* Patches from Apple, SCO, Mandriva, others * Beware worms spreading via AIM
‘Net Buzz: Addressing ‘DDoS extortion’
Paying an extortionist a few thousand dollars to leave your network alone might make bottom-line business sense if the alternative is enduring a distributed denial-of-service attack that could cost your company millions in lost revenue and public relations damage. The trouble is that paying criminals to leave you be is also dangerously shortsighted – especially from a broader societal standpoint – and ought to be every bit as much against the law as extortion. Network World, 05/23/05.
http://www.networkworld.com/columnists/2005/052305buzz.html?nl
For background:
Extortion via DDoS on the rise, 05/16/05
https://mike.nww.com/news/2005/051605-ddos-extortion.html?nl
Today’s bug patches and security alerts:
Bugs plague new Netscape browser
Netscape’s new 8.0 browser, featuring a hybrid rendering engine that is said to combine the best of Internet Explorer and Mozilla Firefox, has some 41 flaws in it. One major problem with the initial release is that it uses older Firefox code, which does not include a number of recent security fixes. Within 24 hours of the 8.0 release, Netscape issued Version 8.01 to fix the issues:
https://browser.netscape.com/ns8/security/alerts.jsp
**********
Two new vulnerabilities in MySQL
Two flaws have been found in the popular MySQL database application, according to alerts from SecurityTracker. The flaws be exploited to gain elevated privileges on the affected machine. For more, go to:
MySQL Non-existent ‘–user’ Error
https://www.securitytracker.com/alerts/2005/May/1013994.html
MySQL ‘mysql_install_db’ Uses Unsafe Temporary Files
https://www.securitytracker.com/alerts/2005/May/1013995.html
**********
Apple releases Mac OS X 10.4.1
The latest Mac OS X update from Apple fixes flaws in Bluetooth, Dashboard, Kernel, and SecurityAgent. Many of the flaws could be exploited in a denial-of-service attack. For more, go to:
https://docs.info.apple.com/article.html?artnum=301630
**********
SecuriTeam warns of flaw in Yahoo Messenger
A flaw in Yahoo Messenger could be exploited by a remote user to terminate the application, disconnecting the user from their chat session. For more, go to:
https://www.securiteam.com/windowsntfocus/5HP0H20FPE.html
**********
SCO patches chroot for OpenServer
The chroot tool for limiting what system resources an application can access has a flaw that could allow a malicious application to break out of its “jail”. A fix is available:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.22
SCO releases telnet fix for OpenServer
A buffer overflow in the telnet client for OpenServer could be exploited to run malicious code on the affected machine. For more, go to:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.23
SCO patches Hyper-Threading flaw
The Hyper-Threading technology in SCO UnixWare and OpenServer, used with Intel processors, could leak information. An attacker could exploit this to start a malicious system thread. For more, go to:
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.24
**********
Mandriva patches gzip
Three flaws have been found in gzip, an open source file compression program. An attacker could exploit the most serious of these to run malicious applications on the affected machine. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:092
Mandriva patches cdrdao
Two vulnerabilities have been found in the Mandriva cdrdao application. The most serious of the flaws could be exploited to overwrite files on the affected machine. For more, go to:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:089
**********
FreeBSD patches ldt
A flaw in the i386_get_ldt could be exploited to disclose kernel memory, which may contain user password information. For more, go to:
http://www.networkworld.com/go2/0523bug1a.html
**********
Mandriva, Ubuntu release updates for bzip2
A flaw in the bzip2 compression application could be exploited by an attacker to overwrite files on the affected machine. For more, go to:
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:091
Ubuntu:
https://www.ubuntulinux.org/support/documentation/usn/usn-127-1
**********
Mandriva, Ubuntu issue patches for nasm
A buffer overflow vulnerability in nasm could be used by an attacker to run code on the target machine. For more, go to:
Mandriva:
https://www.mandriva.com/security/advisories?name=MDKSA-2005:090
Ubuntu:
https://www.ubuntulinux.org/support/documentation/usn/usn-128-1
**********
Today’s roundup of virus alerts:
Troj/Zapchas-J – A backdoor Trojan that drops “svchost.exe” in the Window System directory. It provides access to the infected machine by mIRC. (Sophos)
W32/Oscabot-F – A worm that spreads through AOL Instant Messenger clients by sending a message with a link to the infected file. It drops “userint32.exe” as a hidden, read-only file on the affected machine. (Sophos)
W32/Opanki-I – Another worm that uses AOL buddy lists to spread. It sends a message with a link that, if clicked, will download a PIF file from a specific site. (Sophos)
Troj/Vidlo-J – A download application that attempts to grab “prev.exe” from a remote site. (Sophos)
W32/Mytob-BZ – A new Mybot variant that spreads through network shares and e-mail. It drops “taskgmr.exe” on the infected machine. The infected attachment will have a PIF, SCR, EXE or ZIP extension. (Sophos)
W32/Mytob-EM – Another not-so-original Mytob variant. This one drops “mprmsg32.exe” on the infected machine. (Sophos)
W32/Mytob-CK – This variant too uses “taskgmr.exe” as its infection point. (Sophos)
W32/Kassbot-D- Spreads through networks shares and can be used for a number of malicious purposes, including sending spam, acting as a proxy and logging keystrokes. It drops “spools.exe” in the Windows System folder. (Sophos)
W32/Rbot-RF – A new Rbot worm that exploits a number of known Windows vulnerabilities as it spreads through network shares. It can be used as a proxy, to download code, send spam and log keystrokes. It drops “WindowsSP.exe” on the infected machine. (Sophos)
W32/Agobot-AAZ – A worm that spreads through network shares and allows back door access via IRC. It drops “walg32.exe” on the infected machine. It blocks access to anti-virus sites and can be used for a number of malicious applications. (Sophos)
Troj/Haxdoor-Y – A backdoor Trojan that installs itself as the process “AVPX32”. (Sophos)




