Archive for August 2001

New worm encrypts .exe files

New worm encrypts .exe files. CW360.com Aug 31 2001 11:49AM ET [via Moreover Computer security news]

A Stateful Inspection of FireWall-1 (paper)

Sun shows off new version of StarOffice

An Audit of Active Directory Security

Aaron Sullivan, Security Focus:

An Audit of Active Directory Security:

Part One: An Overview of Active Directory and Security [August 1, 2001]

Part Two: Understanding the Security Implications of Active Directory Default Settings [August 29, 2001]

Security software: blind lead blind

Security software: blind lead blind. Commentary by Elias Levy

It’s incredible that in this day and age some of the most popular security products, products that are marketed as protecting you from the evils of computers, are so badly designed.

Case in point: The many antivirus products that failed to detect and stop the highly effective SirCam worm, even when updated with the latest signatures and when configured correctly.

Symantec’s Norton Antivirus for Gateways v2.x, Norton Antivirus POP email scanner, and TrendMicro’s InterScan VirusWall Standard and CVP editions version 3.51 build 1321 for Windows NT all failed to block SirCam. Why? Because all products “failed open,” i.e., when they encountered email messages they couldn’t handle properly, they sent them through by default.



[via The Register]

Microsoft: Dos and Don’ts of Client Authentication on the Web

Web Application Security:

White Hat Defcon9 presentation: Web Application Security

MIT (Fu, Sit, Smith, Feamster): Dos and Don’ts of Client Authentication on the Web

More cross-site scripting vulnerabilities

More cross-site scripting vulnerabilities from
White Hat Security:

Hotmail STYLE CSS Vulnerability [08.15.2001]

Another MS Hotmail Security Issue with further widespread implications [08.24.2001]

Radio Waves Zap Zebra Mussels

Radio Waves Zap Zebra Mussels. Zebra mussels, a particularly hearty invasive species, have caused millions of dollars in damage to U.S. boats and power plants. Scientists may now have a way to combat the pesky mollusks. From the Environment News Service. [Wired News]

Offensive Trojan horse can disable systems

New MS Tool: Good and Bad

New MS Tool: Good and Bad. Microsoft’s newest ‘user-friendly’ security tool is a grand gesture by the company, experts say. But many users are alarmed at the results, and some say the friendliness of it is far too technical. By Michelle Delio. [Wired News]