Video | Business Headlines | Internet | Science | Scientific Ethics | Technology | Search

 


Symantec Security Response: Microsoft October

Symantec Security Response: Microsoft Oct. Security Bulletin


On Tuesday, November 9, Microsoft issued information on a new vulnerability in Microsoft ISA and Proxy Server impacting both consumer and enterprise users. Microsoft ISA and Proxy Server are prone to an Internet domain name spoofing vulnerability that could allow an attacker to spoof Internet sites. This threat is being rated as a moderate risk by Symantec. In order for an attack to occur, the attacker must entice a vulnerable user to visit a malicious website instead of the site they are attempting to access. The attacker could then present false forms to the user in an effort to gather personal information. To guard against this threat, Symantec strongly encourages all users not to click on links to unknown websites.

"With the increasing prevalence of Phishing attacks, this vulnerability may provide yet another platform for the gathering of identity information," said Oliver Friedrichs, senior manager, Symantec Security Response.

Symantec recommends a proactive approach to vulnerability management as an important element of security best practices. IT administrators can expedite and simplify the patching process by implementing solutions such as Symantec ON iPatch, which proactively scans computer systems, identifies missing security patches, reports on the patch status, and then begins deployment of missing patches. In addition, users and network administrators should keep all antivirus definitions up-to-date and use appropriate firewall settings.

In addition, Symantec has also identified a new Level 2 threat - W32.Mydoom.AH@mm. W32.Mydoom.AH@mm is a mass-mailing worm that spreads itself via email addresses found on an infected system. To date, Symantec has received a total of 25 submissions, with 20 submissions coming from corporate customers. This threat exploits a buffer overflow vulnerability in Microsoft Internet Explorer IFRAME. At this time, there is no patch available for this vulnerability. Symantec strongly advises that administrators deploy the following mitigation strategies:

* Block outbound access to TCP ports 1639 to 1649 as these ports are likely to be used by W32.Mydoom.AH to download malicious code after compromise

* Filter inbound TCP ports 1639 to 1649 traffic in order to prohibit other systems from accessing systems that may already be infected

* Block outbound access to TCP port 6667

* Disable ActiveX on all systems running Internet Explorer

* Keep AV systems up-to-date with the most recent definitions to detect this threat

"With vulnerabilities being announced regularly, organizations need to make patch management part of their ongoing systems maintenance process," said Friedrichs. "And since there is an ever-shrinking window of time between vulnerability announcement and vulnerability exploit, quick implementation of patches and mitigation strategies is critical to the integrity of a network."

ENDS

© Scoop Media

 
 
 
 
 
Business Headlines | Sci-Tech Headlines

 

Sky City : Auckland Convention Centre Cost Jumps By A Fifth

SkyCity Entertainment Group, the casino and hotel operator, is in talks with the government on how to fund the increased cost of as much as $130 million to build an international convention centre in downtown Auckland, with further gambling concessions ruled out. The Auckland-based company has increased its estimate to build the centre to between $470 million and $530 million as the construction boom across the country drives up building costs and design changes add to the bill.
More>>

ALSO:

RMTU: Mediation Between Lyttelton Port And Union Fails

The Rail and Maritime Union (RMTU) has opted to continue its overtime ban indefinitely after mediation with the Lyttelton Port of Christchurch (LPC) failed to progress collective bargaining. More>>

Earlier:

Science Policy: Callaghan, NSC Funding Knocked In Submissions

Callaghan Innovation, which was last year allocated a budget of $566 million over four years to dish out research and development grants, and the National Science Challenges attracted criticism in submissions on the government’s draft national statement of science investment, with science funding largely seen as too fragmented. More>>

ALSO:

Scoop Business: Spark, Voda And Telstra To Lay New Trans-Tasman Cable

Spark New Zealand and Vodafone, New Zealand’s two dominant telecommunications providers, in partnership with Australian provider Telstra, will spend US$70 million building a trans-Tasman submarine cable to bolster broadband traffic between the neighbouring countries and the rest of the world. More>>

ALSO:

More:

Statistics: Current Account Deficit Widens

New Zealand's annual current account deficit was $6.1 billion (2.6 percent of GDP) for the year ended September 2014. This compares with a deficit of $5.8 billion (2.5 percent of GDP) for the year ended June 2014. More>>

ALSO:

Still In The Red: NZ Govt Shunts Out Surplus To 2016

The New Zealand government has pushed out its targeted return to surplus for a year as falling dairy prices and a low inflation environment has kept a lid on its rising tax take, but is still dangling a possible tax cut in 2017, the next election year and promising to try and achieve the surplus pledge on which it campaigned for election in September. More>>

ALSO:

Job Insecurity: Time For Jobs That Count In The Meat Industry

“Meat Workers face it all”, says Graham Cooke, Meat Workers Union National Secretary. “Seasonal work, dangerous jobs, casual and zero hours contracts, and increasing pressure on workers to join non-union individual agreements. More>>

ALSO:

Get More From Scoop

 
 
Standards New Zealand

Standards New Zealand
 
 
 
 
 
 
 
 
Sci-Tech
Search Scoop  
 
 
Powered by Vodafone
NZ independent news