Thursday, July 21, 2005

MS05-036 Exploit Published

A proof of concept exploit has been posted for the "critical" Color Management Module vulnerability patched with MS05-036. The incident handlers at the SANS Internet Storm Center has raised the "patch now" alarm.

Kaminsky on Security at Redmond

Stephen Toulouse comments and points to an interview on SecurityFocus where Dan Kaminsky discusses security at Microsoft. There's also a Slashdot thread on the interview. I haven't had a chance to digest it all, yet.

Win2K Update Rollup Hiccups

My colleague Mary Jo Foley has the details on some compatibility problems being caused by the Windows 2000 "Update Rollup" that Microsoft shipped last month-end.

There's a Microsoft KB article explaining the bugs that are affecting products from Sophos, Panda, Internet Security Systems (ISS) and Citrix.

From the story, it appears that the infamous MS05-019 security bulletin, first released in April and re-released in June because it was breaking some applications, is causing more problems again.

Also of note, the blocking tool to delay the automatic download of Windows Server 2003 SP1 will only be available for a few more days. If you need it, hurry and get it.

Wednesday, July 20, 2005

US-CERT Weekly Windows Security Summary

Summary of security items affecting the Windows operating system from July 13 through July 19, 2005.

80 Super Security Tips

PC Mag's Larry Seltzer has published a long list of super security tips he has put together over the years. This is worth bookmarking.

Acquisitive Microsoft

Microsoft is busy on the acquisition/licensing front. First the announcement that a minority equity stake in Finjan formed part of a security patent licensing deal. Then, we learned that Frontbridge is the has been acquired outright.

What’s The Use of Security Advisories?

Donna Buenaventura explains why pre-patch security advisories should be seen as valuable resources to protect end users.

* When Microsoft adds an RSS feed to its security advisories, it'll be close to perfect.

Tuesday, July 19, 2005

AOL's IE Browser

Nate Mook at BetaNews is reporting that America Online (AOL) has released the final version of AOL Explorer, an alternative IE-based browser. AOL claims it has shored up security by fixing some IE flaws Microsoft has yet to patch.

* That's a bit of a stretch, innit?

Windows Anti-Spy Refresh

Microsoft has refreshed the Windows AntiSpyware software, fixing an issue with the signature update mechanism and improving the way the app provides information to the user about processes running on a PC.

Spyware at Cingular Store

Via Lifehacker:

"At the Cingular store this weekend signing up for a plan, I watched the clerk enter my information into a point-of-service web app running inside Internet Explorer. On the second screen, a window with a picture of a palm tree-studded beach appeared, interrupting him. “Damn popups,” he said, clicking the window closed."


* Can you smell the risk?

Monday, July 18, 2005

Support for Industry Patch Day

Larry Seltzer: "Competitors are increasingly hiding behind Microsoft's patch releases; why not do it openly and in the right way?"

Advisory/Workarounds for RDP Flaw

Microsoft has issued a security advisory with pre-patch workarounds for the publicly reported Remote Desktop vulnerability. More importantly, it clears up the conflicting reports on the severity of the flaw, as explained further by the MSRC's Stephen Toulouse.

Friday, July 15, 2005

Explaining Premature Disclosure for IE Flaw

Michal Zalewski discovers another image rendering bug that crashes Internet Explorer. Virus.org says the flaw could be exploited by an attacker with a specially crafted JPEG picture to trigger a buffer overflow (code execution).

This portion of Zalewski's post is rather instructive:

"It is my experience that reporting and discussing security problems with Microsoft is a needlessly lengthy process that puts too much burden and effort on the researcher's end, especially if you just have a crash case, not a working exploit; hence, they did not get an advance notice."

XP SP2 Zero-Day?

Microsoft has acknowledged it is working on a fix for a denial-of-service flaw in XP SP2, fully patched. Some people think it could lead to code execution attacks. There is already chatter about zero-day exploits. Sounds like the ingredients for a security advisory.

Dell, Spyware and My Way

Dell says the "My Way Speedbar" isn't spyware. Google offers a different interpretation.

SWI Team May Start Blogging

Richie Lai, guest blogging on the MSRC Blog says the Secure Windows Initiative (SWI) team may consider delivering future research on its own blog. This comes one day after Robert Hensing explained what goes on behind the scenes when security flaw discoveries are being investigated.

This new level of openness is refreshing but I have this nagging feeling it's driven more by PR considerations than by a legitimate attempt to openly discuss security at Redmond. If I'm wrong, that's a good thing.

Thursday, July 14, 2005

Pre-Patch Investigations Explained

Robert Hensing, a Softie who recently joined the Secure Windows Initiative (SWI) defense team, dishes some details on what goes into patch-creation process at Microsoft, especially the investigative work that is done long before the product team starts coding the fix.

He describes the work done to create workarounds for the javaprxy.dll issue ahead of the full patch and while he recommends the use of temporary workarounds, Hensing made it clear they should "never be used indefinitely in place of the security update."

Schneier on Microsoft/Claria Hubbub

Security guru Bruce Schneier weighs in on the Microsoft/Claria downgrade hubbub with a simple piece of advice: "I recommend using a different anti-spyware program."

Patch Deluge Redux

Corey Nachreiner on this week's patch deluge: "Administrators already have a hard enough time trying to keep up when Microsoft releases 10 security patches on the same day. Now imagine trying to deal with that while also receiving updates from all your other software vendors. This scenario makes it too likely that an IT staffer will overlook that one, critical security patch within all the vendor noise received that day."

I just filed a news analysis for eWEEK.com on this very topic. The recurring theme from my interviews with researchers and patch management experts is this: We don't mind a patch barrage but just let us know up front.

Still no RSS Feed for Advisories

It's been more than two months since Microsoft launched the excellent security advisories pilot. Based on everything I've seen so far, it's serving the purpose very well but the absence of an RSS feed is a huge weakness in the delivery of this information. Does it really take this long to activate something as basic as an RSS feed?