Thursday, October 28, 2010

Critical Zero-Day, Adobe Products Security Advisory

Yet again we are faced with another critical security advisory for Adobe products.  This time the vulnerability affects Adobe Flash Player, Adobe Reader and Adobe Acrobat.  From the Adobe Security Advisory:
"This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player."
As described at The Register, the Adobe Reader/Acrobat exploit can install a backdoor trojan known as Wisp, which steals sensitive data and installs a backdoor on compromised systems. The vulnerability in Adobe's Flash Player drops two malicious binaries onto Windows machines that open the document files.

Adobe provided mitigations for all platforms of Adobe Reader/Acrobat customers in the Security Advisory.  Personally, I prefer to use an alternate PDF reader and have been satisfied with the performance of Sumatra PDF.


Mitigations for Windows users:
"Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains Flash (SWF) content.

The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat."

Updates:

An update for Adobe Flash Player is expected by November 9, 2010.  Adobe Reader and Acrobat 9.4 are expected to be updated during the week of November 15, 2010.



References:

Critical zero-day vulnerability found in Adobe Flash, Reader, Acrobat
Security Advisory (APSA10-05)
PSIRT Blog: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (APSA10-05)
MMPC Encyclopedia: Trojan:Win32/Wisp

Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, October 27, 2010

Windows Live Essentials 2011 Data Collection

I was rather surprised when the message below rolled up in front of my browser window today. 


Apparently, after installing Windows Live Essentials or the Bing Bar, you will be asked if you want to help Microsoft improve their products.  Strange that I just got the pop-up today.  I have had the Windows Live Essentials on this computer for some time and the Bing Bar was on, off, back on, off, again.

From the "Learn More" link, I discovered that the purpose is to improve Windows Live and the Bing Bar.  If you see this "pop-up" it is very important to note a few important points:

  • Participation is complete voluntary. you can uncheck one, two or all three options.
  • No data will be collected without your agreement to participate (leave the last box checked).
  • All collected data is confidential.

What if you decide to opt-out after you agreed to the data collection?  You can change the setting for Windows Live Essentials by changing the "Help improve Windows Live" setting in the options of any Windows Live program.

Follow the steps below to stop participating in the Bing Bar program:
  1. Launch your browser.
  2. On the right side of Bing Bar, click the Toolbar options button Toolbar options.
  3. Click Quality, select No, I don't want to participate, and then click OK.
References:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Mozilla Firefox 3.6.12 Critical Update to Address Zero-Day


It was just yesterday that Mozilla reported a Critical vulnerability in Firefox 3.5 and Firefox 3.6.  As of this posting, although the release notes for Firefox version 3.6.12 are live, the update is not yet available on the servers.  (Edit Note:  The update is available now.)

Firefox users are advised to follow the instructions below from the Mozilla advisory to disable Javascript and install NoScript.
"Issue:
Mozilla is aware of a critical vulnerability affecting Firefox 3.5 and Firefox 3.6 users. We have received reports from several security research firms that exploit code leveraging this vulnerability has been detected in the wild.
Impact to users:
Users who visited an infected site could have been affected by the malware through the vulnerability. The trojan was initially reported as live on the Nobel Peace Prize site, and that specific site is now being blocked by Firefox’s built-in malware protection. However, the exploit code could still be live on other websites.

Status:
We have diagnosed the issue and are currently developing a fix, which will be pushed out to Firefox users as soon as the fix has been properly tested.

In the meantime, users can protect themselves by doing either of the following:

To manually check for the update, click Help and Check for Updates.


References:


Clubhouse Tags: Clubhouse, Security, Updates, Information







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...