Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, December 16, 2013

Another Vulnerability–and another Patch

Yet another security vulnerability in Windows, Office and Lync has been discovered that could enable remote code execution. The vulnerability is triggered if the user views content that contains specially adapted TIFF files. The vulnerability was first noted in security advisory 2896666 published in early November.

The fix is Microsoft Security Bulletin MS13-096. To resolve the fix, there are a number of potential patches that need to be applied – these now appear to have shipped via Automatic Update. So for home systems, if you are using Lync, or office or later versions of Windows, make sure your systems are all patched (Microsoft/Windows update should do the trick). If you are an an oganisation that managed software updates, make sure the updates for this security bulletin are applied.

Thursday, November 07, 2013

Zero Day Attacks on Lync 2013 Client?

News today of some new vulnerabilities in certain version of Lync, The Microsoft disclosure page on these attacks at https://technet.microsoft.com/en-us/security/advisory/2896666, and were described by ZD at: http://www.zdnet.com/zero-day-attacks-hit-windows-office-lync-7000022836.

The first version of the ZD article seemed to imply that Lync was suffering Zero Day attack, but it was later amended to say that in the wild attacks have only been seen, SO FAR, against Microsoft office. These vulnerabilities ‘only’ allows remote code execution but that’s enough to really mess up someone’s day, to say the least.

Microsoft’s disclosure page includes details on workarounds (to mitigate against the attacks) and a ‘Fix It’ link to automate these. I’ve not yet seen hot fixes to resolve the problem, but will be anxiously looking for them and plan to implement them quickly!

Technorati Tags: ,

Wednesday, January 28, 2009

QDB: Quote #244321- The joys of social engineering

I’ve long enjoyed examples of social engineering, hoping I’d never fall for them. The IRC chat, at QDB: Quote #244321, is a great example of this. Take a read (I had to read it twice!).

Technorati Tags:

Sunday, December 02, 2007

SecPol in Vista Home Premium - there isn't any!

As Susan Bradley has discovered is: There's no secpol in Vista Home Premium and she asks the all important question - now what. Naturally, Susan provides a neat answer - just hack the registry.

This tip will come in handy - I'm getting my wife a new computer and it'll come with Vista loaded and I want to not have to have her deal with UAC.

Thanks Susan.

Sunday, November 25, 2007

Download details: Office Communications Server 2007 Security Guide

Yet more documentation from the OCS team. In this case, the Office Communications Server 2007 Security Guide which is a 42-page document describing the security aspects and features of OCS 2007. This is a must read for all OCS admins!

Sunday, June 10, 2007

NIST Security Controls Guide Published

The National Institute of Standards and Technology (NIST) has published a 387-page Guide for Assessing the Security Controls in Federal Information Systems, which you can freely download as a PDF document. Technically this document is a draft (the third draft), but even so, it contains good information on the fundamentals of security controls and details on the process you undergo to develop and implement controls. This is a useful read for anyone in the IT Security business.

Technorati tags: , ,

Saturday, February 05, 2005

Security MVP

I got a nice email this week from Microsoft, which said I've been selected to be a Security MVP (over and above my MVP award for Software Distribution). This is pretty cool. For more information about the Security MVPs see the IT Pro Security Community page.