Showing posts with label Security Updates. Show all posts
Showing posts with label Security Updates. Show all posts

Tuesday, 19 April 2016

Google Helps Owners Hacked Websites With Maid


If Google webmasters and owners of a hacked website helps to existing vulnerabilities and malicious code quickly resolved, according to research. According to Google , more than 10 million Internet users every week with malicious Web sites in touch.

It often involves hacked websites which install owner or webmaster failed security updates or to choose a strong password.This makes it easy for cyber criminals to take over a website and use for example distributing malware. Google warns Internet users of such web sites, but many webmasters do not follow the Internet giant by that something is wrong.

And even if they are informed of the security incident, they miss to overcome the knowledge to solve the problem. Google therefore decided to look together with the University of California at Berkeley how webmasters can be best informed and the problem as soon as possible can be resolved. From the research shows that if Google cooperates directly with the webmaster, 75% of webmasters manages to secure their website. A process that takes an average of three days.

To help webmasters soon be considered by investigators three important steps. The first and most difficult step is to inform the webmaster. In the case webmasters their website via Webmaster Tools have registered a Google mail ensures that 75% of webmasters secures the website. In the case of the webmaster is unknown the e-mail address, have browser warnings and alerts in the search engine a success rate of 54% and 43%.

The second step in the process is to give hints about the harmful content. Attackers often hide their files, which complicates the cleaning process. In the event Google tips on the infection to the webmaster e-mailed this made sure that the cleaning sheet was 62% faster than warnings without tips. The third step is to make sure that continues to clean the site. Google investigated and cleaned hacked websites and found that 12% had been hacked again within 30 days. That shows, according to the Internet giant how important it is to find the cause of a hack rather than to remedy the effects.

Thursday, 12 November 2015

Google Stops Support Chrome On XP And Vista In 2016


A little more than four months and then stop supporting Google Chrome on Windows XP, Vista and Mac OS X 10.6, 10.7 and 10.8, as Google has announced. The browser will still continue to work, but will not receive security updates and other fixes more.


The reason that Google discontinues the support is that the operating systems are no longer supported by Apple and Microsoft. Users of Windows XP, Vista and the older OS X versions get Google advised to upgrade to a newer operating system. According to the Internet giant walk unsupported platforms such as Windows XP, a greater risk of becoming infected by malware.

The Google story is remarkable. Support for Windows XP expired last April, but Vista until April 11, 2017 supported by Microsoft security updates, according to the Windows life cycle.

Wednesday, 4 November 2015

Mozilla Launches Firefox With Built AdBlocker


Mozilla today released a new version of Firefox was launched which features a built AdBlocker, so as to better protect user privacy. According to Mozilla must Tracking Protection, as the new feature is called, give users more control and choice while browsing the Web.

Users can now determine which data third parties receive them. "The Private Browsing mode on Chrome, Safari, Microsoft Internet Explorer or Edge does not provide the protection that Firefox offers," said Mozilla's Nick Nguyen. Private Browsing with Tracking Protection will namely active ads, analytics trackers and buttons for sharing content on social media block.

Since some sites do not work properly if certain trackers are blocked, it is possible to simply Tracking Protection for a particular website off. There is also a new control center to the browser added that collects all security and privacy settings in one place. Firefox 42 also does not contain security updates. Updating via the browser, Mozilla.org.

Thursday, 8 October 2015

Huawei Will Not Patch 3G Routers Vulnerabilities



A security researcher has several 3G routers from the Chinese manufacturer Huawei network several vulnerabilities discovered that the company will not patch. It involves 14 models used by ISPs around the world, including Tele 2 and E-Plus in Germany.

According to researcher Pierre Kim devices are poorly designed and they are full of vulnerabilities. For example, the password and the name of the administrator stored in plain text in a cookie, the DNS server can be modified without valid credentials, the wifi password can be retrieved without credentials and it is possible for one of the models without authentication to adapt the firmware.

Kim Huawei warned in August about the vulnerabilities, but the Chinese manufacturer announced it will release no security updates because the devices are no longer supported. Huawei also advises users to no longer supported models to replace them with new routers. Kim then finally decided to publish his research.

Tuesday, 6 October 2015

Microsoft Is Investigating Software Development Bug Free


No more blue screens or installing security updates may appear in the future, but Microsoft researchers say they have found a way to produce bug free software. "Program Verification is the last 40 or 50 years the holy grail in computing," said Bryan Parno, a researcher at Microsoft who has published a paper about the project (pdf).

The researchers warn that they are still far away from a world where large computer programs, such as operating systems, bug-free to be built. Recent developments, however, have made it possible for smaller-scale write software which can be mathematically proven that no errors are present so that the program freezes or contains vulnerabilities.

"These tools finally reach the point in this way so that developers can program software," says Jay Lorch, another researcher who works on the project. This involves improved hardware and faster algorithms. At this time, according to the researchers, it is still too expensive and impractical for example, to develop an operating system in this way, since these types of systems contain millions of lines of code that are often based on earlier work.

Initially, therefore, is especially given to systems where safety and reliability are very important. Also, the researchers focus on systems that communicate only with other computers, since they are more predictable. "People are very complicated, so specifying how a man with a program handles is very complex," said Lorch.

"If we are successful, people will look back over 10 to 15 years and say they can not believe that it has been programmed in this way. It is compared with doctors who operate without anesthetics or sterilized equipment," Parno adds. The project, known as the Iron Fleet bears, this week will be presented at the 25th ACM Symposium on Operating Systems Principles.

Tuesday, 1 September 2015

Update Windows 7 And 8.1, Allows Microsoft To Collect Additional Data


Microsoft is again under fire for collecting data from Windows users. Last week, the software giant has published several non-security related updates that add the "telemetry tracking service." Through this service, which also exists in Windows 10, additional system information is sent to Microsoft, reports gHacks.

It's about KB3068708, KB3022345, KB3075249 and KB3080149. The last two updates are optional but KB3068708 is a recommended update. By default Windows install this update whatsoever. Sending the data seems to only happen when users on Microsoft's Customer Experience Improvement Program (CEIP) join in, so let Ars Technica know. However, this is done by default during the installation of Microsoft Office.

What data is accurately collected and sent to Microsoft is unclear. If CEIP is disabled, there appears little data to go to Microsoft's servers. Disabling CEIP requires different actions. Critics say Microsoft should make it easier for users to opt out of this type of data collection programs and clarifies what information is collected.

Sunday, 16 August 2015

The Seven Deadly Sins Of System


System administrators play an important role in the prevention of attacks on their organization. However, there are arranged attacks in the news in which there is, for example, vulnerabilities have been used to infiltrate the corporate network for which for many years were available updates.

However, the security updates were not installed so employees by opening a document or visit a Web site became infected.This relates to old vulnerabilities in, for example Microsoft Office and Java regularly targeted. Among other targeted espionage attacks. Something recently the FBI warned . There are also other things that should have a system in place, or else run the risk organization. Reason for security GFI Software to a list of seven deadly sins to create system in which not installing security updates is called first.

The other mortal sins are using default configurations and passwords, working with admin rights, not documenting changes, IP addresses and license keys, no viewing log files, password sharing and finally the question of passwords. Often alerting system administrators and end users to phishing attacks say that they should never share their passwords, then himself to the user asking his password if there is a problem. End users should also never be asked for their password, according to the explanation of the last mortal sin.

Thursday, 6 August 2015

Illegal Software Hinders Cleaning Infected computers


Almost one million computers are still infected with the Confickerworm from 2008 mainly because of users of pirated software and ICT development in countries. Which enable researchers from the TU Delft , which their study next week at a conference presentation in Washington DC.

According to the researchers, the figures show that the removal of botnets slower than replacing Windows XP computers.Conficker was one of the largest botnets ever. The worm spread via a vulnerability in the Windows Server service which was patched in 2008 through an emergency patch from Microsoft. In addition, used the shared network folders and the Autorun feature. Six years ago, security companies and researchers knew the botnet to "sink holes", which infected computers do not connect to the servers of the cyber criminals behind the botnet.

Despite various measures to clean up infected computers, there are nearly one million computers infected with Conficker. It is in many cases illegal versions of Windows XP and Vista. According to the researchers enable users of pirated software, automatic updates, fearing updates which disables their illegal software, Microsoft has already said that it also provides illegal Windows versions of security updates.

To address the problems with clearing of botnets and cleaning up infected computers the researchers argue that in addition to helping countries with their ICT development, automatic updates and automatic cleanups are the main tools for the issue.Software developers should configure their software so that the installation of security updates is enabled by default and that all computers receive the updates, even if they are using a pirated version of the software.

Saturday, 25 July 2015

Red Hat Patches Leak That Gave Local Users Root Privileges


Red Hat has released security updates for two vulnerabilities allowing a local user to the file / etc / passwd could adapt and root privileges could get. The vulnerabilities are in the libuser library, which is standard on all Red Hat-derived Linux distributions is present.

During an internal investigation discovered security company Qualys different libuser-related vulnerabilities. The first vulnerability is present in the "user helper" and a local user allows to edit the file / etc / passwd. This would be possible to cause a local denial of service. Qualys does not exclude that it is possible for a local user to gain root privileges on the system, but to make the company failed an exploit that realizes this. That did succeed with a second leak in libuser itself.This allows a local user to gain root privileges.

Red Hat released yesterday updates to the vulnerabilities of, after being informed in advance. However, there is a commotion about the publication of Qualys. The company would information about the vulnerabilities, including exploits, published before the Red Hat updates to users could be deployed. Something for discussion on the oss-sec mailing list and Reddit made.

Wednesday, 24 June 2015

US Marine Microsoft Pays Millions For Windows XP


The US Navy has paid millions of dollars to Microsoft to continue to support 100,000 computers still run on Windows XP. The Space and Naval Warfare Systems Command (SPAWAR), which is responsible for communications and information networks of the US Navy, has earlier this month signed a maintenance contract of 9.1 million dollars, reports PC World .

As part of the agreement Microsoft will navy security updates for Windows XP, Office 2003, Exchange 2003 and Windows Server 2003 are provided. The support of this latest Windows version expires next month. The entire contract Microsoft can provide a sum of 30.8 million dollars and continue through 2017.

The US Navy began two years ago with the migration to a newer operating system, but some 100,000 computers are still running XP or other software. A spokesman for the US Navy announced that the Navy still some legacy applications and use programs that work only on older versions of Windows. Until those applications and programs are renewed or phased out the use of these Windows versions is necessary.

Sunday, 21 June 2015

New ExploitKit Focuses Almost Entirely On Flash Player


Adobe Flash Player is the favorite target of cyber criminals has become instead of Java was the last few months several times already demonstrated , but a new trend exploitkit makes this clear again. The Beta Exploitkit, also known as Sundown, is a recently launched exploitkit which is still in the testing phase.

Through exploit kits can cyber criminals Internet users who miss security updates easily infect by example code on a compromised website or to hide in an advertisement. This code then sends visitors to the exploitkit. In the case of Sundown trying to infect the exploitkit Internet via six different vulnerabilities with malware.

This is according to researcher JuK of the blog Malware Do not Need Coffee to four vulnerabilities in Adobe Flash Player and two Windows. Researchers Aditya Sood and Rohit Bansal analyzed a different version in which a Windows vulnerability for IE vulnerability had made. Java, which was a favorite target in the past, is missing. A trend that is also seen in many other recent exploit kits.

The Windows leaks Sundown attacks dating back to 2013 and 2014, while the Flash Player vulnerabilities last year and this year. The IE vulnerability that Sood and Bansal saw was discovered in 2012 and patched. For all vulnerabilities are updates available. Yet there are still internet users who do not install these patches and so risk.

However, the Beta Exploitkit is itself not without faults. Sood and Bansal discovered errors in the administrator panel exploitkit, allowing them to log on and managed to retrieve all kinds of information, such as used server domains, users, domains, location of the victims and what kind of browser that surfing. The exploitkit is still in the testing phase, but the researchers expect that the coming months will be used by cyber criminals.

Friday, 20 March 2015

Multiple Vulnerabilities In OpenSSL Patched


As mentioned earlier this week announced for updates today OpenSSL true that address multiple vulnerabilities. In total, it comes to 14 vulnerabilities, two of which are labeled as "high." This is the highest level for vulnerabilities that uses OpenSSL. The first high-leak is present only in version 1.0.2, and makes it possible to perform a Denial of Service against a server.

The second high-leak was originally labeled as "low", the lowest category that uses OpenSSL. One of the OpenSSL developers had previously indicated that only one high-leak would be, which was in version 1.0.2. Still, it was decided the low-leakage to label as high. It involves "FREAK leak" that previously was revealed by researchers. Through the leak, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

According to the OpenSSL developers was initially assumed that the problem would be small and it was not possible for many servers to downgrade to the weak encryption. Further investigation showed, however, that a significant number of servers supporting the weak encryption. The other vulnerabilities patched today were mainly possible to conduct denial of service attacks against servers. Administrators are advised, depending on which version is installed, upgrade to version 1.0.2a ,1.0.1m , 1.0.0r or 0.9.8zf .

Thursday, 22 January 2015

Windows 10 Free For Users Of Windows 7 And 8.1


Windows 10, Microsoft will make available free of charge for users of Windows 7, Windows 8.1 and Windows Phone 8.1, so the software giant has tonight during a special event let you know. The upgrade to the operating system a year after launch free download. According to Microsoft, this involves more than a "one-time upgrade." Once a machine has been upgraded to Windows 10, Microsoft will continue to support operating system on the machine free of charge for the lifetime of the device.

Windows 10 will release the software giant new features sooner rather that it will wait for a new version of Windows. "We consider it as a Windows Service," said Microsoft's Terry Myerson. Therefore it would soon no longer make use of the device Windows, which would be good news for developers. Companies and business users, however, will have a choice whether they want to receive these consumer-oriented updates or important business rather shielding systems so that only receive critical patches and security updates.

One of the new additions to Windows 10 is an entirely new browser called "Project Spartan". The browser is specially designed for Windows 10 and should provide better interoperability, reliability and traceability. This would include reading articles should be improved and the voice assistant Cortana will be integrated into the browser, so users can find and do things faster. According to Microsoft's Jim alkove Spartan will be safer than ever.

Microsoft also showed tonight that already 1.7 million people in the pilot program of Windows 10 to participate and the software giant has already received 800,000 comments on the operating system. In addition, Windows 7 users were advised to install Internet Explorer 11 already, so they simply can upgrade to Windows 10 as the operating system is available.