ecunia Advisory: SA27063  
Release Date: 2007-10-05

Moderately critical
Impact: Manipulation of data

女人國女性購物社群入口網站被植入惡意連結,此惡意程式為 TROJ_DLOADER.PMG,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒。

詳情按此 rogerspeaking.blogspot.com/2007/10/blog-post_8806.html

創意先進有限公司(HOT)網站被植入惡意連結,此惡意程式為 PWS-Lineage,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒 (此惡意程式會竊取帳號與密碼)。

詳情按此 rogerspeaking.blogspot.com/2007/10/hot.html

詳情按此 rogerspeaking.blogspot.com/2007/10/blog-post_04.html

僑光技術學院網站被植入惡意連結,此惡意程式為 TROJ_DELF.HYF,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒。(Credit: Jimau)

詳情按此 rogerspeaking.blogspot.com/2007/10/blog-post.html

  在2007年上半年,微軟是最易被攻擊的,被攻擊次數最多,Apple第二位,Oracle第三。IBM的Internet Security Systems' X-Force R&D部門在當地時間9月17日公佈了這份全球攻擊報告。具體數字如下:

    EP_X0FF是著名的俄羅斯黑客,曾開發過Rootkit Unhooker,Process walker等國際領先的反ROOTKIT軟件,並擔任微軟SysInternals技術論壇的Malware(惡意軟件)版版主。

ウェブベースのシステム管理ツールである Webmin には、許可されていない Webmin ユーザが OS コマンドを実行できる脆弱性があります。


Windows 版 Webmin 1.360 およびそれ以前

Malware writers in September were sending out waves of spam in an attempt to infect computers with the Pushdo Trojan horse by offering pictures of naked female celebrities.

By Sharon Gaudin

he new book “Securing VoIP Networks,” the vulnerable side of VoIP

By Ellen Messmer, Network World, 10/01/07

A report this week on CNN that showed how a software vulnerability in a control system could be used to physically destroy power grid equipment refocused attention on an issue that some have been quietly trying to fix for several years.

The CNN segment, which aired Thursday, showed a turbine being reduced to a smoking, shuddering, metal spewing mess as the result of malicious code execution on the computer controlling the system.

he secure coding movement got a little boost today as CERT and Fortify Software announced that they have teamed up to automate part of the process of building security into software -- specifically, automating compliance with CERT's C and C++ Secure Coding Standard.

CERT is translating its guidelines into a coding format that will run on Fortify's Source Code Analysis tool. The resulting software module will be available for free from CERT, so other tool vendors can convert it to their products, and organizations that do in-house testing can use it with their tools as well.

One of the difficulties with spy tool applications is that even if they are legitimately used – the application vendor still has the problem of properly handling confidential data.

Case in point: Mobile-Spy for Windows Mobile.

BOSTON - A few weeks ago Candace Locklear's office computer quietly started sending out dozens of instant messages with photos attached that were infected with malicious software.

She was sitting at her desk, with no sign that the messaging software was active. By the time she figured out what was going on, several friends and colleagues had opened the attachments and infected their computers.

October 1, 2007
By Brian Prince

October 1, 2007
By  Larry Seltzer
For weeks now I've been thinking on and off about "deperimeterization," a term that has been used in a variety of ways for years. Some analyst talk got it in the news recently.

October 1, 2007
By  Evan Schuman

