Showing posts with label AppLocker. Show all posts
Showing posts with label AppLocker. Show all posts

Tuesday, 19 April 2016

Microsoft Warns Of E-mails With Attachments JavaScript


Microsoft has issued a warning to spam messages that contain a JavaScript file attached and try to infect your computer with malware, including Locky-ransomware. The JavaScript attachments are back wrapped in a rar or zip file, says Alden Pornasdoro Microsoft.

In addition to use JavaScript files cyber criminals also Office documents with malicious macros to spread ransomware. According to Microsoft can be rapidly infected a computer via a JavaScript file. "It is interesting to note that an Office attachment with malicious macros usually two or more clicks required to open the document. One click for the document, and another click to activate the macro. On the other hand, the JavaScript annex just one or two clicks to run, "Pornasdoro notes.

He adds that it is very unusual for people to send JavaScript files attached. Who receives such a file must therefore not open. Pornasdoro also advises organizations to enable AppLocker so dubious software can not be performed. In addition, administrators are advised to disable macros in Office programs.

Finland's F-Secure has advice given how the Windows Script Host can be disabled so that JavaScript files are no longer open.

Thursday, 23 April 2015

Microsoft Protects Windows 10 Device With Guard


During the RSA Conference in San Francisco, Microsoft announced a new security measure for Windows 10 that infection of computers and laptops by malware should avoid. With Device Guard , as the hot solution, organizations can systems from both known and unknown malware and Advanced Persistent Threats (APTS) protect, as well as zero-day attacks.

Using the security measure merely changes programs of specific suppliers, the Windows Store or organization authorized. All other software will block Windows 10. Companies can decide which providers Device Guard trust. The solution comes with software that makes it possible for applications that are not signed by the original supplier itself signings, so they can be used anyway.

To determine whether a program is executed to trust the Device Guard hardware and virtualization technology to isolate the decision of the rest of Windows 10, which is intended to protect against attackers or malware to gain system privileges have full knowledge. According to Microsoft, this is a significant advance over traditional virus scanners and whitelisting solutions such as AppLocker, which are vulnerable to manipulation by administrators or malware. Several manufacturers, including Acer, Fujitsu, HP, Lenovo and Toshiba, have pledged to support the use of Device Guard on their equipment.