Malware popping up on popular sites

Opinion
Jan 31, 20085 mins

* Patches from Mozilla, Debian, Gentoo, others * New Word attacks pose as news about Tibet * Snopes.com stops serving adware, and other interesting reading

Just when you thought it was safe to wade into the Internet waters, more scary news comes out to chase you back to shore. Expedia.com and Rhapsody.com have been found to be serving up malicious code through banner ads. Neither company was aware of the issue until security experts sent up the red flag. We’ve also got a story of coders rigging Google to deliver malicious code as well.

Today’s malware news:

PHP IRC Bot

Typically, most of the exploits we see install a web-based backdoor such as the C99 shell for the attacker to use. Every once in a while we run into something more sinister. F-Secure, 01/30/08.

New Word attacks pose as news about Tibet

New attacks using rigged Microsoft Word documents have been launched, a security company said today as it warned users to be leery of mail touting news about Tibet. Computerworld, 01/29/08.

Expedia.com, Rhapsody.com serving up malicious code

Legitimate Web sites are increasingly becoming unwitting sources of malware. Security experts report that Expedia.com and Rhapsody.com today have been serving up banner ads that attempt to get visitors to download fake antispyware, while embassy Web sites in Ukraine and Russia have also been spewing out attack code this week. NetworkWorld.com, 1/30/08.

Hackers rig Google to deliver malware

The latest malware trend should prompt you to think twice about the links you click next time you search. PC World, 01/28/08.

**********

Security alerts for today:

Cisco warns of flaw in Wireless Control SystemCisco advisory, “Apache Tomcat is the servlet container for JavaServlet and JavaServer Pages Web within the Cisco Wireless Control System (WCS). A vulnerability exists in the mod_jk.so URI handler within Apache Tomcat which, if exploited, may result in a remote code execution attack.”

According to the

**********

New attack proves critical Windows bug ‘highly exploitable’

Security researchers yesterday said they’d discredited Microsoft’s claim that the year’s first critical Windows vulnerability would be “difficult and unlikely” to be exploited by attackers. On Tuesday, Immunity Inc. updated a working exploit for the TCP/IP flaw spelled out Jan. 8 in Microsoft’s MS08-001 security bulletin, and posted a Flash demonstration of the attack on its Web site. The exploit, which was released to customers of its CANVAS penetration testing software — but is not available to the public — was a revised version of code first issued two weeks ago. Computerworld, 01/30/08.

**********

Mozilla ups Firefox bug threat, slates fix for Feb. 5

Mozilla Corp. bumped up the threat ranking for an unpatched Firefox bug to “high” yesterday, but promised a fix is coming in Version 2.0.0.12, now slated for release on Feb. 5. Computerworld, 01/30/08.

Firefox known vulnerabilities page

**********

Three new updates from Debian:

mysql-dfsg-5.0 (multiple flaws)

yarssr (input sanitization, shell command execution)

pulseaudio (privilege escalation)

**********

11 new patches from Gentoo:

libxml2 (denial of service)

GOffice (multiple flaws)

Kazehakase (multiple flaws)

Netkit FTP Server (denial of service)

MaraDNS (denial of service)

PostgreSQL (multiple flaws)

Blam (user-assisted code execution)

ngIRCd (denial of service)

xine-lib (heap overflow, code execution)

CherryPy (directory traversal, file access)

TikiWiki (multiple flaws)

**********

From the interesting reading department:

Snopes.com stops serving adware

A popular urban legend debunking site has stopped serving up adware downloads after the practice was criticized by security experts and users, according to one researcher. Computerworld, 01/29/08.

Vista’s growing popularity draws hackers’ malice

With more people finally switching to Windows Vista, the operating system is fast becoming a target for security researchers and–surprise!–hackers. PC World, 01/29/08.

New data security breaches come in fours

What do Fallon Community Health Plan, Pennsylvania State University, OmniAmerican Bank and T. Rowe Price Group Inc. all have in common? Each of them recently joined the seemingly never-ending parade of organizations that have disclosed security breaches resulting in the potential compromise of personal data. Computerworld, 01/29/08.

When it comes to security, chaos may be your friend

Viruses and other malware are getting better at evading antimalware systems despite the sophisticated behavioral-analysis systems that are used to detect them. This week a rogue trader in France was able to hide a growing loss until it reached $7 billion and was impossible to hide. What do these two events have in common? Both exploit the predictability of defenses to evade detection. Network World, 01/29/08.

German police Skype-hacking leaked

German police have hired a company to create Trojans capable of capturing traffic from Skype and SSL, leaked documents appear to show. TechWorld, 01/28/08.

Spammers cloak scams by redirecting through Google services

Spammers are using thousands of Google accounts to camouflage their scams from antispam filters, a security researcher said Friday. He dubbed the practice “Spam 2.0.” Computerworld, 01/25/08.

It’s Not a Wonderful Second Life

It’s not very far into 2008 and sadly we are already seeing some of our predictions on the security trends of 2008 come true. I blogged earlier that our security analyses expected to see old style cybercrimes turn up in virtual worlds. While it’s not clear if any crime occurred, they did experience an old fashion run on banks. Unfortunately, unlike in the movie “It’s a Wonderful Life” there was no George Bailey to stop the bank run. Symantec Security Response blog, 01/28/08.