April 2005 - Posts

Report: Kaspersky's Malware Evolution: January - March 2005

http://www.viruslist.com/en/analysis?pubid=162454316


“Kaspersky Lab presents its quarterly report on malware evolution by Alexander Gostev, Senior Virus Analyst. The report addresses questions such as why email worms no longer seem to be causing epidemics, the increase in worms targeting instant messenger applications, what effect the release of SP2 for Windows XP has had on security, and why adware and spyware are the latest buzzwords in the field of IT security.“


This is a quick, but to the point read. If you want to know what the latest trends are in malware evolution, then this report will help you focus on how malware is evolving.

Posted by Anonymous | with no comments

Microsoft Security Bulletin Re-Releases

It is important to keep track of Microsoft Security Bulletin Re-Releases from month to month as well as the Microsoft Security Bulletins. I know that with all of the hype out there on the new vunerabilities, that it is easy to overlook the security bulletin Re-Releases. You can receive notifications of Re-Releases by subscribing to Microsoft Technical Security Notifications.

This month's Re-Release contains a fix for MS05-002 where the original patch was failing to install via SMS or AutoUpdate on Windows XP SP1 machines. The Re-Release corrects this issue.


********************************************************************

Title: Microsoft Security Bulletin Re-Releases, April 2005

Issued: April 12, 2005

********************************************************************

Summary

=======

The following bulletins have undergone a major revision increment.

Please see the appropriate bulletin for more details.

* MS05-002

* MS05-009

Bulletin Information:

=====================

* MS05-002

- http://www.microsoft.com/technet/security/bulletin/MS05-002.mspx

- Reason for re-release: After the release of the MS05-002

security bulletin, Microsoft became aware of an issue affecting

customers deploying the Windows 98, 98SE and ME security update.

In most cases, the issue caused machines to unexpectedly

restart. Microsoft has investigated this issue and has made

available revised security updates for these platforms. These

revised security updates are available from Windows Update and

the Microsoft Download Center. Customers who have not yet

applied the original version of these updates should visit

Windows Update to receive the revised updates. Customers who

have already applied the original Windows 98, 98SE and ME

security update are advised to install the current revision of

the update from Windows Update.

- Originally posted: January 11, 2005

- Updated: April 12, 2005

- Bulletin Severity Rating: Critical

- Version: 2.0

* MS05-009

- http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx

- Reason for re-release: Subsequent to the release of this

bulletin, it was determined that the update for Windows

Messenger version 4.7.0.2009 (when running on Windows XP

Service Pack 1) was failing to install when distributed via SMS

or AutoUpdate. The updated package corrects this behavior.

- Originally posted: February 8,2005

- Updated: April 12, 2005

- Bulletin Severity Rating: Critical

- Version: 2.0

 

********************************************************************

 

17 Mytob Variants discovered in the last 4 days

This is pretty wild. It makes me wonder if the variants are being created by a well organized group, or if a generator or “virus creation kit” has been made available. It would be an interesting read, if a virus researcher posted in depth information on the mytob variants.

 

http://www.trendmicro.com/vinfo/default.asp?advis=more&sort=date&order=desc


MALWARE NAME

RISK RATING

ADVISORY DATE

 

PATTERN FILE

 WORM_MYTOB.BA

Low

Apr 12, 2005

 

 WORM_MYTOB.AX

Low

Apr 12, 2005

 

 WORM_MYTOB.AV

Low

Apr 11, 2005

 

 WORM_MYTOB.AU

Low

Apr 11, 2005

 

 WORM_MYTOB.AP

Low

Apr 11, 2005

2.559.02 (CPR)

 WORM_MYTOB.AO

Low

Apr 11, 2005

2.558.00

 WORM_MYTOB.AF

Low

Apr 10, 2005

2.557.02 (CPR)

 WORM_MYTOB.AG

Low

Apr 10, 2005

2.554.00

 WORM_MYTOB.AI

Low

Apr 10, 2005

2.554.00

 WORM_MYTOB.AH

Low

Apr 10, 2005

2.554.00

 WORM_MYTOB.AK

Low

Apr 10, 2005

2.557.02 (CPR)

 WORM_MYTOB.AL

Low

Apr 10, 2005

2.556.00

 WORM_MYTOB.AM

Low

Apr 10, 2005

2.556.00

 WORM_MYTOB.AN

Low

Apr 10, 2005

2.556.00

 WORM_MYTOB.AC

Low

Apr 9, 2005

2.551.02 (CPR)

 WORM_MYTOB.AD

Low

Apr 9, 2005

2.551.02 (CPR)

 WORM_MYTOB.AE

Low

Apr 9, 2005

2.554.00

 


Trend Micro
Posted by Anonymous | with no comments

LexisNexis is notifying 280,000 of data theft

http://www.reuters.com/newsArticle.jhtml?type=technologyNews&storyID=8152726

LexisNexis said it is now notifying 280,000 people whose data may have been stolen. The data included names, addresses, Social Security and driver's license numbers. This comes after the 30,000 people that were notified in March.

Posted by Anonymous | with no comments
Filed under:

Sun Java JDK/SDK Jar Directory Traversal Vulnerability

http://secunia.com/advisories/14902/

Sun Java JDK/SDK Jar Directory Traversal Vulnerability
Secunia Advisory: SA14902  
Release Date: 2005-04-11
Critical:
Less critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Sun Java JDK 1.5.x
Sun Java SDK 1.1.x
Sun Java SDK 1.2.x
Sun Java SDK 1.3.x
Sun Java SDK 1.4.x
Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
Pluf has discovered a vulnerability in Sun Java JDK/SDK, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an input validation error when extracting compressed ".jar" archives with the Jar utility. This makes it possible to have files extracted to arbitrary locations outside the specified directory using the "../" directory traversal sequence.

The vulnerability has been confirmed in Sun Java JDK 1.5.0_02 and Sun Java SDK 1.4.2_08. Other versions may also be affected.

Solution:
Do not extract untrusted archives.
Provided and/or discovered by:
Pluf

Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others

Secunia - Stay Secure

Posted by Anonymous | with no comments

Help! My keyboard gave me a virus.

http://www.cnn.com/2005/HEALTH/04/11/keyboards.bacteria.reut/index.html

It only takes one trip to the restroom to realize that some people do not wash their hands. As a computer tech, I always wash my hands after working on someone else’s computer. I thought it might be just my paranoia, but it turns out a study confirms my suspicions. HA!

Posted by Anonymous | with no comments

Microsoft Security Updates 12APR05

http://www.microsoft.com/technet/security/bulletin/advance.mspx

On April 12, 2005, the Microsoft Security Response Center is planning to release:

5 Microsoft Security Bulletins affecting Microsoft Windows. The greatest aggregate, maximum severity rating for these security updates is Critical. Some of these updates will require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer (MBSA).

1 Microsoft Security Bulletin affecting Microsoft Office. The greatest aggregate, maximum severity rating for these security updates is Critical. These updates will not require a restart. These updates will be detectable using MBSA.

1 Microsoft Security Bulletin affecting MSN Messenger. The greatest aggregate, maximum severity rating for these security updates is Critical. These updates may require a restart. These updates will be detectable using the Enterprise Scanning Tool (EST).

1 Microsoft Security Bulletin affecting Microsoft Exchange. The greatest aggregate, maximum severity rating for these security updates is Critical. These updates will not require a restart. These updates will be detectable using MBSA.

In addition, Microsoft will release:

An updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update and the Download Center. Note that this tool will NOT be distributed using Software Update Services (SUS).

2 NON-SECURITY High-Priority Updates for Windows on the Windows Update site. These will be distributed to Software Update Services and are not required to install the security updates.

At this time no additional information on these bulletins such as details regarding severity or details regarding the vulnerability will be made available until 12 April 2005.

Register for the Security Bulletin WebcastInformation about Microsoft's April Security Bulletins (Level 100)
Wednesday, April 13, 2005 11:00 AM (GMT-08:00) Pacific Time (US & Canada)
Join this webcast for a brief overview of the technical details of these April security bulletins.  This webcast will provide you the opportunity to raise your questions and concerns about the security bulletins. A majority of the session will be devoted to addressing your questions and providing answers from our security experts. 


Posted by Anonymous | with no comments

The Real Laws of Security

Congress is reviewing the patriot act today. I often wondered how this was passed in the first place. To quote a friend “Show him something shiny, so he will shut up”. I believe this concept was used first hand with the patriot act. I often think that the folks, who worked to enact it, had to be wondering themselves how they would trample all over the rights of the people and make them think they were getting something shiny. That must be how the name patriot came into the picture.  The word ‘Patriot’ sounds American as apple pie. Hey if the people liked that shiny name, there’s more where that came from. Let’s slide “Eagle” in there. You can find many articles on the issue with a simple Google search. Here is one from the register.

 


“He (Gonzales) has indicated that the Bush Administration might compromise slightly on some of the most objectionable permanent provisions, such as so-called "sneak and peek" warrants, or, as the Justice Department prefers to call them, "delayed notification" warrants, that allow the Feds to break into your house secretly, execute a search, and not tell you about it until they wish to.”


 

What? I think there are some real laws of security that many folks are forgetting, the bill of rights. Now arguments may rise that “technically we can get around this because the bill of rights doesn’t specifically state….yada, yada, yada.” This sounds like many of the social engineers whose path crossed mine in life. They always want to skirt around the issue and ride the line. You see much of the same thing coming from the adware/spyware companies with their EULA’s. Our politicians and Law enforcement agency’s need to recognize that the most important security, is the security of people’s rights and freedom. My love for freedom and the rights of the people is the motivation that I needed to enlist in the Army. It is the motivation that drives me to fight viruses and share information on potential attacks. It however scares me to think that people are willing to give up that security when they are shown something shiny.

 

Without further ado, here are the real laws of security.

Amendment I

Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.


Amendment II

A well regulated Militia, being necessary to the security of a free State, the right of the people to keep and bear Arms, shall not be infringed.


Amendment III

No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law.


Amendment IV

The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.


Amendment V

No person shall be held to answer for a capital, or otherwise infamous crime, unless on a presentment or indictment of a Grand Jury, except in cases arising in the land or naval forces, or in the Militia, when in actual service in time of War or public danger; nor shall any person be subject for the same offence to be twice put in jeopardy of life or limb; nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation.


Amendment VI

In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the State and district wherein the crime shall have been committed, which district shall have been previously ascertained by law, and to be informed of the nature and cause of the accusation; to be confronted with the witnesses against him; to have compulsory process for obtaining witnesses in his favor, and to have the Assistance of Counsel for his defence.


Amendment VII

In Suits at common law, where the value in controversy shall exceed twenty dollars, the right of trial by jury shall be preserved, and no fact tried by a jury, shall be otherwise re-examined in any Court of the United States, than according to the rules of the common law.


Amendment VIII

Excessive bail shall not be required, nor excessive fines imposed, nor cruel and unusual punishments inflicted.


Amendment IX

The enumeration in the Constitution, of certain rights, shall not be construed to deny or disparage others retained by the people.


Amendment X

The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people.


You can read all of them here.

 

Posted by Anonymous | with no comments
Filed under:

Virus Bulletin VB 100 April 2005 - Red Hat Linux 9

Here are the results of the VB 100 test results for the Linux folks. http://www.virusbtn.com/vb100/archives/tests.xml?200504

I am surprised that F-Secure isnt all over this, after the Press Release from sophos in Febuary.

Posted by Anonymous | with no comments
Filed under: