HNS Newsletter Issue 187 - 10.11.2003. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. ------------------------------------------------------------------- FREE GUIDE-128-bit encryption ------------------------------------------------------------------- Thawte is one of the few companies that offers 128 bit supercerts. A supercerts will allow you to extend the highest allowed 128 bit encryption to all your clients even if they use browsers that are limited to 40 bit encryption. ------------------------------------------------------------------- Download a guide to learn more. http://ad.doubleclick.net/clk;6091071;8369141;h ------------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Articles 5) Reviews 6) Software 7) Webcasts 8) Conferences 9) Security world 10) Virus news [ Security news ] ---------------------------------------------------------------- ELECTRONIC CHECKS: HOW SECURE ARE THEY? There's no doubt about it: Computer technology makes life easier for con artists and identity thieves. http://www.net-security.org/news.php?id=3953 HP USES VIRUS CODE TO PROTECT ITS NETWORKS FROM WORMS Hewlett-Packard has demonstrated how computer virus technology can be turned around to protect business networks against hackers and worms. http://www.net-security.org/news.php?id=3954 APPLE PLANS TO REMEDY JAGUAR SECURITY ISSUES Apple Computer said Friday that it plans to issue an update to older versions of Mac OS X to fix security flaws that were patched as part of the new Panther OS. http://www.net-security.org/news.php?id=3955 FOUR WAYS TO SECURE YOUR COMPANY ON A SHOESTRING BUDGET Here are four steps you can take, using zero capital dollars, that will visibly reduce risks and improve your security program. http://www.net-security.org/news.php?id=3956 NEW WORM STEALS USER INFORMATION A new Internet worm that steals information from users' computers and attempts to shut down two Web sites is spreading. http://www.net-security.org/news.php?id=3957 RESIST THE URGE - NO MORE POINT SOLUTIONS Buying the latest tools to secure your assets is not the way forward. A structured plan for your infosec is vital, says Illena Armstrong. http://www.net-security.org/news.php?id=3958 NEW RULES CUT HACKERS LESS SLACK As attacks on computers get more sophisticated, more dangerous and more costly, the bad guys responsible rarely do hard time. http://www.net-security.org/news.php?id=3959 BRAZILIAN SCRIPT KIDDIE ARRESTED IN JAPAN A Brazilian teenager has been arrested in Japan last Friday on suspicion of membership of an international hacking group. http://www.net-security.org/news.php?id=3960 PROCESS, NOT TECHNOLOGY, TIGHTENS SECURITY More of a strategic issue than a technological battle, Compsec conference told. http://www.net-security.org/news.php?id=3961 MONITORING NETWORK INTEGRITY WITH NMAP Is your network vulnerable? Can't afford NIDS? Level the playing field with this open-source tool. http://www.net-security.org/news.php?id=3962 LONGHORN MAY POSE SECURITY CONCERNS Microsoft is portraying Longhorn, the version of Windows due in about three years, as its most secure operating system ever. http://www.net-security.org/news.php?id=3965 CSI - CYBERTERRORISM: MORE SOPHISTICATED THAN PAST WORMS Companies advised to develop deeper understanding of their networks. http://www.net-security.org/news.php?id=3966 IT SECURITY NEEDS A NEW METAPHOR IT security managers are rethinking their approaches to security in large organisations and re-evaluating upcoming threats. http://www.net-security.org/news.php?id=3967 SECURE PROGRAMMER: VALIDATING INPUT This article shows how to validate input -- one of the first lines of defense in any secure program. http://www.net-security.org/news.php?id=3968 USERS HAVE SET SECURITY AGENDA When the IT directors of Royal Mail, BP, ICI and other FTSE 100 companies join together to call for a new universal framework for security, IT suppliers should sit up and pay attention. http://www.net-security.org/news.php?id=3969 SECURITY CONSIDERATIONS FOR LAYER 3 SWITCHES Not everyone is enamored with the idea of bringing layer 3 intelligence into the wiring closet, says Stan Schatt, a vice president at Forrester Research. Problems include managing complex routing tables, troubleshooting Layer 3 routes, and making virtual LANs work. http://www.net-security.org/news.php?id=3970 RED HAT LOOKS TO NSA TO BOLSTER LINUX SECURITY Red Hat Inc's Enterprise Linux 4 will feature far greater support for security policy and process management, thanks to work emerging from the US Government's National Security Agency, ComputerWire has learned. http://www.net-security.org/news.php?id=3971 WEB HOAXES SET TO INCREASE Widespread education needed as more consumers are targeted. http://www.net-security.org/news.php?id=3972 THE LATEST TOP 10 LINUX/UNIX SECURITY HOLES How to fix the 10 points where intruders are most likely to gain entry. http://www.net-security.org/news.php?id=3976 TELIA BLOCKS SPAM-SENDING ZOMBIE PCS TeliaSonera, the leading telecommunications group in the Nordic and Baltic regions, will start to immediately block Internet traffic to and from computers that send junk email or spam, the company announced yesterday. http://www.net-security.org/news.php?id=3977 WORMS QUIET IN OCTOBER Despite a new virus, Mimail.C, hitting inboxes worldwide over the last few days, the virus chart, detailing the most prevalent viruses during October shows very little variation in the worms which have been plaguing systems for the past few weeks. http://www.net-security.org/news.php?id=3978 HOW SECURE IS YOUR E-MAIL? Headlines are flying with stories of incriminating e-mail messages and the many court cases that have been launched by "discovered" e-mails. http://www.net-security.org/news.php?id=3979 DDOS ATTACKS STILL POSE THREAT TO INTERNET It has been little more than a year since a massive data attack struck the underpinnings of the Internet, and security experts say a more coordinated attempt could do even worse damage. http://www.net-security.org/news.php?id=3980 MICROSOFT REEDUCATION CAMPAIGN Microsoft's best chance for regaining the revenue lost to security concerns isn't in eliminating bugs, it's in teaching customers how to use buggy software. http://www.net-security.org/news.php?id=3981 NETWORK SECURITY SECTOR ANALYSIS Security issues have reached global proportions, and spending in the sector is rising rapidly. http://www.net-security.org/news.php?id=3982 MICROSOFT TO OFFER BOUNTY ON HACKERS Microsoft will announce on Wednesday that it will offer two $250,000 bounties for information that leads to the arrest of the people who released the MSBlast worm and the SoBig virus, CNET News.com has learned. http://www.net-security.org/news.php?id=3983 WHAT'S NEW IN CERTIFICATION? With the purpose of certification being to verify that an individual has an authenticated level of acumen/proficiency, there is never an end to the stream of new certifications that vendors release or update. This article focuses on new and upcoming certifications. http://www.net-security.org/news.php?id=3984 RECENT VULNERABILITIES SHARPEN FOCUS ON SECURITY A growing plague of worms, viruses and various computing vulnerabilities has forced security issues to center stage for enterprise IT managers. http://www.net-security.org/news.php?id=3985 STARTUP SAYS QUANTUM CRYPTO IS REAL Startup MagiQ Technologies is shipping what appears to be the first security system based on quantum cryptography. http://www.net-security.org/news.php?id=3986 APPLE NEEDS MORE THAN SKIN-DEEP SECURITY If recent events have shown anything, it's that Apple Computer needs to get more serious about handling security issues in Mac OS X. http://www.net-security.org/news.php?id=3987 MOTOROLA NOW OFFERS ADVANCED ENCRYPTION STANDARD Motorola now offers advanced encryption standard on its Canopy wireless broadband equipment. http://www.net-security.org/news.php?id=3989 PC SECURITY AUDITS FOR BUSINESSES? Publicly traded U.S. corporations would have to certify that they have conducted an annual computer security audit, according to a draft of long-awaited legislation the U.S. House of Representatives is preparing. http://www.net-security.org/news.php?id=3990 IS WIRELESS WORLD A SECURE ONE FOR TRAVELERS? The wireless world is spreading rapidly, offering business travelers equipped with laptops or other devices the chance to connect everywhere from coffee shops to hotel lobbies. http://www.net-security.org/news.php?id=3991 SECURITY'S BREWING MESS What do low-level programming languages have in common with a scalding hot cup of coffee? Nothing that a little Java won't cure. http://www.net-security.org/news.php?id=3992 CISCO TO UNVEIL SSL VPN FEATURES Technology will come free in new VPN offerings. http://www.net-security.org/news.php?id=3993 WORLDPAY FIGHTS 'MASSIVE, ORCHESTRATED' ATTACK WorldPay, the Royal Bank of Scotland's Internet payment transaction outfit, is continuing to fight a sustained Internet attack which has left its services mostly unavailable for a second day. http://www.net-security.org/news.php?id=3994 ATTEMPTED ATTACK ON LINUX KERNEL FOILED An unknown intruder attempted to insert a Trojan horse program into the code of the next version of the Linux kernel, stored at a publicly accessible database. http://www.net-security.org/news.php?id=3995 OSSI RELEASES EGOVERNMENT WEB SERVICES PLATFORM The Open Source Software Institute (OSSI) announced the release and availability of Project Leopard (Phase 1), the core component of its eGovernment web services platform based on LAMP (Linux, Apache, MySQL, PHP/Perl/Python). http://www.net-security.org/news.php?id=3996 VIRUS WRITERS DISMISS BOUNTY FUND Virus writers won’t be deterred by Microsoft’s $5 million bounty fund to help capture and convict them. http://www.net-security.org/news.php?id=3997 NETWORK PROS 'MAKE SECURITY HAPPEN,' CISO SAYS Kenneth Tyminski is in an unenviable position. As chief information security officer for Prudential Insurance Company of America, he's the first one likely to receive blame when a network security snafu affects his company's bottom line. http://www.net-security.org/news.php?id=3998 ---------------------------------------------------------------- [ Vulnerabilities ] All vulnerabilities are located here: http://www.net-security.org/archive_vuln.php ---------------------------------------------------------------- Microsoft Internet Explorer ClientCaps "isComponentInstalled" and "getComponentVersion" Registry Information Leakage http://www.net-security.org/vuln.php?id=3054 Liteserve Server Log Handling Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3053 ShoutCast Server Denial of Service Vulnerability http://www.net-security.org/vuln.php?id=3052 EServ Memory Leakage Vulnerability http://www.net-security.org/vuln.php?id=3051 BRS WebWeaver 1.06 remote DoS Vulnerability http://www.net-security.org/vuln.php?id=3050 OpenAutoClassifieds Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3049 OpenAutoClassifieds Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3048 PowerPortal v1.1b Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3047 PhpBB SQL Injection Vulnerability http://www.net-security.org/vuln.php?id=3046 Oracle Application Server Multiple SQL Injection Vulnerabilities http://www.net-security.org/vuln.php?id=3045 NIPrint LPD-LPR Print Server Local Help API SYSTEM Vulnerability http://www.net-security.org/vuln.php?id=3044 NIPrint LPD-LPR Print Server Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3043 ---------------------------------------------------------------- [ Advisories ] All advisories are located at: http://www.net-security.org/archive_advi.php ---------------------------------------------------------------- SCO Security Advisory - OpenLinux: Multiple vulnerabilities have reported in Ethereal 0.9.12 (CSSA-2003-030.0) http://www.net-security.org/advisory.php?id=2691 SOT Linux Security Advisory - Updated cups package for SOT Linux 2003 (SLSA-2003:50¸¸) http://www.net-security.org/advisory.php?id=2690 SCO Security Advisory - OpenLinux: ucd-snmp remote heap overflow (CSSA-2003-029.0) http://www.net-security.org/advisory.php?id=2689 SCO Security Advisory - SCO Security Advisory (CSSA-2003-029.0) http://www.net-security.org/advisory.php?id=2688 Conectiva Linux Security Announcement - ethereal (CLA-2003:780) http://www.net-security.org/advisory.php?id=2687 SCO Security Advisory - OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Perl cross-site scripting vulnerability (CSSA-2003-SCO.30) http://www.net-security.org/advisory.php?id=2686 SCO Security Advisory - OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7: Multiple vulnerabilities affecting several components of gwxlibs (CSSA-2003-SCO.29) http://www.net-security.org/advisory.php?id=2685 SCO Security Advisory - OpenServer 5.0.7 OpenServer 5.0.6 OpenServer 5.0.5 : Various Apache security fixes (CSSA-2003-SCO.28) http://www.net-security.org/advisory.php?id=2684 SCO Security Advisory - OpenServer 5.0.7 : OpenSSH: multiple buffer handling problems (Advisory number: CSSA-2003-SCO.24.1) http://www.net-security.org/advisory.php?id=2683 Conectiva Linux Security Announcement - cups (CLA-2003:779) http://www.net-security.org/advisory.php?id=2682 Conectiva Linux Security Announcement - net-snmp (CLA-2003:778) http://www.net-security.org/advisory.php?id=2681 Bugzilla Security Advisory - SQL injection, information leak http://www.net-security.org/advisory.php?id=2680 Debian Security Advisory - New PostgreSQL packages fix buffer overflow (DSA 397-1) http://www.net-security.org/advisory.php?id=2679 HP Security Bulletin - Tru64 UNIX sendmail Potential Security Vulnerability (SSRT3631) http://www.net-security.org/advisory.php?id=2678 Conectiva Linux Security Announcement - thttpd (CLA-2003:777) http://www.net-security.org/advisory.php?id=2677 Conectiva Linux Security Announcement - ntop (CLA-2003:776) http://www.net-security.org/advisory.php?id=2676 Mandrake Linux Security Update Advisory - cups (MDKSA-2003:104) http://www.net-security.org/advisory.php?id=2675 Conectiva Linux Security Announcement - apache (CLA-2003:775) http://www.net-security.org/advisory.php?id=2674 Conectiva Linux Security Announcement - bugzilla (CLA-2003:774) http://www.net-security.org/advisory.php?id=2673 Guardian Digital Security Advisory - buffer overflow in mod_alias and mod_rewrite http://www.net-security.org/advisory.php?id=2672 Cisco Security Advisory - SSL Implementation Vulnerabilities (Revision 2.0) http://www.net-security.org/advisory.php?id=2671 Slackware Security Advisory - apache security update (SSA:2003-308-01) http://www.net-security.org/advisory.php?id=2670 Apple Security Advisory - Terminal (APPLE-SA-2003-11-04 ) http://www.net-security.org/advisory.php?id=2669 Guardian Digital Security Advisory - openssl ASN.1 parsing denial of service (ESA-20031104-029 ) http://www.net-security.org/advisory.php?id=2668 SCO Security Advisory - UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : CDE libDtHelp buffer overflow (CSSA-2003-SCO.31) http://www.net-security.org/advisory.php?id=2667 Red Hat Security Advisory - Updated CUPS packages fix denial of service (RHSA-2003:275-01) http://www.net-security.org/advisory.php?id=2666 HP Security Bulletin - Tru64 UNIX sendmail Potential Security Vulnerability (SSRT3631) http://www.net-security.org/advisory.php?id=2665 Mandrake Linux Security Update Advisory - postgresql (MDKSA-2003:102) http://www.net-security.org/advisory.php?id=2664 Mandrake Linux Security Update Advisory - apache (MDKSA-2003:103) http://www.net-security.org/advisory.php?id=2663 ---------------------------------------------------------------- [ Articles ] All articles are located at: http://www.net-security.org/articles_main.php Articles can be contributed to articles@net-security.org ---------------------------------------------------------------- RSA CONFERENCE 2003 OPENING WITH RSA CEO KEYNOTE SPEECH "Despite the great efforts, we have not made sufficient progress to make the Internet a safer place". http://www.net-security.org/article.php?id=591 1ST EUROPEAN INFORMATION SECURITY AWARDS The opening day of this year's annual RSA Conference Europe event, hosted a ceremony of announcing the winners of inaugural European Information Security Awards. http://www.net-security.org/article.php?id=593 MICROSOFT DETAILS NEW SECURITY INNOVATIONS Today at RSA Conference 2003, Mike Nash, corporate vice president of the Security Business Unit at Microsoft, detailed a series of new products and programs designed to help customers enhance the security of their computers and networks. http://www.net-security.org/article.php?id=592 SSL VPN GATEWAYS: A NEW APPROACH TO SECURE REMOTE ACCESS Secure Sockets Layer Virtual Private Networks are quickly gaining popularity as serious contenders in the remote-access marketplace. Analysts predict that products based on SSL VPN technology might even replace IP Security Protocol VPNs as remote–access solutions. http://www.net-security.org/article.php?id=595 THE ANATOMY OF CROSS SITE SCRIPTING Many documents discuss the actual insertion of HTML into a vulnerable script, but stop short of explaining the full ramifications of what can be done with a successful XSS attack. While this is adequate for prevention, the exact impact of cross site scripting attacks has not been fully appreciated. This paper will explore those possibilities. http://www.net-security.org/article.php?id=596 ---------------------------------------------------------------- [ Reviews ] All reviews are located at: http://www.net-security.org/reviews.php ---------------------------------------------------------------- REAL 802.11 SECURITY: WI-FI PROTECTED ACCESS AND 802.11I With the development of wireless technology, wireless security issues become more and more important. This book helps you to understand how wireless network security operates and offers you advice for a number of wireless implementation issues you might have to deal with. http://www.net-security.org/review.php?id=111 ---------------------------------------------------------------- [ Software ] Windows software is located at: http://net-security.org/software_main.php?cat=1 Linux software is located at: http://net-security.org/software_main.php?cat=2 ---------------------------------------------------------------- BITDEFENDER ANTI MIMAIL The worm spreads itself via email, attatched as "photos.zip" and is found in mails with subject "Re[2]: our private photos". Download and run this removal to clean your system. http://www.net-security.org/software.php?id=522 ---------------------------------------------------------------- [ Webcasts ] All webcasts are located at: http://www.net-security.org/webcasts.php ---------------------------------------------------------------- Tripwire for Network Devices: Overview and Product Demo Organized by Tripwire on 11 November 2003, 9:00 AM PDT http://www.net-security.org/webcast.php?id=120 The Basics of WLAN Security Organized by Funk Software on 11 November 2003, 1:00 PM EDT http://www.net-security.org/webcast.php?id=89 Wireless LAN Security: Risks & Defenses Organized by AirDefense on 11 November 2003, 2:00 PM ET http://www.net-security.org/webcast.php?id=77 Accelerating XSLT Development with Visual XSLT 2.0 Organized by ActiveState on 12 November 2003, 10:00 AM PST http://www.net-security.org/webcast.php?id=132 Unix to Windows Migration and Interoperability Organized by Microsoft on 12 November 2003, 11:30 AM PT http://www.net-security.org/webcast.php?id=95 Approaches to Wireless LAN Monitoring for Improved Security & Management Organized by AirDefense on 12 November 2003, 2:00 PM ET http://www.net-security.org/webcast.php?id=75 Wireless LAN Security: Risks & Defenses for Financial Service Providers Organized by AirDefense on 12 November 2003, 2:00 PM ET http://www.net-security.org/webcast.php?id=81 Stopping Spam with Sophos PureMessage Organized by ActiveState on 13 November 2003, 10:00 AM PST http://www.net-security.org/webcast.php?id=130 Tripwire for Servers: Overview and Product Demo Organized by Tripwire on 13 November 2003, 11:00 AM PDT http://www.net-security.org/webcast.php?id=123 Penetration Testing with CORE IMPACT Organized by Core Security Technologies on 13 November 2003, 11:00 AM ET http://www.net-security.org/webcast.php?id=127 Inside Windows 2003 Infrastructure Networking Services Organized by Microsoft on 14 November 2003, 9:30 AM PT http://www.net-security.org/webcast.php?id=98 Threats and Countermeasures—Improving Web Application Security Organized by Microsoft on 17 November 2003, 11:00 AM PT http://www.net-security.org/webcast.php?id=99 Tripwire for Servers: Overview and Product Demo Organized by Tripwire on 18 November 2003, 11:00 AM PDT http://www.net-security.org/webcast.php?id=124 Secure Your Networks: Wireless Set Up and Security Organized by Microsoft on 18 November 2003, 1:00 PM PT http://www.net-security.org/webcast.php?id=100 Best Practices: Taking Proactive Measures Before The Next Exploit Organized by eEye on 18 November 2003, 2:00 PM EST http://www.net-security.org/webcast.php?id=86 ---------------------------------------------------------------- [ Conferences ] All conferences are located at: http://www.net-security.org/conferences.php ---------------------------------------------------------------- Detroit SecureWorld Expo Organized by Seguro Group - 11 November-12 November 2003 http://www.net-security.org/conference.php?id=31 SANS Network Security 2003 Annual Conference Organized by SANS - 13 November-19 November 2003 http://www.net-security.org/conference.php?id=45 SC Magazine Conference 2003 Organized by West Coast Publishing - 13 November-14 November 2003 http://www.net-security.org/conference.php?id=57 ApacheCon US 2003 Organized by The Apache Software Foundation - 16 November- 19 November 2003 http://www.net-security.org/conference.php?id=21 Cartes & IT Security Congress 2003 Organized by Cartes - 18 November-20 November 2003 http://www.net-security.org/conference.php?id=58 Australian Information Warfare and IT Security Conference 2003 Organized by University of South Australia - 20 November- 21 November 2003 http://www.net-security.org/conference.php?id=23 Austin HIPAA Security and Privacy Conference 2003 Organized by Data Connectors - 21 November-21 November 2003 http://www.net-security.org/conference.php?id=37 Networkers Africa 2003 Organized by Cisco Systems - 24 November-26 November 2003 http://www.net-security.org/conference.php?id=70 Le Salon de la Securite Informatique Organized by Reed Expositions France - 26 November-27 November 2003 http://www.net-security.org/conference.php?id=33 e-Gov Homeland Security Conference 2003 Organized by e-gov - 2 December-3 December 2003 http://www.net-security.org/conference.php?id=76 The Forum on Information Warfare Organized by MIS Training Institute - 3 December-4 December 2003 http://www.net-security.org/conference.php?id=8 IndoCrypt 2003 Organized by Indian Statistical Institute - 8 December- 10 December 2003 http://www.net-security.org/conference.php?id=14 Department of Defense Cyber Crime Conference Organized by Technology Forums - 8 December-12 December 2003 http://www.net-security.org/conference.php?id=28 Infosecurity 2003 Organized by Information Security Magazine /ISSA - 9 December- 11 December 2003 http://www.net-security.org/conference.php?id=3 HITBSecConf2003 Organized by Hack In The Box - 12 December-14 December 2003 http://www.net-security.org/conference.php?id=64 ---------------------------------------------------------------- [ Security world ] All press releases are located at: http://www.net-security.org/press_main.php Send your press releases to press@net-security.org ---------------------------------------------------------------- iS3 Announces Global Strategic Alliance With Visa International http://www.net-security.org/press.php?id=1822 National Background Data Adapts Astaro for IT Security http://www.net-security.org/press.php?id=1821 Northeast Security Services Organization Recommends That Small and Medium Businesses Pay Special Attention to Information Security http://www.net-security.org/press.php?id=1820 Stonylake Solutions Announced The Release of InsideOut Firewall Reporter Version 3.1 http://www.net-security.org/press.php?id=1819 Cobion says Illegal Online Music Sites More than Doubled in 2003 http://www.net-security.org/press.php?id=1818 Internet Awareness and Advisory Foundation Selects Cobion's OrangeBox for Family Friendly Filtering http://www.net-security.org/press.php?id=1817 Vexira Antivirus For Linux Chosen To Protect KPNQwest, The Leading ISP In Portugal http://www.net-security.org/press.php?id=1816 Websense Award-Winning Master Database Reaches 5 Million Web Site Milestone http://www.net-security.org/press.php?id=1815 Mirapoint Raises The Bar For Spam Protection With Full-Spectrum Email Security Technology http://www.net-security.org/press.php?id=1814 Nasstar Deploys Mirapoint Secure Message Networks Infrastructure http://www.net-security.org/press.php?id=1813 KeyFocus Announces the World's First Windows Networking Emulation Honeypot http://www.net-security.org/press.php?id=1812 Bluesocket ‘Bluesockets’ 200+ Campuses with Wireless LAN Security and Management Systems http://www.net-security.org/press.php?id=1811 Trend Micro InterScan Messaging Security Suite Integrates Critical Messaging Security Applications http://www.net-security.org/press.php?id=1810 Northeastern University Deploys Meetinghouse’s AEGIS Solution for Wireless LAN Security http://www.net-security.org/press.php?id=1809 Spam and Offensive Email a Growing Concern for Educational Institutions http://www.net-security.org/press.php?id=1808 Prominent UK University Deploys Blue Coat and Secure Computing for Advanced Web Filtering http://www.net-security.org/press.php?id=1807 TFS Technology Show Implementation of RSA SecurID Token on the Workstation to Increase Security for Windows and Network Applications http://www.net-security.org/press.php?id=1806 Swivel PINsafe M2F V2.1, Mobile, Two-Factor Authentication, European Debut at RSA Europe 2003 http://www.net-security.org/press.php?id=1805 RSA Security Teams with Accenture to Deliver Identity and Access Management http://www.net-security.org/press.php?id=1804 nCipher Dramatically Boosts Secure Web Server Performance With New Hardware Security Module http://www.net-security.org/press.php?id=1803 Zone Labs Begins Common Criteria Certification Process For its Enterprise Endpoint Security Solution, Integrity http://www.net-security.org/press.php?id=1802 New Zone Labs Integrity 4.5 Strengthens Network Security Policy Enforcement for Today's Borderless Enterprise http://www.net-security.org/press.php?id=1801 ---------------------------------------------------------------- [ Virus News ] All virus news are located at: http://www.net-security.org/viruses.php ---------------------------------------------------------------- Weekly Virus Report - Daker.A and Four Variants of Mimail Worms http://www.net-security.org/virus_news.php?id=325 ---------------------------------------------------------------- Questions, contributions, comments or ideas go to: Help Net Security staff staff@net-security.org http://net-security.org ---------------------- Unsubscribe from this weekly digest on: http://www.net-security.org/subscribe.php The archive of the newsletter in TXT and PDF format is available http://www.net-security.org/newsletter_archive.php ------------------------------------------------------------------- FREE GUIDE-128-bit encryption ------------------------------------------------------------------- Thawte is one of the few companies that offers 128 bit supercerts. A supercerts will allow you to extend the highest allowed 128 bit encryption to all your clients even if they use browsers that are limited to 40 bit encryption. ------------------------------------------------------------------- Download a guide to learn more. http://ad.doubleclick.net/clk;6091071;8369141;h -------------------------------------------------------------------