* Patches from Ubuntu, Gentoo, Debian * Beware Trojan called 'FormSpy' that cloaks itself as Firefox extension * Crypto malware close to being 'uncrackable'
endif; ?>I am still taking opinions on the question “What’s better, a long or complex password?” I pose this to you after InfoWorld columnist Roger Grimes issued a $100 challenge to Bugtraq mailing list to crack is Windows password hash that’s based on a long password.
The Bugtraq post can be found here.
Grimes’ InfoWorld column on the subject is here.
Send your opinion on the topic to jmeserve@nww.com. I’ll be publishing answers the week of August 7th.
Today’s bug patches and security alerts:
New patches for Ubuntu:
PHP4 (regression error in previous update)
mysql-dfsg-4.1 (format string, denial of service)
**********
New patches for Gentoo:
GIMP (buffer overflow, code execution)
Wireshark / Ethereal (multiple flaws)
**********
New updates for Debian:
Kernel 2.6.8 source (race condition)
GIMP (buffer overflow, code execution)
Net::Server Perl module (format string)
libdumb (buffer overflow, code execution)
**********
Today’s roundup of virus alerts:
Trojan cloaks itself as Firefox extension
Security vendor McAfee has detected a new piece of malicious software that masquerades as part of the Firefox Internet browser. McAfee calls the Trojan horse “FormSpy.” Trojan horses are programs, often attached to spam e-mail, that appear innocuous but are harmful to a computer. IDG News Service, 07/26/06.
W32/Tilebot-GA — A new Tilebot variant that allows backdoor access to the infected host through an IRC channel. It spreads through network shares by exploiting known Windows vulnerabilities, dropping “sysdriver.exe” in the System folder. (Sophos)
W32/Tilebot-GB — A second new Tilebot variant that uses IRC to provide backdoor access to the infected host. This variant is installed as “sqlmanagement.exe” in the Windows folder. (Sophos)
Troj/AdClick-CR — This Trojan allows backdoor access to the host by connecting to a remote server using HTTP. It puts two files on the desktop, “Click to Remove Spyware.lnk” and “Remove Spyware Now!.lnk”. It could be used to download and install additional malware on the host. (Sophos)
Troj/Banker-CZC — A Trojan that targets German Internet banking sites. It monitors Web activity and when a specific site is accessed, Banker-CZC will display a fake login page in an effort to steal user credentials. It is installed as a randomly named EXE. (Sophos)
W32/Yurist-B — A Trojan that attempts to steal e-mail password information from the infected hosts and sends the bounty to a remote site. It is installed as “xflash.exe” in the Windows System directory. (Sophos)
Troj/Bancos-AQR — Another Trojan that looks to steal Internet banking login information by logging keystrokes and sending the data to a remote site. It is installed as “tasklist32.exe” in the Windows System folder. (Sophos)
**********
From the interesting reading department:
Crypto malware close to being ‘uncrackable’
File-encrypting Trojans are becoming so complex that the security companies could soon be powerless to reverse their effects, a new report from Kaspersky Lab has said. TechWorld, 07/25/06.




