MS national security threat

"Microsoft's monopoly threatens consumers in a number of ways, it it's clear it is now also a threat to our security, our safety, and even our national security."

"I don't think that Microsoft can ever fix this."

A panel of leading security experts Wednesday blasted Microsoft for vulnerabilities in its software, and warned that reliance on Microsoft's software is a danger to both enterprises and national security.

How many more mailworms does it still take to make people realize this ?

Redhat merges with Fedora, switches name ?

Red Hat has announced a merger of its Red Hat Linux Project with Fedora Linux, a group that has specialized in providing high-quality RPM packages for Red Hat. According to Red Hat, 'The Fedora Project is a Red-Hat-sponsored and community-supported open source project'.

Sounds a lot like the Debian or Gentoo community model, but I'm confused about Redhats future. Will they rename the consumer version 'Fedora' now, and try to bind the Redhat brand name to their RedHat Advanced/Enterprise Server line ?

RIAA pranks

JH: Hello. I just downloaded some illegal MP3s and my friend told me that the RAII is going to sue everyone who downloads music. What should I do?

RIAA: Hold on just a sec.

[..]

RIAA: The best advice I can offer you at this moment is to go to dub-dub-dub-musicunited.org and you can learn there how to uninstall your peer-to-peer software or file-sharing service.

JH: But I don't have a pee service. Someone just e-mailed me a song and I listened to it. Am I going to jail?

More funny stuff at RIAA pranks...

Stopping the Swen/Gibe.F madness

Mail traffic is at an all time maximum here with the Swen/Gibe.F Microsoft mail worm. As the messages are 150 KB in size, a spamfilter solution as the SpamAssassin - Procmail combination isn't optimal as all mail is still being downloaded to my workstation. So I decided to fight the spam the place where it should be, and installed MailFilter, a nifty mail filtering program which even works for POP3 mailboxes.

Anonymous Wed, 06/15/2005 - 19:08

If you use procmail, you can install clamav to catch these suckers. If you already have SpamAssassin installed and don't want to bother with installing another piece of software, you can add these rules:

header _VIRUS_h0_SWEN_A SUBJECT =~ m{(Current|Newest|New|Last|Latest)? ?(Internet|Network|Net|Microsoft)? ?(Security|Critical)? ?(Patch|Upgrade|Pack|Update)}i
header _VIRUS_h2_SWEN_A From =~ m{(Microsoft|MS)? ?(Internet|Corporation)? ?(Technical|Security|Customer|Public)? ?(Assistance|Services|Center|Bulletin|Division|Section)}i
rawbody _VIRUS_b4_SWEN_A m{Undeliver(able|ed) (mail|message)? ?to}i
meta VIRUS_m_SWEN_A ((_VIRUS_h0_SWEN_A && ( MICROSOFT_EXECUTABLE || MIME_SUSPECT_NAME ) && _VIRUS_h2_SWEN_A) || (_VIRUS_b4_SWEN_A && ( MICROSOFT_EXECUTABLE || MIME_SUSPECT_NAME )))
describe VIRUS_m_SWEN_A http://www.trendmicro.com/vinf...o/default5.asp?VName=WORM_SWEN.A
score VIRUS_m_SWEN_A 10.0

Anonymous Wed, 06/15/2005 - 19:09

In reply to by Anonymous

Mailfilter is great indeed; I use the following ruleset (3 lines, begin with DENY - to correct the browser layout mangling) :

REG_TYPE=extended
DENY=^Subject:.*(Current|Newest|New|Last|Latest)? ?(Internet|Network|Net|Microsoft)* *(Security|\r\nCritical)* *(Patch|Upgrade|Pack|Update)
DENY=^From:.*(Microsoft|MS)? ?(Internet|Corporation)* *(Program Security|Technical|Security|Cust\r\nomer|Public)* *(Support|Assistance|Services|Center|Bulletin|Division|Section).*

These 3 lines catch almost 90% of these suckers...

Solaris sadmind exploit

There's a nasty security hole in Solaris'' sadmind daemon; an exploit has been released which targets a weakness in the default security settings of the sadmind RPC application, and which allows to call arbitrary methods in any class available to sadmind. It has been a busy week for Unix sysadmins : first an exploit in SSH, then a security hole in Sendmail, and now this sadmind hole.

But Windows has its share of the problem too : a new mail worm, called Swen/Gibe.F, is preying a flaw that Microsoft first disclosed in a March 2001. In fact, it's the first Microsoft worm which causes annoyances to me as a Linux user; the number of mails with subject Returned Response are really numerous here.