Network and Computer Security

The Network and Computer Security Blog

Bookmark this site!

July 29, 2006

More and more flaws found in Microsoft Office

Filed under: News, Vulnerabilities, Windows — SecuNews @ 9:21 pm

The last Microsoft Office version appears to contain lots of vulnerabilities; so much in fact that many experts fear a new macro-virus like Melissa is quite likely to appear very soon.

Since the end of 2005, about 20 vulnerabilities have been found in Office; that’s more than enough for the virus and worm writers out there to find an easy to exploit one and to take over all the machines with the lastest Office (Word, Excel, PowerPoint, Outlook, and, for professional users, Access) installed.

The problem is even more accute that in takes an average of 4 months to Microsoft to issue patches fixing security problems; so as the number of known vulnerabilities increases tons of systems remain vulnerable.

Read more here: Flaw finders lay siege to Microsoft Office

July 24, 2006

Why popular antiviruses still don’t work well

Filed under: Virus, Articles — SecuNews @ 12:13 pm

It’s no news that no antivirus is 100% safe.

It has always been that way and will always be. The answer is simple: there are actually very few antiviruses sharing the biggest market share (the top 5 AVs most likely represent more than 95% of the installed base). So the virus writters can very quickly check their “lastest,not-released-in-the-wild-yet” virus and see which antivirus applications detect it as a malware and modify it accordingly.

ZDNet just published a good paper on the subject: Why popular antivirus apps ‘do not work’?

July 17, 2006

OSSIM: Be aware of your security

Filed under: Tools, Linux, Software — SecuNews @ 10:02 am

I’ve already featured some tools here like Nmap, OSSEC and Honeytrap, but I’m not talking about security tools nearly enough.

So this time let me introduce you to OSSIM. OSSIM stands for Open Source Security Information Management and aims to unify network monitoring, security, correlation, and qualification in one single tool. It combines Snort, Acid, MRTG, NTOP, OpenNMS, nmap, nessus and rrdtool to provide the user with full control over every aspect of networking or security. It has always been long and painfull to install and maintain many security tools at once and OSSIM allows to benefit from the best security tools in an easy and integrated way.
OSSIM has been under heavy development for a few years now and the last release (0.9.9rc2) is much easier to install than the previous versions.

If you’re in doubt you can get a feel at how it looks by looking at those OSSIM screenshots.

Links:

July 15th edition of Bruce Schneier’s CRYPTO-GRAM

Filed under: Articles, Newsletters — SecuNews @ 9:27 am

The July 15th issue of Bruce Schneier’s Crypto-Gram newsletter is out.

As usualy, plenty of great articles that give a real insight into what matters as far is computer security is concerned. In particular, make sure you read the “Economics and Information Security” article, as it’s the best I’ve read on this subject so far!

Here’s the summary of the newsletter:
Economics and Information Security
Crypto-Gram Reprints
Google and Click Fraud
A Minor Security Lesson from Mumbai Terrorist Bombings
News
Getting a Personal Unlock Code for Your O2 Cell Phone
The League of Women Voters Supports Voter-Verifiable Paper Trails
Brennan Center and Electronic Voting
Comments from Readers

July 1, 2006

Want to know that the best antivirus software is?

Filed under: News, Virus, Articles — SecuNews @ 11:25 am

We’re all wondering which antivirus is the best one to protect our servers.

The guys from Nephentes wondered the same thing and took the time to submit a sample of 4987 viruses to 14 antivirus softwares running on *nix platforms (some free some not).

The full study is here, but if you’re impatient here’s the summary:

Rank Product Hit Rate Trend
1 Antivir 99,04% +7,07%
2 BitDefender 96,23% +1,52%
3 VirusBlokAda 95,17% +1,42%
4 F-Prot 94,02% +2,39%
4 Authentium 94,02% new
5 Norman Virus Control 93,78% +1,19%
6 Fortinet 87,29% +2,35%
7 F-Secure Antivirus 85,22% +5,99%
8 Kaspersky 85,10% +5,73%
9 VirusBuster 82,53% +11,76%
10 Trend Micro 76,19% +5,14%
11 ClamAV 71,41% -0,85%
12 NOD32 70,06% +4,05%
13 Sophos SWEEP 68,58% +2,45%
14 eTrust 63,97% new

(Note: the ‘Trend’ percentage is the variation between the current test and the previous one)