Security News Letter

November 1st

 

   
   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here

Download eEye's Retina Vulnerability Scanner Here
 

 

 Kaspersky Anti-Virus: Install & Feel Safe!

Ten Best Practices to Secure Web Services

Enterprise Systems

As more organizations embrace Web services (which opens back-office processes to partners and the Internet), a problem is emerging: who inside the organization is in charge of Web services security?

by Mathew Schwartz

Who’s watching your Web services? As more organizations embrace Web services, opening back-office processes to partners, and the Internet, a problem is emerging: who’s in charge of its security?

Too often, the answer is “nobody.” While Web services development mirrors application development in many ways, most developers aren’t trained in Web services security. Likewise, overseeing secure code development isn't part of a security-manager's duties. To discuss best practices for creating a Web services security-aware organization, Security Strategies spoke with Eugene Kuznetsov, chairman and chief technology officer of XML-aware device manufacturer DataPower. More....

Google Desktop Search Tool Raises Security Concerns

Enterprise Systems

Free hard-drive indexing utility raises corporate security and privacy questions

by Mathew Schwartz

With Google’s recent release of Google Desktop (http://desktop.google.com/), a free program for indexing hard drive contents, organizations may want to evaluate the still-in-beta tool’s potential security and privacy impacts, and adjust their corporate security policies to explicitly permit or deny its use.

A number of information-retrieval tools, such as Blinx, Copernic, Enfish, Lookout, and X1, already have similar functionality—retrieving information from an array of file formats via one interface. To be sure, such tools have been available for years, though it’s only recently, as processor speeds and available hard drive space has grown, that they’ve become more widely used, and useful. Historically, most of these indexing and search programs weren’t free; many organizations limited their use. Likewise, many users choose to not deal with the mandatory time these programs take to create and maintain an index of contents, preferring to use in-program searching instead. More....

Password Memorability and Security

There has been much talk about what is considered a secure password. So it was a true pleasure for me to recently read a fascinating study on this topic that provided some hard numbers to back up the claims.  The study was published in the current issue of IEEE Security and Privacy and is titled "Password Memorability and Security: Empirical Results" by Jeff Yan, Alan Blackwell, Ross Anderson and Alasdair Grant

First some background. Per the article "Human memory for sequences is temporally limited, with a short term capacity of around seven, plus or minus two items. In addition, when humans do remember a sequence of items, those items be familiar chunks such as words or familiar symbols. Finally, human memory thrives on redundancy-we're much better at remembering information we can encode in multiple ways"

So what these folks did was have three separate test groups: More....

Microsoft Finds 22 New Flaws
Despite New Pack, Holes Remain

New Windows flaws prove that security managers must continue to focus on patch management and protection of client systems.
Oct 28, 2004 | By Curtis Franklin Jr.


Worried that you may have spent too much on your patch-management system? Well, you can stop worrying, because that system is about to earn its keep. Microsoft earlier this month issued seven advisories warning of 22 new vulnerabilities found in Windows and related software, including the just-released Windows XP Service Pack 2 (SP2). And all of the new threats will require patches.

The critical security alerts detail vulnerabilities in Windows, Internet Explorer, Excel, SMTP, NNTP, Compressed Folders (.ZIP files) and the Windows shell. Less-critical Threat Bulletins focus on facilities within development systems or application frameworks, including the RPC Runtime Library, DetDDE and the WebDAV XML Message Handler. Among the various operating systems and versions of applications named in the bulletins, Microsoft labeled 12 vulnerabilities "critical," 11 "important" and another 11 either "moderate" or "not critical." More....

Anti-virus companies warn of new Bagle variants
By Paul Roberts
IDG News Service, 10/29/04

New versions of the Bagle worm rolled onto the Internet Friday, prompting anti-virus companies to warn customers about the threat and to push out software updates to spot the new worms.

Three new versions of Bagle have been seen by anti-virus companies, each similar to earlier forms of the worm, which first stormed onto the Internet in January, spreading through infected e-mail file attachments. McAfee rated two of the new worms "medium" threats. Other anti-virus vendors, including Symantec and Sophos, also reported intercepting many samples of the new worms and advised customers to update anti-virus signatures as soon as possible. More.... 

Gmail accounts 'wide open to exploit' - report
By John Leyden
Published Friday 29th October 2004 16:50 GMT
Google's high profile webmail service, Gmail, is vulnerable to a security exploit that might allow hackers full access to a user's email account simply by knowing the user name, according to reports.
The security flaw allows full access to users' accounts, with no need of a password, Israeli news site Nana says . Using a hex-encoded XSS link, the victim's cookie file can be stolen by a hacker, who can later use it to identify himself to Gmail as the original owner of an email account, regardless of whether or not the password is subsequently changed. Following up a tip from an Israeli hacker, journos from the site confirmed the attack and verified the exploit with local security firm Aladdin Knowledge Systems.
It's unclear whether the hole has been maliciously exploited. Google has been notified of the issue and is reportedly working on a fix. No-one from the company was available to update The Register on the issue at time of going to press. 

New Caller I.D. spoofing site opens
By Kevin Poulsen, SecurityFocus Oct 27 2004 8:03PM

Web-based caller I.D. spoofing is back, and this time it's available to everyone.
A new website offer subscribers a simple Web interface to a caller I.D. spoofing system that lets them appear to be calling from any number they choose.
Called "Camophone," the service functions much like the Star38.com site that struggled with an abortive launch last month: a user types in their phone number, the number they wish to call, and the number they'd like to wear as a disguise. The system instantly dials back and patches the call through with the properly-forged caller I.D.
Camophone is being promoted in ads that appear when searching for competitor "Star38" on Google.
More.... 

Advisories Released in the last 15 days

 
29 October 2004
bulletOpenPKG Security Advisory - squid (OpenPKG-SA-2004.048)
bulletOpenPKG Security Advisory - apache (OpenPKG-SA-2004.047)
bulletOpenPKG Security Advisory - postgresql (OpenPKG-SA-2004.046)
bulletUbuntu Security Notice - XML library vulnerabilities (USN-10-1)
bulletGentoo Linux Security Advisory - Archive::Zip: Virus detection evasion (GLSA 200410-31)
bulletUbuntu Security Notice - ppp Denial of Service (USN-12-1)
bulletUbuntu Security Notice - libgd2 vulnerabilities (USN-11-1)
bulletUbuntu Security Notice - tetex-bin vulnerabilities (USN-9-1)
bulletUbuntu Security Notice - Standard C library script vulnerabilities (USN-4-1)
bulletUbuntu Security Notice - gaim vulnerabilities (USN-8-1)
bulletUbuntu Security Notice - imagemagick vulnerability (USN-7-1)
bulletUbuntu Security Notice - postgresql contributed script vulnerability (USN-6-1)
bulletUbuntu Security Notice - gettext vulnerabilities (USN-5-1)
bulletUbuntu Security Notice - GhostScript utility script vulnerabilities (USN-3-1)
bulletUbuntu Security Notice - xpdf vulnerabilities (2-1)
bulletUbuntu Security Notice - PNG library vulnerabilities (1-1)
bulletDebian Security Advisory - postgresql (DSA 577-1)
bulletDebian Security Advisory - squid (DSA 576-1)
28 October 2004
bulletDebian Security Advisory - catdoc (DSA 575-1)
bulletDebian Security Advisory - cabextract (DSA 574-1)
bulletGentoo Linux Security Advisory - PuTTY: Pre-authentication buffer overflow (GLSA 200410-29)
bulletApple Security Update - QuickTime 6.5.2 (APPLE-SA-2004-10-27)
bulletSGI Security Advisory - SGI Advanced Linux Environment 3 Security Update #16 (20041004-01-U)
27 October 2004
bulletConectiva Linux Security Announcement - foomatic-filters (CLA-2004:880)
bulletFedora Legacy Update Advisory - Updated mozilla resolves security vulnerabilities (FLSA:2089)
bulletGentoo Linux Security Advisory - rssh: Format string vulnerability (GLSA 200410-28)
bulletGentoo Linux Security Advisory - mpg123: Buffer overflow vulnerabilities (GLSA 200410-27)
bulletConectiva Linux Security Announcement - kernel (CLA-2004:879)
26 October 2004
bulletBugzilla Security Advisory - Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2
bulletSUSE Security Announcement - xpdf, gpdf, kdegraphics3-pdf, pdftohtml, cups (SUSE-SA:2004:039)
bulletSlackware Security Advisory - apache, mod_ssl, php (SSA:2004-299-01)
bulletConectiva Linux Security Announcement - zlib (CLA-2004:878)
bulletGentoo Linux Security Advisory - socat: Format string vulnerability (GLSA 200410-26)
bulletGentoo Linux Security Advisory - Netatalk: Insecure tempfile handling in etc2ps.sh (GLSA 200410-25)
25 October 2004
bulletHP Security Bulletin - HP-UX stmkfont local unauthorized privileged access ( SSRT4807 rev.0)
bulletGentoo Linux Security Advisory - MIT krb5: Insecure temporary file use in send-pr.sh (GLSA 200410-24)
24 October 2004
bulletGentoo Linux Security Advisory - Gaim: Multiple vulnerabilities (GLSA 200410-23)
bulletGentoo Linux Security Advisory - MySQL: Multiple vulnerabilities (GLSA 200410-22)
bulletFedora Legacy Update Advisory - Updated glibc packages fix flaws (FLSA:1947)
bulletFedora Legacy Update Advisory - Updated Tripwire packages fix security flaw (FLSA:1719)
bulletSlackware Security Advisory - gaim (SSA:2004-296-01)
bulletConectiva Linux Security Announcement - mozilla (CLA-2004:877)
22 October 2004
bulletSUSE Security Announcement - libtiff (SUSE-SA:2004:038)
bulletMandrakelinux Security Update Advisory - cups (MDKSA-2004:116)
bulletMandrakelinux Security Update Advisory - kdegraphics (MDKSA-2004:115)
bulletMandrakelinux Security Update Advisory - gpdf (MDKSA-2004:114)
bulletMandrakelinux Security Update Advisory - xpdf (MDKSA-2004:113)
bulletGentoo Linux Security Advisory - Apache 2, mod_ssl: Bypass of SSLCipherSuite directive (GLSA 200410-21)
bulletMandrakelinux Security Update Advisory - squid (MDKSA-2004:112)
bulletMandrakelinux Security Update Advisory - wxGTK2 (MDKSA-2004:111)
bulletMandrakelinux Security Update Advisory - gaim (MDKSA-2004:110)
bulletGentoo Linux Security Advisory - Xpdf, CUPS: Multiple integer overflows (GLSA 200410-20)
bulletDebian Security Advisory - cupsys (DSA 573-1)
21 October 2004
bulletDebian Security Advisory - ecartis (DSA 572-1)
bulletSUSE Security Announcement - kernel (SUSE-SA:2004:037)
bulletGentoo Linux Security Advisory - Ghostscript: Insecure temporary file use in multiple scripts (GLSA 200410-18)
bulletGentoo Linux Security Advisory - OpenOffice.org: Temporary files disclosure (GLSA 200410-17)
bulletSGI Security Advisory - SGI Advanced Linux Environment 3 Security Update #15 (20041003-01-U)
bulletDebian Security Advisory - libpng3 (DSA 571-1)
bulletDebian Security Advisory - libpng (DSA 570-1)
20 October 2004
bulletMandrakelinux Security Update Advisory - libtiff (MDKSA-2004:109)
bulletMandrakelinux Security Update Advisory - cvs (MDKSA-2004:108)
bulletUS-CERT Technical Cyber Security Alert - Multiple Vulnerabilities in Microsoft Internet Explorer (TA04-293A)
bulletMandrakelinux Security Update Advisory - mozilla (MDKSA-2004:107)
19 October 2004
bulletConectiva Linux Security Announcement - gtk+ (CLA-2004:875)
bulletSCO Security Advisory - UnixWare 7.1.4 UnixWare 7.1.3 : The error handling in the inflate and inflateBack functions in ZLib compression library allows local users to cause a denial of service (SCOSA-2004.17)
bulletGentoo Linux Security Advisory - PostgreSQL: Insecure temporary file use in make_oidjoins_check (GLSA 200410-16)
bulletGentoo Linux Security Advisory - Squid: Remote DoS vulnerability (GLSA 200410-15)
bulletFedora Legacy Update Advisory - Updated kernel resolves security vulnerabilities (FLSA:1804c)
18 October 2004
bulletGentoo Linux Security Advisory - phpMyAdmin: Vulnerability in MIME-based transformation system (200410-14)
bulletDebian Security Advisory - netkit-telnet-ssl (DSA 569-1)

Advisories in the last 15 days

29 October 2004

bulletRealPlayer Zipped Skin File Buffer Overflow Vulnerability
bulletPHP4 cURL open_basedir Bypass Vulnerability
bulletQuake II Server Multiple Vulnerabilites
bulletApple Quicktime for Windows 6.5.2 Code Execution Vulnerability
bulletRealPlayer Malformed Skin Code Execution Vulnerability

27 October 2004

bulletPuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability
bulletPppd 2.4.1 Denial of Service Vulnerability
bulletInetutils TFTP Client DNS resolving buffer overflow Multiple Vulnerabilities
bulletZgv Image Viewing Heap Overflow Multiple Vulnerabilities

26 October 2004

bulletOpenWFE Web Client Multiple Vulnerabilities

25 October 2004

bulletAOL Journals BlogID Information Disclosure Vulnerability
bulletJ2ME Multiple Security Vulnerabilities
bulletDwc_articles 1.6 SQL Injection Vulnerability

22 October 2004

bulletNovell SuSe Linux LibTIFF Heap Overflow Vulnerability

21 October 2004

bulletmpg123 getauthfromurl Buffer Overflow Vulnerability
bulletAge of Sail II 1.04.151 Buffer Overflow Vulnerability

20 October 2004

bulletMultiple Internet Browsers Malformed HTML Vulnerabilities
bulletVypress Tonecast 1.3 Broadcast Crash Vulnerability
bulletcPanel Symlink Chmod Vulnerability
bulletcPanel Hardlink Chown Vulnerability
bulletcPanel Hardlink Backup Vulnerability

19 October 2004

bulletSage Saleslogix Multiple Vulnerabilities
bulletMultiple Vendor Anti-Virus Software Detection Evasion Vulnerability

18 October 2004

bulletCoolPHP 1.0-stable Multiple Vulnerabilities

17 October 2004

bulletProFTPD 1.2.x Remote Users Enumeration Vulnerability
bulletNorton AntiVirus 2004 Script Blocking Failure Vulnerability
bulletYak! 2.1.2 Directory Traversal Vulnerability

 

 

Security Products:

 

Astaro Security Gateway 

 

Available in 3,4,8 or 12 port. Models with Gigabit Ethernet and VLAN support available.

 

Award winning, Rock-solid network security, simple and affordable.

 "...exceptionally polished and extremely robust security gateway for a very reasonable price.... the most polished and easy to use Web-based management system we've seen to date." --- INFOWORLD


Astaro provides six essential security applications in one easy-to-manage package that protects organizations from hackers, viruses, worms, spam and other threats to security and productivity.


Astaro Security Linux offers: 

bullet

firewall

bullet

intrusion protection

bullet

e-mail virus protection

bullet

web virus protection

bullet

spam protection

bullet

VPN gateway

bullet

URL filtering capabilities. 

 

A unified management platform makes it easy to deploy, 
administer, and update a complete network security solution with surprisingly little cost and effort. The software can be installed on a standard Intel PC, or purchased pre-installed on a variety of security appliances.
Based on the best of open source security software, Astaro Security Linux has won numerous awards, and is in use on over 20,000 networks in 60 countries.

Astaro security Linux is extremely scalable, with the ability to protect small office home office/remote office to enterprise implementations  incorporating  features such as High availability, VLANs, Qos and a configuration manager to manage multiple  sites from a single management platform. 

Prices start at $390 for a 10 user license. Educational discounts are available.

 

 

I

Intrusion Prevention Systems

bulletAstaro Security Linux
bulletIntruvert

Vulnerability Scanners

bullet

eEye's Retina

Firewalls

bulletAstaro Security Linux
bulletNetscreen
bulletCheckpoint
bulletPIX

Management

bulletSolarWinds

Virus Control

bulletAstaro Security Linux
bulletMail Marshall

Content Filter

bulletAstaro Security Linux

Services

bulletSecurity audit
bulletPerimeter vulnerability scan
bulletRouter/ switch optimization for security
bulletFirewall checking and configuration
bulletVPN design and Implementation
bulletNetwork design
bulletNetwork based application analysis
bulletNetwork baselining
bulletSecurity baselining
bulletSecurity policies

 

 

  BlackICE PC Protection

This mailing has been performed by Aavex Technology Corporation
42w588 Still Meadows Lane, Elburn IL 60119 USA,  630-365-0025 in compliance with the "CAN-SPAM Act of 2003",  approved and signed by the president of The United States of America on Dec. 16, 2003. For this reason, this email cannot be considered SPAM This newsletter contains commercial advertisement.

 

 

Copyright © 2004 Aavex Technology