03 February 2007
Vista's First Post-Release Flaw
To be accomplished users have to have already configured the speech recognition and have it activated as well as have a live microphone and speakers. For those who are using speech recognition, this seems to be a very probable situation as most people using the feature would want to continue to use it while on the web and so would not have their microphone turned off, but listening for the next command.
From a security point of view, it could cause a security risk if the command is able to run an installer without user intervention or if it is able to email files to someone. Without this ability, it just becomes a major annoyance and risk that can cause people to lose files, have files moved, their system restarted and at a basic level controlled from an outsider. The outsider under a normal situation would have no view of the system and this would all be visible to the user, who may or may not have time to react to the situation.
Labels: internet, microsoft, os, security, vista, vulnerability, windows
05 January 2007
PDF Exploit is a Big Threat
Originally it was thought that such malicious code would only affect servers and would have limited effect on user's computers. The nature of Java prevents it from modifying any file on a computer it is remotely running on, saving users from security vulnerabilities. What has recently been discovered is that if the link were directed at a PDF file on the user's computer, it could then run locally on the system allowing someone to view the user's files, modify and delete them as well as send files to the attacker.
The limitation to this is that the JavaScript has to know the location of a PDF locally installed on your system. You may be thinking that this saves you and makes it that much more difficult, but also consider that when Acrobat Reader installs it installs sample PDF files, which could very easily be used. Also consider the possibility of the attacker convincing the user to install the file themselves in a specific location (social engineering seems popular). After the people install the file, the attacker is in.
Adobe has yet to confirm the exploit, but has stated that they believe Flash Player, modern browsers and reader should prevent the affect of such an exploit.
Labels: pdf, vulnerability
25 December 2006
Not so Merry Christmas Greeting
The Trojan comes in an email with the subject "Merry Christmas to our hero sons and daughters!". There isn't much known about the attack but it is assumed to be based on the MS06-012 exploit in MS Office that lets commands be executed from a remote source.
Labels: email, microsoft, powerpoint, trojan, vulnerability
23 December 2006
Outlook and Other 3rd Party Applications Cause Vulnerablities in Vista
The problem comes from other software particularly email applications being run on Vista. Outlook fits into this category of applications that can make Vista vulnerable.
The comment from Microsoft that these applications are what causes Vista to be vulnerable is like saying connecting to the Internet is what causes vulnerabilities. Every business needs to run some sort of email application and Outlook is the most popular and in many cases has a lot of very nice features not seen in other Windows email clients.
So we know exactly where the problem comes from, now the issue is how can Microsoft fix Vista so that it's use of (as MS states) 3rd party software does not cause vulnerabilities. People buy computers with the intention of running other software on them.
Labels: microsoft, vista, vulnerability, windows
19 December 2006
More Information on the 'Skype Worm'
When a computer with Skype is infected with this it will give a warning message before running that says,
"Warning!
Allow this program in skype!"
If users do not allow the program to run then it cannot spread. That doesn't of course mean that it cannot find information on your computer, it just won't move to the next random Skype user.
When it does find another random user it will send a message that says:
"Check this! [http://]marx2.altervista.org/surpr"
This URL has been removed by now which gives a lot more protection to users in the spread of the worm.
If you have been infected, it is not so difficult to remove.
The first step is to disable the system restore feature in Windows ME and XP. Then with an updated antivirus definition file, do a complete system scan.
For those who aren't sure how to disable the system restore feature:
From the start menu, right click 'My Computer' then select properties. From there you will see a 'System Restore' tab. Inside that tab will be a option to 'Turn off System Restore' or something very similar. After doing that apply the changes and confirm it then hit OK. At this point you are ready to scan for the virus.
Labels: skype, vulnerability, windows
Skype Worm Crawls Through sp.exe File
When this file is run, it installs spyware that is used to steal passwords and personal information on your computer and as well downloads more code from a remote computer.
This is very new so not much is known about it yet.
Labels: skype, vulnerability
17 December 2006
Symantec Vulnerability Being Actively Exploited
Users can protect themselves by making sure their copy of the antivirus program is patched and that the TCP port 2967 is blocked.
A complete analysis of the worm can be found from eEye Research.
Labels: antivirus, symantec, vulnerability
12 December 2006
More Office Vulnerabilities
The latest exploit is the result of an error when processing word files. Thankfully it is not being exploited very actively and requires a person to open the file to actually be affected by it, which mostly prevents anyone who practices safe computing habits from being affected by the exploit. The word file used in the exploits contains the PWS-Agent.g Trojan which collects passwords from IE, Firefox and email clients.
Unfortunately currently Microsoft has released very little information aside from a confirmation of the exploit and has no patch or workaround.
Labels: microsoft, office, vulnerability
07 December 2006
MySpace being eaten by worms
To spread the worm changes the user's MySpace pages and sends people to a fake log-in page.
On the bright side though it is detectable. Affected pages display a strange blue navigation bar. If this is the case for your page, remove the fake navigation bar and make sure that your friends are not infected. If they are infected the worm will use your friends list to transfer itself back to your profile.
PCAuthority.com has more information on this worm.
Labels: myspace, vulnerability
02 December 2006
Electronic Bookworm In Education
For the most part households should have no problems as it seems to only be targetting .edu domains, but people should still be prepared in case there is a change.
Labels: education, microsoft, symantec, vulnerability
07 November 2006
Another Critical Vulnerability in IE and Windows
Currently attacks have been found using all versions of Internet Explorer (IE) to run code remotely. Banner Advertisements and methods of distributing web content can be dangerous according to Microsoft.
Microsoft has advised users set the registry's kill bit for the ActiveX control or setup IE to provide a prompt before running any ActiveX Control.
More information including suggested workarounds from Microsoft can be found in Microsoft's security advisory.
Labels: IE, microsoft, vulnerability, windows
31 October 2006
Small Possibility of Disabling Windows XP Firewall
The computer has to be running Windows XP and Windows Internet Connection Service (ICS), which is running on any XP computer that is sharing its Internet connection. This of course does not affect networked computers using a router to share the Internet connection, the connection has to be first plugged into that computer then shared with other computers to be vulnerable.
The attack is accomplished by sending a malicious packet to the machine, which will cause ICS to crash. Due to ICS's connection to the Windows Firewall, it also stops working as well.
The good news is that there are many factors that make this less likely to happen. The main factor is that the person doing this must be inside the network. This leaves very few choices over who can do it. The only real way an outsider could perform such an attack would be if you had a wireless network setup that they had gained access to.
Businesses are not likely to be affected by this due to their use of hardware based firewalls or computers dedicated to just that purpose. Households who want to share their Internet connection should be using a NAT Router as well and probably are if they have a wireless network set up. While this flaw is not something one would want on their system, it isn't going to affect 99.9% of users unless there is another method found for exploiting the vulnerability.
Labels: firewall, microsoft, vulnerability, windows, xp
28 October 2006
Data theft alert for those using file sharing
In Denver, police have recently discovered a computer containing records of about 75 different people. Included were tax records, bank accounts, online bill payment records among other things. These records were apparently obtained from the LimeWire software. The software apparently was exploited to allow every file within a computer to be accessed.
LimeWire users are being asked to ensure that their computer's security is updated and firewalls and antivirus software are being used. For those who share their computer with others, it is also advised to check to see if any file-sharing applications are installed.
The Federal Trade Commission has a site describing the risks associated with file-sharing networks with suggestions on how to protect yourself that anyone using such software should read as well as those with children who use such software.
Labels: internet, limewire, p2p, safety, vulnerability
22 October 2006
Is it IE7 or Outlook Express that is vulnerable or does it matter?
Microsoft has responded by saying that it is an exploit that affects Outlook Express and is not a vulnerability in any version of Internet Explorer.
To this statement Secunia responded by saying that the vulnerability is fully exploitable from Internet Explorer and that IE was the primary and possibly only way of exploiting the vulnerability. Secunia does acknowledge that the actual vulnerability may be in Outlook Express, but still stand behind the alert being for IE stating that it is deceiving to users to not say that IE is vulnerable when that is the application being used to exploit the vulnerability.
For a vulnerability that has been around since 2003, one would think that Microsoft would be more interested in patching the vulnerability rather than bickering over which application is vulnerable and which is at fault. If IE is how the vulnerability is being exploited then IE should be patched to prevent the exploit from working on Outlook Express or Outlook Express should be patched to eliminate the vulnerability. Both applications are at fault. The solution could be made in either place and should be made instead of trying to point the finger at other applications. The average user doesn't care exactly which program is vulnerable, they just want to have a fairly secure computer and not worry about viruses or other malicious activities. When there is a problem it doesn't matter which application it is, what matters is that it is fixed.
Labels: IE, microsoft, outlook, vulnerability, windows
19 October 2006
IE7 already vulnerable - Please say this is a joke
Apparently the vulnerability can allow the disclosure of potentially sensitive information and is the result of a handling error in the redirection of URLs with IE7's mhtml URI handler.
There is a test from secunia to see if your browser is actually effected by this vulnerability based on the Proof of Concept code created by codedreamer. From this site you can also sign up to be informed when a patch is made available to fix the vulnerability as well as a weekly newsletter informing people of newly discovered vulnerabilities.
This doesn't do very good to promote Microsoft's image of being very interested in security and quality. This is the first time I've ever heard of a piece of software being released and within hours already having vulnerabilities discovered especially with such a popular product. This is not a good sign of what is to come.
Labels: IE, microsoft, vulnerability
04 October 2006
Firefox Flaw Hoax
While this type of joke is the least funny for anyone, it did teach us a lot about Mozilla and security. Mozilla immediately began investigating the 'flaws' when the news was released and is still continuing even after it has been written off as a hoax. Mozilla states that they take security very seriously and their current actions seem to follow that statement.
Labels: firefox, hoax, vulnerability
01 October 2006
Firefox not as secure as previously thought
As it could have been expected, as Firefox gained popularity people would begin trying to find exploits for the system. This should not trouble people that much as people finding ways to exploit software functions can be expected sooner or later in large applications, what should trouble people is the length of time that it takes to patch the flaws. I have hope that it won't take very long for it to be patched. If it does take several weeks, as is common for IE flaws to be patched, I would advise people to begin looking for another browser to use.
Labels: firefox, hoax, vulnerability
29 September 2006
More Vulnerabilities for Microsoft
The new vulnerability is being used to install a Trojan on the computer. This Trojan runs an executable file and installs two DLL files to function as backdoors. All information entered into Internet Explorer is posted to a web site on compromised computers.
Users need not worry too much about this, it is considered a limited risk due to the small number of victims so far. Also users need to run the malicious file for their computer to be infected so it is very easy to protect yourself from this exploit.
Labels: IE, microsoft, powerpoint, trojan, vulnerability
25 September 2006
Third-Party Patch Released for IE VML Vulnerability
The number of attacks has gotten so bad that at least once cybercriminals redirected 500 websites to point to a site that contains the exploit. People who were browsing sites that they normally go to could then be directed to this malicious site and be infected.
Microsoft has recommended that people not download patches from third parties and said that it was better if they got the updates from original software producers. I agree it is better, but waiting until October for patch Tuesday is a bit too long in the case of a something with this much danger.
ZERT as well addresses the issue of caution when dealing with third-party fixes because the patch doesn't go through the rigorous testing that Microsoft puts its patches through and therefor doesn't provide any guarantee that their patch works completely in every system. There is the possibility of compatibility issues with the patch or more vulnerabilities. ZERT has released the source code for the patch as well so people can see what it does before installing it.
Microsoft and ZERT both urge people to consider using the workarounds that Microsoft has released to protect their system from the exploit before installing the patch.
The official Microsoft workarounds can be found on this page after scrolling down to about the middle under the heading of Suggested Actions.
Labels: IE, microsoft, patch, vulnerability
20 September 2006
Office and IE vulnerability surfaces
This is a slight modification to a bug that was fixed in 2004. The impact of this exploit now is potentially larger as a result of Office's Open XML format which relies on VML.
Microsoft has created a scenario of how an attacker might use the exploit. Their idea is that the exploit will sit on a website. When a person views the site the exploit could give an attacker the same permission as the person using their machine locally. (Another note as to why you shouldn't log on as administrator in Windows and root in Linux.)
Of course this is only one method and others could be possible.
Labels: IE, microsoft, office, vulnerability
