New Trojans stealing data

Opinion
Mar 22, 20072 mins

* New QuickTime exploit hits MySpace, steals passwords * Patches from Ubuntu, Debian, Mandriva, others * How to make a honeypot network security system pay off, and other interesting reading

Today’s virus and malware news:

New QuickTime exploit hits MySpace, steals passwords

A Trojan horse exploiting a flaw in Apple’s QuickTime that was patched two weeks ago is infecting MySpace.com users’ computers, collecting confidential information, including passwords, several security companies said Monday. Computerworld, 03/19/07.

Gozi Trojan leads to Russian data hoard

A Russian Trojan program named Gozi that remained largely undetected for more than 50 days earlier this year has stolen more than 10,000 records containing confidential information belonging to about 5,200 home users. Computerworld, 03/20/07.

**********

Today’s bug patches and security alerts:

Two new update from Ubuntu:

Inkscape (format string, code execution)

libwpd (integer overflow, code execution)

**********

Three new fixes from Debian:

openafs (remote access, privilege escalation)

openoffice.org (multiple flaws)

lookup-el (symlink flaw, code execution)

**********

Two updates from Mandriva:

openafs (remote access, privilege escalation)

nas (denial of service)

**********

Seven new patches from Gentoo:

WordPress (multiple flaws)

Mozilla Network Security Service (buffer overflows, code execution)

PHP (multiple flaws)

LSAT (non-secure temp files, code execution)

LTSP (authentication bypass)

Mozilla Thunderbird (multiple flaws)

ulogd (buffer overflow, code execution)

**********

From the interesting reading department:

How to make a honeypot network security system pay off

Honeypots have largely been relegated to use by academia and antivirus vendors because most enterprise IT teams figure they’re too expensive to run and could land their companies in legal trouble. But honeypots aren’t as scary as all that, according to an expert on the topic who spoke at the InfoSec World Conference & Expo in Orlando Tuesday. Network World, 03/21/07.

Study: Businesses don’t understand Web application security threats

Businesses may unwittingly leave themselves open to application-layer attacks because they don’t understand their networks lack defenses to deflect them, according to a study by Forrester Research. NetworkWorld.com, 03/20/07.

InfoSec: Security professionals share tips

At the InfoSec Conference here this week, security professionals shared tips for tackling some of the biggest issues they face, such as minimizing risks associated with outsourcing, selecting a network-access control mechanism and deploying identity management technologies. Network World, 03/21/07.

Web site hit by tsunami of blog spam

A news Web site has been hit with a massive “trackback spam” attack, which saw 27,000 adult Web links posted to its site in a single day. TechWorld, 03/20/07.