Apple patches a … keyboard flaw?

Opinion
Feb 21, 20083 mins

* Patches from Apple, Debian, Mandriva * Keylogging at the Habbo Hotel * DoS attack prevents access to WordPress.com, and other interesting reading

After a busy week-plus on the security front, things have slowed a bit. Is it a calm before the storm or a normal lull? Of course, there is some security news: a Facebook ImageUploader exploit in the wild, and Apple has released a new patch for its laptop keyboard firmware. Plus, a keylogging Trojan is targeting users of the Habbo social networking site.

Exploitation of the Facebook ImageUploader Vulnerability

As seems to be the trend lately, anytime a vulnerability is disclosed in an ActiveX control, it is only a short time before it is bundled into the Web attack toolkits. For this Facebook vulnerability, it was less than a day from the vulnerability being disclosed on February 12th to it first showing up on our honeypots on February 13th. Symantec Security Response blog, 02/20/08.

**********

Apple issues laptop keyboard patch

The MacBook / MacBook Pro Keyboard Firmware Update 1.0 addresses an issue where the first key press may be ignored if the computer has been sitting idle. It also addresses some other issues. MacWorld, 02/20/08.

**********

Two new updates from Debian:

pcre3 (buffer overflow, code execution)

libimager-perl (buffer overflow, code execution)

**********

One new fix from Mandriva:

Mozilla Thunderbird (multiple flaws)

**********

Today’s malware news:

Keylogging at the Habbo Hotel

Social networking Web sites have become a popular pastime and are a means of staying in touch with friends for many people. Yesterday, Websense reported on a Trojan keylogger aimed at users of Habbo, a popular social networking site for teenagers. Symantec Security Response blog, 02/20/08.

Phish ‘n’ Exploit

Symantec has recently observed millions of user profiles of a certain social networking site carrying malicious links. Symantec Security Response blog, 02/20/08.

**********

From the interesting reading department:

DoS attack prevents access to WordPress.com blogs

The WordPress.com blog-hosting service suffered a denial-of-service (DoS) attack that began Saturday and was still preventing users from logging in or posting to their blogs on Tuesday. IDG News Service, 02/19/08.

Arbor’s Security to the Core blog: DDoS Events of Note: WordPress, Gambling Sites

Russian hosting network runs a protection racket

The Russian Business Network, a notorious hacker and malware hosting network, runs a protection racket that extorts as much as $2,000 a month in fees for “protective Web services” from borderline sites, a researcher alleged Tuesday. Computerworld, 02/19/08.

Kernel space: the vmsplice() exploit

A recent Linux security hole allows local users to seize the power of root. Here’s how three separate bugs came together to create one big vulnerability. LinuxWorld.com, 02/19/08.

Microsoft scrambles to quash ‘friendly’ worm story

Microsoft is moving to counter some scathing comments regarding a security paper authored by researchers at its Cambridge, England, facility. IDG News Service, 02/19/08.

NHS laptop with 5,123 patient records stolen

An NHS laptop holding information on 5,123 patients has been stolen from a hospital in Dudley. The theft occurred on Jan. 8 in the outpatient department at Russells Hall Hospital, which is part of the Dudley Group of Hospitals NHS Trust. Computerworld, 02/19/08.

Code Reuse Good, SQL-Injection Reuse Bad

One of the most common practices in software development is code reuse. Developers use the strategy to save time and money by reducing redundant tasks and the theory is put into practice in several popular content management systems available to users who want to create their own Web presence. But, vulnerabilities can also be reused. Symantec Security Response blog, 02/19/08.

Laptop wipes self to beat thieves

A U.K. company has come up with a nifty laptop-protection system that can automatically wipe hard disk data on machines taken from authorized locations. TechWorld, 02/19/08.