F-Secure warns of PayPal man-in-the-middle attack

Opinion
Aug 31, 20064 mins

* Patches from Gentoo, Mandriva, Debian * Beware 'SMiShing' attacks * Study: Many believe data thefts can't be prevented, and other interesting reading

Today’s bug patches and security alerts:

F-Secure warns of PayPal man-in-the-middle attack

According to the F-Secure blog, “Somebody set up a PayPal phishing site which apparently is designed to perform a man-in-the-middle attack on your password. It displays a genuine-looking login box, and guess what? You have to type in a valid PayPal user name and password – so it’s probably doing a shadow login to the real PayPal site behind the scenes.”

**********

New updates for Gentoo:

X.org (local privilege escalation)

Wireshark (multiple flaws)

Motor (code execution)

PHP (code execution)

**********

New patches from Mandriva:

ImageMagick (multiple flaws)

lesstif (local root flaw)

binutils (multiple flaws)

**********

New fixes from Debian:

kdebase (file disclosure)

ruby 1.8 (multiple flaws)

streamripper (buffer overflow, code execution)

Mozilla Thunderbird (multiple flaws)

Mozilla (multiple flaws)

Mozilla Firefox (multiple flaws)

libmusicbrainz 2.0 and 2.1 (multiple flaws)

gtetrinet (multiple flaws)

**********

Today’s roundup of virus alerts:

McAfee warns of ‘SMiShing’ attacks

Cell phone users should watch out for text messages containing a Web site link which, when visited, could download a Trojan horse, security experts have warned. IDG News Service, 08/28/06.

Troj/Zlob-CN — A Trojan that registers itself as a COM and Browser Helper Object. It drops “msvol.tlb” and a couple of other files in the Windows System folder and can modify Internet Explorer settings. (Sophos)

Troj/DNSBust-N — A backdoor Trojan that installs itself as “fcfno.exe” in the Windows System folder. It can communicate with remote servers via HTTP. (Sophos)

W32/Rbot-EWD — An IRC backdoor Trojan that spreads through network shares by exploiting known Windows flaws. It drops “msdn-nt.exe” in the Windows System directory. (Sophos)

Troj/Borobot-AB — Another IRC backdoor Trojan that adds the ability to terminate security-related processes running on the infected host. It drops “smss.exe” in the Windows System folder. (Sophos)

W32/Vanebot-A — A backdoor Trojan that allows access to the infected host through IRC. It spreads through network shares by exploiting known Windows flaws and installs “javanet.exe” in the System folder. A fake error message is displayed claiming a Linux emulator is needed to run an application. (Sophos)

Troj/Cosiam-K and L — A Windows Trojan with the ability to access remote sites via HTTP. It is initially installed as “TheMatrixHasYou.exe” in the Windows System folder. (Sophos)

Troj/Zapchas-BX — A backdoor worm that is actually a modified version of the mIRC client. It drops a number of files in the Windows System folder, including “svchost.exe”. (Sophos)

W32/Stration-B and D — A Trojan that spreads through e-mail, with targeted addresses harvested from the Windows Address Book. The infected message is titled “Mail transaction failed. Partial message is available” and comes with a double-extension attachment with multiple spaces between the two extensions. It drops “svchost32.exe” in the Windows folder. (Sophos)

Troj/Keylog-HD — A keylogging Trojan that shows a slideshow entitled “Victoria Stasova”. In the background, “svchst.exe” is being installed in the Windows directory. (Sophos)

Troj/Small-COA — A downloader Trojan that is installed as “comine.exe” in the Windows System folder. (Sophos)

**********

From the interesting reading department:

Study: Many believe data thefts can’t be prevented

Fresh on the heels of a string of highly publicized, corporate data breaches, 63% of respondents to a new data security study said they don’t believe they can prevent such breaches. Computerworld, 08/29/06.

Hackers still important, Red Hat exec says

Volunteer hackers still play an important role in open source software development despite the many companies that pay developers to work on open source products, according to Michael Tiemann, Red Hat’s vice president of open source affairs. IDG News Service, 08/29/06.

AOL 9.0 is accused of ‘badware behavior’

AOL’s free Internet client software has earned the company a slap on the wrist from StopBadware.org, a consortium set up to combat malicious software. In a report set to be released Monday, the group advises users to steer clear of the software because of its “badware behavior.” IDG News Service, 08/28/06.

Oakley device targets insider threats

Oakley Networks next week is expected to introduce an appliance that lets customers scan content to detect disclosure of sensitive information. Network World, 08/28/06.