Skip to content

customize
Current Activity Calendar
Left Arrow
April 2008
Right Arrow
Su M Tu W Th F Sa
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • April 02, 2008 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    April 1PayPal Phishing Attack
    April 1Macrovision InstallShield ActiveX Vulnerability
    April 1Internal Revenue Service Scams
    April 1Storm Worm Activity Related to April Fools Day
    March 26Mozilla Releases Firefox 2.0.0.13
    March 26Cisco Releases Security Advisories
    March 26Novell eDirectory Vulnerability
    March 26VLC Media Player Vulnerability
    March 21Microsoft Jet Database Engine Vulnerability
    March 21Apple Aperture and iPhoto Vulnerability



    PayPal Phishing Attack

    added April 1, 2008 at 10:22 am

    US-CERT has seen reports of a phishing attack that targets PayPal users. The attack arrives via an unsolicited email message containing an HTML attachment. The message indicates that the attachment is a verification form intended to offer the user protection from fraudulent activity. Users who open the attachment are instructed to enter their email address and PayPal password. This information is then sent to an attacker.

    US-CERT encourages users to do the following to help mitigate the risks:


    Macrovision InstallShield ActiveX Vulnerability

    added April 1, 2008 at 10:21 am

    US-CERT has seen reports of a vulnerability in Macrovision InstallShield. This vulnerability is due to an error in the One-Click Install ActiveX control for InstallScript projects. This ActiveX control is used for loading DLL files. If a user visits a specially crafted website, a maliciously crafted DLL file may be loaded onto the user's system, allowing an attacker to execute arbitrary code.

    US-CERT encourages users to do the following to help mitigate the risks:

    • Review Macrovision Knowledge Base article Q113640 and apply the appropriate hotfix.
    • Set the kill bit for CLSID {53D40FAA-4E21-459f-AA87-E4D97FC3245A}.
    • Disable ActiveX as described in the Securing Your Web Browser document.


    Internal Revenue Service Scams

    added March 31, 2008 at 03:27 pm | updated April 1, 2008 at 10:20 am

    US-CERT is aware of a series of email scams circulating that are related to the United States Internal Revenue Service. Attacks have been observed that use email to convince users to perform the following actions:

    • open an email attachment containing bogus tax documents that are embedded with malicious code
    • follow a link to an unofficial tax website that contains malicious code
    • follow a link to an unofficial tax website that requests personal information from the users as part of a phishing attack
    • call an unofficial phone number that requests personal information from the user as part of a phishing attack
    US-CERT encourages users to do the following to help mitigate the risks:


    Storm Worm Activity Related to April Fools Day

    added April 1, 2008 at 08:29 am

    US-CERT is aware of a recent increase in Storm Worm activity. The latest activity is related to April Fools Day (April 1). This Trojan is spread via unsolicited email messages that attempt to convince users to follow a link to a malicious website. If a user follows this link, the Trojan may attempt to download and install itself on the user's system.

    Currently, this variant of the Storm Worm Trojan is being observed as having the following file names:

    • aromis.exe
    • foolsday.exe
    • funny.exe
    • kickme.exe
    Subject lines can change at any time, but the following are currently being seen:
    • All Fools' Day
    • Doh! All's Fool
    • Doh! April's Fool
    • Gotcha!
    • Gotcha! All Fool!
    • Gotcha! April Fool!
    • Happy All Fool's Day
    • Happy All Fools Day!
    • Happy All Fools!
    • Happy April Fool's Day
    • Happy April Fools Day!
    • Happy Fools Day!
    • I am a Fool for your Love
    • Join the Laugh-A-Lot!
    • Just You
    • One who is sportively imposed upon by others on the first day of April
    • Surprise!
    • Surprise! The joke's on you
    • Today You Can Officially Act Foolish
    • Today's Joke!
    US-CERT encourages users and administrators to do the following to help mitigate the risk:


    Mozilla Releases Firefox 2.0.0.13

    added March 26, 2008 at 08:23 am | updated March 26, 2008 at 02:27 pm

    Mozilla has released Firefox 2.0.0.13. This version addresses multiple vulnerabilities that may allow an attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information, or conduct cross-site scripting or phishing attacks.  As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect Thunderbird and SeaMonkey.

    US-CERT encourages users to do the following to help mitigate the risks:


    Cisco Releases Security Advisories

    added March 26, 2008 at 02:15 pm

    Cisco has released five security advisories to address multiple vulnerabilities in Cisco IOS. These vulnerabilities may allow a remote, unauthenticated attacker to cause a denial-of-service condition on the affected device.

    US-CERT encourages users to review the Cisco Security Advisories and apply the appropriate updates or workarounds.


    Novell eDirectory Vulnerability

    added March 26, 2008 at 08:23 am

    Novell has released Security Vulnerability document 3382120 to address a vulnerability in eDirectory. This vulnerability is caused by improper handling of large LDAP Extended Request messages. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users to review Novell document 3382120 and update to eDirectory 8.8.2.


    VLC Media Player Vulnerability

    added March 26, 2008 at 08:23 am

    VLC has released a patch to address an integer overflow vulnerability in VLC Media Player. By convincing a user to open an MP4 file with a specially crafted RDRF atom, a remote attacker may be able to execute arbitrary code.

    For users who compile VLC Media Player from source, VLC has provided a patch to address this issue.

    US-CERT will provide more information as it becomes available.


    Microsoft Jet Database Engine Vulnerability

    added March 21, 2008 at 09:54 pm

    Microsoft has released a Security Advisory to address a vulnerability in Microsoft Jet Database Engine. This vulnerability is due to a buffer overflow condition in msjet40.dll. By convincing a user to open a Word document that is designed to load a specially crafted database file using msjet40.dll, an attacker may be able execute arbitrary code.

    US-CERT encourages users to review Microsoft Security Advisory 950627 and apply the suggested workarounds.

    US-CERT will provide more information as it becomes available.


    Apple Aperture and iPhoto Vulnerability

    added March 21, 2008 at 10:14 am

    Apple has released Digital Camera RAW Compatibility Update 2.0 to address a vulnerability in Apple Aperture and iPhoto. This vulnerability is due to a boundary error that occurs when processing DNG image files. By convincing a user to open a specially crafted image file, a remote attacker may be able to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users to review Apple knowledgebase article HT1232 and apply any necessary updates.

    US-CERT will provide more information as it becomes available.