A big breach of security

Security breach may have exposed 40M credit cards | InfoWorld | News | 2005-06-17 | By Tom Krazit, IDG News Service
Another to add to this years seemingly endless stories of large companies sufferering losses of customer information, in this case CC info...
What I'm very interested to see is what actual penalties/negative consequences affect the companies responsible for these breaches, as I think it will shape some of the internal debate in companies that handle this kind of data about appropriate levels of security.
One thing that does seem to have happened is a loss of share price for choicepoint... looking at their stock graph their trading down about 20% from around the point when their breach was publisised....
Actually maybe that's worth looking at (getting a list of the breaches from privacyrights and comparing stock prices before/after)

Interesting new Bluetooth attack

Schneier on Security: Attack on the Bluetooth Pairing Process
Here's a note from Bruce Schneier on an interesting new attack on the bluetooth protocol (or more accurately common implementations of the protocol)...
Following this, if there are tools released which implement the attack, it'll really reduce where bluetooth should be used in corporate settings... all those lovely bluetooth headsets that people in the UK have bought...

Ping Tunnel

Ping Tunnel - Send TCP traffic over ICMP
Another great example of why once you allow one protocol/port through your firewall, it's pretty easy to get any other traffic through... This one's interesting, in that it levereges ICMP...

IIS6 secure?

Richard Monson-Haefel: Is Microsoft IIS 6.0 more secure than Apache HTTP Server 2.0?
Interesting posting on the relative security of IIS 6 and Apache 2.0. I'd agree that IIS 6 seems to have a MUCH better record than previous versions in terms both of vulnerability counts and initial configuration.
The only caveat I've got on it is my usual one about MS security, which is that with their products you have to look at the vulnerability of the whole stack as installed because it's so darn difficult to separate out the bits you don't want, unlike the situation with Apache running on something like Linux or BSD...
but I've done that rant before so I shan't do it again...

Very Nasty Unpatched Windows vuln.

File Selection May Lead to Command Execution
This vulnerability doesn't look tooo bad at first. If you can persuade someone to highlight a file in windows explorer then it executes some abitrary code, which it seems can do most things. However you'd have to get people to download the file anyway for it to work as a virus/word, which isn't too likely (you'd hope, after years of that kind of thing doin the rounds on the 'net).
Then I got to thinking, what about a completely different attack scenario... Joe the disgruntled employee, could go through the corporate file store adding malicious author fields to word files or the like, then as soon as one of his co-workers clicks the file, the javascript runs and actions are taken looking like the person clicking the file has carried them out. (and if joe's got any sense the first one would be change the author field removing any evidence of his modification...)
Hard to catch, unless things like A-V scanners get a signature for this (which might be tough), changes of document metadata don't usually show up in things like security logs, and in many companies people have access to a lot of docs, so it might not be discovered for a long time...
Another interesting point in relation to this vuln. and the unpatched Jet engine one is, how long will it take Microsoft to get a patch out, and will they release it outside the monthly schedule they usually use.....