The National Institute of Standards and Technology Computer Security Resource Center has released two special publications: Guidance for Securing Microsoft Windows XP Home Edition Guidance for Securing Microsoft Windows XP Systems for IT Professionals This is new ground for NIST to be covering, and it seems like it would be a good fit… On second thought, it seems like a waste of my taxpayer dollars. You see, the National Security Agency already publishes a whole bunch of Security Configuration Guides. They’ve got guides there for everything from operating systems to switches, databases to VOIP devices. Yes, Windows XP is covered. I will have to read both to find out the similarities/differences, and see if both guides are actually needed. The[…]
Category: software
If you hadn’t already seen, the Department of Homeland Security is strongly recommending the patch related to Microsoft’s MS06-040 bulletin. The Department of Homeland Security (DHS) is recommending that Windows Operating Systems users apply Microsoft security patch MS06-040 as quickly as possible. This security patch is designed to protect against a vulnerability that, if exploited, could enable an attacker to remotely take control of an affected system and install programs, view, change, or delete data, and create new accounts with full user rights. Kind of gives me the creeps. They don’t normally recommend specific patches, so why this one?
First brought to my attention by this blog post from DDJ, the folks at SPI Labs (part of SPI Dynamics have posted a PDF security briefing entitled Detecting, Analyzing, and Exploiting Intranet Applications using JavaScript. This technique can scan networks protected behind firewalls such as corporate networks. All the code to do this is written in JavaScript and uses parts of the standard that are almost ten years old. Accordingly, the code can execute in nearly any Web browser on nearly any platform when a user opens a Webpage that contains the JavaScript. Since this is not exploiting any browser bug or vulnerability, there is no patch or defense for the end user other than turning off JavaScript support in[…]
Ars Technica is running an article called Recycle Bin not enough, Microsoft adds ‘Previous Versions’ support on the file system level. Much like Windows XP and Windows Server 2003’s “Volume Shadow Copy” and “Previous Versions” capability, with one key difference (emphasis added): With Windows Vista, the operating system will make “shadow” (that is, backup) copies of files and folders for users who have “System Protection” enabled (the default setting). The feature will be called Previous Versions, and will be accessible via the right-click properties menu as “Restore previous versions.” Of course this is subject to change by the time Vista actually ships, but is it a good idea to have backups of every file stored on your system? To me[…]
This past weekend, Slashdot posted a story entitled Why Popular Anti-Virus Apps ‘Don’t Work’. It references two articles containing discussions of the same. Malware authors are writing code that will get around the signatures of the application by testing their code on the most popular anti-virus software before release. Well, duh! I had a computer science professor that would give us an F if he could get our programs to crash. He always sat down and tried the same few things to start with—wrong parameters, corrupt input data, etc. If you didn’t test for these before you turned it in, you got the grade you deserved. If you wanted a virus to propagate, wouldn’t you test that it wasn’t detected[…]
Until tonight, I hadn’t seen a mail client that didn’t support S/MIME out of the box (heck, even Outlook Express has limited support for it). Then I installed KUbuntu Dapper Drake on my laptop and discovered that KMail/Kontact indeed does not support S/MIME out of the box in this distro. I’ve got this setup screen asking me for all kinds of S/MIME Validation information (checking CRLs vs OCSP, etc), but it’s all greyed out. It can be enabled but why should I have to do that? Now comes the fun of importing the 100 or so client certs I have for people into the system. Some comments I have read indicate that KMail is not sure about using OpenSSL because[…]