HNS Newsletter Issue 185 - 27.10.2003. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. ---------------------------------------------------------------- Get Thawte’s NEW Step-by-Step SSL Guide for Apache ---------------------------------------------------------------- In this guide you will find out how to test, purchase, install and use a Thawte Digital Certificate on you Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. Get you copy of this new guide now: http://ad.doubleclick.net/clk;6091061;8369142;h ---------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Articles 5) Reviews 6) Software 7) Webcasts 8) Conferences 9) Security world 10) Virus news [ Security news ] ---------------------------------------------------------------- APPLICATION SECURITY COMES TO FIREWALLS Firewall maker NetScreen is giving its products the ability to inspect application data, in order to protect networks better. However, other vendors such as NetContinuum say the idea is not so new. http://www.net-security.org/news.php?id=3839 DESKTOP AND SERVER SECURITY PULL TOGETHER Network Associates will launch an integrated software security system that covers desktop and server systems. http://www.net-security.org/news.php?id=3840 LET COMMON SENSE GUIDE SECURITY ROI I got another letter from a reader the other day telling me that companies will always consider security a "grudge" spend, despite the increasing awareness of the need to protect our computers, networks, and information. Why? Because there's no demonstrable ROI for executives making purchase decisions. http://www.net-security.org/news.php?id=3841 AFTER TROJAN HORSES AND WORMS, HERE COMES THE BEAST Adapted spyware software is the ultimate in online security threats, allowing hackers to take full control of victims' computers. http://www.net-security.org/news.php?id=3842 ROMANIA EMERGES AS NEXUS OF CYBERCRIME It was nearly 70 degrees below zero outside, but the e-mail on a computer at the South Pole Research Center sent a different kind of chill through the scientists inside. http://www.net-security.org/news.php?id=3843 PC WHIZ CLEARED IN HOUSTON HACKING A British court has cleared a teenager of hacking into the computer of the U.S. port of Houston, Texas, after the youth testified his own computer had been taken over by someone else to mount the attack. http://www.net-security.org/news.php?id=3847 PEERING THROUGH FIREWALLS New keynote service tracks end-to-end net performance. http://www.net-security.org/news.php?id=3848 FOR CYBERSECURITY, IT'S SHARE AND SHARE ALIKE Executives warn that groups must work together to protect infrastructures. http://www.net-security.org/news.php?id=3849 AN OVERVIEW OF HIGH-TECH SURVEILLANCE In our high-tech world, machines track personal records, see through walls, and screen facial features. Will electronic surveillance mean better security, or an end to privacy? http://www.net-security.org/news.php?id=3850 ATTAINING WEB SERVICES SECURITY There's no security in the Web services standards and XML is human-readable, so Web services are inherently insecure. http://www.net-security.org/news.php?id=3851 COMPUTER VIRUSES RAMPANT IN CHINA If you use a computer in China, the chances are that you have to do battle with a virus sooner or later. http://www.net-security.org/news.php?id=3852 MICROSOFT ANSWERS EU ANTITRUST CHARGES Despite complaining this month that it wanted more time, Microsoft Corp. filed its response to European Union antitrust charges just before the deadline expired, an EU spokeswoman said Monday. http://www.net-security.org/news.php?id=3853 SPAM FIGHTERS DEFEAT NUISANCE JUNK MAIL LAWSUIT Anti-spam activists have won an important legal battle against Florida-based junk mailers. http://www.net-security.org/news.php?id=3854 RISK MANAGEMENT FALLS SHORT A new report argues that business leaders have a poor understanding of IT-related risks and responsibilities. http://www.net-security.org/news.php?id=3855 PHONE, POWER, COMPUTERS VULNERABLE, EXPERT SAYS The nation's phone system, power grid and computer networks remain vulnerable to a large-scale terrorist attack, a security expert warned Monday. http://www.net-security.org/news.php?id=3856 VERISIGN PUTS ITS SECURITY NEWS ONLINE Verisign warns of increased fraud. http://www.net-security.org/news.php?id=3857 MICROSOFT PUSHES FOR SECURITY IN LONGHORN Microsoft will preview its forthcoming server-stack software at the Professional Developers Conference in Los Angeles. http://www.net-security.org/news.php?id=3858 WOMAN SENTENCED FOR READING E-MAIL OF HUSBAND'S EX-WIFE A judge sentenced an Arizona woman to 60 days home detention for intercepting her husband's ex-wife's e-mail, saying the penalty is a warning to others who might be tempted to do the same. http://www.net-security.org/news.php?id=3859 DISCLOSURE PLAN WON'T HELP Encouraging publicly-traded companies to disclose their cyber security efforts would only force them to choose between providing vague and useless platitudes, or specific and dangerous details. http://www.net-security.org/news.php?id=3860 THE EVOLUTION OF A CRYPTOGRAPHER Bruce Schneier, who literally wrote the book on cryptography, talks with Senior Editor Scott Berinato about his holistic view of security, both physical and technical. http://www.net-security.org/news.php?id=3861 THE GREAT AMERICAN PRIVACY MAKEOVER An exclusive PC World survey reveals that even savvy Web users can do more to safeguard their privacy and data. Take the quiz and find out how vulnerable you are; then use our tips to improve your score. http://www.net-security.org/news.php?id=3864 SSL-VPNS SIZZLE The SSL-VPN market is expected to heat up with NetScreen's recent US$265 million ($461.1 million) acquisition of Neoteris. http://www.net-security.org/news.php?id=3865 AN EASY WAY TO AVOID SPAM Here's a method of filtering e-mail by using a customizable Perl script. http://www.net-security.org/news.php?id=3866 GETTING THE POINT ON SECURITY SOFTWARE Residents of Israel, a country surrounded by potential enemies, learn to take security seriously. It is not surprising that Check Point software emerged from this environment. http://www.net-security.org/news.php?id=3867 WHAT THE HACK, IT’S MOBILEPHONES NOW For computer-hackers and virus-writers, the next frontier in mischief is the cellphone. http://www.net-security.org/news.php?id=3868 THE CASE OF THE TROJAN WOOKIEE The complex nature of trials involving Trojan horses and flaws in Windows not only puts juries to sleep, it also potentially opens the door to some wacky defence arguments. http://www.net-security.org/news.php?id=3869 ENTRUST TO PROVIDE PKI FOR FBI Northrop Grumman Information Technology selected Entrust Inc. to provide public-key infrastructure (PKI) for the FBI. http://www.net-security.org/news.php?id=3870 BALLMER: WINDOWS IS AS SECURE AS LINUX Security in the Windows operating system matches that of Linux, its open source rival, Microsoft Chief Executive Officer Steve Ballmer told delegates to the Gartner Symposium in Orlando. http://www.net-security.org/news.php?id=3871 NETWORK ASSOCIATES' NEW FOCUS: INTRUSION PREVENTION Network Associates laid out a new product strategy focused on intrusion prevention before a gathering of 650 customers and partners. http://www.net-security.org/news.php?id=3872 SECURITY WOES AREN'T UNIQUE TO MICROSOFT Sure, Microsoft's security snafus are easy targets for critics, but the truth is that the company is doing a good job shouldering responsibility for issues related to its software. Or is it? http://www.net-security.org/news.php?id=3873 DEFENSE DEPARTMENT BEGINS IPV6 INTEROPERABILITY TESTS The Moonv6 network project will be used to study next-generation Internet technology. http://www.net-security.org/news.php?id=3875 PROPER TOOLS SECURE INTERNET CONNECTIONS You've made the leap to broadband. Now what? http://www.net-security.org/news.php?id=3876 JUSTICE E-CENSORSHIP GAFFE SPARKS CONTROVERSY The Department of Justice used Microsoft Word's highlight tool to black out the sensitive portions of a key report on internal workplace diversity, before releasing it to the public as a PDF file. Guess what happened next. http://www.net-security.org/news.php?id=3877 LOCALLY BASED RESOURCE CENTER SUPPORTS VICTIMS OF IDENTITY THEFT About 6:30 a.m., the nationally known Identity Theft Resource Center opens for business when Jay Foley steps from his living room into the cramped office carved out of the foyer of a modest Mira Mesa home. http://www.net-security.org/news.php?id=3878 SECURITY IN CEO SPOTLIGHT Execs extol improvements despite Web services challenge. http://www.net-security.org/news.php?id=3879 BE CAREFUL IN CREATING PASSWORDS I registered with my credit card company so I could view my transactions online, but I typed in the wrong password and checked the "remember my password" box. Now when I try to get to the credit card information, it is grayed out, and the Web site rejects me. http://www.net-security.org/news.php?id=3880 SECURITY AND THE MUCH NEEDED UNIFICATION OF SERVERS Today news sites repeated the monthly Microsoft execute says "Linux is insecure" articles. And while they are comparing apples with eggs (as Linux distributions ship with far more servers and network services than Microsoft offers), it’s hard to deny the fact that Linux is also insecure. http://www.net-security.org/news.php?id=3881 SA COMPANIES STARTED LATER BUT MOVING FASTER WITH SECURITY Though information and communications technology (ICT) security issues don't change fundamentally from country to country, the speed and extent of adoption of enterprise-wide security measures depends on country-specific triggers. http://www.net-security.org/news.php?id=3882 INTERNET SECURITY WOES BOOST SYMANTEC'S BOTTOM LINE A summer of big virus and worm attacks, such as Sobig and Blaster, provided a healthy boost to Internet security company Symantec Corp.'s bottom line. http://www.net-security.org/news.php?id=3883 JOE AVERAGE USER IS IN TROUBLE As security professionals we're at the forefront, like it or not, and it's up to us to help lessen the myriad of user problems we see around us. http://www.net-security.org/news.php?id=3884 SECURITY WOES HIT MICROSOFT BALANCE SHEET A wave of security problems is hurting Microsoft's bottom line. http://www.net-security.org/news.php?id=3885 HACKERS STEAL EASILY GUESSED PASSWORDS Users remain the weakest link when it comes to IT security, according to a survey. http://www.net-security.org/news.php?id=3886 US STUDY FINDS 7 PERCENT BOUGHT PRODUCTS IN RESPONSE TO 'SPAM' Seven percent of American email users have ordered a product or service offered in an unsolicited email, although not all of this is pure "spam", according to a study by Pew Internet and American Life. http://www.net-security.org/news.php?id=3887 DEFENSE DEPARTMENT WANTS RFID TAGS ON EVERYTHING BUT SAND The US Department of Defense has announced a sweeping policy to slap an electronic tag on every item in its inventory - well, almost every item. http://www.net-security.org/news.php?id=3888 FIGHTING INTERNET WORMS WITH HONEYPOTS This paper evaluates the usefulness of using honeypots to fight Internet worms, including a discussion on capturing a worm, redirecting worm traffic to fake services, launching counter attacks to clean infected hosts, and finally removing the worm or negating its effects. http://www.net-security.org/news.php?id=3889 SON OF MSBLAST ON THE WAY? A program that exploits a software vulnerability Microsoft recently described could spell trouble for companies that haven't quickly patched their system, security experts said this week. http://www.net-security.org/news.php?id=3890 A TESTING GROUND FOR TOOLS TO DEFEND THE WEB A consortium of university and industrial scientists has created a computer network designed to test a new generation of tools that may one day lead to a smarter, more secure Internet that can spot problems like congestion and viruses before they affect individual computers. http://www.net-security.org/news.php?id=3891 TAKING BACK CONTROL OF YOUR NETWORK BANDWIDTH You can’t manage what you can’t see. So it’s not surprising that with corporate networks congested more and more by P2P, streaming media, and other “leisure” traffic, network admins are increasingly turning to specialized network management software packages and appliances to give them the information they need to take back control of their bandwidth. http://www.net-security.org/news.php?id=3893 ---------------------------------------------------------------- [ Vulnerabilities ] All vulnerabilities are located here: http://www.net-security.org/archive_vuln.php ---------------------------------------------------------------- SUN Java Virtual Machine Implementation Vulnerability http://www.net-security.org/vuln.php?id=3018 CensorNet Proxy Service Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3017 Gast Arbeiter Privilege Escalation Vulnerability http://www.net-security.org/vuln.php?id=3016 FuzzyMonkey MyClassifieds SQL SQL Injection Vulnerability http://www.net-security.org/vuln.php?id=3015 DeskPRO Multiple SQL Injection Vulnerabilities http://www.net-security.org/vuln.php?id=3014 Opera HREF Escaped Server Name Overflow Vulnerability http://www.net-security.org/vuln.php?id=3013 ByteHoard Directory Traversal Vulnerability http://www.net-security.org/vuln.php?id=3012 PHP-Nuke Path Disclosure Vulnerability http://www.net-security.org/vuln.php?id=3011 cpCommerce File Inclusion Vulnerability http://www.net-security.org/vuln.php?id=3010 Microsoft PCHealth Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3009 Bajie HTTP JServer Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3008 Microsoft Windows Listbox And Combobox Control Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3007 ---------------------------------------------------------------- [ Advisories ] All advisories are located at: http://www.net-security.org/archive_advi.php ---------------------------------------------------------------- Microsoft Exchange Server Security Bulletin Summary for October 2003 (revised) http://www.net-security.org/advisory.php?id=2643 Microsoft Windows Security Bulletin Summary for October 2003 (revised) http://www.net-security.org/advisory.php?id=2642 HP Security Bulletin - Potential vulnerability in nonSSL HP management web agent (SSRT3632) http://www.net-security.org/advisory.php?id=2641 Conectiva Linux Security Announcement - sane (CLA-2003:769) http://www.net-security.org/advisory.php?id=2640 Conectiva Linux Security Announcement - fileutils (CLA-2003:768) http://www.net-security.org/advisory.php?id=2639 Immunix Secured OS Security Advisory - fetchmail, fetchmailconf (IMNX-2003-7+-023-01) http://www.net-security.org/advisory.php?id=2638 SCO Security Advisory - OpenServer 5.0.5 : Insecure creation of files in /tmp (CSSA-2003-SCO.27) http://www.net-security.org/advisory.php?id=2637 SOT Linux Security Advisory - Updated fetchmail package for SOT Linux 2003 (SLSA-2003:47) http://www.net-security.org/advisory.php?id=2636 Turbolinux Security Announcement - kernel and kdebase (20/Oct/2003) http://www.net-security.org/advisory.php?id=2635 OpenPKG Security Advisory - ircd (OpenPKG-SA-2003.045) http://www.net-security.org/advisory.php?id=2634 Conectiva Linux Security Announcement - gdm (CLA-2003:766) http://www.net-security.org/advisory.php?id=2633 Conectiva Linux Security Announcement - ircd (CLA-2003:765) http://www.net-security.org/advisory.php?id=2632 SCO Security Advisory - OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Multiple security vulnerabilities in Xsco (CSSA-2003-SCO.26) http://www.net-security.org/advisory.php?id=2631 ---------------------------------------------------------------- [ Articles ] All articles are located at: http://www.net-security.org/articles_main.php Articles can be contributed to articles@net-security.org ---------------------------------------------------------------- INTERVIEW WITH ARNE VIDSTROM The Swedish security reseacher, author of various security tools, who runs the web site ntsecurity.nu talks with Help Net Security about online security issues, offers network security tips, shares his thoughts on the full disclosure of vulnerabilities, and much more. http://www.net-security.org/article.php?id=579 WIRELESS DATA SERVICES SECURITY PRODUCT ANNOUNCED Bluefire Security Technologies announced the offering of an OEM solution designed to help wireless carriers spur adoption of data services by eliminating the mobile security concerns of enterprise customers. http://www.net-security.org/article.php?id=580 NEW SERVICE HELPS ENTERPRISE IT ADDRESS ENDPOINT VULNERABILITIES The iPass Endpoint Policy Management service helps the IT department stay out in front of threats to the corporate network caused by worms, viruses and other malicious agents, reducing the risk of lost productivity and network downtime. http://www.net-security.org/article.php?id=581 DECEMBER BRINGS HACKERS TO MALAYSIA As the organizers note, the main aim of the Hack In The Box Security Conference 2003 is the dissemination, discussion and sharing of network security information. It's going to be held from December 12th to 14th in Kuala Lumpur, Malaysia. http://www.net-security.org/article.php?id=582 MOD_SECURITY 1.7 APACHE MODULE RELEASED Mod_security is an Apache module whose purpose is to protect vulnerable applications and reject human or automated attacks. It is an open source intrusion detection and prevention system for Apache. http://www.net-security.org/article.php?id=578 ---------------------------------------------------------------- [ Reviews ] All reviews are located at: http://www.net-security.org/reviews.php ---------------------------------------------------------------- HACKNOTES LINUX AND UNIX SECURITY PORTABLE REFERENCE Written by an experienced information security consultant, this portable reference delivers just the things we expect from this kind of a publication: important and up-to-date information on the common Linux/Unix security vulnerabilities, ways and tools to exploit those vulnerabilities and useful tips on securing and protecting your systems. http://www.net-security.org/review.php?id=109 ---------------------------------------------------------------- [ Software ] Windows software is located at: http://net-security.org/software_main.php?cat=1 Linux software is located at: http://net-security.org/software_main.php?cat=2 ---------------------------------------------------------------- REDFANG 2.5 Redfang finds non-discoverable Bluetooth devices by brute-forcing the last six bytes of the device's Bluetooth address and doing a read_remote_name(). http://www.net-security.org/software.php?id=519 ---------------------------------------------------------------- [ Webcasts ] All webcasts are located at: http://www.net-security.org/webcasts.php ---------------------------------------------------------------- Best of Breed Organized by eSecure Live on 28 October 2003, 3:00 PM ET http://www.net-security.org/webcast.php?id=52 Enterprise Storage: Best Practices Organized by ShoutStream on 29 October 2003, 3:00 PM ET http://www.net-security.org/webcast.php?id=66 Top IT Security Risks of 2004 Organized by eSecure Live on 4 November 2003, 3:00 PM ET http://www.net-security.org/webcast.php?id=65 Improving Router Security with RAT: The Top 10 List Organized by SANS on 5 November 2003, 1:00 PM EST http://www.net-security.org/webcast.php?id=71 Getting the Upper Hand Organized by eSecure Live on 7 November 2003, 3:00 PM ET http://www.net-security.org/webcast.php?id=53 Ten Ways To Hack Proof Your Identity Organized by SANS on 3 December 2003, 1:00 PM EST http://www.net-security.org/webcast.php?id=73 ---------------------------------------------------------------- [ Conferences ] All conferences are located at: http://www.net-security.org/conferences.php ---------------------------------------------------------------- SANS Amsterdam 2003 Organized by SANS - 27 October-1 November 2003 http://www.net-security.org/conference.php?id=63 Storage Networking World 2003 Orlando Organized by Miller Systems - 27 October-30 October 2003 http://www.net-security.org/conference.php?id=71 The 5th Wireless Internet Data & Enterprise Applications Conference Organized by UCLA - 29 October-30 October 2003 http://www.net-security.org/conference.php?id=65 Compsec 2003 Organized by Computers & Security Publication - 30 October- 31 October 2003 http://www.net-security.org/conference.php?id=15 ID Smart: Cards for Government and Healthcare Organized by Computers & Security Publication - 30 October- 31 October 2003 http://www.net-security.org/conference.php?id=17 CSI 30th Annual Computer Security Conference and Exhibition Organized by Computer Security Institute - 2 November- 4 November 2003 http://www.net-security.org/conference.php?id=19 RSA Conference 2003 Europe Organized by RSA Security - 3 November-5 November 2003 http://www.net-security.org/conference.php?id=26 SANS Vienna 2003 Operating System Security Organized by SANS - 3 November-8 November 2003 http://www.net-security.org/conference.php?id=62 SecureXchange 2003 User Conference Organized by Symantec - 4 November-7 November 2003 http://www.net-security.org/conference.php?id=38 ShadowCon 2003 Organized by Technology Forums - 5 November-5 November 2003 http://www.net-security.org/conference.php?id=72 SANS AIAL 2003 Organized by SANS - 6 November-7 November 2003 http://www.net-security.org/conference.php?id=43 360 Security Summit Organized by New Leaf Productions - 6 November-8 November 2003 http://www.net-security.org/conference.php?id=74 Detroit SecureWorld Expo Organized by Seguro Group - 11 November-12 November 2003 http://www.net-security.org/conference.php?id=31 SANS Network Security 2003 Annual Conference Organized by SANS - 13 November-19 November 2003 http://www.net-security.org/conference.php?id=45 SC Magazine Conference 2003 Organized by West Coast Publishing - 13 November-14 November 2003 http://www.net-security.org/conference.php?id=57 ---------------------------------------------------------------- [ Security world ] All press releases are located at: http://www.net-security.org/press_main.php Send your press releases to press@net-security.org ---------------------------------------------------------------- Pointsec for Symbian OS Latest Security Solution from Pointsec http://www.net-security.org/press.php?id=1781 Vontu Adds Three Industry Veterans to Executive Team http://www.net-security.org/press.php?id=1780 GFI's Email Security Testing Zone Launches New Free Email Tests Based On Exploits http://www.net-security.org/press.php?id=1779 Cobion Shows Web Usage with Live Graphical Reports http://www.net-security.org/press.php?id=1778 Central Command Protects The Hebrew University Of Jerusalem From Email Borne Viruses Using Vexira Antivirus For Linux http://www.net-security.org/press.php?id=1777 Panda Software and Softonic Team Up To Protect Computer Security http://www.net-security.org/press.php?id=1776 iPass Helps Mitigate Network Security Risks With New Policy Compliance Tools http://www.net-security.org/press.php?id=1775 TManage Announces SSL-enabled Managed Clientless VPN Service for Remote Network Access at Gartner Symposium/ITxpo 2003 http://www.net-security.org/press.php?id=1774 Sybari s NewProducts Deliver Advanced Protection And Anti-spam Component For Exchange 2003 Users http://www.net-security.org/press.php?id=1773 Trend Micro Promotes 20-Year Industry Veteran To President, North America http://www.net-security.org/press.php?id=1772 MailFrontier Announces Anti-Fraud Products And Strategic Partnerships With Cyveillance And Sygate Technologies To Protect Enterprise And Individual Users From Online Identity Theft http://www.net-security.org/press.php?id=1771 Yankee Group Recommendation to Enterprises: Make Network Integrity Systems an Essential Element of Application Security Architecture http://www.net-security.org/press.php?id=1770 NetContinuum Enters Japanese Market Through Strategic Partnership With Sumitomo http://www.net-security.org/press.php?id=1769 Panda Software Analyzes Past and Future Computer Viruses, in China http://www.net-security.org/press.php?id=1768 Blue Coat Strengthens Executive Team With Three New Appointments http://www.net-security.org/press.php?id=1767 San Antonio Community Hospital’s Doctors, Nurses and Patients Reap Benefits of Trapeze Networks WLAN Mobility System http://www.net-security.org/press.php?id=1766 Monthly IT Security Patch Alerts Will Leave Businesses Vulnerable, Warns NetSecure http://www.net-security.org/press.php?id=1765 Teen Hacker Cleared By Jury - Case Highlights Difficulties For Computer Crime Prosecutors Says Sophos http://www.net-security.org/press.php?id=1764 ---------------------------------------------------------------- [ Virus News ] All virus news are located at: http://www.net-security.org/viruses.php ---------------------------------------------------------------- Weekly Virus Report - Lohack.C, Flop.A and Sexer.A Worms http://www.net-security.org/virus_news.php?id=321 Panda Software Reports the Appearance of Lohack.C http://www.net-security.org/virus_news.php?id=320 ---------------------------------------------------------------- Questions, contributions, comments or ideas go to: Help Net Security staff staff@net-security.org http://net-security.org ---------------------- Unsubscribe from this weekly digest on: http://www.net-security.org/subscribe.php The archive of the newsletter in TXT and PDF format is available http://www.net-security.org/newsletter_archive.php ---------------------------------------------------------------- Get Thawte’s NEW Step-by-Step SSL Guide for Apache ---------------------------------------------------------------- In this guide you will find out how to test, purchase, install and use a Thawte Digital Certificate on you Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. Get you copy of this new guide now: http://ad.doubleclick.net/clk;6091061;8369142;h ----------------------------------------------------------------