Security roundup: Crazy Microsoft botnet takedown; hot biometrics; not so hot romance scams; Facebook in trouble again

30.09.2011

Facebook tracking prompts call for FTC probe

Facebook's has landed the social network in hot water, with two lawmakers calling for a Federal Trade Commission (FTC) investigation. Rep. Ed Markey (D-Mass.) and Rep. Joe Barton (R-Tex.) wrote an open letter Wednesday urging FTC Chairman Jon Leibowitz to look into Facebook's tracking of its users even after they log out of the site. The issue came to light just days after an Australian blogger published data showing that Facebook is gathering information on the online activities of its users.

Cisco issues security warnings

Cisco this week issued a slew of on several vulnerabilities in its IOS software. In all, there look to be eight or nine advisories on IOS, dealing with issues like IPv6 over MPLS, IP service level agreements, SIP, NAT, IPv6 DoS and more. Cisco also issued advisories on a DoS condition with its 10000 series routers, a SIP memory leak in its Unified Communications Manager VoIP software, and a DoS condition in its Jabber instant messaging software. For some of the vulnerabilities, Cisco has already issued bulletins on how to identify and mitigate the conditions.

The IPv6 DoS vulnerability is one in which no mitigation bulletin has yet been published. The condition could allow an unauthenticated, remote attacker to cause a reload of an IPv6 device, and it may be triggered when the device processes a malformed IPv6 packet. Repeated exploitation could result in a sustained DoS condition, the Cisco advisory states.