Wednesday, March 7, 2007

Default Router Passwords

Most edge devices (like routers) come with a default passwords which normally is found at the quick setup guide or their manual. But if you are like me, people who don't read manuals, a quick place to find your edge devices passwords would be http://www.routerpasswords.com. Check it out for yourself.

Oh, and once you've accessed the device, CHANGE THE PASSWORD to something complex and document it somewhere safe.

Apple QuickTime Player Remote Heap Overflow

Apple QuickTime Player is reported prone to remote heap overflow vulnerability (exploitable via remotely originated content). Only Windows users are currently affected. Please update to latest at http://www.apple.com/quicktime/win.html

Full advisory can be found at:

http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt

Kaspersky UPX vulnerability revealed

Problem processing packed files led to infinite loop.

Details of a flaw in UPX processing in the Kaspersky anti-virus engine have been made available, a month after the release of a patch to fix the problem.

The vulnerability, which was reported by iDefense, could be exploited by a maliciously created file to cause the software to go into an infinite loop, leading to denial of service on email servers running Kaspersky scanning in their filters, to degradation of performance on other servers and possible total loss of processing on desktop machines.

Kaspersky is the second vendor to be hit by a UPX-related vulnerability this year, after a similar issue hit Trend Micro in early February.

The flaw was patched by Kaspersky within a few weeks of the initial report, and all users should be automatically protected via automatic updates. The iDefense alert on the problem is here, and details from Secunia are here.

PC Hardware Can Be A Malicious Rootkit

I guess, in time, you would need to run your Antivirus on hardware too to check for malicious code. I guess it would be an expensive exploit, nonetheless it could be exploiting hardware and storing itself in your hardware's firmware.

A good practice from now is to buy reliable manufacturer's hardware and update your firmware when they become available.

News excerpt from http://news.com.com/PC+hardware+can+pose+rootkit+threat/2100-7349_3-6162924.html

ARLINGTON, Va.--PC hardware components can provide a way for hackers to sneak malicious code onto a computer, a security researcher warned Wednesday.

Every component in a PC, such as graphics cards, DVD drives and batteries, has some memory space for the software that runs it, called firmware. Miscreants could use this space to hide malicious code that would load the next time the PC boots, John Heasman, research director at NGS Software, said in a presentation at this week's Black Hat DC event here.

Nessus: Be an instant security auditor

I really like those some proclaimed security auditors who come to you and say they can "detect" security flaws in your products and charge you a butt load of money for it. I must say, they did some good work in convincing you.

But seriously speaking, many so called "sec auditors" out there are just a load of scripting kiddies that run tools then Google the findings and look for resolutions, last but not least, they send you their bill. Well, i am not sure if there's a magician's-code like for security auditors not to "reveal" their tricks to the public, i don't really care actually.

So here's a quick trick to become a sufficient auditor (note, by saying sufficient, i mean, basic or enough-for-now level). Try Nessus 3.0, its a vulnerability scanner for almost anything that have an IP (almost).

Its an awesome tool, that i personally use too when performing auditing but, i would provide this type of auditing for free!.

I would suggest to organizations, large or small, to run a basic security audit on all implemented servers, devices, routers or like i said, anything with an IP to see if its secured at least to known security vulnerabilities out there.

Nessus is fast and agentless that runs on many *nix flavors, Windows, Solaris and Macs and even checks for patch levels if configured to do so. Now, try it out for yourself, but first read the how-to-guide then start. Some scans can crash servers so be extremely careful when running on live environment.

And..drum rolls, best part is, its FREE!!! Enjoy!

Brought to you by the good folks at Tenable (http://www.tenablesecurity.com)
Nessus 3.0 download link. http://www.nessus.org/download/
Nessus 3.0 Faq: http://www.nessus.org/plugins/index.php?view=faq

About
The Nessus vulnerability scanner, is the world-leader in active scanners, featuring high speed discovery, asset profiling, and vulnerability analysis of your security posture. Nessus scanners can be distributed throughout an entire enterprise, inside DMZs, and across physically separate networks.

They can also be made available for ad-hoc scanning, daily scans, and quick-response audits. When managed with the Security Center, vulnerability recommendations can be sent to the responsible parties, remediation can be tracked, and security patches can be audited.

Nessus is supported by a world renowned research team and has the largest vulnerability knowledge base, making it suitable for even the most complex environments.

Sunday, March 4, 2007

Best Antivirus & Ratings for 2007

I've summarized some tests performed by Av-comparatives.org, an independent AV research company. The ratings are Advanced+, Advanced, Standard and failed (as of Feb 2007)

Results thanks to: http://www.av-comparatives.org/

Advanced+
========
1. Avira
2. eScan
3. F-Secure (yeah!)
4. Gdata
5. Kaspersky (I use this, proud to have blown 300++ on this baby)
6. TrustPort

Advanced
========
1. Avast
2. AVG
3. Bitdefender
4. Fprot
5. Fortinet
6. NORD32
7. Symantec
8. Norman

Standard
========
1. Dr.Web
2. McAfee (hmm..surprisingly)

Failed
=====
1. Microsoft (not surprising here..)

Another reason to not use Microsoft OneCare *YET* (OneCare may fail to "qualify" further evaluations)

Microsoft product found not up to scratch in AV-Comparatives review.

Respected testing organisation AV-Comparatives has released the results of its latest in-depth test of anti-virus products, with a large batch of products tried out over a wide range of malware. Only one product, Microsoft's Windows Live OneCare, failed to detect enough of the test set to qualify for any level of certification.

As part of a thorough regime of testing, AV-Comparatives runs tests of on-demand detection ability twice a year, pitting products in their most in-depth scanning modes against a vast collection of samples. Top of the test tables this time were GData's AntiVirusKit and AEC's TrustPort (reviewed in the latest issue of Virus Bulletin, available to subscribers here), both multi-engine products which spotted over 99% of the samples. Products from Avira, F-Secure, Kaspersky and MicroWorld also made the top 'Advanced+' grade.

The detection level required for certification at the lowest level, 'Standard', was recently raised from 80% to 85%, and the Microsoft product missed this, scoring just 82.4% overall. As this minimum level of detection is a requirement for inclusion in the review, OneCare risks being excluded from further testing.

'It's very disappointing to see a major product not reaching a good enough level of detection,' said Andreas Clementi, who runs the AV-Comparatives testing. 'For the sake of their customers, I hope Microsoft will be working hard to improve things and ensure OneCare offers full protection to its users.'

OneCare came last in the detection tables for both viruses and trojans. In a further test of polymorphic virus samples, OneCare was placed 15th out of the 17 entries, with fully reliable detection of only four of the 12 viruses used. Microsoft's product also failed to achieve VB100 certification in our recent test of products available for the Windows Vista platform.

McAfee and Doctor Web products achieved the AV-Comparatives 'Standard' grading, with several others including Symantec, BitDefender, Alwil, Grisoft, Eset, Norman, Frisk and Fortinet attaining the 'Advanced' level. Full details of the test results and methodologies can be found at the AV-Comparatives.org website, here.

Skype Users Take Note! (Stration & Storm's gonna get ya..)

Source: http://www.virusbtn.com/news/virus_news/2007/03_01.xml?rss


Skype messages, blogs, forum entries and webmails lead to more malware variants.

Two major gangs of malware distributors have turned to new vectors for spreading their wares this week. While the makers of W32/Stration (aka Warezov) have been spamming Skype messages leading to copies of their latest variant, the 'Storm' series of trojan attacks has evolved a method of inserting links to its malware into forum and blog postings and webmails sent from infected machines.

The Skype attack involves a simple text message sent via Skype, urging recipients to check out a URL link. The messages come from known addresses, thanks to machines infected with the worm sending out the links to their address books. The link carries yet another variant of W32/Stration, but few infections are so far reported, perhaps due in part to the suspicious nature of the message, which aside from posting an unusual-looking URL, also closes the connection as soon as the message is left.

A screenshot of a sample message posting can be seen on the F-Secure blog, here.

The 'Storm worm' gang has also branched out into new territory, with a sophisticated piece of code which recognises when an online form is being sent. Text uploads including blog entries, forum messages and emails sent from web-based services such as MSN Hotmail, Yahoo! mail and Google's Gmail are intercepted as they are sent, and a message with a link posing as an interesting video file are appended. The links, of course, lead to copies the of malware hoping for a new victim.

Responsible for the additions to mail and postings is a trojan downloaded as part of an infection by the 'Storm' series of trojans (aka Peacomm, BAI, Dorf, Small etc.). More detailed information can by found in a blog entry from Symantec's Eric Chien, here.

'Security firms regularly warn users about attachments and links sent by unknown sources,' said John Hawes, Technical Consultant at Virus Bulletin. 'Malware writers love finding ways around this, so users should be wary of executable content whatever the source, and should ensure they are running good quality, up-to-date security software to keep themselves safe from these nasties.'

Month of PHP bugs (PHP language security issues)

Researches have found multiple bugs (which are already discovered) and lots more unknown bugs on the famous scripting language, PHP which stands for Personal Home Page. This famous scripting language is used widely in systems from security companies to large corporations, to embedded devices (for management) and more.

People who use and manage websites on PHP should seriously consider reading about the bugs and vulnerabilities.

Here's a link from the source where i got this from http://www.securityfocus.com/news/11436

Thursday, March 1, 2007

Star Trek Returns in 2008?

Star Trek fans, check this out, paramount Pictures today officially announced a new motion picture tentatively entitled Star Trek XI on Christmas Day 2008. Alas, their website didn't have much info about the new releases.

Anyway, those into ST (not me!, am a starwars fan), gear up those torrents or watch em' on TV.

Link: www.startrek.com | or choose the better of the two, www.starwars.com


Enjoy.