Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Tuesday, September 20, 2011

Microsoft reissues update for Win XP/2003 for DigiNotar certificate revocation


Microsoft Update on Windows XPMicrosoft had to reissue an update for users of Windows XP and Windows 2003 today related to the compromise of certificate authority DigiNotar.
It was not related to further hacking though, it appears to be a quality assurance SNAFU at the software giant.
Microsoft has updated the known issues in security advisory 2607712 to refer to an updated advisory 2616766.
KB article 2616766 points out that the update shipped last week to remove the known compromised certificates from the trusted certificate list omitted the certificates known to have been in use in the wild.
Somehow Microsoft's Patch Tuesday update only removed additional certificates issued to DigiNotar by GTE and Entrust, but did not remove the original root certificates used to intercept communications in Iran.
Users of Windows XP and 2003 with automatic updating enabled will receive the updated patch automatically, but administrators who manually deploy patches using WSUS may be required to push update 2616676 a second time.
Even worse the update requires users of XP and 2003 to reboot after applying the fixed update. Users of Windows 7, Vista, 2008 and 2008 R2 are unaffected.

Sunday, September 18, 2011

SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2



Sophos Security Chet Chat logoThis week my guest for the podcast was Mike Wood, a Senior Threat Researcher at SophosLabs in Vancouver, Canada.
Mike is our expert on digital certificates and how malware authors try to use andabuse digital certificates for their own purposes.
I talked briefly about this month's Patch Tuesday, which fortunately is a small one compared to others this year.
I also briefly mentioned the compromise at DNS registrar NetNames. The attacker pointed the DNS for The Register, UPS and others to a Turkish hacker web site.
We discussed the latest version of Firesheep and how it is now able to steal your Google search history due to a flaw in how some Google sites handle cookies.
The meat of this Chet Chat was spent discussing the recent breach and impact of the hacker(s) who compromised certificate authority DigiNotar.
Mike went into some detail of how certificates have been abused and what these attackers might accomplish if they were to use bogus certificates they purloined from DigiNotar.

(8 September 2011, duration 27:22 minutes, size 12.5 MBytes)
You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 72 or subscribe to our RSS.

Windows 8 to have built-in anti-virus - there's good and bad news



Microsoft will ship Windows 8 with built-in anti-virus software.
That's the big news that is no doubt being discussed furtively at the watercoolers of computer security companies around the world today.
What will it mean to them? A quick glance at Twitter reveals that some people already have pretty good ideas about how the news might have been received..

Jason Hughey
Microsoft announces Windows 8 has anti-virus/anti-malware built in. Loud screams are heard from Symantec/Norton and McAfee headquarters!
But seriously, is this good news for the existing anti-virus companies and - more importantly - consumers?
Microsoft Security EssentialsMicrosoft has been making a free anti-virus software available for a couple of years, in the form of Microsoft Security Essentials. But you had to download it from the internet - it wasn't bundled with Windows itself.
Microsoft has been bundling a program called Windows Defender with Windows 7, Windows XP and Vista, but it doesn't really compare to a proper anti-virus product.
With Windows 8, it sounds as if Windows Defender will be beefed up to incorporate the functionality of Microsoft Security Essentials. Effectively, Windows 8 users will be getting out-of-the-box protection against malware, as well as a firewall and parental controls.
So, it's a case of good news and bad news.

Good news for..

Consumers. Anything which encourages Joe User to run up-to-date anti-virus software has to be a positive thing. There are too many poorly protected home computers out there, which have been commandeered into botnets.
Windows Defender running on Windows 8
But at the same time it's also good news for..
Malware authors. You don't think they're going to ignore this development, do you? If most budget-conscious home users stick with Microsoft's built-in offering, then surely the first thing the bad guys will do is make sure their latest creation can slip past Microsoft's scanner.
No doubt they'll have a new template for their fake anti-virus alerts too.

Bad news for..

Security vendors. It's bad news for those security vendors who rely heavily on consumer sales of their software. It's questionable as to whether many home users will want to reach into their pockets and pay for security from them if there's already one built into Windows 8.
Frankly, it's their own fault. The two big security hippopotamuses have had years of opportunity to gobble up the end-user market, and yet still millions of home users were infected by malware, spyware and pop-ups each year.
It's understandable that Microsoft want to clean up the image of Windows - and if commercial anti-virus vendors haven't managed to do the job, then why shouldn't they do it themselves?
Microsoft's plans for Windows 8 might mean knee jerk reactions from some vendors, and even perhaps more price-cuts and giveaways in an already aggressive market.
I wouldn't be surprised if the legal eagles at rival security firms accused Microsoft of anti-competitive practices, and forced the software giant to offer users security products from a selection of different vendors, just
just as happened in the case of Internet Explorer.
Browser choice screen
But it's not just some security vendors who may struggle, with Microsoft's decision. There's another group who may find life isn't too rosey in the Windows 8 world..
Consumers. Yes, it could be bad news for users too. At least some of them. The thought of running the same anti-virus product as every other home user on the planet, gives me shivers. A security monoculture is not a good thing.
Clued-up folks may well choose to use a non-Microsoft anti-virus (either free or commercial) just to not go with the crowd.
We certainly live in interesting times.
Me? I welcome Microsoft doing more to protect home users from the huge problem of malware, but at the same time I'm pleased to say I don't work for a company which relies on anti-virus sales to home users.

Will Windows 8's new interface herald full-screen scareware?



Microsoft has designed a new user interface for Windows 8, with an emphasis on bright colours and friendliness.
Personally, the interface (dubbed "Metro") reminds me of a child's toy.
Windows 8 and Simon toy
One of the interesting features of the Metro user interface is that apps are designed to be full-screen, without any surrounding furniture. That means you won't see scroll bars and the like, unless you interact with the interface.
One has to wonder whether this will lead to a wave of new scareware/fake anti-virus attacks.
Currently, malicious hackers poison webpages to display what appears to be a warning about malware found on your computer - tricking users into downloading software. The initial alert pops up in your web browser.
Fake anti-virus alert on older version of Windows
These phony alerts have proven to be a very effective way for cybercriminals to fool users into installing their malicious scareware. And it's very likely we'll continue to see hackers trick your browser into displaying bogus warning messages
But, with Windows 8, these browser-based fake anti-virus warnings will be shown full-screen, without the tell-tale visible signs that you're in a browser.
That means it may be even easier to convince a victim into believing they are viewing a genuine security alert from the operating system rather than simply a webpage pretending to be one.
Some will argue, no doubt, that Window 8's Metro simplistic interface is a sign of progress, making the use of computers less threatening to those who are currently put off by complicated GUIs.
The view may be that people get confused between operating systems, apps and browsers - why not make them all look the same?
But these are the very people who are, perhaps, most likely to be tricked into believing that a fake anti-virus alert is genuine and blindly do whatever the computer screen is advising them to do.
It will certainly be interesting to see how cybercriminals evolve their social engineering attacks to take advantage of a Windows 8 Metro-interfaced world.

Blue screens, cute screens

One thing we've already seen is how Microsoft has - after many years - revamped their infamous blue screen of death. Now it's a cute screen of death instead (and a slightly different shade of blue).
Blue screen of death - is this progress?
Wow, that's real progress..
One wonders if the blue screen itself will become an attractive disguise for scammers and malicious hackers.
Will they attempt to duplicate the look of the now oh-so-friendly blue screen of death by popping it up in full screen browser sessions, tricking users into making bad decisions?
One thing we can be sure of - if the bad guys think they will make money effectively this way, they'll do it.