Windows stalked by rogue packets?

Opinion
Feb 28, 20084 mins

* Patches from Gentoo, Mandriva, Debian, others * Virus Tricks of the Old School * 'Out of office' messages turned into spam relays, and other interesting reading

Microsoft’s security team is looking into claims that a flaw in Windows XP and Vista could be exploited through the use of “rogue” packets and that any ‘Net connected PC could be affected. Sounds scary, but I am sure it’s just another day in the Redmond Patch Department. One thing that does scare me, given my “Out of office” message is on this week, is a story about how spammers are using such auto-reply messages as means to relay Spam. Hopefully, I am not inadvertently spamming people while on vacation!

Rogue packets stalk Windows Vista, XP

Just in time for spring, Microsoft has been busy tending to a new swarm of bugs, including a critical hole in Windows Vista and XP that could expose you to an early-season bite without your doing anything other than being online. PC World, 02/26/08.

**********

Four new patches from Gentoo:

xine-lib (buffer overflow, code execution)

Asterisk (multiple flaws)

Python (integer overflow, code execution)

ClamAV (multiple flaws)

**********

Five new fixes from Mandriva:

PCRE (buffer overflow, code execution)

cacti (multiple flaws)

CUPS (denial of service)

CUPS 1.1.23 and earlier (multiple flaws)

nss_ldap (race condition, information disclosure)

**********

Five new updates from Debian:

Ghostscript (buffer overflow, code execution)

koffice (multiple flaws)

Diatheke (shell command execution)

turba2 (authentication bypass)

iceape (multiple flaws)

**********

Today’s malware news:

Virus Tricks of the Old School

Hot on the heels of Trojan.Mebroot, which overwrote the MBR, we have discovered a new worm that is reviving another old school trick in order to hide itself. At first glance it appears to be a regular worm, but there is more going on here than meets the eye. Symantec Security Response blog, 02/26/06.

Orkut Scraps Propagating Malicious Code

This isn’t the first worm on Orkut, and the worm works in a similar manner to its predecessors by using “scraps” – messages considered part of a “scrapbook”. A user receives a scrap from an acquaintance containing a pornographic image that is designed to look like a Flash movie. If the user clicks on the image file, in an attempt to play the “movie”, they are directed to a malicious Web site. Symantec Security Response blog, 02/26/06.

**********

From the interesting reading department:

‘Out of office’ messages turned into spam relays

Spammers have found a new trick that gets around many current antispam filters: abusing the “out of the office” auto-respond feature found in legitimate Webmail services. TechWorld, 02/26/08.

Wireless security foiled by new exploits

Watch out for scary new hacker tools like KARMA, plus exploits in Bluetooth and 802.11n, says Joshua Wright in this recent Network World chat. Network World, 02/26/08.

‘Cold Boot’ encryption hack unlikely, says Microsoft

Users can keep thieves from stealing encrypted data by changing some settings in Windows, a Microsoft product manager said as he downplayed the threat posed by new research that shows how attackers can inspect a “ghost” of computer memory. Computerworld, 02/28/08.

Finjan uncovers database storing more than 8,700 stolen FTP credentials

A fresh discovery by security vendor Finjan Inc. provides yet another example of how easy it is becoming for almost anyone to find the tools needed to break into, infect or steal data from corporate Web sites. Computerworld, 02/27/08.

Healthcare organizations feeling cyberattacks growing

Healthcare organizations feel under increasing attack from the Internet, while security incidents involving insiders and disappearing laptops with sensitive data are piling up. On top of that, there’s now the prospect of a surprise audit from the federal government agency in charge of overseeing the HIPAA security and privacy rules. NetworkWorld.com, 02/27/08.

Security skills of IT workforce lacking, survey finds

CompTIA’s most recent survey reveals wide gap between IT security skills wanted and those workers bring to the job. Network World, 02/27/08.

Phishing attack targets victims of U.K. gov’t data loss

A phishing attack that targets victims of HM Revenue and Customs data scandal, with a fake offer of a tax refund, has been discovered by a security software firm. Computerworld, 02/22/08.

Tenet Healthcare warns 37,000 patients of data compromise

Dallas-based Tenet Healthcare Corp. last week sent out notices to about 37,000 patients informing them about the potential compromise of their personal and financial data. Computerworld, 02/22/08.

Windows Vista SP1 breaks some third-party apps

This week Microsoft gave Windows Vista haters more to fuel their dislike. Tuesday Microsoft pulled KB937287, an update meant to prepare Vista PCs for Service Pack 1, after a flood of complaints to newsgroups that the update made PCs constantly reboot or that they wouldn’t reboot at all.

List of “unreliable” apps for Vista SP1

Microsoft fixes massive site, service log-in glitch

Microsoft Corp. said on Tuesday evening it had fixed the problem that had kept some users from logging on to many, if not most, of its online services throughout much of the day. Computerworld, 02/27/08.

PayPal: Steer clear of Apple’s Safari

If you’re using Apple’s Safari browser, PayPal has some advice for you: Drop it, at least if you want to avoid online fraud. IDG News Service, 02/28/08.