Showing posts with label Windows 10. Show all posts
Showing posts with label Windows 10. Show all posts

Wednesday, 10 February 2016

Major Updates For Windows, IE, Office And Edge


During the February Patch Tuesday, Microsoft released 13 security updates for critical vulnerabilities in Windows, Internet Explorer, Microsoft Edge Office, Microsoft Server Software, the .NET Framework and Adobe Flash Player. Six of the updates are rated as critical.

In this case, an attacker could execute arbitrary code on the computer with hardly any user interaction. It involves, for example just visiting a malicious or hacked website. The remaining updates are for vulnerabilities that an attacker who already had access to a system to increase its rights or cause a denial of service.

Two of the vulnerabilities in Microsoft SharePoint and Windows, were already known before Microsoft had released an update.These vulnerabilities would not be attacked active. Most problems have been resolved in Internet Explorer. It involves a total of 13 vulnerabilities. There are also two critical vulnerabilities in the built-in PDF reader in Windows 8.1 and later. Via a malicious PDF document, it was possible for an attacker to take over your computer. An overview of all updates on this page to find. Updating is done on most Windows computers automatically.

Thursday, 5 November 2015

Automatic Update QuickTime Does Not Work On Windows 10


There is a problem with the automatic update feature of QuickTime on Windows 8 and 10, which indicates that the updater users up-to-date, even though there is a new version available. In August released QuickTime 7.7.8 in which multiple critical vulnerabilities were patched.

Through the nine vulnerabilities could allow an attacker to crash the progam or arbitrary code on the computer can perform, such as installing malware. The opening of a malicious media file would be sufficient in this case.

According to Alton Blom this is probably because QuickTime is not automatically on Windows 8 and 10 installs a new version, while this is the case with other Windows versions. Blom approached Apple. The company informed him that QuickTime 7.7.8 for Windows 7 and Vista is designed. When Apple this version also automatically on Windows 8 and will roll out later is unknown. Users can as a temporary solution to the latest version from the Apple website to download. Although this is in accordance with Blom initially did not work, the version offered would now be able to be installed without difficulty.

Saturday, 31 October 2015

Microsoft Launched Windows 10 Experiment With Pirated Softwares


Microsoft will soon launch an experiment in which users of a pirated version of Windows 7 or Windows 8.1 simply a legal version of Windows 10 can upgrade. At present, users can install a free legal version of either operating system Windows 10.

According to Microsoft, users would an illegal version kinds of "creative ways" seeking to start the upgrading process, then purchase a legal version of Windows 10. How many users it will make Microsoft is not known, but because of these developments, there will soon be in the United States to start an experiment.

Users of a counterfeit version of Windows 7 or 8.1 will be able to make a legal version of its operating system via a mouse click. This can be done via the Windows Store or entering an activation code which is obtained somewhere else. If this make Microsoft allows more users with a genuine Windows version works will expand the experiment and rolling out in other countries.

Microsoft Will Offer Windows 10 Through Windows Update


Microsoft will soon be on computers running Windows 7 and Windows 8.1 start offering Windows 10 through Windows Update. It is primarily an optional update. According to Microsoft, this should make it easier for users to switch to the new operating system.

Early next year, the Windows 10 update will appear as "recommended update" will be offered. Depending on the Windows Update settings, this may mean that the upgrade takes place automatically. Before the actual installation is running, users have the ability to break down the system or put through. After installing Windows 10 users have 31 days to let restore the previous operating system and the latest version of Windows do not like Microsoft as late Terry Myerson know.

Image

There soon a new version of the Media Creation Tool, Microsoft software to witness a DVD or USB stick from which Windows 10 can be installed. Now there are between 32- and 64-bit and Windows version such as Home or Pro are selected, but later allows users to create a single image to make it all installations.

Monday, 19 October 2015

Microsoft Promotes Edge In Windows 10 To Adjust Browser


Windows 10 users that in the future the default browser will be able to customize Microsoft's request to Edge and try not to move. Even when adjusting the default music and photo app praises Microsoft's own apps.

According to a new Preview Build of Windows 10. WinBeta discovered the changes in the test version of the operating system. This is still an adjustment in a Preview Build of Windows 10, but Microsoft often conducts these adjustments in the final version of the OS.

For the launch of Windows 10 had notably Mozilla criticized the policies of the software giant. When upgrading from Windows 7 or 8.1, the browser is set previously been replaced by Microsoft Edge, which is the default browser in Windows 10. Figures show that many users after the upgrade, change the default browser, making Chrome become by far the most popular browser for Windows 10 users.

Wednesday, 9 September 2015

German Company Develops Anti-Espionage Tool Under Windows 10



The German software company Ashampoo has a free program that responds to privacy concerns surrounding Windows 10. "AntiSpy for Windows 10" as the software is called, allows users to configure security, protect their privacy, location services off, and prevents Windows 10 diagnostic and usage data to Microsoft will send.


According Ashampoo Windows 10 offers many 'comfort features' such as Cortana which should simplify everyday life. For this, the operating system collects real 'huge amounts of data "and analyzes user profiles to display personalized ads, according to the developers. "By default, Windows 10 is set to collect than many users would allow more data," as they note.

During the installation of Windows 10 are a lot of options previously enabled and the user remains unclear what use data sends the operating system. "Do you really want Windows 10 to access your calendar, email, location and many other institutions have?" Ashampoo asks. Through AntiSpy users can now easily adjust all settings. The program has two preset preferences, ie disable all reports to Microsoft or use the settings recommended by Ashampoo.

Tuesday, 1 September 2015

Update Windows 7 And 8.1, Allows Microsoft To Collect Additional Data


Microsoft is again under fire for collecting data from Windows users. Last week, the software giant has published several non-security related updates that add the "telemetry tracking service." Through this service, which also exists in Windows 10, additional system information is sent to Microsoft, reports gHacks.

It's about KB3068708, KB3022345, KB3075249 and KB3080149. The last two updates are optional but KB3068708 is a recommended update. By default Windows install this update whatsoever. Sending the data seems to only happen when users on Microsoft's Customer Experience Improvement Program (CEIP) join in, so let Ars Technica know. However, this is done by default during the installation of Microsoft Office.

What data is accurately collected and sent to Microsoft is unclear. If CEIP is disabled, there appears little data to go to Microsoft's servers. Disabling CEIP requires different actions. Critics say Microsoft should make it easier for users to opt out of this type of data collection programs and clarifies what information is collected.

Wednesday, 12 August 2015

Researcher Warns Of DNS Vulnerability In Windows 10



The way Windows handles 10 with DNS requests causes the ISP or the provider of a Wi-Fi network can see what websites are being visited, although there is a VPN (Virtual Private Network) use. Before that warns a Russian researcher.

Windows 10 sends DNS requests to all available network interfaces. These requests are used for example in order to find the location of a web site. The functionality to send the requests to all interfaces are already present in Windows since Windows 8. According to the researcher using the alias "ValdikSS" Microsoft has probably done to accelerate the process, such as a DNS server is unreachable. In this case the answer of a second DNS server is used. However, this ensures that all leaks DNS requests via the network interface, allowing the ISP or provider of the Wi-Fi network can monitor all websites visited.

In the case of Windows 8, the feature that makes this be disabled via the Windows Registry. Even sent Windows 8 and 8.1 all DNS requests through the public interface, DNS spoofing would when using a VPN, however, are tricky. In DNS spoofing is the wrong response to the DNS request from the user data, so for example, will be redirected to a malicious website. In the case of Windows 8 and 8.1 would be the spoofed DNS request will be accepted only if the primary DNS server, which goes through an encrypted VPN connection does not answer.

Windows 10

Windows 10 has changed this, the researcher says. Not only does Windows 10 sends DNS requests to all interfaces, then using the fastest answer arrives. This allows the ISP or provider of the Wi-Fi network can DNS "very straightforward and trustworthy" hijack, warns the researcher. In addition, the option in Windows 10, which for this purpose ensures not to switch off via the Windows Registry. The only solution, according to the researcher is not completely reliable, is to set the DNS servers on the network interface.

Wednesday, 5 August 2015

Privacy Tool Prevents Tracking By Windows 10


A programmer has created an open source privacy tool tracking through Windows 10 turns off, so he has via Reddit announced. The "Disable Windows Tracking Tool" developed by Syed Qazi, alias "10se1ucgo". Since the launch of Windows 10, there is a lot of criticism has been the standard operating system settings because they send back all sorts of information to Microsoft.

The tool of Qazi is primarily intended for non-technical Windows 10 users and let people through a few clicks all kinds of tracking options off. For example, the gathering of telemetry turned off, as well as the log file which collects all kinds of information. Furthermore, removing the tool tracking services and modifies the HOSTS file so there is no longer known tracking domains can communicate. According to the programmer is Windows 10 surrounded by fear, which is not always justified. But much is justified, let it faces ZDNnet know.

Hash:

488d92df87bad53cf422dc528ca63f88e9bdbcf5

Download Link:

Github

Sunday, 2 August 2015

Cisco Warns Of Emails With "Windows 10 Upgrade"


Cyber criminals have seized the launch of Windows 10 to distribute emails that attempt to infect surfers with ransomware. Before warns network giant Cisco . Windows 7 and Windows 8.1 users can upgrade to the new Windows version.

And cyber criminals now play in. The emails have the subject line "10 Free Windows Update" and seem to come from update@microsoft.com. The message that the recipient can upgrade to Windows 10. For this, the attached "installer" should be opened. In reality, the e-mail attachment "Win10installer.zip" a variant of the CTB Locker, a known form of ransomware that encrypts files on the computer for ransom.

Then users get 96 hours to pay the ransom in bitcoin, otherwise they lose their files. According to Cisco, the ransomware is now widely distributed. The networking giant also advises users to backup their files and keep these offline, so they can not be attacked by cyber criminals.

Hashes:

SHA256: ec33460954b211f3e65e0d8439b0401c33e104b44f09cae8d7127a2586e33df4 (zip)
aa763c87773c51b75a1e31b16b81dd0de4ff3b742cec79e63e924541ce6327dd (executable)

Friday, 31 July 2015

Windows 10 Wi-Fi Sense Is Not A Security Risk



A much-discussed component in Windows 10, Wi-Fi Sense , which makes it possible to display contacts access to their own Wi-Fi network. Contrary to what some journalists and websites is no security risk, says Windows Follower Ed Bott .

This week IT journalist Brian Krebs came up with an article in which he warned of Wi-Fi Sense. According to Krebs would Windows 10 standard questions to share the wifi password with all the contacts in Outlook and Skype. Then, these users as they are in the area, can use the Wi-Fi network. Krebs warned that the feature could have serious consequences and advised Windows users, therefore, to eliminate it.

Bott says that Wi-Fi Sense does not work this way. In addition, there is no shared password, but only Internet access. The option to share Wi-Fi access is indeed default. However, it only applies to networks that the user has chosen. Users must select the Wi-Fi network from which they wish to share access yourself first.

According to Bott's Wi-Fi Sense vulnerability and therefore no one will make unauthorized connection to the Wi-Fi network of the user. Krebs responds by stating that many users have been conditioned to this type of windows that Windows just asks "yes" button, and shared networks will be shared as contacts on Facebook, Outlook and Skype.

Friday, 20 March 2015

Free Windows 10 Upgrade Makes Illegal Windows Not Legal


The free Windows 10 upgrade Microsoft for users of pirated Windows Version has announced it will not cause the operating system is suddenly legal, as the software giant says. Yesterday there was great commotion when Microsoft announced that all qualified computers, legal and illegal, will upgrade to Windows 10.

This upgrade will apply to users all over the world and not just in China, as confirmed a spokesman opposite Windows Follower Ed Bott . However, the upgrade does not change the status of the machine. "If a device is an illegal or incorrect license used for the upgrade, the device even after the upgrade as illegally or improperly licensed to be considered," explains a spokesman opposite the site Polygon.com . The spokesman further noted that the use of an illegal Windows version, according to experts increases the risk of malware and fraud.

Expert: Passwords Are Not The Problem But People


This week, Microsoft unveiled Windows 10 biometric logon will support so users no longer have to use password to gain access to their systems and accounts, but according to one expert passwords are not the problem, but people.

"Although there are safer alternatives and other authentication methods that can be used in addition to the password, the password will still be a long time with us, whether you like it or not," said Richard Walters of Inter media. He also thinks there should be more attention to their passwords "work". Most programs currently only works with passwords. "The reality is that there is nothing wrong with passwords. People are the problem. Users choose passwords that are too simple, too short and too predictable."

Walters points to the passwords of Sony and LinkedIn users who came out through data leaks. Then it appears that more than half of the passwords consist of fewer than eight characters. Even when websites take measures such as salting and hashing these kinds of short passwords still a risk, according to the expert. Users also increase the risk by using the same password for multiple websites.

Password Management

"Despite all attempts to educate users on the importance of using relatively long, complex passwords and willing hour, they do not. And they are rarely changed." Walters, however, sees programs a solution that not only choose a password for the user, but also changes regularly. This form of "automated password management" can help prevent attacks or reduce their impact. "The risk of a data breach is now greater than ever. The removal of human interaction with passwords and the selection and re sizing automation will be a big step forward at different levels."

Wednesday, 18 March 2015

Chinese Software Pirates Get Free Windows 10 Upgrade


Chinese software pirates who are still working with an illegal Windows version will be at the launch of Windows 10 can upgrade for free to a legal version of the operating system. That Microsoft CEO Terry Myerson announced at WinHEC technology conference in Shenzhen, China. "We will all qualified PCs, legal and illegal, to Windows 10 upgrade," says Myerson opposite news agency Reuters .

In this way, Microsoft hopes to gain more legal versions of Windows in China. Research would show that three quarters of China's software does not have a valid license. Microsoft is working with the Lenovo Group to roll out Windows 10 in China.The new operating system will also use the Chinese security company Qihoo 360 and the Chinese social networking giant Tencent be offered. Myerson also noted that Windows 10 will appear sometime this summer.

Monday, 16 March 2015

Microsoft Would Consider P2P Updates For Windows 10


Microsoft would consider for Windows 10 updates not only to offer through its own servers, but also spread through other sites. This reports The Verge based on a leaked test version of Windows 10. In this version, users can choose to receive updates from multiple locations so they can be downloaded faster.

In addition, users have the option to download apps and updates to computers on the local network or computers on the local network and computers on the Internet. P2P update feature has not been officially announced by Microsoft and it is unknown what technology the software giant used.

In 2013 was Pando Networks acquired by Microsoft. This company has developed a technology for the exchange of files that was based on that of BitTorrent, but includes various modifications. Soon there will be a new test version of Windows 10 appear to the public. This version will also include the new update method.

Saturday, 14 March 2015

Expert Warns Of Patch Policy Windows 10


Windows 10 has yet to appear, but a security of the Slovak anti-virus company ESET has both end users and businesses warned that Microsoft's patch policy for the new operating system the door for zero-day attacks open.

With Windows 10, Microsoft will roll out updates in several ways. There will be a Long Term Servicing (LTS) branch for companies with important systems. In this case, only security updates will be rolled out, but no new features. Then there is the "Current branch for Business". By computers and devices to set this new feature updates will be rolled out after they have been tested extensively in the consumer and validated.

In this way, systems can be upgraded with great certainty. Talking only about new features. Security updates are still always immediately available. Finally there are the consumers that all updates, both security and new features, immediately received.According to expert Aryeh Goretsky it makes sense to divide Windows users into different groups to test patches. He suspects that the patches are rolled out among consumers and not repaired properly works first before they are distributed to companies.

This approach brings under the expert also has its disadvantages. Consumers and organizations that do not run the enterprise version of Windows 10 could receive less well tested patches and so may have to deal with crashes. Companies on the other hand, may have to wait longer until Microsoft feels that the updates have been tested enough and she gives green light.

Goretsky says the wait is still how the new patch policy of Windows 10 will turn out, but already advises that if the delay with which companies receive updates ensures that the attack surface increases, organizations are better off with an older enterprise version of Windows that receives updates rather than the enterprise version of Windows 10.

Saturday, 28 February 2015

Lenovo Will Reduce Bloatware On Computers


Lenovo is the amount of preinstalled software on computers, also called " bloatware called "reduce significantly. That leaves the company said in a response to the Superfish debacle. "The events of last week, reinforce the principle that the customer experience, security and privacy should be our top priorities. With this in mind, we will pre-installed applications will be greatly reduced."

In a press release here said Lenovo will start right away. Will be at the launch of computers running Windows 10 "standard image" for computers only contain the operating system and related software as well as software needed to make the hardware work, security and Lenovo applications. "This would be what our industry" adware "and" bloatware "calls must eliminate." In some countries will install Lenovo programs that users expect in these areas.

Furthermore, the manufacturer information about all software preinstalled and explain what each application does. In addition, it will also collect feedback from users and experts going to make sure the right applications have been installed. In addition to changing the "preloadbeleid" will provide users with a Lenovo PC also receive a free six-month subscription to McAfee Safe Live service. About this action will soon appear more details.

Monday, 16 February 2015

Microsoft Provides Windows 10 FIDO Support


Windows 10 will support the specification of the Fast IDentity Online (FIDO) -Alliantie, allowing users soon also through other ways than can log in a password. The FIDO Alliance has set itself the goal to replace the password by authentication methods that are "safer, user-friendly". Microsoft's next include Google, Lenovo, MasterCard and PayPal one of the members.

The parties develop products and services that use the FIDO protocol. This would allow devices that support FIDO are automatically detected and gives users the ability to replace passwords with another authentication method. It may involve fingerprint scanners, biometric solutions as well as voice and facial recognition.

In the case of Windows 10, Microsoft will the FIDO 2.0 specification support, both password-less login as logging permits through a second factor (U2F). In the case of U2F the user uses a special device that is detected via the browser and can be used to log into websites. Websites can thus simplify the password, for example by requiring a four-digit PIN.

Windows 10 Technical Preview available already offers implementations of the FIDO 2.0 specification, so says Microsoft's Dustin Ingalls. This allows business users through their Windows computer and two-factor authentication without a password on services from Microsoft and partners login. Windows 10 also will also support Active Directory integration for local scenarios and Microsoft account integration for consumer services such as Outlook.com and OneDrive.

Thursday, 12 February 2015

Researchers Bypass Windows Security With 1 Bit

A group of researchers has managed to overcome all sorts of important security controls in Windows by changing only one bit. The problem in Windows Kernel played until yesterday evening in all supported Windows versions, including the technical preview of Windows 10.

Microsoft has over the years provided the Windows kernel of all additional protective measures to make it more difficult for an attacker to present a possible leak actually exploit. This involves things like Kernel DEP KASLR, SMEP and NULL dereference Protection. The researchers discovered that the leak made it possible for an attacker who had access to the system to bypass all Windows Security.

The exploit that researchers enSilo developed requirement only adjusting one bit to abuse of the leak. The problem a few months ago was reported to Microsoft, which last night in the form of Security Bulletin MS15-010 came with an update.Through the leak, which in this film is demonstrated, an attacker could raise its rights on the system, according to the description of Microsoft.

The researchers say they have shown that even a small bug can give full control over Windows. "Nevertheless, we find that Microsoft's efforts to secure the operating system have raised the bar properly and making reliable exploits have made much more difficult than before." Yet they say that these measures will not keep attackers at bay and that will add this kind of exploits eventually to their arsenal.