Showing posts with label Advisory. Show all posts
Showing posts with label Advisory. Show all posts

Spam Attacks Using Opera Email Signature

In the last few days, Opera received complaints and notifications regarding some emails sent to random people on behalf of the Norway-based company. These emails, bearing fake signatures, contained malicious software that was installed on people's computers as soon as they chose to read what the Opera staff wanted to notify them of.

Seeing as how some were misled by the messages, the company decided to advise all its users to avoid any breaking news as well as celebrity or accident related emails coming from unknown senders or from unsolicited sources. To avoid getting infected after reading said emails, meant to gain people's trust by making use of the brand name, users are advised to remove the default signature from their Opera mail client.

Four easy steps are enough to avoid falling into the trap, as the representatives of the company say. In order to change or remove the signature tab that misleads so many, users have to enter the "Visit Tool" menu and select the "Mail and Chat Accounts" option. Next, they have to choose, out of these two, only the email account, and click on the "Edit" button. From here on, they can either delete the default signature, or change it with a customized one that would not cause any more confusion.

The Opera team reassured users that they had nothing to do with the attacks. Although they keep the emails of their subscribers in a database to notify them when some new products are launched, the list was not lost or sold to any third party. The representatives said that the company was the one to be affected the most by spammers. "These attacks trespass on our brand and undermine the trust we have worked hard to build with both Opera users and non-Opera users around the Web. We take this seriously, and hope this notice will help raise greater awareness of and vigilance against these attacks."

[Source: softpedia]

How to Protect Your Data from Malware

Internet users are no longer so naive as to open files that come from unknown senders and with the promise of revealing celebrities in compromising situations. However, they still open emails that seem to have been sent by their bosses or business partners, without taking any precaution or verifying who really is behind the "No work tomorrow for all the employees" message.

In order to prevent their data from being hijacked, users are advised by the SANS Institute to enable the Principle of Least Privilege, which allows every module to access only the information and resources that are necessary for its functioning. "We tend to operate desktops under the principle of most privilege. How many of you allow your users administrator rights in the workplace? At home, everyone has local administrator. This allows the ‘bad guys’ free reign." says John Bambenek of the SANS Institute.

A common mistake people make is that of considering an anti-virus solution a cure-all tool. Their confidence in it goes to such extents that they don't back it up with other applications, which can really work together with the anti-virus to create a malware shield. SANS also underlines the importance of a firewall, that can enhance the estimated 90% chances of an anti-virus to block an attack – all the more when anti-viruses don't always manage to keep the pace with malware spreaders and that they only remove known threats.

"For instance, the combination of AV protection with a good perimeter firewall brings you a little farther down the road of security. While there is a debate on whitelisting vs. blacklisting technologies for binaries, a good step would be to start digitally signing binaries and go to a ‘bayesian’ method of determining risk. Not perfect, but better." Bambenek advises.

Both end-users and developers have to acknowledge that data, identities and intellectual property are those in need of protection, and not the case that hosts the information, as hardware components are. By acknowledging that their privacy is at stake, people may become more careful when pressing the "next" and "are you sure?" buttons of their anti-virus without reading the text. With all that, the Institute does not hold people responsible. SANS recommends developers to be more careful when alerting users about malware, because they tend to "mash button" the questions and indications, which are often redundant or too difficult to understand.

[Source: softpedia]

Several SQL Injection Vulnerabilities Discovered in Zoph -

According to an advisory recently released by Secunia, an attacker can manipulate data from a remote location thanks to multiple SQL injection vulnerabilities found in Zoph (Zoph Organizes Photos). The vulnerability has been deemed "moderately critical" by Secunia, but a new version of Zoph, which addresses the security issue, has been made available.

SQL injection attacks have been on the increase lately, and numerous sites have consequently become infected. In the case of Zoph, "certain unspecified input is not properly sanitized before being used in SQL queries" and thus an attacker can inject arbitrary SQL code to manipulate SQL queries. This vulnerability has been detected in all Zoph versions prior to 0.7.0.5.

As of yesterday, the 20th of July, Zoph has released version 0.7.0.5 and users are well advised to update as quickly as possible. "During development of Zoph, I found a couple of possible SQL injections. Although most are not exploitable or only exploitable by an admin user, I have created an updated release for Zoph: v0.7.0.5. I recommend everyone upgrading to this version. The release also includes a number of extra 'safety nets' that will make exploiting any future SQL injections a lot harder. It also fixes a number of bugs in the 0.7 release," says Jeroen Roos from Zoph.


Those of you who are unfamiliar with Zoph must know that it is a web based application that one can use to manage all their digital images, or in layman's terms, an open source photo album. You can use Zoph to organize your increasing photo database, generate thumbnail galleries, record additional info in regard to your pictures, and even control access to said pictures.

The security industry started to detect a large number of SQL injection attacks back in March, the current year. The following month, in April, these attacks started to target trusted, well known sites that attracted a large number of visitors. By June, the number of infected sites had risen to a staggering 76%, according to reports from security company ScanSafe.

[Source: softpedia]

Adobe LiveCycle Workflow XSS Vulnerability

Summary

Name: Adobe LiveCycle Workflow XSS Vulnerability
Release Date: 11 March 2008
Reference: LSD002-2008
CVE Number: CVE-2008-1202
Discover: Dave Lewis
Vendor: Adobe Systems
Product: LiveCycle Workflow 6.2 Management Web Interface
Systems Affected: version 6.2 (as tested)
NB. Other versions may be affected.

Risk: Important
Status: Published
Reference:
1) http://www.liquidmatrix.org/blog/2008/03/11/advisory-adobe-…ility/
2) http://www.adobe.com/support/security/bulletins/apsb08-10.html

Time Line

Discovered: 16 January 2008
Reported: 16 January 2008
Fixed: 5 March 2008
Patch Release: 11 March 2008
Published: 11 March 2008

Description

The Adobe LiveCycle Workflow management login page contains a vulnerability which is susceptible to a cross site scripting (XSS) attack.

Impact: a remote attacker could execute a XSS attack that could pass arbitrary html to the user and capture usernames/passwords.

Technical Details

Input passed to the URL of the web management login page is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.

Fix Information

This issue has been resolved.

The patch may be obtained from:

http://www.adobe.com/go/supportportal

Notes

I would like to thank the Adobe team for their attention to this problem and for their professionalism.

Liquidmatrix Security Digest
http://www.liquidmatrix.org/blog/

2255B Queen Street East
suite 156
Toronto, Ontario
Canada
M4E 1G3

[Source: Liquidmatrix]

VMware Releases Security Alert

From US-CERT:

VMware has released a security alert in response to a vulnerability in Windows-hosted VMware Workstation, VMware Player, and VMware ACE. This vulnerability exists in the host-to-guest shared folders feature and allows applications running in the guest operating system to access the host operating system’s file system. Exploitation of this vulnerability may allow an attacker to circumvent the controls on the guest system and gain read and write access to the host file system.

Article Link

VMWare Advisory

[Source: Liquidmatrix]

CiscoWorks Arbitrary Code Execution Vulnerability

Summary

Name: CiscoWorks Arbitrary Code Execution Vulnerability
Release Date: 28 May 2008
Reference: LSD003-2008
Discover: Dave Lewis
CVE Number: CVE-2008-2054
Vendor: Cisco Systems
Systems Affected: CiscoWorks Common Services (various versions): Cisco Unified Operations Manager (CUOM), Cisco Unified Service Monitor (CUSM), CiscoWorks QoS Policy Manager (QPM), CiscoWorks LAN Management Solution (LMS), Cisco Security Manager (CSM), Cisco TelePresence Readiness Assessment Manager (CTRAM)

Risk: High
Status: Published (Vendor Confirmed, Patch Available)

Description

CiscoWorks Common Services versions 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.1, and 3.1.1 contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code with elevated privileges.

This vulnerability exists due to an unspecified error in CiscoWorks Common Services. An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code resulting in complete system compromise.

Impact: Arbitrary code execution with elevated privileges. Fire bad.

TimeLine

Discovered: 14 February 2008
Reported: 14 February 2008
Fixed: 22 April 2008
Patch Release: 28 May 2008
Published: 28 May 2008

Technical Details

The vulnerability exists due to an unspecified error in CiscoWorks Common Services when it processes attacker-supplied URLs. An unauthenticated, remote attacker could exploit this vulnerability through unspecified means to execute arbitrary code with elevated privileges.

Fix Information

This issue has now been resolved.

The patch may be obtained from:

http://www.cisco.com

Cisco Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a00809a1f14.shtml

I would like to thank Cisco for their professional response to this issue.

Liquidmatrix Security Digest
http://www.liquidmatrix.org/blog/

2255B Queen Street East
suite 156
Toronto, Ontario
Canada
M4E 1G3

[Source: Liquidmatrix]