Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Friday, 4 February 2011

Internet Kill Switch Humor

Posted on 18:02 by Unknown
"Congress is proposing a bill that would give President Obama a kill switch that he could use to freeze all activity on the Internet if there were a national emergency. The kill switch goes by the top-secret name Microsoft Windows."


-Conan O'Brien



Read More
Posted in humor, Microsoft | No comments

Wednesday, 28 July 2010

Microsoft's 'Community Watch' Approach to Security

Posted on 16:25 by Unknown
Ars Technica reports:

At the Black Hat security conference today, Microsoft championed a new approach to addressing security issues. The new emphasis is on collaboration between software vendors and security researchers to ensure that customers are kept as safe as possible.

Microsoft likened its approach to Neighborhood Watch schemes—secure computing cannot be achieved with software vendors and researchers all working independently; the landscape is too complex and the attackers are too numerous for this approach to work. Instead, companies must set aside their differences and work together to safeguard customers.


I'm familiar with how neighborhood watches operate. Come with me while I take a jaunty trek through Mr. Ballmer's Neighborhood.

Hey Steve. You left your garage door open.
Yo. Steve-o. Your front door was ajar all night. Again.
Did you know all your Windows are cracked, Steve?
Nice siding and shutters you've got there, Steve. Plan on installing a roof?
Umm, not sure if you noticed, Steve, but Linus Torvald's house seems to have a cloak of invisibility.

Remember, we're all in this together.

Read More
Posted in Microsoft | No comments

Thursday, 10 June 2010

Vulnerability in Microsoft Windows Help and Support Function

Posted on 17:25 by Unknown
In the wake of a patch Tuesday that put forth fixes for 34 flaws, Microsoft has issued Security Advisory 2219475 for a publicly-released vulnerability in the help and support center function of Windows XP and Windows Server 2003. Successful exploit could result in remote code execution.

Google security researchers reported the vulnerability to Microsoft on June 5, and publicly released information about the flaw and how it might be used in attacks on June 9.

Microsoft is obviously cranky at Google for the public disclosure, as evidenced by their snarky entry within their Microsoft Security Response Center blog posting:

As always, Microsoft strives to work with security researchers to address vulnerabilities in our software. This helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of - and work to exploit - a vulnerability. Responsible disclosure protects the computer ecosystem and individual computer users from harm.

No exploits in the wild have been publicly reported, and its Microsoft's hope that this remains the case while a fix is developed. The suggested workaround is to unregister the HCP protocol.

This isn't the first time flaws in Microsoft's help center have been reported. Thankfully, the vulnerability is not present in Vista and Windows 7 on the client side, or Server 2000 and Server 2008.

Don't expect an out-of-band patch for this one, unless widespread attacks begin popping up. 



Read More
Posted in exploit, Microsoft, vulnerability | No comments

Tuesday, 8 June 2010

Microsoft Security Bulletin for June 2010 Is A Doozy

Posted on 14:33 by Unknown
Hope you weren't planning to take any time off for the next couple of weeks if you're a Windows admin, because Microsoft released their June 2010 patches today, and brother, you've got some work to do.

Ten bulletins addressing 34 separate vulnerabilities make up this month's offering. Products affected include Windows, Office, SharePoint, Internet Explorer, IIS, and the .NET framework. You know - just about everything outside of databases.

Three fixes in particular are worthy of your immediate attention. MS10-033 affects Windows and could allow remote code execution, so prioritize testing and deployment in your environment. MS10-034 is an update for ActiveX Kill Bits and Redmond deems it critical for Windows 2000, XP, Vista, and Windows 7. MS10-035 is a cumulative update for Internet Explorer that addresses six issues, only one of which was publicly known prior to release of the bulletin according to Microsoft.

SANS has a nice breakdown of the patches, associated CVEs, known exploits, and their recommendations for patching prioritization.

The Microsoft Security Response Center blog has Redmond's latest information about this month's bulletin.

As always, test these hotfixes in a dev environment to see if anything breaks before you deploy them into production, and make sure your antivirus and IDS signatures are up to date. It's typical to see the bad guys reverse-engineer certain patches seeking the root vulnerability that they can then exploit before patching can commence.

Home users should ensure that automatic updates are turned on and that your antivirus software is at the latest version with the most updated virus definitions.

Enjoy.

Read More
Posted in exploit, Microsoft, vulnerability | No comments

Friday, 4 June 2010

Google vs Microsoft - What's In It For You

Posted on 09:02 by Unknown
Tech blogs are abuzz over Google's recent announcement that they are tossing Windows overboard due to security concerns.

Is this another example of blades of grass (us) suffering when elephants (them) tussle? I don't think so, but let's look at some background.

Google blames Microsoft for the Operation Aurora attacks in which Google systems were compromised and key data stolen, allegedly at the behest of Chinese government officials. In particular, a Microsoft Internet Explorer zero-day exploit was leveraged in the attacks, and Google spent much time and expense cleaning up and securing their environment after the incident.

Microsoft products enjoy a significant, if dwindling, saturation point among both home users and the enterprise. In fact, Google's launch of the Chrome browser and Android mobile platform, along with their upcoming operating system, will result  in Google snatching more market share from Microsoft than from Apple or Linux.

So it makes sense for Google to peel away from Microsoft for all sorts of business reasons outside of security concerns. Internet Explorer is eminently buggy and continually vulnerable, and its percentage of the browser market was dropping even before Chrome was released as users moved to alternatives like Firefox and Opera. Aside from Google developers keeping Internet Explorer around to ensure their products are compatible and render correctly for IE users, there's no compelling reason for anyone other than the coders to have it on their desktops.

The same rationale can be posited from an operating system perspective. If Google's upcoming OS is indeed ready for prime time, Google employees should be using it. Period. Call it the "school of eating your own dog food" if you like, but if you want to convince casual users, application developers, and large companies that your product is worthy of their dollars, you'd better be willing to be a living, breathing use-case.

Speaking as a security guy, there are two concerns I have with Google's announcement. First, the operating system is just one of a myriad of attack vectors available for hackers and exploit frameworks. Secondly, consolidating on a single platform for an enterprise makes life easier for the bad guys.

Let's examine the operating system angle Five years ago, targeting the OS was easy, because Microsoft had a 98% deployment share and, let's face it, their code had more holes in it than Swiss cheese.

As time went on and Microsoft slowly began to execute on their Trustworthy Computing initiative, it became a bit more difficult to penetrate the operating system directly. Part of the solution was the implementation of UAC in Vista and Windows 7 which segregated some of the core kernel functions from direct access, but the enforcement lacks some of the rigor of similar Linux-based controls, and users can dumb down UAC to the point where it isn't all that effective.

Coupled with weak UAC, attackers also stopped breaking down the door and started looking for unlocked windows, pardon the pun, and they found them in peripheral applications like Adobe Reader & Flash, QuickTime, and Microsoft Office. Since these apps also suffer from readily exploitable vulnerabilities and are available in versions that sit atop various operating systems, Google moving away from Windows on the desktop and server is a lesser security achievement than the folks in Palo Alto are trumpeting.

Given that the second most popular attack vector - after peripheral applications - is web-based applications vulnerable to cross-site scripting and SQL injection attacks, it's difficult to believe much protection is gained by switching. Again, regardless of the operating system, you're still at risk if you have poor application development practices that allow such attacks to succeed.

What about moving from a heterogeneous IT environment to a homogeneous shop? Well, there are downsides to that approach, too.

Single platform infrastructures can be a security and resiliency concern. Attackers typically use fingerprinting techniques to systemically profile an organization's IT blueprint. Over time, it becomes apparent what products and versions are in use, and what preventative and detective security controls are in place. This is much easier for attackers when everything is based off of the same underlying code.

Similarly, when a weakness is found, it can be leveraged across the whole enterprise. That can increase both the impact of any attack (or unanticipated failure) and the subsequent time and resources needed to recover and resume normal operations. Having a multi-platform environment lessens that risk, but increases the complexity of an enterprise infrastructure. Few organizations take the resources saved from an uncomplicated, homogeneous environment and pour them back into hardening the underlying backbone.

Google may be firing a marketing shot across Microsoft's bow with their announcement. From a technical perspective, Microsoft is playing catch-up, having lost the cool kids to Apple and Google already. Losing the enterprise customer would be the final nail in Redmond's coffin, and if Google can demonstrate to Fortune 500 companies that they can provide a cost-effective, feature-rich replacement for Windows and Office, they'll be happy to hand businesses the hammer.

Images via Wikimedia Commons
Read More
Posted in Google, Microsoft | No comments

Friday, 7 May 2010

Microsoft Security Intel Report Released

Posted on 16:12 by Unknown
The latest installment of Microsoft's Security Intelligence Report has been released, with a breakdown of threat assessment by country.

Redmond reports that malware was discovered on 7.8 of every 1000 computers scanned in the US, which seems surprisingly low. By comparison, Russia scored a 9.8, while Korea came in at 16.0 per 1000.

Worms and trojans were highlighted as the predominant threats in many of the countries in the report, with password stealers and other trojans/droppers also heavily utilized.

For more details and the full report, check out the Microsoft Security Intelligence Report Volume 8.

Image via Wikimedia Commons

Read More
Posted in cyber security, Microsoft, threats | No comments

Tuesday, 13 April 2010

Microsoft Security Bulletin for April 2010

Posted on 11:22 by Unknown
Microsoft has released the April 2010 Security Bulletin, and it's a doozy!

It's imperative that you install MS10-022 now. The vulnerability in VBScript Engine is being actively exploited in the wild, and there's not a lot of time to waste on this one.

MS10-020 should be next on your list, as exploit code has been made public and there's sure to be attacks that leverage this particular SMB vulnerability.

Several others are rated as critical by Microsoft, so if you're prioritizing your deployment schedule, MS10-019, MS10-026, and MS10-027 should be next in line, as "consistent" exploit code is likely, according to Redmond.

In all, twenty-five vulnerabilities in various platforms and applications are addressed in this bulletin.

So much for the Trustworthy Computing initiative, eh? The only thing on which we can count is the high number of patches requiring deployment each month.


Read More
Posted in exploit, Microsoft, vulnerability | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Colbert - Sunday Morning Fact-Checking
    The Colbert Report Mon - Thurs 11:30pm / 10:30c Sunday Morning Fact-Checking - Jake Tapper & Bill Adair www.colbertnation.com Colbert Re...
  • The Three Great Alabama Icons
    Music by Drive-By Truckers.
  • Krugman - Results, Not Process
    I listened to part of Obama's post-election presser today, and I had to turn it off. I thought about what he was saying and knew I had a...
  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • EFF - Six Things to Know About Facebook Connections
    Each time Facebook makes a change to their privacy practices, it pisses me off a little bit more. So you can guess how infuriated I was when...
  • (no title)
    Hi. You may not remember me, but I am Kevin's son. As you may know, we have been coping with the loss of my mom, and it is very difficul...
  • Stephen Colbert on Arizona's Immigration Law
    The Colbert Report Mon - Thurs 11:30pm / 10:30c The Word - No Problemo www.colbertnation.com Colbert Report Full Episodes Political Humor Fo...
  • What Happens When We Die?
    Andrew Sullivan has been hosting a spirited back-and-forth on the topic of faith, religion, and death, with readers of his blog and Kevin D...
  • Fox News Disrespects Mister Rogers
    You don't tug on Superman's cape. You don't spit into the wind. You don't pull the mask off the old Lone Ranger, and you don...
  • Metasploit 3.4.0 Hacking Framework Released
    Good news if you're looking to test your security defenses - the Metasploit framework has updated to version 3.4.0. You wouldn't use...

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ▼  2013 (1)
    • ▼  March (1)
      • Hi. You may not remember me, but I am Kevin's son....
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ►  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ►  August (28)
    • ►  July (44)
    • ►  June (83)
    • ►  May (147)
    • ►  April (125)
Powered by Blogger.

About Me

Unknown
View my complete profile