* Patches from Mandrake Linux, Debian, Conectiva, others * Beware e-mail worm that spreads via a message claiming your machine is infected with the Netsky worm
Couple items to bring to your attention of the top today. First, Paul Roberts at the IDG News Service, a sister of Network World, has a Q&A with “Holy Father,” the guy that developed rootkits. You can read it here: http://www.nwfusion.com/news/2005/0316holyfathe.html?nl
Couple items to bring to your attention of the top today. First, Paul Roberts at the IDG News Service, a sister of Network World, has a Q&A with “Holy Father,” the guy that developed rootkits. You can read it here:
https://www.nwfusion.com/news/2005/0316holyfathe.html?nl
Why are rootkits nasty? According to Travis Witteveen, vice president of America’s for F-Secure, rootkits had, until recently, been undetectable with current anti-virus technology. Witteveen says anti-virus software such as F-Secure’s rely on the Windows Operating System to tell the anti-virus process what processes are running and files are being written. Rootkits hide themselves from even Windows. Naturally, F-Secure has releases Backlight, a product designed to uncover these nasties. More on Backlight and Rootkits can be found in this F-Secure Weblog entry:
https://www.nwfusion.com/go2/0314bug2a.html
Second, I attented the IDC Directions 2005 conference in Boston yesterday. During the session, “Security Convergence: Collapsing the Chaos,” analyst Christian Christiansen talked about the merging of security applications in a single unified platform that could be served off one or more boxes, depending on scalability. Rather than having a separate firewall/VPN system, anti-virus tool, intrusion protection system and Spam filter, everything will be combined into a Unified Threat Management (UTM) system. He says the days of UTMs are not far down the road.
What are your thoughts on a combined UTM system protecting your enterprise? Drop me a line at jmeserve@nww.com
Today’s bug patches and security alerts:
Java Applet Trojan
A new Trojan Horse written in Java could drop spyware into Internet Explorer even if the Java Applet is run inside a Firefox browser, according to a posting the F-Secure Weblog. The Trojan could even run under Linux, though is not very effective. For more, go to:
https://www.nwfusion.com/go2/0314bug2b.html
**********
SuSE releases Mozilla Firefox update
An update for SuSE’s implementation of the open source Mozilla Firefox fixes a number of security flaws in previous releases. The various flaws could be exploited in phishing attacks, to expose cookie information or to potentially run malicious code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/0314bug2c.html
**********
Mandrake Linux, SuSE release fix for openslp
A number of serious flaws have been found in Mandrake Linux and SuSE implementations of OpenSLP, an open source version of the Service Location Protocol. The flaws could be exploited by a remote attacker. Patches are available:
Mandrake Linux:
https://www.nwfusion.com/go2/0314bug2d.html
SuSE:
https://www.nwfusion.com/go2/0314bug2e.html
**********
KDE warns of DCOP vulnerability
KDE dcopidlng, a DCOP helper script, is vulnerable to a symlink attack. An attacker could use this to overwrite files on the affected system. For more, go to:
https://www.kde.org/info/security/advisory-20050316-1.txt
**********
Conectiva releases gaim fix
A new update for gaim, an open source IM client, is available. The release fixes a number of bugs and security flaws. For more, go to:
https://www.nwfusion.com/go2/0314bug2f.html
Conectiva patches kdenetwork’s kppp
A flaw in kppp, if installed with root privileges, could be exploited to hijack a system’s domain name resolution function. For more, go to:
https://www.nwfusion.com/go2/0314bug2g.html
**********
Gentoo issues curl fix
A buffer overflow in curl’s NTLM authorization base64 decoding could be exploited by an attacker to execute applications with the permissions of the user running curl. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-20.xml
MySQL fix available for Gentoo users
A new update for the popular MySQL database fixes an input validation flaw in certain functions. An attacker with some access privileges could use this to potentially run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-19.xml
Gentoo patches Ringtone Tools
Ringtone Tools, a tool for creating cellphone ringtones, as its name implies, contains a buffer overflow vulnerability that could be exploited to run malicious code on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200503-18.xml
**********
Debian releases patch for squirrelmail
A previous fix for Debian’s implementation of squirrelmail created a new issue when a user session times out. A fix is available for this new issue. For more, go to:
https://www.debian.org/security/2005/dsa-662
Debian patches luxman
A buffer overflow in luxman, a PacMan knockoff, could be exploited to run arbitrary code on the affected machine. For more, go to:
https://www.debian.org/security/2005/dsa-693
**********
Mandrake Linux releases Ethereal fix
The Ethereal protocol analyzer tool is vulnerable to a number of security flaws. These flaws could exploited to run arbitrary code on the affected system. For more, go to:
https://www.nwfusion.com/go2/0314bug2h.html
Mandrake Linux patches cyrus-sasl
According to an alert from Mandrake Linux, “A buffer overflow was discovered in cyrus-sasl’s digestmd5 code. This could lead to a remote attacker executing code in the context of the service using SASL authentication. This vulnerability was fixed upstream in Version 2.1.19.” A patch is available:
https://www.nwfusion.com/go2/0314bug2i.html
Mandrake Linux updates gnupg
According to the Mandrake Linux advisory, “The OpenPGP protocol is vulnerable to a timing-attack in order to gain plain text from cipher text. The timing difference appears as a side effect of the so-called “quick scan” and is only exploitable on systems that accept an arbitrary amount of cipher text for automatic decryption.” A fix is available:
https://www.nwfusion.com/go2/0314bug2j.html
**********
Today’s roundup of virus alerts:
W32/Capside-C – A Windows worm that copies itself into Ireul.pif, NETINSTALLDRV.EXE, WINAPLOGUPD.COM and XPEXTRATDLL.SCR. It spreads via popular file sharing networks and can allow backdoor access to the infected machine via IRC. (Sophos)
W32/Esalone-A – A virus that spreads by inserting itself in to WinZip and WinRAR archives. It drops the file “daemon.exe” in the Windows System folder of the infected machine. (Sophos)
Troj/Dowcen-Gen – This Trojan attempts to download malicious code from a remote site. No word on how it spreads between machines. (Sophos)
W32/Rbot-XS – A new Rbot variant that worms its way through network shares and allows backdoor access via IRC. This variant drops “TAY0X.EXE” in the Windows System folder and can be used for a number of malicious purposes. (Sophos)
W32/Rbot-XW – A similar Rbot variant as Rbot-XS above. This one installs “lsasss.exe” in the Windows System folder. (Sophos)
W32/Tobecho.A.worm – This e-mail worm spreads via a message claiming your machine is infected with the Netsky worm. The attached file is advertised as a removal tool but can be used to change the infected machine’s configuration. (Panda Software)
W32/Agobot-QV – An Agobot variant that exploits a number of known Windows vulnerabilities as it spreads via network shares. This version drops “scvhost.exe” in the Windows System folder and can allow backdoor access via IRC. (Sophos)
W32/Agobot-QX – Another Agobot variant. This one drops “WCEMNGR.EXE” in the Windows System folder. (Sophos)
W32/Mytob-B – A mass-mailing worm that allows backdoor access to its prey via IRC. It drops the file “taskgmr.exe” in the Windows System folder. The infected attachment is an executable or ZIP file. (Sophos)
W32/Myfip-K – Another Windows worm that spreads via weakly protected network shares. It installs “kernel32dll.exe” in the Windows System directory. (Sophos)




