<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/index.html" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.html" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.html" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.html" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.html" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.html" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.html" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.html">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.html">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.html">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">September, 2004 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>Three men pleady guilty to <a href="http://www.securityfocus.com/news/9281">hacking into the Lowe's chain</a> of
		stores.  Two of them used an unsecured unencrypted wireless access point that
		provided access to internal corporate servers which stored credit card information.
		The third man, Timmons, pleaded guilty in the nation's first conviction for
		&quot;wardriving&quot;.  It was when he accessed his email and accidentally browsed a Lowe's
		server that the other two got the idea to steal credit card numbers.  Timmons faces
		up to 12 months in prison for unauthorized access to a protected computer.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>The recent BlackHat and DefCon cracker conferences in Las Vegas exposed a
		number of interesting hacker techniques.  Presenters showed how to use Google and
		the Google cache to find vulnerable information, and how to use Blue Tooth to get phone
		numbers and personal notes off of many popular cell phones.  Tom's hardware has a
		good <a href="http://www6.tomshardware.com/business/200408021/index.html">summary of
		the events</a>.</text></p></li><li>
			<p><text>A <a href="http://secunia.com/advisories/12188/">vulnerability was
		discovered</a> in the popular open-source Mozilla and Firefox web browsers.  This
		could let a malicious web site &quot;spoof&quot; elements of the interface using XUL, which
		could trick users into giving up passwords or installing back doors.</text></p></li><li>
			<p><text>Vulnerabilities were recently announced in both Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx">Internet
		Explorer's handling of &quot;GIF&quot; images</a>, and in the <a href="http://www.kb.cert.org/vuls/id/388984">&quot;libpng&quot; library for handling &quot;PNG&quot;
		images</a>.  Security researchers have long been warning that malicious code doesn't
		have to be placed in executable files at all.  It can be placed in something as
		innocuous as a simple image file, and then a faulty image display program can be
		tricked into running the malicious code.</text></p></li><li>
			<p><text>Clicking on a link in an AIM instant message can allow a remote attacker to <a href="http://www.infoworld.com/article/04/08/09/HNaolimflaw_1.html">take over your
		computer</a>.  This is an example of a trend for attackers to exploit weaknesses in
		all popular internet messaging clients including AIM, Yahoo, and MSN.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/index.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>