Anatomy of a phish

Opinion
Oct 28, 20046 mins

* Patches from RealNetworks, Mandrake Linux, others * Beware latest mass mailing viruses * Biometrics early adopters reveal secrets, challenges, and other interesting reading

Thank God I don’t administer Red Hat Linux servers for my or any company. I would have been completely scammed by this week’s phishing expedition targeted at Red Hat administrators. As you may have seen from our corrected newsletter that went out Tuesday, I published what I thought was a valid advisory (strike one!) from Red Hat about a flaws in its fileutils implementation. I assumed it was real because I do subscribe to the Red Hat security advisory mailing list (strike two!). Finally, I put a direct link to the “patch” instead of the advisory page, as I usually do (Strike THREE!).

Thankfully, my intrepid readers are far smarter than me and quickly warned me that I had fallen for the scam. We were then able to get an updated advisory out quickly. Looking back, the telltale signs should have been obvious: The message was addressed to a common Network World Fusion address, not me directly and the text of the message said it was a “critical-critical update”.

I’ll chalk this up to a learning experience and hopefully history will not repeat itself.

PS. The Boston Red Sox won the World Series! To quote Joe Castiglione, the voice of the Sox, “Can you believe it?!?!”

Today’s bug patches and security alerts:

Vulnerability in Gaim

A buffer overflow in Gaim, an open source instant messaging client, could be exploited in a denial-of-service attack against the application or to potentially run any code on the affected machine. Users should upgrade to Version 1.0.2 to fix the issue. For more, go to:

https://gaim.sourceforge.net/security/?id=9

Gentoo:

https://security.gentoo.org/glsa/glsa-200410-23.xml

Mandrake Linux:

https://www.nwfusion.com/go2/1025bug2a.html

**********

Apple releases QuickTime 6.5.2, Security Update 2004-10-27

A new update is available for Apple QuickTime media player that fixes a couple of overflow vulnerabilities that could impact Windows and Macintosh versions of the application. The most serious of the flaws could be exploited to run any code on the affected machine.

The company also released a new security update for Mac OS X that fixes a vulnerability in the Macintosh Remote Desktop Client. If exploited, an attacker could run an application with root privileges behind the login window.

For more on both updates, go to:

https://www.apple.com/support/security/security_updates.html

**********

RealNetworks patches RealPlayer

A “critical” flaw in the way RealNetworks’ RealPlayer media client handles “skins” could be exploited to run any code on a machine affected by this issue. NGSSoftware discovered this issue, but is withholding details for a few months. A patch is available:

https://service.real.com/help/faq/security/041026_player/EN/

NGSSoftware advisory:

https://www.nextgenss.com/advisories/realra3.txt

**********

Flaw found in HP Serviceguard

A vulnerability in HP’s Serviceguard for HP-UX and Linux could be exploited by non-root users to gain elevated privileges. Users can download patches from the HP IT Resource Center:

http://itrc.hp.com

**********

iDefense warns of PuTTY vulnerability

Security experts at iDefense are warning of a buffer overflow in PuTTY, an open source implementation of Telnet and SSH for Win32 and Unix platforms. The overflow could be exploited to run any code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/1025bug2b.html

Gentoo users:

https://security.gentoo.org/glsa/glsa-200410-29.xml

**********

Vulnerability in PDF viewers

A flaw in various implementations of a PDF viewer application could be exploited to crash the affected application or potentially run arbitrary code on the affected machine. For more, go to:

KDE (kpdf):

https://www.kde.org/info/security/advisory-20041021-1.txt

Mandrake Linux (xpdf):

https://www.nwfusion.com/go2/1025bug2c.html

Mandrake Linux (gpdf):

https://www.nwfusion.com/go2/1025bug2d.html

SuSE:

https://www.suse.com/de/security/2004_39_pdftools_cups.html

**********

Today’s roundup of virus alerts:

W32/Forbot-BR – This bot spreads via network shares and installs itself as “windows.exe” in the Windows System directory. It can be used as a launching point for DoS attacks, to scan for other vulnerable machines and harvest information from the infected machine. (Sophos)

W32/Rbot-NG – A Trojan horse that allows backdoor access via IRC after infecting a machine via shared network drives. This variant installs itself in the Windows System directory as “Netsis.exe” and can be used to steal password information. (Sophos)

W32/Rbot-NJ – Similar to other Rbot variants, this one uses the file “LOGON.EXE” as its infection point in the Windows System directory. In addition to providing backdoor access via IRC, it also disables security related applications running on the infected machine. (Sophos)

OF97/Toraja-I – An old-school office macro virus that infects the XL Start directory with a file named “start25.xls”. No word on damage it may cause. (Sophos)

Troj/Banker-EK – This Trojan horse attempts to log Internet activity and posts the information to a Brazilian Web site. No word on how it spreads. (Sophos)

W32/Baba-A – A mass mailing virus that plants a key logger application on the infected machine. It spreads via a faked “delivery failure” message, which points to a remote site. (Sophos)

W32/Bagz-D – Another mass mailing worm that uses a variety of message types to spread. All of the infected messages will have a .exe attachment. This virus runs as the process “RPC32”. (Sophos)

**********

From the interesting reading department:

Biometrics early adopters reveal secrets, challenges

In a conference room overlooking the site of the World Trade Center, early adopters of biometrics technology this week stressed the importance of determining someone’s true identity. Network World Fusion, 10/28/04.

https://www.nwfusion.com/news/2004/1028biometrics.html?nl

NTT DoCoMo, IBM, Intel team to secure mobile devices

With an eye towards making mobile devices and the commerce services that run over them more secure, NTT DoCoMo, Intel and IBM Wednesday published a jointly developed security specification called the Trusted Mobile Platform. IDG News Service, 10/27/04.

https://www.nwfusion.com/news/2004/1027nttdocom2.html?nl

IBM offers companies monthly security report

IBM Monday introduced a security service that offers a concise, monthly global-network threat report designed to help organizations assess security needs and vulnerabilities from a business perspective. IDG News Service, 10/25/04.

https://www.nwfusion.com/news/2004/1025ibmoffer.html?nl

U.S. Bancorp, VeriSign team on banking security

U.S. Bancorp will use a hardware-token based authentication service from VeriSign to secure access to commercial banking services for its customers, and may soon introduce a similar service for consumer banking customers, according to a VeriSign executive. IDG News Service, 10/26/04.

https://www.nwfusion.com/news/2004/1026usbanco.html?nl

Cisco PBX adds encryption support for VoIP devices

Cisco this week launched an upgrade to its CallManager IP PBX platform, broadening its encryption support for IP phones and other VoIP devices, such as VoIP gateways and voicemail servers. Network World Fusion, 10/26/04.

https://www.nwfusion.com/news/2004/1026ciscocall.html?nl

Microsoft revises, AOL accepts anti-spam plan revisions

After running into opposition to its Sender ID anti-spam plan, Microsoft has revised and resubmitted it to the Internet Engineering Task Force (IETF) for consideration, according to a company spokesperson. IDG News Service, 10/25/04.

https://www.nwfusion.com/news/2004/1025microrevis.html?nl