Archive for the ‘Security’ Category

Homeland Security: Fix your Windows Now!Homeland Security: Fix your Windows Now!

Posted on August 10th, 2006 by Juzman under Security

In a rare alert, the U.S. Department of Homeland Security has urged Windows users to plug a potential worm hole in the Microsoft operating system. The agency, which also runs the United States Computer Emergency Readiness Team (US-CERT), sent out a news release on Wednesday recommending that people apply Microsoft’s MS06-040 patch as quickly as possible. The software maker released the “critical” fix Tuesday as part of its monthly patch cycle.

“Users are encouraged to avoid delay in applying this security patch,” the Department of Homeland Security said in the statement. The patch fixes a serious flaw that, if exploited, could enable an attacker to remotely take complete control of an affected system, the agency said.

The flaw has some similarities to the Windows bug that enabled the notorious MSBlast worm to spread in 2003. Both security vulnerabilities are related to a Windows component called “remote procedure call,” which provides support for networking features such as file sharing and printer sharing.

View: Microsoft Security Bulletin MS06-040
View: Full Story
Source: C|Net News via MSFN

Vista Hacked At Black HatVista Hacked At Black Hat

Posted on August 8th, 2006 by Juzman under Security

While Microsoft talked up Windows Vista security at Black Hat, a researcher in another room demonstrated how to hack the operating system. Joanna Rutkowska, a Polish researcher at Singapore-based Coseinc, showed that it is possible to bypass security measures in Vista that should prevent unsigned code from running.

In the second part of her talk, Rutkowska explained how it is possible to use virtualisation technology to make malicious code undetectable, in the same way a rootkit does. She code-named this malicious software Blue Pill.”Microsoft is investigating solutions for the final release of Windows Vista to help protect against the attacks demonstrated,” a representative for the software maker said. “In addition, we are working with our hardware partners to investigate ways to help prevent the virtualisation attack used by the Blue Pill.”

View: Full Story
Source: ZDnet via MSFN

Apple patches 26 bugs, 17 critical, wi-fi still leakingApple patches 26 bugs, 17 critical, wi-fi still leaking

Posted on August 3rd, 2006 by Juzman under Security

After Apple had their record breaking 43 software problems patched in may, the company has squashed another 26 bugs yesterday. 17 of these were marked critical because they made it possible to execute code remotely on the affected systems. 7 bugs were in the ImageIO-module, 4 are related to the AFP server and 2 for the dyld- and gunzip components. The other bugs are several on applicational level, from fetchmail to telnet. Besides the leak solving, there’s also an update for Bluetooth so that auto generated keys can now be up to 8 in stead of the previous 6 characters.

Two hackers have succeeded in gaining control over a Macbook in 60 seconds though. They used at least two errors in the wireless communication. Although the demo was done with a Macbook, the hackers state there are comparable leaks like this in the wireless networkcards for Windows systems.

The fact that the two hackers want to publish a program which can scan for the chipset- and driverversions of wireless hardware points towards the by Intel patched errors. The Intel patch isn’t available for Apple’s OS though.

The reason the hackers chose a Macbook to show their knowledge is as they claim “The self-confidence in which Mac-users endulge themselves when it comes to security”

Source: Tweakers (Dutch) via Flexbeta

Hijacking a Macbook in 60 Seconds or LessHijacking a Macbook in 60 Seconds or Less

Posted on August 3rd, 2006 by Juzman under Security

If you want to grab the attention of a roomful of hackers, one sure fire way to do it is to show them a new method for remotely circumventing the security of an Apple Macbook computer to seize total control over the machine.
That’s exactly what hackers Jon “Johnny Cache” Ellch and David Maynor plan to show today in their Black Hat presentation on hacking the low-level computer code that powers many internal and external wireless cards on the market today.

The video shows Ellch and Maynor targeting a specific security flaw in the Macbook’s wireless “device driver,” the software that allows the internal wireless card to communicate with the underlying OS X operating system. While those device driver flaws are particular to the Macbook — and presently not publicly disclosed — Maynor said the two have found at least two similar flaws in device drivers for wireless cards either designed for or embedded in machines running the Windows OS. Still, the presenters said they ultimately decided to run the demo against a Mac due to what Maynor called the “Mac user base aura of smugness on security.”

View: Full Story
Source: Washington Post via Flexbeta

Alert over stolen tax file numbersAlert over stolen tax file numbers

Posted on August 2nd, 2006 by Juzman under Security

More than 170 Australians have had their tax file numbers stolen by online scammers who captured the information from their home computers when they were using the online e-tax system.

The Australian Tax Office has issued a warning about the attack, but said the security breach was not specific to the Tax Office or the e-tax system.

A spokeswoman said the data theft had resulted from an attack on the victims’ own computers after they were infected by a trojan horse - which is similar to a computer virus.

The trojan is called Backdoor.Haxdoor.M and it steals information by recording the key strokes entered into the computers, including bank account numbers, passwords and other personal information.

View: Full Story
Source: SMH

RemoveWGA 1.2RemoveWGA 1.2

Posted on July 31st, 2006 by Juzman under Security

RemoveWGA enables you to remove the Microsoft “Windows Genuine Advantage Notifications” tool, which is calling home and connect to Microsoft servers every time you boot. Once the WGA Notification tool has checked your OS and has confirmed you had a legit copy, there is no decent point or reason to check it again and again every boot.

Also, Windows Genuine Advantage Notifications is different than Windows Genuine Advantage Validation. RemoveWGA only removes the notification part, phoning home, and does not touch the Validation part. As the time I’m writting this, the Validation part is mandatory for some not critical downloads from Microsoft, but the Notification part is not mandatory at all, and you are able to install all of the security updates without installing this one. This may change in the future thought, I don’t know what are the Microsoft plans.

Latest Changes:
- Now uses the “RunOnce” registry entry instead of “Run” (starts sooner)
- Added a clean removal procedure for the final WGA notification update
- If every removal procedure fails (possibly for futur WGA versions), offers the brutal removal procedure

Source: BetaNews

Microsoft security updates for July 2006Microsoft security updates for July 2006

Posted on July 12th, 2006 by Juzman under Security

As part of Microsoft’s routine, monthly security update cycle we released the following security updates on July, 2006:

MS06-033 - addresses a vulnerability in Microsoft Windows (Important)
MS06-034 - addresses a vulnerability in Microsoft Windows (Important)
MS06-035 - addresses a vulnerability in Microsoft Windows (Critical)
MS06-036 - addresses a vulnerability in Microsoft Windows (Critical)
MS06-037 - addresses a vulnerability in Microsoft Office (Critical)
MS06-038 - addresses a vulnerability in Microsoft Office (Critical)
MS06-039 - addresses a vulnerability in Microsoft Office (Critical)

View: Microsoft Update
View: Microsoft Security Bulletin Summary for July, 2006
Source: MSFN

End to Win98 support may boost desktop LinuxEnd to Win98 support may boost desktop Linux

Posted on July 11th, 2006 by Juzman under Security

From today, Microsoft will no longer issue security updates or provide support for Windows 98 and Windows ME, which could lead users to trying alternative operating systems such as Linux.

Eight years after launching Windows 98, Microsoft will finally wash its hands of updating and plugging security gaps in its ageing operating system. The software giant originally planned to pull the plug in January 2004 but decided to extend support because of the increasing threat from Linux.

This time round, Microsoft is hoping that the remaining users of Windows 98 and Windows ME will upgrade to Windows XP, according to Peter Watson, chief security advisor, Microsoft Australia.

View: Full Story
Source: ZDNet Australia via MSFN

Another security hole found in ExcelAnother security hole found in Excel

Posted on July 8th, 2006 by Juzman under Security

A hole in Microsoft Excel has been identified that could allow attackers to take control of a computer, a security group said Thursday–the third vulnerability affecting the popular spreadsheet program to surface in less than a month.

The flaw is due to a memory corruption error that occurs when handling or repairing a document containing overly long styles, the French Security Incident Response Team said in an advisory.

The flaw, which affects Excel 2000, 2002 and 2003 and Office 2000, XP and 2003, “could be exploited by attackers to execute arbitrary commands by convincing a user to open and repair a specially crafted Excel file,” the advisory said.

View: Full Story
Source: ZDNet via MSFN

The 10 Biggest Security Risks You Don’t Know AboutThe 10 Biggest Security Risks You Don’t Know About

Posted on June 27th, 2006 by Juzman under Security

Hackers, scammers, and identity thieves are constantly coming up with new ways to attack your PC and your privacy. Here are the newest perils–and how to foil them.

View: Full Story
Source: PC World

 

Bad Behavior has blocked 106 access attempts in the last 7 days.