Saturday, December 16, 2006

Flaw in Symantec's Antivirus being exploited.


News is out that a flaw in the Symantec ANtivirus software for corporates is being exploited by attackers since thursday. The flaw is seven months old and was first detected by Eeye and Symantec had already issued a patch for this. But many of the users have not patched the system.

Also, it seems that many of the users are using counterfeit version of the Symantec software without knowing about it. This can be supported with the fact that it was only recently that Symantec filed a lawsuit against a piracy ring that has been selling counterfeit versions of Symantec's software since the past three years.

The worm is dubbed Big Yellow and the machines infected with this worm allows the attacker to connect with other computers for malicious attacks.

No significant outbreaks have been reported so far. Symantec has so far received three reports of systems infected with this worm.

It was not long back when another Antivirus maker Panda was reported to be having some major security flaws. And now it is seems to be Symantec's turn to be in the news for the wrong reasons. But having said that it is not entirely Symantec's fault as they had issued a patch way back in the month of May.

Thursday, December 14, 2006

Instant buzz and spywares.


On one of the mails my friend recieved yesterday from a person who is supposed to be one of the "Adsense gurus", whom she had subscribed to out of curiosity, a program called Instant Buzz was suggested as a great tool to drive traffic to your website. Now coming from a source like that any unsuspecting user would have just gone to the Instant buzz site and installed the suggested tool bar which is absolutely free.

Going to the site you will see some catchy words and that would entice an unsuspecting user into downloading it and installing it on your PC.

The kind of offers it was making along with the "free" tag made me wonder how this guys are making money out of it and that too with the claimed full support team that they have.

I have written about spywares/adwares only recently and it did not take much time for me to realise this program could be yet another one that fits into that category. And to confirm my suspicion all I had to do was to Google the words "instant buzz" + spyware (this is just one of the ways one must confirm before installing any program that looks supicious, especially the ones that installs tool bars) and there was a plethora of related results with people talking about how it has affected them badly after installing it.

The pestpatrol report confirmed that this program Silently connects to an unintended location to transmit User Data. And it connects to a server every time that a new browser opens even if it's closed in the previous window.

In the scam.com forum about Instant buzz users were even talking about how hard it was to unistall the program.

The bottom line is never ever install programs that are all decked up with all these promises that are hard to digest. Always be cautious and do your own little research no matter who suggests it.

Scam.com is an ideal place for everyone to check out all the scams and stuff. You can find different categories there like Charity Scams, Corporate Scams, Internet scams etc:-

Also one must definitely check out the Spywarewarrior.com site that has a detailed list about all the rogue/suspect Anti-Spyware Products & Web Sites and other Anti-spyware resources.

Also check out the article I wrote about Spywares and Anti-spywares.

Wednesday, December 13, 2006

Social networks vulnerable to QuickTime security flaws.


I guess everyone knows about the recent QuickTime worm that affected a lot of myspace users. And Apple has not yet released a fix for it but instead just gave a fix for Myspace users and also for Internet Explorer users. This means anyone using any other browser and any other other social networking site using QuickTime is still vulnerable to these kind of attacks.

According to the F-secure blog QuickTime fails to warn the users before loading and executing javascript from external resources – two things that all similar applications are expected to do. For example, Flash allows embedded scripts, but it warns the user when a flash application tries to access an external resource.

The HREF track flaw which was the one that was used to attack the myspace users, it seems is not the only flaw with QuickTime. QuickTime is vulnerable to another similar flaw and it still remains unfixed.

According to the gnucitizen blog the basic problem is that because of its flexibility QuickTime seems to allow execution of malicious content in a form of JavaScript from media files such as mp3, mp4, m4a and everything else that is supported. In the article Backdooring MP3Files the writer talks about the QuickTime vulnerability which is different from the recent HREF track vulnerability.

Apple claims these flaws to be a feature of QuickTime while F-secure begs to differ on that and calls it a vulnerability and recommends that websites should block Apple QuickTime content completely until a patch is available from Apple for both vulnerabilities.

Tuesday, December 12, 2006

Yet another vulnerability in Word.


Within five days of a Microsoft Word Unspecified Memory Corruption Vulnerability appearing on the horizon another Word vulnerability has followed suit. This time it is the Microsoft Word Unspecified Code Execution Vulnerability.

Both of these vulnerabilities are extremely critical. It seems it is time to stay away from opening Word documents or excercise extreme caution.

No patches have been released so far for either of the vulnerabilities.

Both of these vulnerabilties allows the attacker to take control of the infected machine.

The vulnerabilties are already being actively exploited. So be careful with those Word documents arriving from untrusted sources or unexpected Word documents from trusted sources.

See the Secunia report here on the latest Word vulnerability.

Also check out the Eeye Zero day vulnerability tracker.

Related Reading:- Word unspecified memory corruption vulnerability.


Sunday, December 10, 2006

Firefox 3 Alpha version released.



Mozilla yesterday released the Alpha version 1 of Firefox 3 which is code named Granparadiso Alpha 1. You can download the Alpha version at the Mozilla's FTP site.

It was only about 6 weeks back that Mozilla released it's FireFox version 2 and it is rumored that Internet Explorer 7 has captured a better market share over FireFox 2. FireFox 3 which is slated to be released in it's full version somewhere at the end of 2007 will incorporate some features modelled after Internet Explorer 7.

Tgdaily reports that FireFox 3 will have the following features:

*One new feature planned to be in the new browser is called "places", which takes a new approach to bookmarks and page history. Reportedly, these items will be transitioned to the left side of the browser, sort of like Internet Explorer 7.

*Improvements to tabbed browsing will include the ability to move around and reorder tabs in a single browser, as well as a button right next to the last open tab that brings up a new tab, taking another page out of the IE7 list of features.

*Additionally, Firefox 3 will add the ability to receive automatic Firefox updates, like security updates.

*Version 3.0 will have increased session saving capabilities, including the ability to save all data logged in a single session, such as data entered into forms and posts, and the entire page viewing history.

*Resumable downloading will also be more easily available.

*Users have the option of whether or not to enable the session restoration prompt upon opening Firefox.

*Improvements to tabbed browsing.

Also apart from these reported features the new version is expected to feature better support for a crucial graphic standard namely Scalable Vector Graphics (SVG) language. It will also support Cairo graphics library project, which has been designed to make Web pages look the same, irrespective of the platform. Pages compiled under this new library, will look the same on both PC and mobile devices.

Firefox 3 will be built on the next generation of Mozilla's layout engine, Gecko 1.9. Gecko 1.9 will affect the web and platform compatibiltity of Gran Paradiso Alpha 1 in the following ways:

* Windows 95, Windows 98 and Windows ME are no longer supported platforms

* OS X 10.2 is no longer supported, and OS X 10.3.9 or higher is recommended

* Moving DOM nodes between documents now requires a call to importNode or adoptNode as per the DOM specification.

If you need an idea about installing and uninstalling Firefox 3 alpha version, go to this page and scroll down to the relevant area.

It has to be noted that the alpha version 1 is intended for web application developers and the testing community. Current users of Mozilla Firefox should not use Gran Paradiso Alpha 1.

Related reading:-
Security flaw and Phishing attacks in Firefox 2
Microsoft and Secunia at it again and FireFox 2 too affected?
ALL IE7 and FIREFOX vulnerabilities as of date.
Highly critical vulnerabilities in Firefox and Explorer.




Friday, December 08, 2006

Eeye's Zero day vulnerability tracker.


Eeye the Digital Security firm has an online tracker which keeps track of all the Zero day vulnerabilities that are currently unpatched. Right now they have listed 7 zero day vulnerabilities that are active.

The list helps you keep track of all the active Zero day vulnerabilities as well as the patched ones.

The currently unpatched Zero day vulnerabilities are:-

*Word Unspecified Exploit

*ASX Playlist

*Internet Connection Sharing DoS

*ADODB.Connection ActiveX

*Microsoft Office 2003 PPT Local DoS

*WMI Object Broker ActiveX

*RPC Memory Exhaustion

All these active Zero day vulnerabilities are Microsoft related.

Also, Eeye's Blink software efficiently protects the user from the vulnerabilities. Home users can download the free version which is without the spyware protection, Windows Server Operating System Support and some other features which is only available with the paid version that costs $ 59.

Related Reading:-
Great free software inspecting tool by Secunia.



Google