HNS Newsletter Issue 230 - 13.09.2004. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. ---------------------------------------------------------------- Multi-Save Offer! Register three colleagues at this year’s RSA Conference, Europe 3rd-5th November 2004, Barcelona and receive a saving of €100 per registration. If you haven’t already registered your place at the RSA Conference, Europe – the most important information security event of 2004 – time is running out. ---------------------------------------------------------------- Visit www.2004.rsaconference.com/europe to register on-line today – you’ll find all the latest information and critical highlights on the Conference. ---------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Articles 5) Reviews 6) Software 7) Webcasts 8) Conferences 9) Security World 10) Virus News [ Security news ] ---------------------------------------------------------------- ARMY PUTS UP ITS DEFENSES Army information technology officials started the Fort Campbell Network Upgrade in December 2003... http://www.net-security.org/news.php?id=5997 SECURITY: THE BIGGER PICTURE Symantec chairman and CEO John W. Thompson tells vnunet.com about the company's strategy, and why he's not bothered about Microsoft's entry into the market. http://www.net-security.org/news.php?id=5998 EBAY DOMAIN HIJACKER ARRESTED Police in Germany have arrested a 19 year-old from Helmstedt for hijacking the site of eBay Germany about a week ago. http://www.net-security.org/news.php?id=5999 V710 HACKERS REWARD PROGRAM The v710 Hacker Reward Program is a community-sponsored initiative to enable key features on the Verizon/Motorola v710 mobile phone which were disabled by the carrier. http://www.net-security.org/news.php?id=6000 SSL VPNS: FULL ACCESS WITH MAXIMUM SECURITY Many companies are turning to a relatively young technology, Secure Sockets Layer Virtual Private Networks, to provide a full range of remote access while ensuring maximum security. http://www.net-security.org/news.php?id=6001 WIRELESS: NEW EYE ON CRIME AIDS SECURITY IN REAL TIME Wireless technology has in recent weeks helped extend the long arm of the law at events ranging from the Republican National Convention in New York City to a rock concert in Staffordshire, England. http://www.net-security.org/news.php?id=6002 WEB APP SECURITY USING STRUTS, SERVLET FILTERS, AND CUSTOM TAGLIBS In this article, you will develop a generic security solution that can be used by most enterprise-level Web applications. http://www.net-security.org/news.php?id=6003 COMPANIES STILL FAIL TO TAKE SECURITY SERIOUSLY Too many firms see security as an IT issue, says survey. http://www.net-security.org/news.php?id=6005 SPAM: SHOOT THE VENDOR The constant evolution of spam to look as much as possible like real email will guarantee that filtering cannot be a complete solution. http://www.net-security.org/news.php?id=6007 PATCH PLUGS WINZIP FLAW WinZip Computing has released a patch WinZip 9.0 Service Release 1, which it claims will resolve a buffer overflow issue. http://www.net-security.org/news.php?id=6008 JUNIPER INCORPORATES THIRD-PARTY SECURITY IN SSL VPNS Juniper Networks Inc. is expanding users' security options by opening new interfaces that allow integration of third-party tools with Juniper's line of SSL VPNs. http://www.net-security.org/news.php?id=6009 IS JBOSS READY FOR YOUR ENTERPRISE? It's been about a month since JBoss, the Open Source J2EE application server, received its full certification from Sun. http://www.net-security.org/news.php?id=6010 MCAFEE AV ATE MY APPLICATION An Australian software developer has been left fuming after the latest virus definition update from McAfee caused his package to be wrongly identified as a Trojan horse programme. http://www.net-security.org/news.php?id=6011 START-UP SAYS IT CAN DELIVER SECURE VOIP A start-up called Net6 claims that its virtual private network products offer companies high-quality voice communications over any network from anywhere. http://www.net-security.org/news.php?id=6012 RED HAT UPGRADES SECURITY Linux software maker Red Hat on Tuesday released an update to its enterprise product with security upgrades, support for IBM Power5 servers, new driver support and bug fixes. http://www.net-security.org/news.php?id=6013 TOP UK COMPANIES ARE FAILING TO DEVELOP WRITTEN SECURITY POLICIES Almost half (47%) of the UK's top 350 companies do not have a fully documented information security policy. http://www.net-security.org/news.php?id=6014 SPAMMERS EXPLOIT ANTI-SPAM TRAP Some spammers are getting their messages through using techniques designed to spot and stop them. http://www.net-security.org/news.php?id=6015 FIVE STEPS TO ENFORCING YOUR ENDPOINT SECURITY Your security policy has to have teeth. Here's how to enforce your endpoint security policy. http://www.net-security.org/news.php?id=6016 METASPLOIT FRAMEWORK, PART 2 Newly updated. This article provides insight into the Metasploit Framework, a very useful tool for the penetration tester. Part two of three. http://www.net-security.org/news.php?id=6017 USING CTELNET IN SUN CLUSTER SOFTWARE WITH SECURE SHELL You can use the ctelnet application in Sun Cluster software to connect to systems by means of the ssh command instead of telnet. The ctelnet tool is part of the Sun Cluster Console (SUNWccon) package in Sun HPC ClusterTools software. http://www.net-security.org/news.php?id=6018 WINDOWS XP SP2 RELEASE SURROUNDED BY A FEAST OF EGOS Eager to tarnish Microsoft's shiny new Service Pack 2, the security press managed to spin the most thin and marginal issues into "gaping holes" and "security craters." http://www.net-security.org/news.php?id=6019 SPYWARE INTERFERES WITH MICROSOFT PATCH Though Microsoft's new security update package is all about protecting systems from worms, viruses and spyware, it can't do much about what's already on computers - and that could pose a problem. http://www.net-security.org/news.php?id=6020 CAN SPAMMERS REALLY EXPLOIT WIRELESS NETWORKS? A US citizen is thought to have become the first person to be accused of hacking a wireless network in order to send spam. http://www.net-security.org/news.php?id=6021 'TRUSTED' SYSTEMS MOVE TO THE MAINSTREAM When it comes to operating systems, it's a matter of trust—or mistrust, as the case may be. http://www.net-security.org/news.php?id=6022 SECURITY: CAN YOU REALLY TRUST JUST TECHIES? HR, senior execs and staff all off the hook as IT team take the blame... http://www.net-security.org/news.php?id=6023 'WAR DRIVE' REVEALS NEW YORK'S HIDDEN SECURITY FLAWS While physical security was tightened to unprecedented levels here last week for the Republican National Convention, IT security researchers uncovered an unsettling number of unencrypted wireless devices that they said created a potential information security nightmare for convention organizers and delegates. http://www.net-security.org/news.php?id=6024 SECURITY: FROM THE HORSE'S MOUTH Network Times decided to ask a few security vendors a set of three questions to hopefully give readers a better idea of what is important and what is available in the security arena. http://www.net-security.org/news.php?id=6026 PRIMUS CLAIMS SECURE BROADBAND FIRST Australia’s fourth largest ISP, Primus Telecom, has launched a secure DSL service in the hope of boosting its credibility as a tier-one carrier. http://www.net-security.org/news.php?id=6027 ISPS GIVEN THUMBS DOWN FOR VIRUS, HACKER CONTROL U.S. residential Internet users are much more satisfied with the spam protection from their Internet service providers, but remain unhappy with their ISPs' defenses against hackers and viruses, J.D. Power and Associates said Wednesday. http://www.net-security.org/news.php?id=6028 SPAMMERS USE E-MAIL ID TO GAIN LEGITIMACY With few junk e-mail filters supporting a protocol for verifying the source address of digital messages, spammers have adopted it themselves as a way to appear more legitimate, according to a report released on Wednesday. http://www.net-security.org/news.php?id=6029 MICROSOFT PUTS FINGERPRINT READERS INTO HARDWARE Microsoft unveiled a new array of keyboard and mice, with some featuring built-in fingerprint readers to make it easier for users to log on to personal computers and Web sites. http://www.net-security.org/news.php?id=6030 MICROSOFT OFFERS MORE TIME TO TEST XP SERVICE PACK 2 Registry key to prevent PCs from automatically downloading update now good for 240 days. http://www.net-security.org/news.php?id=6031 PERIMETER SECURITY IS CHANGING FAST Most security solutions today are built around attempting to protect the vulnerability of the PC and, or the server, by attempting to keep "bad" things outside of the network security perimeter. But, with the changing and disappearing perimeter - security now needs to be intrinsic in every system and for every user. http://www.net-security.org/news.php?id=6032 HOUSE PANEL MOVES TO CRIMINALIZE SPYWARE, NET PIRACY People who illegally share copyrighted music and movies over the Internet could be jailed for up to five years under a bill approved by a powerful congressional panel today. http://www.net-security.org/news.php?id=6033 STILLSECURE ENFORCES NETWORK SECURITY POLICIES StillSecure announced the release of Safe Access version 2.0, which tests all PCs on a network and gives access only to those that meet an organization's established security policies, while quarantining others. http://www.net-security.org/news.php?id=6034 SECURING THAT PC A book on computer security can often be boring. The author of this review thinks Thomas C. Greene's book is not boring at all. http://www.net-security.org/news.php?id=6035 MICROSOFT STICKS WITH CONTROVERSIAL LONGHORN SECURITY Although Microsoft continues to tweak a controversial architecture for securing PCs, it still plans to include the feature in Longhorn, the next release of Windows. http://www.net-security.org/news.php?id=6036 ---------------------------------------------------------------- [ Vulnerabilities ] All vulnerabilities are located here: http://www.net-security.org/archive_vuln.php ---------------------------------------------------------------- OpenOffice World-Readable Temporary Files Disclosure Vulnerability http://www.net-security.org/vuln.php?id=3703 Subjects 2.0 for Postnuke SQL Injection Vulnerability http://www.net-security.org/vuln.php?id=3702 BBS E-Market Professional Multiple Vulnerabilities http://www.net-security.org/vuln.php?id=3701 Icewarp Web Mail 5.2.7 Multiple Vulnerabilities http://www.net-security.org/vuln.php?id=3700 F-Secure Internet Gatekeeper Content Scanning Server Denial of Service Vulnerability http://www.net-security.org/vuln.php?id=3699 Cerulean Studios Trillian 0.74i MSN Module Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3698 Net-Acct Insecure Temporary File Creation Vulnerability http://www.net-security.org/vuln.php?id=3697 PHP-Nuke Delete Message Multiple Vulnerabilities http://www.net-security.org/vuln.php?id=3696 Usermin Remote Arbitrary Shell Command Execution Vulnerability http://www.net-security.org/vuln.php?id=3695 mpg123 Buffer Overflow Vulnerability http://www.net-security.org/vuln.php?id=3694 Serverview 3.0 Insecure File Permissions Vulnerability http://www.net-security.org/vuln.php?id=3693 Site News Authentication Vulnerability http://www.net-security.org/vuln.php?id=3692 Call of Duty 1.4 Broadcast Shutdown Vulnerability http://www.net-security.org/vuln.php?id=3691 Engenio/LSI Logic Controllers Denial Of Service Vulnerability http://www.net-security.org/vuln.php?id=3690 YABBSE 1.5.1 Path Disclosure Vulnerability http://www.net-security.org/vuln.php?id=3689 PHP-Nuke 7.4 Remote Privilege Escalation Vulnerability http://www.net-security.org/vuln.php?id=3688 PHP-Nuke 7.4 DelAdmin Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3687 PHP-Nuke 7.4 ViewAdmin Cross Site Scripting Vulnerability http://www.net-security.org/vuln.php?id=3686 ---------------------------------------------------------------- [ Advisories ] All advisories are located at: http://www.net-security.org/archive_advi.php ---------------------------------------------------------------- Gentoo Linux Security Advisory - Samba: Remote printing non-vulnerability (GLSA 200409-14:02) http://www.net-security.org/advisory.php?id=3717 Conectiva Linux Security Announcement - Multiple vulnerabilities in Kerberos 5 (CLA-2004:860) http://www.net-security.org/advisory.php?id=3716 Gentoo Linux Security Advisory - Samba: Remote printing vulnerability (GLSA 200409-14) http://www.net-security.org/advisory.php?id=3715 Gentoo Linux Security Advisory - LHa: Multiple vulnerabilities (GLSA 200409-13) http://www.net-security.org/advisory.php?id=3714 OpenCA Security Advisory - Site Scripting vulnerability (2004-09-06) http://www.net-security.org/advisory.php?id=3713 Mandrakelinux Security Update Advisory - cdrecord (MDKSA-2004:091) http://www.net-security.org/advisory.php?id=3712 Mandrakelinux Security Update Advisory - zlib (MDKSA-2004:090) http://www.net-security.org/advisory.php?id=3711 Mandrakelinux Security Update Advisory - imlib2 (MDKSA-2004:089) http://www.net-security.org/advisory.php?id=3710 Gentoo Linux Security Advisory - ImageMagick, imlib, imlib2: BMP decoding buffer overflows (GLSA 200409-12) http://www.net-security.org/advisory.php?id=3709 Gentoo Linux Security Advisory - star: Suid root vulnerability (GLSA 200409-11) http://www.net-security.org/advisory.php?id=3708 Apple Security Update - 2004-09-07 (APPLE-SA-2004-09-07) http://www.net-security.org/advisory.php?id=3707 Gentoo Linux Security Advisory - multi-gnome-terminal: Information leak (GLSA 200409-10) http://www.net-security.org/advisory.php?id=3706 SUSE Security Announcement - apache2 (SUSE-SA:2004:030) http://www.net-security.org/advisory.php?id=3705 Gentoo Linux Security Advisory - MIT krb5: Multiple vulnerabilities (GLSA 200409-09) http://www.net-security.org/advisory.php?id=3704 ---------------------------------------------------------------- [ Articles ] All articles are located at: http://www.net-security.org/articles_main.php Articles can be contributed to articles@net-security.org ---------------------------------------------------------------- WHO GOES TO JAIL? Not having kept, or being able to access, the right information at the right time is now a serious offence that puts the CEO and/or the CFO in jail for perjury, regardless of who in the organisation may or may not have been to blame. http://www.net-security.org/article.php?id=728 ---------------------------------------------------------------- [ Reviews ] All reviews are located at: http://www.net-security.org/reviews.php ---------------------------------------------------------------- SAMBA-3 BY EXAMPLE: PRACTICAL EXERCISES TO SUCCESSFUL DEPLOYMENT This is a cookbook you've been searching for. That is a slogan. And it is a fact. If you use Samba or you think of using it, this book is something you are going to need. http://www.net-security.org/review.php?id=138 ---------------------------------------------------------------- [ Software ] Windows software is located at: http://net-security.org/software_main.php?cat=1 Linux software is located at: http://net-security.org/software_main.php?cat=2 Pocket PC software is located at: http://net-security.org/software_main.php?cat=3 ---------------------------------------------------------------- AD-AWARE SE PERSONAL EDITION Build 1.04 (Windows) Ad-aware is a free multi spyware removal utility. http://www.net-security.org/software.php?id=135 AIRSNORT 0.2.5a (Linux) AirSnort is a wireless LAN (WLAN) tool which recovers encryption keys. http://www.net-security.org/software.php?id=262 AUTOPSY FORENSIC BROWSER 2.03 (Linux) The Autopsy Forensic Browser is a graphical interface to the command line digital forensic analysis tools in The Sleuth Kit. http://www.net-security.org/software.php?id=216 CRIPPIN 2.2 (Pocket PC) Crippin was designed to protect confidential files in case a Pocket PC is lost or stolen. http://www.net-security.org/software.php?id=544 DANTE 1.1.15 (Linux) Dante is a circuit-level firewall/proxy that can be used to provide convenient and secure network connectivity to a wide range of hosts. http://www.net-security.org/software.php?id=43 SNORTALOG 2.3.0b (Linux) Snortalog is a powerful perl script that summarize Snort logs making an easy view of what attacks are being seen through your network. http://www.net-security.org/software.php?id=455 THE SLEUTH KIT 1.72 (Linux) The Sleuth Kit is a collection of UNIX-based command line file system forensic tools. http://www.net-security.org/software.php?id=215 ---------------------------------------------------------------- [ Webcasts ] All webcasts are located at: http://net-security.org/webcasts.php ---------------------------------------------------------------- Building Effective & Auditable ITIL Change Management Processes in 4 Steps: Phase 2 of The Visible Ops Methodology Organized by Tripwire on 14 September 2004, 11:00 AM http://www.net-security.org/webcast.php?id=327 Consolidated email protection: An introduction to PureMessage Organized by Sophos on 15 September 2004, 10:00 AM http://www.net-security.org/webcast.php?id=303 Learn the Newest Way to Secure Your Windows Environment Organized by RSA Security on 15 September 2004, 3:00 PM http://www.net-security.org/webcast.php?id=331 What's New in Tripwire for Servers and Tripwire Manager 4.5? Organized by Tripwire on 16 September 2004, 11:00 AM http://www.net-security.org/webcast.php?id=325 All anti-virus software is not created equal Organized by Sophos on 21 September 2004, 10:00 AM http://www.net-security.org/webcast.php?id=286 Combating SPAM: An Overview of Leading Anti-SPAM Solutions Organized by KnowledgeStorm on 21 September 2004, 11:00 AM http://www.net-security.org/webcast.php?id=330 Running Effective and Auditable Change and Configuration Management Processes Organized by Tripwire on 28 September 2004, 11:00 AM http://www.net-security.org/webcast.php?id=326 Building Effective & Auditable ITIL Change Management Processes in 4 Steps: Phase 3 and 4 of The Visible Ops Methodology Organized by Tripwire on 5 October 2004, 11:00 AM http://www.net-security.org/webcast.php?id=328 ---------------------------------------------------------------- [ Conferences ] All conferences are located at: http://net-security.org/conferences.php ---------------------------------------------------------------- 4th Annual International East-West Security Conference Organized by Overseas Exhibitions & Conferences - 6 September-11 September 2004 http://www.net-security.org/conference.php?id=96 HealthSec Conference & Expo / Mobile & Wireless Information Security Expo 2004 Organized by MIS Training Institute - 27 September-28 September 2004 http://www.net-security.org/conference.php?id=93 The 14th Virus Bulletin International Conference (VB2004) Organized by Virus Bulletin - 29 September-1 October 2004 http://www.net-security.org/conference.php?id=83 HITBSecConf2004 Organized by Hack In The Box - 4 October-7 October 2004 http://www.net-security.org/conference.php?id=95 SecurIT Summit Organized by Marcus Evans - 18 October-20 October 2004 http://www.net-security.org/conference.php?id=98 RSA Conference Europe 2004 Organized by RSA Security - 3 November-5 November 2004 http://www.net-security.org/conference.php?id=90 e-Nordic: Business & Technology Integration Summit Organized by Marcus Evans - 8 November-10 November 2004 http://www.net-security.org/conference.php?id=99 IBM SecureWorld Conference EMEA 2004 Organized by IBM - 23 November-26 November 2004 http://www.net-security.org/conference.php?id=91 Middle East IT Security Conference 2004 Organized by MEITSEC - 12 December-14 December 2004 http://www.net-security.org/conference.php?id=97 ECCE E-crime and Computer Evidence 2005 Organized by n-gate ltd. - 29 March-30 March 2005 http://www.net-security.org/conference.php?id=94 ---------------------------------------------------------------- [ Security World ] All press releases are located at: http://www.net-security.org/press_main.php Send your press releases to press@net-security.org ---------------------------------------------------------------- SafeNet Announces Plans to Acquire Datakey, Inc. http://www.net-security.org/press.php?id=2433 Pgp Corporation Reaches 30,000 Corporate Customers, $30 Million In Orders For Its Encryption Solutions In First 2 Years http://www.net-security.org/press.php?id=2432 IDC Names CipherTrust The Market Leader In Secure Content Management Appliances http://www.net-security.org/press.php?id=2431 SAIC Manages Threat of Open Device Ports with DeviceLock http://www.net-security.org/press.php?id=2430 Stanford University Medical Center Goes Wireless With Trapeze Networks http://www.net-security.org/press.php?id=2429 August Is the Hottest Month for Spam as Volumes Peak at 90 Per cent http://www.net-security.org/press.php?id=2428 ServGate and Activar Establish Partnership to Cover Mexico's Network Security Market http://www.net-security.org/press.php?id=2427 Sybari Software Delivers Advanced Spam Manager, Sybari Enterprise Manager, Antigen 8.0 For Exchange and SMTP Gateways http://www.net-security.org/press.php?id=2426 Aventail and NetContinuum Partner To Deliver Industry-Leading Solution For Application-Layer Security http://www.net-security.org/press.php?id=2425 Lucid Security Names Jonathan Palmer President, CEO http://www.net-security.org/press.php?id=2424 Pointsec's Security Solution Adds Support For The New Nokia 9300 Smartphone http://www.net-security.org/press.php?id=2423 Dekart Private Disk reviewed by Michael E. Callahan aka Dr. File Finder and chosen as one of Dr. File Finder's Picks http://www.net-security.org/press.php?id=2422 Armor2net Personal Firewall3.12: Launched by Armor2net Software to Protect PCs from Threats on the Internet http://www.net-security.org/press.php?id=2421 Inappropriate Email Image Attachments Declining, Reports MessageLabs http://www.net-security.org/press.php?id=2420 New Technology Makes Fighting Hackers Spam And Viruses Easier, Cheaper http://www.net-security.org/press.php?id=2419 Sleep Walking, Viruses And Other IT Security Maladies http://www.net-security.org/press.php?id=2418 F-Secure And WRQ Announce Strategic Partnership, Global SSH Distribution Contract http://www.net-security.org/press.php?id=2417 Qualys Bundles New Scanner Appliance with QualysGuard On Demand Vulnerability Management Service http://www.net-security.org/press.php?id=2416 Symantec Guide Helps Small Businesses Understand and Manage IT Security http://www.net-security.org/press.php?id=2415 SafeNet Announces First Intrusion Prevention IP for Network Semiconductor Market http://www.net-security.org/press.php?id=2414 Entrust and Vordel to Deliver a Comprehensive Security Solution to Accelerate Web Services Deployment http://www.net-security.org/press.php?id=2413 Ubizen Announces Managed Security Solution For The Payments Industry http://www.net-security.org/press.php?id=2412 Juniper Networks Grows SSL VPN Market Share Leadership According To Report By Infonetics Research http://www.net-security.org/press.php?id=2411 Vexira Antivirus For Linux Defends Media Capital Group, The Largest Web Portal And Email Provider In Portugal http://www.net-security.org/press.php?id=2410 F-Secure Policy Manager 5.60 Features New Web Based Tool For Centralized Security Status Monitoring http://www.net-security.org/press.php?id=2409 F-Secure Reinforces Position In The Danish Data Security Market http://www.net-security.org/press.php?id=2408 F-Secure Introduces A New, Easy To Use, Automatic Spam Filtering Solution For Corporate Customers http://www.net-security.org/press.php?id=2407 ---------------------------------------------------------------- [ Virus News ] All virus news are located at: http://www.net-security.org/viruses.php ---------------------------------------------------------------- Weekly Report On Viruses And Intruders - Four Variants of Mydoom http://www.net-security.org/virus_news.php?id=461 Mydoom Creators Ask For Job In Anti-Virus Industry, Reports Sophos http://www.net-security.org/virus_news.php?id=460 Teenage Sasser And Netsky Worm Suspect Charged With Computer Sabotage , Sophos Comments http://www.net-security.org/virus_news.php?id=459 ---------------------------------------------------------------- Questions, contributions, comments or ideas go to: Help Net Security staff staff@net-security.org http://net-security.org ---------------------- Unsubscribe from this weekly digest on: http://www.net-security.org/subscribe.php The archive of the newsletter in TXT and PDF format is available http://www.net-security.org/newsletter_archive.php ---------------------------------------------------------------- Multi-Save Offer! Register three colleagues at this year’s RSA Conference, Europe 3rd-5th November 2004, Barcelona and receive a saving of €100 per registration. If you haven’t already registered your place at the RSA Conference, Europe – the most important information security event of 2004 – time is running out. ---------------------------------------------------------------- Visit www.2004.rsaconference.com/europe to register on-line today – you’ll find all the latest information and critical highlights on the Conference. ----------------------------------------------------------------