Google Search

Showing posts with label ready. Show all posts
Showing posts with label ready. Show all posts

Friday, November 15, 2013

Microsoft ready to cough up (potentially big!) bounty bucks for bugs

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Magnifying glass image courtesy of ShutterstockOn Wednesday, Microsoft announced that it's now going to pony up with bounties that can reach $100,000 for vulnerabilities that can crack Windows, starting with the upcoming preview version of Windows 8.1, due to be released later this month.

But that's not all. Researchers who go beyond reporting novel exploits by sending in a whitepaper to describe "effective, practical, and robust" mitigation for qualifying exploits can get up to an additional $50,000 - or what Microsoft has dubbed the "BlueHat Bonus for Defense".

Facebook, Google, Mozilla and Twitter have all offered bounties for some time, but those have ranged from a few hundred to several thousand dollars.

In contrast, Microsoft's bounties are downright lavish.

Plus, they pertain specifically to research on products still in beta.

Their bug bounty program for Internet Explorer 11 Preview, which will pay out $11,000 for unique exploits, runs between June 26 and July 26 2013, so Microsoft is urging researchers to get hopping on preparing those reports.

Microsoft senior security strategist Katie Moussouris said in a blog post that rewarding researchers earlier in the game is better for all:

"[Many organizations] don’t offer bounties for software in beta, so some researchers would hold onto vulnerabilities until the code is released to manufacturing. Learning about these vulnerabilities earlier is always better for us and for our customers."

Maybe it's late to the bug bounty game, but given the generous rewards and the focus on finding bugs early while products are still in beta, there's a greatness to Microsoft's lateness.

Follow @LisaVaas
Follow @NakedSecurity

Image of magnifying glass courtesy of Shutterstock.


View the original article here

Thursday, October 24, 2013

Get ready! Oracle to fix 40 holes in Java on Tuesday, 18 June 2013

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Oracle's official patch frequency for Java is rather unusual: once every four months.

There's no succinct adjective for that, as there is for monthly or quarterly updates: the easiest way to work out Oracle's official dates is simply to remember, "Around the middle of February, June and October."

? Oracle increasingly frequently issues security patches between regular updates, so those aren't the only fixes you'll need each year. But they're the ones that are going to come out no matter what, so you may as well diarise them.

There's definitely an update coming next Tuesday, 18 June 2013, and you might as well get ready for it now if you haven't already.

The details of what will be fixed aren't a matter of public record yet, so we can't spell them out for you in detail.

Nevertheless, Oracle has published a very brief pre-announcement to remind us of the importance of this month's fixes.

(Yes! I know! It's a misnomer - what is a "pre-announcement" if not merely an "announcement" - but don't shoot the messenger!)

The good news is that lots of security vulnerabilities have been repaired - 40 in total, of which all but three are RCEs, or remote code execution holes.

That's where untrusted content sent over the network might be able to trick Java into performing operations that really ought to be limited to already-installed, trusted code.

In short, an RCE means that you could get infected by malware simply by looking around online, without explicitly downloading, authorising or even noticing the malware being installed.

There are two handy ways to reduce this RCE risk:

Apply Oracle's patches as soon as practicable. You can turn on fully-automatic updating if you like.Turn off Java in your browser, so that web-based Java applets can't run at all.

In the future, Oracle expects to switch Java onto a quarterly update cycle, keeping it aligned with other Oracle products.

For the time being, just keep your eyes open on Tuesday 18 June 2013, or engage auto-updating before then: this update sounds important.

We'll spell out the detail of what's changed once Oracle's updates have gone public.

Sophos vulnerability assessments can be found on the official SophosLabs Vulnerabilties page.

Follow @duckblog


View the original article here

Monday, September 16, 2013

Get ready for the next #sophospuzzle - coming soon to a T-shirt near you

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's almost time for the annual AusCERT conference in Queensland, Australia.

And for everyone who's asked, the answer is, "Yes! There's a #sophospuzzle."

And a Sophos AusSHIRT to go with it.

Over the past few years, the Sophos AusSHIRT Puzzle has become a something of an institution.

It's also one of the coolest and most sought-after giveaways of the show.

(What am I saying? It's the most sought-after giveway!)

For those who won't be on Queensland's Gold Coast later this week, we'll also be publishing the puzzle for you to solve and enter online.

There are prizes, as usual: geeky toys at the show, and a bunch of T-shirts for those who solve it online.

In previous years, the puzzles typically had multiple stages, with the shirt decoding to a URL, and the URL taking you to the next level, and so on.

Many of you asked us to make the 2013 puzzle a little more self-contained, notably so that those who are attending the conference don't need to spend hours on their computers working their way through it.

Instead of three stages, this year we've given the puzzle three dimensions (OK, technically it's an isometric projection into two dimensions, but bear with us here), and just one stage.

So you can solve this puzzle straight from the shirt, using nothing but pencil, paper and intellect.

Of course, you can still throw some home-hacked scripts at the problem if you want: a little bit of brute force goes a long way, and you can leave your scripts running while you attend the conference parties.

We'll fill in the real letters in the squares of the Rubik's Cube when the puzzle proper starts. (No, the answer isn't "UTM". Well, not this answer, anyway.)

The real thing, complete with handy hints, will be published on Naked Security to coincide with the official opening of the conference, on the evening of Tuesday 21 May 2013, at 2013-05-21T18:00+10.

That's 6pm Queensland time, 4pm Singapore time, 10am in Berlin, 9am in the UK, 4am in New York and 1am in California.

It'll also be half past five in the morning in Newfoundland, and quarter to two in the afternoon in Kathmandu, for those of you who doubt the need to take fractional timezones into account when programming.

Just so you know, the puzzle is a cryptogram, which means that the letters on the cube have been scrambled using an encryption algorithm.

It's a slightly wacky and unusual cipher, with both substitution and transposition, but the substitution always replaces each plaintext letter with the same encrypted letter.

So you shouldn't need a computer to solve it.

As usual, you'll be able to follow the puzzle on Twitter using the hashtag #sophospuzzle.

Sophos Australia will feed you hints on the @Sophos_ANZ Twitter feed, so follow the SophOz team for some extra help.

And I'll be keeping a watchful eye on proceedings via @duckblog.

Hope you can join us online, even if you won't be there to pick up a shirt!

Follow @Sophos_ANZ

Follow @duckblog


View the original article here