« November 2005 | Main | January 2006 »
Saturday, December 31, 2005
2005 List of (Known!) OS Vulnerabilities
Nothing says 'end of year' like a big honking list of all (known) vulnerabilities in various operating systems.Read it and be afraid, very afraid: http://www.us-cert.gov/cas/bulletins/SB2005.html.
Happy New Year!
Posted by Matthew Carrick at 9:42.19 AM EST | Permanent Link
| Categories: Headlines, Security Alerts
| Categories: Headlines, Security Alerts
Thursday, December 29, 2005
Windows Metafiles (.WMF) Exploits Continue, Part 2
Microsoft has explained how to unregister the Windows Picture and Fax Viewer (Shimgvw.dll):
- Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK.
- A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.
NOTE: The Windows Picture and Fax Viewer will no longer open when yous click on a link to an image type that is associated with the Windows Picture and Fax Viewer.
To undo this change, re-register Shimgvw.dll by following the above steps:
- Click Start, click Run, type "regsvr32 %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK.
- A dialog box appears to confirm that the registration process has succeeded. Click OK to close the dialog box.
Posted by Matthew Carrick at 8:42.40 AM EST | Permanent Link
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
Wednesday, December 28, 2005
Windows Metafiles (.WMF) Exploits Continue
It appears the real time indexing of metafile data using Google Toolbar is enough to exploit the payload. For now you should disable this indexing of media files until Microsoft issues a patch.You should also add the following sites to your hosts file:
- Crackz.ws
- unionseek.com
- www.tfcco.com
- Iframeurl.biz
- beehappyy.biz
Posted by Matthew Carrick at 8:30.00 PM EST | Permanent Link
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
There is no "MSN Messenger 8 Working BETA" !
So don't be clicking those links to download a copy even if the Instant Message comes from a friend. Especially if that friend is not as security aware as you. All you MSN Messenger users read this: http://www.infoworld.com/article/05/12/27/HNmicrosoftvirkelvirus_1.html and this: http://www.f-secure.com/weblog/archives/archive-122005.html#00000751.
Posted by Matthew Carrick at 10:04.35 AM EST | Permanent Link
| Categories: Instant Messaging, Security Alerts, Viruses-Trojans-Worms
| Categories: Instant Messaging, Security Alerts, Viruses-Trojans-Worms
Windows Metafiles (.WMF) Exploits
You might add unionseek[DOT]com to your host file. The site is using images, specifically .WMF files (Windows Metafiles), to carry a payload of trojans. Internet Explorer is vunerable, older versions of Firefox and Opera are also at risk but at least they prompt users before they launch external applications ("Windows Picture and Fax Viewer") to view the image. F-secure has the details here: http://www.f-secure.com/weblog/archives/archive-122005.html#00000752. The first I saw of it was at The Register: http://www.theregister.co.uk/2005/12/28/messenger_virus/.
Posted by Matthew Carrick at 9:54.30 AM EST | Permanent Link
| Categories: Alternative Apps, Best Practices, Security Alerts, Viruses-Trojans-Worms
| Categories: Alternative Apps, Best Practices, Security Alerts, Viruses-Trojans-Worms
Friday, December 23, 2005
Dell Notebook Batteries Recalled
CBC.CA is reporting a recall of 1,500 batteries in Canada here: http://www.cbc.ca/story/canada/national/2005/12/23/Dell-batteries051223.html. The batteries, sold between Oct. 5, 2004 and Oct. 13, 2005, are for these Dell models:- Latitude(TM) D410, D505, D510, D600, D610, D800, D810.
- Inspiron(TM) 510M, 600M, 6000, 8600, 9200, 9300, XPS Gen 2.
- Precision(TM) M20 and M70 mobile workstations.
- Latitude(TM) D410, D505, D510, D600, D610, D800, D810.
- Inspiron(TM) 510M, 600M, 6000, 8600, 9200, 9300, XPS Gen 2.
- Dell Precision(TM) M20 and M70 mobile workstations.
Thursday, December 22, 2005
IM Trojan on the Loose
Various reports, including this one: http://news.zdnet.com/2100-1009_22-6002790.html, have a new Instant Messaging trojan being sent to AOL, MSN and Yahoo users. The link, to some lame Santa whats-it, also installs a Rootkit on users Windows PC. The links arrive from people on users "buddy lists" so folks are not as suspicious as they might otherwise be. Remember to never click, download, accept attachments, etc. unless you have been informed before the fact that they are on the way.
Posted by Matthew Carrick at 8:36.18 AM EST | Permanent Link
| Categories: Instant Messaging, Security Alerts, Viruses-Trojans-Worms
| Categories: Instant Messaging, Security Alerts, Viruses-Trojans-Worms
Monday, December 19, 2005
Bluetooth Vulnerability
The folks at digitalmunition.com have found a security hole in most Bluetooth software. The skinny is here: http://www.digitalmunition.com/DMA%5B2005-1214a%5D.txt. F-secure has an overview of the problem here: http://www.f-secure.com/weblog/archives/archive-122005.html#00000741.
Posted by Matthew Carrick at 8:37.32 PM EST | Permanent Link
| Categories: Best Practices, Bluetooth, Privacy Issues, Security Alerts
| Categories: Best Practices, Bluetooth, Privacy Issues, Security Alerts
Wednesday, December 14, 2005
Fake McAfee Site via Email Links
F-Secure has reported instances of fake emails from McAfee with links that point to a bogus site with downloads that contain viruses. Applications do not update themselves by having their parent company send emails encouraging users to visit sites. Be aware what software is installed on your PC. Determine which of these update automagically and keep a grip on what URL's correspond to what websites. If in doubt do not click that link! Never respond to unsolicited emails.
Posted by Matthew Carrick at 9:03.50 AM EST | Permanent Link
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
| Categories: Best Practices, Security Alerts, Viruses-Trojans-Worms
The Thirty Day Rule
An old Javascriprt vulnerability in all Firefox versions prior to 1.0.5 has taken on a new life since the code to take advantage of it has been published on the web. Those of you who are still happily using older versions should upgrade. Best Practices: Always upgrade to the latest version of software at about the thirty daymark after its release because . . . a) This gives any bugs in the release time to be found by all those early adopters allowing the developers time to patch the bug. b) Not enough time has passed that evil virus writers have released exploits. c) Authors of plugins and other add-ons (such as Firefox extensions) will have had time to patch their products.
Posted by Matthew Carrick at 8:50.06 AM EST | Permanent Link
| Categories: Best Practices, Mozilla Firefox, Security Alerts
| Categories: Best Practices, Mozilla Firefox, Security Alerts
Thursday, December 08, 2005
Sony Rootkit Patch Needs Patch
The Sony Rootkit saga lurches ever onward with news that the recently issued patch can, according to Cnet, ". . . allow Sony's original patch to trigger malicious software on a computer, if that software was already in place when the patch was installed."What to do? Dunno. Wait and see? Sounds good.Wednesday, December 07, 2005
IM Worm 'Chats' to Victims
CNET is reporting a new worm that tricks users on America Online's Instant Messenger to download a .pif file containing a trojan that does the usual evil things. The worm, IM.Myspace04.AIM, appears to respond to keywords. Dubious people asking about possible viruses are assured, "lol no its not its a virus". If this trend continues (oh, it will) make sure you only chat with known users and DO NOT download files unless you have an up to date anti-virus, etc. on your Windows machine. You might also want to try using GAIM IM client.
Posted by Matthew Carrick at 12:37.09 PM EST | Permanent Link
Edited on: Thursday, December 22, 2005 8:36.52 AM EST
| Categories: Alternative Apps, Instant Messaging, Security Alerts, Viruses-Trojans-Worms
Edited on: Thursday, December 22, 2005 8:36.52 AM EST
| Categories: Alternative Apps, Instant Messaging, Security Alerts, Viruses-Trojans-Worms
Aardvark
Posted by Matthew Carrick at 11:52.35 AM EST | Permanent Link
| Categories: Firefox Extensions, Mozilla Firefox, Software Tools
| Categories: Firefox Extensions, Mozilla Firefox, Software Tools
Sony Rootkit Patch
SunnComm Makes Security Update Available To Address Recently Discovered Vulnerability On Its MediaMax Version 5 Content Protection Software, Which Is Included On Certain SONY BMG CDs
br> The full scoop is here: http://www.eff.org/news/archives/2005_12.php#004234. Sony has finally (it appears) got the message that Rootkits are bad. Check the end of the article to determine if you have any of the affected titles and if so download and apply the patch.
Posted by Matthew Carrick at 8:51.44 AM EST | Permanent Link
| Categories: Best Practices, Privacy Issues, Security Alerts, Software Tools, Viruses-Trojans-Worms
| Categories: Best Practices, Privacy Issues, Security Alerts, Software Tools, Viruses-Trojans-Worms
Tuesday, December 06, 2005
Google Desktop Patched
Google has patched the security hole in its Google Desktop application as noted here. You may now go back to using Internet Explorer. Sucker.Sunday, December 04, 2005
Object Lesson in Keeping Current
Much like no one likely suspected that Sony would be involved in Rootkits we have a story about hardware containing a trojan. F-secure has the scoop and the previous horrors: http://www.f-secure.com/weblog/archives/archive-112005.html#00000723. The companies had no intention of placing these trojans but you must always be aware of your own security. Be aware that hardware and/or software could be compromised. So, always have an updated anti-virus running and run applications designed to catch spyware, adware and other evils.
Posted by Matthew Carrick at 7:14.43 PM EST | Permanent Link
| Categories: Best Practices, Security Alerts
| Categories: Best Practices, Security Alerts
Phishing with Google Desktop & Internet Explorer 6
If you use Google Desktop and Internet Explorer 6 you run the risk of exposing information on your PC to evil web site operators. The details are here: http://www.theregister.co.uk/2005/12/03/google_desktop_vuln/. The solution? The usual - use Firefox or Opera ;-)
Posted by Matthew Carrick at 6:59.24 PM EST | Permanent Link
| Categories: Mozilla Firefox, Opera, Security Alerts
| Categories: Mozilla Firefox, Opera, Security Alerts