Monday, December 18, 2006

Websense's security threat predictions for 2007.


Websense, one of the reputed Internet security providers have released their version of security threats for the year 2007.

It was only recently that Mcafee released their own predictions for the year 2007 about security threats.

Mcafee's predictions and Websense's predictions are not much different. They both regard that the underground market for exploits will be on an increase in 2007, Social networks will be under increased attacks and vulnerable to exploits, Botnets will be on the rise etc:- But Mcafee's predictions for 2007 has covered more grounds like Rootkits on 32 bit platforms will increase, Parasitic malware will make a come back etc:- You can read about the Mcafee's predictions under the "Related reading" link below.

Okay, let us have a look at the Websense's predictions:

The Criminal Underground Economy:

As I had written in my article "Underground market for security exploits is growing" it is very true that there is a huge underground market were malicious and organized criminals are queuing up to buy the exploits.

Websense predicts that the market for zero-day attack code will be more competitive. This will result in an increase in the number of zero-day attacks and better attacks on both the client and server-side.

Web 2.0 Security Issues Escalate:

With the huge user base that the popular websites especially the social networking sites and social news networking sites carry more and more attackers are concentrating on exploiting them since the target base is widening. Sites like Myspace has been in the news with it's security flaws and for the phishing attacks almost every month.

Even video files are being used to target the users. Who can forget the QuickTime worm that recently compromised a lot of user data in Myspace. And plenty of phishing sites that is reported to be in Myspace. Also, one should remember that the QuickTime flaw that lead to the QuickTime worm attack is not yet patched by Apple and any other social networking sites that allows embedding of this is prone to this sort of an attack.

Allowing users the total freedom to upload user-created content will only increase the security risks.

Anti-Phishing tool bar exploits:

According to Websense "In 2006, several high profile companies released anti-phishing toolbars embedded within the browser. However, Websense predicts that some anti-phishing toolbars will become targets of exploit code designed to disable or avoid their prevention mechanisms."

Well this is already true with the recent security flaw that was found in Firefox 2 which is known as the Reverse cross site request. This allows a malicious person to exploit the flaw in the Password manager in Firefox 2 by putting a fake site and getting the password Manager to automatically fill in the password without even verifying the login server.

Enhanced Concealment of Data:

As I had written in one of my earlier articles, Rootkits + trojans could be a deadly combination. And according to the Websense prediction this will be more on the rise in 2007. Even Mcafee has said the same thing.Attackers will be using encryption with malicious code to bypass preventive measures.

BOT Evolution:

BOT nets is already having an underground market since a group of Zombie computers can be used for DDOS attacks and spam attacks and this is also going to be a major threat in 2007. Distributed command-and-control and the use of other protocols other than Internet Relay Chat (IRC) or HTTP will be used to control BOT networks. Increased use of encryption and custom packing of BOT’s will also occur.

So, once you read the predictions of both Mcafee and Websense you will get an idea as to what to watch out for in the year 2007 and thus will be aware of the precautions to be taken. Even with the increased protection and detection level today's softwares offer, the attackers too are getting more sophisticated trying to stay one step ahead. So as an user we should also stay educated and learn how to stay protected.

Related Reading:-
Mcafee's prediction about the top 10 security threats for the year 2007.



Saturday, December 16, 2006

Flaw in Symantec's Antivirus being exploited.


News is out that a flaw in the Symantec ANtivirus software for corporates is being exploited by attackers since thursday. The flaw is seven months old and was first detected by Eeye and Symantec had already issued a patch for this. But many of the users have not patched the system.

Also, it seems that many of the users are using counterfeit version of the Symantec software without knowing about it. This can be supported with the fact that it was only recently that Symantec filed a lawsuit against a piracy ring that has been selling counterfeit versions of Symantec's software since the past three years.

The worm is dubbed Big Yellow and the machines infected with this worm allows the attacker to connect with other computers for malicious attacks.

No significant outbreaks have been reported so far. Symantec has so far received three reports of systems infected with this worm.

It was not long back when another Antivirus maker Panda was reported to be having some major security flaws. And now it is seems to be Symantec's turn to be in the news for the wrong reasons. But having said that it is not entirely Symantec's fault as they had issued a patch way back in the month of May.

Thursday, December 14, 2006

Instant buzz and spywares.


On one of the mails my friend recieved yesterday from a person who is supposed to be one of the "Adsense gurus", whom she had subscribed to out of curiosity, a program called Instant Buzz was suggested as a great tool to drive traffic to your website. Now coming from a source like that any unsuspecting user would have just gone to the Instant buzz site and installed the suggested tool bar which is absolutely free.

Going to the site you will see some catchy words and that would entice an unsuspecting user into downloading it and installing it on your PC.

The kind of offers it was making along with the "free" tag made me wonder how this guys are making money out of it and that too with the claimed full support team that they have.

I have written about spywares/adwares only recently and it did not take much time for me to realise this program could be yet another one that fits into that category. And to confirm my suspicion all I had to do was to Google the words "instant buzz" + spyware (this is just one of the ways one must confirm before installing any program that looks supicious, especially the ones that installs tool bars) and there was a plethora of related results with people talking about how it has affected them badly after installing it.

The pestpatrol report confirmed that this program Silently connects to an unintended location to transmit User Data. And it connects to a server every time that a new browser opens even if it's closed in the previous window.

In the scam.com forum about Instant buzz users were even talking about how hard it was to unistall the program.

The bottom line is never ever install programs that are all decked up with all these promises that are hard to digest. Always be cautious and do your own little research no matter who suggests it.

Scam.com is an ideal place for everyone to check out all the scams and stuff. You can find different categories there like Charity Scams, Corporate Scams, Internet scams etc:-

Also one must definitely check out the Spywarewarrior.com site that has a detailed list about all the rogue/suspect Anti-Spyware Products & Web Sites and other Anti-spyware resources.

Also check out the article I wrote about Spywares and Anti-spywares.

Wednesday, December 13, 2006

Social networks vulnerable to QuickTime security flaws.


I guess everyone knows about the recent QuickTime worm that affected a lot of myspace users. And Apple has not yet released a fix for it but instead just gave a fix for Myspace users and also for Internet Explorer users. This means anyone using any other browser and any other other social networking site using QuickTime is still vulnerable to these kind of attacks.

According to the F-secure blog QuickTime fails to warn the users before loading and executing javascript from external resources – two things that all similar applications are expected to do. For example, Flash allows embedded scripts, but it warns the user when a flash application tries to access an external resource.

The HREF track flaw which was the one that was used to attack the myspace users, it seems is not the only flaw with QuickTime. QuickTime is vulnerable to another similar flaw and it still remains unfixed.

According to the gnucitizen blog the basic problem is that because of its flexibility QuickTime seems to allow execution of malicious content in a form of JavaScript from media files such as mp3, mp4, m4a and everything else that is supported. In the article Backdooring MP3Files the writer talks about the QuickTime vulnerability which is different from the recent HREF track vulnerability.

Apple claims these flaws to be a feature of QuickTime while F-secure begs to differ on that and calls it a vulnerability and recommends that websites should block Apple QuickTime content completely until a patch is available from Apple for both vulnerabilities.

Tuesday, December 12, 2006

Yet another vulnerability in Word.


Within five days of a Microsoft Word Unspecified Memory Corruption Vulnerability appearing on the horizon another Word vulnerability has followed suit. This time it is the Microsoft Word Unspecified Code Execution Vulnerability.

Both of these vulnerabilities are extremely critical. It seems it is time to stay away from opening Word documents or excercise extreme caution.

No patches have been released so far for either of the vulnerabilities.

Both of these vulnerabilties allows the attacker to take control of the infected machine.

The vulnerabilties are already being actively exploited. So be careful with those Word documents arriving from untrusted sources or unexpected Word documents from trusted sources.

See the Secunia report here on the latest Word vulnerability.

Also check out the Eeye Zero day vulnerability tracker.

Related Reading:- Word unspecified memory corruption vulnerability.


Sunday, December 10, 2006

Firefox 3 Alpha version released.



Mozilla yesterday released the Alpha version 1 of Firefox 3 which is code named Granparadiso Alpha 1. You can download the Alpha version at the Mozilla's FTP site.

It was only about 6 weeks back that Mozilla released it's FireFox version 2 and it is rumored that Internet Explorer 7 has captured a better market share over FireFox 2. FireFox 3 which is slated to be released in it's full version somewhere at the end of 2007 will incorporate some features modelled after Internet Explorer 7.

Tgdaily reports that FireFox 3 will have the following features:

*One new feature planned to be in the new browser is called "places", which takes a new approach to bookmarks and page history. Reportedly, these items will be transitioned to the left side of the browser, sort of like Internet Explorer 7.

*Improvements to tabbed browsing will include the ability to move around and reorder tabs in a single browser, as well as a button right next to the last open tab that brings up a new tab, taking another page out of the IE7 list of features.

*Additionally, Firefox 3 will add the ability to receive automatic Firefox updates, like security updates.

*Version 3.0 will have increased session saving capabilities, including the ability to save all data logged in a single session, such as data entered into forms and posts, and the entire page viewing history.

*Resumable downloading will also be more easily available.

*Users have the option of whether or not to enable the session restoration prompt upon opening Firefox.

*Improvements to tabbed browsing.

Also apart from these reported features the new version is expected to feature better support for a crucial graphic standard namely Scalable Vector Graphics (SVG) language. It will also support Cairo graphics library project, which has been designed to make Web pages look the same, irrespective of the platform. Pages compiled under this new library, will look the same on both PC and mobile devices.

Firefox 3 will be built on the next generation of Mozilla's layout engine, Gecko 1.9. Gecko 1.9 will affect the web and platform compatibiltity of Gran Paradiso Alpha 1 in the following ways:

* Windows 95, Windows 98 and Windows ME are no longer supported platforms

* OS X 10.2 is no longer supported, and OS X 10.3.9 or higher is recommended

* Moving DOM nodes between documents now requires a call to importNode or adoptNode as per the DOM specification.

If you need an idea about installing and uninstalling Firefox 3 alpha version, go to this page and scroll down to the relevant area.

It has to be noted that the alpha version 1 is intended for web application developers and the testing community. Current users of Mozilla Firefox should not use Gran Paradiso Alpha 1.

Related reading:-
Security flaw and Phishing attacks in Firefox 2
Microsoft and Secunia at it again and FireFox 2 too affected?
ALL IE7 and FIREFOX vulnerabilities as of date.
Highly critical vulnerabilities in Firefox and Explorer.




Google