Thursday, July 21, 2005
MS05-036 Exploit Published
A proof of concept exploit has been posted for the "critical" Color Management Module vulnerability patched with MS05-036. The incident handlers at the SANS Internet Storm Center has raised the "patch now" alarm.
Kaminsky on Security at Redmond
Stephen Toulouse comments and points to an interview on SecurityFocus where Dan Kaminsky discusses security at Microsoft. There's also a Slashdot thread on the interview. I haven't had a chance to digest it all, yet.
Win2K Update Rollup Hiccups
My colleague Mary Jo Foley has the details on some compatibility problems being caused by the Windows 2000 "Update Rollup" that Microsoft shipped last month-end.
There's a Microsoft KB article explaining the bugs that are affecting products from Sophos, Panda, Internet Security Systems (ISS) and Citrix.
From the story, it appears that the infamous MS05-019 security bulletin, first released in April and re-released in June because it was breaking some applications, is causing more problems again.
Also of note, the blocking tool to delay the automatic download of Windows Server 2003 SP1 will only be available for a few more days. If you need it, hurry and get it.
There's a Microsoft KB article explaining the bugs that are affecting products from Sophos, Panda, Internet Security Systems (ISS) and Citrix.
From the story, it appears that the infamous MS05-019 security bulletin, first released in April and re-released in June because it was breaking some applications, is causing more problems again.
Also of note, the blocking tool to delay the automatic download of Windows Server 2003 SP1 will only be available for a few more days. If you need it, hurry and get it.
Wednesday, July 20, 2005
US-CERT Weekly Windows Security Summary
Summary of security items affecting the Windows operating system from July 13 through July 19, 2005.
80 Super Security Tips
PC Mag's Larry Seltzer has published a long list of super security tips he has put together over the years. This is worth bookmarking.
Acquisitive Microsoft
Microsoft is busy on the acquisition/licensing front. First the announcement that a minority equity stake in Finjan formed part of a security patent licensing deal. Then, we learned that Frontbridge is the has been acquired outright.
What’s The Use of Security Advisories?
Donna Buenaventura explains why pre-patch security advisories should be seen as valuable resources to protect end users.
* When Microsoft adds an RSS feed to its security advisories, it'll be close to perfect.
* When Microsoft adds an RSS feed to its security advisories, it'll be close to perfect.
Tuesday, July 19, 2005
AOL's IE Browser
Nate Mook at BetaNews is reporting that America Online (AOL) has released the final version of AOL Explorer, an alternative IE-based browser. AOL claims it has shored up security by fixing some IE flaws Microsoft has yet to patch.
* That's a bit of a stretch, innit?
* That's a bit of a stretch, innit?
Windows Anti-Spy Refresh
Microsoft has refreshed the Windows AntiSpyware software, fixing an issue with the signature update mechanism and improving the way the app provides information to the user about processes running on a PC.
Spyware at Cingular Store
Via Lifehacker:
* Can you smell the risk?
"At the Cingular store this weekend signing up for a plan, I watched the clerk enter my information into a point-of-service web app running inside Internet Explorer. On the second screen, a window with a picture of a palm tree-studded beach appeared, interrupting him. “Damn popups,” he said, clicking the window closed."
* Can you smell the risk?
Monday, July 18, 2005
Support for Industry Patch Day
Larry Seltzer: "Competitors are increasingly hiding behind Microsoft's patch releases; why not do it openly and in the right way?"
Advisory/Workarounds for RDP Flaw
Microsoft has issued a security advisory with pre-patch workarounds for the publicly reported Remote Desktop vulnerability. More importantly, it clears up the conflicting reports on the severity of the flaw, as explained further by the MSRC's Stephen Toulouse.
Friday, July 15, 2005
Explaining Premature Disclosure for IE Flaw
Michal Zalewski discovers another image rendering bug that crashes Internet Explorer. Virus.org says the flaw could be exploited by an attacker with a specially crafted JPEG picture to trigger a buffer overflow (code execution).
This portion of Zalewski's post is rather instructive:
"It is my experience that reporting and discussing security problems with Microsoft is a needlessly lengthy process that puts too much burden and effort on the researcher's end, especially if you just have a crash case, not a working exploit; hence, they did not get an advance notice."
This portion of Zalewski's post is rather instructive:
"It is my experience that reporting and discussing security problems with Microsoft is a needlessly lengthy process that puts too much burden and effort on the researcher's end, especially if you just have a crash case, not a working exploit; hence, they did not get an advance notice."
XP SP2 Zero-Day?
Microsoft has acknowledged it is working on a fix for a denial-of-service flaw in XP SP2, fully patched. Some people think it could lead to code execution attacks. There is already chatter about zero-day exploits. Sounds like the ingredients for a security advisory.
Dell, Spyware and My Way
Dell says the "My Way Speedbar" isn't spyware. Google offers a different interpretation.
SWI Team May Start Blogging
Richie Lai, guest blogging on the MSRC Blog says the Secure Windows Initiative (SWI) team may consider delivering future research on its own blog. This comes one day after Robert Hensing explained what goes on behind the scenes when security flaw discoveries are being investigated.
This new level of openness is refreshing but I have this nagging feeling it's driven more by PR considerations than by a legitimate attempt to openly discuss security at Redmond. If I'm wrong, that's a good thing.
This new level of openness is refreshing but I have this nagging feeling it's driven more by PR considerations than by a legitimate attempt to openly discuss security at Redmond. If I'm wrong, that's a good thing.
Thursday, July 14, 2005
Pre-Patch Investigations Explained
Robert Hensing, a Softie who recently joined the Secure Windows Initiative (SWI) defense team, dishes some details on what goes into patch-creation process at Microsoft, especially the investigative work that is done long before the product team starts coding the fix.
He describes the work done to create workarounds for the javaprxy.dll issue ahead of the full patch and while he recommends the use of temporary workarounds, Hensing made it clear they should "never be used indefinitely in place of the security update."
He describes the work done to create workarounds for the javaprxy.dll issue ahead of the full patch and while he recommends the use of temporary workarounds, Hensing made it clear they should "never be used indefinitely in place of the security update."
Schneier on Microsoft/Claria Hubbub
Security guru Bruce Schneier weighs in on the Microsoft/Claria downgrade hubbub with a simple piece of advice: "I recommend using a different anti-spyware program."
Patch Deluge Redux
Corey Nachreiner on this week's patch deluge: "Administrators already have a hard enough time trying to keep up when Microsoft releases 10 security patches on the same day. Now imagine trying to deal with that while also receiving updates from all your other software vendors. This scenario makes it too likely that an IT staffer will overlook that one, critical security patch within all the vendor noise received that day."
I just filed a news analysis for eWEEK.com on this very topic. The recurring theme from my interviews with researchers and patch management experts is this: We don't mind a patch barrage but just let us know up front.
I just filed a news analysis for eWEEK.com on this very topic. The recurring theme from my interviews with researchers and patch management experts is this: We don't mind a patch barrage but just let us know up front.
Still no RSS Feed for Advisories
It's been more than two months since Microsoft launched the excellent security advisories pilot. Based on everything I've seen so far, it's serving the purpose very well but the absence of an RSS feed is a huge weakness in the delivery of this information. Does it really take this long to activate something as basic as an RSS feed?
Subscribe to:
Posts (Atom)
