|
|
Log in / Subscribe / Register

Security

The Information Technology Security Handbook

The World Bank InfoDev Program has set itself a goal of helping computer users in developing countries avoid security problems. To that end, it has published the Information Technology Security Handbook; it can be downloaded from the site in PDF format. It is a very introductory-level book on security threats to computers and their users; if users at that level can be convinced to read the whole thing, it may well do some good. Unfortunately, however, this book does the developing world a disservice by being strongly biased toward proprietary software.

The "Security for Individuals" section, for example, contains a couple of pages on "non-traditional and non-commercial software." Topics covered are, in this order, shareware, open source software, and pirated software. The open source discussion gives a brief overview of the "which is more secure?" debate, and informs us:

The update processes for Open Source products tend to be more difficult that [sic] those for Windows, but are in line with other Unix products and the installation procedures for the original Open Source products.

The fact of the matter, of course, is that the major distributors have all made the application of security updates into a trivially easy task, which can even be automated. The above statement might have been true some years ago; it certainly is not true now.

The discussion of free software pretty much ends there. So, for example, we get a long section on email problems; infection via email is said to be "highly likely." Six rules are given for protecting a system from email-borne malware ("Do not open an attachment from someone you do know and trust unless you are sure that they sent it deliberately"), but there is no mention of the fact that email-borne malware is, for all practical purposes, unknown outside of the Windows world.

The "security for organizations" chapter is written in an entirely different voice. It covers a wide range of topics, including regulatory compliance, wireless security, personnel threats, etc. There is a lot of useful material there for somebody who is beginning to think about security in an organizational context, but no specifics at all. There is a section on government policy which has mostly to do with bureaucratic organization and the crafting of security-related legislation.

The final and largest section is aimed at technical administrators. Interestingly, this section is mostly oriented around Unix and Unix-like systems. The coverage is strange, however; NIS netgroups warrant several pages, while PAM is breezed over in a single page. There is a long section full of rules on writing safe CGI scripts, but nothing about web server setup. The chapter contains some good stuff, but it looks like it was gathered together from several different sources.

This handbook looks like a useful resource in many ways. It falls short of what a book on security for the developing world could be, however. Like the rich world, the developing world has no need to rely on expensive and insecure proprietary software. A book on information security on developing countries really owes it to its readers to point out that, with free software, they can take greater control over their systems and not have to rely on the good intentions of a large, foreign company.

Comments (1 posted)

New vulnerabilities

Cfengine: RSA Authentication Heap Corruption

Package(s):Cfengine CVE #(s):
Created:August 10, 2004 Updated:August 11, 2004
Description: Two vulnerabilities have been found in cfservd. One is a buffer overflow in the AuthenticationDialogue function and the other is a failure to check the proper return value of the ReceiveTransaction function. An attacker could use the buffer overflow to execute arbitrary code with the permissions of the user running cfservd, which is usually the root user. However, before such an attack could be mounted, the IP-based ACL would have to be bypassed. With the second vulnerability, an attacker could cause a denial of service attack.
Alerts:
Gentoo 200408-08 cfengine 2004-08-10

Comments (none posted)

cvstrac: arbitrary code execution

Package(s):cvstrac CVE #(s):
Created:August 6, 2004 Updated:August 11, 2004
Description: Richard Ngo reported on BugTraq that a vulnerability has been discovered in the CVS repository web browsing tool CVSTrac. If properly exploited an attacker can execute arbitrary code on the CVSTrac host with the privileges of the associated web server.
Alerts:
OpenPKG OpenPKG-SA-2004.036 cvstrac 2004-08-06

Comments (none posted)

opera: remote filesystem read access vulnerability

Package(s):opera CVE #(s):
Created:August 5, 2004 Updated:August 11, 2004
Description: The Opera browser has a vulnerability that may allow a remote attacker to read a local filesystem.
Alerts:
Gentoo 200408-05 opera 2004-08-05

Comments (none posted)

PuTTY: pre-authentication arbitrary code execution problem

Package(s):putty CVE #(s):
Created:August 5, 2004 Updated:October 28, 2004
Description: PuTTY, a telnet and SSH client, contains a vulnerability that can allow an SSH server to execute arbitrary code on a connecting client.
Alerts:
Gentoo 200410-29 putty 2004-10-27
Gentoo 200408-04 putty 2004-08-05

Comments (none posted)

shorewall: temporary file exploit

Package(s):shorewall CVE #(s):
Created:August 10, 2004 Updated:August 11, 2004
Description: Javier Fernández-Sanguino Peña has discovered an exploitable vulnerability in the way that Shorewall handles temporary files and directories. The vulnerability can allow a non-root user to cause arbitrary files on the system to be overwritten. LEAF Bering and Bering uClibc users are generally not at risk due to the fact that LEAF boxes do not typically allow logins by non-root users. The complete advisory is here.
Alerts:
Mandrake MDKSA-2004:080 shorewall 2004-08-09

Comments (none posted)

SpamAssassin: Denial of Service vulnerability

Package(s):spamassassin CVE #(s):CAN-2004-0796
Created:August 9, 2004 Updated:August 11, 2005
Description: SpamAssassin contains an unspecified Denial of Service vulnerability. By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin service.
Alerts:
Fedora-Legacy FLSA:129284 spamassassin 2005-08-10
Fedora-Legacy FLSA:2268 spamassassin 2005-03-24
Red Hat RHSA-2004:451-01 spamassassin 2004-09-30
Conectiva CLA-2004:867 spamassassin 2004-09-22
OpenPKG OpenPKG-SA-2004.041 spamassassin 2004-09-15
Mandrake MDKSA-2004:084 spamassassin 2004-08-18
Gentoo 200408-06 spamassassin 2004-08-09

Comments (none posted)

Page editor: Jonathan Corbet
Next page: Kernel development>>


Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds