CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / august, 2004 / Weekly Report 

Weekly Report

Weekly Report

Madrid, July 31 2004 - Over the last five days, Oxygen3 24h-365d has covered the following news stories -summarized below- and which can be read in full at: http://www.pandasoftware.com/about/press/oxygen3/oxygen.asp

- Denial of service in Microsoft SMS client (07/26/04). Securiteam has reported a vulnerability in SMS Remote Control that could allow denial of service attacks. This service listens on ports TCP 2701 and 2702 and carries out signature checks and size tests on the data received, and assumes the data is correct if those controls are passed. It is possible, however, to create a data packet that will go through basic checks and throw an exception by causing the server to read or write to an invalid memory address.

- Leading search engines affected by Mydoom.N worm (07/27/04). The new Mydoom.N worm has caused critical problems in some search engines including Google, Altavista, Lycos and Yahoo!. Many users have had error messages returned when trying to use the engines. This is down to the fact that Mydoom.N runs searches through Lycos, Altavista, Yahoo and Google for all the addresses it has stolen from infected computers, flooding the search engines with requests and preventing them from operating normally.

- Mydoom.N consequence: Zindos.A (07/28/04). A new worm, Zindos.A has appeared, exploiting the backdoor created by Mydoom.N in the computers it affects. Zindos.A searches IP adresses to see if this port is open, and if it is, it infects the computer. If the computer is connected to the Internet, Zindos.A launches a denial of service attack (DoS) against Microsoft´s website.

- Buffer overflow in Check Point VPN-1/FW-1 (07/29/04). Check Point has confirmed the existence of a vulnerability in Check Point VPN-1 in the treatment of IKE packets with ASN.1 encoded content. A remote user could exploit this vulnerability in order to take control of affected systems.

- Microsoft WSE 2.0 SP1 now available (07/30/04). Microsoft has announced the availability of Web Services Enhancements 2.0 SP1, an update to the utility suite aimed at helping Microsoft Visual Studio .NET and Microsoft .NET Framework developers create secure web services. With respect to the previous version, Service Pack 1 includes numerous changes and improvements to the product kernel, some modifications and additions to the intergration with Visual Studio, RFC3280 support for X.509 certificates, and new features in the WseWsdl2 tool.

 

 

Oxygen3 24h-365d, by Panda Software
© Panda Software 2003

 

 

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel