New Mac updates available from Apple

Opinion
Aug 3, 20063 mins

* Patches from Intel, Apple, McAfee * Beware Internet banking Trojan that looks to steal user login/account information * Black Hat: NAC solutions vulnerable to attack, and other interesting reading

Today’s bug patch and security alerts:

New Mac updates available from Apple

A new Mac OS X update is available from Apple to fix flaws in AFP Server, Bluetooth, Bom, DHCP, dyld, fetchmail, gunzip, Image RAW, ImageIO, LaunchServices, OpenSSH, telnet, WebKit, Attackers could exploit these to bypass access restrictions and potentially run malicious code on an affected system.

Related US-CERT advisory

**********

McAfee to issue patch for vulnerability

McAfee Wednesday will issue a patch for a vulnerability affecting its SecurityCenter application, a security software management tool. IDG News Service, 08/01/06.

Related:

eEye advisory

McAfee version verification tool

**********

Microsoft plays down bug panic

Windows exploit code recently released into the wild is causing confusion in the security world, as it seems to overlap with a critical bug Microsoft patched last month. TechWorld, 08/02/06.

**********

Intel issues patches for wireless vulnerabilities

Intel has issued patches for three vulnerabilities for its wireless hardware and software. Two problems affect certain versions of its Pro/Wireless Network Connection Hardware, part of its Centrino mobile platform, Intel said. The vulnerabilities lie in drivers from Microsoft, Intel said. IDG News Service, 08/02/06.

Intel driver downloads

**********

Today’s roundup of virus alerts:

Prototype worm targets Windows PowerShell

Microsoft has not released its PowerShell scripting technology in commercial products yet, but a group of hackers has already written a prototype virus for it. According to security company McAfee, MSH/Cibyz!p2p is a proof-of-concept worm written in Windows PowerShell script that attempts to spread via the peer-to-peer application KaZaa by dropping a copy of itself in its shared folders. IDG News Service, 08/02/06.

W32/Alcra-E — A Trojan that spreads through peer-to-peer networks. It displays a fake Windows Media Player error and copies itself to MsMoviesMsMovies.exe. It can be used to download and install additional malicious code. (Sophos)

Troj/Banker-DAG — An Internet banking Trojan that looks to steal user login/account information. It drops “Expert_Corp.exe” in the Windows folder. (Sophos)

Troj/Zapchas-BX — A Trojan with code based on the mIRC client. It drops a number of files on the target host, including “svchost.exe” in the Windows System directory. It allows backdoor access through an IRC channel. (Sophos)

Troj/Adclick-CT — A virus that tries to trick the user into buying Spyware removal tools. It is installed as “pmmon.exe” in the Current Folder. (Sophos)

Troj/Stinx-X — A backdoor Trojan that allows access to the infected host via pre-configured IRC channel. It is installed as “smss32bk.exe” in the Windows System folder. (Sophos)

Troj/Countof-B — A Trojan that collects information about the infected host and sends it to a remote site through an HTTP form submission. (Sophos)

Troj/Zlob-QC — A virus that changes Internet Explorer’s settings. It drops both “isaddon.dll” and “isamini.exe” in the current folder. (Sophos)

**********

From the interesting reading department:

Black Hat: NAC solutions vulnerable to attack

Network access control technology has been promoted as the savior of beleaguered enterprise networks, but enterprise IT managers who are hanging their hat on client health screening should think again, according to security expert Ofir Arkin of Insightix. InfoWorld, 08/02/06.

Black Hat: MacBook hit with wireless hack

Security researchers David Maynor and Jon Ellch performed a digital drive-by Wednesday at the Black Hat USA conference. Their target: an Apple MacBook. IDG News Service, 08/02/06