* Patches from Microsoft, KDE, Debian, others * Beware an Atak variant that tries to hide itself in a holiday-related message * New IE hole could perfect phishing scams, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Microsoft fixes ‘critical’ XP firewall issue
Microsoft has quietly released an update to Windows XP to fix a potentially serious configuration problem in the firewall that ships as part of Windows XP Service Pack 2. Users who installed SP2 on their Windows XP machines and also have file and printer sharing enabled may have been sharing their files and printers with the entire Internet, according to Microsoft. IDG News Service, 12/17/04.
https://www.nwfusion.com/news/2004/1217microfixes.html?nl
More information from Microsoft:
https://support.microsoft.com/kb/886185
**********
KDE warns of privacy hole
According to an alert from KDE, “When creating a link to a remote file from various applications including Konqueror, the resulting URL may contain the authentication credentials used to access that remote resource.” For more, go to:
https://www.kde.org/info/security/advisory-20041209-1.txt
KDE patches Konqueror
A flaw in the way Websites are loaded into a window or tab by Konqueror could be exploited to serve pages from an non-trusted source that are wrapped by a legitimate page. Attackers could use this to steal information from an unsuspecting user. For more, go to:
https://www.kde.org/info/security/advisory-20041213-1.txt
Related fix:
Mandrake Linux:
https://www.nwfusion.com/go2/1220bug1a.html
https://www.mandrakesoft.com/security/advisories?name=MDKA-2004:057
**********
Debian patches libXpm
An attacker could use a specially crafted XPM image to gain elevated privileges on the affected machine. For more, go to:
https://www.debian.org/security/2004/dsa-607
**********
iDefense warns of flaw in xzgv
An integer overflow in xzgv, a image thumbnail viewer for Linux, could be exploited by an attacker to run any code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/1220bug1b.html
Related fix:
Debian:
https://www.debian.org/security/2004/dsa-608
**********
Samba vulnerability patched
A flaw in Samba could be exploited to run arbitrary code on an affected machine. Multiple Linux flavors are impacted by this problem. For more, go to:
Gentoo:
https://security.gentoo.org/glsa/glsa-200412-13.xml
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.054-samba.html
Related iDefense advisory:
https://www.idefense.com/application/poi/display?id=165
**********
Gentoo releases patch for File
According to an alert from Gentoo, “The code for parsing ELF headers in File contains a flaw which may allow an attacker to execute arbitrary code.” For more, go to:
https://security.gentoo.org/glsa/glsa-200412-07.xml
**********
Fix for PHP available
A number of security flaws have been patched in the 4.3.10 maintenance release of PHP. An attacker, either local or remote, may exploit the flaws to run arbitrary commands on an affected machine. For more, go to:
OpenPKG:
https://www.openpkg.org/security/OpenPKG-SA-2004.053-php.html
Mandrake Linux:
https://www.nwfusion.com/go2/1220bug1c.html
**********
Today’s roundup of virus alerts:
W32/Forbot-CY – This worm installs “NAVSSE.exe” in the Windows System directory and allows backdoor access via IRC. It can be used to steal CD keys, launch denial-of-service attacks or act as a proxy. (Sophos)
W32/Forbot-BI – Similar to Forbot-CY, except this one uses the file “systemproc.exe” as its infection point. (Sophos)
W32/Forbot-DA – This variant installs the file “HP_DeskJet_500.exe” and creates the registry entry “Level.Kicks-Ass.Org”. (Sophos)
W32/Forbot-EQ – The fourth Forbot variant of the week. This one can be used for a number of malicious purposes after installing the file “mpsvc.exe” in the Windows System folder. (Sophos)
W32/Protoride-Z – Another worm that spreads via network shares, copying itself to the file “rdpty6.7.6.exe” in the Windows System folder. It seems to run as a background process, allowing backdoor access via IRC. (Sophos)
W32/Atak-I – An Atak variant that tries to hide itself in a holiday-related message. The infected attachment will have a ZIP, PIF, COM, SCR or BAT extension. It harvests e-mail addresses from a variety of file types and drops the file “dec25.exe” in the Windows System folder. (Sophos)
W32/Rbot-RR – A Trojan horse that spreads via network shares, installing “iexplorerupdt.exe” in the Windows System folder. The virus allows backdoor access via IRC. (Sophos)
W32/Rbot-RW – This Rbot variant drops the file “servicsmjr.exe” after spreading through network shares by exploiting one of the many common Windows vulnerabilities. It can be used for a number of malicious purposes. (Sophos)
W32/Delf-JB – A nasty little Windows virus that attempts to terminate certain applications then adds itself to any executable file it can find on the infected machine. (Sophos)
W32/Wort-D – Spreads between machines by attempting to exploit the LSASS vulnerability. No word on what damage it may cause once it infiltrates a target. (Sophos)
W32/Oddbob-A – Another worm that exploits the Windows’ LSASS vulnerability as it spreads via network shares. It uses a random file name, but creates a service process called “NetDDEipx”. (Sophos)
**********
From the interesting reading department:
DJB Announces 44 Security Holes In *nix Software
Generationxyu writes “D. J. Bernstein, better known as DJB, has announced the discovery of 44 security holes that were found by students in his course MCS 494: Unix Security Holes this fall at the University of Illinois at Chicago. Vulnerable programs of note include: CUPS, NASM, mpg123, MPlayer, xine-lib, and numerous others. Copies of the notification emails are here. The homework for the course was to find and exploit 10 previously undiscovered security holes in currently deployed Unix software. In a class of 25, 44 security holes seems a bit low. Most of the class failed. I was credited with bsb2ppm (actually libbsb) and jpegtoavi. After 300 hours of work and an A average on the exams, I expect to fail the course.” Slashdot, 12/15/04.
https://it.slashdot.org/article.pl?sid=04/12/15/2113202
Clear Choice Test: Spam in the Wild, The Sequel
How big can a test get? We found out with our latest in-depth look at the anti-spam industry. Spam is still a huge problem, and there is an equally large market opportunity to fix it. Network World, 12/20/04.
https://www.nwfusion.com/reviews/2004/122004spampkg.html
Small firms struggle with WLAN security
InterLink’s LucidLink security software provides enterprise-level network security and access control but hides the configuration details behind a handful of easy setup screens. Network World, 12/20/04.
https://www.nwfusion.com/net.worker/news/2004/122004netlead.html?nl
Nortel working on new security routers
Nortel is working on security routers for businesses looking to move away from dedicated, stand-alone security hardware to software and hardware combinations incorporated in switches, routers and even desktops. Network World, 12/20/04.
https://www.nwfusion.com/news/2004/122004switchsecurity.html?nl
User group to reveal model for IS security future
An influential user group is nearing release of a blueprint for a policy-based security architecture it hopes will become an industry model for securing corporate information systems. Network World, 12/20/04.
https://www.nwfusion.com/news/2004/122004-nac-security.html?nl
Hacker in Lowe’s case sentenced to nine years
Two 21-year-old Michigan men were sentenced– one to nine years and one to 26 months in federal prison – for conspiring to hack into the IT systems of national home center chain Lowe’s Companies Inc. and stealing customer credit card information. Computerworld, 12/17/04.
https://www.nwfusion.com/news/2004/1217hackerlowe.html?nl
In depth: VPNs on the cheap
Charles Duffy needed a no-cost way of building a VPN to link his company’s remote quality-assurance and IT staff to the corporate headquarters at Catalis Health in Austin, Texas. Network World Fusion, 12/17/04.
https://www.nwfusion.com/news/2004/1217vpncheap.html?nl
New IE hole could perfect phishing scams
A newly reported security problem in Microsoft’s Internet Explorer Web browser allows attackers to create a fake Web site that looks exactly like a genuine site. The vulnerability lets an attacker display any Web site while the address bar in IE will display a trusted Web address, for example https://www.paypal.com/, and even show the icon indicating SSL security, security researchers warned on Thursday. IDG News Service, 12/17/04.
https://www.nwfusion.com/news/2004/1217phish.html?nl
Symantec-Veritas deal blends security, storage mgmt. well, analysts say
Symantec’s announcement Thursday that it would acquire storage management vendor Veritas Software for $13.5 billion won praise from analysts who noted that Symantec would now become the largest supplier of backup, recovery and archiving software. Network World Fusion, 12/16/04.
https://www.nwfusion.com/news/2004/1216symanwill.html?nl
Editor’s Note: This is our last scheduled issue of 2004. We’ll be back at the helm on January 3, 2005. Happy Holidays and Happy New Year to all!




