<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/index.html" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.html" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.html" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.html" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.html" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.html" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.html" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.html">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.html">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.html">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">November, 2005 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>A number of California bay area school 
	districts inadvertently <a href="http://sfgate.com/cgi-bin/article.cgi?f=/c/a/2005/10/21/SNAFU.TMP">exposed private information on thousands of students</a> over the web.  
	A new information system was deployed with a widely-known generic 
	password for all teachers.  Be careful to avoid developing or deploying 
	applications with insecure default settings.</text></p></li><li>
			<p><text>A MySpace user created a <a href="http://www.betanews.com/article/CrossSite_Scripting_Worm_Hits_MySpace/1129232391">cross-site scripting worm</a> that added over 1 million friends to his 
	friends list.  MySpace had attempted to screen out &quot;Javascript&quot; from 
	user postings.  Web developers should &quot;whitelist&quot; acceptable data 
	rather than attempt to &quot;blacklist&quot; malicious data.</text></p></li><li>
			<p><text>A satellite TV business used <a href="http://www.wired.com/news/privacy/0,1848,68800,00.html?tw=wn_tophead_1">denial-of-service attacks to cripple its competitors</a>.  The 
	professional cyber-criminals involved are now pleading guilty.  In the 
	Netherlands, Dutch police busted a <a href="http://informationweek.com/story/showArticle.jhtml?articleID=171204550">botnet network of 100,000 zombie PC's</a>.  Cybercrime is committed 
	for profit, not for fun.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>A group of researchers has discovered a way to 
	<a href="http://www.newscientist.com.nyud.net:8090/article.ns?id=dn8208">eavesdrop through walls</a>, by using microwaves to detect vibrations 
	in your clothing when you speak.  Never underestimate the ingenuity of 
	your opponent.</text></p></li><li>
			<p><text>The popular Snort intrusion detection system 
	has a <a href="http://www.kb.cert.org/vuls/id/177500">vulnerability</a> which would allow a remote attacker to take over the 
	system it is running on.  Every additional component of your 
	infrastructure, even security components, creates potential for 
	additional vulnerabilities.</text></p></li><li>
			<p><text>Both <a href="http://secunia.com/advisories/16869">Firefox</a> and <a href="http://news.com.com/IE+flaw+puts+Windows+XP+SP2+at+risk/2100-1002_3-5868867.html?tag=nefd.top">Internet Explorer</a> (including an <a href="http://secunia.com/advisories/16942/">AJAX component</a>) web 
	browsers have newly discovered remotely-exploitable vulnerabilities.  
	As the Firefox browser becomes more widely-deployed it is been both 
	scrutinized and attacked more often.  Keep your systems up to date, and 
	be careful what you click on.</text></p></li><li>
			<p><text>The popular Skype messaging and voip software 
	announced a remotely-exploitable heap overflow vulnerability.  It's 
	important to keep informed and active on patches to your applications, 
	not just your operating system.</text></p></li><li>
			<p><text>Researchers a Penn State belive they have 
	uncovered a way to <a href="http://www.smsanalysis.org/">&quot;take-out&quot; a 
	cell phone system using SMS messaging</a>.  As major segments of our 
	infrastructure become computerized and connected to the Internet, they 
	also become vulnerable to external attack.</text></p></li></ul><h3 xmlns=""><news>News</news></h3>
		<ul xmlns="">
		<li>
			<p><text>Montebello Partners' Ames Cornish has been 
	elected as the President of the Executive Council for the <a href="http://sdforum.org">Software Development Forum</a>.  As if a 
	busy security consulting practice weren't enough, Ames volunteers for 
	SDForum and other silicon valley non-profits.</text></p></li></ul><h3 xmlns=""><event>Upcoming Events</event></h3>
		<ul xmlns="">
		<li>
			<p><text>The next SDForum <a href="http://lists.montebellopartners.com/listinfo/security-sig">Internet Security SIG</a> will be on Thursday, December 1st, on 
	physical security of wireless installations.</text></p></li><li>
			<p><text>The next bay area <a href="http://sfbay-infragard.org/">Infragard meeting</a> will be on 
	Thursday, November 17th, on disaster planning and recovery lessons 
	learned.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/index.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>