Showing posts with label Windows Update. Show all posts
Showing posts with label Windows Update. Show all posts

Saturday, 2 December 2017

Researcher Discovers Keylogger In HP Keyboard Driver


A researcher with the alias ZwClose has discovered a keylogger in an HP keyboard driver that malware could use. The keylogger was in the SynTP.sys file. This is part of the Synaptics Touchpad driver installed on hundreds of HP laptops.

Although the keylogger was turned off by default, it could have been enabled via an adjustment to the Windows Registry. The investigator warned HP and the manufacturer confirmed the presence of the keylogger. It was code that was actually meant for debugging the driver and was left behind. HP has now released an update to remove the code.

The update can be downloaded from the HP and Windows Update website , the researcher says. All affected models are listed on the HP website. It involves almost 500 different laptops. According to HP, the presence of the keylogger did not ensure that the self or Synaptics had access to customer data. Earlier this year, a keylogger was also found in an HP audio driver .

Monday, 12 October 2015

Kaspersky Close Leak That Windows Update Attacker Left Block



The Russian anti-virus firm Kaspersky Lab has closed a vulnerability in Kaspersky Internet Security poem through which attackers could simply block users' access to Windows Update, the Kaspersky website and other websites, as well as the servers of e-mail provider.

The vulnerability was discovered by Google researcher Tavis Ormandy, who earlier other serious problems in the security of Kaspersky Lab laid bare. Earlier Ormandy also found all vulnerabilities in the software from Sophos, ESET and Avast.The problem with the Internet Security package has been caused by a component called the "Network Attack Blocker".This component aims to protect the computer from malicious network activity. Ormandy discovered that it is actually nothing more than a simple stateless packet filter 'that in the event of an attack on the IP address put on a blacklist.

This design made ​​abuse possible, according to Ormandy. For example, the component was found to recognize a forged TCP packets. Also, the filter did not appear to understand the status of the application layer if there is a packet was received. An attacker could create simple abuse of this by sending the signature of an attack to a Kaspersky user, the IP address was falsified. According to Ormandy, the attacker could, for example windowsupdate.microsoft.com can specify as the sender. The Network Attack Blocker could then access to Windows Update are blocked, preventing users from Windows updates would receive more.

The second problem is a possible such scenario, then only via e-mail. In this case, the security component would have blocked user access to its server. Ormandy warned Kaspersky Lab on September 11, after the update was released last Thursday. Then the Google researcher has decided to details of the vulnerabilities disclose.

Thursday, 1 October 2015

Suspicious Windows Update Shows Test Microsoft


A Windows update that was rolled out unannounced yesterday among users caused some panic, but in retrospect it proved to be a wrong test performed by Microsoft. The update, which was labeled as important, was offered as an additional language update.


The name and description of the update consisted of a random string of characters and contained several broken links. On the forum of Microsoft thought users therefore attackers had managed to compromise Windows Update and so spread malicious updates. Twelve hours after the update was released, Microsoft had opposite Ars Technica that unintentionally a test update was issued and the update has now been removed.

A user who installed the update states that after this laptop are not working properly and the regular Windows Explorer crashed. System would no longer work and the update could not be removed. The fear among users was not unjustified. In the past, attackers have managed the Flame malware spreading via Windows Update on a local network.

Thursday, 25 June 2015

Researcher: Samsung Software Disables Windows Update



The software Samsung on some laptops flour evert appears to disable Windows Update, so users do not receive critical security updates. Before warns Microsoft MVP Patrick Barker . He is active on a forum where someone had a problem with Windows Update.

Further research showed that a file on the laptop was named Disable_Windowsupdate.exe that, as the name suggests, Windows Update turned off. The file appeared to be part of the update software that installs on Samsung laptops. Through this software drivers and programs are updated. Barker decided to contact Samsung and was told that indeed Windows Update is turned off by the software.

The reason is that otherwise the standard drivers to be installed that do not necessarily work with the laptop. To prevent this, switches the Samsung software Windows Update. Experts are puzzled about the operation of the software, just because Windows Update is an important tool for users to automatically install updates. Samsung has not yet responded to the criticism. Barker takes at least that Samsung's software as malware should be considered.

Thursday, 19 March 2015

Finn Gets Microsoft SSL Certificate By Sending Email


The reason that Microsoft this week an SSL certificate for Windows Live invalidated came as a Finnish system had requested via email and received. It was revoked certificate for the domain Live.fi issued and made ​​it possible to carry out phishing and man-in-the-middle attacks. Opposite the Finnish Tivi let the guy know now how he got hold of the certificate.

When Microsoft domain Live.fi launched it was possible to register several aliases that are normally used for administrative matters. The Finnish system decided in his own words "a joke" the alias hostmaster@live.fi to create its own email address, which to his surprise, also failed. Through this alias he could then try to apply for the certificate for the domain. SSL certificates are issued by Certificate Authorities. In the case of the wrongly issued certificate for Live.fi was issued by the Certificate Authority Comodo.

Before an SSL certificate for a domain can be registered, the requesting party must prove that he or she is the owner of the domain. For this show Comodo send a confirmation email to an email address like admin @, admin @, postmaster @, hostmaster @ or webmaster @ domain for which the certificate is requested.

The Finnish system decided by the alias hostmaster@live.fi the certificate for the domain Live.fi to ask and indeed received the confirmation email in his inbox. The man, the Finnish telecoms watchdog warned the problem below, but got no help. Then he warned Microsoft, but even there it remained silent until Microsoft this week decided to withdraw the wrongly issued certificate.

Wednesday, 18 March 2015

Problems Solved Updates For Windows Server 2003


Microsoft has problems with two security updates for Windows Server 2003 last week appeared resolved.It is Microsoft Security Bulletin MS15-025 , which fixes multiple vulnerabilities in the Windows kernel. Due to an error, Microsoft continued to offer the update to users, even though they had already installed the patch.

There is now a new version of the update appeared. Both users that the first version of the update had not yet installed, and administrators who had done so, need to install the new version. According to Microsoft, this is necessary to avoid future problems with detection updates.

The second problem arose in Microsoft Security Bulletin MS15-027 , which fixes a vulnerability in NETLOGON. After installing the update could be "connectivity issues" arise. Also in this case there is a new version of the update appeared that administrators need to install Server 2003, regardless of whether they had or not installed the first version of the update.

Microsoft Warns Of Rogue SSL Certificate


Microsoft has warned Internet for a wrongly issued SSL certificate for the domain " Live.fi "that could be used to perform phishing attacks, spoof content and Man-in-the-middle attacks on Windows Live users. Live .fi is a Finnish domain where users can log in with a Microsoft account. Through the wrongly issued certificate, an attacker could create a malicious website, which browsers should show that it is a valid website. Also, an attacker who is between the user and the Internet may be intercepted by the certificate credentials and other data.

Microsoft says that it is not aware of attacks. Meanwhile, the certificate has been revoked by the Certificate Authority (CA) that issued the certificate. According to Paul van Brouwershaven GlobalSign involves Comodo, that would be misled by a false email account to create the certificate and issue.

Measures

To protect users against fraudulent use of the certificate will Microsoft on all supported Windows versions, the Certificate Trust List (CTL) update. In the case of Windows 8 and 8.1, Windows RT and RT 8.1, Windows Server 2012 and 2012 R2 and for devices running Windows Phone 8 and 8.1 users do not do anything, since these versions of Windows are automatically protected.

For Windows Vista, Windows 7, Windows Server 2008 and 2008 R2 users also need to take any action, as the automatic updater of revoked certificates is enabled. In the case of Windows Server 2003 or for users who do not use the automatic updater of revoked certificates, Microsoft recommends that every now available update ( 2.9175 million to install) directly.

Monday, 16 March 2015

Microsoft Would Consider P2P Updates For Windows 10


Microsoft would consider for Windows 10 updates not only to offer through its own servers, but also spread through other sites. This reports The Verge based on a leaked test version of Windows 10. In this version, users can choose to receive updates from multiple locations so they can be downloaded faster.

In addition, users have the option to download apps and updates to computers on the local network or computers on the local network and computers on the Internet. P2P update feature has not been officially announced by Microsoft and it is unknown what technology the software giant used.

In 2013 was Pando Networks acquired by Microsoft. This company has developed a technology for the exchange of files that was based on that of BitTorrent, but includes various modifications. Soon there will be a new test version of Windows 10 appear to the public. This version will also include the new update method.

Friday, 13 March 2015

Microsoft Update Causes Problems On Windows 7


A Microsoft update that was released on Tuesday shows problems on computers running Windows 7, according to all kinds of complaints from users. The update in question is KB3033929 and adds SHA-2 support to Windows 7 and Windows Server 2008 R2 far, according to the description.

Lots of users complain however that the update causes problems with the installation and ultimately not installed can be.On some systems, there would be even a "loop," meaning fail to install the update and restart your computer, and then attempt to reinstall the update, which again failed. A solution does not exist yet and Microsoft has not yet responded. In recent months, Microsoft had to deal with several updates that had to be withdrawn because of problems.

Sunday, 1 March 2015

Microsoft Allows Users To Download Windows 7 ISO


Microsoft has launched a new website where users with a valid license can download a full version of Windows 7, for example, if they have no CD or want to install the operating system from a USB stick.However, this is only the "retail versions" of Windows 7.

These are versions which are sold in retail stores, among other things. Computers that are supplied as standard with Windows 7 use in most cases, an OEM version and who can not use the " Microsoft Software Recovery download "website. To download users must first give up their license the ISO file, after which the language as well as a 32-bit or 64-bit version can be selected. The ISO is then burn to a CD, but there is also a special Microsoft tool to convert the ISO to a USB stick.

Microsoft points to the site to another page where users ISO files from Windows 8.1 can download without specifying the license key. The difference is that windows 7 without a license key can be installed, after which the operating system 30 days is to be used fully. Windows 8.1, however, install only with a valid license.

Thursday, 26 February 2015

Virus Switched On Millions Of PCs From Windows Update


The Ramnit botnet that this week by Europol, investigative services, Microsoft and security from the air was removed the last 5 years more than 3 million computers Windows Update, Windows Firewall, Windows Defender, User Account Control and the virus off, leaving the machines did not receive important updates and risked getting infected by even more malware.

Ramnit first appeared in 2010. The malware is designed to steal passwords and data for Internet banking. Also, .exe virus, .dll- and .html files on hard drives and connected storage devices infect. Once activated switches the kinds of security measures in Windows as well as the present virus. Ramnit above used a special blacklist with more than 300 different anti-virus programs.

The last time the virus would only disable Microsoft virus scanners. The software giant detected the last six months, some 500,000 computers were infected with Ramnit. Since this week the cyber criminals behind the botnet would no longer be able to communicate with the infected computers. The infection and custom settings are still active.

Virus scanning and removal tools could, however, detect and remove malware. Microsoft recommends that users, therefore, to perform a virus scan regularly. In addition, it is recommended to be careful when opening emails and messages on social media from unknown users and software only download from the website of the supplier. In this way, new infections can be prevented.

Hashes:
b87dda7ab5ff13248e3c084c63d02b4a
4390dec38fefb2f7197b6b5cd3f7ab30
69412c0433d966b49795fa10bb7387ed
72609754b056fe8793fb848fe0167112