* Patches from Gentoo, Mandriva, Debian * Beware 'SMiShing' attacks * Study: Many believe data thefts can't be prevented, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
F-Secure warns of PayPal man-in-the-middle attack
According to the F-Secure blog, “Somebody set up a PayPal phishing site which apparently is designed to perform a man-in-the-middle attack on your password. It displays a genuine-looking login box, and guess what? You have to type in a valid PayPal user name and password – so it’s probably doing a shadow login to the real PayPal site behind the scenes.”
**********
New updates for Gentoo:
X.org (local privilege escalation)
**********
New patches from Mandriva:
**********
New fixes from Debian:
streamripper (buffer overflow, code execution)
Mozilla Thunderbird (multiple flaws)
Mozilla Firefox (multiple flaws)
libmusicbrainz 2.0 and 2.1 (multiple flaws)
**********
Today’s roundup of virus alerts:
McAfee warns of ‘SMiShing’ attacks
Cell phone users should watch out for text messages containing a Web site link which, when visited, could download a Trojan horse, security experts have warned. IDG News Service, 08/28/06.
Troj/Zlob-CN — A Trojan that registers itself as a COM and Browser Helper Object. It drops “msvol.tlb” and a couple of other files in the Windows System folder and can modify Internet Explorer settings. (Sophos)
Troj/DNSBust-N — A backdoor Trojan that installs itself as “fcfno.exe” in the Windows System folder. It can communicate with remote servers via HTTP. (Sophos)
W32/Rbot-EWD — An IRC backdoor Trojan that spreads through network shares by exploiting known Windows flaws. It drops “msdn-nt.exe” in the Windows System directory. (Sophos)
Troj/Borobot-AB — Another IRC backdoor Trojan that adds the ability to terminate security-related processes running on the infected host. It drops “smss.exe” in the Windows System folder. (Sophos)
W32/Vanebot-A — A backdoor Trojan that allows access to the infected host through IRC. It spreads through network shares by exploiting known Windows flaws and installs “javanet.exe” in the System folder. A fake error message is displayed claiming a Linux emulator is needed to run an application. (Sophos)
Troj/Cosiam-K and L — A Windows Trojan with the ability to access remote sites via HTTP. It is initially installed as “TheMatrixHasYou.exe” in the Windows System folder. (Sophos)
Troj/Zapchas-BX — A backdoor worm that is actually a modified version of the mIRC client. It drops a number of files in the Windows System folder, including “svchost.exe”. (Sophos)
W32/Stration-B and D — A Trojan that spreads through e-mail, with targeted addresses harvested from the Windows Address Book. The infected message is titled “Mail transaction failed. Partial message is available” and comes with a double-extension attachment with multiple spaces between the two extensions. It drops “svchost32.exe” in the Windows folder. (Sophos)
Troj/Keylog-HD — A keylogging Trojan that shows a slideshow entitled “Victoria Stasova”. In the background, “svchst.exe” is being installed in the Windows directory. (Sophos)
Troj/Small-COA — A downloader Trojan that is installed as “comine.exe” in the Windows System folder. (Sophos)
**********
From the interesting reading department:
Study: Many believe data thefts can’t be prevented
Fresh on the heels of a string of highly publicized, corporate data breaches, 63% of respondents to a new data security study said they don’t believe they can prevent such breaches. Computerworld, 08/29/06.
Hackers still important, Red Hat exec says
Volunteer hackers still play an important role in open source software development despite the many companies that pay developers to work on open source products, according to Michael Tiemann, Red Hat’s vice president of open source affairs. IDG News Service, 08/29/06.
AOL 9.0 is accused of ‘badware behavior’
AOL’s free Internet client software has earned the company a slap on the wrist from StopBadware.org, a consortium set up to combat malicious software. In a report set to be released Monday, the group advises users to steer clear of the software because of its “badware behavior.” IDG News Service, 08/28/06.
Oakley device targets insider threats
Oakley Networks next week is expected to introduce an appliance that lets customers scan content to detect disclosure of sensitive information. Network World, 08/28/06.




