Attack code for Windows flaw

Opinion
Jan 21, 20083 mins

* Patches from Debian, Gentoo, Ubuntu, others * FBI warns of rise in phone-based 'vishing' attacks * Hollywood's 'Untraceable': Fact or fiction?, and other interesting reading

Security researchers are already seeing attack code being circulated around the ‘Net that could be used to crash Windows machines. The code exploits a flaw that was patched last week by Microsoft, but not everyone has installed the patches at this point. Also, eBay’s Skype group is investigating a flaw in its VoIP application that could be used to sneak malicious code on to an affected system.

Attack code released for critical Windows flaw

In what may be the first step toward a major security problem, security researchers have released attack code that will crash Windows machines that are susceptible to a recently patched bug in the operating system. IDG News Service, 01/17/08.

Read about the attack code

**********

Skype flaw turns videos into weapons

A programming error in eBay’s Skype communications software could give cybercriminals a new way to sneak their malicious software onto a victim’s PC. The flaw, which was reported Thursday by security researcher Aviv Raff, has to do with the way that Skype makes use of a Windows Internet Explorer component to render HTML. Because Skype does not apply strict security controls to the software, an attacker could run scripting code on the victim’s system in a dangerous fashion and ultimately install malicious software. IDG News Service, 01/18/08.

Aviv Raff: Skype cross-zone scripting vulnerability

**********

Group points to VoIP flaw in DSL home gateway

A flaw in a DSL home gateway could lead broadband users to divulge personal information over the phone to someone they erroneously believe is calling from their bank, according to a group of self-styled ethical hackers. IDG News Service, 01/21/08.

**********

Eight new patches from Debian:

xine-lib (buffer overflow, code execution)

libvorbis (multiple flaws)

horde3 (bad input sanitisation)

FLAC (multiple flaws)

Tomcat 5.5 (multiple flaws)

Mantis (multiple flaws)

xorg-server (multiple flaws)

apt-listchanges (programming error, shell commands)

**********

Four new fixes from Gentoo:

X.Org X server (multiple flaws)

libcdio (code execution)

Adobe Flash Player (multiple flaws)

Xfce (multiple flaws)

**********

Two new updates from Ubuntu:

apt-listchanges (programming error, shell commands)

X.Org X server (multiple flaws)

**********

Two new patches from Mandriva:

MySQL 5.0.x (multiple flaws)

Apache (multiple flaws)

**********

Two new fixes from rPath:

kernel (file system corruption)

MySQL (privilege escalation)

**********

Today’s malware news:

FBI warns of rise in phone-based ‘vishing’ attacks

With consumers finally getting wise to phishing attacks, scammers are hitting the phones. The U.S. Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) warned Thursday that so-called “vishing” attacks are on the rise. These are scams where criminals send an e-mail or text message to a victim, saying there has been a security problem and the victim needs to call his or her bank to reactivate a credit or debit card. IDG News Service, 01/18/08.

**********

From the interesting reading department:

Hollywood’s ‘Untraceable’: Fact or fiction?

Former FBI Special Agent Ernest E.J. Hilbert II breaks down how the premise of “Untraceable” is not so far-fetched. Network World, 01/18/08.

Red Hat and Firefox more buggy than Microsoft

Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year. TechWorld, 01/17/08.

CIA says hackers pulled plug on power grid

Criminals have been able to hack into computer systems via the Internet and cut power to several cities, a U.S. Central Intelligence Agency analyst said this week. IDG News Service, 01/19/08.

230 retailers affected by data breach after tape lost

A backup tape containing credit-card information from hundreds of U.S. retailers is missing, forcing the company responsible for the data to warn customers that they may become the targets of data fraud. IDG News Service, 01/18/08.