Microsoft plays Whack-a-Mole with fixes

Opinion
Jun 30, 20083 mins

* Patches from rPath, Ubuntu, Debian, others * Fast Flux and New Domains for Storm * Summertime security: No letup for IT, and other interesting reading

Microsoft seems to have gotten its arms around a fix for Windows XP Service Pack 3 that crippled a number machines. But while that fix is in progress, researchers are warning of a Zero-Day bug in Internet Explorer 6. Never a dull moment for the Redmondians. Also, we reported that the popular Ruby on Rails programming environment suffers from some flaws last week. This week, Linux vendors are coming out with patches for the environment.

Researchers warn of IE6 zero-day bug

Security researchers are warning users about an unpatched cross-site scripting bug in Internet Explorer 6 (IE6) that could be used by hackers to capture keystrokes and steal other information. The vulnerability appears to be a variation of a vulnerability first discussed by researchers Manuel Caballero and Fukami at Microsoft’s on-site BlueHat security conference early last month, Yichong Lin, an analyst at McAfee, said in an entry to the company’s blog. Computerworld, 06/26/2008.

F-Secure: Internet Explorer 6 Cross-Domain Scripting Vulnerability

Microsoft repairs PCs crippled by XP SP3 update

Nearly three weeks after security vendor Symantec released a free tool to clean up PCs crippled by the Windows XP Service Pack 3 (SP3) update, Microsoft issued a fix that should reestablish lost Internet and wireless connections. Computerworld, 06/29/2008.

Microsoft advisory

**********

Two new updates from rPath:

ruby (multiple flaws)

kernel (multiple flaws, denial of service)

**********

Three new fixes from Ubuntu:

ruby (multiple flaws)

OpenSSL (denial of service)

Samba (buffer overflow, code execution)

**********

Two new patches from Debian:

dbus (local privilege escalation)

libtk-img (buffer overflow, code execution)

**********

Today’s malware news:

Fast Flux and New Domains for Storm

Storm has changed its tactics constantly in the past year and a half, and this “love theme” is nothing new. We’ll see how long this theme lasts. Security to the Core blog, 06/28/2008.

**********

From the interesting reading department:

Hackers hijack critical Internet organization sites

Turkish hackers yesterday defaced the official sites of the international organizations that oversee the Internet’s critical routing infrastructure and regulate domain names, researchers said today. Computerworld, 06/27/2008.

Summertime security: No letup for IT

What ever happened to the lazy days of summer? For IT and security managers in businesses, hospitals and universities across the country, summer is just another season to get things done. Here’s a roundup of IT security projects we’re hearing about. Network World, 06/27/2008.

Malware, spam, botnets growing faster than ever before

The spam and malware tsunami continues to cast a mounting shadow over the Internet this week. Computerworld, 06/26/2008.

Cisco, IBM, Intel, Juniper and Microsoft fight cyber terror together

Five major network hardware, software and services vendors are banding together to improve IT security by promoting faster responses to threats. Network World, 06/27/2008.