Wednesday, April 30, 2008

Microsoft Helps In Hacker Busting With Its Botnet-hunting Tool

Microsoft is giving law enforcers access to a special tool that keeps tabs on botnets. It's done by using data compiled from the 450 million computer users who have installed the Malicious Software Removal tool coming with Windows.

"The tool includes data and software that helps law enforcers get a better picture of the data being provided by Microsoft's users", said Tim Cranton, associate general counsel with Microsoft's World Wide Internet Safety Programs.

Botnets are networks consisting of hacked computers. This kind of network is like a super computer that is used for example to send spam and attack servers on the Internet. Botnets have been on Microsoft's radar for about four years - since the company identified them as a significant emerging threat.

Microsoft hasn't come to public with the tool before this but it turns out that it was used in Canadian police's bust made in February. The Sûreté du Québec used botnet-buster to break up a network that had infected nearly 500,000 computers in 110 countries according to Captain Frederick Gaudreau, who heads up the provincial police force's cybercrime unit.

Source

Tuesday, April 29, 2008

WordPress 2.5.1 Fixes 2 Vulnerabilities And A Bunch of Bugs

There's been released a new version of WordPress which contains bug fixes and also fixes for a couple of found vulnerabilities.

First one of these makes it possible to bypass administrator access control by using appropriate cookie. The vulnerability provides also a possibility to execute PHP code as the web server user. Vulnerability can be used only if a WordPress blog is configured to freely permit account creation.

Second one of the found vulnerabilities is cross site scripting (XSS) type vulnerability. Incomplete input checking provides a possibility to execute script code in user's browser.


Vulnerable versions for above meantioned vulnerabilities:
- WordPress 2.5 and possible older versions

Solution:
- Update version to 2.5.1

More information can be read here.

Thursday, April 24, 2008

Mass SQL Injection Going On - Over 500,000 web sites infected already

F-Secure reports in its blog that there's ongoing a new wave of attacks in which criminals code has been inserted to web sites. Problem is massive since there are currently over half a million infected websites.

In most web sites it's possible for a site visitor to input text for example thru blog comments, forum discussion boards etc. If this data from the users isn't checked - quite often these checks are missing - the attacker can add in some own attack code. This is what "sql injection" attack is all about.

In this currently ongoing SQL injection attack used code changes some part of web site contained text to links pointing to criminals own sites. "There's a set of files that gets loaded from these sites that attempts to use different exploits to install an online gaming trojan," tells F-Secure. So far the domains used for hosting the malicious content are nmidahena.com, aspder.com and nihaorr1.com. At the moment initial page on all those domains are unaccessible. This could change though.

It's recommended web administrators to check that their sites don't contain this attack code. Now (if not done already) it's also good time to build up some protection to check the data inserted by the users and this way make malicious code insertion impossible.

Monday, April 21, 2008

Unpatched Vulnerability In Windows Operating System

There has been found a new vulnerability in Windows operating system. It could be exploited by authenticated attackers to gain elevated privileges. This issue is caused by an error when running applications in the context of the NetworkService or LocalService accounts, which could be exploited to gain access to resources in processes that are also running as NetworkService or LocalService, and that have the ability to elevate their privileges to LocalSystem, allowing any NetworkService or LocalService processes to elevate their privileges to LocalSystem.

Microsoft is investigating the vulnerability and will release a fix if it's seen as necessary. As a workaround Microsoft recommends to configure or specify a Worker Process Identity (WPI) for an application pool.

For More information please see Microsoft Security Advisory of the vulnerability.

Vulnerable operating systems:
* Windows XP
* Windows Server 2003
* Windows Vista
* Windows Server 2008

Friday, April 18, 2008

Vulnerabilities in Open Office software

Multiple vulnerabilities have been identified in Open Office software, which could be exploited by attackers to cause a denial of service or compromise an affected system. These issues are caused by heap overflow and corruption errors when processing specially crafted ODF text documents with XForms, or when handling malformed Quattro Pro, EMF or OLE files, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted document.

Vulnerable versions are all versions beyond 2.4 version so users are instructed to update their versions to the latest one.

Release Notes of Open Office 2.4 version can be read here

Thursday, April 17, 2008

Firefox 2.0.0.14 update available

Mozilla has released security and stability updates containing 2.0.0.14 version of Firefox Internet browser.

New users can download latest version of the Firefox browser here.

If you already have Firefox 2.x installed you will receive an automated update notification within 24 to 48 hours. To apply the update manually please select "Check for Updates..." from the Help menu.

Release Notes of the update can be read here.

Wednesday, April 16, 2008

Sun released Java Runtime Environment (JRE) 6 Update 6

Sun has released updated version of the Java SE Runtime Environment (JRE) 6. Java SE Runtime Environment allows end-users to run Java applications.

New version can be downloaded from Sun's Java SE Downloads site (by clicking download button on the right side of "Java Runtime Environment (JRE) 6 Update 6" and following given instructions). Before installing new version it's advisable to remove old versions first.

Release Notes of the update can be read here.