Google Search

Showing posts with label Release. Show all posts
Showing posts with label Release. Show all posts

Thursday, February 28, 2013

Microsoft to release an emergency security patch for Internet Explorer zero day flaw

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft will be releasing an out-of-band patch (on Monday 14 January 2013 in the USA) for the recently-disclosed zero-day hole in Internet Explorer.

? The adjective out-of-band in this context is a bit of a metaphorical stretch, but it's what the industry has settled on. It doesn't mean that the patch will arrive via a different frequency channel, as it might in telecommunications. You can still get the patch using Windows Update. It's just outside the usual schedule of patches issued every month on Patch Tuesday.

Actually, we can't be 100% certain that last December's vulnerability, documented by Microsoft in Security Advisory 2794220, is the one that will be fixed.

All we know from the 1750 words in Microsoft's early announcement boilerplate is that Redmond will be fixing "a security vulnerability in Internet Explorer" that is denoted Critical:

Critical: a vulnerability whose exploitation could allow code execution without user interaction. These scenarios include self-propagating malware (e.g. network worms), or unavoidable common use scenarios where code execution occurs without warnings or prompts. This could mean browsing to a web page or opening email.

Nevertheless, I'll assume that tomorrow's fix will deal with Security Advisory 2794220. And on that basis, I urge you to follow Microsoft's own advice:

Microsoft recommends that customers apply Critical updates immediately.

When the crooks are already all over an exploit, as they are in this case, you should give patching your highest priority, even if you already have tools (such as security software) that does a good job of mopping up the trouble.

As we reported already, several websites have already been disseminating malware using this exploit, triggering it with a mixture of HTML, JavaScript and Flash.

Microsoft already published a temporary FixIt tool to protect against this vulnerability. It also recommended its epically-named Enhanced Mitigation Experience Toolkit (EMET) for an layer of mitigation for this and other vulnerabilities, known and unknown.

? EMET is somewhere between a process-hardening tool and a sandbox, forcing security protections onto programs that don't have them by default, and adding an additional layer of protection to software that includes code in which a security holes have been found.

However, there are reports that variants of this exploit exist that work even if you are using EMET, and even after you have run Microsoft's abovementioned FixIt.

Sadly, too, Metasploit, the vulnerabilities-anyone-can-exploit-for-free product, already has what it calls a browser auto pwn plug-in you can download to exploit this vulnerability yourself.

ie10-icon-176In short, tomorrow's patch is one to push out and then deal with any fallout, rather than the other way around.

By all means, test, digest and deploy. But make this one of those patches you deal with in hours, or in the worst case, days. Not in weeks, and very definitely not in months.

Note also that the 2794220 vulnerability affects neither IE 9 nor IE 10. If you're already using one of those versions, you're sitting pretty.

Both IE 9 and IE 10 include designed-in improvements intended to boost security, so if you're clinging to older versions for legacy reasons, please give earnest consideration to striking camp and setting up afresh.

For a discussion of priorities when patching, why not listen to this Technow podcast, in which Chet and Duck discuss whether you should you lead, follow, or get out of the way when patches roll around:

(19 July 2012, duration 15'25", size 11MBytes)

Follow @duckblog

Sophos Anti-Virus on all platforms blocks malicious files relating to this vulnerability as follows:

Exp/20124792-B: Various files associated with the exploit

Sus/Yoldep-A: Seen in related ("Elderwood Project") attacks

Troj/SWFExp-BF: Flash component used to trigger exploit

Sus/DeplyJv-A: JavaScript components from related attacks


View the original article here

Tuesday, January 3, 2012

Cyber-crime security integration for Joomla and Drupal hosting kills hacker ... - PR Web (press release)

Boston, MA (PRWEB) January 02, 2012

CNP Integrations (a team of Joomla CMS and Drupal experts found online at http://www.cnpintegrations.com, http://www.joomladesignservices.com or http://www.cnpsupport.com) teams up with Secure Live and Rackspace to provide the best of breed hosting solution for Joomla, Drupal and other open source CMS platforms.

In October 2011, CNP Integrations made the shift to a completely cloud based hosting environment for their clients, dramatically improving support coverage, ease of use and site performance thanks to the RackSpace infrastructure and “fanatical support”. They have now combined this with an added layer of cyber security monitoring provided by SecureLive software solutions and their advanced security resource team. As a mandatory integrated feature for all hosting accounts, this will allow CNP Integrations to deliver an even higher level of focused and responsive application support service for Joomla CMS and Drupal. This new strategic alliance will prove to offer the most robust and responsive security monitoring and cloud based hosting environments available in the marketplace. When combined with the CNP Integrations support team, clients of this group will experience the safest and most competent options for meeting and surpassing their content delivery needs while protecting their investments from cyber-crime.

Experts in the field anticipate cyber-crime in 2012 could rise as high as 7000% from 6 years ago. “With this type of rise in cyber crime we are making web security a priority for all of our hosting customers. CNP Integrations’ collaboration with the SecureLive team backed by the Rackspace hosting infrastructure we feel will offer the highest level of security, service and technical support available.” Says Chris Nielsen, CEO of CNP Integrations.

Stats on cyber-crime over the past 6 years:
2008 - 2009 +22%
2009 - 2010 +56%
2010 - 2011 +726%
2011 - 2012 +2965% at a cost of 216.7 billion dollars
Competitors and disgruntled employees make up over half of the cyber-attacks sources

SecureLive is a leader in proactive web security support. They have shut down over 97,324,551 IP Address from known hackers. Their patented software monitors traffic from across a global network before it gets to your site content and automatically blocks or shuts down known intruders. The SecureLive security team also works closely with the FBI to proactively hunt down and prosecute hacker threats.

Stats from SecureLive of total blocked attacks:
2008 - 98,584 attacks
2009 - 265,032 attacks
2010 - 2,678,244 attacks
2011 - 476,491,943 attacks (current)

“The more we learn about web security these days and the capabilities of hackers, the more we are in awe at how many folks are just not paying attention to the ramifications of not maintaining or proactively protecting their web assets, “ continues Nielsen.

In a recent security audit CNP concluded that if you are using PHP based web applications and not protected with a tool like Secure Live (http://www.securelive.net) and other server side security monitoring solutions, hackers can find ways to penetrate the deepest levels of your server environment by installing stealth scripts that allow them to do just about anything they want with your data and any other data stored on the server. Many of these scripts can be buried layers deep in directories that you could never find and could go virtually undetected, allowing the hacker to leverage your server for a variety of exploitations.Technology is advancing rapidly and so are the resources and business intelligence available to the hacking community.

“Since our clients often have sensitive information and invest a lot into their portals systems we have to make security a top priority. This led us to make security monitoring a standard service by actually integrating it into our hosting and support platform,” says Nielsen.

Of course, one of the most effective things that can be done to keep the bad guys out, other than server side protection, is to make sure your CMS core files are up to date as well as the third party extensions. If you are using custom integrations or components, you should make sure that you monitor and test the vulnerabilities of the code your developers have used. Often there are so many new threats that it can be a daunting task to keep up on testing and reviewing all of them. However, SecureLive acts like a gate keeper and protects your site through a global network of monitoring systems, backed by a proactive security team.CNP Integrations specializes on providing the proactive maintenance and technical support to reduce risk and optimize your applications.

Core features of our new hosting and security monitoring service include:

·         Cloud based scalable hosting environment

·         Backed by Rackspace Data centers

·         24/7 Fanatical Application, Hosting and technical support services

·         Real Time Hacker Prevention

·         Robust Alerting & Reporting

·         Law Enforcement Interface

·         Patent pending technology: (CST) Continuous Scan Technology

·         Live real-time monitoring

·         Tested 98% effective against hacking and online theft

·         Endorsed by industry experts in independent testing

·         Advanced custom user security controls to fit your site

·         Blocks intruders before attack through advanced recognition

·         Email alerts and text via mobile devices to client and monitors

·         Logs all violations and captures attacker signature

·         Forwards attacker profiles to proper authorities

·         Reduces attacks through systematic banning of violators

Read more about SecureLive FAQs: Click Here

See more articles in our blog; Click Here

To learn more about CNP Integrations visit http://www.joomladesignservices.com, http://www.cnpintegrations.com or http://www.cnpsupport.com
CNP Integrations is known for superior Joomla CMS configuration, consulting, programming and technical support. Now, with this new world class hosting service they are unmatched in the industry for delivering stable secure technology solutions for a variety of Governmental, Commercial and Non-Profit organizations.

###



View the original article here

Friday, July 1, 2011

Hackers Release More Data From Arizona Police

Hackers on Wednesday publicly exposed for the second time information they claimed to have stolen from the computer systems and personnel of the Arizona state police, in a continuation of a nearly two-month hacking spree.

A hacker group known as Lulz Security last week leaked case files, phone numbers and addresses of officers from the department in what it said was a response to the state’s tough laws aimed at illegal immigrants. The latest cache contained material from officers’ personal e-mail accounts, including “humiliating dirt,” according to a statement posted on the Pirate Bay, a site for users of the file-sharing tool BitTorrent, which the hackers used to distribute the data.

A spokesman for the Arizona Department of Public Safety said it was looking into the hackers’ claims and whether its systems had been breached.

The hackers no longer call themselves Lulz Security, or LulzSec for short, after disbanding last weekend and rejoining the larger hacker collective Anonymous. They are now working under a new banner they call “AntiSec,” protesting corruption and censorship.

One of the police department’s spokesmen was singled out for attack in the latest data release for “bragging” about the department’s security upgrades, promising the hackers would be caught and calling them “a cyber terrorism group.”

“The same fate will meet anyone else who tries to paint us as terrorists in an Orwellian attempt to pass more pro-censorship or racial-profiling police state laws,” the group warned in its statement.

It also said it had spared one former officer from having his personal information exposed because it learned that he was a Navajo and planned on suing the department for racial discrimination.

The disclosure followed the release on Tuesday of a pile of stolen content tied to a variety of organizations, including the governments of Brazil, Australia, Anguilla and Zimbabwe; a right-wing Colombian police unit; and Universal Music and Viacom. In a statement, the group said the action was retaliation “against corrupt Governments (in our world this is all Governments) and corrupt companies.”


View the original article here

Bits: Hackers Release More Data From Arizona Police

Hackers on Wednesday publicly exposed for the second time information they claimed to have stolen from the computer systems and personnel of the Arizona state police, in a continuation of a nearly two-month hacking spree.

A hacker group known as Lulz Security last week leaked case files, phone numbers and addresses of officers from the department in what it said was a response to the state’s tough laws aimed at illegal immigrants. The latest cache contained material from officers’ personal e-mail accounts, including “humiliating dirt,” according to a statement posted on the Pirate Bay, a site for users of the file-sharing tool BitTorrent, which the hackers used to distribute the data.

A spokesman for the Arizona Department of Public Safety said it was looking into the hackers’ claims and whether its systems had been breached.

The hackers no longer call themselves Lulz Security, or LulzSec for short, after disbanding last weekend and rejoining the larger hacker collective Anonymous. They are now working under a new banner they call “AntiSec,” protesting corruption and censorship.

One of the police department’s spokesmen was singled out for attack in the latest data release for “bragging” about the department’s security upgrades, promising the hackers would be caught and calling them “a cyber terrorism group.”

“The same fate will meet anyone else who tries to paint us as terrorists in an Orwellian attempt to pass more pro-censorship or racial-profiling police state laws,” the group warned in its statement.

It also said it had spared one former officer from having his personal information exposed because it learned that he was a Navajo and planned on suing the department for racial discrimination.

The disclosure followed the release on Tuesday of a pile of stolen content tied to a variety of organizations, including the governments of Brazil, Australia, Anguilla and Zimbabwe; a right-wing Colombian police unit; and Universal Music and Viacom. In a statement, the group said the action was retaliation “against corrupt Governments (in our world this is all Governments) and corrupt companies.”


View the original article here