Internet Security
Virus News and Alerts
Viruses, they're out there, lurking in the shadows of cyber space just waiting for the perfect moment to invade and infect your machine. Keep up to date on the latest threats, fixes, and preventive measures.
Email Hoax Alerts
Everyone gets them - everyone hates them - those annoying mass forwarded chain emails, and last but not least, those pesky little SPAM hoaxes. The problem now is, how do we differentiate between what is legitimate and what is a hoax. Find out what you need to be on the look out for.
Forwarding Emails
This is a huge, HUGE, big bad no-no, especially in business! We're talking about those emails that have been forwarded to a zillioin-million people and now, poor you, you're one of them. As well intentioned as some of these may seem to be - they are mostly an annoyance, but more importantly, they place your personal or business email address in the hands of SPAMMERS, listers and smart-alecky blankety-blanks who issue emails with viruses attached.
If you receive something in your email that you think is worth sending on, then by all means do this, but do it by copying the fun stuff and then pasting it into your outgoing email.
For some irreverent fun about forwarded emails, watch this creative little gem we found on the Internet!
What to Do About Email Harassment and Scams
Spam, we all get it, but what if the unwanted emails you received were a step beyond Spam and were either threatening or an attempt to thieve you of your identity? How would you be able to report this abuse? The answer to that question is slightly easier than you think.
Canning the SPAM
Each day both inboxes and arteries alike are clogged by this vile substance. So where did this mystery meat of the inbox come from, how did it get distributed to your inbox? Find out.
Keeping Your Kids Safe on the Internet
Did you know that 80 percent of children who use email receive inappropriate, adult oriented SPAM? Did you know that 50 percent of children view the contents of the web without parental guidance? Do you know what your children are doing on the internet? You should. Find out what potential threats children face on the internet and what you can do to keep your children safe on the internet.
Government Information on Internet Security
The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
- Apple Releases iTunes 10
Apple has released iTunes 10 to address multiple vulnerabilities affecting the WebKit package. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
US-CERT encourages users and administrators to review Apple article HT4328 and apply any necessary updates to help mitigate the risks.
- Google Releases Chrome 6.0.472.53
Google has released Chrome 6.0.472.53 for Linux, Mac, and Windows to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information, or conduct spoofing attacks.
US-CERT encourages users and administrators to review the Google Chrome Releases blog entry and apply any necessary updates to help mitigate the risks.
- Insecure Loading of Dynamic Link Libraries in Windows Applications
US-CERT is aware of a class of vulnerabilities related to how some Windows applications may load external dynamic link libraries (DLLs). When an application loads a DLL without specifying a fully qualified path name, Windows will attempt to locate the DLL by searching a defined set of directories. If an application does not securely load DLL files, an attacker may be able to cause the affected application to load an arbitrary library.
By convincing a user to open a file from a location that is under an attacker's control, such as a USB drive or network share, a remote attacker may be able to exploit this vulnerability. Exploitation of this vulnerability may result in the execution of arbitrary code.
Additional information regarding this vulnerability can be found in US-CERT Vulnerability Note VU#707943. US-CERT encourages users and administrators to review the vulnerability note and consider implementing the following workarounds until fixes are released by affected vendors
- disable loading libraries from WebDAV and remote network shares
- disable the WebClient service
- block outgoing SMB traffic
Update: Microsoft has released
Fix it tool 50522 to assist users in setting the registry key value
introduced with Microsoft support article 2264107 to help reduce the risks posed by the DLL loading behavior described in VU#707943. Users and administrators are encouraged to review Microsoft support article 2264107, the Microsoft Security Research & Defense TechNet blog entry,
and to consider using the Fix it tool to help reduce the risks. Users
should be aware that setting the registry key value as described in the
support article or via the Fix it tool may reduce the functionality of
some third-party applications.
US-CERT will provide updates when additional details become available.
- VMware Releases Updates for ESX Service Console Packages
VMware has released security updates for multiple third party packages for the ESX Service Console. These updates address vulnerabilities in the perl, krb5, samba, tar, and cpio packages. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or bypass security restrictions.
US-CERT encourages users and administrators to review VMware security advisory VMSA-2010-0013 and apply any necessary updates to help mitigate the risks.
- Cisco Releases Security Advisory for IOS XR Software Border Gateway Protocol
Cisco has released a security advisory to address a vulnerability in the Cisco IOS XR Software Border Gateway Protocol feature. Exploitation of this vulnerability may result in the continuous resetting of BGP peering sessions, which may cause a denial-of-service condition for affected networks.
US-CERT encourages users and administrators to review Cisco security advisory cisco-sa-20100827-bgp and apply any necessary updates to help mitigate the risks.
|