iPhone Trojan and MBR rootkit kick off 2008

Opinion
Jan 10, 20085 mins

* Patches from Debian, Gentoo, Mandriva, others * First Trojan reported for the iPhone * 'Hacker safe' Web site gets hit by hacker, and other interesting reading

While most of the tech world had its eyes focused on the big Consumer Electionics Show in Las Vegas this week, spammers and malware writers were getting their operations cranked up for 2008 with a new Master Boot Record rootkit and iPhone Trojan.

Microsoft: Flaw could lead to worm attack

Microsoft has fixed a critical flaw in the Windows operating system that could be used by criminals to create a self-copying computer worm attack. IDG News Service, 01/08/08.

Microsoft advisories:

Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution

Vulnerability in LSASS Could Allow Local Elevation of Privilege

Related alert:

US-CERT: Microsoft Updates for Multiple Vulnerabilities

**********

Seven new patches from Ubuntu:

Squid (denial of service)

Net-SNMP (denial of service)

CUPS (multiple flaws)

opal (denial of service)

pwlib (denial of service)

Tomboy (code execution)

MySQL (multiple flaws)

**********

Seven news updates from Debian:

Dovecot (programming error, information disclosure)

fail2ban (programming error)

libarchive1 (multiple flaws)

freetype (integer overflow)

tomcat5 (multiple flaws)

wzdftpd (denial of service)

mysql-dfsg-5.0 (multiple flaws)

**********

Four new fixes from Mandriva:

libexif (multiple flaws)

PostgreSQL (multiple flaws)

ClamAV (multiple flaws)

WireShark (multiple flaws)

**********

Five new patches from Gentoo:

Squid (denial of service)

OpenAFS (denial of service)

Claws Mail (temp files, symlink attack)

R (multiple flaws)

unp (command execution)

**********

Today’s malware news:

First Trojan reported for the iPhone

While not a huge risk, the first Trojan for the iPhone has been discovered. The first reports came from iPhone enthusiast site Modmyifone.com and were later confirmed by security research company F-Secure. MacWorld, 01/08/08.

F-Secure: Trojan Software for iPhone

Nugache worm kicking up a Storm

Although the infamous Storm worm enters 2008 with a reputation as the world’s most dangerous botnet, security experts say there’s an up-and-comer called Nugache that could give it a run for its money. Network World, 01/07/08.

From BootRoot to Trojan.Mebroot: A Rootkit in Your MBR!

There have been recent reports of an MBR (Master Boot Record) rootkit in the wild and, of course, we have been following up these reports and doing our own analysis. An MBR is the first sector of a storage device such as a hard disk, and is generally used for bootstrapping the operating system after the computer’s BIOS has done its startup checks. Basically, if you can control the MBR, you can control the operating system and therefore the computer it resides on. Symantec Security Response blog, 01/08/08.

New MP3 spam surges

The spam wars rage on. For every technique the spammers come up with, a defense is built pushing the spammers into new techniques in an alarmingly rapid game of cat-and-mouse playing out on the Internet every day. The latest volley from the bad guys? Audio spam. CSO, 01/08/08.

Spammers hijack Microsoft site to push pill popping

Spammers have found another great place to hide spam URLs in plain sight – on Microsoft’s Live SkyDrive file sharing service. TechWorld, 01/09/08.

**********

From the interesting reading department:

‘Hacker safe’ Web site gets hit by hacker

Just because a Web site has a certification claiming that it is virtually hackproof, that doesn’t necessarily mean it’s immune to all intrusions. Computerworld, 01/07/08.

Do as I Say, Not as I Do

In these “Stormy” times, here at Symantec we regularly warn users to be wary of following links in unsolicited email. Could it be considered a coincidence then that I received the following gem directly to my work email. Symantec Security Response blog, 01/07/08.

Mass hack infects tens of thousands of sites

Tens of thousands of Web sites have been compromised by an automated SQL injection attack, and although some have been cleaned, others continue to serve visitors a malicious script that tries to hijack their PCs using multiple exploits, security experts said this weekend. Computerworld, 01/06/08.

Boeing Dreamliner could be vulnerable to hackers

The electronics of Boeing’s new 787 Dreamliner jet could be vulnerable to hackers due to the way critical flight systems are linked with those used by passengers, the U.S. Federal Aviation Administration has warned. IDG News Service, 01/07/08.

Researcher says Sears downloads spyware

Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they’d bargained for, a prominent anti-spyware researcher claims. IDG News Service, 01/01/08.

ATO plagued by e-mail scam

It is proving to be the e-mail that wont go away. The Australian Tax Office is again warning people about a fraudulent e-mail that claims to offer recipients a tax refund. Computerworld, 01/07/08.

Firms are still testing with live customer data, study warns

A majority of organizations are creating unnecessary risks by using actual customer data for the development and testing of applications, according to a survey by Compuware and the Ponemon Institute. Computerworld Uk Staff, 01/09/08.

Student antics with cell phones, iPods means heartburn for school IT staff

Students love their iPods, cell phones and social-networking sites, but school IT managers are discovering that student misbehavior with technology is adding to their network security challenges. Network World, 01/08/08.

Report: IRS information security still poor

The U.S. Internal Revenue Service continues to have “pervasive” information security weaknesses that put taxpayer information at risk, and it has made limited progress in fixing dozens of problems the U.S. Government Accountability Office has previously identified, according to a GAO report released Tuesday. IDG News Service, 01/08/08.

Open source security bugs uncovered

A U.S. Department of Homeland Security (DHS) bug-fixing scheme has uncovered an average of one security glitch per 1,000 lines of code in 180 widely used open source software projects. TechWorld, 01/09/08.

Spam your printer from the Web? Researcher shows how

Aaron Weaver has made a discovery the world could probably do without: He’s found a way to spam your printer from the Web. IDG News Service, 01/09/08.