Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, March 12, 2009

It's PDF Patching Day

It's PDF Patching Day

Get the patches while they are hot:

Update Foxit Reader if you have it already.

Update Adobe Reader if you still have it.

APSB09-03 - Security Updates available for Adobe Reader 9 and Acrobat 9

Summary:

A critical vulnerability has been identified in Adobe Reader

9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system.

There are reports that this issue is being exploited.

Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader 9.1 and Acrobat 9.1. Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

Thursday, March 05, 2009

Firefox 3.0.7 targets security issues


Mozilla on Wednesday released an update to the Firefox Web browser that its developers said fixes eight security issues found in Firefox 3.0.6, six of which were rated critical.

The most serious of the vulnerabilities fixed in Version 3.0.7 could allow attackers to run arbitrary code on a victim's computer, Mozilla warned in security advisories Wednesday.

The six critical flaws affected the browser's garbage collection, which monitors how Firefox modules use the computer's memory, as well as the browser's PNG libraries and in the layout and JavaScript engines.

Firefox 3.0.7 fixes several issues found in Firefox 3.0.6:

* Fixed several security issues.
* Fixed several stability issues.
* Official releases for the Estonian, Kannada, and Telugu languages are now available.
* Items in the "File" menu show as inactive after using the "Print" item from that menu - switching to a new tab restores them (bug 425844). This issue has been fixed.
*For some users, cookies would appear to go “missing” after a few days (bug 444600).
* Mac users of the Flashblock add-on, experienced an issue where sound from the Flash plug-in would continue to play for a short time after closing a tab or window (bug 474022).
* Fixed several issues related to accessibility features.

Mozilla developers said they weren't sure the layout and JavaScript flaws could be exploited.

"Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code," Mozilla said in an advisory.

Updates for Windows, Mac OS X, and Linux are available at the Mozilla site. Firefox 3 users will receive an update notification within 48 hours, or they can download the update manually by selecting "Check for Updates" from the Help menu.

The update, Mozilla's second this year, comes as Firefox continues to chip away at Internet Explorer's market dominance. Mozilla now has 21.77 percent of the global browser market share, compared with IE's 67.44 percent, a drop of more than 7 percentage points in a year.

Monday, March 02, 2009

President's Helicopter Blueprints Leaked to Iran Via P2P

President Obama isn't very excited about his fancy new helicopter, but that's not his fault, he just hasn't seen its super-neat blueprints yet, because he's not allowed to have Limewire.

Right, I'll back up for a second. The embattled chopper(s)—under fire for their cost and alleged foreign manufacture have been trotted out by republicans as an example of government spending spun out of control. Just as that controversy seemed to be subsiding, reports surfaced that the blueprints and avionics package for Marine One have been leaked over a peer-to-peer network, to Iran. Oops?

The leak wasn't at all intentional, unless you consider trusting technical illiterates with such sensitive material "intentional". No, the leak happened because an employee at a unnamed defense contractor (The Register thinks it's Lockheed) accidentally stored the files in a P2P folder, or, and this is more likely, just set his entire hard drive to share. Before long, the files had been uploaded to ~~xOsamaFanIran74x~~ and the intelligence community fell into a tizzy, all because some guy wanted to catch up on Big Love during his lunch break. In an interview with WXPI, Wesley Clark summed up the situation—and then, hilariously, the internet—for all of us:

We found where this information came from. We know exactly what computer it came from. I'm sure that person is embarrassed and may even lose their job, but we know where it came from and we know where it went. Once it's out there, it's hard to get it back. I don't think the full ramifications of this have been understood by the watchdog agencies.

Read more at DSL reports

US Contractor Follows Japanese Example: Leaks Military Secrets Via P2P

Nearly four years ago, it was reported that a contractor in Japan who had plans for a nuclear power station leaked them via a file sharing app on his personal computer. It was never clearly explained why he had those classified work-related materials on his personal computer, but it led to quite a mess, with the government begging people to delete the nuclear secrets, if they found them. You would hope that with that as a guide, other government and military contractors around the world would be more careful. No such luck. Apparently no one takes things like basic computer security seriously anymore.

Thursday, January 22, 2009

Understanding and Avoiding Malicious Code Attacks in Linux

Linux is a very secure operating system, immune to Windows viruses and trojans. Instead, the potential security threat lies in running malicious code - by accident or voluntarily. It's easy to avoid the most common attacks by knowing what to look for. Here are a few guidelines and examples of commands that Linux beginners should treat carefully.

Read the article here.
Reblog this post [with Zemanta]

Saturday, January 17, 2009

'Amazing' worm attack infects 9 million PCs

Calling the scope of the attack "amazing," security researchers at F-Secure Corp. yesterday said that 6.5 million Windows PCs have been infected by the "Downadup" worm in the last four days, and that nearly 9 million have been compromised in just over two weeks.

Early Friday, the Finnish firm revised its estimate of the number of computers that had fallen victim to the worm, and explained how it came to the figure. "The number of Downadup infections is skyrocketing, "Toni Koivunen, an F-Secure researcher, said in an entry to the company's Security Lab blog. "From an estimated 2.4 million infected machines to over 8.9 million during the last four days. That's just amazing."


Microsoft has recommended that Windows users install the emergency update, then run the January edition of the MSRT to scrub the worm from compromised computers.
Reblog this post [with Zemanta]

Wednesday, August 27, 2008

Computer viruses make it to orbit

ISS from STS-122Image via Wikipedia A computer virus is alive and well on the International Space Station (ISS).

Nasa has confirmed that laptops carried to the ISS in July were infected with a virus known as Gammima.AG. The worm was first detected on earth in August 2007 and lurks on infected machines waiting to steal login names for popular online games. Nasa said it was not the first time computer viruses had traveled into space and it was investigating how the machines were infected.

Read more about this at BBC News.
Reblog this post [with Zemanta]

Saturday, August 09, 2008

Security Warning fake Microsoft e-mail.

Screen Shot. Click Image to see full size.

If you get an e-mail that says it's from Microsoft asking you to download anything just delete it. It's a Trojan/virus. Microsoft is not going to send you download links. This one leads to, I am not posting the beginning to this URL for security reasons.de/DE44424232V2/images/ie7.0.exe Just delete these kinds of e-mails unless you want to pay me to fix your computer.

Read more about this here at the Internet Storm Center.

Thursday, August 07, 2008

August’s Patch Tuesday Microsoft

Here's what Microsoft has planned for us next Patch Tuesday that affects Microsoft Windows, Microsoft Office and some components of Windows such as:

* Windows Messenger
* Internet Explorer
* Outlook Express/Windows Mail
* Media Player

The affected Operating Systems are as follows:

* Windows 2000
* Windows XP
* Windows Server 2003
* Windows Vista
* Windows Server 2008

The affected Microsoft Office products are:

* Microsoft Works 8
* Microsoft Office 2000 SP3
* Microsoft Office XP SP3
* Microsoft Office 2003 SP2 and SP3
* Microsoft Office System 2007 and with SP1
* Microsoft Office Project 2002
* Snapshot Viewer for Microsoft Access
* Microsoft Office PowerPoint Viewer 2003
* Microsoft Office Excel Viewer 2003 and with SP3
* Microsoft Office Excel Viewer
* Microsoft Office Converter Pack
* Microsoft Office Compatibility Pack
* Microsoft Office SharePoint Server 2007 and with SP1
* Microsoft Office 2004 for Mac
* Microsoft Office 2008 for Mac

They also plan to release an updated version of Microsoft Windows Malicious Software Removal Tool

Microsoft is also planning to release the following non-security update on August 12, 2008 via Windows Update website:

* Windows Mail Junk E-mail Filter [August 2008] (KB905866)
* Windows Home Server Power Pack 1 (KB944289)
* Update for Windows Server 2008, Windows Vista, Windows Server 2003, and Windows XP (KB951072)
* Update for Windows Server 2008, Windows Vista, and Windows XP (KB951618)
* Update for Windows Server 2008, Windows Vista, and Windows XP (KB952287)
* Update for Windows Server Update Services (WSUS) 3 Service Pack 1 (KB954960)


* Seven Microsoft Security Bulletins with maximum severity of Critical.
* Five with maximum severity of Important.
* These updates may require a restart.

This is an advance notification of security bulletins that Microsoft is intending to release on August 12, 2008.

You can read more about these here.
Zemanta Pixie

Sunday, April 13, 2008

My Linux Desktop


I just updated Ubuntu Linux to the latest version after downloading the iso file for it and burning it to a DVD. I inserted the DVD into the linux box and re-booted the computer and booted off the DVD, formatted the hard drive again, installed the latest version and am now doing the 206 updates that needed to be done. Here is a Screenshot of my current Linux desktop.

I found a good article called "Why Use Linux?" that you might want to read. So far it has been smooth sailing here. I installed Synaptic Package Manager on this computer yesterday and it made things allot easier. Now the next step is to get Synergy to work so I can use just one keyboard and mouse to control both computers.

Saturday, April 12, 2008

Over 1 million viruses, worms, and trojans on the loose

The Internet is a very scary place. I'm talking about malware, like viruses, worms, and trojans. According to security company Symantec, the amount of malware on the internet has reached an all-time high, with over 1 million malicious programs in circulation.

A surpisingly large number of those threats were developed in the last year, with 711,912 new pieces of malware coming out in 2007 compared with 125,243 in 2006, an increase of 468 percent bringing the total number of malicious code threats detected by Symantec to 1,122,311 as of the end of 2007.

The good news for Internet users is that most of these applications are variations of older threats, which means if your anti-virus software is up to date, you should be relatively safe.

Tuesday, March 25, 2008

Windows XP Service Pack 3 (SP3) will be released in April

There's some great news for all of us die-hard XP fans: XP Service Pack 3 (SP3) will be released in April! This is most assuredly the last major update the operating system will receive until the end of its life, as Microsoft will remove it from store shelves in June.

SP3 contains 1073 patches and hotfixes. Of those, 114 are security-related. The 959 remaining are geared toward improving the performance and reliability of the OS. It even seems that SP3 could improve XP’s performance by up to 10 percent!

Wednesday, February 20, 2008

Saboteurs may have been responsible for undersea cable cuts


New information from the UN agency tasked with repairing the undersea cable cuts of early February has reported that they can't rule out sabotage at this point of time. Of the five cuts, only one has been ruled an accidental failure — the cause of the other four is still unknown. I guess this blows my theory that Godzilla was responsible.

You can read the entire article here.

Wednesday, January 30, 2008

Keep your private files into password protected Lockbox

Do you have some files on your computer you'd like to hide from others? I see so many people doing their taxes on their computers in spreadsheets that I thought this program might be a good idea. The program is called My Lockbox. It is for hiding your sensitive data.

Here's how it works. Once you install My Lockbox, the application will create a hidden folder. By default that folder will be in your My Documents folder, but you can place it anywhere on your PC. The folder is password protected, and when you hit the "lock" button, nobody can open it. That means they can't copy or open files, and they can't save files to the folder. So you'll need to unlock the folder in order to save new files to your lockbox. My Lockbox is very simple to use, and even hides your files when your PC is running in safe mode.

Access your Macromedia Flash player settings

This is a re-post of a post I did two years ago but it is still relevant.

Most people don't realize how much information their computer stores about what they do on the internet.

Here is a link to access your Macromedia Flash player settings. You can go here to Clean up your Flash sites. This takes you to the Settings manager. It is the actual Settings Manager not an image. If you click Delete All Sites, all websites are removed from your list of visited websites. Any information a website may have stored on your computer is erased.

In this panel, you can change storage settings for a website or delete the website so that, if you visit it again, it will use your global settings instead of any individual settings you may have set. You can also delete all sites, which erases any information that may have already been stored on your computer.

Wednesday, October 24, 2007

Firefox 2.0.0.8 update to be updated soon

From Mozilla "The 2.0.0.8 release fixed some 200 issues, but accidentally regressed a few things. Most users won’t see any difference or experience any problems, and those 200 fixes make the 2.0.0.8 update very valuable, but you should never have to choose functionality over security. So we’re working fast to understand and fix these problems, and will shortly be issuing a 2.0.0.9 update to address them."

Read more about this issue here
.

Monday, October 22, 2007

RealPlayer Security Vulnerability and Fix reported

There's a RealPlayer vulnerability and fix reported. RealNetworks has issued a fix for a vulnerability, identified here by Symantec, that affects the import method of an Active X control.

Read the rest here at the Real Website.

Friday, October 19, 2007

New version of Firefox was released yesterday 2.0.0.8

A new version of Firefox was released yesterday. It's available on the official Mozilla website and through the update check in Firefox itself. Two critical, five moderate and two low security vulnerabilities have been fixed in the new version which makes it a recommended update for all Firefox users.

Fixed in Firefox 2.0.0.8

MFSA 2007-36 URIs with invalid %-encoding mishandled by Windows

MFSA 2007-35 XPCNativeWrapper pollution using Script object

MFSA 2007-34 Possible file stealing through sftp protocol

MFSA 2007-33 XUL pages can hide the window titlebar

MFSA 2007-32 File input focus stealing vulnerability

MFSA 2007-31 Browser digest authentication request splitting

MFSA 2007-30 onUnload Tailgating

MFSA 2007-29 Crashes with evidence of memory corruption (rv:1.8.1.8)

Get Firefox 2.0.0.8 here.

Saturday, October 13, 2007

How to change the location of the My Documents folder


How to change the location of the My Documents folder in Windows.

In my computer I have three hard drives. Having more than one hard drive is becoming more and more popular these days.

By default, the My Documents folder located in Windows XP and Windows Vista is located on the same drive or partition as the Windows operating system. This is fine for anyone who has only a single drive or a single partition on their computer, such as the C drive, but if you have more than one physical or logical drive on your computer, it’s probably a good idea to move your My Documents folder off the system drive.

* Reasons to move the My Documents folder

* Free up hard drive space on the system partition.

With all of the monthly updates for Office and Windows, your C drive might be getting close to full. Also, other system files like the paging file, system restore files, and hibernation files are all stored on the system partition. Once you move the My Documents folder data off, you will gave Windows more space to live and breathe.

* Easy backup and recovery of data in case of Windows crash

Another reason to move the My Documents folder is to better help protect your data. For example, if Windows crashes on you one day and you have to perform a reinstall, all of your data on the primary drive will be lost. However, if your data is on the D drive, let’s say, and your Windows on the C drive craps out, you can reinstall a fresh copy of Windows on the C drive and the rest of your data remains intact. Of course, this will not save your data if the entire hard drive fails physically and your My Documents folder is on the same drive, just in a different partition. But there have been many occasions that I've seen when Windows has become unusable due to a virus, spyware or other problem.

* How to move My Documents folder to a new location

* Moving your My Documents folder is actually a simple process and can be done by anyone.

1. Right-click on the My Documents folder and choose Properties

2. Click Move and choose the desired location for your My Documents folder. Remember, it would be best to move it to a different PHYSICAL drive if possible. If not, move it to a different partition at least.

3. Click Ok and then click Apply. You’ll be asked whether you want to move all of the current documents to the new location or not. Choose Yes.

That’s all there is to it. Your documents will be moved to the new location. When you click the My Documents icon on your desktop, it’ll open just as before but your documents will be stored in the new location that you chose.

Saturday, September 15, 2007

Microsoft downplays stealth Windows Update

Microsoft has sought to downplay the recent, but unpublicized, automatic update of system files on Windows XP and Vista machines as "normal behavior."

A Microsoft spokesperson said, "Windows Update automatically updates itself from time to time to ensure that it is running the most current technology, so that it can check for updates and notify customers that new updates are available."

"The point of this explanation is not to suggest that we were as transparent as we could have been; to the contrary, people have told us that we should have been clearer on how Windows Update behaves when it updates itself," said Nate Clinton, Program Manager Windows Update, in a blog Friday.

For the curious, the updated files on Vista are:

* wuapi.dll
* wuapp.exe
* wuauclt.exe
* wuaueng.dll
* wucltux.dll
* wudriver.dll
* wups.dll
* wups2.dll
* wuwebv.dll

And on XP SP2:

* cdm.dll
* wuapi.dll
* wuauclt.exe
* wuaucpl.cpl
* wuaueng.dll
* wucltui.dll
* wups.dll
* wups2.dll
* wuweb.dll

All nine files are system files related to the XP and Vista versions of Windows Update (WU) itself.

Thursday, September 13, 2007

Microsoft updates Windows without users consent

Microsoft has begun patching files on Windows XP and Vista without users knowledge, even when the users have turned off auto-updates.

In recent days, Windows Update (WU) started altering files on users' systems without displaying any dialog box to request permission. The only files that have been reportedly altered to date are nine small executables on XP and nine on Vista that are used by WU itself. Microsoft is patching these files silently, even if auto-updates have been disabled on a particular PC.

Read the entire article about this here.

I was talking to my son about this tonight and he said that when he went to the pharmacy on base today to get a prescription filled that the computers updated and restarted and it resulted in a delay. Now he won't be able to get his medicine until tomorrow.