Posts tagged: microsoft

Microsoft released IE out-of-band patch

Well..Sorry for the long gap. Was stuck with some work as usual :)

First of all wish you all a happy New Year!! A bit late to wish but better late than never :)

The recent (stale) news much around about the Google/Adobe hack a.k.a “Operation Aurora” is suspected to be executed successfully using a zero-day IE exploit.  The exploit code is publicly available & Metasploit has also released a module for the same. So now you can expect lotta script-kiddies out in action attacking your corporate/home network.

Microsoft had suggested a workaround for the same earlier this week. But the exploit had been much in wild that it had to release an out-of-band patch for the same. We strongly recommend to implement this patch on higher priority. This vulnerability could allow remote code execution if a user simply views a specially crafted Web page using Internet Explorer.

Read more »

Microsoft intending to release 2 out-of-band vulnerbilities

This is an advance notification of two out-of-band security bulletins that Microsoft is intending to release on July 28, 2009. One bulletin will be for the Microsoft Visual Studio product line; application developers should be aware of updates available affecting certain types of applications. The second bulletin contains defense-in-depth changes to Internet Explorer to address attack vectors related to the Visual Studio bulletin, as well as fixes for unrelated vulnerabilities that are rated Critical.

The severity for Internet Explorer patch has been rated as CRITICAL whereas for Visual Studio has been rated as MODERATE.

Read more »

9th June 09- Patch tuesday

Well, as always, Microsoft has vowed to keep as busy by releasing critical patches. The list this tuesday is as follows:

MS09-018

Read more »

Back again!!

Hula All!

Back to blogging after a long time. Well, as the saying goes “Be late then never”

:)

Back to Security world there are quite an important news around.

1. Gumblar.cn : This trojan is reported to be spreading rapidly using mainly the adobe vulnerability and other techniques. It captures your key logs, web traffic etc for any sensitive login credentials. Reportedly it mainly targets for FTP credentials. Then it infects the hosted site by injecting the malware download link into its html content. Scansafe has suggested a way of checking if your system is infected?? Good Read.

2. HPP: A subcategory of variable manipulation attack vector. Well, this is technique is not a new face to most of the security testers. Two researchers presented the details at OWASP, Poland. As per the presentation, HPP can be used to
Read more »

Patch Tuesday – March 11 , 2009

Hi folks!!!

Its patch tuesday again. This time MS has released 1 critical and 2 important patches.

Details:

1. Microsoft Security Bulletin MS09-006 – Critical
Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)

This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system.

Read more »

Conficker arrest!!!

Ahaa!! Microsoft seems to be really pissed off by the impact of conficker worm that it has announced an award of $250000 for the arrest of its author. Conficker is the real latest worm that has badly hit millions of users using Microsoft Windows. Well good luck for catching the author but here I will mention some tips which can help in conficker arrest.

1. Admin access. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Also a study also found that eliminating Admin rights would have stopped or mitigated: Read more »

Microsoft 10 Feb – patch tuesday

Hi all system admins…we again have some work to do : )

Microsoft released 4 patches this Tuesday. Details are as mentioned below.

Read more »

DOWNAD.AD/Conficker- MS08-67 worms

Hi All

Win32/Conficker.B is a worm that infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. It may also spread via removable drives and weak administrator passwords. It disables several important system services and security products.Remember even one unpatched machine is enough to have this worm spread through the entire network.Ms08-67 worm is spreading infection over millions of computers.

http://www.f-secure.com/weblog/archives/00001579.html

Read more »

Tips to protect from Ms08-67 worm

Recent outbreak of MS08-67 worm, Downadup/Conflicker has already infected more than 9 million PCs. A special thing about this Microsoft Security Bulletin MS08-67 was that it was released out-of-band, it was given an “Exploitability Index Assessment” of “1 – Consistent exploit code likely” and it allows for Remote Code Execution, in numerous versions of Windows (particularly critical for 2000, XP, and Server 2003).

ms08-067_remotecodeexecution

Read more »

MS09-001: Microsoft’s first patch release for year 2009

Microsoft has released its MS09 series by patching a highly critical SMB vulnerability affecting Win2k, Win2k3, Winxp and even Vista and Win2k8.

Microsoft ratings are as mentioned below:

Read more »