Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Firefox 3.6.7 is out!!

Published: 2010-07-20
Last Updated: 2010-07-21 00:00:56 UTC
by Manuel Humberto Santander Pelaez (Version: 1)
4 comment(s)

More information at http://www.mozilla.com/en-US/firefox/3.6.7/releasenotes.

-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org

Keywords:
4 comment(s)

Lowering infocon back to green

Published: 2010-07-20
Last Updated: 2010-07-20 20:53:54 UTC
by Manuel Humberto Santander Pelaez (Version: 2)
1 comment(s)

According to the arguments presented by Handler Lenny when the Infocon level was increased, we believe that the purpose of increasing the awareness on this vulnerability has been fulfilled, so we are falling back to green level. This does not imply that the threat is over.

If we see a major attack arise using this vulnerability, we will let you know and if it is bad enough we will raise infocon again.

Update: There is an interesting article from Didier Stevens about how to mitigate LNK exploitation with software restriction policies. Read it at http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/.

-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org

1 comment(s)

Truecrypt 7.0 released

Published: 2010-07-20
Last Updated: 2010-07-20 19:25:31 UTC
by Manuel Humberto Santander Pelaez (Version: 1)
2 comment(s)

For all those who like truecrypt, version 7.0 is out there. Some of the new features are:

  • Hardware-accelerated AES
  • Now it is possible to configure TrueCrypt container on a USB flash drive to mount the drive automatically whenever you insert the USB flash drive into the USB port. This is cool.
  • Partition/device-hosted volumes can now be created on drives that use a sector size of 4096, 2048, or 1024 bytes (Windows, Linux).
  • Favorite Volumes Organizer this means that now you can organize your mounted device upon logon to system as read only or removable medium
  • The Favorites menu now contains a list of your non-system favorite volumes. When you select a volume from the list, you are asked for its password (and/or keyfiles) (unless it is cached) and if it is correct, the volume is mounted. (Windows)
     

More information at Truecrypt website.

 

-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org

Keywords: Truecrypt 70
2 comment(s)

iTunes buffer overflow vulnerability

Published: 2010-07-20
Last Updated: 2010-07-20 12:20:28 UTC
by Manuel Humberto Santander Pelaez (Version: 2)
0 comment(s)

Apple is reporting new version of iTunes (9.2.1), which address CVE-2010-1777: A buffer overflow exists in the handling of itpc: URLs, which might lead to application termination or arbitrary code execution.

More information at http://support.apple.com/kb/HT4263.

This affects version 9 of iTunes, and only on the Windows platform.

-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org

0 comment(s)

LNK vulnerability now with Metasploit module implementing the WebDAV method

Published: 2010-07-20
Last Updated: 2010-07-20 06:54:44 UTC
by Manuel Humberto Santander Pelaez (Version: 1)
0 comment(s)

More of the LNK vulnerability. Additional from our first report from Handler Joel and Infocon raising from Handler Lenny, there is now a Metasploit module that implements the exploit with the WebDAV method.

-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org

0 comment(s)
Diary Archives