s computer. IDG News Service, 06/01/2008.
Aviv Raff: Safari pwns Internet Explorer
Nitesh Dhanjani May 15th warning
**********
Two new patches from Gentoo:
Samba (heap overflow, code execution)
MPlayer (integer overflow, code execution)
**********
Two new updates from Debian:
Samba (heap overflow, code execution)
**********
Today’s malware news:
We get samples – lots of samples – every day. Like tens of thousands of them. They are coming from various sources. From our customers. From honeypots and honeynets. Via our online scanners. Submitted directly from our products. From operators and ISPs. Via sample exchange with our competitors and so on. F-Secure, 06/01/2008.
The lab has been receiving lots of malicious flash files lately. Most of the flash files that we’ve received have obfuscated shellcodes. Our systems flagged one sample and I decided to take a closer look. F-Secure, 05/29/2008.
**********
From the interesting reading department:
Google Earth with Worms, Spam and Malware
Google Earth is cool. We’ve been using it to track worms. If a worm contacts our monitoring system, its IP address is logged and is then converted to latitude and longitude. It alls goes into an XML feed that we use with Google Earth’s network links. F-Secure, 05/31/2008.
Bank loses tapes with data on 4.5M clients
Bank of New York Mellon Corp. officials last week confirmed that a box of unencrypted data storage tapes holding personal information of more than 4.5 million individuals was lost more than three months ago by a third-party vendor during transport to an off-site facility. Computerworld, 06/01/2008.
What the DOS Attack Against Revision3 Was Really About
The denial-of-service attack against online video distributor Revision3 continues to make waves. Revision3 CEO Jim Louderback revealed yesterday that his company had identified the anti-piracy outlet Mediadefender as the source of a massive flood of messages that brought Revision3’s infrastructure to its knees. New Tee Vee, 05/30/2008.




