Vulnerability allows scammers to hijack pop-ups

Opinion
Dec 9, 20045 mins

* Patches from Gentoo, SuSE, Debian, others * Beware e-mail worm that pretends to send updated account information to users * Industry group formed to track and thwart IM threats, and other interesting reading

Today’s bug patches and security alerts:

Vulnerability allows scammers to hijack pop-ups

Security researchers this week warned of a vulnerability in most Web browsers which could potentially allow scammers to launch phishing attacks from pop-up windows on trusted Web sites. The vulnerability arises when an Internet user opens browser windows for both a legitimate Web site and a malicious site at the same time. IDG News Service, 12/09/04.

https://www.nwfusion.com/news/2004/1209popscam.html?nl

Secunia Networks advisory:

https://www.nwfusion.com/go2/1206bug2a.html

**********

New set of Linux security flaws unveiled

A security researcher has uncovered yet another set of security flaws in an image component, which could put Linux users at risk of system compromise if they view a maliciously crafted image. InfoWorld, 12/08/04.

http://www.infoworld.com/article/04/12/08/morelinuxbugs_1.html

Gentoo patch:

https://security.gentoo.org/glsa/glsa-200412-03.xml

**********

Novell NetMail access vulnerability

The default Network Messaging Application Protocol (NMAP) authentication credentials in Novell NetMail could be used exploited to gain read/write access to the entire mail store. A workaround is to change the default NMAP authentication credentials. For more, go to:

Novell advisory:

https://www.nwfusion.com/go2/1206bug2b.html

SecurityTracker advisory:

https://www.securitytracker.com/alerts/2004/Dec/1012429.html

**********

Gentoo patches Sun and Blackdown Java environments

The Java plug-in security for the Sun and Blackdown Java environments could be bypassed, allowing any Java applet to run on the host system. For more, go to:

https://security.gentoo.org/glsa/glsa-200411-38.xml

Gentoo releases update for Open DC Hub

Open DC Hub, a software hub for the Direct Connect file sharing network, contains a buffer overflow that may be exploited by an attacker to run their code of choice on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200411-37.xml

**********

SuSE patches kernel issues

A number of security issues in the SuSE Linux kernel have been fixed. These range from bufer overflow issues to poor boundary checking. An attacker may exploit these to run any code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/1206bug2c.html

**********

Debian releases updated openssl package

Poorly secured temporary files are created by one of the functions in Debian’s openssl implementation. An attacker could exploit these via a symlink attack. For more, go to:

https://www.debian.org/security/2004/dsa-603

Debian fixes hpsockd

According to Debian, “A buffer overflow condition in hpsockd, the socks server written at Hewlett-Packard.  An exploit could cause the

program to crash or may have worse effect.” For more, go to:

https://www.debian.org/security/2004/dsa-604

**********

Conectiva patches abiword

A buffer overflow in the free abiword word processing system could be used to execute code on the affected machine. For more, go to:

https://www.nwfusion.com/go2/1206bug2d.html

Conectiva issues fix for squirrelmail

Squirrelmail, a Webmail client for PHP4, is vulnerable to cross-site scripting attacks. A fix is available. For more, go to:

https://www.nwfusion.com/go2/1206bug2e.html

**********

Today’s roundup of virus alerts:

Mugly.A – An e-mail worm that spreads through an infected attachment called “ATTACHED.ZIP”. The worm displays an image on the infected machine’s screen and installs another worm, Gaobot.BXG. (Panda Software)

Gaobot.BXG – A worm dropped by Mugly.A that spreads via network shares, attempting to exploit the Windows LSASS, RPC DCOM and WebDAV vulnerabilities. It can delete files, steal information and be used in a DDoS attack against a third party. (Panda Software)

Jabbit.A – This virus spreads by passing infected files between machines on removable media. On the 13th of any month, the virus will display various messages on the infected machine’s screen. (Panda Software)

W32/Atak-E – An e-mail worm that pretends to send updated account information to users. The virus installs itself as “dapdll.exe” in the Windows System directory. It comes as a .zip attachment. (Sophos)

W32/Rbot-RE – This Rbot variant can be access via IRC and used to turn on an attached Webcam, steal password and other information, delete network shares and participate in DDoS attacks. It spreads via network shares, installing itself as “msnmsgrsrvc.exe” in the Windows System folder. (Sophos)

W32/Rbot-RF – Similar to Rbot-RE in functionality, this variant spreads via network shares, exploiting the DCOM-RPC, LSASS, WebDAV and UPNP vulnerabilities in Windows. It installs itself in the Windows System folder as “WindowsSP.exe”. (Sophos)

W32/Rbot-RJ – Yet another Rbot variant. This one too spreads via network shares. It can be used to terminate security-related applications running on the infected machine and to prevent access to anti-virus sites by modifying the Windows HOSTS file. (Sophos)

Troj/Agent-BF – A Trojan that can be used to download code from the Internet. It uses a random filename to infect the target machine. No word on how it spreads. (Sophos)

Troj/Banker-BG – A password-stealing Trojan targeting Brazilian banking sites. (Sophos)

W32/Maslan-C – This worm spreads by e-mailing itself to target users. The infected message is titled “123” and has an attachment called “Playgirls2.exe”. It installs the Rbot-RW variant on the infected machine. (Sophos)

**********

From the interesting reading department:

Industry group formed to track and thwart IM threats

A group of Internet security and instant messaging providers Tuesday said they have teamed up to detect and thwart the growing threat of IM and peer-to-peer viruses and worms. IDG News Service, 12/07/04.

https://www.nwfusion.com/news/2004/1207indusgroup.html?nl

Nortel, Symantec team up to secure nets

Nortel and Symantec are joining forces to beef up network security by using Symantec threat discovery technology in combination with Nortel network hardware to block attacks. Network World Fusion, 12/07/04.

https://www.nwfusion.com/news/2004/1207ntsy.html?nl

Gartner: Consumers dissatisfied with online security

The results of a survey conducted by Gartner and shared with IDG News Service show that online consumers are growing frustrated with the lack of security provided by banks and online retailers, and feel that passwords are no longer sufficient to secure their online transactions. IDG News Service, 12/06/04.

https://www.nwfusion.com/news/2004/1206gartnconsu.html?nl