pbh home > > post  

Join in 7 seconds.. Existing users: sign in.

poorbuthappy home  

all forums, active | Off Topic

Infection Control Alert - Only an Internet FYI

Well...only to be helpful to my PBH friends. April is quite a month for activity.

The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.

Last reviewed: April 23, 2008 10:18:56 EDT


April 23 Apple QuickTime Vulnerability
April 22 ICQ Vulnerability
April 18 Microsoft Releases Security Advisory (951306)
April 17 Apple Releases Safari 3.1.1
April 17 Mozilla Releases Firefox 2.0.0.14
April 16 Federal Subpoena Spear-Phishing Attack
April 15 Oracle Releases Critical Patch Update for April 2008
April 15 Multiple ClamAV Vulnerabilities
April 14 Oracle Issues Pre-Release Announcement for April Critical Patch Update
April 14 EMC DiskXtender Vulnerabilities

A few Details

Apple QuickTime Vulnerability
added April 23, 2008 at 10:14 am

US-CERT is aware of public reports of a vulnerability in Apple QuickTime. By convincing a user to open a specially crafted QuickTime file, an attacker may be able to execute arbitrary code. This vulnerability may have several attack vectors, such as visiting a malicious or compromised website.

US-CERT encourages users to use caution when opening QuickTime files, and apply the best security practices described in the Securing Your Web Browser document, to help mitigate the risks.


Microsoft Releases Security Advisory (951306)
added April 18, 2008 at 01:30 pm

Microsoft has released a Security Advisory to address a vulnerability in Windows. This vulnerability may allow an authenticated attacker to execute code with LocalSystem privileges.

US-CERT encourages users to review Microsoft Security Advisory 951306 and apply the workarounds.


Apple Releases Safari 3.1.1
added April 17, 2008 at 08:57 am

Apple has released Safari 3.1.1 to address multiple vulnerabilities in Safari and WebKit. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct cross-site scripting attacks, or spoof the contents of the browser address bar.

US-CERT encourages users to review Apple's About the security content of Safari 3.1.1 document and upgrade to Safari 3.1.1 to help mitigate the risks.


Mozilla Releases Firefox 2.0.0.14
added April 17, 2008 at 08:57 am

Mozilla has released Firefox 2.0.0.14 to address a vulnerability in the JavaScript engine. This vulnerability is due to memory corruption errors during JavaScript garbage collection. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. Products that use the Mozilla rendering engine, such as Thunderbird and SeaMonkey, may also be affected.

Federal Subpoena Spear-Phishing Attack
added April 15, 2008 at 08:31 am | updated April 16, 2008 at 09:34 am

US-CERT is aware of public reports of a spear-phishing attack circulating via email messages that claim to be federal subpoenas. These messages appear to be legitimate because they can contain very specific information about the message recipient. The message requests that the user follow a link to download additional information about the case, but if a user clicks on this link, malicious code may be installed on the system.

By CatGirl on Apr 23, 2008, 12:57 in Off Topic. AddThis Social Bookmark Button


CatGirl says on Apr 23, 2008, 12:58:

Here's the link for all the details and how to fix, update or patch

http://www.us-cert.gov/current/index.html#active_exploitation_of_gdi_v...

Hump!

Love and Time: the only two things that cannot be bought, but only spent

0 funny, 0 helpful.

MaFe says on Apr 23, 2008, 13:02:

Good infor CG!! Thanks!

"All human actions have one or more of these seven causes: chance, nature, compulsions, habit, reason, passion, desire. "-Aristotle

0 funny, 0 helpful.

CatGirl says on Apr 23, 2008, 13:10:

MaFe - they also have a mailing list to warn you as viruses are detected....for those that use firefox...Update asap!

Love and Time: the only two things that cannot be bought, but only spent

0 funny, 0 helpful.

CatGirl says on May 17, 2008, 14:50:

Only an updated FYI - Heads up ;))

United States Tax Court Spear-Phishing Attack
added May 15, 2008 at 03:15 pm

US-CERT is aware of public reports of a spear-phishing attack circulating via email messages that claim to be petitions from the US Tax Court. These messages appear to be legitimate because they may contain very specific information about the message recipient. The message requests that the user follow a link to download additional information about the petition, but if a user clicks on this link, malicious code may be installed on the system.

US-CERT encourages users to do the following to help mitigate the risk:

* Review the alert posted by the United States Tax Court regarding this issue.
http://www.ustaxcourt.gov/

* Do not follow unsolicited web links received in email messages.

* Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
http://www.us-cert.gov/reading_room/emailscams_0905.pdf

* Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
http://www.us-cert.gov/cas/tips/ST04-014.html

* Install anti-virus software and keep virus signature files up to date.

Beso Amigo/as

Love and Time: the only two things that cannot be bought, but only spent

0 funny, 0 helpful.

ColombianoGringo says on May 18, 2008, 12:08:

I reccomend using Firefox WITH the free NoScript add-on. It does not allow any scripts, ActiveX or other code to run on your browser without explicit permission. You can easily exempt site that you trust. It is the safest way to surf and will help avoid all kinds of malicious code.

0 funny, 0 helpful.

CatGirl says on May 20, 2008, 13:09:

Yes, I saw that....keep in mind that is does not allow PBH ;))) It considers it to be "dangerous" jejeje

Love and Time: the only two things that cannot be bought, but only spent

0 funny, 0 helpful.

CatGirl says on May 20, 2008, 13:10:

So what does that tell ya? hmm ;))))

Love and Time: the only two things that cannot be bought, but only spent

0 funny, 0 helpful.

More posts by the same author:

A Letter to The Editor 1

IS IT THE END OF THE INTERNET? 7

PERSONAL MESSAGING ON PBH 40

Bucket List 49

J. Jackson apologizes for verbalizing his desire to castrate Obama 12

The Most Deadliest Job(s) in the USA 13

DATE OR SOUL MATE PART 2 10

Southern China Pics 2

SAN CARLOS, CA: TOUR TESLA MOTORS, MAKE ANNOUNCEMENT 0

Peru trial sensation 2

Tropical Storm Cristina 0

Date or Soulmate - Part One 16

THE NEW NUT CASE 2

Uploading Avatar Pics - Problems anyone? 4

NORTHERN CALIFORNIA GOES UP IN SMOKE? 19

Gay/Lesbian Marriage (Legal) in the USA 143

HUGO'S EX RUNS FOR MAYOR 1

Computer Printer Operational and Photo Advise Needed 25

SPEED DATING 39

Just when I thought I had seen it all - The Potty Whisperer? 2


Americas:

Mexico

Cuba

Colombia

Venezuela

Ecuador

Brazil

Bolivia

Peru

Chile

Argentina

Africa:

Kenya

Congo

Malawi

South Africa

Asia:

China

Japan

India

Nepal

Thailand

Laos

 

Travel:

Travelguide writers

Travelicious

Travel with kids

Around the world trips

Learn travel Spanish

Off topic: your thing

Also:

All forums

Travelers

If you're not a part of this travelicious experiment just yet, just sign up here. It's free & easy.

 

About poorbuthappy | About the travel guides | Travel guide editing | Community rules

© 1998 - 2008 Peter Van Dijck, all rights reserved.