HNS Newsletter Issue 218 - 21.06.2004. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. ---------------------------------------------------------------- ADVERTISEMENT ---------------------------------------------------------------- Windows Server System is integrated server infrastructure software from Microsoft that is designed to work together and interact seamlessly with other data and applications across your IT environment so you can reduce the costs of ongoing operations, deliver highly reliable and secure IT infrastructure, and drive valuable new capabilities for the future growth of your business. For more information visit http://ad.sk.doubleclick.net/clk;8032544;9084238;l ---------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Articles 5) Software 6) Webcasts 7) Conferences 8) Security World 9) Virus News [ Security news ] ---------------------------------------------------------------- SECURITY PAYS OFF AS CYBERCRIME COSTS FALL The number of cybercrimes and hacker attacks, and the cost attributed to such intrusions, declined for the fourth straight year, according to data released by the Computer Security Institute. http://www.net-security.org/news.php?id=5391 APPLE MAKES ITS CASE FOR SECURITY Stung by criticism of its handling of vulnerabilities in Mac OS X, Apple says it's serious about security and vows to be more attentive. http://www.net-security.org/news.php?id=5392 PRE-EMPTIVE SECURITY PROMPTS ALARMS Early warning systems are the latest tactic in security professionals' war on malware. http://www.net-security.org/news.php?id=5393 MICROSOFT'S SP1 FOR SERVER 2003 PACKS A SECURITY PUNCH Microsoft is working on a set of security upgrades for Windows Server 2003 that executives said will deliver on the company's promise to make its products more secure by default. http://www.net-security.org/news.php?id=5394 BACKDOOR PROGRAM GETS BACKDOORED The author of a free Trojan horse program favored by amateur computer intruders found himself with some explaining to do to the underground. http://www.net-security.org/news.php?id=5395 USING JABBER AS A LOG MONITOR Jabber, the streaming XML technology mainly used for instant messaging, is well-suited to its most common task. However, Jabber is a far more generic tool. http://www.net-security.org/news.php?id=5396 SHORTAGE OF COMPUTER SECURITY EXPERTS HAMPERS AGENCIES Bush administration officials and information technology industry experts on Thursday identified areas of cybersecurity that need to be addressed, including more research and development and the training of the next generation of cyber experts in government. http://www.net-security.org/news.php?id=5397 INTERNET EXPLORER HOLES CAUSING ALARM Four new holes have been discovered in the Internet Explorer (IE) Web browser that could allow malicious hackers to run attack code on Windows systems, even if those systems have installed the latest software patches from the Redmond, Washington company, security experts warn. http://www.net-security.org/news.php?id=5398 TIME TO APPLY A PATCH A renewed debate about patch management has highlighted a flaw in federal officials' views on information security. http://www.net-security.org/news.php?id=5399 GROWING NEED FOR WIRELESS SECURITY POLICIES The escalating use of wireless technology demands formal corporate security policies governing that use, according to users and analysts at a Gartner security conference in Washington DC. http://www.net-security.org/news.php?id=5400 HNS NEWSLETTER ISSUE 217 HAS BEEN RELEASED You can read the Newsletter in TXT or PDF format. If you haven't done it yet, consider subscribing. This issue is sponsored by Microsoft. http://www.net-security.org/news.php?id=5401 EXECUTIVE CONVERSATION: WHY CLOUDMARK TOOK THE PATH LESS TRAVELED Spam, spim, spoofs…will it ever end? Cloudmark believes that spam and all of its incarnations will indeed disappear through a combination of carefully harvested human feedback and ground-breaking tools. http://www.net-security.org/news.php?id=5402 MICROSOFT RELEASES SECURITY-MINDED WINDOWS CODE Microsoft on Monday released what it hopes is a nearly final test version of a security-oriented Windows upgrade. http://www.net-security.org/news.php?id=5403 WLANS VULNERABLE TO HACKING Wireless security is fraught with problems, but there are advanced technology solutions for many of them, says research firm Gartner. Fixed wireless intrusion-detection sensors can block hackers from breaching networks and masquerading as legitimate users. http://www.net-security.org/news.php?id=5404 NEW LINUX SECURITY HOLE FOUND A Linux bug was recently uncovered by a young Norwegian programmer that, when exploited by a simple C program, could crash most Linux 2.4 or 2.6 distributions running on an x86 architecture. http://www.net-security.org/news.php?id=5405 RUSSIAN FIRM REPORTS FIRST MOBILE PHONE WORM Antivirus company Kaspersky Labs Ltd. said on Monday that it discovered the first-ever computer virus capable of spreading over mobile phone networks. http://www.net-security.org/news.php?id=5406 GOOGLE'S GMAIL: SPOOK HEAVEN? Google's plans to run targeted advertising with the mail that you see through its new Gmail service represents a potential break for government agencies that want to use autobots to monitor the contents of electronic communications travelling across networks. http://www.net-security.org/news.php?id=5407 EMAIL VIRUSES ARE MORE ANNOYING THAN SPAM I've had my primary email address for many years, and I also get email through a number of work-related aliases. So I get spam. Tons of spam. And I filter it all. I filter viruses, too, not because they can affect my Linux computer, but because they suck up bandwidth. http://www.net-security.org/news.php?id=5408 WORM CUTS OFF ANTIVIRUS PROGRAMS A new worm can shut down antivirus applications, according to security firm F-Secure. http://www.net-security.org/news.php?id=5409 INSIDE THE INSIDER THREAT Mudge, the security expert and chief scientist at Intrusic Inc., details some of the ways that malicious hackers can slip into computer networks undetected. http://www.net-security.org/news.php?id=5410 EASE THE SECURITY BURDEN WITH A CENTRAL LOGGING SERVER Many administrators fall short of spending the necessary time monitoring log files. Because this is a critical security task, one of the best ways to accomplish it is with a central logging server. These tips will help you get started. http://www.net-security.org/news.php?id=5411 A SECURITY TALE: FROM VULNERABILITY DISCOVERY TO DISASTER It's one of the largest wireless companies in the United States. It has billions of dollars in the bank. And last week, it had a colossal security problem on its hands. http://www.net-security.org/news.php?id=5413 AVOIDING IDENTITY THEFT: A PRIMER Your identity is arguably your most valuable possession. A clean legal record and credit history open the door for work, mortgage loans and other day-to-day privileges that most people take for granted. http://www.net-security.org/news.php?id=5414 MICROSOFT: NO ANTIVIRUS PRODUCT YET Microsoft intends to create an antivirus service in the near future, but has not finalized its plans yet, a company executive said Tuesday. http://www.net-security.org/news.php?id=5415 FTC SAYS NO TO ANTISPAM REGISTRY The Federal Trade Commission tells Congress that a "do not e-mail" registry would be ineffective at stopping spam. In fact, it could make the problem worse. http://www.net-security.org/news.php?id=5416 AKAMAI BLAMES 'GLOBAL DNS ATTACK' FOR DISRUPTIONS A global attack on the DNS (domain name system) caused disruptions affecting customers of Internet hosting company Akamai Technologies Inc., including search engine sites, said Jeff Young, an Akamai spokesman. http://www.net-security.org/news.php?id=5417 IRIS SCANS AT UK AIRPORTS The Home Office is to install iris scanning technology in major UK airports. It says this will speed up immigration times for those who register on the scheme, as well as providing a "substantial increase in security". http://www.net-security.org/news.php?id=5418 SECURITY OFFICIALS PLAY NICE Federal agencies are deploying more sophisticated network scanning tools than ever before. http://www.net-security.org/news.php?id=5419 WEB VULNERABILITY ASSESSMENT FOR SMBS One modest-priced and nicely featured solution SMBs must consider is Syhunt's Sandcat Suite. This security software suite includes a security hardening tool, a vulnerability scanner, data mining and log analysis tools, and more. http://www.net-security.org/news.php?id=5420 ANALYST: MOBILE SECURITY IS A TOP PRIORITY With the detection of a virus that could worm its way onto smartphones, security has once again come to the forefront of people's minds. http://www.net-security.org/news.php?id=5421 FEDS' IT SECURITY SPENDING GROWTH SET FOR SLOWDOWN Government market-research firm Input says spending on IT security products and services will drop to 2% next year, down from 10% this year and 50% in 2003. http://www.net-security.org/news.php?id=5422 'SASSER' WORM INFORMANT UNDER INVESTIGATION The informant who tipped Microsoft Corp. to the identity of the "Sasser" computer worm's creator last month is among five people under investigation as possible accomplices, prosecutors said Wednesday. http://www.net-security.org/news.php?id=5423 ONLINE THIEVES EMPTY BANK ACCOUNTS Online thieves known as "phishers" have been gouging unsuspecting consumers by emptying their bank accounts and making fraudulent credit-card purchases. Research firm Gartner conducted a survey of 5,000 adult Web users in the U.S. and found that checking-account theft is the fastest-growing financial consumer fraud in the country. http://www.net-security.org/news.php?id=5424 SPAMMER PROSECUTIONS WASTE TIME AND MONEY The recent US Federal Trade Commission (FTC) report on the futility of establishing a national 'do not email' registry contains a number of interesting observations related to spam control and to the so-called CAN-SPAM Act. http://www.net-security.org/news.php?id=5425 WARDRIVING FOR WLAN SECURITY The 4th Annual Worldwide Wardrive is under way this week, with volunteers scanning the airwaves in a neighborhood near you for WLAN access points. http://www.net-security.org/news.php?id=5426 JUDGE TOSSES ONLINE PRIVACY CASE The dismissal of lawsuits brought against Northwest Airlines has online privacy advocates renewing calls for federal privacy legislation. http://www.net-security.org/news.php?id=5427 APPLICATION DENIAL OF SERVICE ATTACKS Denial of Services attacks aimed at disrupting network services range from simple bandwidth exhaustion attacks and those targeted at flaws in commercial software to complex distributed attacks exploiting specific commercial off-the-shelf software flaws. http://www.net-security.org/news.php?id=5428 SECURITY SPENDING TO PEAK WITHIN THREE YEARS Eight to 12 per cent of European IT budgets by 2007, says Meta. http://www.net-security.org/news.php?id=5429 NO SWAN SONG FOR OPEN SOURCE IPSEC Internet protocol security (define) for Linux got a boost today from Novell, which announced that it would be officially sponsoring and contributing to the Openswan open source project. http://www.net-security.org/news.php?id=5430 READY? SECURE? DISCLOSE Are you ready to declare your company secure against attacks from cyberterrorists? If you're not, get moving. http://www.net-security.org/news.php?id=5431 XML DIGITAL SIGNATURES IN A NUTSHELL Digital signatures are widely used as security tokens, not just in XML. In this article, we look at how to create a digital signature and the way that digital signatures are constructed. http://www.net-security.org/news.php?id=5432 SYMBOL BUYS INTO STRONGER MOBILE SECURITY Symbol Technologies Inc. wants to help secure data and applications on handheld devices via the acquisition of Trio Security Inc., a privately held software vendor. http://www.net-security.org/news.php?id=5433 FREE HOTSPOTS NEED FREE SECURITY Wi-Fi security is getting more attention these days, but most of the solutions are focused on the enterprise or paid-hotspot market. Now one group is trying to tackle the problem for free hotspots as well. http://www.net-security.org/news.php?id=5434 BRODY TO LEAD ENERGY CYBERSECURITY Bruce Brody, the cybersecurity chief at the Department of Veterans Affairs, is moving to the Energy Department to help that agency toughen its security against viruses and hacker attacks. http://www.net-security.org/news.php?id=5435 Q&A WITH SECURITYFOCUS' ALFRED HUGER The cybersecurity expert on why its early-warning system is so hot: "People are sick and tired of being hit blind". http://www.net-security.org/news.php?id=5436 IP PHONES CAN CREATE NETWORK SECURITY RISK The increasing adoption of Internet telephony may be opening up a significant security risk for companies. http://www.net-security.org/news.php?id=5437 TIME TO DUMP INTERNET EXPLORER It's time to tell our users, our clients, our associates, our families, and our friends to abandon Internet Explorer. http://www.net-security.org/news.php?id=5438 IT SECURITY IS A TOP PRIORITY AT THE OLYMPICS Yan Noblot reassures Mark Samuels that his Olympic Games IT security strategy is sound. http://www.net-security.org/news.php?id=5439 TSA TRIES BIOMETRIC CHECKS Frequent travelers at five airports who submit biometric data and pass a background check will be able to breeze through security checkpoints as part of the Transportation Security Administration's Registered Traveler Pilot program. http://www.net-security.org/news.php?id=5440 ---------------------------------------------------------------- [ Vulnerabilities ] All vulnerabilities are located here: http://www.net-security.org/archive_vuln.php ---------------------------------------------------------------- Snitz Forum 2000 XSS Vulnerability http://www.net-security.org/vuln.php?id=3510 IBM acpRunner Activex Dangerous Methods Vulnerability http://www.net-security.org/vuln.php?id=3509 Web Wiz Forums Registration Rules XSS Vulnerability http://www.net-security.org/vuln.php?id=3508 VICE Emulator Format String Vulnerability http://www.net-security.org/vuln.php?id=3507 VP-ASP Shopping Cart Multiple Vulnerabilities http://www.net-security.org/vuln.php?id=3506 ---------------------------------------------------------------- [ Advisories ] All advisories are located at: http://www.net-security.org/archive_advi.php ---------------------------------------------------------------- Gentoo Linux Security Advisory - aspell: Buffer overflow in word-list-compress (GLSA 200406-14) http://www.net-security.org/advisory.php?id=3463 Gentoo Linux Security Advisory - Squid: NTLM authentication helper buffer overflow (GLSA 200406-13) http://www.net-security.org/advisory.php?id=3462 SUSE Security Announcement - subversion (SuSE-SA:2004:018) http://www.net-security.org/advisory.php?id=3461 Debian Security Advisory - New krb5 packages fix buffer overflows (DSA 520-1) http://www.net-security.org/advisory.php?id=3460 SUSE Security Announcement - kernel (SuSE-SA:2004:017) http://www.net-security.org/advisory.php?id=3459 Gentoo Linux Security Advisory - Webmin: Multiple vulnerabilities (GLSA 200406-12) http://www.net-security.org/advisory.php?id=3458 Gentoo Linux Security Advisory - Horde-IMP: Input validation vulnerability (GLSA 200406-11) http://www.net-security.org/advisory.php?id=3457 Gentoo Linux Security Advisory - Gallery: Privilege escalation vulnerability (GLSA 200406-10) http://www.net-security.org/advisory.php?id=3456 Gentoo Linux Security Advisory - Horde-Chora: Remote code execution (GLSA 200406-09) http://www.net-security.org/advisory.php?id=3455 Gentoo Linux Security Advisory - Squirrelmail: Another XSS vulnerability (GLSA 200406-08) http://www.net-security.org/advisory.php?id=3454 Debian Security Advisory - New CVS packages fix several potential security problems (DSA 519-1) http://www.net-security.org/advisory.php?id=3453 SGI Security Advisory - IRIX syssgi system call vulnerability and other security fixes (20040601-01-P) http://www.net-security.org/advisory.php?id=3452 Debian Security Advisory - New kdelibs packages fix URI handler vulnerabilities (DSA 518-1) http://www.net-security.org/advisory.php?id=3451 US-CERT Technical Cyber Security Alert TA04-163A - Cross-Domain Redirect Vulnerability in Internet Explorer http://www.net-security.org/advisory.php?id=3450 OpenPKG Security Advisory - apache (OpenPKG-SA-2004.029) http://www.net-security.org/advisory.php?id=3449 OpenPKG Security Advisory - subversion (OpenPKG-SA-2004.028) http://www.net-security.org/advisory.php?id=3448 OpenPKG Security Advisory - cvs (OpenPKG-SA-2004.027) http://www.net-security.org/advisory.php?id=3447 Gentoo Linux Security Advisory - Subversion: Remote heap overflow (GLSA 200406-07) http://www.net-security.org/advisory.php?id=3446 Mandrakelinux Security Update Advisory - Updated ksymoops packages fix symlink vulnerability (MDKSA-2004:060) http://www.net-security.org/advisory.php?id=3445 Gentoo Linux Security Advisory - CVS: additional DoS and arbitrary code execution vulnerabilities (GLSA 200406-06) http://www.net-security.org/advisory.php?id=3444 Trustix Secure Linux Security Advisory - squid (#2004-0033) http://www.net-security.org/advisory.php?id=3443 Debian Security Advisory - New CVS packages fix buffer overflow (DSA 517-1) http://www.net-security.org/advisory.php?id=3442 ---------------------------------------------------------------- [ Articles ] All articles are located at: http://www.net-security.org/articles_main.php Articles can be contributed to articles@net-security.org ---------------------------------------------------------------- APPLICATION DENIAL OF SERVICE (DOS) ATTACKS Denial of Services attacks aimed at disrupting network services range from simple bandwidth exhaustion attacks and those targeted at flaws in commercial software to complex distributed attacks exploiting specific commercial off-the-shelf software flaws. http://www.net-security.org/article.php?id=701 HNS AUDIO LEARNING SESSION: ALTERNATIVES TO PASSWORDS John Stuart, Signify CEO, discusses what are the alternatives to passwords. There are three fundamental technologies which users could take into consideration: one time passcodes (token based systems), digital certificates and biometrics. Mr. Stuart talks about all of these technologies and provides background and benefits on each of these security systems. http://www.net-security.org/article.php?id=700 EXECUTIVE CONVERSATION: WHY CLOUDMARK TOOK THE PATH LESS TRAVELED Spam, spim, spoofs…will it ever end? Cloudmark believes that spam and all of its incarnations will indeed disappear through a combination of carefully harvested human feedback and ground-breaking tools. Having taken an unorthodox approach to building their company, in two short years Cloudmark has provided innovative ways to wage war against spam for over one million users. http://www.net-security.org/article.php?id=699 ---------------------------------------------------------------- [ Software ] Windows software is located at: http://net-security.org/software_main.php?cat=1 Linux software is located at: http://net-security.org/software_main.php?cat=2 Pocket PC software is located at: http://net-security.org/software_main.php?cat=3 ---------------------------------------------------------------- BOTAN 1.3.14 Botan aims to be a portable, easy to use, and efficient C++ crypto library. http://www.net-security.org/software.php?id=94 DROPBEAR SSH SERVER 0.42 Dropbear is an SSH 2 server, designed to be usable in small memory environments. http://www.net-security.org/software.php?id=490 ETTERCAP NG-0.7.0 RC1 Ettercap is a multipurpose sniffer/interceptor/logger for switched LAN. http://www.net-security.org/software.php?id=83 FLAWFINDER 1.26 Flawfinder searches through source code looking for potential security flaws. http://www.net-security.org/software.php?id=183 NUFW 0.7.1 NuFW is an "authenticating gateway". This means it requires authentication for any connections to be forwarded through the gateway. http://www.net-security.org/software.php?id=526 OS-SIM 0.9.5p1 OSSIM is a distribution of open source products that are integrated to provide an infrastructure for security monitoring. http://www.net-security.org/software.php?id=304 SAMHAIN 1.8.9 Samhain is an open source file integrity and host-based intrusion detection system. http://www.net-security.org/software.php?id=125 SHOREWALL 2.0.3 RC1 Shorewall is an iptables based firewall that can be used on a dedicated firewall system, a multi-function masquerade gateway/server or on a standalone Linux system. http://www.net-security.org/software.php?id=40 TINYCA 0.6.3 TinyCA is a simple graphical user interface to manage a small CA (Certification Authority). http://www.net-security.org/software.php?id=308 ---------------------------------------------------------------- [ Webcasts ] All webcasts are located at: http://net-security.org/webcasts.php ---------------------------------------------------------------- Monthly Update from Microsoft's VP for Security Organized by Microsoft on 22 June 2004, 8:30 AM http://www.net-security.org/webcast.php?id=298 Applied Security Strategies Organized by Microsoft on 23 June 2004, 9:00 AM http://www.net-security.org/webcast.php?id=299 Sophos Anti-Virus: The best choice for K-12 Organized by Sophos on 23 June 2004, 10:00 AM http://www.net-security.org/webcast.php?id=295 Penetration Testing with CORE IMPACT Organized by Core Security Technologies on 24 June 2004, 1:00 PM http://www.net-security.org/webcast.php?id=296 Passwords Demystified Organized by Microsoft on 25 June 2004, 1:00 PM http://www.net-security.org/webcast.php?id=300 Tips & Tricks for Secure Access to Cisco Routers Organized by Global Knowledge on 25 June 2004, 4:00 PM http://www.net-security.org/webcast.php?id=293 Securing the Development Process Organized by Microsoft on 29 June 2004, 11:00 AM http://www.net-security.org/webcast.php?id=301 All anti-virus software is not created equal Organized by Sophos on 30 June 2004, 10:00 AM http://www.net-security.org/webcast.php?id=286 Developing a Software Security Metrics Program Organized by Foundstone on 14 July 2004, 4:00 PM http://www.net-security.org/webcast.php?id=294 ---------------------------------------------------------------- [ Conferences ] All conferences are located at: http://net-security.org/conferences.php ---------------------------------------------------------------- 2004 USENIX Annual Technical Conference Organized by USENIX Association - 27 June-2 July 2004 http://www.net-security.org/conference.php?id=66 Security Leadership Council 2004 Organized by IP Events, Inc. - 29 June-30 June 2004 http://www.net-security.org/conference.php?id=92 DIMVA 2004 Organized by German Informatics Society - 6 July-7 July 2004 http://www.net-security.org/conference.php?id=47 RUXCON 2004 Organized by Australian computer security community - 10 July-11 July 2004 http://www.net-security.org/conference.php?id=88 Open Source Convention 2004 Organized by O'Reilly - 26 July-30 July 2004 http://www.net-security.org/conference.php?id=89 13th USENIX Security Symposium Organized by USENIX Association - 9 August-13 August 2004 http://www.net-security.org/conference.php?id=67 The 14th Virus Bulletin International Conference (VB2004) Organized by Virus Bulletin - 29 September-1 October 2004 http://www.net-security.org/conference.php?id=83 RSA Conference Europe 2004 Organized by RSA Security - 3 November-5 November 2004 http://www.net-security.org/conference.php?id=90 IBM SecureWorld Conference EMEA 2004 Organized by IBM - 23 November-26 November 2004 http://www.net-security.org/conference.php?id=91 ---------------------------------------------------------------- [ Security World ] All press releases are located at: http://www.net-security.org/press_main.php Send your press releases to press@net-security.org ---------------------------------------------------------------- iQuate Provides Corporate Governance Features In Latest Version Of Auditing Software http://www.net-security.org/press.php?id=2227 Round Rock ISD Achieves Pervasive Internal Network Security With Mirage Networks http://www.net-security.org/press.php?id=2226 GFI WebMonitor For Microsoft ISA Server Ensures Productive Internet Use At No Cost http://www.net-security.org/press.php?id=2225 Major Cable Operator com hem Uses F-Secure's Security Services To Offer Protection To Swedish Customers http://www.net-security.org/press.php?id=2224 Application Security Inc. Rounds Out Database Protection Offering with Application Server Security http://www.net-security.org/press.php?id=2223 Symantec And BMC Software Offer Two Real-Time Integrated Security And Service Management Solutions http://www.net-security.org/press.php?id=2222 Qualys Introduces Business Risk Management Capability http://www.net-security.org/press.php?id=2221 Rise in Rapidly Propagating Threats Targeting Internal Networks http://www.net-security.org/press.php?id=2220 The First Mobile Worm Cabir Proves a Point, but Causes No Serious Threat http://www.net-security.org/press.php?id=2219 I-S-Cubed and nCipher Sign Collaboration, Reseller Agreements http://www.net-security.org/press.php?id=2218 WatchGuard Accelerates Firebox X VPN Performance With SafeNet’s SafeXcel-1141 VPN Chip http://www.net-security.org/press.php?id=2217 TippingPoint’s UnityOne IPS Prevents 10,000 Cyber Attacks Per Week at Bergen Community College http://www.net-security.org/press.php?id=2216 Logitech Selects Trapeze Networks For Its Worldwide Wireless Connectivity Needs http://www.net-security.org/press.php?id=2215 Excedent Appoints Adam Williams as Channel Sales Manager http://www.net-security.org/press.php?id=2214 Skybox Security Announces Skybox View Version 1.5 and Interoperability with Over 20 Leading Security Products to Automate Security Risk Management Processes http://www.net-security.org/press.php?id=2213 Ubizen Warns Of New Internet Vulnerbilities - Microsoft Internet Explorer Unsafe http://www.net-security.org/press.php?id=2212 ---------------------------------------------------------------- [ Virus News ] All virus news are located at: http://www.net-security.org/viruses.php ---------------------------------------------------------------- Kaspersky Labs detects Cabir, the first network worm for mobile phones http://www.net-security.org/virus_news.php?id=423 IT Hoaxes: an avoidable danger http://www.net-security.org/virus_news.php?id=422 Widespread Zafi-B computer worm calls for death penalty, reports Sophos http://www.net-security.org/virus_news.php?id=421 Weekly report on viruses and intrusions - Plexus.B, Korgo.H and Korgo.I, and the Trojan Downloader.GK http://www.net-security.org/virus_news.php?id=420 Virus infected computers send racist German spam in run-up to European elections, reports Sophos Run-Up To European Elections, Reports Sophos http://www.net-security.org/virus_news.php?id=419 ---------------------------------------------------------------- Questions, contributions, comments or ideas go to: Help Net Security staff staff@net-security.org http://net-security.org ---------------------- Unsubscribe from this weekly digest on: http://www.net-security.org/subscribe.php The archive of the newsletter in TXT and PDF format is available http://www.net-security.org/newsletter_archive.php ---------------------------------------------------------------- ADVERTISEMENT ---------------------------------------------------------------- Windows Server System is integrated server infrastructure software from Microsoft that is designed to work together and interact seamlessly with other data and applications across your IT environment so you can reduce the costs of ongoing operations, deliver highly reliable and secure IT infrastructure, and drive valuable new capabilities for the future growth of your business. For more information visit http://ad.sk.doubleclick.net/clk;8032544;9084238;l ----------------------------------------------------------------