Google Search

Showing posts with label required. Show all posts
Showing posts with label required. Show all posts

Wednesday, June 19, 2013

Microsoft to issue 9 security updates on Tuesday, critical for all IE versions, reboot required

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft has issued its routine advance notification for the coming week's Patch Tuesday.

As usual, the "pre-announcement" is a bit like a bikini: interesting more for what it conceals than what it reveals.

Nevertheless, there's enough to make sure you're ready for Tuesday 09 April 2013 (or Wednesday, of course, if you live at the longitude of about Thailand or further east).

This month's nine updates don't sound too onerous, with just two at critical level and the remaining seven important, but the critical ones affect Internet Explorer (IE) and Windows itself, and the IE fix will require a reboot.

Just so you know.

Importantly, the IE update applies to all supported versions of the browser, from IE 6 to IE 10, on all supported version of Windows, from XP and Server 2003 to Eight and Server 2012, in both 32-bit and 64-bit flavours.

Server Core installs, happily, aren't affected by either of the two critical flaws.

? Internet Explorer isn't part of a Core install, which doesn't support GUI applications for safety's sake. This reduces your attack surface area tremendously and you should go for a Server Core installation whenever you can.

As you may have seen, there has been plenty of speculation that the critical updates will include patches for the IE vulnerabilities exploited in the recent PWN2OWN competition.

Mozilla and Google triumphantly rushed out patches to the holes in Firefox and Chrome that were found at PWN2OWN, closing down the vulnerabilities within 24 hours.

As we remarked at the time, this certainly threw down the patching gauntlet to Microsoft, though we also pointed out that:

Redmond, to be fair, has many more products with much more complex inter-relationships to juggle than Mozilla, and even Google.

With the PWN2OWN rules this year requiring responsible disclosure, meaning that winners had to reveal their attacks to the affected vendors and allow time for a considered and tested fix, it wasn't actually necessary for Microsoft to rush.

If Redmond's security team does fix IE's PWN2OWN bugs on its offical April patch day, it will in my opinion have done a timely job, but until Tuesday, Microsoft is keeping the details up its sleeve.

Note that five of the non-critical patches fix what's known as elevation of privilege, a trick that allows untrusted software to do things beyond its official authority.

Usually, that means a program running as a regular user can complete operations that would normally require administrator privileges, such as modifying system settings or altering critical files,

As you can imagine, attackers often combine RCE, or remote code execution, with EoP, or elevation of privilege.

They use the RCE to escape from the strictures of your browser, or some other interactive application, and then the EoP to escape from the limitations of your regular login account.

Either sort of exploit is dangerous on its own, but together they are much more harmful.

So plan to patch all the holes, not just the critical ones, and watch out on Naked Security and the SophosLabs Vulnerabilities page for our analysis and assessment of the updates once we're clear to publish.

(We have to wait until Microsoft has made the updates live before we give away any details.)

Bonne chance!

Follow @duckblog


View the original article here

Tuesday, January 3, 2012

No hacking required. Murdoch signs up to Twitter - Telegraph.co.uk

Eighty-year-old Rupert Murdoch plunged the micro-blogging website into uproar with a series of Tweets on everything from his family holiday in the Caribbean to the number of holidays taken by British workers.

The arrival of the News Corporation chairman, who has been said to view the internet as “a place for porn, thievery, and hackers”, was greeted by most members of the site with incredulity and horror. But by last night the octogenarian had amassing a huge following on the site, with more than 32,000 people signing up to receive his Tweets within hours of him joining.

His decision to join Twitter was even more surprising, because the site was host to a campaign during the hacking scandal last year, in which advertisers were urged to boycott the News of the World before the Murdoch-owned paper’s closure.

There were, however, immediate suspicions that his foray into social media was part of a News Corporation PR strategy to improve Mr Murdoch’s image after the hacking revelations, especially as several of his initial posts mentioned his company interests.

Another post, since deleted, read: “Happy 2012. May it be better than all experts predict. Has to be! Must change everything to create jobs for all, especially young.”

News Corporation sources dismissed the suggestions it was a PR stunt, saying it was a genuine attempt by the company head to learn about new technology. A company spokesman later confirmed the account’s authenticity. News of Mr Murdoch’s account spread after Jack Dorsey, Twitter’s executive chairman, posted a message saying the controversial billionaire would grace the site “with his own voice, in his own way”.

The account @rupertmurdoch was created on New Year’s Eve and a stream of wide-ranging comments followed. Betraying a certain unease with technology and punctuation, he aired views on British life and the US presidential elections. Mr Murdoch chose to “follow” just four people, including Larry Page, the co-founder of Google, and Mr Dorsey.

He also likes to receive the thoughts of Lord Sugar, the British businessman, and Mark Pincus, the Silicon Valley entrepreneur.

Last night Mr Murdoch posted directly to the Twitter chairman: “My resolutions, try to maintain humility and always curiosity. And of course diet!” There was initial scepticism from many, who questioned whether it was genuine, despite the feed carrying a blue-ringed “tick” that denotes a verified account.

Britain featured prominently among Mr Murdoch’s initial posts, with him posting one in which he gave his backing to Scotland’s First Minister Alex Salmond. “Great to see alexsalmond Briton of the year.” In response to a tweet by Lord Sugar in which he said he would not be back at work until tomorrow, Mr Murdoch wrote: “Maybe Brits have too many holidays for broke country!”

His debut post exhorted users to read Matt Ridley’s The Rational Optimist, and he also tweeted about the forthcoming George Clooney movie, The Descendants, distributed by the News Corp-owned Fox Searchlight Pictures.

Piers Morgan, the former News of the World editor, tweeted: “Now this is going to be fascinating?… welcome to Twitter my old boss @RupertMurdoch.” And John Prescott, the former deputy prime minister, wrote: “Welcome to Twitter?… @? RupertMurdoch. I’ve left you a Happy New Year message on my voicemail!”


View the original article here