Anti-virus

Anti-virus solutions and rectification

Cisco and Other Vendors Vulnerable to Denial of Service (DoS) flaws

The Finnish Computer Emergency Response Team (CERT-FI) has released an alert which lists a number of vendors that have reported vulnerability to a new Denial of Service (DoS) vulnerability.  A DoS attack on the flaw can cause network devices to crash or lockup generating service outages for your network.

The vulnerability was discovered by researchers utilising a testing tool known as Sockstress, but can be replicated by flooding a device with specially crafted data packets (TCP packets in particular).

Below is a list of the affected vendors and links to their alerts:

[AzTechNotes] Web Hosting FTP virus warning - GUMBLAR

Attn: Aztech Hosting Clients and AztechNotes Subscribers,
 
Firstly, apologies if you receive this email twice because you are on both lists but I thought it worth making sure everyone receives this virus warning.
 
It has been quite some time since we have seen a security alert that is worth passing on, however there is a growing concern in the security fields regarding a virus commonly known as "Gumblar".  The virus is named after the original Chinese domain name (gumblar .cn) that hosted the malicous code, but this site has since been closed and an alternative domain has been established.
 

McAfee Groupshield 7.0.1 Anti-Spam Rules Updater service not updating

If you notice your Anti-SPAM rules in McAfee Groupshield 7.0.1 for Exchange are not updating and probably reflecting a date in November 2008, then the McAfee knowledgebase article below may resolve your issue and restarting the streaming updater service.

After the completion of the steps below, your Anti-SPAM rules should be updated to the current date / time to reflect the correct operation.

====================================================

Junos to include Embeded Security Applications (UTM, Anti-SPAM, Anti-Virus, Web filtering)

Juniper Networks has extended the functionality of its Junos network operating system with the inclusion of a range of embedded security applications.

McAfee Strategic Security Summit - Sydney Australia

McAfee Security

 

Aztech Networks would like to invite all of its customers to the McAfee Strategic Security Summit which is on Friday July 17 2009 at the Sydney Convention and Exhibition Centre in Darling Harbour (Sydney) Australia.

The full invitation and details can be found below or at this link. I hope everyone can make it to what promises to be this years premier security industry conference.

Regards,

Aaron Wheeler (Aztech Networks Pty Ltd)

ERROR: setup detected an error reading db.properties file required to continue installation (issue: TCP/IP Dynamic Port used)

Courtesy McAfee KB: KB53935

Environment

McAfee ePolicy Orchestrator 4.0 Patch 2
Microsoft Windows (all supported versions, see KB51109 )

Problem 1

The following error reported when installing ePolicy Orchestrator 4.0 Patch 2:

Microsoft Patch for high cpu (100%) usage by svchost

Micrsoft patch released for the 100% CPU utilisation by svchost problem during software update checks.

If you are one of the millions of customers that have experienced the problem of high cpu use by svchost when the system checks for updates, then relief is at hand.  The most common symptom is extremely poor performance after initial boot and a check of processes in Task Manager shows "svchost.exe" using 100% cpu.

TCPView from Sysinternals

 

A great little utility I use all the time is TCPView from Sysinternal (MS Technet). 

 

This little program shows you which application is using which TCP or UDP ports on your workstation.  It is fantastic for identifying what is generating outgoing connections from a PC.  Particularly with todays prevelant amount of Malware / Spyware out there, it is great to see what is happening on your PC in the background (usually without your knowledge).

[AzTechNotes] Phishing Season is open and Flash Player Vulnerability

Hi Everyone,

 

It has been a while since my last TechNote, which might really mean good
news.  If I haven't had to send out any security alerts, then that is a good
thing. Eye-wink

The only really pertinent alert in the last month is a security
vulnerability of "Adobe Flash Player" which is exploited when you visit a
malicious Flash (.swf) file.  There is no patch for the player, so best
defence is really to avoid any suspect sites (which is always good advice).
 

[AzTechNotes] New Government Security Awareness Website and Alerts for SMB

Hi All,

This week is National E-security Awareness Week, which is a Government
initiative aimed at boosting awareness of e-security risks.  To kick-off the
week, the government has announced a new subscription-based "Stay Smart
Online Alert Service" to help Australian Internet users stay up-to-date on
the latest security threats.

The government also has a very helpful website which provides good
information for home users and Small Businesses about "Staying Safe Online".
You can check the site out at: http://www.staysmartonline.gov.au/

For those interested in subscribing to the alert service, it can be found at
http://www.staysmartonline.gov.au/e-sec ... ice.  Otherwise, you
can always just keep up with AzTechNotes for any major threats Eye-wink.

Regards,
Aaron