* Patches from Gentoo, Mandrake Linux, others * Beware MyDoom.O * E-commerce attack tops McAfee's threat ranking, and other interesting reading Today’s bug patches and security alerts:ISS patches CheckPoint VPN-1 ASN.1 Decoding Remote CompromiseAccording to an alert from ISS, “When establishing an encrypted connection to a VPN, it is possible for an attacker to trigger a buffer overflow vulnerability in an ASN.1 decoding library within the VPN-1 product.” For more, go to:https://xforce.iss.net/xforce/alerts/id/178 **********DoS in Microsoft System Management Server SecuriTeam is reporting a denial-of-service vulnerability in the Microsoft System Management Server Remote Control. An attacker could send specially crafted packets to crash the system. For more, go to:https://www.securiteam.com/windowsntfocus/5WP0N1FDFW.html**********@Stakes warns of HP dced flawA flaw in the HP DCE implementation could be exploited by a remote user to run commands on the affected server with root privileges, according to a warning from @Stake. For more, including links to all the appropriate patches, go to:https://www.atstake.com/research/advisories/2004/a072204-1.txt **********Gentoo patches OperaA bug in Opera could allow an attacker to spoof a Web site using frame injection. This has been fixed:https://forums.gentoo.org/viewtopic.php?t=200323 **********Mandrake Linux releases Samba fixA buffer overflow has been found in SWAT, the Samba Web Administration Tool. This flaw could be exploited prior to a user being authenticated and could allow an attacker to take control of the affected machine. For more, go to:https://www.nwfusion.com/go2/0726bug2a.htmlMandrake Linux issues mod_ssl updateA code review for mod_ssl found another “risky” call to the ssl_log file. A fix is available. For more, go to:https://www.nwfusion.com/go2/0726bug2b.htmlMandrake Linux patches postgresqlA flaw in postgresql’s ODBC implementation could be exploited to crash the application accessing the database. For more, go to:https://www.nwfusion.com/go2/0726bug2c.htmlMandrake Linux fixes webminA vulnerability in Webmin could allow an attacker to bypass the system’s access control list “and gain read access to configuration information for a module.” For more, go to:https://www.nwfusion.com/go2/0726bug2d.htmlMandrake Linux patch available for XFree86According to an alert from Mandrake Linux, “Steve Rumble discovered XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.” For more, go to:https://www.nwfusion.com/go2/0726bug2e.html**********Today’s roundup of virus alerts:MyDoom.O hammering search enginesAnti-virus software companies are warning e-mail users about a new version of the MyDoom e-mail worm, dubbed MyDoom.O, which is spreading on the Internet and causing slowdowns at search engines, including those run by Lycos and Google. IDG News Service, 07/26/04.https://www.nwfusion.com/news/2004/0726mydoom.html?nlW32/Zindos-A – This is the other foot of MyDoom.O (or MyDoom.M, depending on what vendor is doing the reporting). Zindos-A uses the backdoor opened by MyDoom to infect systems. It’s used in a DDoS attack against microsoft.com. (Sophos)W32/Rbot-EK – A bot that exploits older viruses, Windows vulnerabilities, SQL Servers with weak passwords and network shares to spread between machines. The bot installs itself as “scvhost.exe” in the Windows System folder and allows backdoor access via IRC. It also tries to terminate certain anti-virus applications running on the infected machine. (Sophos)W32/Rbot-EP – Exploiting network shares, this bot installs itself as “wuamgrd.exe” in the Windows System directory. It too allows backdoor access via IRC. (Sophos)W32/Rbot-EQ – Another Rbot variant that has similar properties to Rbot-EP above. (Sophos)W32/Spybot-CZ – A keystroke logger that looks for passwords and other sensitive information. It installs itself as “DLL32SYS.EXE” in the Windows System folder and spreads via network shares. (Sophos)Troj/PatchLs-A — A Trojan that tries to exploit the LSASS vulnerability by injecting code into the application. Doesn’t appear to have any malicious properties at this time. (Sophos)OF97/Toraja-I – A macro virus for Office 97 that infects Excel spreadsheets. No word on any damage caused by the infection. (Sophos)Troj/Small-AO – A backdoor Trojan that allows remote access of the infected machine. No word on how it spreads. (Sophos)**********From the interesting reading department:The insecure state of securityThe 2004 InfoWorld Security Survey shows IT managers are worried about the effectiveness of their security systems. InfoWorld, 07/26/04.http://www.infoworld.com/reports/30SRsecurityrr.htmlE-commerce attack tops McAfee’s threat rankingA rivalry between the creators of the Netsky and Bagle viruses helped cause a dramatic increase in threats against home and enterprise computers in the first half of this year, but the most serious threat was Download.Ject, a Trojan that exploited a vulnerability in Microsoft’s Internet Explorer Web browser, according to McAfee. IDG News Service, 07/26/04.https://www.nwfusion.com/news/2004/0726ecomattac.html?nlDoubleClick downed by denial-of-service attackInternet advertising company DoubleClick was shut down Tuesday by a denial-of-service attack launched from computers on the Internet, a company spokeswoman confirmed. IDG News Service, 07/27/04.https://www.nwfusion.com/news/2004/0727doubldowne.html?nlCybersecurity experts wantedNew worries about national cybersecurity are prompting government officials to press colleges for rigorous curricula that train future cyberprotectors. PC World, 07/23/04.https://www.nwfusion.com/news/2004/0723cyberexper.html?nleEye lifts the lid on endpoint security productEEye Digital Security Monday announced a new endpoint security product that it says will help organizations stop attacks launched from the Internet that use previously unknown, or “zero day,” software vulnerabilities. IDG News Service, 07/26/04.https://www.nwfusion.com/news/2004/0726eeyelifts.html?nl Related content news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Network Management Software Networking opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software brandpost Sponsored by HPE Aruba Networking SASE, security, and the future of enterprise networks By Adam Foss, VicePresident Pre-sales Consulting, HPE Aruba Networking Nov 28, 2023 4 mins SASE news AWS launches Cost Optimization Hub to help curb cloud expenses At its ongoing re:Invent 2023 conference, the cloud service provider introduced several new and free updates that are expected to help enterprises optimize their AWS costs. By Anirban Ghoshal Nov 28, 2023 3 mins Amazon re:Invent Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe