Friday, June 27, 2008

Friday News Feed 6/27/08

Hackers hijack critical Internet organizations Turkish hackers on Thursday managed to deface the Web sites of the international organizations that run the Internet's critical routing infrastructure and regulate domain names. Read more...

Turkish gang redirect ICANN, IANA traffic, taunt 'We control the domains!'




Web firewalls trumping other options as PCI deadline nears





'Vista Capable' lawyers bicker over document discovery





Researchers warn of IE6 zero-day bug





Avaya, Cisco and Nortel face VoIP vulnerabilities





Preventing SQL injection






Startup Promises to Slow Software Tampering - 6/25/2008 12:03:00 PM Metaforic says its anti-hacking tools aren't invulnerable, but definitely will make software exploits less fun





News from FIRST 2008: Driving Security Response Excellence and Innovation







Laptop Searches at Airports Raises Privacy Questions
TSA agents' search of air travelers' laptops is under scrutiny by the US Senate. The search of air travelers' luggage is routine, while the search of electronic devices is not. The practice by government agents at airports of accessing and copying the content of computers and other digital devices have raised 4th Amendment questions. The Senate Judiciary Subcommittee hearing Laptop Searches and Other Violations of Privacy Faced by Americans Returning from Overseas Travel explored the issue.
Laptop Searches in Airports Draw Fire at Senate Hearing, New York Times, June 26, 2008
Posted by EPIC on June 26, 2008.Permanent link to this item.






Carrier Pigeons Bringing Contraband into Prisons
In Brazil.
I think this is the first security vulnerability found in RFC 1149: "Standard for the transmission of IP datagrams on avian carriers." Deep packet inspection seems to be the only way to prevent this attack, although adequate fencing will prevent the protocol from running in the first place.
Posted on June 27, 2008 at 6:32 AM






Internet Explorer 7 Frame Location Handling Vulnerability - Moderately critical - From remoteIssued 1 day ago. sirdarckcat has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct spoofing attacks.






Internet Explorer 6 Window "location" Handling Vulnerability - Moderately critical - From remoteIssued 1 day ago. Updated 11 hours ago. Ph4nt0m Security Team has discovered a vulnerability in Internet Explorer 6, which can be exploited by malicious people to conduct cross-domain scripting attacks.






New PDF exploits: “Old wine in a new bottle!”







National health-record privacy law in Congress
Chuck Miller June 26, 2008
A new law in Congress would require every U.S. citizen to have electronic health records by 2014. It would also set up privacy rules for those records, requiring information keepers to notify patients of security breaches.






Privacy standards help safeguard online health data
Dan Kaplan June 26, 2008
Just a few months after Google and Microsoft announced they were launching online consumer health platforms, a nonprofit has unveiled a common framework to protect sensitive medical records.






Man's "Parrot Fever" Death Tests Products Liability Law
The family of a Texas man who allegedly died of a disease contracted from a sick cockatiel has sued PetSmart for wrongful death, but the fate of similar cases around the country suggests their products liability theory will not fly.
http://www.onpointnews.com/







Former White House Advisor: Hackers Didn't Cause 2003 Blackout
By Kevin Poulsen June 27, 2008 1:38:56 PMCategories: Cybarmageddon!
Cyber security consultant Paul Kurtz threw some cold water this week on a report that Chinese hackers caused the massive 2003 northeastern U.S. blackout. He worked for the White House at the time of the outage.






Marshall Islands email paralysed by 'zombie' attack AFP - Tue Jun 24, 6:42 AM ET
MAJURO (AFP) - Email communication in the Marshall Islands was paralysed Tuesday after hackers launched a "zombie" computer attack on the western Pacific nation's only Internet service provider, officials said.







Antispam Group Outlines Defenses to Block Botnet SpamPC World - Thu Jun 26, 9:40 AM ET
A major antispam organization is pushing a set of new best practices for ISPs to stop increasing volumes of spam generated by...






Russian hackers working inside China…






Summary: Chinese cyberwarfare threat by the Heritage Foundation






European Union Study Security Economics and The Internal Market By Grey McKenzie Today







Can Your Employer Read Your Personal Email After You Are No Longer Employed There?
from the questions-for-the-courts dept
While we already know that plenty of companies have systems in place to monitor your corporate email, what about your personal email accounts? And, just to make it more interesting, what about your personal email accounts after you are no longer employed at the firm? That's what's at stake in a new lawsuit, filed by a guy who was fired from a company, and later learned that they were reading his personal Yahoo email -- including messages he sent to his lawyer about responding to the firing.

Apparently, he left a computer at the office logged in to his Yahoo account, and that made it easy for the company to read his email -- and the company claims that since it's on a company computer, it's fair game. It's not exactly clear how he found out they were reading his email, however. Also, the company claims that the reason they looked at his email was because after getting fired, he used a computer (in plain view of other employees) to send himself various confidential company info. Even if that's true, it's not clear that the company should still be able to read emails in his personal account.







Nate McFeters: Another Trojan hits Mac OS X







Nate McFeters: Russian hackers planning attacks against Baltic countries and Ukraine






The World of Warcraft developer is announcing that it plans to release a "Blizzard Authenticator". It’s a keychain addition which gives all WoW players a six digit security code designed especially by the company to "help prevent unauthorized account access".






.confusion: ICANN opens up Pandora's Box of new TLDs
ICANN voted today on a measure that will allow businesses and other organizations to apply for almost any new top level domain they can think of. The organization believes the measure will help foster growth in online properties, despite some looming concerns about user frustration.
June 26, 2008 - 12:11PM CT - by Jacqui Cheng






Breach-notification laws not working? Robert Lemos, 2008-06-25 Research fails to find a correlation between states with disclosure laws and reduced identity theft, suggesting the best defense for concerned citizens is to take action themselves.






EU advisors: Secure ISPs, form "cyber-NATO"News Brief, 2008-06-26Academic researchers tasked with making information-security recommendations to the European Union call for Internet service providers to clean up their networks and for the creation of a group to aid international investigations.

Thursday, June 26, 2008

Thursday News Feed 6/26/08

Researchers warn of IE6 zero-day bug
Cross-site scripting flaw is variant of a bug reported to Microsoft in May
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9103859&taxonomyId=17&intsrc=kc_top





Fired Director of IT accused of destroying organ donor information of former company






http://www.wyff4.com/news/16710144/detail.html
GREENVILLE, S.C. -- Greenville County technical staff members told county council members Thursday that least five county-owned computers have been accessed illegally. Thursday's meeting included nine council members, but Councilman Tony Trout was not one of them.

The FBI has accused Trout of accessing information on county administrator Joe Kernell's computer as well as council chairman Butch Kirven's computer.







State attorney general becomes identity theft victim
http://www.kentucky.com/210/story/444133.html







Avaya, Cisco and Nortel face VoIP vulnerabilities






Cleaning Chinese malware sites a 'bigger challenge' than in U.S., says researcher






ISP backs off behavioral ad plan






Senators question border laptop searches






$1B market for meddling with DNS poses security problem






CNET employees notified after data breach

Wednesday, June 25, 2008

Wednesday Daily Feed 6/25/08

SQL Injection Attacks Exploiting Unverified User Data InputPosted Tuesday, June 24, 2008 11:35 AM by MSRCTEAM

New tools to block and eradicate SQL injection






Adobe Reader and Acrobat 8.1.2 Security Update


Vulnerability in Adobe Acrobat leads to public exploit
Dan Kaplan June 24, 2008
Adobe has updated its Reader and Acrobat products to shore up a major vulnerability that already is being exploited in the wild.






Using Google Earth to Find Unguarded Houses
UK teens are using Google Earth to find swimming pools they can crash.
How long before someone finds a more serious crime that can be aided by Google Earth?






Malicious Spam Traffic Triples in One Week - 6/25/2008 6:30:00 AM Sudden massive bot recruitment campaign by Srizbi botnet drives malicious spam up 9.9%, according to researchers at Marshal






The Difference Between Application and Session Layer Firewalls
by Ricky M. Magalhaes
Articles / Firewalls & VPNs
A review of the differences between Application and Session layer firewalls.






Two new Linux kernel vulnerabilities discovered & patched








Safari update fixes "carpet bomb" flawNews Brief, 2008-06-20Apple releases a patch for the Windows version of its browser, fixing four flaws including one that allows attackers to place an unlimited number of untrusted executable files on the desktop.






You Thought You Hated Windows? Check Out What Bill Gates Had To Say
from the classic dept
This one is getting passed around pretty quickly, but as he retires from Microsoft, we couldn't resist highlighting this fantastic internal email from Bill Gates complaining about the usability of some Windows features. It's old -- from 2003 -- but it's difficult to read it and not identify with some of the complaints.

Monday, June 23, 2008

Monday News Feed 6/23/08

Laptops break - Do your backups!





Flooded Firms Reassess Disaster Recovery Plans Executives from companies in Cedar Falls, Iowa, said they are assessing how the massive Midwestern floods are affecting their IT operations, and how it is forcing them to reassess disaster recovery plans. Read more...





Microsoft security fix clobbers 2 million password stealers






One-third of IT admins admit snooping with privileged passwords






Filling Out Forms: Still a Dangerous Game - 6/20/2008 5:00:00 PM Despite upgrades and fixes, most browsers are still vulnerable to attacks via Web forms, researcher says






Tech Insight: Finding Security-Sensitive Data – on a Shoestring Budget - 6/20/2008 2:50:00 PM Thanks to open-source tools, discovering the heart of your data doesn't always mean paying an arm and a leg






Fraud-Fighting Community Launches in US - 6/19/2008 5:40:00 PM Subscribers share information about fraudulent online transactions in online service






FCC moves ahead with plan for smut-free wireless broadband






Serious Security Vulnerabilty In Apple OS X Leopard
An unpatched security hole in Apple's OS X operating system could be used by attackers to change key system settings or to take control of vulnerable computers, security researchers warn.
In a posting to news-for-nerds site Slashdot.org on Wednesday, an anonymous reader noted that a core component of OS X 10.4 (Tiger) and 10.5 (Leopard) called Apple Remote Desktop Agent could be leveraged by any user on the machine to install new programs or alter important system settings. Generally, these tasks are reserved for only the "root" account -- the most powerful user account on the system -- or at the very least they require the user to first enter a password for the requested changes to take effect.







Researchers disclose Firefox 3 flawsNews Brief, 2008-06-19Looking to make a big splash, at least three researchers publish details of flaws a few hours after the release of Mozilla's latest browser.






SPY PICTURE: First image of Virgin Galactic SpaceShipTwo structure
http://www.flightglobal.com/articles/2008/06/21/224834/spy-picture-first-image-of-virgin-galactic-spaceshiptwo-structure.html






MPAA Explains Why Proof Shouldn't Be Necessary In Copyright Infringement Cases







Disgruntled hacker sentenced to five years
Sue Marquette Poremba June 20, 2008
A network engineer and technical services manager for San Diego's Council of Community Health Clinics was sentenced to 63 months in prison on federal hacking charges.






The Web's Dark Energy
By Jonathan Zittrain 0 Comments
Community policing can help make the Web safe.






Your Medical Data Online
By Amanda Schaffer 0 Comments
Google and Microsoft are offering rival programs that let people manage their own health information. Do potential users understand the risks?






Four Shanghai hackers admit to DoS extortion - promise not to do it again.






Bank Accounts And PINs Stolen Over Internet Reap Hackers Millions From Citibank By Grey McKenzie 06/20/2008

Friday, June 20, 2008

Friday News Feed 6/20/08

Apple does about-face, fixes Safari's 'carpet bomb' bug Apple has updated the Windows version of Safari, patching four flaws including one that prompted rival Microsoft to urge users to stop using Apple's browser. Read more...

Safari 3.1.2 for Windows released to address vulnerabilities






EBay boosts fraud protections for PayPal users






Fraudulent ATM transactions overseas could be tied to Indiana bank breach






Microsoft admits XP's Bluetooth patch didn't work






Mozilla investigates critical Firefox 3.0 bug
Windows, Mac and Linux versions all have the vulnerability
June 19, 2008 (Computerworld) Mozilla Corp. today downplayed a threat posed by the first vulnerability reported for Firefox 3.0, telling users that the risk is "minimal."
"There is no public exploit, the details are private, and so the risk to users is minimal," Window Snyder, Mozilla's chief security officer, said in an entry to a company blog.
...
Snyder was responding to news yesterday that 3Com Corp.'s TippingPoint, a security vendor that runs the Zero Day Initiative bug bounty program, had purchased a critical Firefox 3.0 vulnerability from an unnamed researcher and then forwarded information on the bug to Mozilla.






Nuance sues start-up Vlingo over speech recognition patent infringement
I wonder who their lawyers are... ;-)






Patch-blocking bug also stymies Microsoft's WSUS







Fraud-Fighting Community Launches in US - 6/19/2008 5:40:00 PM Subscribers share information about fraudulent online transactions in online service







ID Protection Startup Prepares Commercial Push - 6/19/2008 10:00:00 AM After completing identity theft study and numerous breach response engagements, Debix says it's good to go







Stolen Healthcare, Airline Credentials Found on Servers - 6/18/2008 5:45:00 PM Researchers at Finjan say cybercriminals are looking beyond stolen credit card accounts







Why Global Hackers Are Nearly Impossible to Catch
livescience.com — They're in our computers, reading our files. The Chinese government, that is, according to two U.S. Congressmen who recently accused Beijing of sending hackers to ferret out secret documents stored on Congressional computers. The Chinese deny any involvement, but if they were lying, would we be able to prove it?More… (Security)







Teens Charged With Loading Spyware, Changing GradesPC World - Wed Jun 18, 8:30 PM ET
Two Orange County teenagers have been charged with breaking into school computers, installing spyware and altering grades.






MS08-030 Re-released for Windows XP SP2 and SP3








Federal Court Limits Employers' Access to Employees' E-Communications
The 9th Circuit Court upheld the workplace privacy rights of employees in its decision in Quon v. Arch Wireless. Sgt. Jeff Quon and 3 other officers sued Arch Wireless for sharing wireless communication records with their employer, the Ontario Police Department. The City contracted for text messaging service for employees, and later obtained records to investigate whether all communications were work related. The court's decision reversed a lower court ruling, and found that the carrier was in violation of the 4th Amendment and California constitutional guarantees.
Court limits employer access to worker messages, Associated Press, June 19, 2008
Posted by EPIC on June 19, 2008.Permanent link to this item.







Citibank to Replace ATMs Following Crime Spree
http://blogs.washingtonpost.com/securityfix/
One of my sources, the other day, tipped me off that Citibank was in the process of replacing most of its automated teller machines (ATMs), but the source couldn't definitively say why. Citibank told ATM & Debit News that it was replacing some 2,000 proprietary ATMs in "a bid to improve customer service." But a story today by Wired.com reporter Kevin Poulsen suggests that the financial giant is responding to a computer intrusion into a Citibank server that processes ATM withdrawals, an incident that appears to have led to an ATM crime spree.







FISA deal worries privacy groupsNews Brief, 2008-06-18Congressional leaders are reportedly close to a compromise on revamping the Foreign Intelligence Surveillance Act and allowing telecoms a way to sidestep wiretapping lawsuits.







...And worth every penny...
Windows Live OneCare 2.0 Available for Free

Microsoft is indeed offering Windows Live OneCare 2.0 for free, but only the 90-day trial period version. However, the fully fledged security solution can be grabbed from Amazon.com for a total cost of $0. The official price of the product is $49.95. But the actual deducted price is just $30, the e-commerce website offering no less than 40%, or $19.95 off. But in addition to the discount, Amazon.com has also set up a rebate of no less than $30, e...







AP: China admits taking, burying US POW (AP)







Local root escalation vulnerability in Mac OS X 10.4 and 10.5 discovered








Breaking News… NOT!
Friday June 20, 2008 at 4:18 am CSTPosted by Kevin McGhee
No Comments
There mustn’t be much going on in the world today as the Nuwar spammers have moved from jumping on real news of natural disasters and current affairs to creating their own fictional events! This high volume spam campaign is using some wacky subjects to lure people into clicking on the links:

Subject: Britney found hanged in locker room
Subject: White House hit by lightning, catches fire
Subject: Oprah found sleeping the streets
Subject: Eiffel Tower damaged by massive earthquake
Subject: Donald Trump missing, feared kidnapped
Subject: Lastest! Obama quits presidential race

This clever social engineering technique plays on peoples inquisitiveness in news of natural disasters and celebrities. The emails also follow the simple format of some text and a link that looks fairly harmless to the uneducated user.
All the links go to a fake pornotube page hosted on legitimate sites that have been hacked. If you click on the video (that’s actually just an image) it tries to download a .exe file. This is detected as BackDoor-DNM and the spam is also currently detected with our Anti-Spam products.
So it goes without saying.. NEVER click on links in an email unless you are sure of its origin, keep your Anti-Virus software up-to-date and if you have a website make sure its properly secured so you’re not hosting stuff like this.







Disgruntled hacker sentenced to five years
Sue Marquette Poremba June 19, 2008
A network engineer and technical services manager for San Diego's Council of Community Health Clinics was sentenced to 63 months in prison on federal hacking charges.







Kentucky Agrees To Stop Selectively Blocking State Employees From Reading Critical Blogs








Lame NHS loses 31,000 patient records
Michael Krigsman:Setting an example for irresponsibility while violating internal Department of Health policies, the UK National Health Service has lost unencrypted data on 31,000 patients.

Wednesday, June 18, 2008

Wednesday News Feed 06/18/2008

iPhone 3G's business-readiness still in question, Gartner says

On Friday, analyst Jack Gold, of J.Gold Associates LLC, issued a report citing security and support concerns regarding the iPhone 3G, concluding that it is "still coming up short for the enterprise." Gold said he was particularly concerned about the lack of native encryption to protect data on the device if it is stolen. Research in Motion Ltd. offers encryption of the data on its BlackBerries, and the latest versions of Windows Mobile and some other operating systems offer similar functionality, according to Gold

Dulaney said the new iPhone 3g has neither a firewall nor native encryption, "so banks and federal officials are not going to use it." He said Nokia Corp. has introduced native encryption on its E series devices, and he added that the iPhone 3G could eventually have something comparable, but so far it does not.






Blogging gets more dangerous as worldwide arrests triple A University of Washington study found that arrests of bloggers not affiliated with news organizations tripled from 2006 to 2007, mostly due to organizing or reporting on protest movements or exposing public corruption. Read more...






China quake fake in police custody





IBM's Roadrunner zooms to No. 1 on Top500 supercomputer list





Former 'spam king' must pay MySpace $6 million






Iowa floods forcing firms to race to keep IT afloat
June 17, 2008 (Computerworld) As historic floodwaters continue to hammer Cedar Falls, Iowa, local businesses are already assessing the environmental disaster's impact on IT operations, and how their disaster recovery plans are faring.

As of today, 100 blocks in the city's downtown are underwater and 3,900 homes have been evacuated in Cedar Falls.





Microsoft fixes patch-blocking bug
The problem, which Microsoft acknowledged late last Friday, affected administrators using System Center Configuration Manager (ConfigMgr) 2007 to update users' PCs running System Management Server (SMS) 2003 software.

System Center Configuration Manager 2007 is the successor to SMS 2003 that assesses, deploys and updates server and client computers.

According to Microsoft, customers with that combination had been unable to push June's security updates to end users' PCs. Those updates, which patched 10 vulnerabilities in Windows and Internet Explorer, were released on June 10.





June 17, 2008 Ex-official readies suit over bogus child porn rap
http://www.crime-research.org/news/17.06.2008/3417/
...“The overall forensics of the laptop suggest that it had been compromised by a virus,” said Jake Wark, spokesman for Suffolk District Attorney Daniel Conley.

Nationally recognized computer forensic analyst Tami Loehrs told the Herald Michael Fiola’s ordeal was “one of the most horrific cases I’ve seen.” “As soon as you mention child pornography, everybody’s senses go out the window,” she said. Loehrs, who spent a month dissecting the computer for the defense, explained in a 30-page report that the laptop was running corrupted virus-protection software, and Fiola was hit by spammers and crackers bombarding its memory with images of incest and pre-teen porn not visible to the naked eye.

Two forensic examinations conducted by the state Attorney General’s Office for the prosecution concurred with that conclusion, Wark said. Still, Fiola, 53, whose wife, Robin, described as “computer-illiterate,” wants his day in court. He intends to sue the DIA for “destroying our lives.”

“Our lives have been hell,” said Fiola, a former state park ranger now living in Rhode Island. “I hope to recover my reputation, but our friends all ran.”

DIA spokeswoman Linnea Walsh confirmed Fiola “was terminated,” but declined to say if any internal discipline has been meted out as a result of his name being cleared in court.“We stand by our decision,” she said.






Encryption: DLP's Newest Ingredient - 6/17/2008 6:00:00 PM Major vendors increasingly add encryption offerings to their data loss prevention packages





New DNS Trojan Hacks Home Routers - 6/17/2008 5:40:00 PM Researchers discover new variant of DNSChanger that changes DNS settings in home routers





Olympics Part II
On June 16th we published a short diary asking for comments about the dangers of bringing laptops, PDAs, cell phones, etc. to China if you are planning to attend the Olympics in August. We've received a number of interesting comments and I want to share two of them with our readers.

"...I can say that senior scientists and engineers employed by great Asian nations have not been bringing any laptops/notebooks/gadgets to said meetings (in the US). When they carry cel phones/PDAs, these are all scrupiously powered off and tucked out of sight, prior to entering "foreign" (to them) corporate campuses. It is a parking lot ritual of sorts that I have personally witnessed. "






Online Terror Threats Result in Jail Time
A federal court sentenced a Wisconsin man to 6 months in jail plus house arrest for false online threats. 14-Jun-2008







Dallas Airport's Very Revealing Passenger Screening
The Dallas Fort Worth International Airport is testing two millimeter wave whole body imaging machines on travelers. The technology allows a very detailed view of what is under clothing. Unlike an x-ray which penetrates skin, this technology does not. The technology also known as Backscatter X-Ray has been called a virtual strip-search.
New security scan at DFW Airport has privacy advocates worried, Dallas Morning News, June 16, 2008
Posted by EPIC on June 16, 2008.Permanent link to this item.







Magnetic Ring Attack on Electronic Locks
Impressive:
The 'ring of the devil' is capable of attacking this kind of electronic motor lock on two ways.





From http://www.schneier.com/blog/
In reality, forcing lenders to verify identity before issuing credit is exactly the sort of thing we need to do to fight identity theft. Basically, there are two ways to deal with identity theft: Make personal information harder to steal, and make stolen personal information harder to use. We all know the former doesn't work, so that leaves the latter. If Congress wanted to solve the problem for real, one of the things it would do is make fraud alerts permanent for everybody. But the credit industry's lobbyists would never allow that.






from http://blogs.washingtonpost.com/securityfix/
...
Out of the 15,000 spam-advertised domains we examined, nearly half -- 7,142 names -- were registered through a Broomfield, Colo. company called Dynamic Dolphin. As I noted in my previous story, Dynamic Dolphin is the seventh most-popular registrar among spammers who provide patently false information in their public WHOIS records.

Dynamic Dolphin is owned by a company called CPA Empire, which in turn is owned by Media Breakaway LLC. The CEO of Media Breakaway is none other than Scott Richter, the once self-avowed "Spam King" who claims to have quit the business. Anti-spam groups also have recently implicated Media Breakaway in the alleged hijacking of more than 65,000 Internet addresses for use in sending e-mail and hosting commercial Web sites.
...
Continue reading this post »»






"Web traffic volumes will almost double every two years from 2007 to 2012, driven by video and web 2.0 applications, according to a report from Cisco Systems. Cisco's Visual Networking Index (PDF) predicts that visual networking will account for 90 per cent of the traffic coursing through the world's IP networks by 2012. The upward trend is not only driven by consumer demand for YouTube clips and IPTV, according to the report, as business use of video conferencing will grow at 35 per cent CAGR over the same period."







"Craig Wright discovered that the Jura F90 Coffee maker, with its honest-to-God Jura Internet Connection Kit, can be taken over by a remote attacker, who can cause the coffee to be weaker or stronger; change the amount of water per cup; or cause the machine to require service (call this one a DDoC). 'Best yet, the software allows a remote attacker to gain access to the Windows XP system it is running on at the level of the user.' An Internet-enabled, remote-controlled coffee-machine and XP backdoor — what more could a hacker ask for?"







How to repair a dropped Wi-Fi signal on Vista laptops







Virginia Won't Stop Publishing People's Social Security Numbers; But Will Fine You For Republishing Them







Vendor IT security software revenue increases
Dan Kaplan June 17, 2008
Fueled by continued compliance demands and an evolving threat landscape, global software security revenue totaled $10.4 billion last year, a jump of nearly 20 percent, an analyst firm said Tuesday.





Breaking Phone-Call Encryption
By Erica NaoneTuesday, June 17, 2008
A data compression scheme could leave Internet phone calls vulnerable to eavesdroppers.






Bogus Domain Registrar Scamming Small Business, FTC Says







Anonymouse proxy now blocked in PRC






Stolen Medical, Business and Airline Data Discovered on Crimeware Servers in Argentina and Malaysia By Grey McKenzie Today






Islamic Jihad Adds Cyber-War Division To Its Armed Al-Quds Brigades By Grey McKenzie Today

Sunday, June 15, 2008

Monday News Feed 6/16/08

Microsoft snafu blocks enterprise patching
System Center Configuration Manager problem stymies last week's security updates

http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9098078&taxonomyId=17&intsrc=kc_top



June 15, 2008 (Computerworld) Microsoft confirmed late Friday that enterprise administrators using one of its patch distribution tools have not been able to install last week's security updates.
The company offered a workaround and said it is working on a fix.
"We're aware of an issue that is affecting the deployment of the June 2008 security updates," acknowledged Christopher Budd, spokesman for the Microsoft Security Response Center (MSRC), in a post to the group's blog Friday night.
Only corporate administrators using System Center Configuration Manager (ConfigMgr) 2007, which itself was just updated to Service Pack 1 (SP1), are affected, Budd said, and only those systems running System Management Server (SMS) 2003 client software refuse to update. "The impact of this issue is that customers in this configuration cannot deploy the June 2008 security updates to their SMS 2003 clients," said Budd.



Security Advisory 954474: Deployment Issue affecting System Center Configuration Manager 2007servers with SMS 2003 clients













Man gets six months for posting terror threat online


Online Terror Threats Result in Jail Time
A federal court sentenced a Wisconsin man to 6 months in jail plus house arrest for false online threats. 14-Jun-2008













iPhone 3G not there yet for widescale business use















Danish filter catches Romanian child-porn sites














Experts: Spyware legislation needs more work











June 14, 2008 Forensic computer analysts become real employment in police divisions
http://www.crime-research.org/news/14.06.2008/3411/













Email Surveillance Switch Pays Off at Brokerage - 6/13/2008 3:25:00 PM Frustrated by high rate of false positives, Scott and Stringfellow moves to Orchestria













"Some time ago, most electronics were soldered with old-fashioned lead solder, which has been tried and tested for decades. In 2006, the EU banned lead in solder, and so most manufacturers switched to a lead-free solder. Most made the switch in advance, I guess due to shelf-life of products and ironing out problems working with the new material. Lead is added to solder as it melts at low temperature, but also, it prevents the solder from growing 'whiskers' — crystalline limbs of metal. The affect of whiskers on soldered equipment would include random short-circuits and strange RF-effects. Whiskers can grow fairly quickly and become quite long. Robert Cringley wrote this up this some time ago, but it seems that the world has not been taking notice. I guess cars (probably around 30 processors in a modern car) and almost every appliance would be liable to fail sooner than expected due to tin whiskers. Note that accelerated life-expectancy tests can't simulate the passing of time for whiskers to grow. I've googled, and there is plenty of research into the effects of tin whiskers. I should point out that the Wikipedia page linked to above states that tin whisker problems 'are negligible in modern alloys,' but can we trust Wikipedia? So: was the tin whisker problem overhyped, was it an initial problem that has been solved in the few years since lead-free solder came into use, or is it affecting anyone already?"











"Verizon has declared it will no longer offer access to the entire alt.* hierarchy of Usenet newsgroups to its customers. This stems from last week's agreement for major ISPs to cut off access to 'newsgroups and Web sites' that make child pornography available. The story notes, 'No law requires Verizon to do this. Instead, the company (and, to varying extents, Time Warner Cable and Sprint) agreed to restrictions on Usenet in response to political strong-arming by New York State Attorney General Andrew Cuomo, a Democrat. Cuomo claimed that his office found child porn on 88 newsgroups — out of roughly 100,000 newsgroups that exist.' In response, Verizon will cut its customers off from a large portion of Usenet, as it will only carry newsgroups in the Big 8."













EFF, others fighting privacy-invading border laptop searches
The Electronic Frontier Foundation and the Association of Corporate Travel Executives have challenged a court decision allowing border patrols to search and seize citizens' laptops for no reason. They argue that it's not only an "enormous" privacy invasion, the decision also renders the Fourth Amendment of the US constitution useless.
June 13, 2008 - 01:26PM CT - by Jacqui Cheng












Microsoft warns: Get ready for IE 8
Mary Jo Foley: Microsoft is cautioning Web site owners now that they need to be prepping now for possible problems the new, more standards-compliant browser may cause.













'Free Software' Scammers Fined $2.2 Million
from the this-is-not-the-'free'-business-model-we're-talking-about dept














Floods, tornadoes may encourage internet trickery
Dan Kaplan June 13, 2008
The deadly twisters that ripped through Kansas this week and the historic floods sweeping across the Upper Midwest will soon give rise to donation scams and malicious attacks, the SANS Storm Center warned on Friday.














FTC says fining would aid in spyware deterrence
Sue Marquette Poremba June 13, 2008
The Federal Trade Commission wants the power to punish and fine spyware purveyors.













Doubling Laptop Battery Life
By Kate GreeneFriday, June 13, 2008
Intel's new integrated power management could dramatically reduce power consumption in your laptop by shutting down operations not being used.













Containing Internet Worms
By Erica NaoneThursday, June 12, 2008
A new method could stop Internet worms from spreading.















Judge Scuttles Ameritrade Hacking Settlement















British Hacker Faces Extradition Hearing Next Week PC World - Fri Jun 13, 6:00 AM ET
A British hacker fighting extradition to the U.S. on charges of computer hacking is preparing for his final U.K. appeal on...














Nation States' Espionage and Counterespionage
An overview of the 2007 Global Economic Espionage Landscape
» full story













Green Computing & Virtualization – June 24thLearn virtualization best practices and tips - Discover how to reduce energy and IT costs while increasing the efficiency, utilization, and flexibility of your existing computer hardware.