Archive for the ‘Security’ Category

How to Make sure you Aren’t Framed by Facebook

Thursday, August 19th, 2010

Yet another reason to not use Facebook.  In their latest non-security decision others can now tag you as being somewhere even if you don’t want them to…or if you aren’t even there.  Like this is a good idea.  Here’s how to turn it off(other than not using faceobok at all):

1. Go to privacy settings
2. Go to “customize”
3. Scroll to “things others share”
4. Disable “friends can check me into places.”

It’s getting to the point that the amount of time you spend trying to NOT let Facebook tell everyone everything about you and where you are all the time outstrips the amount of time you find valuable use out of the site.

Disable Facebook Places From Letting Others Tag Your Location Without Your Consent – The Consumerist.

Why AVG Remains my reccomendation for businesses

Saturday, August 14th, 2010

Virus Bulletin : News – A third of anti-malware products fail to secure Vista Business Edition, Virus Bulletin reveals.

If you look at the linked graphic you’ll see AVG proudly near the top with Symantec and Macafee much lower.  Microsoft Security Essentials isn’t high on the chart either..wow.  So if you really want an anti-something i would go with AVG for both home and business use at this point.  If you head here you can see that Macafee actually failed this test.  Symantec passed however i can tell you from personal experience I wouldn’t run it as i have had to clean up many machines with Symantec installed..:)

Patch now!

Saturday, August 7th, 2010

Microsoft has released the fix for the LNK issue. this coming Tuesday is going to be a monster patch day with a total of 37 issues fixed in 14 patches.

Even the Iphone isn’t immune from Apple’s Arrogance

Tuesday, August 3rd, 2010

It’s either that or incompetence.  At this point I’m not sure which it is.

How To Prevent iOS From Automatically Loading PDFs [Vulnerability].

Fix for LNK Hole Coming on Monday

Saturday, July 31st, 2010

Normally I advocate caution in major patches.  This hole however is so important that i am going to immediately patch and then workaround any issues this is going to cause.  Again on mOnday htis patch gets released.  PATCH IMMEDIATLY!!!  Read the previous advisories I posted about this here.

Third LNK Vulnerability Update

Thursday, July 22nd, 2010

Steve Gibson talks about this issue in a very understandable manner.  Look at my previous post at the bottom..aka update 3.

Second LNK Vulnerability Update

Thursday, July 22nd, 2010
Well the vulnerabilities threat profile has expanded:
http://www.f-secure.com/weblog/archives/00001994.html
If the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.

Well the vulnerabilities threat profile has expanded:http://www.f-secure.com/weblog/archives/00001994.htmlIf the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.

.LNK Zero Day Update

Wednesday, July 21st, 2010

http://www.emmanuelcomputerconsulting.com/archives/2421

The podcast software crashed so I was able to make a written update to the post with the help of Arstechnica.com.  Go checkout the updated post.

New Zero Day problem with all versions of windows(High Potential for Mass Infections..Stay Alert)*UPDATED*

Tuesday, July 20th, 2010

I am going to provide you with the summary from Ars Technica as it’s the clearest explanation of the problem I have seen:

The attack uses specially crafted shortcut (.lnk) files, which trick Windows into running code of an attacker’s choosing. Any Windows application that tries to display the shortcut’s icon—including Explorer—will cause exploitation, so even the mere act of browsing a directory with the malicious shortcuts is sufficient for a system to be exploited. Analysis suggests that the shortcuts are not improperly formed; rather they depend on a flaw in the way that Windows handles shortcuts to Control Panel icons.

The first reports of the problem came last month from Belorussian security company VirusBlokAda. The company found systems infected with the flaw through infected USB keys. The keys use the flaw to install a rootkit to hide the shortcuts, dubbed Stuxnet, including kernel-mode drivers, and a malicious payload. The rootkit is itself noteworthy: the drivers it installs are signed. The certificate used to sign them belongs to Realtek, suggesting that somehow the attackers have access to Realtek’s private key. The certificate used to sign the rootkit has now been revoked by Verisign.

The current in-the-wild attacks are using USB keys to distribute the shortcuts, but the attack could equally use network shares or local disks. The malware payload appears to be designed to specifically compromise the databases used by Siemens’ SIMATIC WinCC software. WinCC is SCADA software, used to control and monitor industrial systems, found in manufacturing plants, power generation facilities, oil and gas refineries, and so on. Siemens’ software uses hardcoded passwords, making attack particularly simple.

The best option for mitigating the flaw is to disable Windows’ ability to show shortcuts’ icons; details on how to do this are provided in Microsoft’s security bulletin. However, this mitigation comes at some cost; it removes all the icons from the Start menu, for example, which is sure to be detrimental to usability. Disabling Autorun provides slight protection, as it prevents Explorer windows from opening automatically when a USB key or CD is inserted.

This one has the potential to be very very bad.   What I am going to do is put some of the links below.  I am going to record a podcast tonight about this and have it posted in the next 24 hours.  While the threat right now is low the potential for this one to explode is very very high.  I do not get concerned about Windows exploits very often..this one has the very real potential to be on the scale of sasser, code red, or conficker.  ECC is gearing up for this to be a widespread event and I am hoping it fizzles(which is dependent on a timely patch from Microsoft.)  As of right now there is no anti-anything that will stop the .LNK vulnerability itself and any malware that appears WILL be able to leverage this before the a/v vendors can react as of right now.  I am sure the security companies will be able to catch up..however we really need a patch from Microsoft on this one.  The big problem for Microsoft is this is endemic to their ENTIRE codebase from Windows 95 on up.  They have to now re-engineer every version of Windows to protect against this flaw.  This is one time that if it takes Microsoft more than a week to come up with a fix there’s a very good reason. The following operating systems will NOT get a patch from Microsoft:

Windows 95

Windows 98

Windows ME

Windows NT

windows 2000(all versions)

Windows XP below SP3(this includes XP 64-bit which is now end of life..no support)

Windows VistaRTM (all versions).  Vista SP1 is still supported until July 12 2011.  You really should upgrade to SP2 of Vista.

I have some of the links below I have been following for this:

1

2

3

4

5

6

7

8

*UPDATE* Microsoft has posted their workaround.  This nukes ALL shortcuts on the system though.  If you want to guarentee your protection use this patch..but you won’t be able to easily launch anything.

*UPDATE 2*

Well the vulnerabilities threat profile has expanded:
If the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.
*UPDATE3*  List to this videocast from Steve Gibson..it’s well explained.

http://www.twit.tv/sn258

There are several attack vectors.  It can be triggered via a webpage.  it may even be able to be done from within any browser…not just IE.  I just just got done informing a client that this could have many more attack vectors due to this being a problem with the core of windows.

*UPDATE 4* Normally I advocate caution in major patches.  This hole however is so important that i am going to immediately patch and then workaround any issues this is going to cause.  Again on mOnday htis patch gets released.  PATCH IMMEDIATLY!!!  Read the previous advisories I posted about this here.

Cloud Computing is NOT immune to Microsoft and other vendor style lock-in

Saturday, July 17th, 2010

This is very good reading.  IF you decide to go with a cloud solution the big question is..are you in control of your data or are you at the total mercy of the cloud vendor?  This has significant ramifications for your business if the cloud vendor either fails to provide proper service or worse..goes totally and permanently dark.  Redhat’s CEO warns, and properly so, that the cloud can result in more lock-in than was ever possible on the desktop.  He is absolutely correct.

Here’s serveral article about cloud lock-in

here

here

here

here

Zenoss Blog: No Node Left Behind: Three Cloud Lock-in Considerations – Open Source Network Monitoring and Systems Management.