Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, April 5, 2008

Symantec Has Bugs in Software

Symantec confirms flaws in its most popular consumer security software.

Symantec Confirms ActiveX Bugs in its Own Consumer Software

Symantec has confirmed flaws in its most popular consumer security software that could give attackers the means to hijack the Windows PCs that the programs are supposed to protect.

The vulnerabilities are in an ActiveX control that ships with several products, including Norton AntiVirus, Norton Internet Security, Norton SystemWorks and Norton 360.

Ironically, Symantec analysts have both cited the popularity of ActiveX bugs and urged caution when using the controls in comments about other companies' product flaws.

According to alerts released Wednesday by VeriSign Inc.'s iDefense, the ActiveX control "SymAData.dll" sports two vulnerabilities that could be used "to execute arbitrary code with the privileges of the currently logged in user" by attackers able to entice victims to malicious Web sites.

Symantec confirmed the vulnerabilities Wednesday in its own advisory, and said the buggy control has shipped with Windows versions of Norton AntiVirus 2006-2008, Norton Internet Security 2006-2008, Norton SystemWorks 2006-2008 and Norton 360 version 1.0.

While it acknowledged the bugs, Symantec also downplayed the threat, saying that attacks would only succeed from specially crafted sites. "To successfully exploit either vulnerability, an attacker would need to be able to masquerade as the trusted Symantec Web site, such as through a cross-site scripting attack or DNS poisoning," read the company's advisory .

However, cross-site scripting attacks have become common, and although DNS (domain name system) "poisoning" -- fooling a DNS server into thinking the bogus routing directions it's received are authentic -- is less common, it's not unheard of.

Symantec said it was unaware of any attempts to exploit the vulnerabilities.

The flawed ActiveX control is used by Symantec's AutoFix tool, which is included with some of the company's software and may also be downloaded to a PC during a live chat with a Symantec technical support representative. AutoFix diagnoses PC problems and offers up solutions.

Previously, Symantec researchers have called on the company's statistics to point out widespread problems with ActiveX. In February, for example, Oliver Friedrichs, director of the company's security response team, reported ActiveX composed 89% of all the browser plug-in vulnerabilities his team had counted in the first half of 2007.

That same month, Symantec joined with the U.S. Computer Emergency Readiness Team (US-CERT) and other security vendors to urge caution when using ActiveX controls after a wave of bugs were revealed in several other software makers' products, including those from Yahoo Inc., Facebook and MySpace.

Symantec has updated the affected consumer security software with new detection definitions designed to block any exploit of the ActiveX flaws, but will not automatically patch everyone's copy of the flawed control.

"An updated (non-vulnerable) version of the AutoFix tool will be automatically installed if customers participate in an online Chat session with Symantec Technical Support," Symantec said. Alternately, users can manually download and install a patched AutoFix from its Web site.

Friday, January 4, 2008

Ransomware Extorts Payment with Phone Call

New "ransomware" that locks up your PC and demands $35 to return control to you is on the prowl, a security researcher said this week.


'Ransomware' Extorts Payment With Phone Call

New "ransomware" that locks up a person's PC and demands US$35 to return control to its user is on the prowl, a security researcher said this week.

The extortionists tell victims of the Delf.ctk Trojan horse to dial a 900 number, said Alex Eckelberry, CEO of Sunbelt Software Distribution Inc., a Clearwater, Fla.-based security developer. That number can be traced to "passwordtwoenter.com," a payment processor also used by hardcore pornography Web sites to charge for access to their content, added Eckelberry.

Users infected with the Trojan horse see a full-screen message posing as an error generated by Windows, according to screenshots posted by Eckelberry on the Sunbelt company blog on Monday. "ERROR: Browser Security and Antiadware [sic] Software component license exprited [sic]," the message reads. "Surfing PORN, ADULT and some other kind of sites you like without this software is dangerous and threatens with infection of your computer by harmful viruses, adware, spyware, etc."

The bogus update window includes a "Click to activate new license" button that in turn brings up another screen, this one telling U.S. users to dial a 900 telephone number and enter a personal identification number (PIN). If the 900 number doesn't work, the page instructs users to dial alternate numbers -- one in the West African nation of Cameroon, the other a satellite telephone number.

"You're completely locked out of the system" after the Delf.ctk Trojan horse installs and runs, said Eckelberry. The only way to regain control is to pay up by dialing.

A search on Google for the 900 number returns results pointing to passwordtwoenter.com, a Web site registered to Global Voice SA, a company based in the Republic of Seychelles, an island nation in the Indian Ocean. The IP address used by passwordtwoenter.com is shared with similar domains, including "pintoenter.com" and "chargemyphonebill.com," which are also registered to Global Voice.

Global Voice did not respond to e-mail sent to the address listed in the domain registration information for passwordtwoenter.com.

Ransomware, a term used to describe malware that tries to extort money from users after an infection -- usually to return access to suddenly-encrypted files -- is rare, but not unknown. The last outbreak of any note was in July 2007, when another Trojan horse, dubbed "GpCode," demanded $300 to unlocked frozen files.

source: www.computerworld.com

Tuesday, November 20, 2007

Mozilla Releases Firefox 3.0 Beta

Close to 15,000 developers have been testing the 'alpha' version of Firefox 3.0, and today, Mozilla has released the first beta version. The release of the beta is tad delayed than originally expected, but from the early looks of the Firefox 3 beta 1 browser it was worth the wait


Firefox 3 Adds More Security

Mozilla has released a beta version of Firefox 3.0 today, and said they one-step closer into releasing their next-generation web browser to the public.

Close to 15,000 developers have been testing the early 'alpha' versions of Firefox code for several months now, but the first beta release of the code should open up the software to a broader public.

"The move from alpha to beta typically means that we've hit a point of quality where we believe the browser is useable as a daily browser," said Mike Schroepfer, Mozilla's vice president of engineering. "For us, it's a step up in terms of getting closer toward the final release." Schroepfer expects a second beta to follow by year's end followed by a final beta 3 update in early 2008.

One of the big changes with Firefox 3.0 is an overhaul of the way the browser bookmarks and keeps track of browsing history. With this new feature, called Places, browsing history will now be stored in a database, meaning that it will be much easier for Firefox users to search for sites they've visited. "Because of the new Places infrastructure we're able to store a much larger component of your history," Schroepfer said.

Another addition is the browser's ability to search what is being typed into the address bar to see it it's relevant to your browsing history.

Security has also taken a front seat with Firefox 3.0. The browser is now integrated with Google's database of known malicious Web sites and will warn users before they visit sites that are considered to be dangerous.

The Download Manager works better with antivirus software, giving users extra security by spotting malicious files before they are placed on the computer. Also, Firefox will no longer permit add-ons to be downloaded from insecure sites.

A lot of the work has been done under the hood. Firefox has a new overhauled HTML rendering engine, known as Gecko 1.9. They promised that the new engine will perform better in the graphically rich Web 2.0 world, where developers are trying to find new ways of running software whether the PC is connected to the Internet or not. "You won't see those as a user right away," Schroepfer said. "But you'll see Web applications do more interesting things and run more quickly in Firefox over time."

Don't use Firefox with Yahoo! Mail and Gmail yet - errors occur on some website that heavily depend on Ajax technology. There is no planned release date for Firefox 3.0 final release. The release of the beta is tad delayed than originally expected, but from the early looks of the Firefox 3 beta 1 browser it was worth the wait.