Security News Letter

August 2nd

 

   
   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here

Download eEye's Retina Vulnerability Scanner Here
 

 

 Kaspersky Anti-Virus: Install & Feel Safe!

Sentencing Rules Pressure CIOs
Accused CEOs could fire IS execs to avoid Sarbox punishment

Proposed sentencing guidelines for Sarbanes-Oxley Act violations, scheduled to take effect Nov. 1, bring risks for CIOs. While it's unlikely any CIOs would go to jail under the proposal, which awaits congressional approval, legal experts say the guidelines could set up CIOs to be the fall guys if another C-level executive faces conviction.

The proposed guidelines, published by the U.S. Sentencing Commission in its May 1 report to Congress, attempt to spread accountability for unethical or illegal behavior throughout a corporation. If any C-level executive, not just the CEO or the CFO, is responsible for such behavior, he can now go to jail. This isn't a big deal for CIOs—unless they're engaged in Enron-style fraud or they're charged with their company's Sarbanes-Oxley compliance efforts. Most CIOs aren't in charge of compliance (see "The Sarbox Conspiracy").  More.... 

The Sarbox Conspiracy
Sarbanes-Oxley compliance efforts are eating up CIO time and budgets. Worse, CIOs are being relegated to a purely tactical role. And that may be the CFO's plan.
BY CHRISTOPHER KOCH

When CIOs began installing ERP systems in the '80s and '90s, they unwittingly took something that used to belong to CFOs: financial controls. The things that accountants used to monitor manually—such as making sure that two signatures from the right people went on every check, or reconciling purchase orders against invoices—all became automated inside ERP systems. The meticulous audit trail that controllers and accountants had established over generations for demonstrating that money was being handled properly (think of black, leather-bound ledgers and long ribbons of adding machine paper) disappeared into those ERP systems without a trace—or at least without being properly documented, and certainly not to the extent now required by the 2002 Sarbanes-Oxley Act, a.k.a. Sarbox.

Today, CFOs want those controls back. If they don't get them, they believe they could go to jail. Section 404 of the Sarbanes-Oxley Act mandates that CFOs have to do more than simply pledge that the company's finances are correct; they have to vouch for the processes used to add up the numbers.  More....  

Locking Down Endpoints to Prevent Virus Resurgence
Verifying PC security compliance before granting network access


by Mathew Schwartz



Nesky.D and Bugbear.B are readily recognized by security as past threats, discovered months or over a year ago. Yet each appeared on Symantec’s Top 10 Malicious Threats for May 2004. In reality, despite rapidly updated signatures for antivirus engines whenever a new threat breaks, and the wide use of antivirus software on servers and desktops, many viruses and worms aren’t eradicated; they just fade away.

Laptops are one culprit, say experts. Mobile workers may use their PC at home or on the road, cancel antivirus or other important software updates, or just not be available to install them. When such PCs reconnect to the corporate LAN, they can restart an infection. Of course, it’s up to security managers to clean up the mess, perhaps again. “Back in the virus [attacks] of last fall, one behavior we saw is you’d have this initial bump in vulnerability, followed by infections, followed by a smaller bump two weeks later from people who hadn’t been updated,” notes Rick Bilodeau, director of corporate marketing for iPass. More....  

Hackers Are Discovering a New Frontier: Internet Telephone Service
By KEN BELSON, NY Times

Most new technology comes with risks, no matter how great the advantages. Computers, for instance, can store huge amounts of information, but they can also freeze, crash and melt down.

The challenge is no different with Internet phones, which more and more consumers and businesses are using. The phones break voice conversations into data packets and route them over the Internet, a cheap and more flexible alternative to traditional phone calls that travel over copper wires.

But Internet phones and the routers and servers that steer and store the digitized calls are susceptible to the bugs, viruses and worms that have plagued computer data systems for years. Already, a few malicious attacks have shut down corporate Internet phone networks, disrupting business at a cost of millions of dollars. With Internet phones, hackers or disgruntled employees with access to a company's phone server can eavesdrop on conversations by surreptitiously installing software that can track voice packets. More.... 

Internet's 'white pages' allow data attacks

By Robert Lemos
Staff Writer, CNET News.com

LAS VEGAS--The same technology that allows Web surfers to locate and connect to computers on the Internet can be used to create covert communications channels, bypass security measures and store distributed content, a security researcher said Saturday.

The security hack essentially uses data transferred by domain name service (DNS) servers to hide additional information in the network communications. DNS servers act as the white pages of the Internet, invisibly transforming easy-to-remember domain names--such as www.cnet.com--into the numerical network addresses used by computers. Moreover, corporate security measures, such as firewalls, tend to ignore DNS data because they assume it's harmless, said Dan Kaminsky, a security researcher for telecommunications firm Avaya and a speaker at the Defcon hacking conference here.

"DNS is everywhere--you cannot communicate over the global Internet without knowing where to go," he said. "No one notices DNS. No one monitors it." More....  

Hackers plan global game of 'capture the flag'

By Robert Lemos Staff Writer, CNET News.com 

LAS VEGAS--If everything goes as planned, for 72 hours next February hackers from all over the United States will hit targets across the Internet in the largest mass attack to date. But the affected systems won't be corporate Web servers or networks, they'll be computers set up and maintained by other hackers as part of a capture-the-flag game. When the digital dust clears, the team from either the East Coast or the West Coast will be named winner.

"We have people take over someone's box and play the game from there," said "D.D.," a member of the Seattle-based security group Ghetto Hackers, which kicked off a smaller version of the game, Root Fu, at the Defcon hacking convention here on Friday. "In terms of our machines, we are pretty confident that we can contain it." The Ghetto Hackers have run the smaller capture-the-flag-type game, where eight teams hack each other on a closed network, for three years at the convention.

Next year, the group of hacking hobbyists hopes to take the game global. Dubbed Mega Root Fu, the new game will be the first large-scale hacking contest played over the public Internet. The group is allowing teams throughout the United States to sign up at its Web site and hopes to have a thousand players come February. More....  

Google a favorite among hackers, too

By Robert Lemos
Staff Writer, CNET News.com

LAS VEGAS--The world's most popular search engine is one of the handiest tools for hackers, a security expert said Thursday.

Google's ability to record Internet sites' content can be used to pinpoint those with weak security, Johnny Long, a security researcher and computer scientist for Computer Sciences, told attendees at the Black Hat Security Briefings here. Though the technique is not new, well-crafted searches turned up so many sites with vulnerabilities that even jaded researchers laughed during the session.

"It is an old dog with new tricks," Long said. "It never ceases to amaze people, all the vulnerabilities out there."

By searching for default server page titles, for example, an attacker can find easily exploitable servers. Applications left in default modes can also be found by searching for error pages generated by the software. And searching for specific file names can pinpoint vulnerable servers connected to the Internet. More.... 

Vulnerabilities

02 August 2004

bulletOpenFTPD Format String Vulnerability
bulletFusion News Unauthorized Account Addition Vulnerability

30 July 2004

bulletJaws 0.4 Authentication Bypass Vulnerability
bulletDansGuardian Hex Encoding URL Banned Extension Filter Bypass Vulnerability
bulletLostBook v1.1 Javascript Execution Vulnerability

29 July 2004

bulletApple OS X Panther Internet Connect Local Root Vulnerability
bulletRiSearch and RiSearch ProPro Multiple Vulnerabilities
bulletPavuk Digest Authentication Buffer Overflow Vulnerability
bulletAntiBoard 0.7.2 Cross Site Scripting and SQL Injection Vulnerabilities

27 July 2004

bulletASPRunner Multiple Vulnerabilities
bulletMozilla Firefox Certificate Spoofing Vulnerability

26 July 2004

bulletEasyWeb FileManager Directory Traversal Vulnerability
bulleteSeSIX Thintune Thin Client Multiple Vulnerabilities
bulletEasyins Stadtportal Code Inclusion Vulnerability

23 July 2004

bulletHP dced Remote Command Execution Vulnerability
bulletSamba 3.x Swat Preauthentication Buffer Overflow Vulnerability

22 July 2004

bulletFlash FTP Server v2.1 Directory Traversal Vulnerability
bulletXitami Web Server v2.5c1 Denial of Service Vulnerability
bulletConceptronic CADSLR1 Router Denial of Service Vulnerability

21 July 2004

bulletWhisper FTP Surfer 1.0.7 Buffer Overflow Vulnerability
bulletPhpBB HTTP Response Splitting and Cross Site Scripting Vulnerabilities
bulletLexmark Multiple HTTP Servers Denial of Service Vulnerability
bulletLionMax Software WWW File Share Pro Remote Denial of Service Vulnerability

20 July 2004

bulletMedal of Honor Remote Buffer Overflow Vulnerability
bulletArtmedic Kleinanzeigen Code Injection Vulnerability

19 July 2004

bulletMicrosoft Internet Explorer Overly Trusted Location Variant Method Cache Vulnerability
bulletPhpBB Cross Site Scripting and Full Path Disclosure Vulnerabilities
bulletPhpNuke Search Module Multiple Vulnerabilities
bulletWeb_Store.cgi Command Execution Vulnerability
bulletCuteNews v1.3.x HTML Injection Vulnerability
bulletPostNuke 0.75-RC3 Multiple Vulnerabilities
bulletOutblaze Cross Site Scripting Vulnerability

Advisories

02 August 2004

bulletSCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : uudecode does not check for symlink or pipe (SCOSA-2004.7)
bulletSCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : OpenSSL Multiple Vulnerabilities (SCOSA-2004.10)
bulletSCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : Xsco contains a buffer overflow that could be exploited to gain root privileges (SCOSA-2004.3)
bulletSCO Security Advisory - UnixWare 7.1.3 Open UNIX 8.0.0 : Xsco contains a buffer overflow that could be exploited to gain root privileges. (SCOSA-2004.2)
bulletMicrosoft Security Bulletin Re-release, August 2004
bulletMicrosoft Security Bulletin Summary for July 2004
bulletUS-CERT Technical Cyber Security Alert TA04-212A - Critical Vulnerabilities in Microsoft Windows
bulletConectiva Linux Security Announcement - sox (CLA-2004:855)
bulletConectiva Linux Security Announcement - samba (CLA-2004:854)
bulletConectiva Linux Security Announcement - kernel (CLA-2004:852)
bulletGentoo Linux Security Advisory - MPlayer: GUI filename handling overflow (GLSA 200408-01)
bulletGentoo Linux Security Advisory - SoX: Multiple buffer overflows (GLSA 200407-23)

30 July 2004

bulletMandrakelinux Security Update Advisory - OpenOffice.org (MDKSA-2004:078)
bulletMandrakelinux Security Update Advisory - wv (MDKSA-2004:077)
bulletGentoo Linux Security Advisory - phpMyAdmin: Multiple vulnerabilities (GLSA 200407-22)

29 July 2004

bulletGentoo Linux Security Advisory - Samba: Multiple buffer overflows (GLSA 200407-21)
bulletMandrakelinux Security Update Advisory - sox (MDKSA-2004:076)
bulletSCO Security Advisory - UnixWare 7.1.3up : tcpdump several vulnerabilities in tcpdump (SCOSA-2004.9)
bulletSCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : Multiple Vulnerabilities in Sendmail (SCOSA-2004.11)
bulletMandrakelinux Security Update Advisory - XFree86 (MDKSA-2004:073)

28 July 2004

bulletMandrakelinux Security Update Advisory - mod_ssl (MDKSA-2004:075)
bulletMandrakelinux Security Update Advisory - webmin (MDKSA-2004:074)
bulletMandrakelinux Security Update Advisory - postgresql (MDKSA-2004:072)
bulletDebian Security Advisory - New libapache-mod-ssl packages fix multiple vulnerabilities (DSA 532-2)
bulletTrustix Secure Linux Security Advisory - apache, mod_php4, samba (2004-0039)
bulletGentoo Linux Security Advisory - Pavuk: Digest authentication helper buffer overflow (GLSA 200407-19)

27 July 2004

bulletGentoo Linux Security Advisory - Subversion: Vulnerability in mod_authz_svn (GLSA 200407-20)
bulletSlackware Security Advisory - alternate samba package for Slackware 10.0 (SSA:2004-208-01)

26 July 2004

bulletHP Security Advisory - HP-UX xfs and stmkfont remote unauthorized access (SSRT4773)
bulletMandrakelinux Security Update Advisory - samba (MDKSA-2004:071)
bulletSlackware Security Advisory - new mod_ssl packages (SSA:2004-207-02)
bulletSlackware Security Advisory - new samba packages (SSA:2004-207-01)
bulletNetwosix Linux Security Advisory - ethereal (2004-0016)
bulletNetwosix Linux Security Advisory - samba (2004-0015)

23 July 2004

bulletTinysofa Security Advisory - samba (TSSA-2004-014)
bulletConectiva Linux Security Announcement - samba (CLA-2004:851)
bulletDebian Security Advisory - New courier packages fix cross-site scripting vulnerability (DSA 533-1)
bulletDebian Security Advisory - New mailreader packages fix directory traversal vulnerability (DSA 534-1)
bulletDebian Security Advisory - New libapache-mod-ssl packages fix multiple vulnerabilities (DSA 532-1)
bulletSUSE Security Announcement - samba (SUSE-SA:2004:022)
bulletSCO Security Advisory - OpenServer 5.0.7 : Mozilla Multiple issues (SCOSA-2004.8)

22 July 2004

bulletGentoo Linux Security Advisory - mod_ssl: Format string vulnerability (GLSA 200407-18)
bulletGentoo Linux Security Advisory - Linux Kernel: Multiple DoS and permission vulnerabilities (GLSA 200407-16)
bulletOpenPKG Security Advisory - samba (OpenPKG-SA-2004.033)
bulletCisco Security Advisory - Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities

21 July 2004

bulletFedora Legacy Update Advisory - Updated mailman resolves security vulnerability (FLSA:1724)
bulletFedora Legacy Update Advisory - Updated libxml2 resolves security vulnerability (FLSA:1324)
bulletSlackware Security Advisory - PHP (SSA:2004-202-01)
bulletDebian Security Advisory - New php4 packages fix multiple vulnerabilities (DSA 531-1)
bulletGentoo Linux Security Advisory - Opera: Multiple spoofing vulnerabilities (GLSA 200407-15)

20 July 2004

bulletGentoo Linux Security Advisory - Unreal Tournament 2003/2004: Buffer overflow in 'secure' queries (GLSA 200407-14)
bulletSCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : MMDF Various buffer overflows and other security issues

19 July 2004

bulletConectiva Linux Security Announcement - webmin (CLA-2004:848)
bulletConectiva Linux Security Announcement - php4 (CLA-2004:847)
bulletDebian Security Advisory - New netkit-telnet-ssl package fixes format string vulnerability (DSA 531-1)
bulletDebian Security Advisory - New l2tpd packages fix buffer overflow (DSA 530-1)
bulletDebian Security Advisory - New netkit-telnet-ssl package fixes format string vulnerability (DSA 529-1)
bulletDebian Security Advisory - New ethereal packages fix denial of service (DSA 528-1)
bulletOpenPKG Security Advisory - apache [with_mod_ssl=yes] (OpenPKG-SA-2004.032)

 

 

 

Security Products:

 

Astaro Security Gateway

Available in 2,3,4,or 6 port.

Other models  scale to 23 ports

and from a 10 user network to an  enterprise network.

Award winning, Rock-solid network security, simple and affordable.

 "...exceptionally polished and extremely robust security gateway for a very reasonable price.... the most polished and easy to use Web-based management system we've seen to date." --- INFOWORLD


Astaro provides six essential security applications in one easy-to-manage package that protects organizations from hackers, viruses, worms, spam and other threats to security and productivity.


Astaro Security Linux offers: 

bullet

firewall

bullet

intrusion protection

bullet

e-mail virus protection

bullet

web virus protection

bullet

spam protection

bullet

VPN gateway

bullet

URL filtering capabilities. 

 

A unified management platform makes it easy to deploy, 
administer, and update a complete network security solution with surprisingly little cost and effort. The software can be installed on a standard Intel PC, or purchased pre-installed on a variety of security appliances.
Based on the best of open source security software, Astaro Security Linux has won numerous awards, and is in use on over 20,000 networks in 60 countries.

Astaro security Linux is extremely scalable, with the ability to protect small office home office/remote office to enterprise implementations  incorporating  features such as High availability, VLANs, Qos and a configuration manager to manage multiple  sites from a single management platform. 

Prices start at $390 for a 10 user license. Educational discounts are available.

 

 

Intrusion Detection Systems

bulletIntruvert

Vulnerability Scanners

bullet

eEye's Retina

Firewalls

bulletNetscreen
bulletCheckpoint

Management

bulletSolarWinds

Virus Control

bulletMail Marshall

Services

bulletSecurity audit
bulletPerimeter Vulnerability Scan
bulletRouter/ switch optimization for security
bulletFirewall checking and configuration
bulletVPN Design and Implementation
bulletNetwork design
bulletnetwork based application analysis
bulletNetwork Baselining
bulletSecurity baselining

 

 

  BlackICE PC Protection

This mailing has been performed by Aavex Technology Corporation
42w588 Still Meadows Lane, Elburn IL 60119 USA,  630-365-0025 in compliance with the "CAN-SPAM Act of 2003",  approved and signed by the president of The United States of America on Dec. 16, 2003. For this reason, this email cannot be considered SPAM This newsletter contains commercial advertisement.

 

 

Copyright © 2004 Aavex Technology