Dinesh 的个人资料SamuraiDinesh照片日志列表 工具 帮助
2月24日

New NIST documents released

The NIST (National Institute of Standards and Technology ) had released  3 new documents:

1. SP 800-45 Version 2, Guidelines on Electronic Mail Security
2. SP 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)
3. SP 800-97, Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i

It was interesting to see how the documents complement each other. The E-mail document has good references to IDPS, which also include good information regarding WLAN...really nice and it is recommend that to take a look at least on the Table of contents.

2月20日

Oz PM health alert spammed with links to exploit

There are some reports of a spammed email with a hyperlink that ultimately attempts to install malware. The email is targeting Austrailians, the email references a heart attack that the Prime Minister has suffered, of course no such heart attack has occurred.

The email tells the reader to go to Australia's "The Australian - keeping the nation informed" website but the link is not for the real "The Australian" website.

The bogus link is to austr-news com

AusCERT has issued an alert with additional details including the following malicious sites linked in variants of the email attack;

2月19日

Clamav security vulnerabilities

The Clamav development team released version 0.90 of their open-source antivirus toolkit today. This version contains fixes for security vulnerabilities described in a number of iDefense advisories that were published today.

ClamAV CAB File Denial of Service Vulnerability (CVE-2007-0898)
Remote attackers can perform a service degradation attack by sending a malformed CAB file through a gateway scanner running ClamAV. The vulnerability can prevent ClamAV from scanning archives succesfully by depleting the available local file descriptors. iDefense investigated a number of common setups and observed that in most cases, mails that cannot be scanned will be auto-denied.

ClamAV MIME Parsing Directory Traversal Vulnerability (CVE-2007-0897)
An input validation bug allows a remote user to overwrite files on the system that are owned by the clamd scanner. A potential target mentioned in the advisory is the virus database. By overwriting this file, the scanner's effectiveness against certain threats can be reduced significantly.

Both vulnerabilities were resolved in ClamAV's new stable 0.90 release, which was released yesterday. Do note that users that automatically download and install signature updates are not automatically covered. When vulnerabilities in anti virus software are addressed, it is important to understand whether they are fixed in the signatures or scanning engines.

Depending on the solution in use, most setups are configured to automatically update the former, while the latter may require separate upgrades. One user wrote in with the really good idea of leveraging the common logwatch tool to check for the typical Freshclam error:

WARNING: Your ClamAV installation is OUTDATED!
WARNING: Local version: 0.88.7 Recommended version: 0.90

Windows Easy Transfer Companion (Beta)

Windows Easy Transfer Companion enables you to automatically transfer your most important programs from your Windows XP-based PC to your new Windows Vista-based PC. The software will move more than 100 of the most popular programs, as well as many others that you may have installed. You have complete control over selecting which programs to transfer, so only the programs you care about will move. The software will alert you if some programs may not be able to transfer, or may not transfer with high confidence. Most security software is not able to transfer due to technical reasons.
Easy Transfer Companion is designed to be used in addition to Windows Easy Transfer—which is part of Windows Vista and automatically transfers your data and settings. Connecting your two computers can be done with either an Easy Transfer Cable (available online, from retailers, and from PC manufacturers), or a home or small business network. If using an Easy Transfer Cable, you must first install Windows Easy Transfer on your Windows XP-based PC. By using Easy Transfer and Easy Transfer Companion you will be able to quickly and easily setup your new PC with all the data, settings, and programs that matter to you, so you can be productive on your new PC right away.
Easy Transfer Companion only transfers programs from a Windows XP-based PC to a Windows Vista-based PC. Easy Transfer Companion is currently in Beta, and only available for the US market.

Download at Microsoft Downloads