Video Screencast Help
Security Response
Showing posts in English
Peter Ferrie | 12 Oct 2006 07:00:00 GMT | 0 comments

Some time ago, the author of W32.Gatt had posted a comment on his Web site that said he read my blog entry aboutthis particular virus. From there on in he assumes that we visit hispage often. In fact, we have no need for it—customers are doing thatfor us.

We receive samples almost as soon as they appear on any Web site,anywhere in the world, and we are notified about curious comments likethat one. To quote the virus author's entry: "Interpretation without acontext of information." Well, exactly. Interestingly, while the authorclaims that Symantec was wrong about why the source was not released,he does not tell us why the source wasn’t released. It must be quitesensitive, maybe even better than my reason, but until we know, I'llstick with my reason.

...

Sarah Gordon | 11 Oct 2006 07:00:00 GMT | 0 comments

VB-Oct06_small.jpg

Monday was a holiday in the United States, but since I’m in Canada I took advantage of that fact in order to not take the day off. My boss should like that. :) Instead, I created some more slides for my upcoming VB presentation;but, I didn’t have a very easy time of it. Some people are naturals atputting together presentations—complete with nice graphics,easy-to-read charts, and a minimum of animation. I’m not one of them.Not only do I fight (and I’m finally winning, I might add) theanimation daemon that seems to want to add flying horses and spinningcircles of yellow and black to each slide, I am dyslexic and I suffer from more than moderate dyscalculia, making charts more than a small challenge.

I think...

Joji Hamada | 10 Oct 2006 07:00:00 GMT | 0 comments

Recently, we have seen a trend in Trojanhorse programs exploiting popular desktop applications. Theapplications that have been exploited have included Microsoft Word,Excel, Powerpoint, and JustSystem's Ichitaro. Now, we have uncovered aTrojan horse exploiting a vulnerability in WinRar—software which maynot be quite as well known as those examples I have just mentioned.

Symantec Security Response has confirmed that Trojan.Radropper exploits the RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability.This vulnerability was first made public in July of this year and hassubsequently been fixed. The current version of WinRAR (version 3.61)does not contain this vulnerability.

The attack was email based and was executed when an email with a RARarchive...

Ben Greenbaum | 10 Oct 2006 07:00:00 GMT | 0 comments

This month is a busy one, with 10 updates in total, fixing 27 distinct vulnerabilities. Of the 10 updates, seven of them are listed as “Critical” by Microsoft. Interestingly, all seven of them are intended to patch various client-side vulnerabilities—four of them in the Office suite.

Critical bugs:

The patched Office vulnerabilities are all file-format vulnerabilities that will allow an attacker to run the code of their choice on the victim machine, provided a user on that machine opens the malicious file.

There are patches for Powerpoint (MS06-058: BIDs 20322, 20304, 20325, 20226), Excel (MS06-059: BIDs...

Sarah Gordon | 10 Oct 2006 07:00:00 GMT | 0 comments

VB-Oct06_small.jpg

I landed in Montreal on Sunday morning and immediately began sortingout pictures of my dogs (!) so I could put the finishing touches on myVirus Bulletin presentation. “Everything I Need to Know About Security I Learned from My Dog and a Country Western Song”is not your usual security paper title; in fact, the initial ideaevolved as a tongue-in-cheek “what if” mental exercise. However, themore I thought about it, and the more people I talked to about it, themore I realized the idea was worth pursuing to the next level.Somewhere along the way it changed to “two dogs”, I submitted theabstract to Virus Bulletin, it was accepted, and the paper began totake shape.

Virus Bulletin is undoubtedly one of the best opportunities(globally...

Dave Cole | 10 Oct 2006 07:00:00 GMT | 0 comments

apocalypse1.JPG

Read ‘em and weep. Doesn’t matter what it is, how much you spent onit, or what you’ve done it implement it, its outlook is about as goodas the Cleveland Browns’ Super Bowl chances. Got your attention? That’sthe idea. This type of apocalyptic proclamation has been alive and wellin information security over the past few years and never ceases to getits share of eyeballs and chatter. Gartner fired a shot across the bowa while back with the “IDS is dead” statement and similar things arenow being said about antivirus. The siren call of these alarmiststatements has proven irresistible, but I’ll offer that while they makefor catchy headlines, they obscure a more complex, but much moreaccurate reality. In this spirit, I’ll offer up a couple of alternateheadlines that are a lot less captivating, but also do a better job ofhitting the mark, in my eyes....

Eric Chien | 09 Oct 2006 07:00:00 GMT | 0 comments

Over the weekend, the Google blog was hacked and someone made a fake post stating Google was discontinuing their Click-To-Call service. A few weeks ago, Randy Charles Morin's blog was reportedly hacked using a new unknown and unpatched exploit by Jason Schramm known as the Host Overflow Application eXception.

Now,some people are putting one and one together and assuming Google's blogwas hacked via the unpatched Host Overflow Application eXception. Theproblem? The Host Overflow Application eXception appears to be a HOAX(follow the capital letters). Jason followed up with a post to his blogwith a supposed patch. The patch itself...

Peter Ferrie | 06 Oct 2006 07:00:00 GMT | 0 comments

“Garry’s Mod” is a fairly popular modification add-on to the first-person shooter game Half-Life 2. Garry’s Mod doesn’t actually contribute any benefits to the game play, but it allows Half-Life 2 players or enthusiasts to modify objects and/or features in the Source engine, which is the 3-D gaming engine used to run Half-Life 2. Lua scripting has also been added to Garry’s Mod to allow players to create personalized game modes and weaponry. Of course, along with the introduction of Lua scripting support to Garry's Mod comes the predictable appearance of Garry's Mod-specific Lua viruses. So far, all of them simply copy themselves into a specific location and add a reference to themselves in the startup list.

Corresponding with the appearance of the virus scripts was the appearance of antivirus scripts. Unfortunately, some of those antivirus scripts are themselves viruses—the classic and misguided...

Jonathan Omansky | 05 Oct 2006 07:00:00 GMT | 0 comments

As a security professional with over 10years of experience in both government and private industries, I amstill surprised at how little awareness the industry has about thetechnology, intent, and challenges surrounding intrusion prevention. Iintend to use this blog (and others moving forward) to lay out a basicunderstanding of what this thing called "IPS" is, from an analyst'spoint of view. Firstly, let's start with some simple explanations andlay to rest the history of the differences between the terms "IPS" and"IDS". I often hear these words used interchangeably in conversations,meetings, papers, and email threads; yet, there is a clear differencein these terms, based on the evolution of the technology.

In the early days of network traffic pattern patching, intrusiondetection software (IDS) was used to match a set of specified stringswithin a network stream and alert and/or log the event for the user.This information was used by system administrators to detect...

Marc Fossi | 04 Oct 2006 07:00:00 GMT | 0 comments

It’s that time of year when the kids goback to school and the leaves start changing colors. In some parts ofthe world (like where I live) the air starts to get cool and the sky isgray in anticipation of snow and freezing temperatures. The thought ofthis approaching cold front might be enough to send some people to seekout an alternate reality online.

One of these online alternate reality worlds, Second Life,reported a data breach in September. Apparently, one of their databasescontaining customer information was breached. The attackers managed toget users’ names and addresses, as well as encrypted credit cardnumbers. While the unencrypted data may not be too much to worry about,users should still make sure to change their passwords. Hopefully, thecredit card numbers were encrypted using a strong algorithm.

Maybe you’ve already been playing around in one of the variousonline worlds, but you feel...