Microsoft's June Patch Tuesday release included a critical fix affecting all Windows Vista and XP systems, which could allow attackers to wirelessly steal confidential information from laptops by exploiting a flaw in the Bluetooth stack.
The Bluetooth stack flaw, detailed in Microsoft bulletin CVE-2008-1453 and rated 'critical', could allow an attacker to take complete control of an affected system, install programs, alter data or create new accounts with full user rights.
The MS08-030 patch modifies the way the Bluetooth stack handles a large number of service description requests.
Microsoft recommends applying the patch immediately and security experts advise users to turn off Bluetooth features until the patch has been applied.
Matthew Aburn, director of security consultancy Halcyon, said the flaw was particularly dangerous because hardware manufacturers usually set the factory default for Bluetooth as 'active'.
"Hardware-wise, most ship with Bluetooth on by default. I'd definitely recommend that if you're not using Bluetooth, you should turn it off," Aburn told ZDNet.com.au.
Rob Pregnall, Symantec's senior manager of Technical Product Management for Endpoint Security in Asia Pacific and Japan, agreed. He said hardware manufacturers should do this to make those features easier to access.
"When I look at a freshly bought machine from a reputable manufacturer, the first thing I notice is that every bell and whistle is turned on. I see it across different hardware manufacturers, including Macs," he said.
"All the different communication technologies are generally activated, so I think it's a move by manufacturers to ensure that everything is turned on so that minimal effort is needed to use the capabilities that users were sold on," Pregnall said.
In a blog, Microsoft admits that although in most cases an attacker would need to be in close range to exploit the vulnerability, there are ways to increase that distance.
"The standard range of Bluetooth is in the order of metres, although an attacker could use specialised antennas to increase this," the blog said.
This was backed up by Halcyon's Aburn.
"People look at the standard specifications for Bluetooth range of connectivity, which says you need to be so many metres away but using a directional antenna, people can target you from much further away," he said.
This month's Patch Tuesday includes fixes for a drive-by download weakness in Internet Explorer, as well as flaws in affecting Microsoft's multimedia.
The critical vulnerability affecting Internet Explorer described in CVE-2008-1442 and CVE-2008-1544 only affects Windows XP and Vista systems. The MS08-031 cumulative patch fixes a couple of vulnerabilities, including one that could allow remote code execution if a user viewed a specially crafted web page using Internet Explorer and another which could allow information disclosure if a similarly configured page was viewed using the browser.
The DirectX flaws affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-0011 and CVE-2008-1444. Microsoft says the vulnerability "could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
My New Blog
June 11, 2008
I am controlling your PC via Bluetooth.
June 8, 2008
Students Hack Windows Cardspace
Students at the Ruhr University of Bochum, Germany, say they have found a way to steal security tokens in Microsoft's new CardSpace authentication framework. Attackers can apparently get access to protected, encrypted user data – such as passwords, credit card numbers, and delivery addresses – when they are transmitted. CardSpace (formerly InfoCard) is the successor to Passport. In both architectures, users' personal data are stored locally on the user's system. Depending on the web site, users can decide which data they want to transmit. CardSpace is designed to make classic passwords a thing of the past, by replacing them with digital certificates that may be self-signed or signed by an authoritative CA such as Verisign.
According to the report, anti-DNS pinning, DNS rebinding, DNS spoofing, and drive-by pharming are apparently all successful ways to steal transmitted tokens. Attackers basically need to manipulate the user system's name resolution so that the token for the browser-based CardSpace is sent to the attacker. To this end, attackers manipulate the DNS entries on a router, for instance by means of cross-site request forgery, and send the attacked user to a malicious name server. If the attacker manages to switch name resolution during an authentication process so that the victim lands both on a shop's genuine CardSpace website and on a malicious forgery, the attacker then gets the token. During the token's validity, attackers can then pretend to be the user in question when they go shopping.
The students have created a demo server that they claim demonstrates the problem. To reproduce the demonstration, you should change your own DNS settings and install an untrusted certificate. In our test at heise Security, we could not get the demonstration to run, however. Microsoft has apparently already been informed of the problem and is working on a solution. In their report, the students propose improving Same Origin Policy as a security function for browsers.
June 7, 2008
MICROSOFT SCAMS AGAIN!
Businesses that skip Windows Vista and upgrade their computers directly from the XP operating system to Windows 7 could expose themselves to security risks and other problems, Microsoft says in a new white paper.
Bypassing Vista could have "implications for security, support, and regulatory compliance and reduce flexibility in the face of changing business requirements," writes Microsoft VP Mike Nash, in the paper.Specifically, Nash says that businesses that wait for Windows 7 -- set for release in late 2009 or early 2010 -- to upgrade from XP could find themselves using outdated applications that don't employ proper security safeguards or are no longer supported.
They also won't get the advantage of new security technologies and other improvements that Microsoft embedded in Vista, Nash says. "By not deploying Windows Vista, it means missing out on the proven benefits such as better security, productivity, search, mobility, manageability and infrastructure optimization," Nash says in the paper, which is titled "The Business Value Of Windows Vista."
Do you remember any similar pushes with previous operating systems? This could possibly be because of the absolute travesty that is Vista security, that has kept so many large businesses from switching to the operating system. After such an outcry from the IT community and backlash against their prettiest operating system, Microsoft has decided to switch their tactics from marketing to George Bush-esque "strategertizing". Overheard in a consultation, "OH so you don't want to upgrade to Vista? If you don't You will never be able to Upgrade again!!!" Basically they are trying to tell you that if you don't upgrade to Vista, You can't upgrade to 7. And you can bet that the software of 7 wont allow a install from XP. And will most likely have a discount upgrade to Vista. 49.99 so that you can upgrade to vista so that you can upgrade to 7 (It's a steal!!!)
Posted by
Gillis57
at
1:56 PM
0
comments
Labels: Admin, Bill Gates, Expensive, Force, Gillis Jones, Hewlett Packard, IT, microsoft, Security, Social Engineer, Vista, Windows, Windows 7
June 2, 2008
Microsoft wants your Opinion?
In the continuing effort to improve computer and network security, Microsoft has developed the End to End Trust initiative. As a part of that initiative, Microsoft is seeking input from users and information security professionals to help answer the questions that need to be addressed in order to evolve computer security such as How should we enhance security on the Internet without undermining social values, such as privacy and anonymity? There are more questions to be answered in the End to End Trust Forums. Scott Charney, Microsoft's Corporate Vice President of Trustworthy Computing, has developed a white paper entitled Establishing End to End Trust which provides more details on Microsoft's vision.
While it is not beyond the stretch of a reasonable person's imagination that a giant of the industry would want to keep it's users secure. The employees and designers of microsoft have showed a lack of willingness to address serious security issues, and wrap every tiny piece of security as the next big step in computing. Rather than the required software that all of this should have been back in Windows 98. It seems that every time Microsoft attempts security, it undoubtedly blows up in it's face. So I would encourage you to voice your opinion to microsoft- Let them know you value your security, as well as your wallet.
May 18, 2008
Microsoft Vista Security... Yeah Right!
Lately, Microsoft has been trumping the myriad of new security measures that have been included in Windows Vista. However, IT techs have been screaming their guts out that between the lack of any substantial changes (aside from a circular start bar), the forced User Account Control, and big brother like computing- That everyone should stay with XP. Well, now we have actual basis for this. Notice how that Microsoft is quick to shift ALL the blame to the incompetent user.
The claim that Vista is less secure than Windows 2000 was made last week by security vendor PC Tools, which said that over the past six months Vista had suffered 639 unique threats, whereas Windows 2000 has suffered 586. PC Tools's research was conducted by collecting data from customers using its ThreatFire behavioural detection software. "Ironically, the new operating system has been hailed by Microsoft as the most secure version of Windows to date," said Simon Clausen, the chief executive of PC Tools last week. "However, recent research conducted with statistics from over 1.4 million computers within the ThreatFire community has shown that Windows Vista is more susceptible to malware than the eight-year-old Windows 2000 operating system, and only 37 percent more secure than Windows XP," Clausen said.
However, Microsoft strongly hit back at the claims, blaming users for executing malicious code on their machines. On Tuesday, Technet blogger and Microsoft evangelist Michael Kleef said the number of infections found by PC Tools was an indication of poor user behaviour
639 unique threats? This coming from the billion dollar brain-trust that spent four years to develop a circular start bar? I am truly, truly stunned.
Posted by
Gillis57
at
12:44 PM
2
comments
Labels: Anti-Virus, Exploit, Malicious, Michael Kleef, microsoft, Security, Spam, ThreatFire, Virus, Vista
April 29, 2008
Microsoft A Good Guy?
In a recent set of closed door meetings, Microsoft met with Law Enforcement Officials to help solve a rash of crimes. Although Microsoft has generally gotten a bad-wrap for Bullying opponents out of the market place, it seems all that consolidation of resources is finally paying off. They gave a tool to the Officials that allows them to track botnets as they progress! How is this achieved you may ask? By tracking your computer :) Thats right- The Malicious Software Removal Tool is now Identifying you to law enforcement as a part of a global botnet! Oh Happy Day! We don't know exactly what the name is, what technology it uses, or even if it really exists- The Microsoft spokesperson offered this explanation: " Although Microsoft is reluctant to give out details on its botnet buster -- the company said that even revealing its name could give cyber criminals a clue on how to thwart it "
All my indicators went off at that comment- It seems that Microsoft is now engaging in the Propoganda market. We know who you are but we aren't going to do anything! Okay.
From a Microsoft White Paper:
With regard to phishing and spam, for example, it engaged in broad consumer education campaigns and worked on developing technological solutions such as phishing filters and SenderID. For both phishing and botnets, Microsoft began working more extensively with law enforcement to identify phishers and botnet herders in an attempt to create deterrent to such activity, even though the deterrent effect is limited by the current environment because it is hard to find offenders, and criminal penalties may be applied without sufficient force.