SecurityProNewsAbout UsNewsArchivesFeedback
 

Virus Warnings / Patches
Risk
Virus Name
Date Discoverd
2004-10-07
2004-10-05
2004-10-05
2004-10-05



From The Forum: SecurityWatch

New Spoof: Is It Coming From Within Yahoo?
Posted By: salomon741
A new email out there is being sent with a new spoof of Citibank...
Click to read more...

Website hacking and remedy
Posted By: Mumtaz
Two of our websites are indexed and ranked among top 10-12 search engine listings under most relevant keywords on major search engines. Yet, we are not getting any queries or orders...
Click to read more...

protecting your domain from hackers
Posted By: seolution
What measures do you advise me to undertake to protect my domains from hackers?
Click to read more...


Top Security News

CyberGuard Develops a Custom Mobile Security Appliance
2004-10-07
CyberGuard has developed a custom mobile security appliance - the sVPN or single virtual private network - for remote employees of a leading electronic commerce business...


Inverted Firewall Prevents Rapidly Propagating Worms and Viruses
2004-10-07
Centenary College, the first College in the State of New Jersey to become completely 100% wireless, has deployed the Inverted Firewall to prevent the spread of rapidly propagating worms and viruses on its internal network...


Trust and Protection for Electronic Communications
2004-10-06
RSA Validation Solution v3.0 enables enterprises and government organizations to validate the integrity of digital certificates in real-time to help promote high levels of trust....


Expanded Enterprise Vulnerability Management
2004-10-06
Citadel Security Software will soon release Hercules 3.5 and the new AssetGuard component....


Cost-effective Enterprise Security
2004-10-05
SSH Communications Security released new versions of its SSH Tectia solution, featuring a new pricing model designed to make powerful enterprise security more cost-effective...


McAfee Ranked Highest Overall
2004-10-05
The threat detection technology available in the recently released 2005 version of McAfee VirusScan for home users achieved the overall highest ranking...





Jeremy MuncySecurityProNews UpdateJeremy Muncyjmuncy@securitypronews.com
Friday: October 08, 2004
Opting-Out Could Be Opting-In For Trouble
MessageLabs has issued a warning to Internet users informing them not to click on the “opt-out” link in spam emails. They had discovered a number of messages turning PC’s into a spam distribution point.

Being dubbed the “drag-and-drop javascript exploit”, MessageLabs said the scam uses an Internet Explorer flaw to "download an EXE file when the mouse is scrolled across the malicious domain page, allowing the machine to be turned into an open proxy that spammers can control".

FREE Software

“Users should already know that it is never a good idea to press the 'click here to remove' link on spam emails as it confirms to spammers that the email address is real", said senior antivirus technologist for MessageLabs, Alex Shipp.

"This latest spam attack, however, presents a double whammy: it not only opens up the floodgates to endless amounts of spam as the address is sold to other spammers, but it allows a compromised machine to be used to host their next spam run while spammers are busy in the background stealing confidential data," he said.

Flaw Found In Older Office Versions. A flaw has been discovered that could allow a denial-of-service attack to be executed on systems running older versions of Microsoft Office.

Secunia has said that the vulnerability is the result of an error in the way Microsoft Word manages input when parsing document files. The flaw could be exploited by using a custom made document.

In an email a Microsoft representative said "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports".

"Microsoft is concerned that this new report of a vulnerability in Word was not disclosed responsibly, potentially putting computer users at risk," the representative said. "We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities with no exposure to malicious attackers while the patch is being developed."

It’s been suggested that Microsoft users not open un-trusted Word documents.

Security Patches Released For Apple. A security update has been issued that fixes several flaws in the Mac OS X operating system.

The update, Security Update 2004-09-30, sheds some light on the DNS vulnerabilities in the AFP server and CUPS printing module and a flaw in QuickTime.

Apple has issued fixes for both Mac OS X 10.2 and 10.3. Some of the flaws affect both versions of Mac OS X.

Firewalls Are Failing. According to a Microsoft security expert, firewalls aren’t doing a good job protecting corporate networks.

"We are all bloody lucky that something hasn't obliterated IT on earth," said Microsoft security technology architect Fred Baumhardt, Monday at a technical briefing on the need for next generation firewalls in London. "Firewalls are like retarded routers. They just look at the ports, sources and destinations they like. If a train comes from Gare du Nord [Paris] to Waterloo [London] via Eurostar you allow it to enter the country because you trust it. That's what firewalls currently do. They don't check to see if al-Quaeda is riding inside."

Baumhardt gave an example on how many hackers actually use port 80 to enter a network because it is treated as trusted traffic. He also added that it’s important to protect your network internally, instead of just at the outskirts.

"I don't care which vendor you get it from," he said. "I just want to see [next generation firewall] technology in front of your network."

Security Concerns For MSN Messenger Beta. The beta testing of the newest version of Microsoft’s MSN Messenger has been suspended due to security problems, a company spokeswoman said yesterday.

The potential hazard is located in a new MSN feature called “winks” which allows users to send each other sound animations. The new feature can be over-used to overwhelm a users system.

It is unclear how many people downloaded the potentially vulnerable version of MSN Messenger.




Enjoy!
Jeremy Muncy + The SecurityProNews Team


 

About SecurityProNews
SecurityProNews is updated in real time with vital internet security alerts, news and in-depth articles for IT Managers. SecurityProNews understands that IT Management Begins With Security.
 

SecurityProNews is brought to you by:

SecurityConfig.comNetworkingFiles.com
ITmanagementNews.comNetworkNewz.com
DatabaseProNews.comSQLProNews.com
ITcertificationNews.comSysAdminNews.com
LinuxProNews.comWirelessProNews.com

 
 

AdvertisingNewslettersCorporate InfoSite MapSupport
© 2004 SecurityProNews. An email newsletter.
, Inc. 880 Corporate Drive, Lexington, KY 40503
All Rights Reserved. Terms under which this service is provided to you. Read our privacy policy. Contact us.
SecurityProNews is part of the iEntry Inc. Network of sites and newsletters.