* Patches from Gentoo, Debian, rPath, others * Beware the latest batch of Rbot variants * Unisys contractor arrested in VA theft, and other interesting reading
endif; ?>Twisted Pair podcast: Throwing the book at virus authors
Jason Meserve and Keith Shaw discuss the sentence handed down to the Zotob worm authors and wonder if it’s harsh enough?; the As the HP World Turns soap continues; a new mobile phone security spec; and good news for YouTube.
Today’s bug patches and security alerts:
New Firefox fix patches security bugs
Mozilla developers have released an updated version of their Firefox browser that fixes a number of security issues, four of them rated critical. Research firm Secunia rates the flaws as “highly critical,” saying that they can be exploited to “conduct man-in-the-middle, spoofing and cross-site scripting attacks, and potentially compromise a user’s system,” according to an alert. IDG News Service, 09/15/06.
Download the new Firefox update
**********
New patches for Gentoo:
FFmpeg (buffer overflow, code execution)
DokuWiki (arbitrary command execution)
**********
New updates from Debian:
**********
New updates for rPath
xorg-x11 (code execution, root privileges)
Firefox/Thunderbird (multiple flaws)
**********
Today’s roundup of virus alerts:
W32/Rbot-FMX — An Rbot variant that spreads through network shares by exploiting known Windows flaws, installing an IRC backdoor in the process. The worm drops “WinSock32.exe” in the System folder and can be used to terminate processes, act as an Internet proxy and download additional code from remote sites. (Sophos)
W32/Rbot-CCY — Another Rbot variant that exploits known Windows flaws as it spreads through network shares. This variant drops “msnse.exe” in the Windows System folder and allows backdoor access through IRC. (Sophos)
W32/Rbot-FMZ — The third Rbot variant of the day can be used to steal passwords and allow malicious users to access the infected machine via an IRC backdoor. It spreads through network shares by exploiting weak passwords and known Windows flaws and drops “svchosl.exe” in the System folder. (Sophos)
W32/Rbot-FNA — Rbot variants are popular today. This variant spreads through the same means as the previous three and also can spread through instant messaging links. It drops “mshcp.exe” in a sub-folder of the Windows System folder. (Sophos)
Troj/Banker-DLJ — A password stealing Trojan that targets Brazilian banking sites. It drops “smss.exe” in the System folder. (Sophos)
Troj/Banworm-H — A worm that is used to block access to security-related Web sites and hijack banking sites through modification of the HOSTS file. It drops “crypt32net.dll” on the infected host and can communicate with remote sites via http. (Sophos)
Troj/Bankem-Z — Another worm that targets password information for Brazilian banking sites, sending the captured data to a remote site. (Sophos)
W32/Sdbot-CPP — An IRC backdoor worm that spreads through network shares by exploiting known Windows flaws. It drops “0.exe” in the Windows System folder. (Sophos)
W32/Brontok-M — This Trojan drops a number of files on the infected host including “cmd-bro-mkx.exe” in the Windows System folder. It can mess with Internet Explorer’s settings. (Sophos)
W32/Brontok-BO — A second Brontok variant that drops a bunch of files on the target machine, including “MrHelloween.scr” in the Windows System directory. (Sophos)
W32/Spybot-MH — A backdoor Trojan that can act as a keylogger and participate in denial-of-service attacks. It installs “zanbor.exe” in the Windows System folder. (Sophos)
Troj/Mondo-A — This Trojan is used to download and install additional malicious code. Initially, two files are dropped in the current folder: “drsmartload815a.exe” and “loadadv559.exe”. (Sophos)
Troj/Agent-CIO — A backdoor Trojan that can communicate with remote servers via HTTP. It drops “mcvswin.exe” in the Windows directory. (Sophos)
**********
From the interesting reading department:
Unisys contractor arrested in VA theft
Authorities have charged a 21 year-old Unisys subcontractor with stealing a desktop computer with billing information on as many as 38,000 Department of Veterans Affairs medical patients. IDG News Service, 09/15/06.
IBM debuts encrypted tape drive
IBM today debuted a new tape drive that encrypts data in the drive itself. It’s designed for markets that are increasingly regulated and concerned with data loss. Network World, 09/12/06.




