<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet href="/css/rss.css" type="text/css"?>
<rss version="2.0">
<channel>
  <title>      SANS Internet Storm Center, InfoCON: green</title>
  <link>       http://isc.sans.edu</link>
  <description><![CDATA[]]></description>
  <language>   en-us</language>
  <lastBuildDate>   Sat, 04 Feb 2012 01:48:03 +0000</lastBuildDate>
  <pubDate>   Sat, 04 Feb 2012 00:58:01 GMT</pubDate>
<copyright>(C) SANS Institute 2012</copyright>
             <generator>isc rss feed maker</generator>
             <ttl>30</ttl>
             <webMaster>handlers@sans.org (ISC Handlers)</webMaster>
             <image>
               <title>SANS Internet Storm Center, InfoCON: green</title>
               <url>http://isc.sans.org/images/status.gif</url>
               <link>http://isc.sans.org</link>
             </image>
  <item>
    <title>Apple Security Advisory 2012-001 v1.1, (Sat, Feb 4th)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12532&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12532&amp;rss</guid>
    <description><![CDATA[Earlier today, Apple announced v 1.1 of the Security update 2012-001. The advisory announced the availability of Security Update for Mac OSX10.6.8 that addresses a compatibility issue, and the removal of security fixes that were present in original update for Snow Leopard. I am not confident why Apple removed security fixes from the original release, but maybe one of our readers can help us understand the issues behind the ImageIOsecurity fix removal.<br />
Below is the security advisory and we will link to the advisory once it is available on Apple's website.<br />
<br />
APPLE-SA-2012-02-03-1 Security Update 2012-001 v1.1<br />
<br />
<br />
<br />
Security Update 2012-001 v1.1 is now available<br />
<br />
for Mac OS X v10.6.8 systems to address a compatibility<br />
<br />
issue.<br />
<br />
<br />
<br />
Version 1.1 of this update removes the ImageIO security<br />
<br />
fixes released in Security Update 2012-001.<br />
<br />
<br />
<br />
OS X Lion systems are not affected by this change.<br />
<br />
<br />
<br />
Update #1:<br />
Apple Support shows there were 3 different issues which were corrected in ImageIO in the original Security Update information located at http://support.apple.com/kb/HT5130.<br />
Elsewhere, it appears that there are a number of users of OS XLion which had problems after applying the original update as reported in Apple Support forums, 9to5Mac, and thevarguy.com. The Security Advisory only mentions OS X Snow Leopard, so I am not sure that the two issues are related or just coincidental. Stay tuned for more information.<br />
----<br />
Guy Bruneau  Scott Fendley (ISC Handler On Duty)
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Sat, 04 Feb 2012 00:58:01 GMT</pubDate>
  </item>
  <item>
    <title>
Sophos 2012 Security Threat Report, (Fri, Feb 3rd)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12526&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12526&amp;rss</guid>
    <description><![CDATA[Last week Sophos released it 2012 Security Threat Report which highlighted some key finding from 2011:<br />
- Smartphones and tablets causing significant security challenges<br />
<br />
- Major data breaches and targeted attacks on high-profile companies and agencies<br />
<br />
- Hacktivism - A shift from hacking for money to hacking as a form of protest or to prove a point<br />
<br />
- Conficker worm is still the most commonly encountered pieces of malicious software seen is Sophos customers<br />
<br />
- Fake antivirus software is still the most common type of malware but in second half of the year appears to be on the decline<br />
<br />
- Spearphishing attacks on the rise<br />
Despite all this, some successes On March 16, 2011 a coordinated effort known as Operation b107 between Microsoft, FireEye, U.S. federal law enforcement agents and the University of Washington knocked Rustock offline. [1] The entire report available here.<br />
Handler Mark published a diary on some of the things to take in consideration When your service provider has a breach. [3]<br />
[1] http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-07.aspx<br />
<br />
[2] http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx<br />
<br />
[3] https://isc.sans.edu/diary.html?storyid=10651<br />
<br />
[4] http://www.sophos.com/medialibrary/PDFs/other/SophosSecurityThreatReport2012.pdf<br />
Data breach diaries reported by ISC in 2011:<br />
[1] Wordpress.com https://isc.sans.edu/diary.html?storyid=10729<br />
<br />
[2] RSA Breach https://isc.sans.edu/diary.html?storyid=10609<br />
<br />
[3] Lockheed Marting https://isc.sans.edu/diary.html?storyid=10939<br />
<br />
[4] Sega Pass https://isc.sans.edu/diary.html?storyid=11065<br />
<br />
[5] SonyPictures https://isc.sans.edu/diary.html?storyid=10996<br />
<br />
[6] DigiNotar SSL Breach (result = bankruptcy) https://isc.sans.edu/diary.html?storyid=11479<br />
<br />
[7] GlobalSign https://isc.sans.edu/diary.html?storyid=12205<br />
<br />
[8] Stratfor Global Intelligence https://isc.sans.edu/diary.html?storyid=12271<br />
-----------<br />
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Fri, 03 Feb 2012 22:34:15 GMT</pubDate>
  </item>
  <item>
    <title>
ISC StormCast for Friday, February 3rd 2012 http://isc.sans.edu/podcastdetail.html?id=2302, (Fri, Feb 3rd)</title>
    <link>http://isc.sans.edu/podcastdetail.html?id=2302</link>
    <guid>http://isc.sans.edu/podcastdetail.html?id=2302</guid>
    <description><![CDATA[
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Fri, 03 Feb 2012 06:25:05 GMT</pubDate>
  </item>
  <item>
    <title>
Critical PHP bug patched, (Fri, Feb 3rd)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12520&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12520&amp;rss</guid>
    <description><![CDATA[Just about a month ago, PHP 5.3.9 was released, which included a patch for the hash collision problem. The basic hash collision problem affected various languages, including php and .Net (Microsoft fixed the issue in an out of band patch 2011-100 in late December).<br />
PHP fixed the issue not by introducing a new hash function, but instead it limited the number of input parameters. Just like the php hardening patch suhosin did all along, PHP now supported a max_input_var parameter to limit the number of input parameters a request may send. The default limit was set to 1,000, plenty for most web applications.<br />
Sadly, the fix was implemented incorrectly, and introduced a more severe vulnerability, a remote code execution vulnerability. Thats right: An attacker could craft a request, that will execute code on a web server running PHP 5.3.9.<br />
Today, the PHP team released PHP 5.3.10 to address the issue.<br />
If you are running PHP 5.3.9: PATCH NOW! This is a very critical bug<br />
If you are running PHP 5.3.8: DO NOT UPGRADE TO 5.3.9. I would actually recommend that you wait.<br />
Additionally, try to enable Suhosin if at all possible. There is a slight performance hit, but it is unlikely to break your web application unless you are already tight in resources. Many Linux distributions include Suhosin, so it may be pretty easy to set up.<br />
------<br />
<br />
Johannes B. Ullrich, Ph.D.<br />
<br />
SANS Technology Institute<br />
<br />
Twitter
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Fri, 03 Feb 2012 05:40:36 GMT</pubDate>
  </item>
  <item>
    <title>
New Poll - What security issue concerns you the most this year?, (Fri, Feb 3rd)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12517&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12517&amp;rss</guid>
    <description><![CDATA[-----------  Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Fri, 03 Feb 2012 01:19:27 GMT</pubDate>
  </item>
  <item>
    <title>
PHP 5.3.10 Released, Fixes CVE-2012-0830 available for download http://www.php.net/archive/2012.php#id2012-02-02-1, (Fri, Feb 3rd)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12514&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12514&amp;rss</guid>
    <description><![CDATA[-----------  Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Fri, 03 Feb 2012 00:56:37 GMT</pubDate>
  </item>
  <item>
    <title>
ISC StormCast for Thursday, February 2nd 2012 http://isc.sans.edu/podcastdetail.html?id=2299, (Thu, Feb 2nd)</title>
    <link>http://isc.sans.edu/podcastdetail.html?id=2299</link>
    <guid>http://isc.sans.edu/podcastdetail.html?id=2299</guid>
    <description><![CDATA[
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Thu, 02 Feb 2012 05:06:11 GMT</pubDate>
  </item>
  <item>
    <title>
Apple and Apache security fixes and releases, (Wed, Feb 1st)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12502&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12502&amp;rss</guid>
    <description><![CDATA[Apple updates released today:<br />
<br />
    security update 2012-001 for Snow Leopard (Mac OS X 10.6) and Snow Leopard server<br />
    update for Lion and Lion server (Mac OS X 10.7.2 - 10.7.3)<br />
    remote desktop 3.5.2 client<br />
    server admin tools 10.7.3<br />
<br />
<br />
http://support.apple.com/kb/HT1222<br />
<br />
10.7.3:http://support.apple.com/kb/HT5048<br />
<br />
server admin tools:http://support.apple.com/kb/HT5050<br />
<br />
Apache HTTP Server 2.2.22 Released<br />
<br />
This version of Apache is principally a security and bug fix release, including significant security fixes:<br />
http://httpd.apache.org/security/vulnerabilities_22.html<br />

 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Wed, 01 Feb 2012 22:02:51 GMT</pubDate>
  </item>
  <item>
    <title>
Oracle Security Alert: http://www.oracle.com/technetwork/topics/security/alert-cve-2011-5035-1506603.html, (Wed, Feb 1st)</title>
    <link>http://isc.sans.edu/diary.html?storyid=12499&amp;rss</link>
    <guid>http://isc.sans.edu/diary.html?storyid=12499&amp;rss</guid>
    <description><![CDATA[
 
 (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
    <pubDate>Wed, 01 Feb 2012 21:40:25 GMT</pubDate>
  </item>
</channel>
</rss>

