Firefox v2.0.0.6 Released
Mozilla has released Firefox v2.0.0.6 today to address two critical security vulnerabilities. Users should update as soon as possible.
Advisories
To update Firefox go to Help > Check for Updates
My thoughts on tech, with a security angle
Mozilla has released Firefox v2.0.0.6 today to address two critical security vulnerabilities. Users should update as soon as possible.
Advisories
To update Firefox go to Help > Check for Updates
Posted by Nellie2 at 4:50 PM 0 comments
Labels: Updates
I mentioned in a previous post that Scotty of Winpatrol fame will soon get his bark back. The new version of Winpatrol is almost ready for release but if you are feeling adventurous then you can download and test the Beta version here.
There are a couple of interesting and exciting additions to this great program and Scotty has a new icon and of course he woofs again on Vista.
This is a beta version of the program so do follow the advice given by Winpatrol and back up your system before installing it and please do feedback to them if you find any bugs.
Posted by Nellie2 at 3:38 PM 0 comments
F-Secure reports of another Messenger worm, it sends messages to other Messenger contacts that are along the lines of:
Psssssst …. just between me and you, please accept
Looking for hot summer pictures ? well here they are !!
…and includes a link to a file hosted on chatamis.net.
Posted by Nellie2 at 4:57 PM 0 comments
Labels: News
US District Judge Audrey B. Collins has forbidden Sanford Wallace and his associates from creating or maintaining MySpace profiles, using the site to send private messages or post public comments or to suggest in commercial emails or other electronic communications that that they are affiliated with the social network.
The preliminary injunction came in a lawsuit MySpace filed in March. It claims Wallace created more than 11,000 MySpace profiles that churned out private messages, comments and bulletins that directed users to spoofed MySpace pages seeking their login information.
The ruse allowed him to hijack at least 320,000 accounts, which he used to send 400,000 private messages and post 890,000 comments, both of which redirected MySpace users to the sites freevegasclubs.com and realvegas-sins.com. The sites are owned by Feeble Minded Productions, an aptly-titled firm affiliated with Wallace.
See the full story at The Register.
Posted by Nellie2 at 7:15 PM 1 comments
Labels: News
The latest versions of Firefox and Safari contain a password management security flaw that could allow certain websites to access stored usernames and passwords.A message on the Full Disclosure mailing list warned that users who have either browser configured to remember passwords, and have JavaScript enabled, are at risk.
Mozilla fixed a similar reverse cross-site scripting flaw in Firefox last November, but this was a lot more serious as it did not require JavaScript to be enabled.Heise Security has a demonstration of the vulnerability on its website to allow users to determine whether they are vulnerable to the attack.
However, some developers and commentators have questioned whether this constitutes a vulnerability in the browser, as it requires the attacker to place malicious code on the web server.
If an attacker can place script code on a server, they would be able to manipulate the pages anyway, and would have other ways to steal user access data.
Until a fix is released, users are urged to disable JavaScript in their browser or avoid the use of the password manager on sites where users are allowed to post JavaScript pages.
Source | vnunet.com
To disable Java Script in Firefox, go to Tools > Options > Content and untick the Enable Javascript checkbox
To disable Java Script in Safari, go to Preferences > Security > and untick the Enable Javascript checkbox
Posted by Nellie2 at 4:48 PM 0 comments
Labels: News
Anyone who knows me will know that I love Winpatrol, one of it’s endearing features has been the little bark that Scotty gives when alerting you to something or when you launch the program.
However… for some reason, Scotty lost his bark on Windows Vista. But the good news is that Scotty will get his bark back on the next Winpatrol update…. I can’t wait! Woof Woof!
Check out all the technical details at Bits From Bill
Posted by Nellie2 at 2:38 PM 0 comments
Labels: Updates
This summary is not available. Please click here to view the post.
Posted by Nellie2 at 1:41 AM 0 comments
Labels: News, Rogue Alerts
McAfee have put up a little quiz so you can see just how good you are at spotting fake sites. Remember, I gave you a few tips here on how to avoid Phish sites but this quiz really shows just how good some of these pages can be.
So get yourself a coffee and a biscuit and spend 10 minutes on this quiz. You can access it here
Incidentally, I got 8 out of 10
Posted by Nellie2 at 4:15 PM 0 comments
Labels: Off Topic
Drivers for Windows Vista have been a bit of a problem since the Beta version was released last year. A friend of mine couldn’t wait to try it out, but he just couldn’t fix the problem he had with finding a compatible sound driver.
Things are a bit better now, but hardware manufacturers are still taking their time updating their drivers so that your kit will play nice with Vista.
Of course, finding the right driver is the difficult bit. Ed Bott has set up a Vista Master Driver List so if you can’t find it there then it’s probably not been released yet. Thanks to Ed for a great resource and thanks to Corrine of Security Garden for the tip… she’s added this list to Vista Bookmarks which is another site you should check out regularly.
Posted by Nellie2 at 2:34 PM 0 comments
Apple has released a new version of its ubiquitous QuickTime player for both Mac OS X and Microsoft Windows computers. The latest version, v. 7.2, plugs at least eight security holes in the software.
QuickTime vulnerabilities that span both operating systems may present a very attractive target for malicious hackers, as the program is installed by default on all Apple machines, and on most Windows PCs (if you have iTunes installed, chances are you also have QuickTime on your system). Indeed, recent automated attack tools have been found to exploit QuickTime flaws.
Mac users can grab the latest, patched version using the built-in Software Update feature. Windows users should be able to fetch the patches using the Apple Software Update program that comes bundled with most relatively recent versions of QuickTime and iTunes.
Source | Security Fix
Posted by Nellie2 at 5:15 PM 0 comments
There has been a Flash Player update that addresses two security vulnerabilities.
Please note; You don't have to have the Google Toolbar to install the update so just uncheck it.
Talking of Adobe, there are also some Photoshop CS2 and CS3 updates to address security vulnerabilities.
Posted by Nellie2 at 5:08 PM 0 comments
Labels: Updates
Firefox is prone to a remote denial-of-service vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions.
Firefox 2.0.0.4 is vulnerable to this issue; other versions may also be affected.
Source | Security Focus
Posted by Nellie2 at 9:31 AM 0 comments
Labels: News
The MVPS Hosts File was updated yesterday.
What is a hosts file? It's a very useful piece of kit that sits in a little folder not bothering anyone. When you tell your browser that you want to go to a particular website, the browser will convert the address you typed to a bunch of numbers called an IP address, before it connects to the website it will check the hosts file to make sure it's got the numbers right. If there is nothing there, then it will connect.
That seems straight forward enough, but why have a hosts file when your browser always goes where you want it to go.. well if you think about it, sometimes it doesn't. Lots of websites have adverts on them.. some of these ads try to connect to a separate server so they can dump a tracking cookie into your system. Or, maybe you are searching for something and inadvertently click on a link to a bad site which could infect your computer with something horrible. This is where the hosts file comes into it's own. If you have an entry in your hosts file like this;
127.0.0.1 www.thisisnotasiteyouwanttovisit.com
Then if your browser tries to connect to thisisnotasiteyouwanttovisit.com, when it checks the hosts file it will just come back on itself because the IP 127.0.0.1 is your computer.
So... a hosts file is a very useful security feature to have on your computer, it's not much good though if it isn't kept up to date. The MVPS hosts file is updated regularly. See mvps.org for more information, tips and installation instructions.
Posted by Nellie2 at 11:28 AM 0 comments
Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday.
Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.
On 10 July 2007 Microsoft is planning to release:
Security Updates
- Three Microsoft Security Bulletins affecting Microsoft Windows with a Maximum Severity rating of Critical. These updates will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.
- Two Microsoft Security Bulletins affecting Microsoft Office with a Maximum Severity rating of Critical. These updates will not require a restart and will be detectable using the Microsoft Baseline Security Analyzer
- One Microsoft Security Bulletin affecting Microsoft .NET Framework with a Maximum Severity rating of Critical. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.
Microsoft Windows Malicious Software Removal Tool
Non-security High Priority updates on MU, WU,WSUS and SUS
- Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.Note that this tool will NOT be distributed using Software Update Services
- Microsoft will release one NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
- Microsoft will release four NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
Microsoft Security Bulletin Advance Notification
Obtaining Other Security Updates
Updates for other security issues are available from the following locations:
Posted by Nellie2 at 4:45 PM 0 comments
Did you know about this? It's an online scanner from Panda, but unlike some online scanners this one just takes a minute or two.
It claims to detect more than 1,031,124 virus's and spyware.
You do need to download and install an ActiveX to run it and therefore Internet Explorer is recomended, although if it's Firefox or nothing for you then you can install the IEtab addon to run it.
Nanoscan only detects and it's recomended that you run TotalScan if anything is found.
Here is the science bit .
Don't forget, there are other online scanners available and you should always have an active and up to date resident anti virus program on your system.
Posted by Nellie2 at 1:27 PM 0 comments
Labels: Spyware Removal