Showing posts with label Search. Show all posts
Showing posts with label Search. Show all posts

Thursday, April 07, 2016

Critical Out-of-Band Adobe Flash Player Update

Adobe Flashplayer

Adobe has released Version 21.0.0.213 of Adobe Flash Player for Microsoft Windows and Macintosh due to reports that CVE-2016-1019 is being actively exploited on systems running Windows 10 and earlier.

It is strongly advised that Flash Player be updated as soon as possible.


Release date: April 7, 2016
Vulnerability identifier: APSA16-01
CVE number: CVE-2016-1006, CVE-2016-1011, CVE-2016-1012, CVE-2016-1013, CVE-2016-1014, CVE-2016-1015, CVE-2016-1016, CVE-2016-1017, CVE-2016-1018, CVE-2016-1019, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1030, CVE-2016-1031, CVE-2016-1032, CVE-2016-1033
Platforms: Windows, Macintosh, Linux and Chrome OS

Warning:  Although Adobe suggests downloading the update from the Adobe Flash Player Download Center, that link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive.  If you use the download center, uncheck any unnecessary extras. 

    Notes:
    • If you use the Adobe Flash Player Download Center, be careful to uncheck any optional downloads that you do not want.  Any pre-checked option is not needed for the Flash Player update.
    • Uncheck any toolbar offered with Adobe products if not wanted.
    • If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
    • The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.

    Verify Installation

    To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. 

    Do this for each browser installed on your computer.

    To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.

    References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...








    Tuesday, September 08, 2015

    Microsoft Security Bulletin Release for September, 2015


    Microsoft released twelve (12) bulletins.  Five (5) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.

    The updates address vulnerabilities in Microsoft Windows, Microsoft,.NET Framework, Microsoft Office, Microsoft Lync, Microsoft Silverlight, Skype for Business Server, Microsoft Lync Server, Microsoft Edge and Internet Explorer.

    Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.

    Update:  You won't want to miss the new Monthly Patch Review by Dustin Childs.

    Critical:
    • MS15-094 -- Cumulative Security Update for Internet Explorer (3089548) 
    • MS15-095 -- Cumulative Security Update for Microsoft Edge (3089665) 
    • MS15-097 --Vulnerabilities in Microsoft Graphics Component  Could Allow Remote Code Execution (3089656) 
    • MS15-098 -- Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669)  
    • MS15-099 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)  
    Important:
    • MS15-096 -- Vulnerability in Active Directory Service Could Allow Denial of Service (3072595)
    • MS15-100 -- Vulnerability in Windows Media Center Could Allow Remote Code Execution (3087918) 
    • MS15-101 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662) 
    • MS15-102 -- Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657) 
    • MS15-103 -- Vulnerabilities in Microsoft Exchange Server Could Allow Information Disclosure (3089250) 
    • MS15-104 -- Vulnerabilities in Skype for Business Server and Lync Server Could Allow Elevation of Privilege (3089952) 
    • MS15-105 -- Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (3091287) 

    Additional Update Notes

    • MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the prevalent ransomware family Win32/Teerac. Details are available in the MMPC Blog Post.
    • Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.

    References




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...




      Wednesday, October 27, 2010

      Windows Live Essentials 2011 Data Collection

      I was rather surprised when the message below rolled up in front of my browser window today. 


      Apparently, after installing Windows Live Essentials or the Bing Bar, you will be asked if you want to help Microsoft improve their products.  Strange that I just got the pop-up today.  I have had the Windows Live Essentials on this computer for some time and the Bing Bar was on, off, back on, off, again.

      From the "Learn More" link, I discovered that the purpose is to improve Windows Live and the Bing Bar.  If you see this "pop-up" it is very important to note a few important points:

      • Participation is complete voluntary. you can uncheck one, two or all three options.
      • No data will be collected without your agreement to participate (leave the last box checked).
      • All collected data is confidential.

      What if you decide to opt-out after you agreed to the data collection?  You can change the setting for Windows Live Essentials by changing the "Help improve Windows Live" setting in the options of any Windows Live program.

      Follow the steps below to stop participating in the Bing Bar program:
      1. Launch your browser.
      2. On the right side of Bing Bar, click the Toolbar options button Toolbar options.
      3. Click Quality, select No, I don't want to participate, and then click OK.
      References:



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, September 07, 2010

      Mozilla Firefox 3.6.9 Security Update

      Mozilla released Firefox version 3.6.9 which fixes several security and stability issues.  In addition, this version introduces support for the X-FRAME-OPTIONS HTTP response header. Site owners can use this to mitigate clickjacking attacks by ensuring that their content is not embedded into other sites.


      If not prompted to update, existing Firefox users can update via Help > Check for Updates.

      Security Issues Fixed in Firefox 3.6.9

      • MFSA 2010-63 Information leak via XMLHttpRequest statusText
      • MFSA 2010-62 Copy-and-paste or drag-and-drop into designMode document allows XSS
      • MFSA 2010-61 UTF-7 XSS by overriding document charset using type attribute
      • MFSA 2010-59 SJOW creates scope chains ending in outer object
      • MFSA 2010-58 Crash on Mac using fuzzed font in data: URL
      • MFSA 2010-57 Crash and remote code execution in normalizeDocument
      • MFSA 2010-56 Dangling pointer vulnerability in nsTreeContentView
      • MFSA 2010-55 XUL tree removal crash and remote code execution
      • MFSA 2010-54 Dangling pointer vulnerability in nsTreeSelection
      • MFSA 2010-53 Heap buffer overflow in nsTextFrameUtils::TransformText
      • MFSA 2010-52 Windows XP DLL loading vulnerability
      • MFSA 2010-51 Dangling pointer vulnerability using DOM plugin array
      • MFSA 2010-50 Frameset integer overflow vulnerability
      • MFSA 2010-49 Miscellaneous memory safety hazards (rv:1.9.2.9/ 1.9.1.12)


      Clubhouse Tags: Clubhouse, Security, Vulnerabilities, Updates, Information





      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, August 10, 2010

      Adobe Flash Player Security Update


      An Adobe Security Bulletin has been posted to address critical security issues in Adobe Flash Player and Adobe Air.

      Although Adobe suggests downloading the upate from the Adobe Flash Player Download Center or by using the auto-update mechanism within the product when prompted, if you prefer, the direct download links are as follows:

      If you use the Adobe Flash Player Download Center, be careful to UNCHECK the box shown below. It is not needed for the Flash Player update!

      1 MB

      McAfee Security Scan Plus

      Verify Installation:

      To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. Do this for each browser installed on your computer.

      Verify the version of Adobe AIR installed on your system in the Adobe AIR TechNote.

      Details from Security Bulletin APSB10-16:

      Release date: August 10, 2010

      Vulnerability identifier: APSB10-16

      CVE number: CVE-2010-0209, CVE-2010-2188, CVE-2010-2213, CVE-2010-2214, CVE-2010-2215, CVE-2010-2216

      Platform: All Platforms

      Summary

      Critical vulnerabilities have been identified in Adobe Flash Player version 10.1.53.64 and earlier. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.

      Adobe recommends users of Adobe Flash Player 10.A1.53.64 and earlier versions update to Adobe Flash Player 10.1.82.76. Adobe recommends users of Adobe AIR 2.0.2.12610 and earlier versions update to Adobe AIR 2.0.3.

      Affected software versions

      • Adobe Flash Player 10.1.53.64 and earlier versions for Windows, Macintosh, Linux, and Solaris
      • Adobe AIR 2.0.2.12610 and earlier versions for Windows, Macintosh and Linux


      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, July 20, 2010

      Mozilla Firefox 3.6.7 Security Update

      Mozilla released Firefox version 3.6.7 which fixes several security and stability issues.

      If not prompted to update, existing Firefox users can update via Help > Check for Updates.


      Clubhouse Tags: Clubhouse, Security, Vulnerabilities, Information,

      Clubhouse Tags: Clubhouse, Security, Vulnerabilities, Updates, Information






      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, June 29, 2010

      Bing Search Engine Statistics

      When reviewing the visitor statistics for Security Garden, I have been noticing a steady increase in visitors resulting from Bing searches.

      Although the bar graph below is from U.S. visitors, I noticed today that the results from Bing.com overshadowed those from Google.com.


      Thus far, international visitors to Security Garden are not using Bing for their locale and are staying with Google. To set Bing to your part of the world go to the Bing Worldwide page. To change your display language, go to preferences.

      Clubhouse Tags: Clubhouse, Microsoft, Bing, Search, Information,



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, April 13, 2010

      Microsoft Security Bulletin Release, April 2010

      Microsoft released 11 security bulletins to address 25 vulnerabilities: five rated Critical, five rated Important and one rated Moderate. The release affects Windows, Microsoft Office, and Microsoft Exchange.

      Also note that the Malicious Software Removal Tool (MSRT) was updated to include Win32/Magania.

      The table from the Security Research & Defense blog, referenced below, clarifies the importance of the updates. Note further that Windows 7 is not affected in several of the updates.


      References:


      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Thursday, January 21, 2010

      Update Now! Security Bulletin MS10-002 Released


      Microsoft released out-of-band Microsoft Security Bulletin MS10-002. It is strongly recommended that this update be installed as soon as possible.

      MS10-002 is identified as Critical for all supported releases of Internet Explorer, including Internet Explorer 5.01, Internet Explorer 6, Internet Explorer 6 Service Pack 1, Internet Explorer 7, and Internet Explorer 8. The only exception is Internet Explorer 6 for supported editions of Windows Server 2003, in which case the update is rated Moderate.

      MS10-002 is accelerated from the regularly scheduled February release update.

      References:


      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Vulnerabilities, Information


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Thursday, May 28, 2009

      The sound of found: Bing!

      As you can see with a glance to the right, I removed the Live Search image and replaced it with the brand new logo for Bing, the new Microsoft search engine.
      Discover Bing
      Making the top trends in Twitter today has been the sound of Bing. In fact, that is the idea behind the title of the introduction to Bing at the Live Search blog:
      "Why did we pick Bing as the new brand name? We needed a brand that was as fresh and new as our approach. It needed to be like the product — optimized for the Internet. A name that was memorable, short, easy to spell, and that would function well as a URL around the world. We like Bing because it sounds off in our heads when we think about that moment of discovery and decision making — when you resolve those important tasks. And frankly, the name needed to clearly communicate that this is something new, to invite you to come back, to re-introduce you to our new and improved service and encourage you to give it a try."
      Learn more about Bing at Why Bing?.

      Update: Listen to Apple co-founder Steve Wozniak in Woz Bing! Apple Co Founder a "Big Fan" of Microsofts New Search Engine

      References:




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Thursday, May 14, 2009

      Google currently falls short

      In a carefully documented report, Ben Edelman, a well known and respected security expert, reveals how Google and its partners
      • intercede to divert traffic that would have reached advertisers' sites directly -- without advertisers incurring any advertising expense.
      • pass the traffic back to the advertisers users were trying to reach -- but only after collecting pay-per-click advertising fees.
      Also demonstrated is what appears to be conveniently overlooking Google's "Software Principles" requirements for their WhenU and IAC partners.

      See how
      • WhenU Covers Advertisers' Sites with Advertisers' Own Google Ads
      • IAC's SmileyCentral Grab Advertisers' Organic Traffic to Show Google Ads
      • Typosquatting: Cmcast.com, MediaLogik, and Thousands More Intercept Users' Misspellings to Show Google Ads
      • Google Chrome Suggestions Divert Users from Direct Navigation to Search
      in How Google and Its Partners Inflate Measured Conversion Rates and Inflate Advertisers' Costs.




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Saturday, March 14, 2009

      Privacy and Google Ads, Voice, Docs

      Yesterday morning I was reading about Google's change to "interest-based advertising" when I received a message from a friend at WinVistaClub directing me to a Preston Gralla article at ComputerWorld about Google Voice. Then I came across an article at TechCrunch about "inadvertent" sharing of documents. Individually, these three topics are worth being concerned about. Taken in combination, one followiong the other, I find it quite disturbing.

      Google Ads

      Google has given in to their advertisers and announced "interest-based advertising". What is the difference between "interest-based advertising" and the ads you see now? With the current format of serving ads, if you are on a website reading about computer keyboard shortcuts, the ads presented will be targeted toward the key words on that page -- i.e., keyboards, mice or other computer-related products.

      With interest-based advertising, the ads will be based on the types of sites you visit and the pages you view. For example, if you spend a lot of time on sports-related websites, you are likely to see ads for running shoes when investigating the purchase of a new refrigerator. In other words, the ads will be based on your browsing history.

      As Google admits:
      This kind of tailored advertising does raise questions about user choice and privacy — questions the whole online ad industry has a responsibility to answer.
      As a result, in the Google Privacy Center, Advertising and Privacy, there is an Opt out option:


      Edit Note: It appears that my security settings were such that I was unable to access the Opt Out links. Thanks to the comment posted by Microsoft MVP Donna Buenaventura and the information she provided at Calendar of Updates, I followed Donna's lead and as a result have accordingly edited this posting.

      Only one minor problem. When I clicked the Opt out link, this is what happened each time I tried:

      [Image Removed]

      It didn't matter which browser I used.

      [Image Removed]

      There is also supposed to be the ability to edit the preferences that are associated with the cookie at the Ads Preferences Manager. That link does not work either.

      Based on the inability of those opt-out options to work, do I really want to trust installing the browser plugin to permanently opt-out of the Double Click cookie?

      Google Voice

      Google Voice unifies your phone numbers, transcribes your voice mail, blocks telemarketers and allows you to archive and search all of the SMS text messages you send and receive and more. (Features: Google Voice).

      As Marc Rotenberg indicated, with those features come other concerns.
      "The service would allow Google, which already collects vast amounts of data about the behavior of Internet users, to gather information on their calling habits.

      “It raises two distinct problems,” said Marc Rotenberg, executive director of the Electronic Privacy Information Center. “In the privacy world, it is increased profiling and tracking of users without safeguards. But the other problem is the growing consolidation of Internet-based services around one dominant company.”"

      Google Docs

      As reported at TechCrunch, Google sent a notice to a number of users of its Document and Spreadsheets products informing them that it may have inadvertently shared some of their documents with contacts who were never granted access to them. Reportedly the sharing was limited to people “with whom you, or a collaborator with sharing rights, had previously shared a document”.

      TechCrunch reported that they were informed by Google that the error affected less than .05% of all documents. Is that .05% of one hundred documents or multiple millions of documents? Consider carefully what you share and who you share documents with.

      References:


      Remember - "A day without laughter is a day wasted."

      May the wind sing to you and the sun rise in your heart...

      Sunday, October 12, 2008

      Cyber Security Awareness Tip of the Day: October 12

      The tip today is from a sharp-shooting friend, Winchester73. Even though Winchester73 provides help at Freedomlist too, his primary "home" is LandzDown. So, I'll credit LandzDown Forum for this tip.

      October 12 Tip of the Day

      Have you read before you clicked?

      I hope most people now recognize the "Nigerian Scams" or Advanced-Fee Fraud and if they don't make it to the spam folder, those emails are promptly deleted. (If you didn't take the SonicWALL Phishing and Spam IQ Quiz from the October 4 Tip of the Day, give it a try now.)

      Reading before you click also applies to links on web pages. Mouse over the link to be sure it is going to the expected site. Before purchasing that one size fits all, must have cure- and fix-all tool that promises to cure the common cold, do some research about the product.

      Check the "Better Business Bureau" or Ripoff Report and read before you click!








      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Saturday, May 12, 2007

      Windows Vista Search

      I started writing this the other day when Nick White posted the first segment in the Windows Vista Team Blog highlighting advanced searching in Windows Vista. Knowing he was going to add another part to the piece, I held off publishing.

      Now that Part II has been posted, below is a brief synopsis of
      Putting advanced searches to work for you and Searching, part II: Using Search Folders along with additional links collected.

      All links have been bookmarked in Features and Tutorials.

      Search
      • Explorers (Microsoft)
        In the new Explorers, the menus, toolbars, Navigation Pane, Task Pane, and Preview Pane have all merged into a single intuitive interface that's consistent across all of Windows Vista.
      • Using Search Folders (Advanced Search) (MSDN Blog)
        Examples of using Search Folders. Be sure to read the additional information in the comments.

      Friday, December 15, 2006

      Google Patent Search

      (Click the image to open site in a new tab/window)


      Spotted this addition to Google's latest search "portfolio" over at SunbeltBLOG. Having worked with people in the Patent area for many years, I am sure they will find this interesting.

      By the way, Patent Friends, Garett Rogers at ZD Net would like to know if Google Patents will make the job easier for patent lawyers. Apparently he doesn't realize that (1) the patent lawyers rely on someone else to obtain the patent copies and (2) there has been services for obtaining patent copies for many years, some free while others are fee-based.

      One nice feature I observed is that it is easy to copy/paste the text from the patents in Google Patent. That will at least make it easier when quoting portions of patents the "Description of the Prior Art".

      This is what a friend who has "been in the business" for many years had to say about Google Patent:
      "Interesting. Nice search page. Nothing "new and improved" though."
      It doesn't sound as though Google should bother running to the USPTO with this feature.