IT
Security Bulletin - October 2004
JPEG Vulnerability
=============
The exploit code for the vulnerability described in MS04-028 has been
available for a few days now, and it is likely that more prolific attacks
are being designed. Please ensure that vulnerable computers are patched.
Attempts to compromise vulnerable computers have been seen using
America On-line's instant messaging program:
http://www.zdnet.com.au/news/security/0,2000061744,39161347,00.htm
McAfee antivirus with signature files 4395 and later are available
and can
handle this exploit:
http://vil.nai.com/vil/content/v_128461.htm
The bulletin from Microsoft on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx
E-crime Watch Survey
================
The research was conducted to unearth e-crime fighting trends and
techniques, including best practices and emerging trends. The
document is available at:
http://www.cert.org/archive/pdf/2004eCrimeWatchSummary.pdf
"Sender ID" Antispam Shelved
======================
Intellectual property and patent issues raise by Microsoft have resulted
in
withdrawal of support toward making Sender ID an Antispam standard.
http://news.com.com/Microsoft-backed+antispam+spec+gets+filtered+out/2100-1032_3-5380029.html
Networked Photocopiers
==================
Could attackers be viewing what you are photocopying?
http://news.zdnet.co.uk/communications/networks/0,39020345,39167848,00.htm
New Apache HTTP Server Released
==========================
Apache has released version 2.0.52, which has been described as
"principally a bug fix release". More information is available
at:
http://www.apache.org/dist/httpd/Announcement2.html
|