Tuesday, July 07, 2009

Microsoft Security Advisory: Vulnerability in Microsoft Video ActiveX control could allow remote code execution

Business as usual...this time an Active X control that can be used to remotely execute code on a Windows machine. No patch available just a work around, this time from Microsoft, which seems to understand how critical this one is.

Find the workaround at: http://support.microsoft.com/kb/972890

1SSA - Security consulting, training and products: http://www.1ssa.net

Sunday, July 05, 2009

New MI6 chief on Facebook

This is kind of funny and kind of shocking but then again it is real life. Here is Sir John Sawers, the upcoming MI6 chief (I am sure I do not need to explain to Bond fans what that stands for, but for the ones that wonder what MI6 stands for: It is the British secret service) and his wife is posting on Facebook all kinds of personal information that you normally do not want the public to have.

Read the full article at: http://www.mailonsunday.co.uk/news/article-1197562/MI6-chief-blows-cover-wifes-Facebook-account-reveals-family-holidays-showbiz-friends-links-David-Irving.html

1SSA - Security consulting, training and products: http://www.1ssa.net

Friday, July 03, 2009

Microsoft Update Quietly Installs Firefox Extension

We could call it business as usual for Microsoft or simply another irresponsible move of Microsoft to dominate the browser market. According to various sources, and confirmed by 1SSA, Microsoft has pushed a .Net update that automatically installs an add-on in Firefox that allows for silent(!) installation of code from the web. Some people made a choice to use Firefox because the people creating it prevented this feature. Now Microsoft just installs it without any consent from the user.

Read more here: http://voices.washingtonpost.com/securityfix/2009/05/microsoft_update_quietly_insta.html?wprss=securityfix

Here are instructions on how to de-install it (for sure):http://annoyances.org/exec/show/article08-600

1SSA - Security consulting, training and products: http://www.1ssa.net

Hackers crack ColdFusion - Drive-by download attack hits multiple hosts

Time to finally upgrade or at least apply some patches if you run an older version of Cold Fusion on your servers. According to SANS the number of infected hosts is going up by the hour.

Read more: http://isc.sans.org/diary.html?storyid=6715

1SSA - Security consulting, training and products: http://www.1ssa.net

Latin Best Buy surfers sprayed by drive-by download malware

This is really bad. A major website that the whole nation is going to once in a while has a malware download problem. I am sure Best Buy's management has some words for its website and security teams, which I believe are both outsourced to a major outsourcing company here in the US.

Read more about it at: http://blog.trendmicro.com/gumblar-invades-best-buy/#ixzz0KBzplb8I&D

1SSA - Security consulting, training and products: http://www.1ssa.net

iPhone crashing bug could lead to serious exploit

As cool as it is the Iphone, the more I read about it the more I am disappointed by some of the features it offers. I was for example not aware that it could not execute multiple applications at once, or at least Apple did not allow for it. So far people are still waiting for a tethering option, which seem to be coming soon. And all those poor people that chose not to use AT&T as provider and got locked out by Apple's patch. And now a simple SMS can crash the whole device. I think Apple needs to adjust a bit here...this hype over the Iphones is only going to last as long as it is special....I only say Starbucks. After that it is just a phone that needs to be fixed ;-)

Read the full story at: http://www.theregister.co.uk/2009/07/02/critical_iphone_sms_bug/

1SSA - Security consulting, training and products: http://www.1ssa.net

Thursday, July 02, 2009

Clear the company pre-screening frequent fliers stopped operating

I always though who is doing this, who is paying $199 a year for this privilege of bypassing normal airport security? According to a CSO article 260,000 individuals were part of the program paying each. This is $52M a year...not enough I guess to operate. Clear, the company providing the service has declared that it cannot longer operate the service. Interesting aspect, and nothing new for security professionals, the "data life cycle" for the data collected (e.g. Iris scans, finger prints, etc.) is not clear. Does Clear delete all data or maybe sell it to a competitor?

Read the full article at: http://www.csoonline.com/article/496471/Lawsuit_Seeks_Refund_for_Clear_Subscribers

1SSA - Security consulting, training and products: http://www.1ssa.net