Security News Letter

July 5th, 2004

 

 

Back Home Up Next

   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here

Download eEye's Retina Vulnerability Scanner Here
 

 

 Kaspersky Anti-Virus: Install & Feel Safe!

Wireless Networks Continue to Bleed Data, Study Reveals

 New study says 80 percent of companies have at least some unsecured wireless traffic

by Mathew Schwartz 6/30/2004 Enterprise Systems

Are corporate networks bleeding secrets wirelessly? A new study by security company Red-M says 80 percent of companies have at least some unsecured wireless network traffic broadcasting corporate secrets beyond the company walls. In other words, someone within range with a wireless sniffer could intercept potentially sensitive information.

Red-M studied 100 global companies in a range of industries over the course of six months. Of those studied, education, manufacturing, paper and packaging, and food and beverage industries were particularly at risk. Electronics companies, followed by IT, fared slightly better, with about four out of five broadcasting data. Two-thirds of the banks and financial services institutions studied likewise broadcast data.

“Most businesses haven’t yet grasped the fact that once there is any sort of wireless device on their premises—and today you have to presume there is at least one device in your company—it acts as a point of insecurity by broadcasting company information over the airwaves,” says Red-M’s CEO, Karl Feilder. More....    

Are the Browser Wars Back?
How Mozilla's Firefox trumps Internet Explorer.
By Paul Boutin, Slate
Posted Wednesday, June 30, 2004, at 11:03 AM PT 
I usually don't worry about PC viruses, but last week's Scob attack snapped me awake. The clever multi-stage assault, carried out by alleged Russian spam crime lords, infiltrated corporate Web servers and then used them to infect home computers. The software that Scob (also known as Download.ject) attempted to install on its victims' machines included a keystroke logger. 
In less than a day, Internet administrators sterilized the infection by shutting down the Russian server that hosted the spyware. But not before a barrage of scary reports had circled the world. "Users are being told to avoid using Internet Explorer until Microsoft patches a serious security hole," the BBC warned. (Disclosure: Microsoft owns Slate.) CNET reporter Robert Lemos zeroed in on why the attack was so scary. "This time," he wrote, "the flaws affect every user of Internet Explorer." That's about 95 percent of all Net users. No matter how well they had protected themselves against viruses, spyware, and everything else in the past, they were still vulnerable to yet another flaw in Microsoft's browser.
Scob didn't get me, but it was enough to make me ditch Explorer in favor of the much less vulnerable Firefox browser. Firefox is built and distributed free by the Mozilla Organization, a small nonprofit corporation spun off last year from the fast-fading remnants of Netscape, which was absorbed by AOL in 1999. Firefox development and testing are mostly done by about a dozen Mozilla employees, plus a few dozen others at companies like IBM, Sun, and Red Hat. I've been using it for a week now, and I've all but forgotten about Explorer.  More....  

Top Five Security Control Points Auditors Miss Make sure you check these essential control points in any Windows network audit by Derek Melber, Enterprise Systems Security

6/30/2004

Auditors face two limiting factors: time and money. Budgets normally prohibit an auditor from compiling a 100-percent-complete audit on all computers, even for small and mid-size networks. As for the time restriction, if a company has tens of thousands of computers, it is impossible to consider auditing all of them. So how can you be more proficient and efficient in audits of Windows networks?

One or more of the missed audit control points I describe below may come as a surprise. You might be checking a portion of the control point but miss the entire picture. You may not consider an item on this list to even be a security concern because it isn't part of your audit program. However, these control points have security written all over them and should be included in every audit program for Windows networks. Missed Control Point #1: Domain Admins Missing from Local Administrators Group More....  

McAfee: New Lovegate worm spreading
It's infecting computers worldwide, including those at some Fortune 500 firms
News Story by Jaikumar Vijayan

JULY 02, 2004 (COMPUTERWORLD) - A new version of the Lovegate worm has begun infecting computers worldwide, including those belonging to several Fortune 500 companies, according to a statement from antivirus firm McAfee Inc.

Like its predecessors, Lovegate.ad@MM is a mass-mailing worm that spreads through e-mail and network file sharing and by exploiting a previously disclosed vulnerability in the remote procedure call interface in multiple Windows versions. Last year's widespread Blaster worm took advantage of the same flaw.

The worm drops a back door on infected systems and also tries to propagate itself on other systems using a variety of methods, including mailing itself using its own SMTP engine, according to the McAfee advisory.

This is the 30th version of the Lovegate worm, but it's one of only a few that have been assessed as a medium risk by the company. "It's a little bit more successful than the other ones," said Chris Schmugar, virus research manager at McAfee.

The company has received reports of infections from several of its major clients, Schmugar said. In some cases, hundreds and even thousands of systems have been infected, he said. 

Usenix: Experts debate security through diversity 
Most of those on hand for a debate on OS and browser diversity like the idea
News Story by Tom Krazit

JULY 01, 2004 (IDG NEWS SERVICE) - The sheer number of worms and viruses directed at Microsoft Corp.'s Windows operating system and Internet Explorer browser have many in the computer industry wondering whether the cyberworld would be more secure if more users relied on alternatives to Microsoft's products. That description appeared to fit about two-thirds of the few hundred system administrators and engineers attending a debate between two prominent security experts at the Usenix 2004 conference in Boston yesterday. A show of hands before and after the debate indicated that most of those in attendance would prefer a more diverse group of operating system and Web browser software. 
A monoculture, whether it be in biological terms or in computing terms, has been shown to be inherently dangerous to members of that group, said Dan Geer, chief scientist at Verdasys Inc. Geer was formerly chief technology officer at security company @stake Inc. until he was fired last year for authoring a report critical of Microsoft's dominance of the computing industry and the insecurity of its products that stems from that position. Microsoft is an @stake client. More....

Spyware Gets Top Billing
An infection on the CEO's home system leads to a call for new preventive measures.
Security Manager's Journal by Mathias Thurman

JULY 05, 2004 (COMPUTERWORLD) - This week, I was suddenly called into my boss's office for an urgent meeting. From the look on his face, I expected to hear that we had a serious security incident under way. Instead, he asked what our department was doing about spyware.

Apparently, a spyware program had infected our CEO's home computer, so he asked the CIO if we had a plan to deal with adware and spyware. The CIO marched down to a vice president's office to ask the same question. That VP then asked a director, who asked me whether we have any infrastructure to deal with an increase in spyware activity within our company. The short answer is that we don't have any. So now the question is, Why don't we have that infrastructure in place?

It's funny how these sorts of inquiries roll downhill. At a previous job, I once had to bring in several vendors after the CEO read an article about public-key infrastructure. We explained to him that PKI was still in its infancy and would cost several million dollars to implement. The project died quickly after that. More....  

Wireless Hackers Leave No Tracks 
Unprotected WLANs give hackers an untraceable way to launch attacks across the Internet.
Security Manager's Journal by Vince Tuesday 

  I'm a parasite. I didn't pay for the bandwidth I'm using right now. I didn't ask for permission to use it -- I don't even know whom to ask. But I'm on holiday, I have a few bits of work to finish up before I can relax, and I need to send my e-mail. The broadband service in the rented house doesn't work, so I stuck in my wireless LAN card and found two WLANs covering the house. One has a Secure Set Identifier of "lopez" and has Wired Equivalent Privacy turned on; the other has an SSID of "default" and no WEP. 
My wireless card has automatically associated with the "default" base station, which gave me a Dynamic Host Configuration Protocol address. Now I'm connected to the Internet at 11Mbit/sec. with no fee and no restrictions on what I can do. 
When WLANs hit the mainstream a few years ago, the security focus was on confidentiality, and vendors included WEP to encrypt data in the air. WEP has flaws -- it might not stop a snooper in your parking from reading your data -- but just the fact that "lopez" had it turned on was enough to turn my attention elsewhere. Why hack "lopez" when "default" is sending in the clear?  More....  

Vulnerabilities

05 July 2004

bulletSCI Photo Chat Server 3.4.9 Cross Site Scripting Vulnerability
bulletDLINK 624 Script Injection Vulnerability
bulletEnterasys XSR Security Router Denial of Service Vulnerability
bulletCart32 Input Validation Vulnerability
bulletNetegrity IdentityMinder Cross Site Scripting Vulnerability
bulletEasy Chat Server 1.2 Multiple Vulnerabilities
bulletMiller Group Centre Input Validation Vulnerability

02 July 2004

bulletDomino 6.5.1 Denial of Service Vulnerability
bulletphpMyAdmin version 2.5.7 PHP Code Injection Vulnerability
bulletDomino 6.5.1 Unprivileged User Quota Changing Vulnerability
bulletWinGate Information Disclosure Vulnerability

30 June 2004

bulletLinux Kernel 2.6.x Remote Denial of Service Vulnerability
bulletSbus PROM Driver Multiple Integer Overflow Vulnerabilities

28 June 2004

bulletLotus Notes URL Argument Injection Vulnerability
bulletDLINK 614+ DHCP Service Denial of Service Vulnerability
bulletDLINK 614+ System Denial of Service Vulnerability
bulletInfinity WEB SQL Injection Vulnerability
bulletcsFAQ Full Path Disclosure Vulnerability
bulletPowerPortal Multiple Vulnerabilities
bulletCuteNews Cross Site Scripting Vulnerability

27 June 2004

bulletFreeBSD Local Denial of Service Vulnerability
bulletGnats Format String Vulnerability
bulletArtmedic_links5 File Include Vulnerability
bulletDrcatd Multiple Vulnerabilities

25 June 2004

bulletrlprd 2.0.4 Format String Vulnerability
bulletvBulletin HTML Injection Vulnerability

24 June 2004

bulletLinux Broadcom 5820 Cryptonet Driver Integer Overflow Vulnerability
bulletBT Voyager 2000 Wireless ADSL Router Cleartext Password Vulnerability
bulletSqwebmail 4.0.4 Cross Site Scripting Vulnerability
bulletInternet Explorer HTML Printing Denial of Service Vulnerability
bulletArbitroWeb v0.6 Javascript Injection Vulnerability
bulletLotus Notes URI Handler Argument Injection Vulnerability

23 June 2004

bulletDLink 704 Script Injection Vulnerability
bulletDLink 614+ Script Injection Vulnerability
bulletZoneAlarm Pro 'Mobile Code' Bypass Vulnerability
bulletNetgear FVS318 Web-Based Administration Denial of Service Vulnerability
bulletMicrosoft MN-500 Wireless Router Web-Based Administration Denial of Service Vulnerability

21 June 2004

bulletInternet Scanner 7 Restriction Bypass Vulnerability
bulletDNSONE Appliance Script Injection Vulnerability
bullet"IBM Access Support" (eGatherer) Activex Dangerous Methods Vulnerability

Advisories

05 July 2004

bulletGentoo Linux Security Advisory - Apache 2: Remote denial of service attack (GLSA 200407-03)
bulletGentoo Linux Security Advisory - Pure-FTPd: Potential DoS when maximum connections is reached (GLSA 200407-04)
bulletGentoo Linux Security Advisory - Linux Kernel: Multiple vulnerabilities (GLSA 200407-02)

03 July 2004

bulletDebian Security Advisory - New pavuk packages fix buffer overflow (DSA 527-1)
bulletDebian Security Advisory - New webmin packages fix multiple vulnerabilities (DSA 526-1)
bulletUS-CERT Technical Cyber Security Alert - Internet Explorer Update to Disable ADODB.Stream ActiveX Control (TA04-184A)
bulletSUSE Security Announcement - kernel (SUSE-SA:2004:020)

01 July 2004

bulletGentoo Linux Security Advisory - Esearch: Insecure temp file handling (GLSA 200407-01)
bulletFreeBSD Security Advisory - Linux binary compatibility mode input validation error (FreeBSD-SA-04:13.linux)

30 June 2004

bulletCisco Security Advisory - Cisco Collaboration Server Vulnerability
bulletTrustix Secure Linux Bugfix Advisory - apache, libpng, python (#2004-0038)
bulletGentoo Linux Security Advisory - Pavuk: Remote buffer overflow (GLSA 200406-22)
bulletMandrakelinux Security Update Advisory - apache (MDKSA-2004:065)
bulletMandrakelinux Security Update Advisory - apache2 (MDKSA-2004:064)
bulletMandrakelinux Security Update Advisory - libpng (MDKSA-2004:063)

29 June 2004

bulletGentoo Linux Security Advisory - mit-krb5: Multiple buffer overflows in krb5_aname_to_localname (GLSA 200406-21)

26 June 2004

bulletDebian Security Advisory - New apache packages fix buffer overflow in mod_proxy (DSA 525-1)
bulletGentoo Linux Security Advisory - FreeS/WAN, Openswan, strongSwan: Vulnerabilities in certificate handling (GLSA 200406-20)

24 June 2004

bulletGentoo Linux Security Advisory - gzip: Insecure creation of temporary files (GLSA 200406-18)
bulletGentoo Linux Security Advisory - giFT-FastTrack: remote denial of service attack (GLSA 200406-19)
bulletMandrakelinux Security Update Advisory - kernel (MDKSA-2004:062)

23 June 2004

bulletSUSE Security Announcement - dhcp-server (SuSE-SA:2004:019)
bulletUS-CERT Technical Cyber Security Alert TA04-174A -- Multiple Vulnerabilities in ISC DHCP 3
bulletGentoo Linux Security Advisory - IPsec-Tools: authentication bug in racoon (GLSA 200406-17)
bulletConectiva Security Announcement - kernel (CLA-2004:845)

22 June 2004

bulletSGI Security Advisory - SGI Advanced Linux Environment 2.4 security update #22 (20040605-01-U)
bulletSGI Security Advisory - SGI Advanced Linux Environment 3 Security Update #4 (20040604-01-U)
bulletGentoo Linux Security Advisory - Apache 1.3: Buffer overflow in mod_proxy (GLSA 200406-16)
bulletSGI Security Advisory - SGI Advanced Linux Environment 3 Security Update #3 (20040603-01-U)
bulletSGI Security Advisory - SGI Advanced Linux Environment 2.4 security update #21 (20040602-01-U)
bulletGuardian Digital Security Advisory - 'kernel' Several vulnerabilities (ESA-20040621-005)

21 June 2004

bulletDebian Security Advisory - New rlpr packages fix multiple vulnerabilities (DSA 524-1)
bulletDebian Security Advisory - New www-sql packages fix buffer overflow (DSA 523-1)
bulletDebian Security Advisory - New super packages fix format string vulnerability (DSA 522-1)
bulletDebian Security Advisory - New sup packages fix format string vulnerabilities (DSA 521-1)
bulletGentoo Linux Security Advisory - Usermin: Multiple vulnerabilities (GLSA 200406-15)

 

Back Home Up Next

 

 

Security Products:

 

Astaro Security 

Gateway

 

Award winning, Rock-solid network security, simple and affordable.

 "...exceptionally polished and extremely robust security gateway for a very reasonable price.... the most polished and easy to use Web-based management system we've seen to date." --- INFOWORLD


Astaro provides six essential security applications in one easy-to-manage package that protects organizations from hackers, viruses, worms, spam and other threats to security and productivity.


Astaro Security Linux offers: 

bullet

firewall

bullet

intrusion protection

bullet

e-mail virus protection

bullet

web virus protection

bullet

spam protection

bullet

VPN gateway

bullet

URL filtering capabilities. 

 

A unified management platform makes it easy to deploy, 
administer, and update a complete network security solution with surprisingly little cost and effort. The software can be installed on a standard Intel PC, or purchased pre-installed on a variety of security appliances.
Based on the best of open source security software, Astaro Security Linux has won numerous awards, and is in use on over 20,000 networks in 60 countries.

Astaro security Linux is extremely scalable, with the ability to protect small office home office/remote office to enterprise implementations  incorporating  features such as High availability, VLANs, Qos and a configuration manager to manage multiple  sites from a single management platform. 

Prices start at $390 for a 10 user license. Educational discounts are available.

 

 

Intrusion Detection Systems

bulletIntruvert

Vulnerability Scanners

bullet

eEye's Retina

Firewalls

bulletNetscreen
bulletCheckpoint

Management

bulletSolarWinds

Virus Control

bulletMail Marshall

Services

bulletSecurity audit
bulletPerimeter Vulnerability Scan
bulletRouter/ switch optimization for security
bulletFirewall checking and configuration
bulletVPN Design and Implementation
bulletNetwork design
bulletnetwork based application analysis
bulletNetwork Baselining
bulletSecurity baselining

 

 

  BlackICE PC Protection

This mailing has been performed by Aavex Technology Corporation
42w588 Still Meadows Lane, Elburn IL 60119 USA,  630-365-0025 in compliance with the "CAN-SPAM Act of 2003",  approved and signed by the president of The United States of America on Dec. 16, 2003. For this reason, this email cannot be considered SPAM This newsletter contains commercial advertisement.

 

 

Copyright © 2004 Aavex Technology