Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, January 16, 2008

Apple Patches iPhone, iPod, QuickTime Security Flaws

http://blog.eitb24.com/media/Image/apple.jpg

Apple has released its first security updates of the new year, fixing bugs in its QuickTime media player and iPhone and iPod touch devices.

As with previous updates, the iPhone 1.1.3 software patch sent those who had installed the unauthorized Jailbreak software -- used to run third-party applications on the iPhone -- scrambling to get their phones up and running. That's because Apple's updates have so far always rendered Jailbreak unusable, forcing users to go through a complex re-installation process.

According to the Unofficial Apple Weblog, it is possible to run third-party software following this latest update, but the process is complex. A simpler Jailbreak 1.1.3 script is expected to be posted eventually at the iPhone Wiki, which is the hub of much iPhone hacking.

The iPhone update fixes two flaws in the Safari browser, including a critical bug that could be exploited to run unauthorized software on the device. A third bug could let an unauthorized user bypass Passcode Lock and launch iPhone applications. The iPod touch is susceptible to the Safari bugs, Apple said.

These updates will be rolled out to customers over the next week via the devices' iTunes update mechanism.

The QuickTime 7.4 update fixes four critical flaws in the software that could be exploited by attackers to crash the media player or even run unauthorized software on a victim's computer. The update is available for both the Windows and Mac OS X operating systems.

However, the software does not fix a serious flaw in the player that was disclosed over the weekend.

Security experts are particularly concerned over this flaw because attack code showing how it can be exploited has also been published. Apple is still working to fix the vulnerability, which has to do with QuickTime's use of the Real-Time Streaming Protocol (RTSP).

Source

Friday, January 11, 2008

Warning on stealthy Windows virus

The image “http://newsimg.bbc.co.uk/media/images/44349000/jpg/_44349061_mbr-getty203.jpg” cannot be displayed, because it contains errors.

Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts.

In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe.

Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code.

Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.

Old tricks

The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR).

This is where a computer looks when it is switched on for information about the operating system it will be running.

"If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog.

Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer.

Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information.

Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.

The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.

Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December.

Between 12 December and 7 January, iDefense detected more than 5,000 machines that had been infected with the program.

Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software.

Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running.

Independent security firm GMER has produced a utility that will scan and remove the stealthy program.

Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.

Source

Sunday, December 30, 2007

Microsoft Security & Critical Releases ISO December 2007

http://www.grupogeek.com/wp-content/uploads/2007/05/microsoft-logo.jpg

This ISO-9660 CD image file contains all security and critical updates for Windows released on Windows Update on October, 2006. October 2006 Security and Critical Releases ISO Image does not contain security updates for any other Microsoft products.

This CD image is intended for corporate administrators who manage large multinational organizations, who need to download multiple individual language versions of each security update and who do not use an automated solution such as WSUS. Use this image to download multiple updates in all languages at the same time.

Caution: Be sure to check the individual security bulletins at http://www.microsoft.com/technet/security prior to deployment of these updates to ensure that the files have not been updated at a later date.

Download

Tuesday, December 11, 2007

Norton AntiVirus 11 for Leopard Announced

Symantec has introduced Norton AntiVirus 11 for Mac, featuring support for Mac OS X 10.5 Leopard.

The software furnishes vulnerability protection technology, which watches the web application layer. Norton AntiVirus automatically detects and removes viruses, scans and cleans downloaded files and email attachments, and protects against software vulnerabilities.

To address the growth of multi-platform PC and Mac environments, Norton AntiVirus 11 for Mac scans for both PC and Mac vulnerabilities, viruses and macro viruses.

Symantec promises performance and engine improvements to ensure better compatibility and less impact on system startup and resource usage. Product, virus definition, and vulnerability protection updates are automatic.

A new Norton AntiVirus dashboard widget gives a quick summary of system protection and status. This also offers a 'snooze button' scan, if a Mac user's engaged in another task on their computer they can reschedule the virus scan for a more convenient time.

For power users, Norton AntiVirus 11 for Mac can be accessed using the Terminal, bypassing the application completely and allowing such users to add antivirus scans and other capabilities to their own custom scripts.

Norton AntiVirus 11 costs £39.99.

Source

Wednesday, November 14, 2007

One Care 2.0 Final - Coming Soon


Looks like OneCare 2.0 could be going gold very soon. As well as it showing up on Amazon.com with a retail release date of next week, an email sent to OneCare users tonight suggests that a web release will be even sooner than that. On top of that, the OneCare installation page has been unavailable for several hours tonight, which is always a good sign that a release is right around the corner.



For those of you already using OneCare, you should be prompted to upgrade once the new version is available, though you can still upgrade manually once its out. If you haven't been testing the OneCare 2.0 beta, you should read up on the new features before it launches - new features include multi PC management, centralised backups and much more. You never know, it might just catch your eye... ;)

Source

Thursday, August 23, 2007

Four Tips For Increasing Wireless Network Security

Passwords aren't enough to protect home wireless networks, and they're particularly poor security choices for networks of larger organizations, according to a University of Maryland assistant professor.

Michel Cukier, assistant professor of mechanical engineering and affiliate of the A. James Clark School of Engineering Center for Risk and Reliability and Institute for Systems Research, said that many users who link to an organization's network from home do so through their own unmanaged wireless networks. He released a paper Wednesday explaining the risks and outlining steps that wireless users can take to increase security.

"If these secondary connections are not secure, they open up the entire network to trouble," Cukier said in a prepared statement. "Unsecured wireless access points pose problems for businesses, cities, and other organizations that make wireless access available to customers, employees, and residents. Unsecured connections are an open invitation to hackers seeking access to vulnerable computers."

Cukier said there are several steps that wireless network owners and administrators can take to improve security and discourage "parasites" trolling for access and unsecured connections.

First, he suggests limiting the strength of wireless networks so they cannot be detected beyond the walls of a home or office. Cukier advises disabling the Service Set Identifier broadcasting. SSID is a code attached to packets on a wireless network. It identifies each packet as part of that network and allows all wireless clients within range to spot the network. When it's disabled, it's more difficult for unauthorized users to spot the network.

Cukier said that regularly changing encryption keys may increase network protection. He said Wi-Fi Protected Access should be used when possible, because Wired Equivalent Privacy can be decrypted with special software.

Cukier said that MAC addresses can also increase protection if the wireless access point is set up to only accept connections from a known MAC address.