sábado, 25 de abril de 2009
terça-feira, 21 de abril de 2009
NIST Released Draft SP 800-118
DRAFT SP 800-118 Guide to Enterprise Password Management
NIST announces that Draft Special Publication (SP) 800-118, Guide to Enterprise Password Management, has been released for public comment. SP 800-118 is intended to help organizations understand and mitigate common threats against their character-based passwords. The guide focuses on topics such as defining password policy requirements and selecting centralized and local password management solutions.
NIST requests comments on draft SP 800-118 by May 29, 2009. Please submit comments to 800-118comments@nist.gov with "Comments SP 800-118" in the subject line.
Drafts page URL for 800-118:
http://csrc.nist.gov/publications/PubsDrafts.html#800-118
-
Postado por
Aureo Monteiro Tavares da Silva
às
15:50:00
0
comentários
quinta-feira, 16 de abril de 2009
O helicóptero de Obama tinha um cliente P2P com ligação direta com o Irã
Uma empresa norte-americana, de nome Tiversa, especializada em segurança de informática, encontrou os detalhes dos sistemas de comunicação e de engenharia do "Marine One", ou seja, o helicóptero presidencial usado por Barack Obama, num computador em Teerã ligado a uma rede P2P.
A informação que estaria replicada para este cliente P2P iraniano continha, além dos já citados, detalhes dos sistemas de engenharia e de comunicações do helicóptero, informações sobre as atualizações de engenharia programadas, dados sobre a rede do helicóptero e vários planos do aparelho.
Ora se toda esta informação estava numa rede P2P, então é porque um cliente P2P estaria também instalado no helicóptero, parece que instalado por um outsourcing trabalhando para o Departamento de Defesa e que teria usado ou o LimeShare ou o BearShare num portátil que ligou na rede local do helicóptero.
Segundo a Tiversa, ainda que a instalação do cliente P2P no helicóptero possa ter sido não intencional, o fato destes dados terem aparecido em Teerã pode não o ser, já que se sabe que os iranianos estão particularmente atentos a informação que apareça nestas redes e que lhe possa ser útil.
O incidente, além de aumentar o risco de segurança para o Presidente dos EUA, expõe também o erro que é o de entregar a manutenção de meios tão sensíveis como este a empresas de outsourcing, que não têm regulamentos e implementações de segurança tão exigentes como os dos meios militares ou das forças de segurança. Isto não quer dizer que este tipo de programas não apareça instalado em computadores militares, já que a própria Tiversa admite que isso aconteceu diversas vezes na última guerra do Iraque e que o que existe, além de outsourcings relaxados, inconscientes e com uso exagerado, é também uma fraca cultura de segurança, ausente no sempre mais inseguro e exposto (porque mais usado) sistema Windows e utilizando (ou não) Group Policies relaxadas ou incorretamente implementadas.
FONTE: http://topnews.us / COLABOROU: Edilson Moura
Postado por
Aureo Monteiro Tavares da Silva
às
07:39:00
0
comentários
quinta-feira, 9 de abril de 2009
Microsoft Security Intelligence Report v6
A Microsft liberou a última versão de seu Security Intelligence Report (SIRv6), com análises de vulnerabilidades em softwares próprios e de terceiros.
Postado por
Aureo Monteiro Tavares da Silva
às
07:08:00
0
comentários
sábado, 21 de março de 2009
New CS Anti-Virus based on ClamAV/ClamWin engine
Include a Window service (CSAntivirus.exe) that perform all scans through the libclamav.dll, the control executable for
desktop interaction (CSAVTray.exe) and a small tool for generate new virus signatures (CSigTool.exe).
Follow a list of features:
Freeware, usable on server and client O.S., desktop interaction on system login (application on try bar), use of ClamAV engine and ClamAV virus database (main.cvd and daily.cvd), resident shield (File Guard) at the moment only for one HD (or one root path), memory/process scan (on idle), File/Path scan, daily and weekly schedule scans, daily update, manual update, events log, event notify, virus log, quarantine (not yet complete), user-define signature creation tool, GUI for engine control, service control, program settings, notify, etc...
There are still many bugs (obviously), but the entire system is already usable.
On the follow link there are others information and the setup file:
http://www.creasoftware.net/prodotto.asp?id=16
Postado por
Aureo Monteiro Tavares da Silva
às
13:00:00
0
comentários
sexta-feira, 20 de março de 2009
NIST Announces the Release of Draft Special Publication 800-16 Revision 1
> NIST announces the release of the Initial Public Draft (IPD) of
> Special Publication 800-16, Revision 1, Information Security
> Training Requirements: A Role- and Performance-Based Model. This
> publication is now available for public comment.
>
> The comprehensive training methodology provided in this publication
> is intended to be used by federal information security professionals
> and instructional design specialists to design (1) role-based
> training courses or modules for personnel who have been identified
> as having significant responsibilities for information security, and
> (2) a basics and literacy course for all users of information systems.
>
> We encourage readers to pay special attention to the Notes to
> Reviewers section, as we are looking for feedback on the many
> changes we have made to this document.
>
> Comments will be accepted until June 26, 2009. Comments should be
> forwarded via email to 800-16comments@nist.gov.
>
> URL to Draft SP 800-16 Rev. 1:
> http://csrc.nist.gov/publications/PubsDrafts.html#800-16-rev1
>
>
> Quick update - in the email sent to list on March 3, the NIST IR
> 7536 2008 Computer Security Division Annual Report was released. We
> have updated the PDF file for this document. We now have a final
> layout version available which includes charts, graphics, etc. The
> text inside this report did not change. For those interested in
> viewing the final printed version can find the updated PDF file here:
>
> It is a PDF file and depending on your Internet speed, it may take a
> couple extra seconds to load - PDF file is about 3.9 MB.
> http://csrc.nist.gov/publications/nistir/ir7536/NISTIR-7536_2008-CSD-Annual-Report.pdf
>
Postado por
Aureo Monteiro Tavares da Silva
às
23:03:00
0
comentários
quarta-feira, 18 de março de 2009
Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5K
Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5K
March 18, 2009 (Computerworld) Charlie Miller, the security researcher who hacked a Mac in two minutes last year at CanSecWest's PWN2OWN contest, improved his time today by breaking into another Mac in under 10 seconds.
Miller, a principal analyst at Independent Security Evaluators LLC, walked off with a $5,000 cash prize and the MacBook he hacked.
"I can't talk about the details of the vulnerability, but it was a Mac, fully patched, with Safari, fully patched," said Miller Wednesday not long after he had won the prize. "It probably took 5 or 10 seconds." He confirmed that he had researched and written the exploit before he arrived at the challenge.
The PWN2OWN rules stated that the researcher could provide a URL that hosted his or her exploit, replicating the common hacker tactic of enticing users to malicious sites where they are infected with malware. "I gave them the link, they clicked on it, and that was it," said Miller. "I did a few things to show that I had full control of the Mac."
Two weeks ago, Miller predicted that Safari running on the Mac would be the first to fall.
PWN2OWN's sponsor, 3Com Inc.'s TippingPoint unit, paid Miller the $5,000 for the rights to the vulnerability he exploited and the exploit code he used. As it has at past challenges, it reported the vulnerability to on-site Apple representatives. "Apple has it, and they're working on it," added Miller.
According to Terri Forslof, the manager of security response at TippingPoint, another researcher later broke into a Sony laptop that was running Windows 7 by exploiting a vulnerability in Internet Explorer 8. "Safari and IE both went down," she said in an e-mail.
TippingPoint's Twitter feed added a bit more detail to Forslof's quick message: "nils just won the sony viao with a brilliant IE8 bug!"
Forslof was not immediately available to answer questions about the IE8 exploit.
TippingPoint will continue the PWN2OWN contest through Friday, and will pay $5,000 for each additional bug successfully exploited in Apple Inc.'s Safari, Microsoft Corp.'s Internet Explorer 8, Mozilla Corp.'s Firefox or Google Inc.'s Chrome. During the contest, IE8, Firefox and Chrome will be available on the Sony, while Safari and Firefox will be running on the MacBook. The researcher who exploited IE8 will, like Miller, be awarded not only the cash, but also the laptop.
"It was great," said Miller when asked how it felt to successfully defend his title. "But I was really nervous for some reason this time. Maybe it was because there were more people around. Lucky [the exploit] was idiot-proof, because if I had had to think about it, I don't know if I'd had anything."
This year's PWN2OWN also features a mobile operating system contest that will award a $10,000 cash prize for every vulnerability successfully exploited in five smartphone operating systems: Windows Mobile, Google's Android, Symbian, and the operating systems used by the iPhone and BlackBerry.
Miller said he won't enter the mobile contest. "I can't break them," said Miller, who was one of the first researchers to demonstrate an attack on the iPhone in 2007, and last year was the first to reveal a flaw in Android. "I don't have anything for the iPhone, and I don't know enough about Google."
CanSecWest, which opened Monday, runs through Friday in Vancouver, British Columbia.
Postado por
Aureo Monteiro Tavares da Silva
às
23:02:00
0
comentários
sexta-feira, 27 de fevereiro de 2009
Para configurar o Safari 4
Segue o link com os comandos para reconfigurar o Safari 4: http://swedishcampground.com/safari-4-hidden-preferences
Postado por
Aureo Monteiro Tavares da Silva
às
23:22:00
0
comentários
sexta-feira, 13 de fevereiro de 2009
Apple libera atualização de segurança
A Apple liberou uma atualização de segurança que corrige mais de 55 falhas. Faça a atualização de software ou leia mais aqui.
Postado por
Aureo Monteiro Tavares da Silva
às
06:47:00
0
comentários
segunda-feira, 26 de janeiro de 2009
INTEGO SECURITY ALERT - January 26, 2009
INTEGO SECURITY ALERT - January 26, 2009 Exploit: OSX.Trojan.iServices.B Trojan Horse Discovered: January 25, 2009 Risk: Serious Description: Intego has discovered a new variant of the iServices Trojan horse that the company discovered on January 22, 2009. This new Trojan horse, OSX.Trojan.iServices.B, like the previous version, is found in pirated software distributed via BitTorrent trackers and other sites containing links to pirated software. OSX.Trojan.iServices.B Trojan horse is found bundled with copies of Adobe Photoshop CS4 for Mac. The actual Photoshop installer is clean, but the Trojan horse is found in a crack application that serializes the program. After downloading this version of Photoshop, users will run the crack application to be able to use it. The crack application extracts an executable from its data, than installs a backdoor in /var/tmp/, a directory which is not deleted when the computer is restarted. (If the user runs the crack application again, the Trojan horse creates a new executable with a different name; these random names make it harder to ensure safe removal of the malware.) The crack application then requests an administrator password, launching the backdoor with root privileges. This copies the executable to /usr/bin/DivX, then creates a startup item in /System/Library/StartupItems/DivX. The program checks to see if it has been launched with root privileges, then saves the root hash password in the file /var/root/.DivX. It listens on a random TCP port, and answers requests such as GET / HTTP/1.0 by sending a 209-byte packet, and makes repeated connections to two IP addresses. Next, the crack application opens a disk image which is hidden in its resource folder, in a folder named .data, and proceeds to crack the Photoshop program, allowing it to be used. Intego is issuing this alert to warn Mac users not to download Photoshop CS4 installers from sites offering pirated software. (As of 6 am EST, nearly 5,000 people have downloaded this installer, according to a major BitTorrent tracker site.) Since the Trojan horse, in this case, is found merely in the crack application that is bundled with Photoshop CS4, users should avoid downloading any cracking software from sites that distribute pirated software. The risk of infection is serious, due to the number of infected users, and these users may face extremely serious consequences if their Macs are accessible to malicious users. The first version of this Trojan horse was seen downloading new code to infected computers, which were then used in a DDoS (distributed denial of service) attack on certain web sites. Since this new variant uses the same technology, and contacts the same remote servers, it is likely that it will attempt to download new code and perform such actions. Intego VirusBarrier X4 and X5 with virus definitions dated January 25, 2009 or later protect against this Trojan horse. Intego recommends that users never download and install software from untrusted sources or questionable web sites. In spite of Intego’s security alert regarding the first version of this Trojan horse, and in spite of comments on torrent trackers, people continue to download these infected torrents. The iWork 09 torrent that we warned about on January 22 has been downloaded by at least 1,000 more people since our warning. This is why we consider this Trojan horse to be a serious risk. Intego provides the widest range of software to protect users and their Macs from the dangers of the Internet. Intego's multilingual software and support repeatedly receives awards from Mac magazines, and protects more than one million users in over 60 countries. Intego has headquarters in the USA, France and Japan. We protect your world.
New Variant of Mac Trojan Horse iServices
Found in Pirated Adobe Photoshop CS4
Since the malicious software connects to a remote server over the Internet, the creator of this malware will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.
About Intego
Intego develops and sells desktop Internet security and privacy software for Macintosh.
Postado por
Aureo Monteiro Tavares da Silva
às
21:50:00
0
comentários
