Showing posts with label Security Alerts. Show all posts
Showing posts with label Security Alerts. Show all posts

Monday, June 29, 2009

Adobe Shockwave - New Version Addresses Security Vulnerability

Adobe has released version 11.5.0.600 of Shockwave Player. This version fixes a critical security vulnerability which, according Adobe could beused by an attacker to take control of a user's computer. In order for the attack to be successful the user first had to open a compromised Shockwave file.

All previous versions of Shockwave are affected by the vulnerability and Adobe recommend that all users update to the latest release.

Thursday, June 18, 2009

Microsoft Optical Desktop 1000 and 2000 keyboard vulnerabilities

Users of the Microsoft Optical Desktop 1000 and 2000 wireless keyboards should consider replacing them as it has now become a practical possibility to sniff out their keystrokes. Dreamlab have published the required software and instructions for building the sniffing device based on the Texas Instruments TRF7900A 27 Mhz receiver.

Currently only Microsoft's wireless keyboards transmitting on the 27 Mhz band are vulnerable; Bluetooth keyboards are not at risk.

The vulnerabilities in Microsoft keyoboards have been known about since December 2007 but as yet there are no indications that Microsoft has taken steps to mitigate the them.

If you want to use a wireless keyboard the answer, for now at least is to use a Bluetooth device otherwise use a wired keyboard.

Your Computer Might be Traded Online - Without Your Knowledge

Security provider Finjan has released analysing a botnet trading platform. The "Golden Cash" platform allows criminals to buy and sell botnets with prices varying between $5 and $100 per 1000 computers. The platform also allows criminal to place "orders" for botnets of particular sizes and wait for offers.

Golden Cash also provides an exploit tool kit for infecting PCs and manipulating websites. Finjan's report suggests that this platform represents a highly lucrative system. See Finjan's report here for more details.

New web server attack

Security specialist Robert Hansen (aka RSnake) has released a tool that can disable even large web servers using a standard PC. The tool, called "Slowloris" does not exploit security vulnerabilities but instead works by using a feature in the HTTP protocol known as partial HTTP requests.

The HTTP protocol allows clients to split the data from a GET or POST request over a number of HTTP queries; depending on the server configuration, the first such request can cause the server to allocate a large amount of resources for the response while waiting for the rest of the request. The web servers that are vulerable to this type of attack are those that implement strategies to avoid system overloads by, for example, limiting the number of simulataneous HTTP queries. These include Apache HTTP server, DHTTPD, GoAhead Web Server and Squid, but not Microsoft IIS or Light HTTPd. The basic concept behind this new attack is similar to the half-open TCP connections attacks that have been seen in the past, except that this attack generally only affects the HTTP component of the server and other services are largely unaffected.

There are a number of ways to defend against this attack; web servers could be protected using load balancers and web application firewalls that only forward complete HTTP requests to the server or the reducing the time out for HTTP requests.

Apple release iPhone OS 3.0

Apple has released iPhone OS3.0. This addresses multiple vulnerabilities across many packages, exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial of service, obtain personal information, bypass security restrictions or conduct cross site scripting attacks. Users should review Apple article HT3639 and upgrade to iPhone OS 3.0 to assist in the mitigation of these risks..

Tuesday, June 16, 2009

Apple Releases Java Updates for Mac OS X 10.4 and 10.5

Apple has released Java for Mac OS X 10.4 Release 9 and Java for Mac OS X 10.5 Update 4. These updates address multiple vulnerabilities in Java which may allow an attacker to execute arbitrary code. Further information is available in Apple articles HT3633 and HT3632.

Monday, June 15, 2009

New malware for Mac OS X

Security experts have discovered two new forms of MacOS X malware both of which were foiund on popular pornographic websites. Historically, the MacOS platform has had very little in the way of virus and trojans; but attacks against the Mac platform have been increasing.

The small amount of malware in circulation for the Mac platform has made some Mac owners complacent; Mac owners are less likely to running antivirus software, for example. This complacency has not been helped by Apple's approach to marketing.

In summay, the Mac platform is not exempt from malware. It is true that there is less than 70 known malware programs for the Mac (compared to millions for PC/Windows); but Mac owners should still make sure that they have an appropriate, up to date security suite installed and that they take sensible precautions.