Potential weakness Cisco ACS default configuration

Opinion
Jun 26, 20064 mins

* Patches from Trustix, Debian, Gentoo * Beware latest Rtob, Mytob, Sdbot and Tilebot variants * Symantec to exit security appliance business, and other interesting reading

As part of our new Security Buyer’s Guide launch, we’re hosting “Security Week” on NetworkWorld.com featuring the most popular Hot Seat videos dealing with, you guessed it, security. Check out our home page each day for the featured show or get a sneak peek at the

Today’s bug patches and security alerts:

Potential weakness Cisco ACS default configuration

Cisco is looking into a reported security weakness in the default configuration of its Access Control System. A security researcher believes a hole in ACS’s session management system could be exploited by attackers to gain administrative privileges on an affected system. Cisco has not released an update yet.

Original advisory

********

Trustix releases another “multi”

This latest Trustix update fixes flaws in the kernel and NetPBM. The most serious of the vulnerabilities could be exploited in a denial-of-service attack.

********

Debian releases new courier update

According to a Debian advisory, “A bug has been discovered in the Courier Mail Server that can result in a number of processes to consume arbitrary amounts of CPU power.”

********

New updates from Gentoo:

wv2 (integer overflow, code execution)

KDM (symlink attack)

aRts (privilege escalation)

********

Today’s roundup of virus alerts:

W32/Rbot-EMH — A new Rbot variant that uses a randomly named file to infect the target host. It spreads through network shares by exploiting known Windows flaws and allows backdoor access through IRC. (Sophos)

W32/Banker-CTA — A virus that can monitor Internet activity, report back to a remote host and terminate security applications running on the infected system. (Sophos)

W32/Mytob-IF — Another Mytob e-mail worm that spreads through message looking to be an account suspension warning. The virus installs “lspool.exe” in the Windows System folder and enables backdoor access through IRC. (Sophos)

W32/Mytob-HX — A second Mytob variant that spreads through e-mail messages that look like an account warning and try to get the recipient to click a link. This variant is installed as “windows.exe” in the System directory. (Sophos)

Troj/Opnis-C — A Trojan that drops three files in the Windows System file: A randomly named DLL and similarly named EXE as well as “vsre446EC7DB.exe”. No word on any permanent damage caused by Opnis-C. (Sophos)

W32/Sdbot-BZD — This Sdbot variant spreads through network shares by exploiting weak passwords. It installs “iop.exe” in the Windows System folder, allows backdoor access through IRC and modifies the Windows HOSTS file to limit access to certain Web sites. (Sophos)

W32/Tilebot-FO — A backdoor IRC worm that spreads through network shares by exploiting known Windows flaws. It drops “netdrvr.exe” in the System directory and can be used for a number of malicious purposes, including routing Internet traffic and stealing system information. (Sophos)

W32/Tilebot-FP — A second Tilebot variant that is very similar to the one mentioned above. This variant drops “remon.sys” in the Windows System folder. (Sophos)

Troj/Ranck-EN — An HTTP proxy server Trojan that can be used to relay spam. It installs itself as Windowsetcservices.exe. (Sophos)

Troj/Mailbot-AJ — A Trojan that can turn the infected host into a proxy server or spambot. It drops “helpermnew6win.exe” in the Windows System folder. (Sophos)

Troj/Banker-BZV — A password stealing Trojan targeting specific Brazilian banking sites. It is installed as “msnmsgr.exe” in the Config folder. (Sophos)

**********

From the interesting reading department:

Symantec to exit security appliance business

Symantec this week laid off staff and said it is shaking up its network and gateway security business, ending the company’s experiment with security hardware appliances. InfoWorld, 06/23/06.

Security vendor warns of porn-clicking browser

A free Web browser that bills itself as a tool for privacy protection is, in fact, a click-fraud engine for pornographic Web sites, security vendor Panda Software warned Friday. IDG News Service, 06/23/06.

TorrentSpy names hacker and details attack

TorrentSpy named the hacker who it claims broke into its computer systems on behalf of the Motion Picture Association of America, as part of a legal request that would force the MPAA to turn over documents stolen from the Internet file-searching company. IDG News Service, 06/23/06.