April 2006 - Posts

McAfee reports 700% increase in Rootkits

McAfee published the first of a series of whitepapers on rootkits. The following is an excerpt from their website.

"Comparing the first quarter of 2006 to that of 2005, we have witnessed an increase by 700% of the number of rootkits submitted to McAfee AVERT Labs. Our numbers further show that rootkits are getting more sophisticated and that rootkits have moved from Trojans into malware and Potentially Unwanted Programs. Follow the "Learn More" link for a copy of the paper."

Learn More

Posted by Anonymous | with no comments

Microsoft Security Updates 11APR06

Date  Bulletin Description  Affected Software Service Packs  Bulletin Rating 
Apr 11, 2006 Cumulative Security Update for Outlook Express (911567): MS06-016

Affected Software: Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows XP Professional 64-Bit Edition, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows Server 2003 Datacenter Edition for Itanium-based Systems, Windows Server 2003 Enterprise Edition for Itanium-based Systems, Windows Server 2003 Datacenter x64 Edition, Windows Server 2003 Enterprise x64 Edition, Windows Server 2003 Standard x64 Edition, Windows 98, Windows 98 SE, Windows Me, Outlook Express 6 on Windows Server 2003, Outlook Express 6 on Windows Server 2003 (64 bit edition), Outlook Express 6 for Microsoft Windows Server 2003 for Itanium-based Systems, Outlook Express 6 for Microsoft Windows XP 64-Bit Edition, Outlook Express 6.0, Outlook Express 5.5
Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows XP Service Pack 2, Windows XP 64-Bit Gold, Windows Server 2003 Gold, Windows Server 2003 SP1, Windows Server 2003 for Itanium-based Systems Gold, Windows Server 2003 for Itanium-based Systems SP 1, Windows Server 2003 x64 Gold, Windows 98 Gold, Windows 98 SP1, Windows 98 SE Gold, Windows Me Gold, Outlook Express 6 on Windows Server 2003 Gold, Outlook Express 6 on Windows Server 2003 SP1, Outlook Express 6 on Windows Server 2003 (64 bit edition) Gold, Outlook Express 6 for Microsoft Windows Server 2003 for Itanium-based Systems Gold, Outlook Express 6 for Microsoft Windows XP 64-Bit Edition Version 2003 Gold, Outlook Express 6.0 SP1, Outlook Express 5.5 SP2 Important
Apr 11, 2006 Vulnerability in Windows Explorer Could Allow Remote Code Execution (908531): MS06-015

Affected Software: Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows XP Professional 64-Bit Edition, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows Server 2003 Datacenter Edition for Itanium-based Systems, Windows Server 2003 Enterprise Edition for Itanium-based Systems, Windows Server 2003 Datacenter x64 Edition, Windows Server 2003 Enterprise x64 Edition, Windows Server 2003 Standard x64 Edition, Windows 98, Windows 98 SE, Windows Me
Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows XP Service Pack 2, Windows XP 64-Bit Gold, Windows Server 2003 Gold, Windows Server 2003 SP1, Windows Server 2003 for Itanium-based Systems Gold, Windows Server 2003 for Itanium-based Systems SP 1, Windows Server 2003 x64 Gold, Windows 98 Gold, Windows 98 SP1, Windows 98 SE Gold, Windows Me Gold Critical
Apr 11, 2006 Vulnerability in the Microsoft Data Access Components (MDAC) Function Could Allow Code Execution (911562): MS06-014

Affected Software: Windows XP Home Edition, Windows XP Professional, Windows XP Professional 64-Bit Edition, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows Server 2003 Datacenter Edition for Itanium-based Systems, Windows Server 2003 Enterprise Edition for Itanium-based Systems, Windows Server 2003 Datacenter x64 Edition, Windows Server 2003 Enterprise x64 Edition, Windows Server 2003 Standard x64 Edition, Windows 98, Windows 98 SE, Windows Me, Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, MDAC 2.7, MDAC 2.8, MDAC 2.5
Windows XP Service Pack 1, Windows XP Service Pack 2, Windows XP 64-Bit Gold, Windows Server 2003 Gold, Windows Server 2003 SP1, Windows Server 2003 for Itanium-based Systems Gold, Windows Server 2003 for Itanium-based Systems SP 1, Windows Server 2003 x64 Gold, Windows 98 Gold, Windows 98 SP1, Windows 98 SE Gold, Windows Me Gold, Windows 2000 Service Pack 4, MDAC 2.7 SP1, MDAC 2.8 SP1, MDAC 2.8 SP2, MDAC 2.8 Gold, MDAC 2.5 SP3 Critical
Apr 11, 2006 Cumulative Security Update for Internet Explorer (912812): MS06-013

Affected Software: Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows XP Professional 64-Bit Edition, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows Server 2003 Datacenter Edition for Itanium-based Systems, Windows Server 2003 Enterprise Edition for Itanium-based Systems, Windows Server 2003 Datacenter x64 Edition, Windows Server 2003 Enterprise x64 Edition, Windows 98, Windows 98 SE, Windows Me, Internet Explorer 5.01, Internet Explorer 6.0, Internet Explorer 6.0 for Windows XP Service Pack 2, Internet Explorer 6.0 for Windows Server 2003, Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems, Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition, Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows XP Service Pack 2, Windows XP 64-Bit Gold, Windows Server 2003 Gold, Windows Server 2003 SP1, Windows Server 2003 for Itanium-based Systems Gold, Windows Server 2003 for Itanium-based Systems SP 1, Windows Server 2003 x64 Gold, Windows 98 SP1, Windows 98 SE Gold, Windows Me Gold, Internet Explorer 5.01 SP4, Internet Explorer 6.0 SP1, Internet Explorer 6.0 Gold Critical
Apr 10, 2006 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting (917627): MS06-017

Affected Software: FrontPage Server Extensions 2002, FrontPage Server Extensions 2002 64-bit, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows Server 2003 Datacenter Edition for Itanium-based Systems, Windows Server 2003 Enterprise Edition for Itanium-based Systems, Windows Server 2003 Datacenter x64 Edition, Windows Server 2003 Enterprise x64 Edition, Windows Server 2003 Standard x64 Edition, Windows XP Professional 64-Bit Edition, Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, SharePoint Team Services 2002
FrontPage Server Extensions 2002 Gold, FrontPage Server Extensions 2002 64-bit Gold, Windows Server 2003 Gold, Windows Server 2003 SP1, Windows Server 2003 for Itanium-based Systems Gold, Windows Server 2003 for Itanium-based Systems SP 1, Windows Server 2003 x64 Gold, Windows XP 64-Bit Gold, Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows XP Service Pack 2, SharePoint Team Services 2002 Gold Moderate
Posted by Anonymous | with no comments

Let The Microsoft Bashing Begin..

 

Let The Microsoft Bashing Begin...

I say that, because I fear that it is coming. I suspect that we will start to see a flurry of articles blasting Microsoft on next Tuesday's Updates for Internet Explorer. Anytime there is change, there are folks that will cry bloody murder, and forget that change is inevitable, and that the attention should be focused on dealing with the change. Microsoft is changing active X capabilities in Internet Explorer. A good write-up of the changes and the reasons prompting the change can be found on Microsoft's Security Response Center Blog. 

I hope to see articles explaining how to deal with the changes, rather than blasting Microsoft, but I know the latter is the most probable outcome. I have already seen emails by vendors that are using very strong language suggesting that customers do not apply Microsoft patches. One vendor stated "THIS COULD ADVERSELY AFFECT ANY APPLICATION FROM ANY VENDOR".

So what can you do?

Here is what Microsoft Recommends for Enterprise Customers:

o       Test the ActiveX change that we shipped on February 28th.

o       Deploy the cumulative IE security update when it ships.

o       If you have concerns about application compatibility with the ActiveX change, then deploy the compatibility patch to temporarily revert back to the old behavior for Active X.  I STRONGLY advise that you NOT use this patch if you can avoid it, but if you do use the patch, as soon as you fix your application, remove the patch so that you can be sure that your applications work with the new ActiveX functionality.

o       Know that starting in June we really will not be supporting the old ActiveX behavior.

It is of my opinion, that testing should be the priority here, and that you should alert application owners within your organization, to utilize the patch that Microsoft made available to developers on MSDN on February 9, 2006. This includes applications created by vendors as well as any applications created internally. If you have a team that normally tests patch(s) for compatibility, they may want to solicit the help of all application owners as this change could affect a wide variety of applications.

 

Posted by Anonymous | 1 comment(s)