* Patches from Cisco, Mandriva, Debian, others * Beware new AIM worm * Schneier: We are losing the security war, and other interesting reading
Today’s bug patches and security alerts:
According to the Cisco advisory, “A vulnerability in the Cisco Guard may enable an attacker to send a web browser client to a malicious website with the use of Cross Site Scripting (XSS) when the Guard is providing anti-spoofing services between the web browser client and a webserver. The attacker may exploit this by providing a malicious URL for the web browser client to go to, often in email, followed off of a malicious website, or in an instant message. This issue may occur even if the protected website does not allow XSS. A software upgrade is required to fix this vulnerability. There is a workaround available to mitigate the effects of the vulnerability.”
The Cisco Intrusion Prevention System is vulnerable to a denial-of-service attack through malformed SSL packets. A free update is available to patch the flaws.
A flaw in specific versions of Cisco IOS could be exploited to gain privileges on affected devices, according to a Cisco advisory. Affected systems include Cisco IAD2400 series, 1900 Series Mobile Wireless Edge Routers and Cisco VG224 Analog Phone Gateways. An update is available.
**********
According to a post on PCWorld.com: There’s a new IE vulnerability being actively exploited in the wild that can nail fully patched systems with a virus or other malicious software.
**********
New patches from Mandriva:
**********
New fixes from Debian:
alsaplayer (multiple buffer overflows)
**********
New fixes for Ubuntu:
linux-restricted-modules-2.6.15 (updates to a previous fix)
**********
Today’s roundup of virus alerts:
New AIM worm may prove difficult to fight
A sophisticated computer worm spreading via AOL Instant Messenger is setting up a botnet that may be difficult to combat, security researchers said. The worm, known as W32.pipeline, propagates when AIM users click on a Web link that appears to have been sent to them by someone on their buddy list. They receive a message along the lines of, “Hey, would it be okay if I upload this picture of you tomy blog?” If the recipient clicks on the link, an executable file that looks like a JPEG will download into a Windows folder, according to researchers at security company FaceTime Communications. IDG News Service, 09/19/06.
Troj/Certif-R — A Trojan designed to capture data (including username and password) entered into online banking applications. It is installed as “systray.com” in the Windows System folder. (Sophos)
Troj/Banloa-ANI — A backdoor Trojan with the ability to access remote sites via HTTP. This functionality may be used to download additional malicious code. It is initially installed as “msng.exe” in the Windows directory. (Sophos)
W32/Spybot-MH — A backdoor Trojan that can act as a keylogger and participate in SYN Flood attacks against other systems. It may also try to terminate security related applications running on the affected machine. It drops “zanbor.exe” in the Windows System folder. (Sophos)
Troj/Lager-K — Another backdoor Trojan with the ability to access remote sites via HTTP. This one drops “taskdir.exe” in the Windows System folder. (Sophos)
W32/Looked-S and T — Yet another backdoor HTTP worm. This one also tries to infect any EXE it finds on the target host. It is installed as “rundl132.exe” in the Windows System folder. (Sophos)
W32/Rbot-FLL — Another day, another Rbot variant. Like previous versions, this one spreads through network shares and allows backdoor access through IRC. It is installed as a randomly-named EXE. (Sophos)
W32/Rbot-EWD — Another Rbot variant that uses known Windows flaws to spread. This one drops “msdn-nt.exe” in the System directory. (Sophos)
W32/Vanebot-C — A Trojan that spreads through network shares by exploiting known Windows flaws. It can be used to download additional code, terminate anti-virus applications and steal information. It is installed as “jconsole.exe” in the Windows System folder. (Sophos)
Troj/Clagger-AC — A downloader Trojan that spreads through an e-mail message written in what looks like German. The infected attachment is called “Rechnung.pdf.zip”. It drops “ipf.exe” in the Windows System folder. (Sophos)
Troj/Spyjack-O — A Trojan that tried to get a user to download so-called anti-spyware applications. It drops a number of files on the target host, including “intell32.exe” in the System folder, and changes the Windows Desktop image. (Sophos)
**********
From the interesting reading department:
Schneier: We are losing the security war
Companies are losing the battle to secure their IT systems from attacks by hackers and other threats, warned Bruce Schneier, the founder and CTO of Counterpane Internet Security. IDG News Service, 09/20/06.
VoIP presents major security risk, expert warns
Banks and other companies switching their phone systems to VoIP are making themselves vulnerable to phishing attacks for which there are currently no effective detection or prevention tools, a security researcher warned Wednesday. IDG News Service, 09/20/06.
Cross-site scripting the top security risk
Web administrators beware: cross-site scripting vulnerabilities are now far more attractive targets than more notorious bugs such as buffer overflows, according to new figures from Mitre, a U.S. government-funded research organization. TechWorld, 09/18/06.
Interop panel: NAC holds promise, but tread lightly
While network access control is generating great interest at Interop, show-goers were told Tuesday they need to carefully evaluate their need for NAC before jumping in — and then to do so only carefully. Network World, 09/20/06.




