HNS Newsletter Issue 213 - 17.05.2004. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. ---------------------------------------------------------------- Windows Server System is integrated server infrastructure software from Microsoft that is designed to work together and interact seamlessly with other data and applications across your IT environment so you can reduce the costs of ongoing operations, deliver highly reliable and secure IT infrastructure, and drive valuable new capabilities for the future growth of your business. For more information visit http://ad.sk.doubleclick.net/clk;8019795;9084238;y ---------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Articles 5) Software 6) Webcasts 7) Conferences 8) Security world 9) Virus news [ Security news ] ---------------------------------------------------------------- WINDOWS XP SERVICE PACK 2 EVEN FOR UNLICENSED USERS Both legitimate and unlicensed users of Microsoft's XP operating system software will be able to download the Service Pack 2 security patch for free. http://www.net-security.org/news.php?id=5175 E-POSTMARK MAY THWART CYBER CROOKS "Right now, none of the ISPs or router vendors is motivated to act, because Microsoft has promised to solve the spam problem by 2006," Penn State professor George Kesidis said. "They have the presumptive monopoly, and they're calling the shots." http://www.net-security.org/news.php?id=5176 WI-FI SECURITY STANDARD TO REQUIRE NEW HARDWARE In June the IEEE is expected to finally ratify the 802.11i security standard that uses for the first time AES (Advanced Encryption Standard) technology, a powerful 128-bit encryption technology. http://www.net-security.org/news.php?id=5177 POLICE: SASSER SUSPECT CONFESSES A German high school student has confessed to creating the "Sasser" worm that generated chaos across the globe by infecting hundreds of thousands of computers, authorities said Saturday. http://www.net-security.org/news.php?id=5178 MYSTERY OF MS'S MISSING AV SOFTWARE Microsoft's plans to improve the security of Windows through the purchase of an anti-virus company almost a year ago appear to be stuck in limbo. The software giant entered the AV market with the surprise acquisition of little known Romanian AV firm GeCAD Software for an undisclosed sum in June last year. http://www.net-security.org/news.php?id=5179 MICROSOFT MODIFYING PALLADIUM Company officials said that a published report that Microsoft has decided to do away with the hardware and software security project was completely inaccurate. http://www.net-security.org/news.php?id=5180 A GUIDE TO CENTRALIZED SPAM AND VIRUS FILTERING This article explores the integration of Sendmail, MIMEDefang, ClamAV, SpamAssassin, and Vipul's Razor as a partial measure against spam and viruses. http://www.net-security.org/news.php?id=5184 COURT TAKES GAG OFF ANTISPAM SERVICE A district court judge has rescinded a temporary restraining order against antispam operation SpamCop, in an early blow to a case brought by self-professed "Spam King" Scott Richter. http://www.net-security.org/news.php?id=5226 CYBER-CRIME LAWS HURT MORE THAN THEY HELP The Council of Europe's Convention on Cybercrime is too far-reaching. http://www.net-security.org/news.php?id=5186 HAND OVER SECURITY Physical and information security have been converging, often under the control of IT. But companies are increasingly moving the role of policing security out of IT and into the hands of an independent CSO. Here's why you should consider doing the same. http://www.net-security.org/news.php?id=5187 CAN MICROSOFT BOUNTY END VIRUSES? Microsoft's $5 million reward for antivirus informants may help catch script kiddies such as the German teenager suspected of authoring a variant of the Sasser worm, but it is unlikely to have any effect on virus writers working for organized crime syndicates, according to security experts. http://www.net-security.org/news.php?id=5188 PHISHING SPREADS IN EUROPE Phishing is slowly becoming more common in languages like Spanish, French, Dutch and German, a senior official of a company that markets security devices for online transactions says. http://www.net-security.org/news.php?id=5189 SECURITY THREATS RAISE CONCERNS ABOUT BLUETOOTH Some IT managers take steps to limit wireless use; vendors claim risks aren't widespread. http://www.net-security.org/news.php?id=5190 HP DEBUTS RFID SERVICES Hewlett-Packard unveiled on Monday services for companies trying to start radio frequency identification projects. http://www.net-security.org/news.php?id=5191 EXPERTS: TIMING OF NEW SASSER WORM RAISES QUESTIONS Questions raised on whether sole author is in custody. http://www.net-security.org/news.php?id=5192 DMCA CHALLENGE TO BE CONSIDERED THIS WEEK The Digital Millennium Copyright Act, better known as the DMCA, is a travesty of law. http://www.net-security.org/news.php?id=5193 LOTTERY SCAMS NEW FLAVOUR OF THE MONTH Lottery scam emails are increasing at an alarming rate, according to Fraudwatch International, the Australian website that protects consumers from identify theft. http://www.net-security.org/news.php?id=5194 WHY COMPUTER SECURITY'S SO PRIMITIVE We've only been working on it for a few years. http://www.net-security.org/news.php?id=5195 SPEC IN WORKS TO SECURE WIRELESS NETWORKS The Trusted Computing Group said Monday that it is working on a specification to ensure that wireless clients connecting to a network won't serve as a back door to worms and crackers. http://www.net-security.org/news.php?id=5196 UNDERSTANDING TCP RESET ATTACKS To better understand the reality of this threat, KernelTrap spoke with Theo de Raadt, the creator of OpenBSD, an operating system which among other goals proactively focuses on security. http://www.net-security.org/news.php?id=5197 MICROSOFT PATCHES NEW WINDOWS FLAW Microsoft on Tuesday detailed a new vulnerability in Windows XP and Windows Server 2003 that could enable an attacker to remotely execute malicious code. http://www.net-security.org/news.php?id=5201 VIRUS ARRESTS CONTINUE, AS DO WORMS Gartner research vice president Richard Stiennon told TechNewsWorld that the recent arrests are likely to deter lower-level virus writers. http://www.net-security.org/news.php?id=5202 SASSER COPYCATS GET BUSY Copycat virus authors have released a pair of worms targeted at the same vulnerability in Microsoft's operating system exploited by the infamous Sasser worm. http://www.net-security.org/news.php?id=5203 MICROSOFT CORRECTS: NO XP SP2 FOR PIRATED COPIES Despite reports indicating that Microsoft Corp. was planning to allow users with pirated copies of Windows XP to install Service Pack 2, the company has confirmed to eWEEK.com that this will not be the case. http://www.net-security.org/news.php?id=5204 RSA FOUNDERS GIVE PERSPECTIVE ON CRYPTOGRAPHY Rivest, Shamir and Adleman implemented public-key cryptography in the 1970s following the landmark work of Whitfield Diffie, Martin Hellman and Ralph Merkle. They then founded RSA Security, which became one of the most respected security companies in the world. http://www.net-security.org/news.php?id=5205 ANALYST: SECURITY WOES ADD TO WINDOWS COST Prominent security analyst John Pescatore has put a new twist on the Windows cost of ownership debate with a call for enterprises to add the expense of managed intrusion prevention software to the price of Microsoft's operating systems. http://www.net-security.org/news.php?id=5206 ANTIVIRUS COMPANIES MUTING FALSE ALARMS They were wrong, and they were annoying, so now they've been stopped. http://www.net-security.org/news.php?id=5207 BROWSER HIJACKERS RUINING LIVES Malicious programs called browser hijackers install a lot of nasty stuff on people's computers. Some victims are facing firings, divorces and even criminal prosecution. http://www.net-security.org/news.php?id=5208 'WHISPERING KEYBOARDS' COULD BE NEXT ATTACK TREND Listen to this: Eavesdroppers can decipher what is typed by simply listening to the sound of a keystroke, according to a scientist at this week's IEEE Symposium of Security and Privacy in Oakland, Calif. http://www.net-security.org/news.php?id=5209 APACHE AUTHENTICATION This article describes authentication and how to control user access. http://www.net-security.org/news.php?id=5210 FEDS COMBINE SMART CARD BUYS Five federal agencies have agreed to pool their smart card needs into a large contract buy of up to 40 million cards during the next three years. http://www.net-security.org/news.php?id=5211 A THIRD OF UK CORPORATES OPEN TO HACKERS Firms ignoring basic flaws as they fight high-risk vulnerabilities, warns research. http://www.net-security.org/news.php?id=5212 US CONSIDERS "LEGALISING HACKING" WITH COPYRIGHT RULING The people v the entertainment industry - who carries the most sway? http://www.net-security.org/news.php?id=5213 WHY ARE VIRUS WRITERS SO TOUGH TO CATCH? The fight to rout Sasser and its ilk is fraught with ethical ambiguities. "Out of the 75,000 viruses that are written each year, all but 1,000 never infect anybody. So is it a crime to just write a virus?" asked David Perry of Trend Micro. "We are an open society. Do we give up all those [liberties] that make us Americans?" http://www.net-security.org/news.php?id=5214 MICROSOFT TO BATTLE SPYWARE Microsoft says the upcoming release of Windows XP Service Pack 2 will make it much harder to sneak deceptive software onto users' computers. Is it game over for spyware authors? http://www.net-security.org/news.php?id=5215 WALLON VIRUS WRECKS WINDOWS MEDIA PLAYER A new mass-mailing virus called Wallon, which destroys Windows media player and is activated when a user tries to play MP3 or video files from an infected PC, was discovered in Europe on Tuesday. http://www.net-security.org/news.php?id=5216 ACOUSTIC CRYPTANALYSIS Preliminary analysis of acoustic emanations from personal computers shows them to be a surprisingly rich source of information on CPU activity. http://www.net-security.org/news.php?id=5217 NETWORLD+INTEROP SECURITY BRIEFING Enterprises on the lookout for answers to security struggles have plenty of wares to pick from at the NetWorld+Interop 2004 conference, as suppliers such as FaceTime Communications, RedSiren and Senforce Technologies introduced offerings. http://www.net-security.org/news.php?id=5218 SYMANTEC PATCHES FOUR CRITICAL FIREWALL FLAWS Symantec has issued patches for most of its firewall and antivirus products in order to fix four serious security holes. http://www.net-security.org/news.php?id=5219 GERMAN POLICE RAID FIVE HOMES IN SASSER CASE German police have widened the hunt for the vandals responsible for the distribution of the infamous Sasser and NetSky worms by raiding the homes of five new suspects. All are close to the home of Sven Jaschan, the prime suspect. http://www.net-security.org/news.php?id=5220 'SURVIVOR' SITE CONTAINS MALICIOUS CODE Code embedded in a site likely to be surfed by fans of the 'Survivor' TV show takes advantage of known software flaws. http://www.net-security.org/news.php?id=5222 PRIVACY JAM ON CALIFORNIA HIGHWAY The pictures show a driver peering angrily out his window at the photographer. In one, his middle finger is raised at the camera. In the last, his license plate is captured on digital film as he drives away. http://www.net-security.org/news.php?id=5223 HELP: I GOT HACKED. NOW WHAT DO I DO? So, you didn’t patch the system and it got hacked. What to do? The Security Program Manager at Microsoft Corporation will tell you. http://www.net-security.org/news.php?id=5224 CONGRESS MULLS REVISIONS TO DMCA Congress has taken a step toward revising the Digital Millennium Copyright Act, which has attracted extensive criticism over the past six years. http://www.net-security.org/news.php?id=5225 COURT TAKES GAG OFF ANTISPAM SERVICE A Northern California District Court judge issued a temporary restraining order last week to prevent SpamCop from interfering with messages sent by alleged junk e-mailer OptInRealBig.com, whose owner and president is Richter. http://www.net-security.org/news.php?id=5226 ---------------------------------------------------------------- [ Vulnerabilities ] All vulnerabilities are located here: http://www.net-security.org/archive_vuln.php ---------------------------------------------------------------- Opera Telnet URI Handler File Creation/Truncation Vulnerability http://www.net-security.org/vuln.php?id=3451 Symantec Multiple Firewall NBNS Response Remote Heap Corruption Vulnerability http://www.net-security.org/vuln.php?id=3450 Symantec Multiple Firewall DNS Response Denial of Service Vulnerability http://www.net-security.org/vuln.php?id=3449 Symantec Multiple Firewall NBNS Response Processing Stack Overflow Vulnerability http://www.net-security.org/vuln.php?id=3448 Symantec Multiple Firewall Remote DNS KERNEL Overflow Vulnerability http://www.net-security.org/vuln.php?id=3447 Linux Kernel sctp_setsockopt() Integer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3446 Net(Free)BSD Systrace Local Root Vulnerability http://www.net-security.org/vuln.php?id=3445 phpShop Arbitrary Code Inclusion Vulnerability http://www.net-security.org/vuln.php?id=3444 Microsoft Active Server Pages Cookie Retrieval Vulnerability http://www.net-security.org/vuln.php?id=3443 Microsoft Internet Explorer Memory Access Violation Vulnerability http://www.net-security.org/vuln.php?id=3442 Heimdal kadmind v4 Remote Heap Overflow Vulnerability http://www.net-security.org/vuln.php?id=3441 Trend OfficeScan Corporate Edition Weak Permissions Vulnerability http://www.net-security.org/vuln.php?id=3440 Microsoft Windows IPSec Vulnerabilty http://www.net-security.org/vuln.php?id=3439 Eudora File URL Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3438 NukeJokes Multiple Vulnerabilities http://www.net-security.org/vuln.php?id=3437 DeleGate SSL-filter Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3436 ---------------------------------------------------------------- [ Advisories ] All advisories are located at: http://www.net-security.org/archive_advi.php ---------------------------------------------------------------- Trustix Secure Linux Security Advisory - apache (2004-0027) http://www.net-security.org/advisory.php?id=3329 Trustix Secure Linux Security Advisory - kernel (2004-0029) http://www.net-security.org/advisory.php?id=3328 Gentoo Linux Security Advisory - Utempter symlink vulnerability (GLSA 200405-05) http://www.net-security.org/advisory.php?id=3327 Debian Security Advisory - New mah-jong packages fix denial of service (DSA 503-1) http://www.net-security.org/advisory.php?id=3326 NetBSD Security Advisory - Systrace systrace_exit() local root (2004-007) http://www.net-security.org/advisory.php?id=3325 Slackware Security Advisory - apache (SSA:2004-133-01) http://www.net-security.org/advisory.php?id=3324 OpenPKG Security Advisory - apache (OpenPKG-SA-2004.021) http://www.net-security.org/advisory.php?id=3323 Microsoft Security Update Summary For May 2004 http://www.net-security.org/advisory.php?id=3322 Gentoo Linux Security Advisory - OpenOffice.org vulnerability when using DAV servers (GLSA 200405-04) http://www.net-security.org/advisory.php?id=3321 Microsoft Windows Security Bulletin Summary for May 2004 http://www.net-security.org/advisory.php?id=3320 Microsoft Security Bulletin Re-releases, May 2004 http://www.net-security.org/advisory.php?id=3319 Debian Security Advisory - New exim-tls packages fix buffer overflows (DSA 502-1) http://www.net-security.org/advisory.php?id=3318 Gentoo Linux Security Advisory - ClamAV VirusEvent parameter vulnerability (GLSA 200405-03) http://www.net-security.org/advisory.php?id=3317 Mandrakelinux Security Update Advisory - apache2 (MDKSA-2004:043) http://www.net-security.org/advisory.php?id=3316 Mandrakelinux Security Update Advisory - rsync (MDKSA-2004:042) http://www.net-security.org/advisory.php?id=3315 SCO Security Advisory - OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol (SCOSA-2004.5) http://www.net-security.org/advisory.php?id=3314 Fedora Legacy Update Advisory - Updated OpenSSL resolves security vulnerability (FLSA:1395) http://www.net-security.org/advisory.php?id=3313 Gentoo Linux Security Advisory - Multiple vulnerabilities in LHa (GLSA 200405-02) http://www.net-security.org/advisory.php?id=3312 Gentoo Linux Security Advisory - Multiple format string vulnerabilities in neon 0.24.4 and earlier (GLSA 200405-01) http://www.net-security.org/advisory.php?id=3311 OpenPKG Security Advisory - ssmtp (OpenPKG-SA-2004.020) http://www.net-security.org/advisory.php?id=3310 ---------------------------------------------------------------- [ Articles ] All articles are located at: http://www.net-security.org/articles_main.php Articles can be contributed to articles@net-security.org ---------------------------------------------------------------- HNS LEARNING SESSION: INTRODUCTION TO COMPUTER FORENSICS In this audio session the Senior Security Engineer at Guidance Software discusses the need and importance of forensics in the IT environment and gives a number of valuable tips regarding the process, including creating methodology guidelines, incident simulation and more. http://www.net-security.org/article.php?id=688 COMBATING INTERNET WORMS In recent years, not only has the number of network and computer attacks been on the rise, but also the level of complexity and sophistication with which they strike. The most common and perhaps most damaging of these attacks are called worms. http://www.net-security.org/article.php?id=687 COMBATING THE CYBER CRIMINALS Detective Chief Superintendent Len Hynds, Head of the National Hi-Tech Crime Unit discusses the problems associated with hi-tech crime. http://www.net-security.org/article.php?id=686 ---------------------------------------------------------------- [ Software ] Windows software is located at: http://net-security.org/software_main.php?cat=1 Linux software is located at: http://net-security.org/software_main.php?cat=2 Pocket PC software is located at: http://net-security.org/software_main.php?cat=3 ---------------------------------------------------------------- ID_BANK ID_Bank is a secure identity and password protection system. http://www.net-security.org/software.php?id=91 OS-SIM OSSIM is a distribution of open source products that are integrated to provide an infrastructure for security monitoring. http://www.net-security.org/software.php?id=304 SMOKEPING With SmokePing you can measure latency, latency distribution and packet loss in your network. http://www.net-security.org/software.php?id=178 MIMEDEFANG MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. http://www.net-security.org/software.php?id=214 TINYCA TinyCA is a simple GUI written in Perl-Gtk to manage a small certification authority. It works as a frontend to OpenSSL. http://www.net-security.org/software.php?id=308 LINUX-VSERVER Linux-VServer allows you to create virtual private servers and security contexts which operate like a normal Linux server, but allow many independent servers to be run simultaneously in one box at full speed. http://www.net-security.org/software.php?id=527 ROOTKIT HUNTER Rootkit scanner is scanning tool to ensure you for about 99.9% you're clean of nasty tools. http://www.net-security.org/software.php?id=531 ---------------------------------------------------------------- [ Webcasts ] All webcasts are located at: http://www.net-security.org/webcasts.php ---------------------------------------------------------------- Top Five Web Application Server Protection Strategies Organized by eEye on 18 May 2004, 10:00 AM PST http://www.net-security.org/webcast.php?id=279 Architecting Your 802.1x-Based WLAN Deployment Organized by Funk Software on 18 May 2004, 1:00 PM EDT http://www.net-security.org/webcast.php?id=276 The Next Generation of Managed Security Services Organized by ISS on 25 May 2004, 11:00 AM EDT http://www.net-security.org/webcast.php?id=273 Automate Remediation Activities for Efficient Vulnerability Management Organized by eEye on 27 May 2004, 10:00 AM PST http://www.net-security.org/webcast.php?id=280 Virtual Patch - The Next Generation of Managed Protection Services Organized by ISS on 8 June 2004, 11:00 AM EDT http://www.net-security.org/webcast.php?id=274 ---------------------------------------------------------------- [ Conferences ] All conferences are located at: http://www.net-security.org/conferences.php ---------------------------------------------------------------- Computer Security Mexico 2004 Organized by Computer Security Department and UNAM-CERT - 27 May-28 May 2004 http://www.net-security.org/conference.php?id=87 RSA Conference 2004 Japan Organized by RSA Conference 2004 Japan Executive Comittee - 31 May-1 June 2004 http://www.net-security.org/conference.php?id=82 Infosecurity Canada Conference & Exhibition 2004 Organized by Reed Exhibitions - 1 June-3 June 2004 http://www.net-security.org/conference.php?id=86 BCS Birmingham IT Security Conference 2004 Organized by British Computer Society - 8 June-8 June 2004 http://www.net-security.org/conference.php?id=81 16th Annual FIRST Conference Organized by FIRST - 13 June-18 June 2004 http://www.net-security.org/conference.php?id=22 NetSec 2004 Organized by Computer Security Institute - 14 June-16 June 2004 http://www.net-security.org/conference.php?id=20 2004 USENIX Annual Technical Conference Organized by USENIX Association - 27 June-2 July 2004 http://www.net-security.org/conference.php?id=66 DIMVA 2004 Organized by German Informatics Society - 6 July-7 July 2004 http://www.net-security.org/conference.php?id=47 RUXCON 2004 Organized by Australian computer security community - 10 July-11 July 2004 http://www.net-security.org/conference.php?id=88 Open Source Convention 2004 Organized by O'Reilly - 26 July-30 July 2004 http://www.net-security.org/conference.php?id=89 13th USENIX Security Symposium Organized by USENIX Association - 9 August-13 August 2004 http://www.net-security.org/conference.php?id=67 The 14th Virus Bulletin International Conference (VB2004) Organized by Virus Bulletin - 29 September-1 October 2004 http://www.net-security.org/conference.php?id=83 RSA Conference Europe 2004 Organized by RSA Security - 3 November-5 November 2004 http://www.net-security.org/conference.php?id=90 ---------------------------------------------------------------- [ Security world ] All press releases are located at: http://www.net-security.org/press_main.php Send your press releases to press@net-security.org ---------------------------------------------------------------- Trocaire Aid Workers Get Helping Hand from LAN Communications http://www.net-security.org/press.php?id=2137 Kranos Unveils World's First Secure Enterprise Instant Messaging Service http://www.net-security.org/press.php?id=2136 Version 2.00 of Dekart Logon for Citrix ICA Client - a New Solution To Securing Access to Citrix Servers http://www.net-security.org/press.php?id=2135 TippingPoint’s UnityOne Intrusion Prevention System Awarded SANS ‘Trusted Tool’ Designation http://www.net-security.org/press.php?id=2134 Infosecurity Europe 2004 A Record Breaking Success! http://www.net-security.org/press.php?id=2133 Major Scandinavian Bank makes New Long-term Investment in Utimaco Safeware Security Solutions http://www.net-security.org/press.php?id=2132 Forum Systems Releases Forum XWallT 3.0 For Developers With WS-I Compliance http://www.net-security.org/press.php?id=2131 Sybari Announces Linux Platform Support for Lotus Domino Users http://www.net-security.org/press.php?id=2130 AEP Systems Releases SSL VPN for Small-Scale Deployments http://www.net-security.org/press.php?id=2129 F-Secure Celebrates Ten Years In The Web http://www.net-security.org/press.php?id=2128 Datakey, Inc. Announces Agreement with HID to Provide Integrated Physical and Logical Access Solution http://www.net-security.org/press.php?id=2127 nCipher and Broadcom to Provide Advanced, Embedded Security Infrastructure http://www.net-security.org/press.php?id=2126 Sygate Named To Red Herring 100 Top Private Companies http://www.net-security.org/press.php?id=2125 Sygate Joins Trusted Computing Group To Develop Open Industry Standard Specification For Securing Endpoint Host Connections To Networks http://www.net-security.org/press.php?id=2124 New Trojan Demonstrates Increasing Complexity Of Converged Email Security Threats http://www.net-security.org/press.php?id=2123 Braun Consulting Selects AEP Systems' SSL VPN to Provide Secure Remote Access for Employees Worldwide http://www.net-security.org/press.php?id=2122 Sigaba’s DiMaggio Presented with AFCEA International 2004 Meritorious Service Award http://www.net-security.org/press.php?id=2121 Sigaba Earns Afcea Golden Link Award http://www.net-security.org/press.php?id=2120 Sierra Wireless Embeds Certicom's movianVPN Client in new Voq Professional Phone http://www.net-security.org/press.php?id=2119 Datapower's XG4 Xml Chip Named A Finalist In The Best Of Interop Awards For Networld+Interop 2004 Las Vegas http://www.net-security.org/press.php?id=2118 Datapower First To Break Gigabit Barrier For XML Processing With Its XG4 XML Chip http://www.net-security.org/press.php?id=2117 Juniper Networks Showcases Solutions For Transforming The Business Of Networking At Networld+Interop http://www.net-security.org/press.php?id=2116 TippingPoint’s UnityOne Intrusion Prevention System Blocks Cyber Threats at ALON USA http://www.net-security.org/press.php?id=2115 Bluesocket Announces Version 4.0 Software for Enterprise Wireless LANs http://www.net-security.org/press.php?id=2114 SSH Managed Security Middleware Achieves Entrust Ready Status http://www.net-security.org/press.php?id=2113 Cherry and ISL Biometrics Collaborate to Bring Biometrics to Every Desktop http://www.net-security.org/press.php?id=2112 Trapeze Networks Increases Security and Adds New Mobility Point Options To Lineup http://www.net-security.org/press.php?id=2111 Syngress Publishing Announces the Release of "Hacking the Code: ASP.NET Web Application Security" http://www.net-security.org/press.php?id=2110 Astaro Ships Version 5 of Astaro Security Linux http://www.net-security.org/press.php?id=2109 ---------------------------------------------------------------- [ Virus News ] All virus news are located at: http://www.net-security.org/viruses.php ---------------------------------------------------------------- Weekly Report on Viruses and Intrusions - Sasser.F, Cycle.A, Bagle.AC, Sober.G and Wallon.A Worms http://www.net-security.org/virus_news.php?id=408 Alert: BMP Files May Contain a New Virus http://www.net-security.org/virus_news.php?id=407 Police Breaking Open Skynet Gang In North Germany, Sophos Reports http://www.net-security.org/virus_news.php?id=406 Sasser Creator Copycats: a New Worm Has Been Discovered, Cycle.A http://www.net-security.org/virus_news.php?id=405 Other Hackers Pick Up Where The Sasser Author Left Off: Variant F Appears http://www.net-security.org/virus_news.php?id=404 Weekly Report on Viruses and Intrusions - Sasser Worm Variants, DSScan, JohnTheRipper and Brutus.A http://www.net-security.org/virus_news.php?id=403 ---------------------------------------------------------------- Questions, contributions, comments or ideas go to: Help Net Security staff staff@net-security.org http://net-security.org ---------------------- Unsubscribe from this weekly digest on: http://www.net-security.org/subscribe.php The archive of the newsletter in TXT and PDF format is available http://www.net-security.org/newsletter_archive.php ---------------------------------------------------------------- Windows Server System is integrated server infrastructure software from Microsoft that is designed to work together and interact seamlessly with other data and applications across your IT environment so you can reduce the costs of ongoing operations, deliver highly reliable and secure IT infrastructure, and drive valuable new capabilities for the future growth of your business. For more information visit http://ad.sk.doubleclick.net/clk;8019795;9084238;y ----------------------------------------------------------------