Tuesday, December 12, 2006

Black Tuesday - Microsoft December Patches

As part of Microsoft's routine, monthly security update cycle, we released the following security updates on December 12, 2006:
  • MS06-072 - Critical - Microsoft Internet Explorer (KB925454)
  • MS06-073 - Critical - Microsoft Visual Studio (KB925674)
  • MS06-074 - Important - Microsoft Windows (KB926247)
  • MS06-075 - Important - Microsoft Windows (KB926255)
  • MS06-076 - Important - Microsoft Windows (KB923694)
  • MS06-077 - Important - Microsoft Windows (KB926121)
  • MS06-078 - Critical - Microsoft Windows Media Player (KB923689 and KB925398)
  • MS06-059 (re-release) - Critical - Microsoft Office (KB924164)

Note that the MS06-059 bulletin has been updated, revised and re-released for Microsoft Excel 2002 to address the issues identified in Microsoft Knowledge Base Article 924164. So no fix for the new Office zero-day, as expected.

Also, note that the ASX vulnerability that was released by sehato recently has been patched as part of MS06-078.

Patch'em if you got'em!

New IBM Memory Device Could Trash Flash

Via Unstrung -

Leap-frogging Moore's Law, scientists from IBM Corp. will announce on Wednesday a prototype of a new type of memory device that has the potential to replace flash memory in mobile devices such as music players, cell phones, and digital cameras.

Called "phase-change memory," the new technology runs more than 500 times faster than today's flash memory while using less than half the power to store information. Like flash, phase-change memory is "non-volatile" in that it retains data even when power to the device is switched off.

[...]

In other words, unlike flash, phase-change memory technology can improve as it gets smaller. The prototype device has a cross section of 3 nanometers (nm) by 20 nm, far smaller than flash can be built today and equaling the industry's chip-making size goals for 2015.

Because it uses so much less power, the new technology could also help solve the battery-life limitations now facing mobile-device makers.

[...]

Built around a core of a sophisticated alloy of germanium and antimony, phase-change memory devices work by alternating between a crystalline, ordered "phase," or arrangement of atoms, and a random, "amorphous" phase. An electrical pulse triggers the rapid shift by heating the alloy almost to the melting point.

So powerful and economic is phase-change memory, at least in theory, that it is seen as a possible replacement for disk drives in computers.

Monday, December 11, 2006

How to Survive a Robot Uprising

If popular culture has taught us anything, it is that someday mankind must face and destroy the growing robot menace.In print and on the big screen we have been deluged with scenarios of robot malfunction, misuse, and outright rebellion. Robots have descended on us from outer space, escaped from top-secret laboratories, and even traveled back in time to destroy us.

Today, scientists are working hard to bring these artificial creations to life. In Japan, fuzzy little real robots are delivering much appreciated hug therapy to the elderly. Children are frolicking with smiling robot toys. It all seems so innocuous. And yet how could so many Hollywood scripts be wrong? So take no chances. Arm yourself with expert knowledge. For the sake of humanity, listen to serious advice from real robotics experts. How else will you survive the inevitable future in which robots rebel against their human masters?

http://www.robotuprising.com/home.htm

McAfee's 2006 Virtual Criminology Report Released in Europe

Via the BCC -

Some criminal gangs are paying students while they study to ensure they have a pool of tech-savvy workers to call on, says the report from McAfee.

Others are cashing in on the glamour of the hi-tech world to tempt youngsters into embarking on a life of crime.

McAfee said children as young as 14 years old were being targeted by some criminal gangs.

Greg Day, security analyst at McAfee and one of the authors of the Virtual Criminology report, said it aimed to explore the digital underground and how and where the criminal and hi-tech worlds meet.

"We wanted to understand a bit more about the motivation and how people end up on this career path," said Mr Day.

The most successful cyber crime gangs were based on partnerships between those with the criminals skills and contacts and those with the technical ability, said Mr Day.

"Traditional criminals have the ability to move funds and use all of the background they have," he said, "but they don't have the technical expertise."

As the number of criminal gangs looking to move into cyber crime expanded, it got harder to recruit skilled hackers, said Mr Day. This has led criminals to target university students all around the world.

"Some students are being sponsored through their IT degree," said Mr Day. Once qualified, the graduates go to work for the criminal gangs.



So this report was released in Europe last week, but won't be released in the US until early January. So can someone in Europe provide a link to the report somewhere? =)

Sunday, December 10, 2006

EPA to Consider Removing Lead from Regulated Pollutant List

Every since I was a little kid, I have had various government groups telling me that lead was not something I wanted in my body. So why now is the EPA talking about maybe pulling it from the Regulated Pollutant List??

According to Wikpedia,

Lead is a poisonous metal that can damage nervous connections (especially in young children) and cause blood and brain disorders. Long term exposure to lead or its salts (especially soluble salts or the strong oxidant PbO2) can cause nephropathy, and colic-like abdominal pains. The historical use of lead acetate (also known as sugar of lead) by the Roman Empire as a sweetener for wine is considered by some to be the cause of the dementia which affected many of the Roman Emperors. At one point in time, some lead compounds, because of their sweetness, were used by candy makers. Although this has been banned in industrialized nations, there was a 2004 scandal involving lead-laced Mexican candy being eaten by children in California.

The concern about lead's role in mental retardation in children has brought about widespread reduction in its use (lead exposure has been linked to schizophrenia). Lead-white paint has been withdrawn from sale in industralised countries. The yellow lead chromate is still in use; for example, Holland Colours Holcolan Yellow. Many older houses may still contain substantial lead in their old paint; it is generally recommended that old paint should not be stripped by sanding, as this generates inhalable dust.
We have created tons of laws and rules to reduce the amount of lead in our environment, to remove lead from paint and gas, to educate the public on the dangerous of lead in the body......we even worked to remove it from the air. And this measures appear to have worked.

So can someone tell me why we would remove lead from the Regulated Pollutant List (as it applies to the Clean Air Act)?

Perhaps I am just missing something.

Saturday, December 9, 2006

MS Windows DNS Resolution Remote DoS PoC (MS06-041)

This was posted on Milw0rm today.

http://www.milw0rm.com/exploits/2900

This vulnerabilitiy was patched by Microsoft in August 2006 (MS06-041).

According to Microsoft, code execution is possible with this hole. So take this DoS PoC seriously and patch if you haven't already.

Then again, if you haven't applied the patches that were released in August, then you have a load of other trouble beyond this...

Humor: Apple Employee Fired For Thinking Different

Via theOnion (1999) -

CUPERTINO, CA—Brent Barlow, 27, a software analyst and beta-tester at Apple Computer headquarters in Cupertino, was fired Monday for "thinking a little too different."

Apple spokespersons said the firing was necessary because Barlow "consistently failed to adhere to the normal standards of conduct and daily routines expected of employees of Apple Computer."

Among the floutings of convention cited in Barlow's Apple employee file: developing a pulley system to store his mountain bike above his workstation, listening to Bob Dylan on his headphones while testing software, and taking barefoot walks around the Apple campus to "feel more connected to the creative energy of others."

"It's okay to think outside the box," said Avie Tevanian, Apple senior vice-president of software engineering. "In fact, we very much encourage that sort of thing here at Apple. But in Mr. Barlow's case, he went just a bit too far."

Barlow was first written up in September 1996, when he was cited for "unprofessional and inappropriate personal modifications to his workspace." In addition to taped-up pictures of Mahatma Gandhi, Albert Einstein and R. Buckminster Fuller, Barlow painted a large red question mark on the side of his monitor, scanned and displayed a non-approved desktop screen image of Jim Henson, and replaced his computer's trademarked Apple system beep with a snippet of the John Lennon song "Imagine."

"I like to explore problems from unusual angles," said the ponytailed Barlow, cleaning out the desk he has occupied since joining Apple in 1995. "And being in a free-form environment of my own creation really helps me get in the right frame of mind."

Barlow's most recent formal write-up came last Thursday, when his team supervisor caught him doing a headstand.

"I was stuck on this bug I discovered in the new Mac OS X system software that Apple's developing. No matter what I tried, nothing worked," Barlow said. "So I thought to myself, what I need to do is turn my whole approach to this problem upside-down. And what better way to do that than by standing on your head?"

In an effort to prevent such incidents of "excessive iconoclasm" in the future, Apple has developed a manual outlining the company's rules and regulations regarding individualism. Permitted will be such unorthodox activities as removing shoes when seated or within four feet of a desk; whistling when given prior written permission from a direct supervisor; and kicking puddles, provided the kicking is conducted during one's lunch hour and the puddle is one of the 35 on the Apple campus specifically designated for such a purpose. Prohibited will be such "gratuitously idiosyncratic" behaviors as singing out loud, flying kites and catching butterflies.

"Of course, we want our employees to be individuals and 'do their own thing,' so to speak," Apple director of corporate communications Michael Landau said. "But Mr. Barlow's behavior consistently crossed the line. If he wants to think that different, he can do it on his own time."

Technology in the Public - Rebooting Airplanes

There are some interesting yet kind of scary stories over at the Risks Digest - Forum on Risks to the Public in Computers and Related Systems.

These two really stood out...


Rebooting Airplanes
<"Douglas W. Jones">
Tue, 28 Nov 2006 13:29:42 -0600


In the last few weeks, I've done quite a bit of flying, and twice, now, I've been on planes where they had to reboot.

The first trip where this happened, as we were scheduled to leave the gate, there was a delay, and then the pilot said over the intercom: "We're having trouble with some of the cockpit instruments, so I'm going to force a hard reboot by switching off all the power for a bit." The lights and all other power on the plane then went off, and after a fifteen second pause, on again. A minute later, the pilot said: "That seems to have fixed the problem," and we were off.

I wasn't impressed. As far as I am concerned, this is clear evidence of a genuine design error somewhere in the system.

The second problem happened on Sunday, on a flight back from Amsterdam. On that flight, they had serious problems with the in-flight video on demand system. They tried a "soft reboot" of some kind, and it didn't work, so they then tried two "hard reboots," their term, and after the second try, it worked fine. Their instructions were "until the system comes all the way up, please don't touch any buttons." That alone suggests poor design. The system ought to come up with interrupts disabled on any devices that it's not ready to listen to, after all.

The reboot process took close to half an hour, and watching the displays in the seat backs that were visible from my seat, I could see that they were being rebooted in sequence, about one per second. Furthermore, as each in-seat display was rebooted, it showed the Linux penguin and then a Linux boot script, revealing that each seat-back display was a little Linux system, suggesting that they were all networked to a video server for the plane.

Again, the need for these global reboots is strong evidence that the systems were not well designed,

I wonder if both of these stories illustrate problems with the kinds of graduates we are turning out these days. CS programs across the country are emphasizing high-level courses in web programming, but fewer and fewer students know anything about the fundamentals of parallel programming that underly things. So, in constructing the kinds of distributed applications that show up in contexts like streaming video and cockpit instrumentation, they are working without the theoretical underpinnings needed to understand the problems they encounter.


Mascalls, Manchester, what's the difference?
<"Mark Brader">
Sat, 2 Dec 2006 04:36:21 -0500 (EST)

A British ambulance crew, transferring a patient to a hospital where they had never gone before, drove 200 miles out of their way before realizing that their satellite navigation device had given them the wrong directions.

These reports mention other incidents of sat-nav gaffes, but don't say what the actual error was this time; this shorter one says that the system showed their destination's address as being in Brentwood in Manchester instead of Brentwood in West London.

The patient was not harmed, and the crew has been told they should have known better.

Friday, December 8, 2006

Tools of the Trade - Increased Flavanol Formula!!

Flavanol is the antioxidant in dark chocolate which lowers blood pressure by neutralizing potentially cell-damaging substances known as oxygen free radicals. Anyways, on to the tools...

1) Nmap 4.20 has broken free of its RC chains and is now free to come outside and play. You might as well, run over to Winpcap.org and grab the new Winpcap 4.0 beta 3 as well. Download it, use it, and then tell Fyodor how cool it is. Improvements made over RC2 include the following:

  • Updated nmap-mac-prefixes to reflect the latest OUI DB from the IEEE as of Dec 7.
  • Integrated the latest OS fingerprint submissions. The 2nd generation DB size has grown to 231 fingerprints. Please keep them coming! New fingerprints include Mac OS X Server 10.5 pre-release, NetBSD 4.99.4, Windows NT, and much more.
  • Fixed a segmentation fault in the new OS detection system which was reported by Craig Humphrey and Sebastian Garcia.
  • Fixed a TCP sequence prediction difficulty indicator bug. The index is supposed to go from 0 ("trivial joke") to about 260 (OpenBSD). But some systems generated ISNs so insecurely that Nmap went berserk and reported a negative difficulty index. This generally only affects some printers, crappy cable modems, and Microsoft Windows (old versions). Thanks to Sebastian Garcia for helping me track down the problem.

2) GnuPG 1.4.6 was recently released. This update version fixes the highly critical vulnerability exposed in early December.

3) On Dec 7th, GooglePath 0.3 was released by Matteo Cantoni. Googlegath is a free open source perl utility to obtain information through Google searches. It could be useful for penetration testing, security scanning, script kiddies stuff etc..

4) On Nov 30th, ModSecuirty 2.0.4 was released. Mod Security is an intrusion detection and prevention engine for Web applications which operates as an Apache module or Java Servlet filter. It should be noted that ModSecurity & Thinking Stone Ltd. were recently acquired by Breach Security, Inc. For more info about ModSecurity, check out this great SecurityFocus interview with Ivan Ristic.

5) On Nov 30th, Stunnel 4.20 was released. Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL available on both UNIX and Windows.

5) On Nov 27th, Matteo Cantoni released Snmpcheck 1.6. Snmpcheck is a free open source perl utility to get information via SNMP protocols. It works fine against Windows, Linux, Cisco, HP-UX, SunOS systems and any devices with SNMP protocol support. Snmpcheck runs on GNU/Linux, *BSD and Windows (Cygwin) systems.

If you are into fuzzers, check out JBroFuzz from OWASP. JBroFuzz is a stateless network protocol fuzzer that emerged from the needs of penetration testing. Written in Java, it allows for the identification of certain classes of security vulnerabilities; by means of creating malformed data and having the network protocol in question consume the data.

Go fuzz some stuff, all the cool kids are doing it. Many software development companies are fuzzing the crap out of their products before release...but security researchers are still finding very serious flaws with simple fuzzers.

In other news, I noticed that my THC Amap install appears to be updating correctly again. There were no updates available, but it wasn't throwing an error anymore. You might remember that THC has some domain issues a while back ago...and this was causing the problem.

Litvinenko Believed Poisoned At Hotel Bar

Via playfuls.com -

Investigators in London said they believe former Russian spy Alexander Litvinenko was poisoned at a hotel bar while meeting with two Russian businessmen.

The investigators said the seven staff members at the Pine Bar in London's Millennium Hotel who were working Nov. 1 -- the night of meeting -- tested positive for polonium-210, the radioactive isotope that poisoned the former spy, The Times of London reported Friday.

Health authorities were working Thursday to contact some 250 customers who visited the bar that night to see if those patrons were also exposed to radioactivity.

Pat Troop, of Britain's Health Protection Agency, told The Times the levels of the isotope found in the bar staff were similar to the level found in Litvinenko's wife. He said the levels posed no short-term danger to the infected staff but there was a "very small" risk that they could later develop cancer as a result of exposure.

Thursday, December 7, 2006

Hollywood Starts to Sell "Fair Use" Rights

Via EFF -

"Apparently, Hollywood believes that you should have to re-purchase all your DVD movies a second time if you want to watch them on your iPod." That's what I said last week, commenting on the Paramount v. Load-N-Go lawsuit, in which Hollywood studios claimed that it is illegal to rip a DVD to put on a personal video player (PVP), even if you own the DVD.

Well, this week the other shoe dropped. According to an article in the New York Times:

Customers who buy the physical DVD of Warner Brothers’ “Superman Returns” in a Wal-Mart store will have the option of downloading a digital copy of the film to their portable devices for $1.97, personal computer for $2.97, or both for $3.97.


So you buy the DVD, and if you want a copy on your PVP or computer, you have to pay a second time. Despite the fact that you bought the DVD, and you have a DVD drive in your computer that is perfectly capable of making a personal-use copy. Imagine if the record labels offered you this "deal" for every CD you bought -- pay us a few dollars extra, and you can have a copy for your iPod. And a few more dollars, if you want a copy on your computer, too!

As LA Times reporter Jon Healey puts it
in his blog: "So from the perspective of the studios and federal officials, consumers have to pay for the privilege of doing the sorts of things with DVDs that they're accustomed to doing with CDs (and LPs and cassettes)."

This latest bitter fruit from Hollywood is brought to you by the
DMCA, which treats "protected" content (like the encrypted video on DVDs), differently from "unprotected" content (like every audio and video media format introduced before 1996). Thanks to the DMCA, Hollywood believes fair use personal-use copies simply do not exist when it comes to DVDs.

Given that the Copyright Office has refused [
PDF, see p. 71-72] to recognize any DMCA exemption for space-shifting, claiming that putting a DVD you own on your iPod "is either infringing, or, even if it were noninfringing, would be merely a convenience," (excuse me, Copyright Office, that's a decision for a court to make) the ball is now in Congress' court. Let's hope Congressman Rick Boucher is listening and will reintroduce his DMCA reform bill first thing next year.

---------------------------------------

This is just twisted...and seems very underhanded, but we are talking about the MPAA.

Polonium: The Terrorists' Perfect WMD

Via the CounterTerroism Blog -

The disclosure that "seven workers at the Millennium Hotel, where former KGB agent Alexander Litvinenko met a contact on the day he fell ill, have tested positive for 'low levels' of polonium" further expands the serious consequences of the investigation into Litvinenko's murder. (UPDATE: A former KGB who met with Litvinenko in London has fallen into a coma from contact with "a radioactive substance.")

A CTB reader who graduated from MIT wrote me recently with the following information on polonium:

Polonium 210 can be manufactured in any small research reactor such as those found in universities around the world. The single poisoning seems to me to be a wakeup call that polonium 210 is probably the best WMD in the world. Wikipedia gives the lethal dose as 0.1 micrograms, think of a Vitamin C tablet divided into 10 million pieces. When dissolved in mild acid, such as is in the gut, a lethal dose will produce about 10 trillion atoms which tend to permeate the body and leak out of the pores. If divided and encapsulated (think time release capsule) a small amount of polonium 210 could be weaponized to float on the breeze like anthrax, it would be undetectable, indestructible and any residue would lose potency after
just a few years.

-------------------------------------

Very interesting idea to say the least...

Microsoft Windows Media Player DoS Zero-Day

Recently a Windows Media Player zero-day was released. The exploit uses the ASX playlist as the attack vector.

eEye and others are researching the issue with the view that remote code execution is highly possible. This could turn ugly on social sites (like Myspace) if someone finds the memory "sweetspot", so keep an eye out on this one.

ASX radio station streaming is done all the time on Myspace.

http://research.eeye.com/html/alerts/zeroday/20061122.html

Shocking Drug Trend - Texas Cheese

I read about this several weeks ago in another article but decided not to post it. It seems the problem isn't as limited as I was hoping...so here you go.

Via ABC News -

A new wave of 10- to 12-year-olds addicted to heroin is washing up at Dallas drug rehab centers and emergency rooms.

The preteens are mixing the powerful opiate with crushed Tylenol PM, a concoction they call "cheese," according to Michelle Hemm, Director of the Dallas Phoenix House drug treatment facility.

As reported in "The Blotter" in May, a few 11-year-olds in Dallas were using "cheese," but now that is a common phenomenon in Dallas schools.

"We've seen a huge increase in referrals for 'cheese,' and a huge decrease in the age of the kids that are being referred," said Hemm. "We've had mostly 11- and 12-year-olds in the last few months."

Hemm says she has had to turn away most of the preteen referrals because they are too young. She is only licensed to treat addicts between 13- and 17-years-old. "The young kids aren't emotionally ready for our program," said Hemm.

An exception was made for one 11-year-old whose mother lied about his age to get him admitted, according to Hemm. "The 11-year-old that we had in here had overdosed several times and had detoxed several times."

A 14-year-old who overdosed on heroin was rushed to the Dallas children's hospital ER last week in critical condition. The teen had been snorting "cheese," according to Dr. Kurt Kleinschmidt, who was on call when the patient arrived. "He should have died; it's amazing he didn't," said Kleinschmidt.

The heroin crosses the Mexican border into Texas, where traffickers sell it to high school and middle school students in Dallas, who mix it up with Tylenol PM into "cheese," according to the Dallas Independent School District Police Department.

The elementary school-aged children often get the "cheese" from older siblings at the middle school across the street from the elementary school, Hemm says her patients tell her.

DEA officials in Washington say they have not seen the "cheese" phenomenon anywhere outside of Dallas.

The TSA and Fake Boarding Pass Generator Drama

Via SlightParanoia -

Dear Christopher,

We were slightly worried that you might spend Christmas relaxing and spending quality time with your family. We can't have that.

Thus, please enjoy the enclosed letter - we're quite confident that it'll occupy your thoughts for the next few weeks. Have fun mulling things over. We expect a reply from you by Christmas day.

Enjoy your holidays!

Love,

Your Friends at TSA.

P.S. We continue to ignore the existence of a different boarding pass generator, written by someone else and which has been online for the past month. It wasn't in the Washington Post, so our bosses haven't seen it yet. Phew!

P.P.S. We don't actually plan on fixing any of the underlying security problems. That'd be far too difficult. We may, however, switch from requiring Ziplock bags to Reynolds Wrap foil pouches for passengers' liquids. The idea of people constructing oragami foil pouches in the security line has been making us crack up at the office, and we think it should do much to spread Christmas Cheer at the Airports.

------------------------------

This is just too rich not to post up...is this really the the mindset that the public wants the TSA to have? Thanks to Fergie for pointing this out to me. Check out the SlightParanoia page for pics of the letter.

Wednesday, December 6, 2006

MS Word Remote Code Execution Zero-Day Alert

Via eWeek.com -

Microsoft on Dec. 5 warned that an unpatched vulnerability in its Word software program is being used in targeted, zero-day attacks.

A security advisory from the Redmond, Wash., company said the flaw can be exploited if a user simply opens a rigged Word document.



Secunia is rating it as "Extremely critical" in SA23232

CVE-2006-5994 has been reserved but contains no additional information at this time.

Inside the US National CounterTerrorism Center (NCTC)

Via BBC -

In a Washington suburb, I am on a journey. No address, no postcode. Just the phone number of a US government official known only as "T".

After months of requests, he has granted us permission to visit one of America's newest and most secret establishments: the National Counterterrorism Center, the NCTC.

It is a nondescript building, but inside is the beating heart of America's counter-terrorism nerve centre.

"This is where we maintain a 24-hours-a-day, seven-days-a-week operational watch in the counter-terrorism intelligence community and monitor situational awareness in the world of counterterrorism," says Vice Admiral Don Loren, one of the watch officers in the Operations Room.

The Operations Room is a large open-plan chamber filled with desks and computer terminals.

It is here in this room three times a day, every day, that America's specialists in counter-terrorism gather to share information.


But today it is almost empty. Because we are media, all the undercover agents from the Federal Bureau of Investigation, the National Security Agency and the Central Intelligence Agency who would normally sit here have been moved out of sight.

But up on the wall is a giant plasma screen showing every plane approaching the United States.

"Right now, you're looking at the Eastern Seaboard air corridor, and we use that to monitor events of special interest and to keep an eye should there be any reports of what we call no-fly activity," Vice Adm Loren says.

A "no-fly" means a plane with a passenger suspicious enough that the flight can even get turned back over the mid-Atlantic.

In everyone's minds is the thought: "9/11, never again."

Tuesday, December 5, 2006

Flatulence, Not Turbulence Forces Plane Landing In Nashville

Via WBIR.com -

Flatulence brought 99 passengers on an American Airlines flight to an unscheduled visit to Nashville early Monday morning.

American Flight 1053, from Washington Reagan National Airport and bound for Dallas/Fort Worth, made an emergency landing here after passengers reported smelling struck matches, said Lynne Lowrance, a spokeswoman for the Nashville International Airport Authority.

The plane landed safely. The FBI, Transportation Safety Administration and airport authority responded to the emergency, Lowrance said.

The passengers and five crew members were brought off the plane, together with all the luggage, to go through security checks again. Bomb-sniffing dogs found spent matches.

The FBI questioned a passenger who admitted she struck the matches in an attempt to conceal body odor, Lowrance said. The woman lives near Dallas and has a medical condition.

The flight took off again, but the woman was not allowed back on the plane."American has banned her for a long time," Lowrance said.

She was not charged but could have been. While it is legal to bring as many as four books of paper safety matches onto an aircraft, it is illegal to strike a match in an airplane, Lowrance said.

Mac OS X ftpd Buffer Overflow Vulnerability

A vulnerability has been reported in Mac OS X, which potentially can be exploited by malicious users to compromise a vulnerable system.

The vulnerability is caused due to a boundary error in ftpd when handling commands with globbing characters (e.g. "*") and can be exploited to cause a buffer overflow.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in Mac OS X 10.3.9 and 10.4.8. Other versions may also be affected.

http://secunia.com/advisories/23178/

Egypt Arrests American, Europeans In Terrorist Cell Case

Via FreeInternetPress.com -

Egyptian authorities said Monday that they had arrested an American and nearly a dozen Europeans after breaking up an international terrorist cell that was recruiting operatives to go to Iraq.

The Egyptian Interior Ministry said the cell was "related to some terrorist organizations abroad" but did not name the network or those arrested. The official Egyptian news agency MENA reported that the suspects included nine French citizens and two Belgians, as well as two Syrians, a Tunisian woman and an undisclosed number of Egyptians.

In Washington, State Department spokesman Sean McCormack said U.S. officials knew the identity of the American and are "seeking consular access to this individual". He said the U.S. suspect was arrested Nov. 26 but declined to name the person, citing federal privacy laws.

A U.S. law enforcement official said the U.S. citizen "was not on our radar at all" before his arrest in Egypt and is not named on the government's voluminous terrorism watch list.

"He was not a known figure to the U.S.," said the official. "There's no record of him in the sense that he would have been a person of concern."

A handful of U.S. citizens have faced charges of engaging in terrorism overseas since the Sept. 11, 2001, attacks.