CORRECTION: Google patches hole

Opinion
Oct 26, 20046 mins

* Patches from Google, SuSE, Mandrake Linux, others * Beware latest Rbot and Forbot variants * VoIP security a moving target, and other interesting reading

EDITOR’S NOTE: The second item in yesterday’s newsletter (“Red Hat urges users to patch fileutils”) was not a legitimate security alert, but a phishing attack aimed at Red Hat users:

https://www.freeke.org/ffg/tech/computers/security/redhatphish.html

https://lists.netsys.com/pipermail/full-disclosure/2004-October/028030.html

https://www.mcarthurweb.com/archive/1098545263.html

Please do not install the patch, it will cause a security compromise on your system. We thank reader Bob Powers for pointing out our error and providing the links above.

Below is yesterday’s newsletter, minus the Red Hat entry.

Today’s bug patches and security alerts:

Google patches one security hole, but another surfaces

Search engine darling Google has patched a hole in its search engine the could have allowed malicious hackers to modify the content of the Google search results page or silently modify search results, but a new hole may have already appeared. IDG News Service, 10/21/04.

https://www.nwfusion.com/news/2004/1021googlpatch.html?nl

Advisory from Jim Ley:

https://jibbering.com/2004/10/google.html

**********

iDefense warns of flaws in anti-virus software

Security consultants at iDefense are warning of a flaw in many anti-virus packages that could be exploited to bypass virus detection when using ZIP files. For more, go to:

https://www.nwfusion.com/go2/1025bug1a.html

**********

SuSE patches libtiff

The libtiff image handling library used by many vendors contains heap and buffer overflow vulnerabilities. One of the flaws could be exploited to affect memory allocation. For more, go to:

https://www.suse.com/de/security/2004_38_libtiff.html

SuSE releases kernel update

According to SuSE, “An integer underflow problem in the iptables firewall logging rules can allow a remote attacker to crash the machine by using a handcrafted IP packet. This attack is only possible with firewalling enabled.” For more, go to:

https://www.suse.com/de/security/2004_37_kernel.html

**********

Conectiva, Mandrake Linux release Mozilla update

A new version of the Mozilla browser is available for Conectiva and Mandrake Linux that fixes a number of vulnerabilities in previous versions. Most of the flaws are overuns or buffer overflows. For more, go to:

Conectiva:

https://www.nwfusion.com/go2/1025bug1b.html

Mandrake Linux:

https://www.nwfusion.com/go2/1025bug1c.html

**********

Mandrake Linux patches CUPS

An information leak in the Common UNIX Printing System (CUPS) could disclose user and password information when it is written to a log file. For more, go to:

https://www.nwfusion.com/go2/1025bug1d.html

Mandrake Linux updates cvs

Version of cvs prior to 1.1.17 have an undocumented switch that could be used to disclose the history of a document and whether it exists or has been altered. For more, go to:

https://www.nwfusion.com/go2/1025bug1e.html

**********

OpenPKG patches mod_ssl

The mod_ssl implementation for OpenPKG may not always use a strong enough cipher when making a connection with the Apache Web server. For more, go to:

https://www.openpkg.org/security/OpenPKG-SA-2004.044-modssl.html

**********

Today’s roundup of virus alerts:

W32/Sluter-E – A Trojan that spreads between network shares and allows backdoor access via IRC. It tries to disable anti-virus applications running n the infected machines and can be used to run DoS attacks, log keystrokes, steal CD keys and more. (Sophos)

W32/Rbot-NA – This Rbot variant copies itself into “TASKMSG.EXE” and logs keystrokes in the file “key.txt”. (Sophos)

W32/Rbot-ND – An Rbot variant that targets Microsoft SQL server installations. It installs itself as “webm.exe” in the Windows System folder on the infected system. It can be used for video capture, file transfer or proxy server. (Sophos)

W32/Forbot-AR – A new Forbot variant that spreads via network shares and allows backdoor access via IRC. It installs itself as “securitychk.exe” in the Windows System folder. (Sophos)

W32/Forbot-BN – This Forbot version exploits the Windows LSASS vulnerability as it spreads via network shares. It installs itself as “rundll.exe” in the Windows System folder. It can be used for a variety of malicious intents. (Sophos)

W32/Forbot-BP – Yet another network Trojan that uses various exploits to spread via network shares. This variant installs itself as “crsrs.exe”. It can be used to steal information or launch DoS attacks against remote machines. (Sophos)

W32/Forbot-BQ – Similar to the BN variant, this one too exploits the LSASS vulnerability to infect a machine. It installs itself as “win32usb.exe”. (Sophos)

W32/Forbot-BR – It’s Forbot week. This one uses the filename “windows.exe” in the Windows System folder as its infection point. (Sophos)

W32/Spybot-DF – Another network worm. Spybot installs itself as “WINDOWSUPDATER.EXE”. It is said to be able to log keystrokes and send them to a remote user via IRC. (Sophos)

**********

From the interesting reading department:

VoIP security a moving target

Those who want to operate secure VoIP networks must be mindful of myriad threats because the technology is susceptible to vulnerabilities that might be foreign to traditional telecom managers and their staffs. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504von.html?nl

Review: Early products handle traffic well, but need some polish

New Web front-end devices from Array Networks, NetScaler and Redline Networks each offer valuable techniques for dealing with growing traffic and security concerns. But while they can help improve site performance, we found plenty of rough edges. Network World, 10/25/04.

https://www.nwfusion.com/reviews/2004/1025rev.html?nl

Security vendors take softer approach

Worm prevention and Internet monitoring are the primary focus of new security products expected this week from Symantec, Sana Security, Zix and Websense. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504security.html?nl

Enterasys upgrades its security suite

Enterasys this week is expected to announce an upgrade to its Dragon intrusion-detection-system product that the company says will make it easier for customers to protect their networks. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504enterasys.html?nl

Check Point bolsters LAN security

Check Point is upgrading its application-layer security appliance with a management interface that makes it possible for customers to send updates to the machines as a group rather than one at a time. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504checkpoint.html?nl

Security management products on tap from CA, SenSage

New versions of enterprise security-information management products from Computer Associates and SenSage look to combine event data and logs from several sources to provide users a bird’s-eye view of security. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504ca.html?nl

Storage vendors try to ease back-up and protection tasks

A plethora of storage vendors are expected to announce this week at Storage Networking World in Orlando software and hardware that lets IT managers better protect and back up data on Fibre Channel and IP storage-area networks. Network World, 10/25/04.

https://www.nwfusion.com/news/2004/102504snw.html?nl

Intel outlines wireless USB security, use

Intel is backing the 128-bit Advanced Encryption Standard protocol for securing wireless USB connections, which it hopes will replace USB cables for connections over very short distances, a company engineer said this week. IDG News Service, 10/22/04.

https://www.nwfusion.com/news/2004/1022inteloutli.html?nl

Cisco buys network security company Perfigo

Network equipment maker Cisco said it intends to buy Perfigo for $74 million in cash, boosting the company’s efforts to secure network “endpoints” and protect them from worms, viruses and hacking. IDG News Service, 10/21/04.

https://www.nwfusion.com/news/2004/1021ciscobuys.html?nl