
Hackers could exploit content checking and antivirus products...
By Andy McCue
Published: 13 September 2004 13:20 GMT
The body responsible for protecting the UK's critical national infrastructure against electronic attack has issued an urgent alert to users about eight serious new security flaws affecting hundreds of email gateway products.
The National Infrastructure Security Co-ordination Centre (NISCC) alert (issued by UNIRAS - the UK equivalent of CERT) warns that flaws in the MIME internet email protocol extension could, if exploited, allow hackers to bypass content checking and antivirus tools and launch denial of service attacks.
MIME is a standard for encoding attachments to emails and is used in email clients, web browsers, antivirus products and content checkers.
The vulnerabilities can be exploited with "malformed" subjects using multiple occurrences of fields, non-standard presence of whitespace and non-standard quoting to evade content checking functionality. This could allow malicious code through content filtering and antivirus software.
It is over a year since the flaws were discovered by security consultancy Corsaire after working on arge insurance company's email system.
Corsaire said it passed details of the vulnerabilities onto the NISCC last summer because of the scale of the problem and the co-ordination needed between vendors to fix their products.
Many vendors have already silently issued patches for the flaws and Apple, HP, MessageLabs and Mozilla have already declared their products are not affected by the vulnerabilities.
Antivirus company F-Secure has confirmed its Internet Gatekeeper server products are vulnerable and that this will be fixed in the next release, scheduled for the fourth quarter this year.
Dealing with both permanent and contracts administration, including responsibility for logging all new jobs, checking candidate coversheets, ...
Candidates must have thorough experience of web application penetration testing which include both knowledge and experience in Man in the Middle ...
Planning and application of system software patches to fix problems. Use of the current processes/tools to assist with security health checking and ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Is Your Enterprise Architected for Tomorrow's Growth?
Improving IT service delivery through an integrated approach to software asset management...
TechRepublic Resource Guide: Software as a Service (SaaS) for Small and Midsize Businesses...
Download a Free Trial of SmartDraw: Learn why SmartDraw is the ideal alternative...
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy