Processors Motherboards Chipsets Memory Graphics Cards Storage Cases and Cooling Mobile Systems Displays Shows and Expos
Latest Sponsors

Powered By
Newegg
Tyan Motherboards
Corsair Memory
Western Digital Hard Drives
Red Hat Linux

PC Perspective Forums Sponsor

Go Back   PC Perspective Forums > General Tech > Networking And Associated Security
User Name
Password
Register FAQ Rules Members List iTrader Search Today's Posts Mark Forums Read

Networking And Associated Security Sort out your networking, security and Windows exploit issues here.

Reply
 §   #541  
Old 12-21-2006, 12:45 PM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

SANS currently have a nice list of "missing" Microsoft patches - security issues for which Microsoft has yet to release a patch:

http://isc.sans.org/diary.php?storyid=1940

Be on your guard against these, particularly the 3 (yes, count 'em, there are 3 now!) unpatched remote code execution vulnerabilities in Microsoft Word. Public exploits are available and are circulating in the wild which, even by Microsoft's definition (see note), makes these issues critical.

Note: Microsoft define a vulnerability as being critical only if it may result in remote code execution and is being actively exploited.
__________________

~ Want to try Linux - check out the PC Perspective Linux FAQ ~
~ Please take some time to read the Forum Rules ~
~ Feed the spamb0tz, don't mail me here: C3B0tz917328@nirvana.admins.ws ~


Last edited by Ned Slider : 12-21-2006 at 12:48 PM.
Reply With Quote
 §   #542  
Old 12-23-2006, 06:14 PM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

From F Secure

Saturday, December 23, 2006
Careful with Christmas.exe Posted by Mikko @ 14:10 GMT
We've just received a sample of something that's called CHRISTMAS.EXE.
When run, this IRCBot variant will try to download various malicious executables from web servers at waiguadown.008.net and user.free.77169.net.
As a decoy, it shows this Christmas-themed image:

Obviously, a gift that keeps on giving. To be avoided.
Reply With Quote
 §   #543  
Old 12-27-2006, 09:43 AM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

From our friends at SANS. Slightly OT but of interest

Handler's Diary December 27th 2006


previous -

Taiwan Earthquakes cut undersea cables (NEW)

Published: 2006-12-27,
Last Updated: 2006-12-27 06:52:00 UTC by George Bakos (Version: 1)

A number of readers submitted reports of Internet slowness to/from Asia. We now know that this is a direct result of up to six submarine cables being severed during a series of temblors off the coast of Taiwan. From Bloomberg:

"Taiwan was jolted by three earthquakes yesterday, killing two people
and injuring 42 others, the island's National Fire Agency said. The
tremors damaged undersea cables, causing a disruption to Internet
traffic and some telephone calls in the region for customers including
Singapore Telecom, PCCW, Chunghwa Telecom Co., Taiwan's biggest
telephone operator, and KDDI Corp., Japan's second-largest telephone
carrier."
Reply With Quote
 §   #544  
Old 01-03-2007, 03:56 PM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

OpenOffice WMF Buffer Overflow

There is a potential issue with OpenOffice WMF buffer overflow allowing remote code execution. Details at this time are unavailable, although Red Hat released the following update notice relating to version 1.x currently shipping with their products:

https://rhn.redhat.com/errata/RHSA-2007-0001.html

Quote:
Originally Posted by Red Hat
Several integer overflow bugs were found in the OpenOffice.org WMF file
processor. An attacker could create a carefully crafted WMF file that could
cause OpenOffice.org to execute arbitrary code when the file was opened by
a victim. (CVE-2006-5870)
The original CVE report provides no details at this time.

It is unclear whether other versions (and/or platforms) are affected at present - we'll post more info when we have it.
Reply With Quote
 §   #545  
Old 01-04-2007, 07:06 AM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Quote:
Originally Posted by Ned Slider View Post
OpenOffice WMF Buffer Overflow

There is a potential issue with OpenOffice WMF buffer overflow allowing remote code execution. Details at this time are unavailable, although Red Hat released the following update notice relating to version 1.x currently shipping with their products:

https://rhn.redhat.com/errata/RHSA-2007-0001.html



The original CVE report provides no details at this time.

It is unclear whether other versions (and/or platforms) are affected at present - we'll post more info when we have it.
More information:

http://secunia.com/advisories/23612/
http://www.openoffice.org/issues/show_bug.cgi?id=70042
http://www.openoffice.org/servlets/R...es&msgNo=10454

It would appear that all current branches of OpenOffice on all platforms are affected.

Mitigation

Users should upgrade to the latest version for their platform or apply the vendor fix.
Reply With Quote
 §   #546  
Old 01-07-2007, 04:09 PM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

Opera users

http://secunia.com/advisories/23613/
Reply With Quote
 §   #547  
Old 01-09-2007, 09:51 PM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Acer Laptop users

http://www.f-secure.com/weblog/archi....html#00001073

Quote:
Originally Posted by F-Secure
Yesterday, we tested a library taken from a Acer notebook. It's very common that vendors sell machines with preloaded applications and system components of their own. The library, named LunchApp.ocx, is probably supposed to help with browsing the vendor's website, enable easy updates and such – it turns out… it also makes all those machines vulnerable to a specially crafted html file that could instantly download malicious file(s) onto the user's machine and then execute them. It gets even better… Acer enabled "safe for scripting" on that ActiveX library so you wouldn't even see when it's used.

It would be nice if Acer (and other vendors) thought twice before providing a "feature" like this in the future.
Reply With Quote
 §   #548  
Old 01-09-2007, 09:54 PM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Microsoft Security Updates for January

http://www.microsoft.com/technet/sec.../ms07-Jan.mspx

3 Critical and 1 Important.

Note that fixes for the 3 existing security vulnerabilities in MS Word are still not fixed
Reply With Quote
 §   #549  
Old 01-10-2007, 10:49 AM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

http://isc.sans.org/diary.html?storyid=2034

The deal on the MS Patches^^

Adobe has a fix

http://isc.sans.org/diary.html?storyid=2037

Last edited by jimzinsocal : 01-10-2007 at 10:51 AM.
Reply With Quote
 §   #550  
Old 01-14-2007, 11:42 AM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

Heres a nasty I was reading about at SANS

http://www.trendmicro.com/vinfo/viru...AC%2EF&VSect=T
Reply With Quote
 §   #551  
Old 01-19-2007, 03:31 AM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Nero 7.7.5.1

Breaking news: We're currently investigating early reports that Nero may have inadvertently posted an infected download yesterday. Here are the details of the affected file as posted on Nero's website:

Quote:
Filename: Nero-7.7.5.1_eng_update.exe
Release Date: January 18th, 2007
Filesize: 105,00 MB ( 110.104.224 bytes )
MD5 checksum: 9d651deff6e350e5859f97d652f4279e
The link for this now appears to be down.

We are looking at reports that the download contained a virus (IM-Worm.Win32.Licat.f) and a piece of adware (MyWebSearch).

If you downloaded this file yesterday, please scan the file and your system. If you have yet to install it, please hold off until we can establish whether it is a real infection or a false positive.

More news to follow as we get it
Reply With Quote
 §   #552  
Old 01-19-2007, 04:59 AM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Quote:
Originally Posted by Ned Slider View Post
Nero 7.7.5.1

More news to follow as we get it
Here's what we're seeing:

Quote:
Complete scanning result of "24A3D0FE.cab", received in VirusTotal at 01.19.2007, 09:46:36 (CET).

Antivirus Version Update Result
AntiVir 7.3.0.26 01.18.2007 no virus found
Authentium 4.93.8 01.19.2007 no virus found
Avast 4.7.936.0 01.18.2007 no virus found
AVG 386 01.18.2007 no virus found
BitDefender 7.2 01.19.2007 Win32.Worm.IM.Licat.J
CAT-QuickHeal 9.00 01.19.2007 no virus found
ClamAV devel-20060426 01.19.2007 no virus found
DrWeb 4.33 01.19.2007 no virus found
eSafe 7.0.14.0 01.19.2007 Win32.Licat.f
eTrust-InoculateIT 23.73.117 01.19.2007 no virus found
eTrust-Vet 30.3.3336 01.19.2007 no virus found
Ewido 4.0 01.18.2007 no virus found
Fortinet 2.82.0.0 01.19.2007 no virus found
F-Prot 3.16f 01.19.2007 no virus found
F-Prot4 4.2.1.29 01.19.2007 no virus found
Ikarus T3.1.0.27 01.09.2007 no virus found
Kaspersky 4.0.2.24 01.19.2007 no virus found
McAfee 4942 01.18.2007 no virus found
Microsoft 1.1904 01.19.2007 no virus found
NOD32v2 1990 01.19.2007 no virus found
Norman 5.80.02 01.18.2007 no virus found
Panda 9.0.0.4 01.19.2007 no virus found
Prevx1 V2 01.19.2007 no virus found
Sophos 4.13.0 01.19.2007 no virus found
Sunbelt 2.2.907.0 01.12.2007 no virus found
TheHacker 6.0.3.151 01.19.2007 no virus found
UNA 1.83 01.18.2007 no virus found
VBA32 3.11.2 01.18.2007 no virus found
VirusBuster 4.3.19:9 01.19.2007 no virus found

Aditional Information
File size: 616169 bytes
MD5: b405db52c1b85813543444f3867b35fc
SHA1: 86fe429aeb4ee74e822d9ed462ff553a1d2548dd
packers: PE_Patch, Aspack
At this point it's still unclear if this is a false positive or real infection.
Reply With Quote
 §   #553  
Old 01-20-2007, 11:53 AM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

http://isc.sans.org/diary.html?storyid=2071
Reply With Quote
 §   #554  
Old 01-20-2007, 08:36 PM
Ned Slider's Avatar
Ned Slider
Moderator
Moderator
 
Profile
Joined: Jul 2001
Location: UK
Age: 42
My System
Status: ( Offline )
Posts: 20,207
Re: Virus Alerts/Security Warnings/Solutions

Quote:
Originally Posted by jimzinsocal View Post
We've seen quite a few variants of this one Jimz.

It looks like a new incarnation of a spambot that's been around for a while... turns your PC into a spam spewing zombie

The initial attachment installs a service (wincom32.sys) that acts as a P2P network and then downloads the spambot together with an email address harvester.

Filtering .EXE email attachments and blocking traffic to or from it's control port (UDP/4000) should provide good defense against this particular nasty. Monitoring for traffic on port UDP/4000 will also allow identification of infected hosts until the AV companies get definitions out for all the different variants, although even then they won't necessarily find infected hosts as the spambot is protected by a rootkit too.

F-Secure have blogged it too:

http://www.f-secure.com/weblog/archi....html#00001088

Last edited by Ned Slider : 01-20-2007 at 08:39 PM.
Reply With Quote
 §   #555  
Old 01-23-2007, 04:28 PM
jimzinsocal
Super Moderator
Super Moderator
 
Profile
Joined: Aug 2001
Status: ( Offline )
Posts: 73,206
Re: Virus Alerts/Security Warnings/Solutions

SANS today.

Remove old JRE!
Published: 2007-01-22,
Last Updated: 2007-01-23 00:53:25 UTC
by Adrien de Beaupre (Version: 1)
As new versions of the Sun Java JRE keep coming out to address security vulnerabilities do NOT forget to remove the old versions. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run, update the applications and then update the JRE, and then remove the old JRE versions. Why? A Java applet can request which version of JRE it wishes to use, that's why.
How to.
Corporate silent install/uninstall (Thanks Andrew!)
BTW: "The Sun Java Runtime Environment contains multiple vulnerabilities that can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system" released today. Either permanently disable Java AND Jscript in your browser(S) or keep as close an eye on JRE versions as you do Microsoft Windows patches.
http://sunsolve.sun.com/search/docum...=1-26-102731-1
http://sunsolve.sun.com/search/docum...=1-26-102729-1
http://sunsolve.sun.com/search/docum...=1-26-102760-1
Cheers, Adrien de Beaupré
BSSI/Cinnabar
Reply With Quote
Reply



Go Back   PC Perspective Forums > General Tech > Networking And Associated Security

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:37 PM.


Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© PC Perspective 2000 - Present