Showing posts with label Microsoft Windows. Show all posts
Showing posts with label Microsoft Windows. Show all posts

Thursday, 15 March 2018

Registry Key No Longer Required For Windows 10 Updates


Users of Windows 10 no longer need a specific registry key to receive security updates, Microsoft announced. The reason for the mandatory registry key was a compatibility problem with various anti-virus products that can provide a blue screen of death (BSOD).

To stop these problems from incompatible anti-virus products, Microsoft security updates from January 3 and beyond were only offered to systems that had a compatible virus scanner. Anti-virus vendors had to confirm to Microsoft that their software was compatible with January and beyond security updates, which was added to the Windows Registry by adding a special registry key. In case the virus scanner did not enter this registry key, users no longer received updates and were vulnerable to attack. When users did not run a virus scanner, Microsoft advised to manually enter the registry key to receive the January and after updates.

Now Microsoft's John Cable reports that there is no longer a check on the compatibility of anti-virus programs. All Windows 10 machines will therefore receive the March security updates as well as the previously released updates for the Spectre and Meltdown attacks, regardless of whether they have the previously required registry key. In the coming weeks, Microsoft will provide more information about the compatibility of anti-virus software on older Windows versions.

Meltdown Update For 32-Bit Versions Windows 7 and 8.1


Microsoft released two months after the unveiling of the Spectre and Meltdown attacks , which should protect users of the 32-bit versions of Windows 7 and Windows 8.1 against Meltdown. In addition, Intel microcode updates for various Intel processors have been rolled out.

At the beginning of January, the software giant already released security updates for the 64-bit versions of Windows. A Meltdown update for the 32-bit versions of Windows 10 followed on 18 January. Microsoft now announced that security updates for the 32-bit versions of Windows 7 and Windows 8.1 have also been made available to protect users from the Meltdown attack.

To be fully protected against Spectre and Meltdown attacks, systems require both software and firmware (microcode) updates, Microsoft said. That is why in early March it started to offer microcode updates from Intel via the Microsoft Update Catalog . Initially, it concerned updates for systems that have a Skylake processor and run the Windows 10 Fall Creators Update. Now, Microsoft has also made updates for Kaby Lake and Coffee Lake processors on the same platform.

Tuesday, 19 April 2016

Gates Supports Microsoft's Lawsuit Against US Government


Bill Gates supports the lawsuit by Microsoft against the US government users whose data must be warned searched by the authorities. At present receive email providers from the US government often a 'gag order', said she is not allowed to inform users. According to Microsoft, this is going too far and the software giant wants the court therefore corrects the situation.

Gates leaves in front of Reuters know that the government in some cases information from email providers must obtain without the user in question gets to know this, but this is the exception and not the rule. Gates further calls for cooperation between government and tech companies to find the right balance when requesting private data. "I do not think there is anyone who thinks that the government should get all or that the government absolutely must get nothing."

Friday, 13 November 2015

Microsoft Patches Update Outlook To Crash


Microsoft has released a new update for Windows 7, because the previous in some users Outlook to crash. Last Tuesday, Microsoft issued a critical security update (MS15-115) for multiple Windows computers leaks through which attackers could take over completely.

The 3097877 update caused some users of Outlook 2010 and 2013 ensure that the email program crashed when opening HTML emails, as evidenced by numerous complaints on the forum Microsoft and Reddit. The problems disappeared if the relevant update was removed. Microsoft allows now in the Security Bulletin MS15-115 know that the update has been re-released to fix the problem that caused crashes when viewing certain emails. Users also are advised to install the update again.

Wednesday, 11 November 2015

Microsoft Patches 53 Vulnerabilities In Windows, IE And Office


During the November Patch Tuesday, Microsoft has 53 vulnerabilities in Windows, Internet Explorer, Microsoft Edge, Office and several other products poem, including four zero-day vulnerabilities. The total contribution amounts to four twelve security updates, which are labeled as critical.

Critical updates address vulnerabilities that could allow an attacker to run arbitrary code on the computer can perform, without much user interaction. These four are updates for Internet Explorer, Edge and Microsoft Windows. There are also updates for Office, Lync, Skype for Business and .NET Framework appeared. Most leaks are fixed in Internet Explorer, namely 25.

In the case of the four zero-day vulnerabilities were those found in Windows and Office. It involved vulnerabilities that had already been announced for the release of the patches. According to Microsoft, there are no indications that the vulnerability for the appearance of the updates are attacked. An overview of all published Security Bulletins on this page to find. Updating via the Automatic Update feature, which is enabled on most Windows computers.

Thursday, 5 November 2015

Automatic Update QuickTime Does Not Work On Windows 10


There is a problem with the automatic update feature of QuickTime on Windows 8 and 10, which indicates that the updater users up-to-date, even though there is a new version available. In August released QuickTime 7.7.8 in which multiple critical vulnerabilities were patched.

Through the nine vulnerabilities could allow an attacker to crash the progam or arbitrary code on the computer can perform, such as installing malware. The opening of a malicious media file would be sufficient in this case.

According to Alton Blom this is probably because QuickTime is not automatically on Windows 8 and 10 installs a new version, while this is the case with other Windows versions. Blom approached Apple. The company informed him that QuickTime 7.7.8 for Windows 7 and Vista is designed. When Apple this version also automatically on Windows 8 and will roll out later is unknown. Users can as a temporary solution to the latest version from the Apple website to download. Although this is in accordance with Blom initially did not work, the version offered would now be able to be installed without difficulty.

Saturday, 31 October 2015

Microsoft Launched Windows 10 Experiment With Pirated Softwares


Microsoft will soon launch an experiment in which users of a pirated version of Windows 7 or Windows 8.1 simply a legal version of Windows 10 can upgrade. At present, users can install a free legal version of either operating system Windows 10.

According to Microsoft, users would an illegal version kinds of "creative ways" seeking to start the upgrading process, then purchase a legal version of Windows 10. How many users it will make Microsoft is not known, but because of these developments, there will soon be in the United States to start an experiment.

Users of a counterfeit version of Windows 7 or 8.1 will be able to make a legal version of its operating system via a mouse click. This can be done via the Windows Store or entering an activation code which is obtained somewhere else. If this make Microsoft allows more users with a genuine Windows version works will expand the experiment and rolling out in other countries.

Wednesday, 21 October 2015

Microsoft Makes OpenSSH For Windows Open Source


Already a few months working with Microsoft to develop OpenSSH support for Windows and the first milestone is achieved, namely to open up the source code. Via SSH, users can remotely log on to machines. By popular demand, Microsoft decided therefore to add SSH support on Windows PowerShell, so soon administrators can easily manage different platforms.

The Luxembourg NoMachine had in the past developed a port of OpenSSH for Windows. Microsoft has now taken the port and synchronized with OpenSSH 7.1. Now that this milestone has been reached, the software giant decided to publish source code so that others can respond. Steve Lee Microsoft warns that it is still at very early code comes mainly as a "developer preview" should be seen and not for production environments is intended. Eventually, Microsoft hopes a version that does here is suitable to be delivered in the first half of 2016.

Wednesday, 7 October 2015

Dozens Of Fake Apps In Windows Phone Store Discovered


In the Windows Phone Store Microsoft researchers have discovered dozens of fake Apps posing as popular apps like Facebook Messenger, CNN, BBC and WhatsApp. Reported anti-virus company Avast. A total of 58 different apps from its two developers coming.

The purpose of the apps is to maximize revenue. The developers use two tactics, namely, ad-clicks and misleading advertisements. The apps include several ad kits, where both users and app itself is clicked. Misleading ads try to lure users to certain malicious Websites, for example, claim that the device is infected or has other problems. How many people have downloaded the apps is unknown. At the time of writing were still finding the apps in the Windows Phone Store.

Thursday, 10 September 2015

Microsoft Checks On Millions Of Computers Ransomware


Since yesterday evening, Microsoft has millions of Windows computers on the presence of an active ransomware family-controlled. It involves the Teerac-ransomware, which has been active since early 2014. In recent months, hundreds of thousands of computers with ransomware in touch.

These are essentially computers in Australia, Germany and Turkey. Teerac spreads via email attachments. When a user opens the attachment kinds of files are encrypted and there should be a fee of $ 500 in bitcoin paid to recover the files.According to Microsoft appear every day new instances of ransomware to avoid being detected by anti-virus software.

Due to the increasing activity of Teerac decided the Microsoft Malicious Software Removal Tool (MSRT) update in Windows so that the program can recognize and remove ransomware. The MSRT is a removal tool which is updated every month with new virus definitions and then scan the computer. In the case of an infection, the malware found is then removed. According to Microsoft, prevention is better than cure. Users also are advised to make backups, to keep software up to date, use a pop-up blocker and not to open attachments from strangers.

Wednesday, 9 September 2015

German Company Develops Anti-Espionage Tool Under Windows 10



The German software company Ashampoo has a free program that responds to privacy concerns surrounding Windows 10. "AntiSpy for Windows 10" as the software is called, allows users to configure security, protect their privacy, location services off, and prevents Windows 10 diagnostic and usage data to Microsoft will send.


According Ashampoo Windows 10 offers many 'comfort features' such as Cortana which should simplify everyday life. For this, the operating system collects real 'huge amounts of data "and analyzes user profiles to display personalized ads, according to the developers. "By default, Windows 10 is set to collect than many users would allow more data," as they note.

During the installation of Windows 10 are a lot of options previously enabled and the user remains unclear what use data sends the operating system. "Do you really want Windows 10 to access your calendar, email, location and many other institutions have?" Ashampoo asks. Through AntiSpy users can now easily adjust all settings. The program has two preset preferences, ie disable all reports to Microsoft or use the settings recommended by Ashampoo.

Wednesday, 12 August 2015

Researcher Warns Of DNS Vulnerability In Windows 10



The way Windows handles 10 with DNS requests causes the ISP or the provider of a Wi-Fi network can see what websites are being visited, although there is a VPN (Virtual Private Network) use. Before that warns a Russian researcher.

Windows 10 sends DNS requests to all available network interfaces. These requests are used for example in order to find the location of a web site. The functionality to send the requests to all interfaces are already present in Windows since Windows 8. According to the researcher using the alias "ValdikSS" Microsoft has probably done to accelerate the process, such as a DNS server is unreachable. In this case the answer of a second DNS server is used. However, this ensures that all leaks DNS requests via the network interface, allowing the ISP or provider of the Wi-Fi network can monitor all websites visited.

In the case of Windows 8, the feature that makes this be disabled via the Windows Registry. Even sent Windows 8 and 8.1 all DNS requests through the public interface, DNS spoofing would when using a VPN, however, are tricky. In DNS spoofing is the wrong response to the DNS request from the user data, so for example, will be redirected to a malicious website. In the case of Windows 8 and 8.1 would be the spoofed DNS request will be accepted only if the primary DNS server, which goes through an encrypted VPN connection does not answer.

Windows 10

Windows 10 has changed this, the researcher says. Not only does Windows 10 sends DNS requests to all interfaces, then using the fastest answer arrives. This allows the ISP or provider of the Wi-Fi network can DNS "very straightforward and trustworthy" hijack, warns the researcher. In addition, the option in Windows 10, which for this purpose ensures not to switch off via the Windows Registry. The only solution, according to the researcher is not completely reliable, is to set the DNS servers on the network interface.

Saturday, 8 August 2015

WSUS Allows Attacker Distribute Infected Windows Updates



Companies and organizations that their Windows Server Update Services (WSUS) have not configured securely give attackers the ability to provide the entire corporate network from infected Windows updates.WSUS acts as a proxy for Windows Update. Companies can deploy effectively via WSUS Windows updates within their local network.

Instead of all company computers to connect to Microsoft servers to download updates, this is done once by WSUS. The WSUS server is installed in the corporate network and all connected business computers then will their Windows updates downloaded from the WSUS server. By default, WSUS, however not enabled to use HTTPS. An attacker who already has access to the corporate network can use to take then other company computers.

That researchers Paul Stone and Alex Chapman at the Black Hat conference demonstrated in Las Vegas ( pdf ). To prevent attacks via Windows Updates Windows only accepts updates that are signed by Microsoft. The researchers showed that an attacker Microsoft signed files can reuse to inject malicious updates, which are then to execute arbitrary commands on the attacked computers.

The attack, according to Stone and Chapman easy to avoid, namely setting up SSL. Most companies would also do this, so let them versus SC Magazine know. Companies, however, have not brought the risk that a system at one time the entire corporate network can compromise, the researchers said. In addition to enabling SSL by companies that use WSUS, Microsoft may also screwing security. The software giant would namely to use a separate certificate for the signings of Windows updates.

Thursday, 6 August 2015

Illegal Software Hinders Cleaning Infected computers


Almost one million computers are still infected with the Confickerworm from 2008 mainly because of users of pirated software and ICT development in countries. Which enable researchers from the TU Delft , which their study next week at a conference presentation in Washington DC.

According to the researchers, the figures show that the removal of botnets slower than replacing Windows XP computers.Conficker was one of the largest botnets ever. The worm spread via a vulnerability in the Windows Server service which was patched in 2008 through an emergency patch from Microsoft. In addition, used the shared network folders and the Autorun feature. Six years ago, security companies and researchers knew the botnet to "sink holes", which infected computers do not connect to the servers of the cyber criminals behind the botnet.

Despite various measures to clean up infected computers, there are nearly one million computers infected with Conficker. It is in many cases illegal versions of Windows XP and Vista. According to the researchers enable users of pirated software, automatic updates, fearing updates which disables their illegal software, Microsoft has already said that it also provides illegal Windows versions of security updates.

To address the problems with clearing of botnets and cleaning up infected computers the researchers argue that in addition to helping countries with their ICT development, automatic updates and automatic cleanups are the main tools for the issue.Software developers should configure their software so that the installation of security updates is enabled by default and that all computers receive the updates, even if they are using a pirated version of the software.

Thursday, 30 July 2015

Researchers Crack Smart Safe Via USB Stick


Researchers from the US security Bishop Fox managed a "smart safe" by manufacturer Brinks with nothing more than to get a USB stick open. The problem is playing in the CompuSafe Galileo of Brinks, which can contain up to $ 240,000.

The vault has a touch screen and Internet and runs on an embedded version of Windows XP. Once there is money in the safe it is placed automatically by a reader scanned and added to the total. Information about the contents of the safe can be printed daily and is also sent to Brinks over the internet. The smart safe also has a USB port for technicians and making backups. The researchers wrote a malicious script that loads automatically from a connected USB stick.

To open the safe door the USB stick only needs to be connected, then after a minute automatically opens the safe door. For this, an attacker must have physical access to the safe. To erase traces of theft can also database that keeps track of how much money there is to be adapted in the safe. The vulnerability was more than a year ago reported to Brinks, but according to the researchers, the company's problems still not resolved, so let them Wired know. The researchers will present their attack this year at the Def Con hacker conference in Las Vegas show .

Friday, 24 July 2015

AV Comparatives Test Lab: Experienced Mac User To A Virus Scanner


Experienced Mac users can watch what they download a virus scanner, according to the Austrian test lab AV-Comparatives . The test lab decided to test ten virus for Mac OS X on the detection of malware. In addition, specimens were taken for both Mac and Windows, because the Mac virus indicate that they can also detect Windows malware.

The reason is that Mac computers can also get in touch with Windows malware, for example in the case of e-mail attachments or USB sticks. What is striking about the test, the amount of malware which has been tested. In the case of Mac malware is about 105 newly discovered specimens, while the most prevalent malware specimens were used for Windows. In other tests of AV-Comparatives for Windows be used thousands of malware examples, but the number for Mac is so low that the counter remains stabbing at 105.

Of the ten scanners able to detect seven parcels 100% of all Mac malware, while a similar number this occurs in the Windows malware. Avast, AVG, ESET, Kaspersky and Sophos are the scanners that detect all malware in both areas. When it comes to Windows malware are the only F-Secure (28%) and Intego (50%) who stabbing drop in the detection of Windows malware.Meanwhile, all the anti-virus companies have their signatures updated to missed malware are detected.

The question remains whether Mac users now need a virus scanner. "Experienced and responsible Mac users to be careful with the programs they install and where they get which can reasonably argue that they do not risk running Mac malware," said AV-Comparatives. The lab says that users who are not experts, children and users with regular software experiment there can take advantage of to use a Mac virus scanner.

Monday, 20 July 2015

Researchers "Freeze" Software To Stop Malware


Researchers have devised a way to stop malware on computers, namely the "freezing" of software. Most software for Windows is dependent dynamic-link libraries (DLLs). A DLL is an executable file that is used by programs to share code and other resources required for certain tasks to carry. Windows contains several DLLs with functions and resources needed programs to the Windows environment function.

Since a DLL contains various related code, a program that will make use of it more code into memory than it actually needs.Malware can make use of this extra code if it knows how to use a vulnerability in the application. Researchers Collin Mulliner and Matthias Neugschwandtner invented a tool called Code Freeze a program that analyzes the code exactly you need from a DLL and which part is missing. Then, the tool overwrites the unused DLL code that the program loaded into the computer's memory, so malware can not make use of it.

Overhead

Code Freeze itself is offered as a DLL and would provide little overhead. During a demonstration appeared that Adobe Reader Code Freeze opened a few seconds slower than without the tool was. However, more than half of the DLL code reader loaded in the memory has been switched off, without the impact that this had on the program. An instance of malware which Mulliner had made earlier Adobe Reader still managed to attack, here succeeded after switching Code Freeze no longer.

Because the adjustment of the DLL code occurs in memory and not on the hard disk, both plans would be used as DLL files are not permanently changed. The software has been tested on Windows 8.1 32-bit. Mulliner late Tom's Guide that he wants to offer along with Neugschwandtner Code Freeze to Microsoft. Eventually, the researcher hopes that Microsoft will implement the tool and software developers here will go along. Next month Code Freeze will be discussed at the Black Hat conference demonstrated in Las Vegas.

Friday, 12 June 2015

Windows 10 Apps Let Users Protect Against Malware


Microsoft has added new technology to Windows 10 apps which use the virus present in the system to protect users from malware. These involve any security solution and not just Microsoft. According to Microsoft can help application developers as a new way to protect users from dynamic script-based malware and special attack vectors.

The solution that Microsoft has coined the Antimalware scanning interface (AMSI). This is an interface standard that allows applications and services can integrate with any installed security program. It is primarily intended for difficult to detect script malware. However, Microsoft looks beyond "scripting engines" as PowerShell, which require the virus to control specific code.

It is also considered communications apps inspecting messages for malware before they are presented to the user or games that monitor plug-ins to install. It will happen in a way that users do not need to do. In this way, malware that tries to hide and use built-in Windows scripting hosts will be inspected on a much deeper level, which should provide additional protection.

Wednesday, 3 June 2015

Bug In Skype Chat Fixed


The bug in the chat function of Skype's already solved: Skype has released a software update.
In the chat you came into trouble if you typed the following characters and sent: http: // :. Then crashed chat program. Even if you got sent to the characters: Skype quit and each time the program rebooted, the chat service crashes again.


The bug affected only people who use a Skype version for Windows, Android or iOS. The problem did not occur with the Mac version and those using the touchscreen version for Windows 8, reports VentureBeat .

On skype.com/download can now download the latest version of the program.

iMessage crash

A painful situation for Skype, says tech editor Nando Kasteleijn. "Especially because typing http: // :. prevents faster than the strange series that marks late crash iMessage So if you want to send a link to someone, you better direct copy and paste the entire URL. "

SkypeSupport We need a new version of Skype asap. Crashing Bug Affecting phone and desktop clients.- Rafael Rivera (WithinRafael) June 2, 2015

Last week it was announced that a message with a series of strange characters include your iMessage, WhatsApp and Twitter Account may crash. "It is striking that several platforms prove to crash relatively quick succession after entering certain characters," said Nando.

Skype has thus solved the problem and that's a lot faster than Apple.

Wednesday, 27 May 2015

Microsoft Is Software That Adapts Engine Block


For users from adware and other unwanted changes to protect the browser Microsoft last year, various measures announced with programs that do not comply with the rules by the security of the software giant will be identified and blocked.

One of the measures announced by Microsoft to prevent users can not change their search engine after it has been modified.Some adware programs and change the default search engine by their own search engine and then try to prevent users restore the original engine in many ways.

From June 1 this year, Microsoft will detect and block these types of programs. It also involves programs that contain code to avoid customizing the search engine, but where this is not enabled. To avoid detection later Microsoft advises developers of these programs is therefore to remove the code.