Security News Letter

July 12th

 

   
   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here

Download eEye's Retina Vulnerability Scanner Here
 

 

 Kaspersky Anti-Virus: Install & Feel Safe!

Cover Your Apps
5 Security Myths 
By Jeremiah Grossman, VARBusiness 
9:00 AM EDT Wed. Jul. 07
Like water, hackers take the path of least resistance. Today, this path leads over Secure Sockets Layer (SSL) to get past most corporate firewalls, where nothing exists between a hacker, a Web site and the information it holds. Using a browser and a few simple tricks, hackers can penetrate a Web site, access its credit-card database and make off with the goods unseen. With firewalls and patch management now being standard practices, the network perimeter has become increasingly secure. Determined to stay a step ahead, hackers have moved up the software stack, focusing on the Web site itself. According to a Gartner analyst, more than 70 percent of cyberattacks occur at the application layer. So what's a solution provider to do? To improve the security of the Web, you must dispel five largely held misconceptions. 
1. "The Web site uses SSL, so it's secure."
SSL by itself does not secure a Web site. The tiny SSL lock symbol located at the bottom of a Web browser indicates that the information sent to and from a site is encrypted. Nothing more. SSL does not protect the information stored on the site once it arrives. Many sites using strong 128-bit SSL have been hacked just the same as those that do not. In addition, SSL has nothing to do with how a user's private information is safeguarded. When private data is stored on the Web site, the risk is at the server, not in between.  More.... 

 

The nuts and bolts of a security assessment 
Opinion by Mark Perry, Symantec Corp.

JULY 08 (COMPUTERWORLD) - A year ago, the announcement of a patch for an operating system vulnerability preceded an attack by an average of 30 days. In May, the average vulnerability announcement-to-attack code propagation was less than 18 days. In other words, the attack-code propagation cycle was 60% faster than for the same period a year ago. This marks a dramatic change in the threat profile for corporations over the past year. Yet our response to these threats via policy, procedures, testing, monitoring and mitigation techniques in this same time frame have not seen the same 60% improvement. 
One step that can immediately improve information security efficiency is to conduct routine security assessments. The real value of an assessment is not in vulnerability identification but in interpreting results that lead to the root cause of risks. The vast number of vulnerabilities identified in an assessment report can be mitigated with relatively minimal effort. Without an information security program in place, other vulnerabilities will surface, however, and could spread within your organization's infrastructure. For this reason, root-cause analysis, when combined with a robust security program, will achieve the maximum return on your organization's information security investment.

The attack of the $2 million worm

By CNET News.com Staff 

Internet-based business disruptions triggered by worms and viruses are costing companies an average of nearly $2 million in lost revenue per incident, market researcher Aberdeen said on Tuesday. Out of 162 companies contacted, 84 percent said their business operations have been disrupted and disabled by Internet security events during the last three years. Though the average rate of business operations disruption was one incident per year, about 15 percent of the surveyed companies said their operations had been halted and disabled more than seven times over a three-year period. 
The portends for enterprises are alarming, given the increased use of the Internet for core business activities. About three-fourths of the companies contacted by Aberdeen indicated they are increasing online sales and customer service, 55 percent will do more procurement and sourcing through the Web, and 48 percent want to enhance online distribution and fulfillment activities.
"Increasing usage of the Internet for these core business functions means that business disruptions from Internet security can seriously impact a company's revenue,"

Could search sites spawn worms? 
News Story by Joel Strauch

JUNE 30 (PC WORLD) - Worm attacks are bad enough by themselves, but some experts warn of an even more devastating variation: one that strikes at the application level instead of targeting network infrastructure, and spreads to Web sites through Web-based search engines. Essentially, a smart worm could crawl into the data gathered by a search engine to identify the most vulnerable sites and target them, say some security experts and analysts. 

List of victims 
"Search engines basically crawl Web sites and all their links and categorize them," says Shlomo Kramer, CEO and president of Imperva Inc., a Web application security company. Among the ways search site "bots" categorize sites is by their vulnerability. 
"These vulnerabilities are indexed and saved in a very organized way and are available for anybody to access," Kramer says. 
A worm could contain code to seek out those particular search engine lists. It wouldn't have to scan thousands, or tens of thousands, of pages to find its next target, Kramer says. The worm could just check the search engine's list of vulnerable sites, because every site on that list would be a good target.  More....   

VoIP hacks gut Caller I.D.
Implementation quirks in Voice over IP are making it easy for hackers to spoof Caller I.D., and to unmask blocked numbers. 
By Kevin Poulsen, SecurityFocus Jul 6 1:54PM 
Caller I.D. isn't what it used to be. 
Hackers have discovered that the handy feature that tells you who's calling before you answer the phone is easily manipulated through weaknesses in Voice over IP (VoIP) programs and networks. They can make their phone calls appear to be from any number they want, and even pierce the veil of Caller I.D. blocking to unmask an anonymous phoner's unlisted number. 
At root, the issue is one of what happens to a nugget of authentication data when it leaves the tightly-regulated realm of traditional telephony, and passes into the unregulated domain of the Internet. 
On the old-fashioned phone network, Caller I.D. works this way: your local phone company or cell phone carrier sends your "Calling Party Number" (CPN) with every call, like a return address on an envelope. Transmitted along with your CPN is a privacy flag that tells the telephone switch at the receiving end of the call whether or not to share your number with the recipient: if you have blocking on your line, the phone company you're dialing into knows your number, but won't share it with the person you're calling. More....

Security strategies ‘not working'
By Iain Scott , ITWeb
Posted: 12 July
Today's strategies to defend networks against viruses, worms and Trojan horses are not working, says Gary Middleton, IT security specialist at Dimension Data.Addressing the BMI-TechKnowledge/International Data Corporation African banking forum in Midrand last week, Middleton said there was a huge interest in how companies needed to comply with legislation and corporate governance requirements.
In auditing and risk management there was also a requirement to reduce business risk in order to comply to audit reports. Security was also key to customer confidence. The better the security, the higher the customer confidence.
The security market is growing, with a BMI-T survey showing that the market, worth almost R1.05 billion last year, would be worth R1.22 billion this year.
However, while network infrastructure was now more able to defend itself from attack, in 2002 the number of reported security vulnerabilities reached a record high, as did the number of reported security incidents. At the same time security product spending is also reaching record levels.
“There's a huge increase in attacks and vulnerabilities, but also huge increases in spending. Something's wrong,” he said. More....

Vulnerabilities

12 July 2004

bulletIBM WebSphere Edge Server Denial of Service Vulnerability
bulletNorton AntiVirus Denial Of Service Vulnerability
bulletwvWare Library Buffer Overflow Vulnerability

09 July 2004

bulletComersus Cart Cross Site Scripting Vulnerability
bulletComersus Cart Improper Request Handling Vulnerability

08 July 2004

bulletSSLTelnet Remote Format String Vulnerability

07 July 2004

bulletLinux Virtual Server Secure Context Procfs Shared Permissions Vulnerability
bulletZoom X3 Conexant Chipset DSL Router Default Password Vulnerability

06 July 2004

bulletMySQL Authentication Bypass Vulnerability
bulletFastream NETFile FTP/Web Server Multiple Input Validation Vulnerabilities
bulletUnreal ircd IP Cloaking Subsystem vulnerability
bullet12Planet Chat Server 2.9 Cross Site Scripting Vulnerability

05 July 2004

bulletSCI Photo Chat Server 3.4.9 Cross Site Scripting Vulnerability
bulletDLINK 624 Script Injection Vulnerability
bulletEnterasys XSR Security Router Denial of Service Vulnerability
bulletCart32 Input Validation Vulnerability
bulletNetegrity IdentityMinder Cross Site Scripting Vulnerability
bulletEasy Chat Server 1.2 Multiple Vulnerabilities
bulletMiller Group Centre Input Validation Vulnerability

Advisories

12 July 2004

bulletMozilla Security Advisory 2004-07-08 - Windows shell: scheme exposed in Mozilla
bulletMandrakelinux Security Update Advisory - ethereal (MDKSA-2004:067)
bulletGentoo Linux Security Advisory - MoinMoin: Group ACL bypass (GLSA 200407-09)
bulletGentoo Linux Security Advisory - Ethereal: Multiple security problems (GLSA 200407-08)

08 July 2004

bulletOpenPKG Security Advisory - dhcpd (OpenPKG-SA-2004.031)
bulletGentoo Linux Security Advisory - Shorewall : Insecure temp file handling (GLSA 200407-07)
bulletGentoo Linux Security Advisory - libpng: Buffer overflow on row buffers (GLSA 200407-06)

07 July 2004

bulletMandrakelinux Security Update Advisory - kernel (MDKSA-2004:066)
bulletMandrakelinux Security Update Advisory - tripwire (MDKSA-2004:057-1)

06 July 2004

bulletOpenPKG Security Advisory - png (OpenPKG-SA-2004.030)
bulletGentoo Linux Security Advisory - XFree86, X.org: XDM ignores requestPort setting (GLSA 200407-05)

05 July 2004

bulletGentoo Linux Security Advisory - Apache 2: Remote denial of service attack (GLSA 200407-03)
bulletGentoo Linux Security Advisory - Pure-FTPd: Potential DoS when maximum connections is reached (GLSA 200407-04)
bulletGentoo Linux Security Advisory - Linux Kernel: Multiple vulnerabilities (GLSA 200407-02)

 

 

 

Security Products:

 

Astaro Security Linux 

Gateway

 

Award winning, Rock-solid network security, simple and affordable.

 "...exceptionally polished and extremely robust security gateway for a very reasonable price.... the most polished and easy to use Web-based management system we've seen to date." --- INFOWORLD


Astaro provides six essential security applications in one easy-to-manage package that protects organizations from hackers, viruses, worms, spam and other threats to security and productivity.


Astaro Security Linux offers: 

bullet

firewall

bullet

intrusion protection

bullet

e-mail virus protection

bullet

web virus protection

bullet

spam protection

bullet

VPN gateway

bullet

URL filtering capabilities. 

 

A unified management platform makes it easy to deploy, 
administer, and update a complete network security solution with surprisingly little cost and effort. The software can be installed on a standard Intel PC, or purchased pre-installed on a variety of security appliances.
Based on the best of open source security software, Astaro Security Linux has won numerous awards, and is in use on over 20,000 networks in 60 countries.

Astaro security Linux is extremely scalable, with the ability to protect small office home office/remote office to enterprise implementations  incorporating  features such as High availability, VLANs, Qos and a configuration manager to manage multiple  sites from a single management platform. 

Prices start at $390 for a 10 user license. Educational discounts are available.

 

 

Intrusion Detection Systems

bulletIntruvert

Vulnerability Scanners

bullet

eEye's Retina

Firewalls

bulletNetscreen
bulletCheckpoint

Management

bulletSolarWinds

Virus Control

bulletMail Marshall

Services

bulletSecurity audit
bulletPerimeter Vulnerability Scan
bulletRouter/ switch optimization for security
bulletFirewall checking and configuration
bulletVPN Design and Implementation
bulletNetwork design
bulletnetwork based application analysis
bulletNetwork Baselining
bulletSecurity baselining

 

 

  BlackICE PC Protection

This mailing has been performed by Aavex Technology Corporation
545 S. Main St, Elburn IL 60119 USA,  630-365-0025 in compliance with the "CAN-SPAM Act of 2003",  approved and signed by the president of The United States of America on Dec. 16, 2003. For this reason, this email cannot be considered SPAM This newsletter contains commercial advertisement.

 

 

Copyright © 2004 Aavex Technology