<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/index.html" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.html" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.html" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.html" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.html" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.html" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.html" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.html">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.html">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.html">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">August, 2004 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>Miami-Dade County's touchscreen voting machine system crashed in
	May and in November of 2003, <a href="http://www.nytimes.com/aponline/national/AP-Florida-Voting.html">erasing information from gubernatorial primaries</a>.  Daily backups
	were not started until December 2003.  A Florida state rule prevents
	counties using touchscreen voting from conducting manual recounts.  At
	a recent SDForum Security SIG, Dr. David Dill of Stanford spoke on the <a href="http://www.verifiedvoting.org/">risks of electronic voting
	systems</a> with no paper audit trail.</text></p></li><li>
			<p><text>A number of leading web sites running Internet Information Server 5
	were compromised.  Malicious JavaScript was appended to the bottom of
	pages on these sites, which then in turn compromised end-user computers
	by installing backdoors and tools to collect banking passwords. No defensive
	patches were available at the time these attacks occurred.  The US CERT
	center recommends <a href="http://www.us-cert.gov/current/current_activity.html#iis5">disabling JavaScript if you use Internet Explorer</a>, even though
	some web sites will not display properly.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>A variant of the <a href="http://www.us-cert.gov/cas/alerts/SA04-208A.html">MyDoom
	worm</a> spread widely on July 26th, and interfered with Google and
	Yahoo search sites.  Many desktop computers have been left with
	&quot;back-doors&quot; that will allow the worm author to enter their system at a
	later date.</text></p></li><li>
			<p><text>Microsoft released a <a href="http://www.microsoft.com/security/bulletins/200407_windows.mspx">security bulletin</a> which identifies five separate Windows
	vulnerabilities which could allow remote attackers to
	run arbitrary code on your system.  Most of these are triggered by
	accidentally browsing a malicious web page with Internet Explorer, or
	by viewing a malicious html-formatted email with Outlook. Patch, patch, patch!</text></p></li><li>
			<p><text>A <a href="http://www.us-cert.gov/cas/techalerts/TA04-174A.html">vulnerability
	in the popular ISC open source dhcp server</a> could let malicious users on your local
	network execute arbitrary code.  Patch, and make sure your firewall is
	nice and tight!</text></p></li><li>
			<p><text>The two most popular wireless routers for the home have recently
	discovered vulnerabilities.  The LinkSys WRT54G's <a href="http://www.securityfocus.com/archive/1/364822">continues to allow
	remote administration</a> even if disabled in the configuration
	screens.  The Netgear WG602 <a href="http://www.securityfocus.com/archive/1/365069/2004-06-21/2004-06-27/2">allows remote administration</a> with the
	username &quot;super&quot; and the password &quot;5777364&quot;, even if the user has
	configured a different username and password.  Patches are available.</text></p></li></ul><h3 xmlns=""><event>Upcoming Events</event></h3>
		<ul xmlns="">
		<li>
			<p><text>The next <a href="http://sdforum.org/sigs/security">SDForum Security
	SIG</a> will feature venture capitalist
	Asheem Chanda of Greylock and CheckPoint, along with a re-cap of information from
	Defcon and Black Hat conferences.  The meeting will be in Palo Alto on
	Wednesday, August 25th.</text></p></li><li>
			<p><text>The next meeting of the <a href="http://www.sfbay-infragard.org">Bay Area
	Infragard</a> chapter will focus on current information security threats.
	The meeting will be held at the San Francisco Federal Reserve Bank on
	Thursday August 19th.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/index.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>