Gmail, Yahoo Mail join Hotmail; passwords exposed

Google's Gmail and Yahoo's Mail were also targeted by a large-scale phishing attack, perhaps the same one that harvested at least 10,000 passwords from Microsoft's Windows Live Hotmail, according to a report by the BBC. Microsoft , for its part, said late yesterday that it had blocked all hijacked Hotmail accounts, and offered tools to help users who had lost control of their e-mail. The BBC also said it has seen a list of some 20,000 hijacked e-mail accounts; the list included accounts from Gmail, Yahoo Mail, AOL, Comcast and EarthLink. Gmail was the target of what Google called a large-scale phishing campaign, the company told the BBC . "We recently became aware of an industry-wide phishing scheme through which hackers gained user credentials for Web-based mail accounts including Gmail accounts," a Google spokesperson told the news network. The latter two are major U.S. Internet service providers. "As soon as we learned of the attack, we forced password resets on the affected accounts," the Google spokesperson also told the BBC. "We will continue to force password resets on additional accounts when we become aware of them." Neither Google's or Yahoo's U.S. representatives responded to e-mails from Computerworld seeking confirmation that their Gmail and Yahoo Mail services were targeted by phishers, or answers to questions about how many accounts had been compromised and what the firms are doing to help users.

Late Monday, Microsoft said it was blocking access to all the accounts whose details had been posted on the Web last week. "We are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts," the company said on its Windows Live blog . Microsoft posted an online form where users who have been locked out of their accounts can verify their identity and reclaim control, and also pointed users to a support page from October 2008 that spells out steps users can take if they think their accounts have been hijacked. Neowin.net, the site that first reported the Hotmail account hijacking early Monday, today added that it had seen the same list of compromised accounts as the BBC. "Neowin can today reveal that more lists are circulating with genuine account information and that over 20,000 accounts have now been compromised," said the Windows enthusiast site . "[The] new list contains e-mail accounts for Gmail, Yahoo, Comcast, EarthLink and other third-party popular Web mail services." Microsoft has acknowledged that log-on credentials for "several thousand" Hotmail accounts had been obtained by criminals, probably through a phishing attack that had duped users into divulging their usernames and passwords. After a slump earlier this year, phishing attacks are on the upswing, according to the Anti-Phishing Working Group (APWG). Its most recent data - for the first half of 2009 ( download PDF ) - noted that the number of unique phishing-oriented Web sites had surged to nearly 50,000 in June, the largest number since April 2007 and the second-highest total since the industry association started keeping records. Yesterday, Dave Jevans, the chairman of APWG, called the Hotmail phishing attack one of the largest ever, but cautioned that the usernames and passwords may have been harvested over several months, and not by a single, defined attack.

Users nervous about Oracle's acquisition of MySQL

The European Union is not the only one antsy about Oracle taking possession of the open source MySQL database should the commercial database giant's merger with Sun Microsystems get final approval. On its Web site, Oracle merely notes that "MySQL will be an addition to Oracle's existing suite of database products." "I wish that Oracle would broadcast its intentions a little bit more" on the Sun acquisition, says Duane Kimble, a Linux technologist who works in the banking industry. So are MySQL users. (The E.U.'s executive arm has held up approval of the merger, fearing that Oracle's acquisition of MySQL could reduce competition in the database market, as well as harm the open source nature of MySQL. Sun's stockholders and the U.S. Justice Department have approved Oracle's $7.4 billion acquisition of Sun.) "We've got a fair number of databases and Web applications that use those databases in MySQL. If Oracle does something that sort of makes it look like MySQL's days are numbered or something is going to change that we don't like, we'll probably look at alternatives," says Ernest Joynt, a contractor for the National Oceanic and Atmospheric Administration. [ Relive Sun's storied history in InfoWorld's slideshow "The rise and fall of Sun Microsystems." | Learn why attendees at the JavaOne conference were skeptical of Oracle's buyout of Sun. ] Anand Babu Periasamy, CTO of clustered storage technology company Gluster, expresses doubts that Oracle would add enterprise capabilities to MySQL. "I hope that they will retain MySQL. [But] I am doubtful [that] they will ever improve MySQL to take it mid-enterprise level, but at least it will help them compete with Microsoft SQL Server on the low end," he says. (Gluster uses MySQL for its Web site operations.) Thus far, Oracle has said little about its intentions for MySQL and declined to discuss the issue with InfoWorld. For him, Oracle's ownership of MySQL is a specific cause for caution.

His firm has begun looking at other enterprise-scale open source databases such as EnterpriseDB's Postgres database in case it has to replace MySQL. Standing to reap a harvest from unease about the Oracle-MySQL pairing are open source database vendors EnterpriseDB and Ingres. MySQL users start looking at alternatives A key issue is that Oracle is a main competitor to MySQL, notes Timothy Dion, CTO of mobile and Web apps builder Sensei. "I'm very concerned about what that means," he says. EnterpriseDB, which builds its products on the PostgreSQL open source database, has been hearing from concerned MySQL users, says Larry Alston, EnterpriseDB's vice president of product management and marketing. "They're telling us that they're nervous" about the future of MySQL, he says. Doubts remain over the fate of other Sun technologies Users remain concerned over the fate of other Sun technologies such as Java and Solaris, not just of MySQL. "We are rethinking our Solaris deployments," says Linux technologist Kimble. "We are moving swiftly toward more of an AIX and Linux environment, depending on the size or the scale of the project." Although Kimble notes it is "too early to say whether we'll move off [Solaris] or not," he does say his employer is rethinking its Solaris commitment: "Certainly, we're not going full-bore with Solaris as we were before the merger." Kimble does see a positive side to the Sun acquisition: "I think it kind of simplifies the platform offering somewhat. Ingres also sees opportunities. "The phones ring a lot," says Ingres CEO Roger Burkhardt. Oracle is a strong company and if they keep Sun Java, which I'm sure is what they bought [Sun] for, I think it will make Java a better product." But Bryce Pier is not so sure.

Another large company buying another large company reduces competition," he says. The senior systems engineer at Target sees no benefits of the buyout - at least not yet. "I'm not really certain that it's going to be good for anybody. Pier expects the acquisition to cause Target to move away from Solaris to Red Hat's Linux over time. Oracle, said Craig Muzilla, Red Hat's vice president for middleware, was very active in the Java Community Process for updating Java and has strived for openness in Java. "We don't see anything from Oracle that [would indicate that] they would do anything" that would differ with the past, he said. One reason is the uncertainty: "We're just not sure what Oracle's commitment is going to be to the Java stack and to maintaining it as an open source project." Another is Oracle's reputation for extracting revenues from customers: "We certainly fear that all of the subscription fees are going to change for everything from Sun." At its recent conference, Red Hat sought to reassure customers about the continued openness of Java-based JBoss technology, which Red Hat owns, now that Oracle is buying Java founder Sun.

Microsoft Internet Explorer SSL security hole lingers

Microsoft still does not acknowledge a weakness in its Internet Explorer browser that was pointed out seven weeks ago and enables attackers to hijack what are supposed to be secure Web sessions. If Microsoft doesn't fix the problem, Apple can't fix it on its own, Apple says. The company says it is still evaluating whether the weakness exists, but Apple, which bases its Safari for Windows browser on Microsoft code, says Safari for Windows has the weakness and the Microsoft code is the reason.

Apple has fixed the problem for Safari for Macs. Once our investigation is complete, we will take appropriate action to help protect customers," a Microsoft spokesperson said via e-mail. "We will not have any more to share at this time." The weakness can be exploited by man-in-the-middle attackers who trick the browser into making SSL sessions with malicious servers rather than the legitimate servers users intend to connect to. Black Hat's most notorious incidents: a quiz "Microsoft is currently investigating a possible vulnerability in Microsoft Windows. Current versions of Safari for Mac, Firefox and Opera address the problem, which is linked to how browsers read the x.509 certificates that are used to authenticate machines involved in setting up SSL/TLS sessions. The attacks involve getting certificate authorities to sign certificates for domain names assigned to legitimate domain-name holders and making vulnerable browsers interpret the certificates as being authorized for different domain-name holders. In July two separate talks presented by researchers Dan Kaminski and Moxie Marlinspike at the Black Hat Conference warned about how the vulnerability could be exploited by using what they call null-prefix attacks.

For instance, someone might register www.hacker.com. In that case, the authority would sign a certificate for bestbank.hacker.com, ignoring the sub-domain bestbank and signing based on the root domain hacker.com, Marlinspike says. In many x.509 implementations the certificate authority will sign certificates for any request from the hacker.com root domain, regardless of any sub-domain prefixes that might be appended. At the same time, browsers with the flaw he describes read x.509 certificates until they reach a null character, such as 0. If such a browser reads bestbank.com\0hacker.com, it would stop reading at the 0 and interpret the certificate as authenticating the root domain bestbank.com, the researcher says. An attacker could exploit the weakness by setting up a man-in-the-middle attack and intercepting requests from vulnerable browsers to set up SSL connections.

Browsers without the flaw correctly identify the root domain and sign or don't sign based on it. If the attacking server picks off a request to bestbank.com, it could respond with an authenticated x.509 certificate from bestbank.com\0hacker.com. The user who has requested a session with bestbank would naturally assume the connection established was to bestbank. The vulnerable browser would interpret the certificate as being authorized for bestbank.com and set up a secure session with the attacking server. Once the link is made, the malicious server can ask for passwords and user identifications that the attackers can exploit to break into users' bestbank accounts and manipulate funds, for example, Marlinspike says. These certificates use an asterisk as the sub-domain followed by a null character followed by a registered root domain.

In some cases attackers can create what Marlinspike calls wildcard certificates that will authenticate any domain name. A vulnerable browser that initiated an SSL session with bestbank.com would interpret a certificate marked *\0hacker.com as coming from bestbank.com because it would automatically accept the * as legitimate for any root domain. Such a wildcard will match any domain, he says. This is due to "an idiosyncrasy in the way Network Security Services (NSS) matches wildcards," Marlinspike says in a paper detailing the attack. The differences between what users see on their screens when they hit the site they are aiming for and when they hit an attacker's mock site can be subtle.

A Microsoft spokesperson says Internet Explorer 8 highlights domains to make them more visually obvious, printed in black while the rest of the URL is gray. "Internet Explorer 8's improved address bar helps users more easily ensure that they provide personal information only to sites they trust," a Microsoft spokesperson said in an e-mail. The URLs in the browser would reveal that the wrong site has been reached, but many users don't check for that, Marlinspike says. Marlinspike says the null character vulnerability is not limited to browsers. "[P]lenty of non-Web browsers are also vulnerable. Outlook, for example, uses SSL to protect your login/password when communicating over SMTP and POP3/IMAP. There are probably countless other Windows-based SSL VPNs, chat clients, etc. that are all vulnerable as well" he said in an e-mail.

Ncomputing kit talks to virtual desktops over USB

Ncomputing is launching a device that can be used to add a virtual client to a host PC via a USB connection. Multiple U170 boxes can add extra users to a host machine, which can be cheaper than buying separate machines, said Carsten Puls, vice president of strategic marketing at Ncomputing. The U170 can run full multimedia applications when it is connected to a host machine's USB port. The device has a video port, audio port and two USB ports for the keyboard and mouse. "The only thing you have to connect back to the PC is a single USB connection," Puls said.

Users must still buy a monitor and peripherals to complete a workstation. The device is priced at US$99 and will be available by the end of the year, Puls said. Beyond reducing the need for a PC, the device also helps reduce energy costs, Puls said. Virtual desktop software from Ncomputing called Vspace on host machines sets up individual desktops as new U170 boxes are connected. It draws about 2 watts of power, Puls said, far less than a full clients PC. In this case, the USB cable takes the place of the Ethernet cable for a client to communicate with a host machine. One host PC can support up to four boxes.

The typical USB cable extends up to five feet, but USB extenders can lengthen that. Vspace is compatible with multiple versions of Windows, including Microsoft's upcoming Windows 7 OS. The company is targeting small-and-medium businesses with the device. The company has set up configurations where the device connects to PCs from up to 50 feet. The company has other products that let users access host PCs over Ethernet. USB has advantages as the ports are included on most PCs, but over longer distances it may be better to use Ethernet, Puls said.

Hackers exploit year's fourth PDF zero-day

For the fourth time this year, Adobe has admitted that hackers were using malicious PDF documents to break into Windows PCs. The bug in the popular Reader PDF viewer and the Acrobat PDF maker is being exploited in "limited targeted attacks," Adobe said yesterday. Adobe promised to patch the vulnerability on Tuesday, Oct. 13, the same day that Microsoft plans to issue its biggest-ever collection of security updates . The bug exists in Reader and Acrobat versions 9.1.3 and earlier on Windows, Mac OS and Linux, said Adobe in a security advisory published Thursday, but as far as the company knows, it is being exploited only to hijack Windows PCs. "There are reports that this issue is being exploited in the wild in limited targeted attacks," said Adobe. "The exploit targets Adobe Reader and Acrobat 9.1.3 on Windows." Adobe will plug the hole next week as part of its quarterly security update for Reader and Acrobat. That phrasing generally means hackers are sending the rigged PDF documents to a short list of users, oftentimes company executives or others whose PCs contain a treasure trove of confidential information. Last June, Adobe announced it would follow the lead of companies like Microsoft and Oracle, and release regular security updates for Reader and Acrobat.

It said more than a month ago that it would instead push the patch date into October. Originally, Adobe was to post patches last month, but a scramble during July to fix several flaws, including some introduced by Microsoft in a code "library" used by its own developers, as well as those in other companies, wreaked havoc on Adobe's schedule. Until a patch is released next week, Windows Vista and Windows 7 users can protect themselves by enabling Data Execution Prevention (DEP), a security feature designed to stop some kinds of exploits - buffer overflow attacks in particular - by blocking code from executing in memory that's supposed to contain only data. Windows XP users should disable JavaScript in Reader and Acrobat, added Adobe. Instructions on how to enable DEP are available on Microsoft's support site.

That wouldn't block all possible attacks, but will stymie the exploit now in the wild. In March, the company quashed a PDF bug that attackers had been using for more than two months . It again patched Reader and Acrobat in May to block another zero-day . In July Adobe fixed a Flash PDF-related flaw that was being used by hackers. Adobe has struggled this year to stay ahead of hackers. Next Tuesday's Reader and Acrobat updates will also patch a unknown number of other vulnerabilities, Adobe said.

Malware Threat Emanates from Growing Unemployed Ranks

Looking at the statistics, February was a positively brutal month for workers being idled. There were 2,769 mass layoff actions putting throwing 295,477 out of work. Last Friday, the Bureau of Labor Statistics (BLS) released the ugly numbers. That's 542 mass layoff actions more than January and 57,575 laid off.

The BLS only obliquely breaks out what could represent IT workers as "professional and technical services." Not surprisingly, manufacturing bore the brunt of February's layoffs accounting for 47% of the unemployment claims, but IT folks could represent a small piece in all the 19 industry sectors that BLS follows. I wondered how many of those were IT people and what percentage might turn to cyber crime. Suffice it to say there's plenty of IT folks with little or nothing to do. The story explores how idled workers in China are turning to cyber crime. That out of work IT professionals turn to cyber crime should come as no surprise so the headline China becoming the world's malware factory on top of an IDG News service is to be expected.

Everyone needs to be vigilant (but not turn into vigilantes). Indeed, a story at Chief Security Officer cites a Symantec study that says 98 percent of organizations suffer "tangible loss" as the result of cyber crime (more than a little self-interest on Symantec's part should be noted). With the third variant of the Conficker worm set to strike on April 1, take the message of vigilance to heart (let's hope it's as tepid as Y2K). By the way, the BBC reported this morning that the U.K. Government is monitoring social networking sites like Facebook to "tackle criminal gangs and terrorists." That's vigilance of a controversial nature. It's obvious: the latter. Is this just another day in the cyber jungle or is the cyber crime problem exacerbated by the expanding ranks of the idled? So if you want to freshen up your knowledge of malware, check out the many primers on the subject. I like Wikipedia's or check out the Chief Security Officer web site.

ProMOS plans to sign R&D pact with Taiwan Memory

ProMOS Technologies may soon sign a deal to work on DRAM manufacturing technology with Taiwan Memory Company (TMC), the government-sponsored entity designed to take over debt-ridden DRAM makers in Taiwan. "We have reached a mutual understanding to start working with them," ProMOS vice president Ben Tseng said by phone on Monday. ProMOS has been manufacturing DRAM in Taiwan since 1996 and was the first company on the island to run a factory making chips on 12-inch wafers. The cooperation will begin with research and development work, but Tseng says ProMOS is hopeful it will turn into a manufacturing partnership as well. "It only makes sense," he said. "Once the R&D is done, then you do the manufacturing on the same site." TMC could not immediately be reached for comment.

TMC is a brand-new company designed by the government to bail out its heavily indebted DRAM makers. DRAM prices have rallied over the past several months, recently hitting profitable levels for most DRAM companies. Taiwan's five big DRAM makers ran into financial trouble amid the global recession and after suffering two years of losses caused by a massive chip glut. Before ProMOS and TMC can enter an agreement, TMC needs to finalize its funding plans. The company slashed production as the DRAM downturn bit, and is currently producing chips on fewer than half of its production lines. The Taiwan government has discussed investing NT$30 billion (US$925.9 million) in the new company, while TMC chairman John Hsuan has said private investors will also be invited to put money into TMC. ProMOS needs money to move forward.

It has used up most of its cash paying off debt. The coming launch of Microsoft's new operating system, Windows 7, has stirred demand for new PCs and they need DRAM chips inside. New funds from TMC would help ProMOS reopen closed factories just as DRAM prices are hitting profitable levels. Tseng said his company must also soon decide whether to invite workers back full time after keeping some on unpaid leave for months due to the global recession. Once the company ends the unpaid leave, however, it will have to start paying full salaries again. Under Taiwanese labor law, companies putting workers on unpaid leave must do so for fixed periods of months at a time, but ProMOS may need them back quickly to ramp up factory lines if it signs a deal with TMC soon.