VMWare patches critical bug

Opinion
Feb 25, 20083 mins

* Patches from VMware,Opera, Ubuntu, others * You're Under Investigation! * Goolag makes Google Hacking a snap, and other interesting reading

In the movie “Untraceable,” the FBI cybercrime team uses virtual machines to protect its real systems from the malware they’re investigating. But in real life, the virutal machine is not always foolproof, as witnessed by this week’s patches from VMWare that fix a bug which could allow attackers to “zap” the Windows operating system the virtual machine is running on top of. Also, Opera has managed to patch a trio of bugs while at the same time bashing Mozilla. Sounds like presidential politics!

Critical VMware bug lets attackers zap ‘real’ Windows

A critical vulnerability in VMware’s virtualization software for Windows lets attackers escape the “guest” operating system and modify or add files to the underlying “host” OS, the company has acknowledged. Computerworld, 02/24/08.

VMWare advisory

**********

Opera patches bugs

Opera Software patched a trio of bugs in its flagship browser Tuesday, including one that a company manager used last week to slam rival Mozilla. The update, dubbed Opera 9.26, plugs three security vulnerabilities. The most serious is rated “highly severe” by the Oslo-based developer and could be used by attackers to dupe the browser into treating image-file comments as script.

Download the latest version of Opera

**********

Three new updates from Ubuntu:

PCRE (buffer overflow, denial of service)

libcdio (denial of service, code execution)

Qt (may accept invalid SSL certificate)

**********

Six new patches from Denbian:

alsa-driver (memory leak)

Kernel 2.6.8 (multiple flaws)

Kernel 2.4.27 (multiple flaws)

WordPress (multiple flaws)

dspam (information disclosure)

splitvt (privilege escalation)

**********

Two new fixes from Mandriva:

Firefox (multiple flaws)

xine-lib (buffer overflow, code execution)

**********

Today’s malware news:

You’re Under Investigation!

Earlier Thursday afternoon in Italy hundreds of thousands of people received an email from a “friend” stating (approximately) the following: “You’re under investigation! Hide everything and be quick!!!” Of course, it is a scam. Symantec Security Response blog, 02/21/08.

**********

From the interesting reading department:

Goolag makes Google Hacking a snap

The hacking group Cult of the Dead Cow has released a tool that should make Google hacking a little easier for novices. IDG News Service, 02/22/08.

Constant patch releases force IT to adopt new processes

The first Sunday after the second Tuesday of every month is a big day for the Arlington County, Va., IT unit’s network operations team. Computerworld, 02/25/08.

McAfee: Virus writers going local

Over the past two years virus writers have increasingly targeted their malicious programs to users in different regions of the globe, creating programs that are specially designed to infect users in countries like Japan, Brazil, China or Germany. IDG News Service, 02/21/08.

Services are tapping people power to spot malware

People-driven security, an approach that pools the judgments of individual participants to identify new threats, is gathering momentum, with uses popping up in everything from antimalware and spam blocking to site filtering. PC World, 02/20/08.

Hard drive encryption has Achilles heel, say researchers

If you think that encrypting your laptop’s hard drive will keep your data safe from prying eyes, you may want to think again, according to researchers at Princeton University. IDG News Service, 02/21/08.

17 arrested in Canadian hacking bust

Quebec provincial police conducted raids on Wednesday, breaking up a hacking ring that police say is responsible for an estimated CDN$45 million ($44.3 million) in damage to computer systems. IDG News Service, 02/22/08.

Hackers ramp up Facebook, MySpace attacks

Hackers are actively exploiting an Internet Explorer plug-in that’s widely used by Facebook and MySpace members with a multi-attack kit, a security company warned Friday. Computerworld, 02/23/08.