Wednesday, August 09, 2006

This Call's For You, WGA Team!

It appears that a recent call to Microsoft's Windows Genuine Advantage (WGA) has been missed.

In Ed Bott's report of "Another WGA Failure", he indicates that he was working with his Microsoft contacts to obtain a pirated Volume License Key (VLK). His purpose in doing this was to provide a report of what a user would experience if they had a "non-Genuine" Windows key. When the Microsoft-provided license key was unsuccessful installing, Ed reports that in about fifteen minutes he located a bunch leaked VLK's through a Google search . Reportedly, those keys have been publicly posted for almost two years!

So, with keys in hand, he figured he was golden and would achieve his goal of providing his readers with the messages they would receive with pirated or illegal VLKs. The problem, however, is that the keys did NOT fail the WGA test. In fact, the passed over and over.

I am sure the WGA Team is working very hard to iron out any problems with the WGA software. In the meantime, if you run into difficulties with the WGA tool, you can learn more at the Genuine Microsoft Software website. Help is available at the Microsoft WGA help forum, "Speak to Us at Microsoft!"

Trackback

Tuesday, August 08, 2006

Patch Time!


It is Patch Tuesday and Microsoft has released the security bulletins identified below. Please see Nellie2's instructions on "How to Prepare for Patch Tuesday" and update ASAP.

MS06-040 - Vulnerability in Server Service Could Allow Remote Code Execution (921883) (Note: Addresses a critical security problem)

MS06-041 - Vulnerability in DNS Resolution Could Allow Remote Code Execution (920683)

MS06-042 - Cumulative Security Update for Internet Explorer (918899)

MS06-043 - Vulnerability in Microsoft Windows Could Allow Remote Code Execution (920214)

MS06-044 - Vulnerability in Microsoft Management Console Could Allow Remote Code Execution (917008)

MS06-045 - Vulnerability in Windows Explorer Could Allow Remote Code Execution (921398)

MS06-046 - Vulnerability in HTML Help Could Allow Remote Code Execution (922616)

MS06-047 - Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (921645)

MS06-048 - Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922968)

MS06-049 - Vulnerability in Windows Kernel Could Result in Elevation of Privilege (920958)

MS06-050 - Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution (920670)

MS06-051 - Vulnerability in Windows Kernel Could Result in Remote Code Execution (917422)


View the summary and all the details here

Saturday, August 05, 2006

Garden Certificate Warnings

This discussion of Certificates started with "Garden Certificate Basics", which included background information about digital certificates as well as a sample of a "domain name mismatch". In that situation, it was apparent that a site was providing bogus information.

"Garden Certificate - Microsoft MVP Site" included an illustrated examination of digital certificate information provided to a reader of this blog. The certificate was received as a result of the MS MVP link in an earlier blog post here.

I was reminded today by a respected member of Freedomlist that there are circumstances where an unsigned certificate should not be accepted.
"Anyone can create a certificate that will show mvp.support.microsoft.com or anything they want in the cname and in the hierarchy. Checking those fields doesn't tell you anything particularly useful about the certificate or the website.

I'm afraid advice to accept the certificate is likely to give people the impression that the site is what it claims to be. That's fine for a site like mvp.support.microsoft.com where you just read their pages and don't send them any information, but people should absolutely never accept an unsigned certificate for a site that needs sensitive information like online-banking or shopping, because there is no way to know whether the webserver at the other end is really their bank or store, or if it is some random person spoofing the site and trying to get their data.

A simple summary:
A certificate signed by a certificate authority (verisign, for example) protects against eavesdropping and confirms the identity of the site.

An unsigned certificate (like the one at mvp.support.microsoft.com) protects against eavesdropping, but does NOT confirm the identity of the site."

Thank you, digger, for the explanation and excellent advice!

Additional reference information:

VeriSign Described
VeriSign.com
Digital Certificate Defined
Public Key Certificate