Monday, May 12, 2008

Windows Vista and Malware

Is Windows Vista more susceptible to malware than Windows 2000? I do not believe that it is and neither does Austin Wilson and members of the Microsoft security team. Austin explains why Microsoft rejects that claim in Windows Vista and Malware.

Based on what I see in the forums, most of the malware infections are due to computers that are not properly updated -- and this is not limited to Microsoft software. It is very common to see out of date, vulnerable versions of Sun Java and/or Adobe software.

To check if your system is missing security updates or has insecure applications installed, visit Secunia Software Inspector. The Secunia Software Inspector runs through your browser with no installation or download required and does the following:

  • Detects insecure versions of applications installed
  • Verifies that all Microsoft patches are applied
  • Assists you in updating your system and applications

Then, take Austin's advice and
"follow the Protect Your PC guidance of keeping the firewall turned on, keeping the operating system up to date, and having up to date anti-virus and anti-spyware software."




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, May 08, 2008

May 2008 - Microsoft Security Bulletin Advance Notice

In addition to an updated version of the Microsoft Windows Malicious Software Removal Tool, Microsoft is planning to release four new security bulletins on May 13, 2008 -- three critical and one moderate.

Two of the critical updates are to fix remote code execution vulnerabilities in Microsoft Office. The third critical update is Jet Bulletin in Microsoft Windows. For complete information see the Affected Software section of the Advanced Notification.

References:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, May 07, 2008

Compromised file in Vietnamese Language Pack for Firefox 2

Just released on the Mozilla Security Blog:

"The Vietnamese language pack for Firefox 2 contains inserted code to load remote content. This code is the result of a virus infection, but does not contain the virus itself. This usually results in the user seeing unwanted ads, but may be used for more malicious actions.

Everyone who downloaded the most recent Vietnamese language pack since February 18, 2008 got an infected copy. While we cannot determine the exact number of compromised downloads, there have been 16,667 total downloads of the Vietnamese language pack since November 2007, so we anticipate the impact on users to be limited.

Mozilla does virus scans at upload time but the virus scanner did not catch this issue until several months after the upload. We are also adding after-the-fact scans of everything to address this sort of case in the future.

A new language pack will be available shortly. Until then, Vietnamese language pack users should disable this package using the add-ons dialog on the Tools menu.

More information is available in bugzilla: https://bugzilla.mozilla.org/show_bug.cgi?id=432406"






Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...