<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/index.html" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.html" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.html" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.html" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.html" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.html" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.html" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.html">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.html">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.html">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">March, 2003</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text><a href="http://www.cert.org/advisories/CA-2003-08.html">CERT</a> is reporting
	a dramatic increase in successful attacks on home broadband users. These
	attacks typically exploit weak passwords on Windows file shares, and
	concentrate on IP ranges of consumer DSL and Cable customers. A successful
	attack installs a hidden &quot;backdoor&quot; on the system, and tools for launching
	Distributed Denial of Service (DDoS) attacks from the system. All broadband
	users should have a software or hardware firewall, and should check their
	systems for any default or weak passwords. (Examples of weak passwords are
			&quot;password&quot;, a blank password, &quot;123&quot;, or any dictionary
			word.)</text></p></li><li>
			<p><text>Eight million credit card records were stolen from
	an east coast third-party processor. It is unclear if usable data,
	including cardholder names, was fully compromised. The companies involved
	have decided not to notify individual consumers, but will monitor the
	relevant accounts for fraud. All credit card holders should regularly check
	their bills and their <a href="http://www.experian.com/yourcredit/">credit
	reports</a> for unauthorized use.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>The most popular mail server software, Sendmail,
	has a serious buffer overflow vulnerability. SIG members have reported
	already seeing attacks based on this vulnerability. Anyone running Sendmail
	should install the appropriate <a href="http://www.cert.org/advisories/CA-2003-07.html">patches</a>.</text></p></li></ul><h3 xmlns=""><news>News</news></h3>
		<ul xmlns="">
		<li>
			<p><text>The Privacy sections of the <a href="http://www.sans.org/projects/hipaa.php">Health Insurance Portability and
	Accountability Act</a> (HIPAA) will take effect in April 21. HIPAA applies
	to all companies that transmit personal health-care information
	electronically. HR departments may be affected. Federal penalties for
	violations are up to $250,000 and 10 years in jail. Affected organizations
	must conduct a risk analysis and implement reasonable
	safeguards.</text></p></li><li>
			<p><text>A new California law, <a href="/sb1386.txt">SB
	1386</a>, will take effect on July 1st. The law requires all companies
	doing business with California customers (not just companies based in
			California), to promptly notify customers of possible compromise of
	private data including social security numbers and financial account
	numbers. If a company is unable to notify affected customers, they must
	feature notice of the compromise prominently on their website, and must
	alert national media. All companies which store personal data should review
	their security posture and their notification procedures.</text></p></li><li>
			<p><text>The FBI is creating a fifth <a href="http://www.nationalrcfl.org">Regional Computer Forensics Lab</a> in Menlo
	Park. This lab will support all law enforcement agencies in the area, and
	has an initial budget of $3,000,000. A company which is the victim of a
	possible cybercrime should take care to preserve evidence, and can contact
	the FBI Computer Intrusion Squad at (510) 886-7447.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/index.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>