Storm Worm works overtime during holidays

Opinion
Jan 3, 20084 mins

* Storm Worm rears ugly head(s) for holidays * Patches from Adobe, Apple, Debian, others * HP patches 'bricking' bug in software update service, and other interesting reading

While many of us were taking a break to celebrate the holidays, hackers were busy creating new variations of the Storm Worm and malware authors attempted to take advantage of a high-profile assassination in Pakistan.

Malware news:

Storm Worm rears ugly head(s) for holidays

Interestingly, a few days before Christmas, some of the security blogs were noting with surprise that no new Christmas-themed Storm Worm variations had yet appeared. Turns out it was the calm before the Storm, so to speak. First, a new variant of Storm featuring Christmas-themed strippers hit e-mail inboxes. By New Year’s day, the message changed again, this time with an e-mail featuring a executable files named “happy-2008.exe” and “happynewyear2008.exe”.

Personally, I didn’t see any of the Christmas Storm Worm variants in my various inboxes, but gMail did filter out quite few of the Happy New Year virus into the automated Spam folder. Hopefully, most (or all) corporations are blocking executable attachments at the gateway so this was nothing to worry about.

Some related Storm coverage:

Storm switches tactics third time, adds rootkit

Storm worm tempts with Christmas strip show

F:Secure: It’s a Stormy Christmas Eve…

F-Secure: Happy2008.exe

Arbor Networks Security to the Core: Storm and 2008 – New Campaign

Hackers quickly move to exploit Bhutto assassination

Hackers will use any major event/disaster for a social engineering exploit. The assassination of former Pakistani Prime Minister Benazir Bhutto was no different, creating sites designed to lurn in people searching for news, but instead delivering malware.

Researcher says Sears downloads spyware

Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they’d bargained for, a prominent anti-spyware researcher claims. IDG News Service, 01/01/08.

Trojan bumps Google ads from Web pages

A security company has identified a Trojan horse program that replaces Google text advertisements on Web pages with ads from another source, depriving Google of revenue and potentially causing problems for end users. IDG News Service, 12/20/07.

**********

Today’s bug patches and security alerts:

Adobe patches nine critical flaws in Flash

Adobe Systems Inc. patched its Flash Player earlier this week, fixing nine critical vulnerabilities that hackers could use to attack Windows, Mac and Linux machines. Computerworld, 12/21/07.

Adobe advisory: Flash Player update available to address security vulnerabilities

US-CERT advisory: Adobe Updates for Multiple Vulnerabilities

**********

Apple patche Safari hole

Security Update 2007-009 v1.1 for Mac OS X v10.5.1 and Mac OS X v10.4.11 fix a flaw in Apple’s Safari browser that could cause the application to crash when visiting certain sites.

**********

Asterisk patches flaw in SIP channel driver

A flaw in Asterisk 1.4’s implementation of the SIP channel driver could be exploited in a denail of service attack against the PBX software. Users should download version 1.4.14 to fix the problem.

**********

Seven new updates from Debian:

libsndfile (buffer overflow, code execution)

peercast (buffer overflow, code execution)

inotify-tools (buffer overflow, code execution)

typo3-src (SQL injection)

tar (multiple flaws)

cupsys (multiple flaws)

linux-2.6 (multiple flaws)

**********

11 new patches from Gentoo:

OpenOffice.org (user-assisted code execution)

GTK+ library (user-assisted code execution)

Wireshark (multiple flaws)

Opera (multiple flaws)

Mozilla Firefox, SeaMonkey (multiple flaws)

ClamAV (multiple flaws)

Syslog-ng (denial of service)

Multi-Threaded DAAP Daemon (multiple flaws)

exiftags (multiple flaws)

Exiv2 (integer overflow, code execution)

libexif (multiple flaws)

**********

From the interesting reading department:

HP patches ‘bricking’ bug in software update service

HP has fixed flaws in a patch-management program bundled with its computers, printers and other hardware that could be used by hackers to “brick” HP or Compaq PCs. Computerworld, 12/24/07.

Why Did My Next Door Neighbor Erect a 50-Foot Radio Antenna?

Wireless keyboards have been around for several years. After developing the first series of infrared devices, vendors have developed radio-based keyboards that run at 27 MHz. Symantec Security Response blog, 12/28/07.