Australia's Leading Computer Emergency Response Team

AusCERT is 15!
Date: 09 March 2008
Original URL: http://www.auscert.org.au/render.html?cid=7066&it=8924


Greetings,

This week has been reasonably quiet with the exception of new versions of Suns Java JRE and JDK. These new versions correct some reasonably serious vulnerabilities - serious enough for US-CERT to push a Technical Cyber Security Alert for them.

     http://www.us-cert.gov/cas/techalerts/TA08-066A.html

Lighttpd has also been patched fixing multiple vulnerabilities. Now, I know when I think "Web Server" I think Apache or IIS, but many small and/or embedded devices that have web interfaces that use lighttpd. There are many sites and devices that use it:

     http://trac.lighttpd.net/trac/wiki/PoweredByLighttpd

This week Cisco announced that they are changing the publication schedule for the Cisco Internetwork Operating System (IOS) Security Advisories. Starting this March 26, they will only release advisories on the fourth Wednesday of the month in March and September. They advised that their reasoning for the change is due to "extensive feedback from customers, who seek further predictability for support planning and deployment cycles". The announcement is available on their website:

     http://www.cisco.com/go/psirt

Finally, we have have released an update to our paper "Protecting your computer from Malicious Code". This update includes information for Mac and Linux based personal computers as well as an update of the content. For those of who who jumped the gun and viewed it last week (it was linked to from the "Practical Computer Security slides") you can now view the updated version as the latest installment in Fraud Fortnight.

     http://www.auscert.org.au/AntiMalware

More conference news, the schedule has been updated and the tutorial program is now available:

     http://conference.auscert.org.au/conf2008/program_schedule.html

Also for quick access the registration page (including tutorials) is available from here:

     http://conference.auscert.org.au/conf2008/reg_transition.php?type=delegate

I should also mention AusCERT is fifteen years old on the 8th of March. Happy birthday to us... happy birthday to us... Ok I'll stop now.

Have a great weekend everyone - put down the keyboard!

Regards,


Zane