Monday, February 9, 2009

Kaspersky Breach Exposes Sensitive Database, Says Hacker

"A security lapse at Kaspersky has exposed a wealth of proprietary information about the anti-virus provider's products and customers", writes The Register.

"In a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing "users, activation codes, lists of bugs, admins, shop, etc." Kaspersky has declined to comment, but two security experts who reviewed the evidence said the claims appeared convincing."

Assuming that the hack is real it wouldn't be the first time that Kaspersky site has been hacked with a SQL injection. In July 2008, Kaspersky's Malaysian site and several subdomains were harmed by hacker leaving pro-Turkish slogans behind.

Wednesday, February 4, 2009

Vulnerabilities In Mozilla Products

There have been found in Mozilla products: Mozilla Firefox, Thunderbird and SeaMonkey. One (MFSA 2009-01) is categorized as critical, two (MFSA 2009-02 & MFSA 2009-03) as high, one (MFSA 2009-04) as moderate and two (MFSA 2009-05 & MFSA 2009-06) as low.

Vulnerable are following versions:
- Mozilla Firefox 3.x several different versions (2009-01, 2009-02, 2009-03, 2009-04, 2009-05, 2009-06)
- Mozilla Firefox 2.x several different versions (2009-01, 2009-03, 2009-04, 2009-05, 2009-06)
- Mozilla Thunderbird 2.x several different versions (2009-01)
- Mozilla SeaMonkey 1.x several different versions (2009-01, 2009-04, 2009-05)

Non vulnerable versions:
- Mozilla Firefox 3.0.6
- Mozilla Thunderbird 2.0.0.21
- Mozilla SeaMonkey 1.1.15

At the moment of writing this only Firefox fixed version is available. That can be updated with in-built updater or alternatively new version can be downloaded here.

When released, new version for Mozilla Thunderbird can be downloaded here and Mozilla SeaMonkey here.

Sunday, February 1, 2009

Ukrainian DNSChanger websites taken offline

"A Ukrainian Web hosting provider that, according to published reports, has long served as home base to a prolific and invasive family of malicious software has been taken offline following abuse reports from Security Fix to the company's Internet provider", writes Washington Post.

"Since at least 2005, and perhaps earlier, an entity known as UkrTeleGroup Ltd. has hosted hundreds of Web servers that control a vast network of computers infected with some variant of "DNSChanger," according to security software vendor McAfee, which monitors worldwide malware. DNSChanger is a Trojan horse program that changes the host system's settings so that all of the Internet traffic flowing to and from the infected computer is sent through servers controlled by the attackers."

Good news is that this finally happened. Sad thing is that users currently infected with DNSChanger can't now get online since they don't have working DNS servers available. Also, as stated in the article, seems that groups behind DSNChanger trojan have begun to move to a new network called 'Zlkon.lv' in Latvia.

Wednesday, January 28, 2009

Downadup Worm Taking Advantage of Universal Plug And Play

Downadup aka Conficker worm is at the moment a hot topic in computer security. This parasite has infected systems all over the world using a variety of methods to spread itself. One of these is a remote procedure call (RPC) exploit against the MS08-067 vulnerability. Using the vulnerability, the worm injects shellcode that connects back to the infecting machine. This is known as a back-connect. The back-connect works via HTTP on a randomly selected port and the infecting machine responds to incoming requests by providing the entire worm file. The shellcode receives this file and executes it on the remote host, causing it to then become infected.

Nowadays, many users have routers and other gateway devices that by default prevent external computers from connecting their home systems in addition to using network address translation (NAT). Normally that makes back-connect establishing fail and that way protect against Downadup infection.

However, this worm is a sneaky one and tries to bypass the issue by taking advantage of Universal Plug and Play (UPnP) protocol. Eric Chien describes in Symantec Security Response Blog entry how that is done.

Monday, January 26, 2009

New Rogue: Total Defender

"A new Rogue Antivirus program called Total Defender appeared over the weekend", writes Sean-Paul Correll in PandaLabs blog. Found parasite keeps its home behind Total-Defender. com domain located in Latvia.

"An interesting thing we noticed is that the Rogue did not attempt to scare us into purchasing it, rather telling us that the computer was secure after the scan. The Rogue authors are probably doing this to keep a high amount of Rogue installations active for the purposes of data theft or for hire services", Correll states.

Thursday, January 22, 2009

Patched Apple QuickTime And Its Component Released

Apple has released a new version for QuickTime player. Version 7.6 fixes seven different vulnerabilities related to handling of audio and video contents. Vulnerabilities make it possibly to cause an unexpected application termination or arbitrary code execution on target machine.

Also, one vulnerability in QuickTime mpeg-2 playback component for Windows -component was fixed. Fixed problem is related to mpeg-2 file handling and makes it possible to cause an unexpected application termination or execute arbitrary code on target machine.

QuickTime 7.6 can be downloaded and installed via Software Update preferences, or from Apple Downloads.

The QuickTime MPEG-2 Playback Component is not installed by default, and is provided separately from QuickTime. Details are available via http://www.apple.com/quicktime/mpeg2.

Wednesday, January 21, 2009

Rogue Security Program Leaves Russian Systems Alone?

Alex Eckelberry posted to Sunbelt's Blog a snippet of Antivirus 2009 rogue security program. By looking at it seems like the parasite is instructed to not install itself on systems with Russian Windows.