Reichle & De-Massari (R&M, www.rdm.com), the Swiss structured cabling specialist, expands the security system for data networks with a lock for RJ45 patch cords. The name of this new product is Patch Guard. The plug-out protection consists of a plastic clamp with a locking mechanism that can be mounted tool-free at anytime. Users can attach and lock it in a few steps onto the cable end. The clamp blocks the unlatching lever of the RJ45 connector. As a result, only authorized people who have the compatible key can open the plug-out protection. This solution closes the last security gap in passive cabling.
According to Laurent Amestoy, Regional GM, R&M Middle East & Africa, Patch Guard is compatible with the standard RJ45 patch cords from R&M. In addition, Patch Guard can be color coded with colored clips from the R&M security system in order to avoid erroneous patching.
The plug-out protection with the security lock is appropriate for all data and communications networks with RJ45 patch cords — particularly in office, home and industrial cabling. For corporate networks it can be used together with its peripheral devices from the server room via active network components and distributors to the individual PC workstation.
Sudoku Puzzle Spyware
A new spyware program is particularly dangerous due to its enticing bait: A sudoku puzzle. The application in fact operates perfectly, allowing users to play the game. However, without users knowing, every time the application is opened, it downloads YazzleSudoku, a type of spyware, onto the computer.
Once YazzleSudoku is installed on a computer, it creates several Windows registry entries in order to ensure it remains active. Similarly, it generates a series of files that it needs to operate, with names such as RL_SudokuInstaller.rar.lnk, or Yazzle Sudoku. Then, from time to time, YazzleSudoku displays advertising messages on screen.
It is important to note that when starting to play the game, users are warned that spyware will be installed. If the user agrees, the spyware will be installed on the computer. However, if users do not agree, they will not be able to use the sudoku program.
According to Luis Corrons, director of PandaLabs, “Spyware is, without a doubt, one of the major threats to users. This type of malware clearly conforms to the current objective of malware creators: Earning money. Nevertheless, as the effects of spyware are not particularly obvious and do not appear to be dangerous, many users do not treat spyware with the respect it deserves. This however is a mistake, as spyware does not just slow down systems and cause errors, it also intrudes upon the privacy of users who should not consent to its installation.”
Notable Rise in Cybercrime
Symantec has released its ninth volume of the Internet Security Threat Report. The semiannual report, covering the six-month period from July 1-Dec. 31, 2005, marks an increase in threats designed to facilitate cybercrime.
While past attacks were designed to destroy data, today’s attacks are increasingly designed to silently steal data for profit without doing noticeable damage that would alert a user to its presence. In the previous Internet Security Threat Report, Symantec cautioned that malicious code for profit was on the rise, and this trend continued during the second half of 2005. Malicious code threats that could reveal confidential information rose from 74 percent of the top 50 malicious code samples last period to 80 percent this period.
“Cybercrime represents today’s greatest threat to consumers’ digital lifestyle and to online businesses in general,” said Arthur Wong, VP, Symantec Security Response and Managed Security Services.
The report also details the growing trend of attackers using bot networks, targeted attacks on web applications and web browsers, and modular malicious code. Based on this and data from previous reporting periods, Symantec expects to see more diverse and sophisticated threats used for cybercrime as well as an increase in the theft of confidential, financial and personal information for financial gain.
Cybercrime-related threats are gaining momentum through the use of crimeware, software tools built with the purpose of committing online scams and stealing information from consumers and businesses. Attackers are focusing their efforts on regional targets, desktops and web applications that may allow an attacker to steal corporate, personal, financial or confidential information; this information could then be used for additional criminal activity.
Programs that provide attackers with unauthorized control of a computer, known as bots, also contribute to the rise in cybercrime threats. Bot networks are increasingly used for criminal activities such as denial of service (DoS)-based extortion attempts. Symantec estimates that this measurement is only capturing a portion of global activity and that the actual infection numbers are likely to be much higher. On average, Symantec observed 1,402 DoS attacks per day, a 51 percent increase over the previous reporting period. Symantec speculates that this growth trend will continue.
In its previous report, Symantec speculated that attacks directed at web applications would increase. During the current reporting period, 69 percent of the vulnerabilities reported to Symantec affected web application technologies, a 15 percent increase over the previous period. Symantec has also seen an increase in modular malicious code, which initially possesses limited functionality but is designed to update itself with new, more damaging capabilities. Modular malicious threats often expose confidential information that can then be used in identity theft, credit card fraud or other criminal financial activities. During the last six months of 2005, modular malicious code accounted for 88 percent of the Top 50 malicious code samples reported to Symantec, up from 77 percent last period.
Additional key findings:
• Phishing threats, which are attempts to deceive users into revealing confidential information, continued to increase during the last half of 2005 while focusing on smaller, regional targets. During the last half of 2005, 7.92 million daily phishing attempts were identified, an increase over the 5.70 million attempts per day in the previous reporting period. Symantec expects to see an increase in the number of phishing messages and malicious code distributed through instant messaging services in the future.
• Symantec documented 1,895 new software vulnerabilities, the largest total recorded number of vulnerabilities since 1998. Of these, 97 percent were considered moderately or highly severe and 79 percent were considered easy to exploit.

