Showing posts with label Software Vulnerability. Show all posts
Showing posts with label Software Vulnerability. Show all posts

Sunday, 8 November 2015

NSA Would Most Zero-Day Vulnerabilities In Software Report


The NSA would be 91% of the most critical zero-day vulnerabilities it finds in software used in the United States or developed report, as the US Secret Service let the website know. How many software vulnerabilities and what exactly is going unreported.

The remaining 9% of the vulnerabilities found is resolved before the NSA, the supplier can inquire or is not reported due to national security reasons. Zero-day vulnerabilities are vulnerabilities for which no security update from the vendor is available.Through this kind of leak attackers have a greater chance of a successful attack, for example, to gain access to systems.

"The US government is committed to an open, interoperable, secure and reliable internet. In most cases, the reporting responsibility of a newly discovered vulnerability clearly in the national interest," according to the explanation of the NSA.Secret Service claims that there advantages and disadvantages to the decision to report a leak. This could cause the possibility of being lost to collect important foreign intelligence among other "terrorist attacks" may occur.

The NSA now uses a process to determine when it reports a vulnerability. "While these decisions may be complicated, the government tends to be a responsible and discreet reporting vulnerabilities." According to current and former government officials, the reassurances of the NSA, however, misleading, because the Secret Service vulnerabilities yourself first used to conduct attacks them before the companies inform that these problems can fix and patches to users can roll, reports news agency Reuters .

Wednesday, 28 October 2015

Google Friday Close Critical Vulnerability In Picasa


Upcoming Friday, October 30th, Google will for the second time trying to close a critical vulnerability in Picasa, the photo service of the Internet giant. The vulnerability a remote attacker to take over the system, as security reports Secunia which discovered the problem.

Picasa is a free service and Google's program to edit your photos and share. By using the vulnerability in the software, it is possible to create a 'integer overflow "to cause, after which random code on the computer may be carried out, such as the installation of malware. The problem has been fixed in version 3.9.140 build version 3.9.140 build 248 and 239 for Windows.

Secunia warned Google in early August for the issue. On September 19 there appeared an update in the form of version 3.9.140 build 248, only this version does not solve the problem. Next Friday, Google has shown once again that it will release an update for the vulnerability. In the meantime, there is no solution to the problem, according to Secunia.

Sunday, 15 February 2015

Google Relaxes Deadline For Revealing Leaks


Google has the deadline that applies to vulnerabilities to reveal something more flexible in the products of other software companies. Since last year, the search giant puts a team of hackers called Project Zero that is actively looking for vulnerabilities in widely used programs.

Once a vulnerability is found getting the informed supplier 90 days to come up with a patch, otherwise Google will automatically reveal the details. Much to the annoyance of Microsoft, which in one case after 92 days came with an update.The software giant Google had asked for the details after the release of the update to disclose, but no reply was given.Therefore users would have run unnecessary risks.

Now, Google announced that it will somewhat lenient policy. If a deadline expires on a weekend or US holidays, the deadline for the next working day will be postponed. In addition, there is a grace period of 14 days. If the deadline of 90 days expires but the supplier in the next 14 days say they come with an update, the details will appear only after the release of the patch.

"The publication of a non-issue patches will now only take place if the deadline is missed more than two weeks," said Chris Evans of the Project Zero team. The new rules apply not only to the research team at Google, but for all the parts and members of the search giant who discover vulnerabilities in software from other parties.

Despite criticism from some parties that the deadline is certainly successful, suggests Evans. Most vulnerabilities Project Zero discovered were found in Adobe Flash Player. All 37 reported vulnerabilities in Adobe were patched within the deadline of 90 days. In total discovered Project Zero 154 vulnerabilities, of which 85% were resolved within the deadline.

In the case of the 73 leaks that were reported to suppliers after October 1, 2014 even it comes to 95%. And as it looks now, there will be no missed deadlines in February. "Deadlines seem to work to improve the patch time and safety for users, especially if they are consistently maintained," Evans says.