The Wayback Machine - https://web.archive.org/web/20080211133724/http://blogs.zdnet.com:80/security/
Larry Dignan & George Ou
zdsecurity image
Tracking the hackers
February 8th, 2008

Why is security usually an afterthought?

Posted by Larry Dignan @ 5:17 am Categories: Patch Watch, Hackers, Vulnerability research, Punditocracy, Responsible disclosure, Exploit code Tags: Software, Security, Vulnerability, Explanation, It, Larry Dignan

You can stumble onto an ActiveX vulnerability with a little help from Google and a 5 minute tutorial on fuzzing. When you ask and technology executive about potential security issues with virtualization you get a blank stare. And we’re stuck on this patch-go-round that never ends.

All of these issues are side effects of one illness: The software industry and the customers that implement applications rarely think about security first. You see it with Web 2.0 apps, shoddy browsers and the huge patches (basically code rewrites) that plug holes in some of the more favorite Web software (IE, Skype, QuickTime etcetera). Does it strike anyone as odd that we were hit by patches for four major vulnerabilities in 24 hours this week?

Here are the priorities among software developers:

  • Cook up applications quickly;
  • Gain massive distribution;
  • Get people to install it;
  • Monetize it.

Among customers the priorities go something like this:

  • Save money;
  • Ease of use;
  • Ease of installation;
  • Enable the business somehow (and save more money).

In this state of affairs little things like security is bolted on once these applications are widely adopted. Does that make sense?

Why should we need an attack on (pick your hot software of the moment) to think about security and all of the processes that enable it? The only explanation is that developers and software companies are lazy and know there’s no immediate return. It’s a far easier business model to turn out crappy software and then sell us stuff to fix it. Bizarre.

Simply put, security would be a lot better if companies gave just a smidge of forethought to vulnerabilities. Sure there are a few bright spots–I thought MySpace’s move to put its third party apps through some security testing before unleashing them to users was a great idea. But far too often I’m wondering why security isn’t at least thought about a bit before we move on to the latest and greatest thing.

Thoughts?

February 7th, 2008

Mozilla delivers patches for Firefox; Plugs flat file vulnerability

Posted by Larry Dignan @ 9:26 pm Categories: Patch Watch, Vulnerability research, Exploit code, Viruses and Worms, Open source, Mozilla, Firefox Tags: Mozilla Firefox, Vulnerability, Web Browser, Mozilla Corp., MFSA, Memory Corruption, Web Browsers, Security, Internet, Larry Dignan

Mozilla on Friday delivered its Firefox 2.0.0.12 update including patches that fix a Web forgery flaw, browsing history and forward navigation stealing and the directory traversal via chrome, which has been the most visible vulnerability of late.

According to the Firefox security advisory, Mozilla filed the following fixes in its flagship browser:

The most notable of the bunch is MFSA 2008-05. This fix covered that vulnerability that allowed an attacker to run off with stored cookies and other data contained in flat files. The vulnerability was discovered by researcher Gerry Eisenhaur. On Jan. 29, Mozilla security chief Window Snyder upgraded the vulnerability and set plans for Firefox 2.0.0.12. On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by Eisenhaur on Jan. 19.

Regarding the flat file flaw Mozilla said:

URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used “flat” packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.

Mozilla researcher moz_bug_r_a4 reported that this vulnerability could be used to steal the contents of the browser’s sessionstore.js file, which contains session cookie data and information about currently open web pages.

mozilla.png

Another critical flaw (MFSA-2008-06) was one that allowed the stealing of Web browsing and forward navigation stealing. Mozilla noted:

Mozilla contributor David Bloom reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes designMode frames. The reported issue can be used to steal a user’s navigation history, forward navigation information, and crash the user’s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.

And a third critical vulnerability (MFSA-2008-03) covered a “privilege escalation, XSS Remote Code Execution.”

Mozilla said:

Mozilla contributors moz_bug_r_a4 and Boris Zbarsky submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by moz_bug_r_a4 demonstrated that the XMLDocument.load() function can be used to inject script into another site, violating the browser’s same-origin policy.

And finally Firefox 2.0.0.12 addresses crashes due to memory corruption (MFSA-2008-01). Mozilla noted:

Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

The remaining patches covered vulnerabilities that were deemed less critical. These vulnerabilities also affected Thunderbird and SeaMonkey.

February 7th, 2008

McAfee by the numbers

Posted by Larry Dignan @ 2:00 pm Categories: Uncategorized, McAfee Tags: McAfee Inc., Earnings, Deal Breakdown, Financial Accounting, Finance, Larry Dignan

McAfee reported its fourth quarter earnings of $12.2 million, or 7 cents a share, on revenue of $356.5 million. Excluding charges, McAfee reported earnings of $75.1 million, or 46 cents a share.

Wall Street was expecting earnings of 45 cents a share, according to Thomson Financial. McAfee projected first quarter earnings of 24 cents a share to 29 cents a share. Excluding charges, McAfee is projecting 42 cents a share to 47 cents a share on revenue between $345 million to $360 million. For the year, McAfee projected revenue of $1.42 billion to $1.52 billion and earnings of $1.25 a share to $1.35 a share. Excluding items, McAfee is projecting 2008 earnings of $1.85 a share to $1.95 a share.

That outlook was in line with expectations with room to top estimates.

So what’s working for McAfee?

McAfee’s corporate business had revenue growth of 24 percent in the fourth quarter compared to a year ago. Sales were driven by the Total Protection for Endpoint and IntruShield products. Sixty percent of McAfee’s revenue comes from the enterprise. The deal breakdown is as follows:

  • 453 deals over $100,000;
  • 56 deals over $500,000;
  • 14 deals over $1 million.

The consumer business had growth of 7 percent to $141 million in the fourth quarter. McAfee said it changed its revenue model from up front payment to subscriptions.

February 7th, 2008

Microsoft previews 12 security bulletins, 7 ‘critical’; Excel fix likely en route

Posted by Larry Dignan @ 10:58 am Categories: Patch Watch, Microsoft Tags: Vulnerability, Microsoft Corp., Bulletin, Microsoft Excel, Microsoft Office, Security, Office Suites, Software, Larry Dignan

Microsoft on Thursday issued advance notice of 12 security bulletins ahead of its February batch of patches with seven critical flaws affecting Vista, Internet Explorer and Office.

The most notable patch will likely cover that Excel zero day vulnerability that surfaced last month. Since Microsoft confirmed the Excel vulnerability and issued an advisory on Jan. 16 it’s a safe bet that its patches on Feb. 12 will cover it.

In its advance notification posting, Microsoft said the seven critical bulletins all cover remote code executions vulnerabilities. These bulletins affect Windows XP and Vista, Office, Internet Explorer and Visual Basic.

Here’s a breakdown by product:

  • Microsoft’s critical bulletins address remote code execution flaws in Microsoft Office 2004 for the Mac, Microsoft Office 2000 Service Pack 3, Microsoft Word 2000 Service Pack 3 and Microsoft Office Publisher 2002. An important bulletin was issued for Microsoft Office 2003 Service Pack 2, Microsoft Word 2002 Service Pack 3, Word 2003 Service Pack 2 and Microsoft Office 2004 for the Mac.
  • Internet Explorer had a few bulletins rated critical due to remote code execution flaws. Versions affected include: IE 5.01 Service Pack (SP) 4 on Windows 2000 Service Pack 4; IE 6 SP 1 when installed on Windows 2000 SP 4; IE 6 for various flavors of XP; IE 6 for Windows Server 2003 (various flavors); IE 7 for XP, Windows Server 2003 and Vista. In a nutshell, if you have IE you’ll need these upcoming patches.
  • XP SP 2, Windows 2000 SP 4, Windows Server SP 1 and SP2, Windows Server 2003 x64 Edition (and any service pack) and Vista all had critical bulletins for remote code execution. There are also important denial of service bulletins for these versions of Windows too.
  • Visual Basic had critical bulletins for remote code execution vulnerabilities. Versions affected include: VBScript 5.6 on Windows 2000, XP and Server 2003 (various service packs.
  • Microsoft Internet Information Services 5.0, 5.1, 6.0 on Windows XP, Server 2000 and Server 2003 (including service packs) had important bulletins covering mostly elevation of privilege and remote code execution issues.
  • Active Directory on Windows 2000 SP 4, XP SP2, and Server 2003 had important to moderate bulletins for denials of service flaws.
February 7th, 2008

Secunia: Skype, Java, QuickTime, PDF patches oh my; It’s been an ugly 24 hours for Windows users

Posted by Larry Dignan @ 5:03 am Categories: Patch Watch, Hackers, Zero-day attacks, Apple, Microsoft, Vulnerability research, Viruses and Worms Tags: Apple QuickTime, Adobe PDF, Java, Patch Management, Skype Technologies S.A., Microsoft Windows, Secunia, Computer, Patches, Productivity, Larry Dignan

The last 24 hours has been a patch barrage with Sun, Adobe, Apple and Skype all issuing patches. But what’s notable is how these patches affect Windows users.

According to statistics compiled via Secunia’s PSI application the number of users that need to get patching is staggering. And these patches aren’t a big deal individually. Collectively, however, the message from the patch fest on Wednesday is clear: You can’t do basic surfing without these patches.

Some stats (with links to the patches or blog posts detailing the issue):

Currently, the Secunia PSI has been installed on 282,726 computers.

Unique installations, counting each application only once per. computer:

Adobe Reader 8.x    172,653    61.07% of all computers affected
Apple QT 7.x         133,169    47.10% of all computers affected
Sun Java 1.5.x    98,618    34.88% of all computers affected
Skype 3.x (upgrade required for patch)    57,496    20.34% of all computers affected

Bottom line: Secunia reckons that 81 percent of all computers connected to the Internet need to install at least one of these security updates.

February 7th, 2008

Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

Posted by Larry Dignan @ 4:46 am Categories: Microsoft, Vulnerability research, Spam and Phishing, Botnets Tags: CAPTCHA, Microsoft Windows Live Mail, Websense Inc., Microsoft Windows Live, Microsoft Windows, Microsoft Corp., Bot, Larry Dignan

Microsoft’s Windows Live Mail is being targeted by spammers adept at eluding CAPTCHA protection, according to Websense.

According to Websense, spammers have created bots that are capable of creating random Live Mail accounts and then using them to launch attacks. In other words, the CAPTCHA defense doesn’t work. A CAPTCHA is a program that protects websites against bots by generating tests that humans can pass but current computer allegedly programs can’t.

wbsn1.pngIn its blog, Websense says the whole bot-as-email-account process is automated. For instance, Jay’s email account to the right was created by a bot. Websense added:

Websense believes that there are three main advantages to this approach for the spammers. First, the Microsoft domain is unlikely to be blacklisted. Second, they are free to sign up. And third, it may be hard to keep track of them as there are millions of users worldwide using the service.

Here’s how the bot works:

1. The bot goes to the Live Mail registration page and fills out the form fields (just as you would do) with random data;

2. When the CAPTCHA verification comes up, the bot sends the image to its breaking service.

3. The bot gets the answer and plugs it in.

4. Now spammers add a few gazillion accounts for malicious endeavors.

5. The spam barrage ensues. Here’s an image courtesy of Websense, which features a lot more on its blog.

wbsn.png

Websense estimates that about 30 percent to 35 percent of these CAPTCHA killing attempts works. Websense has the screen shot walk through. It’s a fascinating–and totally evil–bot. Websense also reckons that these attacks could extend to other Live services including Messenger and online storage.

February 6th, 2008

Apple drops QuickTime patch

Posted by Larry Dignan @ 2:10 pm Categories: Patch Watch, Apple, Vulnerability research, Exploit code Tags: Apple QuickTime, Vulnerability, Apple Inc., QuickTime 7.4.1, Digital Music, Digital Media, Security, Personal Technology, Consumer Electronics, Larry Dignan

Apple on Wednesday dropped a patch for QuickTime to fix a arbitrary code execution vulnerability.

Relative to other recent QuickTime patches this one was small–only one vulnerability that could lead to an “unexpected application termination or arbitrary code execution” if a user visits a malicious Web site.

QuickTime 7.4.1 covers the following vulnerability (CVE-2008-0234). Here’s Apple’s description.

A heap buffer overflow exists in QuickTime’s handling of HTTP responses when RTSP tunneling is enabled. By enticing a user to visit a maliciously crafted webpage, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

This flaw has been around for about a month.

February 6th, 2008

WordPress 2.3.3. an ‘urgent security release’

Posted by Larry Dignan @ 12:51 pm Categories: Patch Watch, Vulnerability research, Exploit code Tags: Wordpress, Blogging, Security, Internet, Larry Dignan

WordPress has released version 2.3.3 to plug a flaw that would allow a specially crafted request to edit posts of other users on that blog.

In a post, WordPress noted that 2.3.3 is “an urgent security release.” You can fix the flaw without downloading the new version. WordPress says the following:

If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php.

In addition, WordPress detailed vulnerability in the WP-Forum plugin that is being exploited. WordPress advises that folks remove this plugin until a fix emerges.

This update is a bit of inside baseball, but given that WordPress powers a lot of blog platforms, including ZDNet’s, it is worth a mention.

February 6th, 2008

Adobe delivers Reader patch (very quietly)

Posted by Larry Dignan @ 12:12 pm Categories: Patch Watch, Vulnerability research, Responsible disclosure, Exploit code Tags: Adobe Systems Inc., Immunity, Security, Larry Dignan

If you got a prompt to upgrade your Adobe Reader to version 8.1.2 you’re not alone. Betcha didn’t know it’s a major security fix though.

Why? You wouldn’t know because Adobe hasn’t told anyone. The best information you’ll get is a few snippets in an Adobe Knowledge Base article. The Reader update is AWOL on Adobe’s security bulletin site. Here’s what Adobe had to say:

The Adobe Reader 8.1.2 update addresses a number of customer workflow issues and security vulnerabilities while providing more stability.

Oh really? I got this update prompt early this am and as usual I did the “remind me later” trick. I would have taken the update more seriously if I knew there was a vulnerability issue.

Ryan Naraine reports that this Adobe update on the sly plugs a vulnerability that allows rigged PDF files to launch code execution attacks. Immunity has posted a proof-of-concept exploit to boot.

In the grand scheme of things Adobe is delivering a run of the mill patch. What’s annoying is the disclosure–or lack of it. This gets to the heart of what IBM’s ISS unit was talking about this yesterday when it reported that vulnerability disclosures were down in 2007. A sign of progress? Not quite. It’s is just that people are keeping mum about vulnerabilities.

Update: Adobe has issued a statement. Here’s the full text:

On Feb. 6, Adobe made available an update to Acrobat and Adobe Reader 8.x. It updates the Windows and Mac versions of Acrobat to 8.1.2, and the Windows, Mac, Linux, and Solaris versions of Adobe Reader to 8.1.2.

In addition to addressing bug fixes and providing support for Mac OS X Leopard (up through version 10.5.1), the update includes several important security fixes, among them a few of critical severity that could be remotely exploitable.

Adobe recommends users of Acrobat and Adobe Reader 8.x install the update to protect themselves.

Adobe plans to share further information on the topic within a few days via the company’s Security Bulletins and Advisories page (http://www.adobe.com/support/security/), at which point the company has completed the process of responsible disclosure with third-party stakeholders.

February 6th, 2008

Firefox patch imminent

Posted by Larry Dignan @ 3:38 am Categories: Hackers, Browsers, Vulnerability research, Responsible disclosure, Exploit code, Viruses and Worms, Data theft, Open source, Mozilla, Firefox Tags: Mozilla Firefox, Vulnerability, Mozilla Corp., Web Browsers, Security, Internet, Larry Dignan

Mozilla said that it plans to release Firefox 2.0.0.12 Feb. 7 or Feb. 8. The release will fix a high severity vulnerability.

The vulnerability, which was given a severity rating on Jan. 29, allows an attacker to swipe cookies and other critical data that can leak out of Firefox via flat files (add-ons).

In a brief post, Mozilla said
:

Since the security of our users is of utmost importance, the release schedule for Firefox 2.0.0.12 is being pushed up as much as possible, with a current release date estimated to be February 7th or 8th.

On Jan. 29, Mozilla security chief Window Snyder said the vulnerability will be patched with Firefox 2.0.0.12, which will be pushed out “shortly.”

On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by researcher Gerry Eisenhaur on Jan. 19. Simply put, Firefox leaks information that can allow an attacker to load any javascript file on a machine. This “chrome protocol directory transveral” is in play whenever there are “flat” files–common in add ons–are installed.

advertisement

Recent Entries

Most Popular Posts

advertisement

Archives

ZDNet Blogs

Popular white papers