Showing posts with label Windows XP. Show all posts
Showing posts with label Windows XP. Show all posts

Thursday, December 06, 2007

New Exploit Targets Internet Explorer

Article by Jabulani Leffall
One week before the last Patch Tuesday of 2007 and two weeks after a researcher in New Zealand discovered holes in Microsoft's Web Proxy Automatic Discovery (WPAD) program, Redmond this week issued its latest in a long line of security advisories. Tim Rains of Microsoft's Security Response Center wrote in a blog post on Monday that Windows XP SP2, Windows Server 2003 SPs 1 and 2 and Windows Vista are all vulnerable to WPAD server manipulation.
This vulnerability also affects all supported versions of Internet Explorer, a browser which most commonly uses the WPAD function to locate an automatically configured proxy file to determine settings on offsite servers and by extension affecting Internet traffic flow through server indentification and authentication.
Potential vulnerabilities first came to light around Thanksgiving weekend when Redmond's software engineers responded to the results of a presentation made by Beau Butler, a New Zealander and self-described "ethical" hacker. Butler's work revealed that a hacker can use WPAD files to intercept and manipulate all Internet traffic on a given network. Butler said 160,000 computers in New Zealand alone could be seized with just one attack.

Media reports have claimed that U.S. computers are not vulnerable to the attack. However, it appears Microsoft isn't taking any chances, as the software giant said it released the security advisory as it investigates "new public reports of a vulnerability in the way Windows resolves hostnames that do not include a fully-qualified domain name." Thus an issue that was supposed to have been resolved in 2005 has become a 2007 fix as the minute technical overhaul made back then only addressed the ".com" domain name, and not other suffixes such as ".org," ".tv," and non-U.S. country tags -- in the case of the hacker's findings, "nz."

This week, Microsoft added a new specification to the vulnerability profile stating that "Customers whose domain name begins in a third-level or deeper domain, such as "contoso.co.us," are at risk. Conversely, among those not at risk are IT shops where a manually specified proxy server is in place for IE. Additionally, those who have disabled the "Automatically Detect Settings" command in IE can also work around the issue.

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Friday, September 28, 2007

How to Put an End to Microsoft's Sneaky "Silent Updates"

The following is an excerpt from Scott Dunn's informative September 20th article in Windows Secrets Newsletter on how to keep Microsoft from installing silent updates without your permission...

If you're an individual or a small business using Windows Update (or its enhanced sibling, Microsoft Update), you may be concerned about Microsoft installing patches before you've had a chance to research their reliability. In that case, you can completely turn off the Automatic Updates Agent, thereby preventing updates or even notifications from occurring. If you take this step, you'll become solely responsible for learning about new Microsoft patches yourself. I'll explain below how to adapt to this situation. In the meantime, here's how to turn off Automatic Updates and prevent stealth installs:

In Windows XP, take these steps:
Step 1. Open Control Panel and launch Automatic Updates (in the Security Center
Step 2. Select Turn off Automatic Updates. Click OK.

In Windows Vista, take these steps:
Step 1. Open Control Panel and launch Windows Update (in the System and Maintenance category).
Step 2. In the left pane, click Change settings.
Step 3. Click Never check for updates (not recommended). Click OK.
Step 4. Click Continue, if prompted by User Account Control.
category).

With Automatic Updates turned off, Windows Update will still update itself (and notify you of patches), but only when you manually launch Windows Update and give your consent.

What to do about repeated boot-up warnings:
Turning off Automatic Updates can cause Windows Security Alert pop-up balloons to appear in the taskbar tray every time you log on. (See Figure 1.)

Automatic Updates off
Figure 1. Turning off Automatic Updates causes scary
error balloons featuring a red shield.


If this bothers you, Windows XP allows you to suppress any warnings that relate to Automatic Updates. You can also do this in Vista but, unfortunately, the newer OS forces you to turn off all security alerts just to suppress the Automatic Updates warnings.

To eliminate the warning balloons about Automatic Updates in both XP and Vista, take these steps:
Step 1. Double-click the red shield icon in the taskbar, or open the Control Panel and launch the Security Center.
Step 2. In the left pane or box, click Change the way Security Center alerts me.
Step 3-XP. In XP, uncheck Automatic Updates and click OK.
Step 3-Vista. In Vista, select the second or third option.

Use Secunia's Software Inspector to check for updates:
With the Windows Update Agent turned off, how will you know if you have the latest security patches and updates you need?
First, read the Windows Secrets Newsletter that comes out two days after Patch Tuesday. Look in their paid section for descriptions of any patches that are reported to have negative side-effects, and use their recommended workarounds if any problems might affect you. Then, to check for needed updates to Windows and dozens of other programs, use the Secunia Software Inspector. This is a free service.

Once you know what updates you need, you can visit the Microsoft Update Web site, which offers updates for both Windows and Microsoft Office. The Secunia report includes a link to Microsoft's site and other update sites so you don't even have to bookmark them. Download and install the necessary patches. Reboot your PC and you should be good to go -- without the sneaky, underhanded, stealth "updates" Microsoft is trying to force on computer users.

Thursday, September 27, 2007

STEALTH UPDATES CONTINUE TO PLAGUE MICROSOFT

Microsoft continues to get itself into trouble with "stealth" or silent updates. The first round of silent updates was reported September 13th. This time, the issue is over a silent update the company broadly distributed in July and August that's apparently restraining Windows XP's repair feature from fully carrying out its task.
According to this week's Windows Secrets Newsletter, since the silent download of new support files for Windows Update, the Windows XP repair function is unable to install the last 80 patches from Microsoft.

Apparently, the trouble surfaces when users reinstall Windows XP's system files using the repair capability contained on the XP CD. At this point, the repair option, which is mostly used when XP becomes unbootable, rolls "many aspects" of XP back to a pristine state. In the process, it blows away many updates and patches and kicks Internet Explorer back to the version that originally shipped with the OS.
Typically, users who repair XP can simply download and install the latest updates, using either Automatic Updates control panel or going to Microsoft's Windows Update site. But once you run the repair option from the CD, Automatic Updates defaults to "on" and the new 7.0.600.381 executables are automatically downloaded and installed. According to the report, these new executables will not register themselves with the OS, thereby preventing Windows Update from working. This then prevents the 80 updates from being installed.

While everyday users rarely attempt a repair install, the flaw figures to be a constant irritant to a lot of admins who frequently have to repair Windows. However, the report states that if Windows Update refuses to install patches, admins can register the missing DLLs by manually entering the necessary commands at the command prompt.

Tuesday, August 07, 2007

MCPMag POLL: Upgrade to Microsoft Vista or wait for "Windows 7"?

The Question: Will you upgrade to Microsoft Vista or wait for "Windows 7"?

I'll stick with XP as long as I can. (50.5%)
I've already upgraded to Vista. (21.3%)
I'll eventually upgrade to Vista. (16.0%)
Skipping Vista and going straight to Windows 7. (6.9%)
I've already moved on to a non-MS OS. (4.8%)
Not even considering Windows 7. (0.5%)

The total number of votes was just shy of 200, but the outcome was a little surprising. According to Microsoft PR (propaganda reports), Vista is selling like hotcakes. The telling part of this poll is that the majority of MCP Mag readers are Microsoft Certified Professionals. Hmm, even those certified in MS technologies and software are not clamoring for Vista. The majority are holding on to Microsoft Windows XP Professional"as long as they can". This makes me wonder about the truth in Microsoft claims of more than one million copies of Vista being sold.

As an MCP (and CompTIA A+) certified tech myself, I tend to agree with the majority of poll respondents. I am holding out for Vista's Service Pack 1 release before considering an upgrade. Along with SP1, the price will need to drop a bit before Vista will become part of my budget. BTW, the only choice worth making (IMO) regarding Windows Vista is Premium Edition. All the others are lesser versions.

Friday, January 26, 2007

'Storm' Trojan Hits 1.6 Million PCs; Vista May Be Vulnerable

Photo from TechSpot.com
Article by Gregg Keizer
The Trojan horse that began spreading Friday has attacked at least 1.6 million PCs, a security company said Tuesday. In addition, it appears that Windows Vista, the new operating system Microsoft will launch next week, is vulnerable to the attack.
Originally dubbed the "Storm worm" because one of the subject heads used by its e-mail touted Europe's recent severe weather, the Trojan's author is now spreading it using subjects such as "Love birds" and "Touched by Love," said Finnish anti-virus vendor F-Secure. The Trojan, meanwhile, piggybacks on the spam as an executable file with names ranging from "postcard.exe" to "Flash Postcard.exe," more changes from the original wave as the attack mutates.
The first several spam blasts of the Trojan -- which was named "Peacomm" by Symantec -- came with current event subject heads, including ones claiming to include video of a Chinese missile attack or proof that Saddam Hussein lives, and bore attached files such as "video.exe."
"Peacomm has, not surprisingly, evolved. The attachments have new filenames, some files [dropped onto the PC] have changed, and the subject lines of the spam are also changing," noted Amado Hidalgo, a researcher with Symantec's security response group, in an entry on the team's blog. By Symantec's reckoning, Peacomm is the most serious Internet threat in 20 months.
Monday, it raised the alert level to "3" in its 1 through 5 scale; the last time the Cupertino, California, security software developer tagged a threat as "3" was for Sober.o in May 2005. So far, Symantec has received 1.6 million detection reports from its sensor system. "This means Peacomm has hit 1.6 million systems in the past seven days," a company spokesman said in an e-mail. An accurate number of infected machines is not yet known. The most recent variants of the Trojan include rootkit cloaking technologies to hide it from security software, said both F-Secure and Symantec. The latter, however, pointed out that flawed rootkit code voids some of the Trojan maker's plans. "The rootkit service can be stopped by running a simple command: net stop wincom32. All files, registry keys, and ports will appear again," said Hidalgo.
A personal firewall also offers some protection from the rootkit, as it will warn you that the Windows process "services.exe" is trying to access the Internet using ports 4000 or 7871.
Peacomm's turn to rootkits brought out comparisons to Rustock, a year-old family of Trojan horses that has become a model of sorts for hackers. Rustock, as Symantec warned in December 2006, relies on rootkit technology, but adds an ability to quickly change form as another evasion tactic. "It's similar to Rustock," acknowledges Dave Cole, director of Symantec's security response team, "but [Peacomm is] not nearly as technically sophisticated." As with most large-scale Trojan attacks, the goal seems to be to acquire a large botnet, or collection of compromised PCs, that can be used to send traditional scam spams or for later identity mining. Symantec's researchers said that PCs hijacked by Peacomm send "tons and tons of penny stock spam" in a typical pump 'n' dump scheme.
"During our tests we saw an infected machine sending a burst of almost 1,800 emails in a five-minute period and then it just stopped," said Hidalgo. "We are speculating that the task of sending the junk e-mail is then passed on to another member of the botnet." Windows 2000 and Windows XP are vulnerable to all the Peacomm variations, but Windows Server 2003 is not; the Trojan's creator specifically excluded that edition of Windows from the code.
Symantec's Hidalgo took a guess why. "We presume the malware writers didn't have time to test it on this operating system." Microsoft's soon-to-release-to-consumers Vista, however, does appear at risk, added Symantec Tuesday. "It appears most if not all variants could execute on Vista," the spokesman said. "The only way the Trojan would be unsuccessful is if somehow Vista is able to detect/prohibit the e-mail. This seems unlikely." Anti-virus companies have updated their signature databases with fingerprints that identify and then delete (or quarantine) the Trojan as it arrives. Other defensive advice includes filtering traffic on UDP ports 4000 and 7871, update anti-spam products, and configure mail gateways to strip out all executable attachments.

EDITORIAL: If you have NOT updated your anti-virus and anti-spam products within the past 3-5 days, it would be advisable to use one of the FREE online scanners -- such as those from TrojanScan.com, McAfee, Trend Micro and/or Symantec. It would also be to your advantage to use tools such as Ad-aware SE Personal, Spybot Search & Destroy v1.4 and Spyware Blaster v.3.51.

Tuesday, December 26, 2006

Old Cracks Found in New Windows Vista

NewYorkDailyNews.com
Redmond, we have a problem. The brand spanking-new Windows operating system called Vista - billed as "the most secure version of Windows yet" on the Microsoft Web site - has proven a pushover for Internet hackers. Microsoft has acknowledged Vista has a flaw that could allow users to increase their access level to administrator, a problem first posted by a Russian hacker.
A flaw was also found in Microsoft's new Internet Explorer 7 that could download viruses from a booby-trapped Web page. That flaw and five others were reported by Determina, a Silicon Valley computer security company. "We are closely monitoring developments," said Microsoft's Mike Reavey, operations manager for the Redmond, Wash. company's emergency response team. "Currently we have not observed any public exploitation or attack activity regarding this issue," he wrote. And, he insisted, "I still have every confidence that Windows Vista is our most secure platform to date."
But news of the IE7 flaw and the hacker postings is a black eye for Bill Gates and Microsoft - and for the thousands of PC makers who will begin selling their computers next month with Vista. Thousands of consumers put off buying computers this Christmas season waiting for the release at the end of January of the new upgrade from Windows XP to Windows Vista.
One online tech expert, Jay Dougherty, wrote for the German Press Agency that Vista may prove a tough sell for folks already happy with their home computers, especially because the current XP system has proven to be relatively stable. "People are tired of upgrading - especially when the benefits of doing so are difficult to articulate or uninspiring. That's the problem with Microsoft's Vista operating system in a nutshell," he wrote.
Vista's big selling points, besides it supposed safety and security, are its stunning 3D graphics that many critics argue is simply an attempt - and a bad one at that - to match what Apple has had for years on the Macintosh.

Thursday, November 02, 2006

Windows Vista Arriving on November 30th

by Tim Gray


The November 30 launch date for Windows Vista is Microsoft's way of giving businesses a head start in their Vista upgrade plans. Windows Vista for consumers will not be available until January 2007, although Microsoft has not announced a formal release date as of yet.
After several years of delays and false starts, Microsoft is finally gearing up for the big launch of Windows Vista and Office 2007 for businesses on November 30 at an event in New York.
Business customers with either an enterprise license or a software assurance contract are scheduled to get the first look at the final versions of the long-awaited programs during Microsoft event held at New York's Nasdaq stock exchange. Corporate users will have access to the applications early to allow them to test the programs before rolling them out.

The Big Picture
Although Microsoft has not set a formal rollout date for the retail versions of Windows Vista, Simon Yates, an analyst with Forrester Research, said the date of the business launch signals that Microsoft is on track to release Vista to consumers in January 2007. "It says a lot that they are confident to deliver the business version at the end of the month after years slipping and delays," Yates said.
Both Vista and Office had originally been scheduled to arrive on store shelves and on new PCs in time for this year's holiday season. But in March, the software giant pushed back the debut of the consumer versions until January. At the time, the company said it couldn't meet the schedule required by some PC manufacturers and others in the industry.
"Clearly, retailers are bummed out they didn't have it in time for Christmas," said Laura DiDio, an analyst with the Yankee Group. "But most users don't care; it is not like 1995 when people were lining up at midnight." DiDio, who has been testing the beta versions of Vista as they have rolled out, said there are some "very good improvements" in Windows Vista, but she also said the operating system is more evolutionary than revolutionary. She said the Vista interface looks good and has a faster search engine. "The whole environment has changed from 10 years ago," she said. "It better have, because we have waited so long for it."

Company Updates
According to Forrester's research, one-fourth of larger companies (1,000 or more employees) will deploy Vista within the first year of its release, and another one-fourth expect to do the same within two years of the release. "From that standpoint, there will be gradual replacements for the new hardware requirements," said Forrester's Yates.
While Microsoft fell short of getting Vista out to the masses for the 2006 holiday season, Yates noted, the release of the business version is a positive step toward finally getting the retail version out of the gate.
Windows is, by far, Microsoft's most profitable product. Some experts expect Windows Vista will be Microsoft's last major rollout before the operating system begins migrating to a Web-based format. "The software has become bloated and difficult to manage, constantly needing patches and fixes," said Yates. "You will always need some applications on local machines but we are now moving toward having the programs sit on the back end of servers somewhere."
Office 2007 is slated to have retail prices of between $149 for the student edition and $679 for an "ultimate" package. Vista will sell for $200 to $400 for new customers, and $100 to $260 for users who want to upgrade from Windows XP.