Friday, February 20, 2009

Around The Horn vol.1,45

Alerts

2:45 AM (3 hours ago)

New BackDoor Attacks Using PDF Documents

from McAfee Avert Labs by Geok Meng Ong

Needless to further remind everyone, zero-day attacks are the preferred choice of cyber criminals and will continue to be so in 2009. If the recent W32/Conficker.worm (MS08-087) and Exploit-XMLhttp.d (MS08-078, MS09-002) were not good enough to prove our point, here is another one.

4:46 AM (1 hour ago)

Conficker worm gets an evil twin

from Network World on Security by Robert McMillan

The criminals behind the widespread Conficker worm have released a new version of the malware that could signal a major shift in the way the worm operates.

Security News

2:31 AM (4 hours ago)

How the Feds shook hands with an internet pedophile

from The Register - Security

Crime and punishment in the digital age

As former moderators for an internet relay channel dedicated to hacking, Francine Campbell and Sterlin Ward have seen some of the net's darker quarters. But nothing prepared them for their group's encounter with an internet pedophile who called himself Digerati.…

 

9:31 PM (9 hours ago)

New in-the-wild attack targets fully-patched Adobe Reader

from The Register - Security

Locked and loaded

Security watchers are warning of a serious unpatched vulnerability in Adobe's Reader program that's actively being exploited to install malware on the PCs of unsuspecting users.…

12:34 AM (6 hours ago)

Phishing with a small twist, (Fri, Feb 20th)

from SANS Internet Storm Center, InfoCON: green

A reader sent this through to us (thanks) and it has an interesting little twist. The message ...(more)...

12:34 AM (6 hours ago)

MS09-002, XML/DOC and initial infection vector, (Thu, Feb 19th)

from SANS Internet Storm Center, InfoCON: green

The MS09-002 exploit that we posted a diary about two days ago (http://isc.sans ...(more)...

Thursday, February 19, 2009

Around The Horn vol.1,44

Alerts

9:04 PM (1 minute ago)
Adobe/Acrobat 0-day in the wild?, (Fri, Feb 20th)

from SANS Internet Storm Center, InfoCON: green
According to our friends over at Shadowserver, There is a new Acrobat 0-day in the wild. They ...(more)...

4:29 PM (4 hours ago)
MS09-002, XML/DOC and initial infection vector, (Thu, Feb 19th)

from SANS Internet Storm Center, InfoCON: green
The MS09-002 exploit that we posted a diary about two days ago (http://isc.sans ...(more)...

9:09 AM (11 hours ago)
Denial of Service against Time Warner (San Diego)?, (Thu, Feb 19th)

from SANS Internet Storm Center, InfoCON: green
We've had unconfirmed reports this morning of a Denial of Service against the DNS servers for Time W ...(more)...

Security News

6:54 PM (2 hours ago)
Practical Example of csSQLi Using (Google) Gears Via XSS

from CGISecurity - Website and Application Security News by Robert A.
"Yesterday, at the Blackhat DC security conference, I spoke about the dangers of persistent web browser storage. Part of the talk focused on how emerging web browser storage solutions such as Gears (formerly Google Gears) and the Database Storage functionality included in the emerging HTML 5 specification, could be attacked on...

1:36 PM (7 hours ago)
Bot Busts Newest Hotmail CAPTCHA

from CGISecurity - Website and Application Security News by Robert A.
"The botnet, or collection of compromised PCs, can decipher Live Hotmail's CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) registration safeguard in about 20 seconds, said Websense Inc. security researcher Sumeet Prasad.CAPTCHA is the term for the distorted characters that many Web sites, such as e-mail services...

12:36 PM (8 hours ago)
Wikileaks Accidentially Leaks Its Donor List

from CGISecurity - Website and Application Security News by Robert A.
"What's Wikileaks, the net's foremost document leaking site, supposed to do when a whistle-blower submits a list of email addresses belonging to the site's confidential donors as a leaked document? That's exactly the conundrum Wikileaks faced this week after someone from the controversial whistle-blowing site sent an emergency fund-raising appeal on...

Feb 18, 2009 (yesterday)
MS09-002 exploit in the wild

from CGISecurity - Website and Application Security News by Robert A.
Sans is reporting the MS09-002 exploit is in the wild."Several AV vendors reported about MS09-002 exploits in the wild. We can confirm this – the exploit for the CVE-2009-0075 vulnerability (Uninitialized Memory Corruption) in Internet Explorer 7 is definitely in the wild and working as charm on an unpatched Windows XP...

Feb 17, 2009 (2 days ago)
Top-10 Vulnerability Discoverers of All Time (as well as 2008)

from CGISecurity - Website and Application Security News by Robert A.
"Who discovers the most security vulnerabilities? That’s one of the more frequent questions I’ve encountered over the past few years. Funnily enough there’s usually a high correlation between the timing of my being asked and the latest marketing blitzkrieg customers may have encountered (not from IBM of course). It seems that...

2:31 PM (6 hours ago)
US feds pull travel site offline after hacker break-in

from The Register - Security
GovTrip trips up
A travel reservations website used by US government agencies remains offline more than a week after it was infected with malware that tried to install malicious code on the PCs of those who visited the site.…

11:31 AM (9 hours ago)
Grifters punt 'get rich quick' scams at Facebook users

from The Register - Security
Social networking marks made an offer you can refuse
Grifters are using Facebook to lend credibility to an elaborate get rich quick scam designed to trick punters into handing over credit card details.…

8:30 AM (12 hours ago)
Laptop facial recognition defeated by Photoshop

from The Register - Security
Taking a long hard stare at biometric security
White hat security researchers have demoed how to bypass the facial recognition systems on several laptops.…

7:30 AM (13 hours ago)
Pirate Bay supporters ram Swedish IFPI website

from The Register - Security
'We're winning, stop hacking plz'
Pirate Bay co-founder Peter Sunde has pleaded with fans to stop attacking official entertainment industry websites after the Swedish wing of the The International Federation of the Phonographic Industry’s (IFPI) site was hacked yesterday.…

6:30 AM (14 hours ago)
Cybercrime losses tax UK small business

from The Register - Security
Exposed SMEs call for reporting security blanket
Cybercrime and fraud are costing Britain's small business £800 a year each, according to a survey by the UK's Federation of Small Businesses (FSB).…

10:31 AM (10 hours ago)
Romeo 419ers take Canadian women for $300k

from The Register - Security
Lonely hearts, empty wallets
Nigerian fraudsters have relieved a number of Edmonton women of a total of $300,000 in what the local Sun describes as "an online dating scam".…

1:30 AM (19 hours ago)
Hacker pokes new hole in secure sockets layer

from The Register - Security
Moxie Marlinspike's man-in-the-middle
Website encryption has sustained another body blow, this time by an independent hacker who demonstrated a tool that can steal sensitive information by tricking users into believing they're visiting protected sites when in fact they're not.…

Feb 18, 2009 (yesterday)
Google gears Gmail for PC hack attack

from The Register - Security
'Offline' web apps exposed
Over the past year, dozens of web-based services have adopted new features that allow them to be used even when an internet connection isn't available. The technologies making this possible may offer plenty of convenience, but they also make end users susceptible to powerful new attacks, a security researcher warns.…

Feb 18, 2009 (yesterday)
Using Group Policy to Negate Conflicker on Windows

from WindowSecurity.com by (Derek Melber)
Different methods you can use to help secure a desktop from being infected with the ConFlicker worm.

3:47 PM (5 hours ago)
Hacker claims SQL bug on Symantec site

from Network World on Security by Robert McMillan
A Romanian hacker who has spent the past few weeks exposing a common, but dangerous, Web programming error on security vendors Web sites says he's found a SQL injection flaw on Symantec's Web site. But Symantec says it's not a security issue.

3:47 PM (5 hours ago)
DHS names Callahan privacy chief

from Network World on Security by Ellen Messmer
The Department of Homeland Security Thursday named Mary Ellen Callahan as the department's Chief Privacy Officer.

3:47 PM (5 hours ago)
Cloud security fears are overblown, some say

from Network World on Security by James Niccolai
It may sound like heresy to say it, but it's possible to worry a little too much about security in cloud computing environments, speakers at IDC's Cloud Computing Forum said on Wednesday.

3:47 PM (5 hours ago)
Pirate Bay supporters hack Swedish IFPI Web site

from Network World on Security by Jeremy Kirk
Hackers defaced the International Federation of the Phonographic Industry's (IFPI) Swedish Web site on Wednesday as The Pirate Bay trial continued.

3:47 PM (5 hours ago)
Researchers detail Intel TXT hacks at Black Hat

from Network World on Security by Jaikumar Vijayan
Two security researchers fleshed out details Wednesday at the Black Hat conference in Washington of a method they disclosed earlier this year for circumventing Intel's new Trusted Execution Technology (TXT) security software.

3:47 PM (5 hours ago)
The Ultimate Browser Security Face-Off

from Network World on Security by Tom Kaneshige
The Web is teeming with venomous exploits. And an ever-increasing quantity of that malware sneaks onto hard drives via the browser.

3:47 PM (5 hours ago)
The case for flat-rate services

from Network World on Security by Steve Taylor and Jim Metzler
As we look at today's economic landscape, only one thing seems scarier than controlling expenses, and that is having unpredictable expenses. For that reason, we expect lots of services that have traditionally been usage based to be even more attractive if offered as a flat-rate service.

3:47 PM (5 hours ago)
Guidelines for securing IEEE 802.11i wireless networks

from Network World on Security by M. E. Kabay
A useful free document, one not requiring registration and having 162 pages, is "Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i," which is Special Publication 800-97 from the National Institute of Standards and Technology.

3:47 PM (5 hours ago)
Bangkok upgrades surveillance network at Chinatown

from Network World on Security by Carol Ko
The Bangkok government is now operating a 24-hour video surveillance network in the city's Chinatown for public safety and traffic management.

3:47 PM (5 hours ago)
NAC market continues to evolve

from Network World on Security by Tim Greene
The NAC market continues to evolve, including the necessary and sometimes painful process of consolidation.

7:01 AM (14 hours ago)
Satellite Feed Hacking - Your Data Isn’t Private!

from Darknet - The Darkside by Darknet
Hardware hacking is an interesting area and something not too many people get into as the soldering irons, capacitors and chipsets seem daunting. I did have a play around with cable boxes and satellite feeds in my earlier years and was surprised to find how insecure they were. Most traffic is transmitted unencrypted, the stuff that [...]Read the full post at darknet.org.uk

Feb 18, 2009 (yesterday)
Fast-Track 4.0 - Automated Penetration Testing Suite

from Darknet - The Darkside by Darknet
The latest big buzz is Fast-Track released recently at ShmooCon by Securestate, basically Fast-Track is an automated penetration suite for penetration testers. For those of you new to Fast-Track, Fast-Track is a python based open-source project aimed at helping Penetration Testers in an effort to identify, exploit, and further penetrate a network....Read the full post at darknet.org.uk

3:29 PM (5 hours ago)
Sourcefire VRT posts some interesting Conflickr Analysis, (Thu, Feb 19th)

from SANS Internet Storm Center, InfoCON: green
Just wanted to put out an article from a few friends of mine at the Vulnerability Research Team at S ...(more)...

4:10 PM (4 hours ago)
News: Advisor: U.S. needs policy to defend cyberspace

from SecurityFocus News
Advisor: U.S. needs policy to defend cyberspace

1:11 PM (7 hours ago)
Brief: Kaminsky calls for DNSSEC deployment

from SecurityFocus News
Kaminsky calls for DNSSEC deployment

Feb 18, 2009 (22 hours ago)
Brief: Man-in-the-middle attack sidesteps SSL

from SecurityFocus News
Man-in-the-middle attack sidesteps SSL

12:02 AM (21 hours ago)
Black hat, blank face: researchers crack biometric scanners

from Ars Technica - Front page content by nate@arstechnica.com (Joel Hruska)

Biometric systems have been touted as the next big thing in computer security for the past several years, despite the fact that some of them—fingerprint scanners, for example—have proven to be incredibly easy to bypass, requiring little more, in some cases, than some scotch tape and a bit of patience. Facial-recognition scanners have been a hot commodity on laptops of late, but researchers scheduled to present at the ongoing Black Hat DC conference this week have demonstrated that current implementations have flaws of their own.

9:27 PM (12 minutes ago)
Group Spots Giant Hacks by Combing Small Newspapers

from Wired Top Stories by Kim Zetter
A volunteer group of security researchers and ex-hackers track diverse sources for info on consumer data spills. Logging more than 394 million records lost or compromised in 1,700 incidents, they sometimes spot major breaches before the company at fault warns the public.

6:08 PM (3 hours ago)
IFPI Site Hacked to Protest Pirate Bay Trial

from Wired Top Stories by David Kravets
Hackers protesting the Pirate Bay trial in Stockholm break into the Swedish website of the International Federation of the Phonographic Industry's website to show their displeasure.

5:01 PM (4 hours ago)
Hacker Claims SQL Bug on Symantec Site

from PC World Latest Technology News
Symantec is the latest company to fall prey to a Romanian hacker who has been finding SQL injection bugs in security sites.

4:01 PM (5 hours ago)
Computer Thefts Prompt Los Alamos Security Review

from PC World Latest Technology News
The Los Alamos National Laboratories has launched a month-long project aimed at ensuring that offsite computer systems fully comply with the institution's information security policies.

4:01 PM (5 hours ago)
Fugitive Hacker Indicted for Running VoIP Scam

from PC World Latest Technology News
Just days after his apprehension in Mexico following two years on the run from law enforcement authorities, an alleged hacker...

4:01 PM (5 hours ago)
Researchers Detail Intel TXT Hacks at Black Hat

from PC World Latest Technology News
Two security researchers fleshed out details at the Black Hat conference in Washington this week of a method for circumventing Intel's Trusted Execution Technology security software.

4:01 PM (5 hours ago)
Hackers Break Into Government Travel Site

from PC World Latest Technology News
A travel reservations Web site used by several federal agencies was hacked last week, and shunted unsuspecting users to a malicious domain.

12:54 AM (21 hours ago)
Cloud Security Fears Are Overblown, Some Say

from PC World Latest Technology News
Concerns about the security of cloud computing services may be overstated, panelists at IDC's Cloud Computing Forum said.

Feb 18, 2009 (yesterday)
Hackers Steal Thousands of Wyndham Credit Card Numbers

from PC World Latest Technology News
Criminals stole tens of thousand of credit card numbers from Wyndham Hotels and Resorts after hacking into a computer.

9:50 PM (13 minutes ago)
Conficker Worm Gets an Evil Twin

from PC World Latest Technology News
Researchers have spotted a new variant of the Conficker worm, dubbed Conficker B++.

Other News

Intel Eyes Cloud Computing With New Hardware, Software

from PC World Latest Technology News
Intel earlier this week pitched hardware improvement that could boost performance of a cloud while cutting energy costs.

Tuesday, February 17, 2009

Around The Horn vol.1,43

Alerts

3:05 PM (6 hours ago)
MS09-002 exploit in the wild, (Tue, Feb 17th)

from SANS Internet Storm Center, InfoCON: green
Several AV vendors reported about MS09-002 exploits in the wild. We can confirm this the exp ...(more)...


6:29 PM (3 hours ago)
MS09-002 Exploit in the wild uses MSWord Lure

from McAfee Avert Labs by Rahul Mohandas
An exploit found to be targeting a recently patched vulnerability for Internet Explorer 7 was discovered in-the-wild. Malware crooks were quick to develop a working exploit for the vulnerability in Internet Explorer 7, which was part of the February Microsoft patch release. Microsoft rated this vulnerability critical with the possibility of a consistent exploit code. The modus operandi bears close resemblance to the zero-day attack using word documents, we blogged about in December 2008.

6:41 PM (3 hours ago)
New attacks on IE7 go wild

from The Register - Security Info-stealing software remotely installedCybercriminals have begun attacking a critical hole that Microsoft patched in its Internet Explorer 7 browser last week, corroborating the company's warning that the vulnerability would be easy to exploit.…

Security News

3:41 PM (6 hours ago)
IP security shortcomings unpicked

from The Register - Security
UK infrastructure watchdog issues RFC
The UK's Centre for the Protection of National Infrastructure has completed a study on the TCP protocol that underpins intenet communications.…

9:32 AM (12 hours ago)
Holy cow! The infrastructure has gone critical

from The Register - Security
Three papers for big organisations
And so to the Reg Library to unfurl some big IT blueprints for big organisations. Without further ado we kick off with Secure Computing, which knows how to get our attention - it cites a Reg article in its paper.…

9:32 AM (12 hours ago)
Sun wades into key management kerfuffle

from The Register - Security
Encryption standards soup thickens
Sun has thrown its open source key management ideas into the key management standards giant brandy glass, offering license-free management that it hopes will become an industry standard.…

9:48 PM (8 minutes ago)
Anthony Giandomenico, Security Hero

from SANS Technology Institute - Security Laboratory
Anthony Giandomenico weighs in on Data Loss/Data Leakage Protection (DLP).

5:38 PM (4 hours ago)
John Pirc, IBM, ISS Product Line & Services Executive: Security and Intelligent Network

from SANS Technology Institute - Security Laboratory
John Pirc from IBM's Network Security Solutions has agreed to be interviewed by the Securitylab; we certainly thank him for giving us his time to discuss security and the Intelligent Network.

3:02 PM (6 hours ago)
Cisco bakes software security into new Linksys routers

from Ars Technica - Front page content by nate@arstechnica.com (Joel Hruska)

Linksys/Cisco announced Tuesday that it's teaming up with online security provider Trend Micro to offer a router with a suite of malware protection tools baked into the device itself. Hardware-based firewalls are nothing new, but the duo claims that the new service—dubbed Home Network Defender—will offer an unsurpassed level of intrusion tracking and detection, all while lifting the computing burden off of your PC. That first claim may be accurate, but a close look at the fine print indicates PCs won't be unburdened anytime soon.

7:30 PM (2 hours ago)
Top 9 Dirty Tricks Scammers Use

from PC World Latest Technology News
Beware the outlandish come-ons and pick-up lines you'll encounter when criminals are on the prowl.

7:30 PM (2 hours ago)
New Attacks Target IE7 Flaw

from PC World Latest Technology News
A bug patched just last week in Internet Explorer 7 is under assault. Make sure you have the fix.

7:30 PM (2 hours ago)
Cisco, Trend Micro Put Security in Home Routers

from PC World Latest Technology News
Cisco and Trend Micro teamed up to build an Internet security service into some home Wi-Fi routers

2:52 PM (7 hours ago)
New Attack Singles out IE Flaw

from PC World Latest Technology News
Trend Micro says it has spotted the first online attack based on a critical IE bug, patched last Tuesday

12:51 PM (9 hours ago)
Mobile Security: A Busy, Buggy Week

from PC World Latest Technology News
Security flaws hit Android, RIM, and MobileMe users, but fixes are available.

12:51 PM (9 hours ago)
Hackers Attack Antivirus Firm's Tech Support Site

from PC World Latest Technology News
A Kaspersky Lab technical support site was hacked late last month, exposing private customer information for 11 days.

12:51 PM (9 hours ago)
Forensics Firm Finds Private Data on Drives Sold on EBay

from PC World Latest Technology News
A New York computer forensics firm said that 40 of 100 hard disk drives it recently purchased in bulk orders on eBay contained personal data.

12:51 PM (9 hours ago)
Norton Online Family Gives Parents New Tools to Monitor Kids

from PC World Latest Technology News
Symantec's Norton consumer division Tuesday introduced the beta version of a product intended to let parents monitor children's online activities.

11:51 AM (10 hours ago)
Norton Online Family Safety Service Launches

from PC World Latest Technology News
Symantec has announced the public beta launch of Norton Online Family, a new Internet safety service that's compatible with...

Other News

10:03 PM (9 minutes ago)
Return from Hyperlinks in Word

from PC Magazine Tips and Solutions
Want to arrange your Word 2007 document so that a reader can use a hyperlink and then return direct to the hyperlink last used? Read this tip to learn how.

10:03 PM (9 minutes ago)
Lost "Follow Up" Folder in Outlook

from PC Magazine Tips and Solutions
How to recover your For Follow Up folder in Outlook.

-- Aurora Report says more site updates tonight plus look there was some news today, oh my!

Monday, February 16, 2009

Around The Horn vol.1,42

Alerts

SB09-047: Vulnerability Summary for the Week of February 9, 2009

from US-CERT Cyber Security Bulletins
Vulnerability Summary for the Week of February 9, 2009

1:20 PM (6 hours ago)
Internet Routing Issues, (Mon, Feb 16th)

from SANS Internet Storm Center, InfoCON: green
Several readers have reported difficulty in reaching parts of the Internet today. The source o ...(more)...

10:04 PM (8 hours ago)
McAfee 2009 Mobile Security Report, (Tue, Feb 17th)

from SANS Internet Storm Center, InfoCON: green
We received notice of the 2009 McAfee Mobile Security Report today from our fellow SANS collegues, s ...(more)...

Security News

12:28 PM (7 hours ago)
Obama's BlackBerry still hackable, warns Mitnick

from The Register - Security
You'd be a nut to try and crack it
President Obama's 'bullet-proof' BlackBerry might still be cracked, according to uber-hacker Kevin Mitnick.…

2:29 PM (5 hours ago)
Hackers: BitDefender site exposes private data (yet again)

from The Register - Security
Second time in seven days
Updated Romanian hackers have discovered a security flaw in the website of anti-virus provider BitDefender. They said it was the second time in a week the company has inadvertently exposed a database that is supposed to remain private.…

12:21 AM (6 hours ago)
DShield Web Honeypot - Alpha Preview Release, (Tue, Feb 17th)

from SANS Internet Storm Center, InfoCON: green
The attack dynamics had significantly changed since DShield went into service 8 years ago. Web attac ...(more)...

9:03 PM (9 hours ago)
MS09-002 - Critical: Cumulative Security Update for Internet Explorer (961260) - Version:1.1

from Microsoft Security Content: Comprehensive Edition
Severity Rating: Critical - Revision Note: V1.1 (February 16, 2009): Added a link to Microsoft Knowledge Base Article 961260 under Known Issues in the Executive Summary.Summary: This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

6:32 AM (8 minutes ago)
UK childcare voucher site offline after security snafu

from The Register - Security
Busy Bees stung by breach
A UK childcare voucher scheme has admitted that confidential customer data was briefly left exposed to other users during an upgrade last week, but denied suggestions that any sensitive information leaked as a result.…

12:30 AM (6 hours ago)
Satellite-hacking boffin sees the unseeable

from The Register - Security
Lady Di gossip plucked from sky
White-hat hacker Adam Laurie knows better than to think email, video-on-demand, and other content from Sky Broadcasting and other satellite TV providers is a private matter between him and the company. That's because he's spent the past decade monitoring satellite feeds and the vast amount of private information they leak to anyone with a dish.…

11:30 PM (7 hours ago)
MySQL daddy juices Finnish security firm

from The Register - Security
Wot? A SQL injection of cash?
MySQL creator Michael "Monty" Widenius is injecting some venture capital and executive experience into a Finnish firm that makes a community-driven security add-on for browsers.…

5:02 AM (1 hour ago)
NSA Together With Mitre CWE and SANS Identifies Top 25 Programming Errors

from Darknet - The Darkside by Darknet
Secure programming is a huge issue and it’s the lack of it that causes all the problems we have with vulnerabilities and the exploits associated with them. If everywhere developers followed secure programming practices we wouldn’t have buffer overflow issues or unsanitized parameters leading to SQL Injection. The NSA (National Security...

-- Aurora Report says well it has been a relatively quiet few days and we hope we are not missing anything. For now we are content to enjoy the relative solace the quietude embues. We made several changes to the blog today so we'll see how it goes over.

-- Updated 2/17/2009 still pretty quite on the western front added 6 security interest pieces 1 sorta new alert.

Sunday, February 15, 2009

Around The Horn vol.1,41

Alerts

Microsoft Time Sync Appears to Down , (Sat, Feb 14th)

from SANS Internet Storm Center, InfoCON: green
We have received several reports today of Microsoft's Time Server being unreachable at time.microsof ...(more)...


Security News

8:02 PM (11 hours ago)
Debit Card Compromise Letter, (Sat, Feb 14th)

from SANS Internet Storm Center, InfoCON: green
Well for the second time in 4 months I have received a letter from my bank indicating that their Cre ...(more)...

7:40 PM (11 hours ago)
Not Among Friends: The Dangers of Social Networks

from PC World Latest Technology News
From sabotage to phishing, security risks to simple time-wasting, social networks are a hotbed of hazards.

Feb 14, 2009 (19 hours ago)
Mac OS X Gets Huge Security Update

from PC World Latest Technology News
Apple issued multiple updates for Mac OS X and Java, patching 55 bugs, including one for Safari.

Feb 14, 2009 (20 hours ago)
Florida Arrests 3 in Heartland Breach

from PC World Latest Technology News
The first arrests have been made in connection with the recently disclosed breach at Heartland Payment Systems.

6:53 PM (11 hours ago)
Does Microsoft's Patch Tuesday Need Fixing?

from PC World Latest Technology News
Release of security patches on a regular basis is handy for planning, but does Microsoft's schedule keep up with security threats?

Feb 15, 2009 (15 hours ago)
Many Brits Too Scared to Shop Online

from PC World Latest Technology News
Security concerns are keeping more than 40 percent of Britons from buying from online stores, a study says.

Saturday, February 14, 2009

Around The Horn vol.1,40

Alerts

7:02 PM (11 hours ago)
Canada Calling, (Fri, Feb 13th)

from SANS Internet Storm Center, InfoCON: green
A reader wrote in to ask about the uptick in port 5060 activity (visible here: isc.sans ...(more)...

Security News

Feb 12, 2009 (2 days ago)
Paraskavedekatriaphobia and something I haven't found a word for, (Fri, Feb 13th)

from SANS Internet Storm Center, InfoCON: green
Today is Friday the 13th, and also the day when we reach the symbolic 1234567890th second of Unix ti ...(more)...

Feb 13, 2009 (yesterday)
Third party information on conficker, (Fri, Feb 13th)

from SANS Internet Storm Center, InfoCON: green
(This will be updated as more information becomes public) In an effort to provde YOU the enduser t ...(more)...

Feb 12, 2009 (2 days ago)
We want your logs, obfuscated even., (Fri, Feb 13th)

from SANS Internet Storm Center, InfoCON: green
We always have a banner up on the webpage that says We want your logs or How to su ...(more)...

12:56 AM (6 hours ago)
Defacement archive Zone-h gets defaced

from CGISecurity - Website and Application Security News by Robert A.
"Defacement archive Zone-h.org has itself been defaced. The hack - claimed in the names of Cyber-Terrorist, HeLL cYbEr, and Jurm - involved posting a link to a YouTube video and dancing babies on the site's altered home page. The Arab language video, featuring an ad promoting nappies, replaced the site's usual...

12:56 AM (6 hours ago)
Security Vendor Kasperky Hacked Via SQL Injection

from CGISecurity - Website and Application Security News by Robert A.
A security lapse at Kaspersky has exposed a wealth of proprietary information about the anti-virus provider's products and customers, according to a blogger, who posted screen shots and other details that appeared to substantiate the claims. In a posting made Saturday, the hacker claimed a simple SQL injection gave access to...

12:56 AM (6 hours ago)
PHP filesystem attack vectors

from CGISecurity - Website and Application Security News by Robert A.
ascii writes"On Apr 07, 2008 I spoke with Kuza55 and Wisec about an attack I found some time before that was a new attack vector for filesystem functions (fopen, (includerequire)[_once]?, file_(putget)_contents, etc) for the PHP language. It was a path normalization issue and I asked them to keep it “secret” [4],...

Feb 13, 2009 (16 hours ago)
Twitter attack exposes awesome power of clickjacking

from The Register - Security
Hard to stop, harder to resist
A worm that forced a wave of people to unintentionally broadcast messages on microblogging site Twitter shows the potential of a vulnerability known as clickjacking to dupe large numbers of internet users into installing malware or visiting malicious pages without any clue they're being attacked.…

Feb 13, 2009 (17 hours ago)
Defacement archive Zone-h gets defaced

from The Register - Security
Web graffiti attack harks back to age of innocence
Defacement archive Zone-h.org has itself been defaced.…

Feb 13, 2009 (18 hours ago)
Kaspersky breach: No user info lifted, auditor confirms

from The Register - Security
But data was exposed
No customer information was accessed during last weekend's breach of a Kaspersky website, an independent auditor has concluded, confirming the results of an internal investigation conducted earlier by members of the anti-virus firm.…

Feb 13, 2009 (19 hours ago)
Wanna see how to use Win 7 UAC to pwn a PC?

from The Register - Security
Just press play...
White hat hackers have created a proof of concept demo illustrating how improved User Account Control (UAC) features in Windows 7 might be completely bypassed.…

Feb 13, 2009 (22 hours ago)
Serial security hackers hit F-secure

from The Register - Security
Sequel SQL assault
F-Secure admitted on Thursday that it had been hit by the same Romanian group that previously hit Kaspersky Lab and Bitdefender's reseller-run Portugese website over recent days.…

Feb 13, 2009 (yesterday)
McAfee sales strong despite recession

from The Register - Security
Security firm rides out economic storm
McAfee bucked the trend of poor financial news from the IT industry by posting strong results that exceeded analyst expectations on Thursday.…

Feb 13, 2009 (yesterday)
Microsoft Offers $250K Bounty for Conficker Author

from Darknet - The Darkside by Darknet
We did mention Conficker when it broke out back in January causing one of the largest scale infections ever seen (an estimated 9 million machines in just a few months). The latest news is that Microsoft are offering a bounty to catch the author of the malware, we have seen this back in 2003/4 (The Anti-virus [...]Read the full post at darknet.org.uk

Feb 13, 2009 (20 hours ago)
News: Cabal forms to fight Conficker, offers bounty

from SecurityFocus News
Cabal forms to fight Conficker, offers bounty

Feb 13, 2009 (15 hours ago)
Brief: Online thieves nab employee info from FAA

from SecurityFocus News
Online thieves nab employee info from FAA

Feb 13, 2009 (14 hours ago)
Why Google's Software Update Tool Is Evil

from Wired Top Stories by Scott Gilbertson
When Google Earth 5 was released last week, the Mac OS X version of the free desktop application came with an auto-updater that was installed on users' machines. The update tool runs in the background and can't be easily disabled — a tactic other software makers have long known is a huge no-no, and one some users are hopping mad about.

Feb 13, 2009 (18 hours ago)
With Global Effort, a New Type of Worm Is Slowed

from PC World Latest Technology News
There have been big computer worm outbreaks before, but nothing quite like Conficker

Thursday, February 12, 2009

Around The Horn vol.1,39

Alerts

5:19 PM (4 hours ago)
Apple Security Updates, (Thu, Feb 12th)

from SANS Internet Storm Center, InfoCON: green
Apple today released a number of security updates: 1 - Safari for Windows. This update will bring ...(more)...

Security News

5:54 PM (3 hours ago)
Security assessment of the Transmission Control Protocol (TCP)

from CGISecurity - Website and Application Security News by Robert A.
The following email was sent to Full Disclosure today. I haven't had a chance to read this monster 140 document yet but it sure sounds interesting."The TCP/IP protocol suite was conceived in an environment that was quitedifferent from the hostile environment they currently operate in.However, the effectiveness of the protocols led...

4:10 PM (5 hours ago)
F-Secure Hacked Via XSS, SQL injection

from CGISecurity - Website and Application Security News by Robert A.
"A Romanian hacker site said on Wednesday it was able to breach the website of Helsinki-based security firm F-Secure just as it had gained access to the sites of two other security companies earlier in the week. F-Secure is "vulnerable to SQL Injection plus Cross Site Scripting," an entry on the...

8:57 PM (33 minutes ago)
Kaiser Permanente breach leads to ID theft

from The Register - Security
Workers notified after police cuff suspect
Kaiser Permanente has admitted a breach of its employee records systems has resulted in incidents of identity theft.…

8:57 PM (33 minutes ago)
Apple update plugs over two dozen security vulns

from The Register - Security
Beefs OS X, Java, Safari for Windows
Apple has released a set of security updates that plug over two dozen holes in Mac OS X - including the Safari RSS vuln discovered last month - plus a vuln apiece in Java for Mac OS X 10.5, 10.4, and Safari for Windows.…

3:57 PM (5 hours ago)
Heartland data breach hit 160 banks (and rising)

from The Register - Security
How deep does the rabbit hole go?
More than 160 banks have been affected by the information security breach at US payment processor Heartland Security.…

3:57 PM (5 hours ago)
IBM, HP, and EMC call for encryption key juggler standard

from The Register - Security
Push unified protocol though open standards org
Any key management platform will be able to communicate across all of a company's encryption systems - if IBM, Hewlett-Packard, Thales, and EMC have their way.…

3:57 PM (5 hours ago)
MS puts up $250K bounty for Conficker author

from The Register - Security
Zombie masterminds wanted undead or alive
Microsoft is offering a $250,000 reward for information that leads to the arrest and conviction of the virus writers behind the infamous Conficker (Downadup) worm.…

11:38 AM (9 hours ago)
Scareware scammers Rickroll Digg

from The Register - Security
Bot comment blitz intensifies
Digg.com has become the latest Web 2.0 service to be abused by hackers in order to punt malware.…

9:38 AM (11 hours ago)
Win 7 and smartphones targeted in Pwn2own challenge

from The Register - Security
Hacker security shootout shindig
An annual hacking challenge has put the security of browsers and smartphones in the firing line.…

Feb 11, 2009 (23 hours ago)
New Windows virus attacks PHP, HTML, and ASP scripts

from The Register - Security
Virut gets around
Researchers have identified a new strain of malware that can spread rapidly from machine to machine using a variety of infection techniques, including the poisoning of webservers, which then go on to contaminate visitors.…

4:29 PM (5 hours ago)
IT, security funds find place in stimulus package

from Network World on Security by Jaikumar Vijayan
The massive economic stimulus package that is working through Congress includes hundreds of millions of dollars for various IT and physical security projects, including $448 million for a new headquarters for the U.S. Department of Homeland Security .

4:29 PM (5 hours ago)
HP, IBM push new OASIS encryption key standard

from Network World on Security by Robert McMillan
A group of industry vendors, led by IBM, Hewlett-Packard and EMC, is proposing a new standard to make their encryption management software work together.

4:29 PM (5 hours ago)
Microsoft puts $250,000 bounty on Conficker worm

from Network World on Security by Robert McMillan
Microsoft is trying to put some pressure on the criminals responsible for the worst Internet worm outbreak in years, offering a US$250,000 reward for information leading to the arrest and conviction of Conficker's creators.

4:29 PM (5 hours ago)
StillSecure on the fence about hosted NAC

from Network World on Security by Tim Greene
When StillSecure announced this week it will offer services as well as security gear, it was still on the fence about whether to include hosted NAC.

4:29 PM (5 hours ago)
NSA identifies top 25 programming errors

from Network World on Security by M. E. Kabay
The National Security Agency, working with MITRE Corp., SANS, and dozens of industry experts from many other organizations, has published a valuable list of the top 25 most dangerous programming errors.

4:29 PM (5 hours ago)
Los Alamos National Lab missing 67 computers

from Network World on Security by Jaikumar Vijayan
New Mexico-based Los Alamos National Laboratory (LANL) , the nation's leading nuclear weapons lab, once again finds itself the focus of concerns about potentially serious cybersecurity lapses.

7:40 PM (2 hours ago)
ID Theft: Yes, It Is the Hackers

from Wired Top Stories by Kevin Poulsen
A new report claims that lost or stolen wallets are responsible for most identity theft, and slams the media for blaming data breaches and other hack attacks. But the fine print in the report tells another story.

8:17 PM (1 hour ago)
Conficker Worm Draws a Counter-Attack

from PC World Latest Technology News
Microsoft, Symantec and others announce a heavy-hitter team to fight the Conficker worm, with a $250,000 reward..

6:16 PM (3 hours ago)
Apple Releases Security, Java Updates

from PC World Latest Technology News
Apple on Thursday released the first security update of 2009, the aptly named Security Update 2009-001. The update, which is...

6:16 PM (3 hours ago)
Twitter Clickjacking Attack Causes Post-Awards Annoyance

from PC World Latest Technology News
Just as Twitter Nation celebrates its first official Shorty Awards, so called Twitter clickjacking attacks are crashing the party.

6:16 PM (3 hours ago)
Enterprise, Orgs Unite to Stanch Downadup Worm

from PC World Latest Technology News
Task force is attempting to stop worm that is infecting nearly 2.2 million machines each day.
4:09 PM (5 hours ago)
Microsoft Puts $250,000 Bounty on Conficker Worm

from PC World Latest Technology News
Microsoft is offering a $250,000 reward for information leading to the conviction of the Conficker worm's author.

4:09 PM (5 hours ago)
Web Site: Number of Banks Affected by Heartland Breach Grows

from PC World Latest Technology News
The number of financial institutions that have said they were affected by the data breach disclosed last month by Heartland Payment Systems is growing.

12:16 PM (9 hours ago)
Hacker Challenge Takes Aim at Browsers, Smartphones

from PC World Latest Technology News
The hacking contest that has grabbed headlines two years running will take aim next month at browsers and smartphones...

10:16 AM (11 hours ago)
HP, IBM Push New OASIS Encryption Key Standard

from PC World Latest Technology News
HP and IBM are promoting a new encryption key management standard called KMIP.

Wednesday, February 11, 2009

Around The Horn vol.1,38

Alerts

6:55 PM (1 minute ago)
ProFTPd SQL Authentication Vulnerability exploit activity, (Wed, Feb 11th)

from SANS Internet Storm Center, InfoCON: green
We had a reader report seeing exploit attempts related to a new ProFTPd authentication vulnerability ...(more)...

Security News

2:50 PM (4 hours ago)
The Business Justification for Data Security

from SANS Information Security Reading Room
Category: Data Loss Prevention

2:24 PM (4 hours ago)
MS09-002 - Critical: Cumulative Security Update for Internet Explorer (961260) - Version:1.0

from Microsoft Security Content: Comprehensive Edition
Severity Rating: Critical - Revision Note: Bulletin published.Summary: This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

2:24 PM (4 hours ago)
Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution

from Microsoft Security Content: Comprehensive Edition
Revision Note: V2.0 (February 10, 2009): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-004 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-004. The vulnerability addressed is the Microsoft XML Core Services Vulnerability - CVE-2008-5416.

2:24 PM (4 hours ago)
Microsoft Security Advisory (960715): Update Rollup for ActiveX Kill Bits

from Microsoft Security Content: Comprehensive Edition
Revision Note: Advisory published.Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.

2:44 PM (4 hours ago)
Popular Security Website Hit By Big DDoS Attack

from CGISecurity - Website and Application Security News by Robert A.
"Several renowned white-hat hacker security sites have been hit during the past few days with a distributed denial-of-service attack (DDoS). Immunity, Milw0rm, and Packet Storm were in the clear as of this posting, but attackers were still hammering away at Metasploit. The attackers behind the DDoS -- which began on Feb....

1:44 PM (5 hours ago)
Putting Vulnerabilities in Perspective

from CGISecurity - Website and Application Security News by Robert A.
"AppSec Notes complains that Netflix has not fixed all of their CSRF vulnerabilities. You can no longer access account information, billing information, change shipping address, or anything of value, but you can still add movies to someone’s queue. This apparently still bothers the author who has a note of annoyance that...

5:38 PM (1 hour ago)
Fugitive VOIP hacker cuffed in Mexico

from The Register - Security
More than 10 million minutes hijacked
A fugitive hacker accused of illegally rerouting millions of dollars worth of VOIP calls through telecommuncations companies' networks has been apprehended in Mexico.…

2:37 PM (4 hours ago)
Hackintosh maker leaves web doors unlocked

from The Register - Security
'Enough junk to choke a horse'
Add Psystar to the growing list of companies that have have allowed sophomoric mistakes to jeopardize the security of their websites in recent days.…

11:35 AM (7 hours ago)
German Interior minister's website pwned in wiretap protest

from The Register - Security
Schäuble Schadenfreude
Lax password security allowed hackers to bust into the German interior minister’s website.…

8:35 AM (10 hours ago)
Obama orders 'root and branch' cybersecurity review

from The Register - Security
Reboot
President Obama has ordered a wide-ranging review of the US's cybersecurity defences.…

10:34 AM (8 hours ago)
What's new on the security front with Windows 7?

from WindowSecurity.com by deb@shinder.net (Deb Shinder)
Taking a look at Windows 7 security features and whether, from a purely security standpoint, it is worth the upgrade.

7:11 PM (6 minutes ago)
Security Pro: Redmond Should Sever IE's Ties to Windows

from PC World Latest Technology News
By cutting the connections, Microsoft could better protect users with more frequent browser patches.

11:30 AM (7 hours ago)
Identity Theft: It's Out of Your Hands

from PC Magazine Tips and Solutions
The most important thing you have is you, right? And online, you are your identity. If xyz.com doesn't value you enough to keep you safe, then does that company really deserve your business?

Other News

IT grows up: consortium launches new framework for IT
http://arstechnica.com/business/news/2009/02/it-grows-up-consortium-launches-new-framework-for-it.ars

A consortium of academic and business groups has launched the IT Capability Maturity Framework, a buzzword-heavy abstraction that provides a fascinating snapshot of a discipline in transition.
By Jon Stokes Last updated February 11, 2009 8:30

My Blog List