* Patches from Ubuntu, Debian, Mandriva, others * From SMTP to HTTP to FTP * Behavior-based malware detection software on the way, and other interesting reading
Is it me or does it seem Patch Tuesday comes quicker every month? Maybe it’s because February is a “short” month. In any case, this is the week Microsoft delivers its monthly patch update. Administrators will be looking at four new updates, all critical. And if you need something to keep yourself busy until Tuesday’s release, we’ve got new patches from Ubuntu, Debian, Mandriva and Gentoo ready to roll.
Microsoft slates four patches for next week
Microsoft Thursday said that it will release four security updates next week to patch every supported version of the company’s Office business suite. All four updates will be labeled “critical,” the company’s highest threat ranking. Computerworld, 03/08/08.
**********
Three new patches from Ubuntu:
Evolution (format string, code execution)
**********
Two new updates from Debian:
lighttpd (information disclosure)
kernel 2.4.27 (multilpe flaws)
**********
Five new fixes from Mandriva:
Evolution (format string, code execution)
Mozilla Thunderbird (multiple flaws)
Mailman (cross-scripting attack, code execution)
**********
Four new patches from Gentoo:
Ghostscript (buffer overflow, code execution)
Evolution (format string, code execution)
**********
Today’s malware news:
Sending EXE attachments in e-mail doesn’t work anymore. Almost every organization is now dropping such risky attachments from their e-mail traffic. So virus writers have made a clear shift away from e-mail attachments to the Web: drive-by-downloads. F-Secure blog, 03/07/08.
**********
From the interesting reading department:
Behavior-based malware detection software on the way
Start-up NovaShield says that in May it will release its first security product for the PC, behavior-based detection software designed to catch, quarantine and eradicate malware not ordinarily detected by signature-based antivirus products. Network World, 03/05/08.
Simple SNMP scans yield network data
System administrators have long been wary of the security implications of Simple Network Management Protocol (SNMP), but a recent experiment by “ethical hacking” group GNUCitizen has shown that many SNMP-enabled devices are left unguarded and may be prone to giving away sensitive information. TechWorld, 03/05/08.
RFID encryption flawed in smart cards, researchers claim
New research showing that smart cards with encrypted RFID chips might not be as secure as previously thought is raising concerns in Boston, where the subway CharlieCards use just such technology. The research raises the specter of thieves with $1,000 worth of equipment cracking smart-card encryption and making counterfeit cards to do everything from swipe fares to gain access to high-security areas. Network World, 03/06/08.
Top cybercrook targets for 2008
A recent Internet Security Outlook Report issued by CA warns that social networks and Web 2.0 are among the top potential targets for online attacks in 2008. The study, based on data compiled by CA’s Global Security Advisor researchers, features Internet security predictions for 2008 and also reports on trends from 2007. CIO, 03/08/08.
Want better security apps? Make vendors accountable, Geekonomics author says
Security software vendors have gotten away with writing defective and insecure code only because the market has allowed them to, according to David Rice, the author of Geekonomics. Computerworld, 03/06/08.
Development model predicts chance of software flaws
Researchers from a German university have developed a model to predict programming errors in applications. IDG News Service, 03/06/08.
29A is a well known underground virus research group. It had many notorious members, such as Benny, VirusBuster, Super, ValleZ who were prominent in the virus-writing circles. This group published a virus magazine in order to spread the know how to create viruses. Up until now they have published seven full versions of the magazine on their Web site. Symantec Security Response blog, 03/06/08.




