* Patches from Gentoo, Debian, others * Beware new Bagle and MyDoom variants * Study: MasterCard, others unwittingly help 'phishers', and other interesting reading Today’s bug patches and security alerts:Bug in Solaris Volume ManagerA flaw in Sun’s Solaris Volume Manager, a tool for managing disk partitions and virtual drives, could be exploited to cause a system panic on the affected machine. Only Solaris 9 implementations running Volume Manager are impacted. For more, go to:SPARC platform: https://www.nwfusion.com/go2/0719bug2a.htmlx86 platform: https://www.nwfusion.com/go2/0719bug2b.html**********Cross-scripting attack in HotmailSecurityTracker is reporting a potential cross-scripting vulnerability in the Hotmail service that could allow a malicious user to gain access to another user’s account. The flaw involves sending a message with some embedded code in it. No workaround is available at the moment, other than to not open message from questionable parties. For more, go to:https://www.securitytracker.com/alerts/2004/Jul/1010726.html********** Gentoo patches rsyncThe rsync incremental file transfer utility is vulnerable to a directory traversal attack. This could be used by a hacker to write files outside the directories that rsync has access to. For more, go to:https://forums.gentoo.org/viewtopic.php?t=196895Gentoo patches MoinMoin A bug in MoinMoin, a Python clone of WikiWiki, allows users to bypass access control lists. For more, go to:https://forums.gentoo.org/viewtopic.php?t=196538Gentoo fixes buffer overflow in wvA buffer overflow in wv, a tool for accessing Microsoft Word files, could be exploited to allow any code to be run on the affected machine. For more, go to:https://forums.gentoo.org/viewtopic.php?t=197732**********Debian patches PHPA flaw in the popular PHP server-side scripting language could be exploited remotely to cause a “memory_limit request termination” on the affected machine. An attacker could exploit this to take control of the machine and run any code they wanted. For more, go to:https://www.debian.org/security/2004/dsa-531Debian releases patch for EtherealA flaw in the Ethereal network monitoring package could be exploited by a invalid SNMP packet, which would cause the system to crash. For more, go to:https://www.debian.org/security/2004/dsa-528**********Today’s roundup of virus alerts:New Bagle, MyDoom variants roil InternetNew versions of the Bagle and MyDoom worms surfaced on the Internet Monday, and appear to be spreading. Bagle.AI and MyDoom.N are both so-called “mass mailing” worms that use a built-in SMTP engine that sends e-mail messages carrying worm-infected file attachments from computer to computer on the Internet, both using faked (or “spoofed”) sender addresses, anti-virus companies said. IDG News Service, 07/20/04.https://www.nwfusion.com/news/2004/0720newbagle.html?nlAnti-virus companies warn about Bagle.AG threatNetwork administrators returning to work after the weekend can enjoy a fresh Bagle with their coffee – and no, it’s not that kind of bagel. On Monday, anti-virus companies warned of another virulent new version of the Bagle e-mail worm, dubbed Bagle.AG. IDG News Service, 07/19/04.https://www.nwfusion.com/news/2004/0719antivcompa.html?nlW32/Rbot-DX – Installing itself as “WUAMGRD.EXE” in the Windows System folder, this virus penetrates systems via poorly protected network shares. The virus accepts remote commands via IRC and disables anti-virus applications running on the infected machine. (Sophos)W32/Lovgate-AJ – A member of the Lovegate family that spreads via e-mail, file sharing networks and network shares. No word on the damage it can cause, but it does infect a number of files in the Windows System directory. (Sophos)W32/Sdbot-KK – This Sdbot variant copies itself into “VIDEONS32.EXE” in the Windows System directory. The virus spreads via network shares and will allow backdoor access to the infected machine via IRC. The virus also terminates security applications and access to related sites. (Sophos)Troj/Bancban-C – A password-stealing Trojan horse that targets customers of a Brazilian bank. No other characteristics given. (Sophos)**********From the interesting reading department:Study: MasterCard, others unwittingly help ‘phishers’Leading financial institutions have adopted a more aggressive attitude toward online identity theft cons known as “phishing scams” in recent months. But companies, including MasterCard International, may be unwittingly helping phishers trick online shoppers, says a new report from a U.K. Web developer. IDG News Service, 07/19/04.https://www.nwfusion.com/news/2004/0719studymaste.html?nlTool nabs malware masked by SSLFinjan Software Monday released a product that protects networks from malicious code trying to sneak into corporate networks as SSL traffic. Network World Fusion, 07/19/04.https://www.nwfusion.com/net.worker/news/2004/0719finjan.html?nl‘Deceptive Duo’ hacker charged by U.S. governmentA 20-year-old man from Pleasant Hill, Calif., suspected of being a hacker calling himself “the Deceptive Duo,” Monday will face a U.S. Magistrate Judge on charges that he hacked into government computers and defaced government Web sites. IDG News Service, 07/19/04.https://www.nwfusion.com/news/2004/0719deceduo.html?nlStolen code shop back in business – on UsenetAn online group claiming to have the source code for two popular computer programs for sale opened its doors for business again Saturday. IDG News Service, 07/19/04.https://www.nwfusion.com/news/2004/0719stolecode.html?nlFirst Windows CE virus emergesA virus designed to demonstrate security holes in Microsoft’s Windows CE operating system but not to cause damage was identified by security companies over the weekend. IDG News Service, 07/19/04.https://www.nwfusion.com/news/2004/0719firstwindo.html?nl Related content news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center news AWS and Nvidia partner on Project Ceiba, a GPU-powered AI supercomputer The companies are extending their AI partnership, and one key initiative is a supercomputer that will be integrated with AWS services and used by Nvidia’s own R&D teams. By Andy Patrizio Nov 30, 2023 3 mins CPUs and Processors Generative AI Supercomputers news VMware stung by defections and layoffs after Broadcom close Layoffs and executive departures are expected after an acquisition, but there's also concern about VMware customer retention. By Andy Patrizio Nov 30, 2023 3 mins Virtualization Data Center Industry Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe