Bug found in classic ICQ client

Opinion
Sep 11, 20065 mins

* Patches from Ubuntu, rPath, FreeBSD, Debian, OpenPKG and Mandriva * Beware new Rbot variant * Two new security videos, and other interesting reading

A lot has happened in the last five years to change the way IT security is handled at organizations big and small. The question is, What has affected your security processes more – the terrorist attacks of 9/11 or the corporate scandals and resulting compliance laws?

Drop me a line and I’ll publish the results next week.

Today’s bug patches and security alerts:

Nasty bug found in ‘classic’ ICQ client

AOL is advising users of its ICQ instant message service to update to the latest version of the IM software following the discovery of a bug in an older version of the product. Security researchers at Core Security Technologies Thursday reported that they had discovered the flaw in ICQ Pro 2003b, a version of the ICQ client that AOL still offers for download, billing it as a “veteran version” of the product for users who prefer the earlier look-and-feel. IDG News Service, 09/07/06.

**********

September looks quiet with three Microsoft patches

After handling 19 sets of patches in July and August, system administrators will catch a bit of a break next week when Microsoft is expected to release just three security updates for its Windows and Office products. IDG News Service, 09/07/06.

**********

New updates for Ubuntu:

libxfont (integer overflow, code execution)

PHP (multiple flaws)

bind9 (multiple flaws)

**********

New updates from rPath:

OpenSSL (unauthorized access)

Mailman (denial of service)

bind (multiple flaws)

**********

New updates for FreeBSD:

Bind (multiple flaws)

OpenSSL (unauthorized access)

**********

New patches for Debian:

Bind9 (multiple flaws)

Ethereal (multiple flaws)

**********

New fixes for OpenPKG:

Bind (multiple flaws)

OpenSSL (unauthorized access)

**********

New updates from Mandriva:

Bind (multiple flaws)

OpenSSL (unauthorized access)

PHP (multiple flaws)

*********

Today’s roundup of virus alerts:

W32/Rbot-FLL — This Rbot variant spreads through network shares by exploiting weak passwords and known Windows flaws. It drops “wkssvr.exe” in the System folder and allows backdoor access through IRC. (Sophos)

Troj/Torpig-BH — A Trojan used to steal information from the infected host and sends it to a remote site via HTTP. It drops a number of files on a Common Files sub-folder, including “bm00001.exe”. (Sophos)

W32/Puce-H — A virus that infects compressed RAR and ZIP files on an infected host. It initially installs “svchost.exe” in the Temp folder. (Sophos)

Troj/Banker-DIX — An Internet banking Trojan that displays fake login pages in an effort to steal user credentials. It is installed as “winupdate.exe” in the Windows folder. (Sophos)

Troj/Clagger-AB — This Trojan Horse is used to download and install additional malicious code. It is installed as “ipf.exe” in the System folder. (Sophos)

W32/Tilebot-GM — A new Tilebot variant that allows backdoor access through IRC. It spreads through network shares by exploiting known Windows buffer overflows. It drops “lsass.exe” in the Windows directory. (Sophos)

Troj/GWGhost-BH — A Trojan that injects itself into running processes and communicates with remote sites via port 8086. It is installed as “wzsml.dll” in the Windows System folder. (Sophos)

Troj/Dowdec-B — A virus that spreads through an e-mail message that looks to be an order confirmation and comes with an attached ZIP file. It drops a number of files on the target host, including “msvoid.dll” in the Windows System directory. (Sophos)

Troj/Haxdoor-DC — A new Haxdoor variant that spreads through an e-mail message that has a title such as “Perfect Job. Your Chance”. It drops “prt47sys.sys” and “sysprint.dll” in the System folder. (Sophos)

Troj/Glupzy-A — A Trojan that runs a telnet server on the infected host and changes the administrator password to “hacked”. It is installed as “Flashy.exe” in the System folder. (Sophos)

W32/Kwbot-L — An IRC backdoor Trojan that can be used to steal passwords, participate in DoS attacks and terminate processes. It drops “mscidaemon.com” in the Windows System folder. (Sophos)

Troj/Crybot-C — A backdoor Trojan that communicates with a remote site via HTTP and can adjust the Windows’ firewall setting to allow greater access. It is registered as a process called “DirectLujp”. (Sophos)

W32/Vanebot-I — An IRC backdoor worm that spreads through MSN Messenger messages and network shares. It drops “msijavaup32.exe” in the System directory. (Sophos)

**********

From the interesting reading department:

Video: A better NAC plan than Cisco?

StillSecure’s Mitchell Ashley says his company offers greater interoperability and broader security. Find out how in this week’s Network World Hot Seat.

Video: What’s your biggest security threat?

Network World Senior Editor Denise Dubie polled attendees of The Security Standard event in Boston about what security issues keep them up at night.

Carnegie Mellon researchers develop ‘Phoolproof’ antiphishing system

A professor and two students at Carnegie Mellon University’s CyLab have developed software designed to protect Web users from phishing sites by getting their mobile devices involved. NetworkWorld.com, 09/08/06.

The new reality for IT security

Security executives from around the country converged in Boston this week to hear how their peers are tackling enterprise security and managing risk. NetworkWorld.com, 09/08/06.

Cisco, Microsoft reveal network access product plans

Cisco and Microsoft this week shared details of their partnership on network access control technologies, which will include interoperable products and “out-of-the-box” capabilities in future product releases. NetworkWorld.com, 09/07/06.

ISS jumps into e-mail security fray

Security vendor Internet Security Systems this week plans to announce its foray into the packed e-mail security market with an appliance that does double duty: blocking spam and viruses while also preventing intrusion. Network World, 09/08/06.

Samsung site hijacked as malware host

The U.S. corporate Web site of Samsung Telecom has been hijacked and used to host and distribute malware, security vendor Websense has revealed. TechWorld, 09/08/06.