December 2003
Welcome to December's edition of Internet Security News, the monthly risks bulletin detailing the latest Internet software and system vulnerabilities from NTA Monitor, a leading IT security testing company. It provides a convenient way to keep up to date with the fast changing world of IT security; this month's edition includes a total of 11 risk issues: 7 Medium, 1 Low and 3 Informational .
Well that buffer overflow didn't take long to spread
(Medium risk) Sun On November 11th 2003, Microsoft released a security bulletin indicating that the Workstation service of Windows 2000 and Windows XP was vulnerable to exploits. However at that point the exploit code was not in general circulation. It now appears though that this may not be the case. 30th December 2003 Read MoreCredit Card Fraud Focus
(Medium risk) Card-not-present fraud has jumped 33% to £110 million since 2001 and online fraud has risen 81% to £28 million. The Association for Payment Clearing Services (Apacs) has blamed customer carelessness rather than the Internet for this rise. Visit the NTA web site for a selection tips to help readers keep their credit card details more secure, and for retailers to help cut fraud through their sites. 30th December 2003 Read MoreEmail? No thanks. I get enough Spam already...
(Informational) According to new research published this month, it appears that people are starting to turn their backs on using email due to the spam plague that is affecting us all. 30th December 2003 Read MoreNasty flea bugs Windows users
(Low risk) A new worm is performing its rounds on the Internet at present, bringing yet more misery to Windows users. The Visual Basic Script (VBS) worm disguises itself as the 'signature file' in any infected HTML-formatted mail. 30th December 2003 Read MoreLet's overflow FrontPage server's buffer shall we?
(Medium risk) Microsoft have released further information and patch updates for its FrontPage Server Extensions product that could allow attacks to execute arbitrary code. 30th December 2003 Read MoreUsers or manufactures? Gates believes that users are to blame
(Informational) Microsoft CEO blames users for all security issues with regards to software security issues. 30th December 2003 Read MoreGone are the days of market share, now it's your security
(Informational) Microsoft believes that it is superior when it comes to security over the OpenSource operating system Linux. A new battle is to ensue between the two. 30th December 2003 Read MoreOne, Two, Three, Four ... MS patches are knocking at your door
(Medium risk) It's that time of the month again when Microsoft does a bulk release of patches to users of its Microsoft Windows platform and associated software. This time round it's the turn of Internet Explorer, Microsoft Word and Microsoft FrontPage Server. 30th December 2003 Read MoreInjecting code as root using Sendmail? Surely not?
(Medium risk) CERT have recently announced that a bug in all open-source versions of Sendmail prior to 8.12.10 are currently vulnerable to attackers injecting and executing spurious code with the same privileges as the Sendmail daemon which is typically root. 30th December 2003 Read MoreMore woes for Windows users ... it's sober this time
(Medium risk) A virus, which poses itself as an email from an AV firm, is yet another nuisance for Windows users around the world. 30th December 2003 Read MoreWant to rampage a corporation? Just use a ZIP file then...
(Medium risk) A NEW variant of the MiMail worm family, version C, is proliferating across the world, according to security firm iDefense. 30th December 2003 Read MoreAbout NTA Monitor
This bulletin is produced as a by-product of ongoing research carried out to develop NTA Monitor's Internet security testing service, Regular Monitor. NTA are a full-service Internet security testing company with a comprehensive range of testing services including:
- VPN Testing
- Onsite Auditing
- Web Application Test
- War Dialling
- Wireless Infrastructure Testing
- RM Vulnerability Testing
For more information on the above services please see our services page.