- +
Your World. . . Hacked 02/10/2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network - +
The 10 Most Common Internal Security Threats 05/07/2007 10:09:09
Who’s gaining access to your internal network? New criminal tactics and new kinds of malware are probing networks for vulnerabilities — and increasingly, finding them. We identify the top candidates for security breaches inside your own companyA recent buzzword in security is endpoint: any device that can connect to the corporate network, ranging from a desktop workstation to a laptop, PDA or even mobile phone. As the number of endpoints increases, firewalls and antivirus software are no longer adequate protection
A just-disclosed bug in Windows Vista's built-in e-mail program can be used by hackers to run malicious code on a victimized PC, said a researcher Friday who two weeks ago touted an exploit-for-sale service.
Microsoft acknowledged the report, and said it is investigating the vulnerability.
Symantec's DeepSight network, which issued a warning about the vulnerability in Windows Mail early this morning, upped the threat rating from 6.8 to 7.5 in a follow-up alert after it confirmed that the bug was remote code exploitable. That means an attacker could introduce his or her own malware onto a compromised computer. Windows Mail is the successor to Outlook Express, the entry-level e-mail app that's been bundled with the operating system since the Windows 95 edition.
By crafting an e-mail message with a link to a malicious file -- one hosted on a remote Internet server, say -- and duping the recipient to click on the link, an attacker could infect a Vista PC with software that steals identities or with a backdoor Trojan horse.
In some cases, all that's required is that the user clicks on the link, said Symantec. "An attacker can deliver an e-mail message containing a malicious link that references a local executable," the DeepSight alert read. "If the victim clicks on this link, the native program is executed with no further action required. For instance: An attacker could achieve the execution of the local file 'winrm.cmd.'"
If run, "winrm.cmd" -- the Windows Remote Management command-line tool -- would give an attacker complete access to a PC.
If the link points to a malicious file not on the PC, the user has one more chance to figure out the scam, added Symantec. "If the user follows [this] link, they are presented with a dialog box where they must click 'Yes' to open the file. Once the user clicks 'Yes,' the file opens or executes with the privileges of that user."
Microsoft's Security Response Center (MSRC) team downplayed the potential risk. "Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time," the MSRC said through a company spokeswoman Friday.
It's possible that could change. The researcher who disclosed the bug and posted exploit code on the Full Disclosure security mailing list also announced an exploit-for-sale service nearly almost two weeks ago on the same list.
On March 11, the researcher, who goes by "Kingcope" posted a message on Full Disclosure touting the new service. "We now have our Exploit selling site up and running ... [where] you can purchase quality advisories and exploits. Feel free to contact our sales person for getting the latest Zero-Days," Kingcope wrote.
The Web site referenced in Kingcope's message was unavailable Friday, and sported a "The system is down for maintenance" message. Kingcope did not respond to e-mails requesting details of the bug-for-sale service.
Both Symantec and Microsoft urged users not to click links in unsolicited e-mail, while the former also recommended that users disable HTML within Windows Mail.
As is its practice, Microsoft said it may issue an additional advisory, or patch the problem in a future -- but unspecified -- security update. The next scheduled patch release date for Microsoft products, including Vista, is April 10.
Coincidentally, it was only last week that an executive in Microsoft's security technology unit boasted about Vista and gave the new operating system an A-plus for security in its first 90 days of release.
Computerworld Member Login
Beyond Virtualisation - The Roadmap to 2012
CIO Breakfast Briefing
8:30am - 10:30am
Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt
Attend and discover:
- What happens after virtualisation
- The benefits automation drives
- When automated infrastructures will emerge
- What the roadmap to 2012 looks like
- How to deliver an automated architecture
- How to maximise your investment in virtualisation
- +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years.
Ballarat Grammar Improves Student Access to Computer Based Learning with HP ProCurve 2008-07-04 16:49:00+10
Media release: 40 Per Cent of Australian Businesses Do Not Validate Their Data 2008-07-04 10:29:00+10
Kaseya helps turbo charge BlueFire’s service delivery model 2008-07-03 17:23:00+10
Computershare Selects Symantec for Data Loss Prevention Globally 2008-07-03 14:52:00+10
DST International moves to new Shanghai office 2008-07-03 13:21:00+10
Microsoft 2008 Mission Critical IT
To help you deploy the new Microsoft ’08 technologies into your mission-critical environments, EMC and Microsoft have developed and validated a number of reference architectures. Discover the benefits of leveraging these skills.








