Adobe has released version 11.5.0.600 of Shockwave Player. This version fixes a critical security vulnerability which, according Adobe could beused by an attacker to take control of a user's computer. In order for the attack to be successful the user first had to open a compromised Shockwave file.
All previous versions of Shockwave are affected by the vulnerability and Adobe recommend that all users update to the latest release.
Thoughts and opinions on all things related to IT and Network Security
Showing posts with label Security Alerts. Show all posts
Showing posts with label Security Alerts. Show all posts
Monday, June 29, 2009
Thursday, June 18, 2009
Microsoft Optical Desktop 1000 and 2000 keyboard vulnerabilities
Users of the Microsoft Optical Desktop 1000 and 2000 wireless keyboards should consider replacing them as it has now become a practical possibility to sniff out their keystrokes. Dreamlab have published the required software and instructions for building the sniffing device based on the Texas Instruments TRF7900A 27 Mhz receiver.
Currently only Microsoft's wireless keyboards transmitting on the 27 Mhz band are vulnerable; Bluetooth keyboards are not at risk.
The vulnerabilities in Microsoft keyoboards have been known about since December 2007 but as yet there are no indications that Microsoft has taken steps to mitigate the them.
If you want to use a wireless keyboard the answer, for now at least is to use a Bluetooth device otherwise use a wired keyboard.
Currently only Microsoft's wireless keyboards transmitting on the 27 Mhz band are vulnerable; Bluetooth keyboards are not at risk.
The vulnerabilities in Microsoft keyoboards have been known about since December 2007 but as yet there are no indications that Microsoft has taken steps to mitigate the them.
If you want to use a wireless keyboard the answer, for now at least is to use a Bluetooth device otherwise use a wired keyboard.
Your Computer Might be Traded Online - Without Your Knowledge
Security provider Finjan has released analysing a botnet trading platform. The "Golden Cash" platform allows criminals to buy and sell botnets with prices varying between $5 and $100 per 1000 computers. The platform also allows criminal to place "orders" for botnets of particular sizes and wait for offers.
Golden Cash also provides an exploit tool kit for infecting PCs and manipulating websites. Finjan's report suggests that this platform represents a highly lucrative system. See Finjan's report here for more details.
Golden Cash also provides an exploit tool kit for infecting PCs and manipulating websites. Finjan's report suggests that this platform represents a highly lucrative system. See Finjan's report here for more details.
New web server attack
Security specialist Robert Hansen (aka RSnake) has released a tool that can disable even large web servers using a standard PC. The tool, called "Slowloris" does not exploit security vulnerabilities but instead works by using a feature in the HTTP protocol known as partial HTTP requests.
The HTTP protocol allows clients to split the data from a GET or POST request over a number of HTTP queries; depending on the server configuration, the first such request can cause the server to allocate a large amount of resources for the response while waiting for the rest of the request. The web servers that are vulerable to this type of attack are those that implement strategies to avoid system overloads by, for example, limiting the number of simulataneous HTTP queries. These include Apache HTTP server, DHTTPD, GoAhead Web Server and Squid, but not Microsoft IIS or Light HTTPd. The basic concept behind this new attack is similar to the half-open TCP connections attacks that have been seen in the past, except that this attack generally only affects the HTTP component of the server and other services are largely unaffected.
There are a number of ways to defend against this attack; web servers could be protected using load balancers and web application firewalls that only forward complete HTTP requests to the server or the reducing the time out for HTTP requests.
The HTTP protocol allows clients to split the data from a GET or POST request over a number of HTTP queries; depending on the server configuration, the first such request can cause the server to allocate a large amount of resources for the response while waiting for the rest of the request. The web servers that are vulerable to this type of attack are those that implement strategies to avoid system overloads by, for example, limiting the number of simulataneous HTTP queries. These include Apache HTTP server, DHTTPD, GoAhead Web Server and Squid, but not Microsoft IIS or Light HTTPd. The basic concept behind this new attack is similar to the half-open TCP connections attacks that have been seen in the past, except that this attack generally only affects the HTTP component of the server and other services are largely unaffected.
There are a number of ways to defend against this attack; web servers could be protected using load balancers and web application firewalls that only forward complete HTTP requests to the server or the reducing the time out for HTTP requests.
Apple release iPhone OS 3.0
Apple has released iPhone OS3.0. This addresses multiple vulnerabilities across many packages, exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial of service, obtain personal information, bypass security restrictions or conduct cross site scripting attacks. Users should review Apple article HT3639 and upgrade to iPhone OS 3.0 to assist in the mitigation of these risks..
Tuesday, June 16, 2009
Apple Releases Java Updates for Mac OS X 10.4 and 10.5
Monday, June 15, 2009
New malware for Mac OS X
Security experts have discovered two new forms of MacOS X malware both of which were foiund on popular pornographic websites. Historically, the MacOS platform has had very little in the way of virus and trojans; but attacks against the Mac platform have been increasing.
The small amount of malware in circulation for the Mac platform has made some Mac owners complacent; Mac owners are less likely to running antivirus software, for example. This complacency has not been helped by Apple's approach to marketing.
Subscribe to:
Posts (Atom)