quinta-feira, 10 de setembro de 2009

Saiu o primeiro pacote de correções do Snow Leopard

De: Apple Product Security <product-security-noreply@lists.apple.com>
Data: 10 de setembro de 2009 17h46min30s GMT-03:00
Assunto: APPLE-SA-2009-09-10-1 Mac OS X v10.6.1

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

APPLE-SA-2009-09-10-1 Mac OS X v10.6.1

Mac OS X v10.6.1 is now available and addresses the following:

Flash Player plug-in
CVE-ID:  CVE-2009-1862, CVE-2009-1863, CVE-2009-1864, CVE-2009-1865,
CVE-2009-1866, CVE-2009-1867, CVE-2009-1868, CVE-2009-1869,
CVE-2009-1870
Available for:  Mac OS X v10.6, Mac OS X Server v10.6
Impact:  Multiple vulnerabilities in Adobe Flash Player plug-in
Description:  Multiple issues exist in the Adobe Flash Player plug-
in, the most serious of which may lead to arbitrary code execution
when viewing a maliciously crafted web site. The issues are addressed
by updating the Flash Player plug-in to version 10.0.32.18. Further
information is available via the Adobe web site at
http://www.adobe.com/support/security/bulletins/apsb09-10.html


Mac OS X v10.6.1 may be obtained from the Software Update
pane in System Preferences, or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/

For Mac OS X v10.6
The download file is named: MacOSXUpd10.6.1.dmg
Its SHA-1 digest is: 2e0c303e0078a488702172d782cb1b882eef543

For Mac OS X Server v10.6
The download file is named: MacOSXServerUpd10.6.1.dmg
Its SHA-1 digest is: 736474bbfc70244c1ff951621fa484ccdfcaf3c7

Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (Darwin)

iQEcBAEBAgAGBQJKqV+gAAoJEHkodeiKZIkBux8H/3wrRgCPvoFJrSMN4u8SqzPd
jN4HyUwhPFuU/ueL3ZngtVmNjEgkw/+mlP4ARwAcogA2f6F+U4Rx0mEXE07fd/5Z
1Ghw+3P/mf0NNEFuFGBjoLNrUIcTORT0tWIZjo/OFZK07C8YtSfmZDcnXAXSskKh
uuxGZhoXFNA29K65KoPQw7O2Pbdj7s2WSos92tWof4j+NNIq9XsryTzLi/attiwz
R9m5WJ0mUf2Bc7u4o+Ka5FEK7Hp1GtypEoi/fa46iwArAvUKJwe8bWwO9c/Kr2Po
0zJmZ+fwHYq5dtIKbNBD586U44sP7DLal9O6Big0np2CCWcOTjR6cczdYes4UhU=
=su8u
-----END PGP SIGNATURE-----
_______________________________________________

TSE oferece urnas a hackers para testar segurança

16h33 - 10/09/2009

TSE oferece urnas a hackers para testar segurança

 

O Tribunal Superior Eleitoral fará amanhã (11.set.2009) uma audiência pública para testar a segurança das urnas eletrônicas usadas em eleições no Brasil. Segundo informação divulgada hoje, a ideia é fazer um teste de stress nos equipamentos e nos softwares usados, permitindo aos participantes atuarem como verdadeiros hackers –demonstrando se há ou não segurança no modelo brasileiro.

 

Só poderá participar quem se inscrever antecipadamente. Quem tiver interesse, precisa enviar um e-mail para testeseguranca@tse.gov.br e aguardar instruções. Mas, atenção: O prazo para inscrições se encerrahoje, às 18h.

 

Aqui, a íntegra do edital convocando para a audiência de amanhã. No post abaixo, o comunicado do TSE.

 

Trata-se de uma iniciativa positiva do TSE. Há sempre muitas dúvidas sobre a segurança completa das urnas brasileiras. Volta e meia alguém no Congresso reclama que falta transparência e propõe a volta de algum tipo de voto impresso.

 

O problema da recontagem, por exemplo, é algo aparentemente insolúvel. Como se trata de um arquivo digital, não há propriamente recontagem dos votos digitados em uma urna. Quando há um erro de programa, a possibilidade de recontagem inexiste. Essa é uma das razões pelas quais países como os Estados Unidos relutam em adotar urnas eletrônicas de maneira generalizada.

 

E que tal seguir o blog no TwitterAqui, depois clique em "follow" 

 

Por Fernando Rodrigues

Novo roubo de segredos na DuPont?

DuPont Alleges Second Insider Breach In Two Years
Chemical giant claims former employee was headed to China with company secrets

Set 09, 2009 | 05:47 PM

By Tim Wilson
DarkReading

Just two years after discovering an insider breach that might have cost it $400 million, DuPont is alleging theft of trade secrets by another one of its employees

According to an article in DuPont's home state of Delaware, DuPont has filed a lawsuit against -- and fired -- a Chinese-born employee who was allegedly about to leave Delaware and return to China with company trade secrets.

The suit, filed in late August in the Delaware Court of Chancery, accuses Hong Meng of breach of contract and misappropriation of trade secrets -- specifically, research into a paper-thin computer display technology called an "organic light-emitting diode," or OLED.

The suit alleges Meng was planning to take the proprietary information to his alma mater, Peking University in Beijing, which is involved in research on OLED technology, the report says.

DuPont issued a brief statement Friday, indicating Meng, a Chinese national with permanent residency status in the United States, was fired after an internal investigation, and the lawsuit was filed "to ensure that he not use or disclose DuPont trade secrets," according to the report.

"As a science company, DuPont acts to protect our unique and confidential technologies," the statement said. "These events underscore our unwavering commitment to protect the integrity of our proprietary science and technology for the benefit of DuPont shareholders, employees and customers."

DuPont says it spotted Meng's actions when it reviewed his hard drive prior to transferring him to China. Meng had downloaded a number of proprietary files about the OLED, the company alleges.

The chemical giant faced a similar problem two years ago, when former employee Gary Min was found to be in possession of thousands of files relating to the company's trade secrets. The estimated value of the information was assessed at around $400 million.

In that case, Min -- who also has ties to China -- downloaded thousands of documents without authorization from company systems. He also made paper copies of thousands more documents and stored them in an apartment he had rented for that purpose.

Min received a sentence of 18 months in jail and a $30,000 fine.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


sábado, 16 de maio de 2009

GFI fornece scanner free!

A GFI (www.gfi.com), empresa de soluções de segurança, dentro da iniciativa "We Care" (http://www.gfi.com/wecare/), disponibilizou dois de seus produtos em versões gratuitas.
 
O primeiro é o aclamado GFI Languard (www.gfi.com/lannetscan), para verificação de vulnerabilidades em servidores. A versão gratuita é para 5 IPs.
 
O outro é o GFI Backup Home Edition (www.gfi.com/backup-hm/), para backup e recuperação.
 
Vale à pena conferir, e usar!
 

sábado, 25 de abril de 2009

CISA - Best Certification Program - SC Magazine Awards 2009

A certificação CISA (Certified Information Systems Auditor) foi a vencedora do prêmio Best Professional Certification Program da SC Magazine Awards 2009.

Saiba mais detalhes aqui e aqui.

terça-feira, 21 de abril de 2009

NIST Released Draft SP 800-118

DRAFT SP 800-118 Guide to Enterprise Password Management

 

NIST announces that Draft Special Publication (SP) 800-118, Guide to Enterprise Password Management, has been released for public comment. SP 800-118 is intended to help organizations understand and mitigate common threats against their character-based passwords. The guide focuses on topics such as defining password policy requirements and selecting centralized and local password management solutions.

 

NIST requests comments on draft SP 800-118 by May 29, 2009. Please submit comments to 800-118comments@nist.gov with "Comments SP 800-118" in the subject line.

 

Drafts page URL for 800-118:

http://csrc.nist.gov/publications/PubsDrafts.html#800-118

 

 

-


quinta-feira, 16 de abril de 2009

O helicóptero de Obama tinha um cliente P2P com ligação direta com o Irã


marine-one

Uma empresa norte-americana, de nome Tiversa, especializada em segurança de informática, encontrou os detalhes dos sistemas de comunicação e de engenharia do "Marine One", ou seja, o helicóptero presidencial usado por Barack Obama, num computador em Teerã ligado a uma rede P2P.
A informação que estaria replicada para este cliente P2P iraniano continha, além dos já citados, detalhes dos sistemas de engenharia e de comunicações do helicóptero, informações sobre as atualizações de engenharia programadas, dados sobre a rede do helicóptero e vários planos do aparelho.

Ora se toda esta informação estava numa rede P2P, então é porque um cliente P2P estaria também instalado no helicóptero, parece que instalado por um outsourcing trabalhando para o Departamento de Defesa e que teria usado ou o LimeShare ou o BearShare num portátil que ligou na rede local do helicóptero.

Segundo a Tiversa, ainda que a instalação do cliente P2P no helicóptero possa ter sido não intencional, o fato destes dados terem aparecido em Teerã pode não o ser, já que se sabe que os iranianos estão particularmente atentos a informação que apareça nestas redes e que lhe possa ser útil.

O incidente, além de aumentar o risco de segurança para o Presidente dos EUA, expõe também o erro que é o de entregar a manutenção de meios tão sensíveis como este a empresas de outsourcing, que não têm regulamentos e implementações de segurança tão exigentes como os dos meios militares ou das forças de segurança. Isto não quer dizer que este tipo de programas não apareça instalado em computadores militares, já que a própria Tiversa admite que isso aconteceu diversas vezes na última guerra do Iraque e que o que existe, além de outsourcings relaxados, inconscientes e com uso exagerado, é também uma fraca cultura de segurança, ausente no sempre mais inseguro e exposto (porque mais usado) sistema Windows e utilizando (ou não) Group Policies relaxadas ou incorretamente implementadas.

FONTE
: http://topnews.us / COLABOROU: Edilson Moura

quinta-feira, 9 de abril de 2009

Microsoft Security Intelligence Report v6

A Microsft liberou a última versão de seu Security Intelligence Report (SIRv6), com análises de vulnerabilidades em softwares próprios e de terceiros. 


O documento pode ser baixado em www.microsoft.com/sir

sábado, 21 de março de 2009

New CS Anti-Virus based on ClamAV/ClamWin engine

Interessante, novo projeto baseado no ClamAV, agora para Windows.
 
Aguns detalhes (em inglês):

Include a Window service (CSAntivirus.exe) that perform all scans through the libclamav.dll, the control executable for
desktop interaction (CSAVTray.exe) and a small tool for generate new virus signatures (CSigTool.exe).
 
The project is developed in Visual Basic 6.0 and Visual C++ 6.0 (The C++ ATL CSAVCoreEngine.dll is a proxy for libclamav.dll). The project is "not yet stable".
 
This build is only 0.1.2 and is Beta. Anyhow the system is already usable on all NT based Windows Server and Client O.S. (from Windows 2000 to Windows 7) Tested on 2000/XP/Vista.

Follow a list of features:

Freeware, usable on server and client O.S., desktop interaction on system login (application on try bar), use of ClamAV engine and ClamAV virus database (main.cvd and daily.cvd), resident shield (File Guard) at the  moment only for one HD (or one root path), memory/process scan (on idle), File/Path scan, daily and weekly schedule scans, daily update, manual update, events log, event notify, virus log, quarantine (not yet complete), user-define signature creation tool, GUI for engine control, service control, program settings, notify, etc...

There are still many bugs (obviously), but the entire system is already usable.

On the follow link there are others information and the setup file:

http://www.creasoftware.net/prodotto.asp?id=16

sexta-feira, 20 de março de 2009

NIST Announces the Release of Draft Special Publication 800-16 Revision 1

> NIST announces the release of the Initial Public Draft (IPD) of
> Special Publication 800-16, Revision 1, Information Security
> Training Requirements: A Role- and Performance-Based Model. This
> publication is now available for public comment.
>
> The comprehensive training methodology provided in this publication
> is intended to be used by federal information security professionals
> and instructional design specialists to design (1) role-based
> training courses or modules for personnel who have been identified
> as having significant responsibilities for information security, and
> (2) a basics and literacy course for all users of information systems.
>
> We encourage readers to pay special attention to the Notes to
> Reviewers section, as we are looking for feedback on the many
> changes we have made to this document.
>
> Comments will be accepted until June 26, 2009. Comments should be
> forwarded via email to 800-16comments@nist.gov.
>
> URL to Draft SP 800-16 Rev. 1:
> http://csrc.nist.gov/publications/PubsDrafts.html#800-16-rev1
>
>
> Quick update - in the email sent to list on March 3, the NIST IR
> 7536 2008 Computer Security Division Annual Report was released. We
> have updated the PDF file for this document. We now have a final
> layout version available which includes charts, graphics, etc. The
> text inside this report did not change. For those interested in
> viewing the final printed version can find the updated PDF file here:
>
> It is a PDF file and depending on your Internet speed, it may take a
> couple extra seconds to load - PDF file is about 3.9 MB.
> http://csrc.nist.gov/publications/nistir/ir7536/NISTIR-7536_2008-CSD-Annual-Report.pdf
>