Friday, September 30, 2011

Mozilla Firefox 7.0.1 Released to Fix Missing Add-On Problem

The rapid release path for Firefox version updates did not run all that smoothly for Version 7.  After updating to Version 7, there were instances in which users discovered one or more of their add-ons were hidden.  As a result, the release of the new updates to Firefox Version 7 was paused in order to minimize the impact.

An update fixing the issue has been released.  To get the update now, select Help, About Firefox, Check for Updates.

Also available now is the list of vulnerabilities that were fixed in Version 7.

Fixed in Firefox 7

MFSA 2011-45 Inferring Keystrokes from motion data
MFSA 2011-44 Use after free reading OGG headers
MFSA 2011-43 loadSubScript unwraps XPCNativeWrapper scope parameter
MFSA 2011-42 Potentially exploitable crash in the YARR regular expression library
MFSA 2011-41 Potentially exploitable WebGL crashes
MFSA 2011-40 Code installation through holding down Enter
MFSA 2011-39 Defense against multiple Location headers due to CRLF Injection
MFSA 2011-36 Miscellaneous memory safety hazards (rv:7.0 / rv:1.9.2.23)

References



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, September 27, 2011

Mozilla Firefox 7 Released, Includes Security Updates


In keeping with the rapid release schedule, Mozilla released Firefox 7 today.

As expected when a version update is released, you may find that many of your favorite add-ons are not compatible with the new release.  Use Add-on Compatibility Reporter to test and report on your favorite add-ons in version 7.

The Release Notes listed the following new features in version 7,  At this point the indicated security updates are not listed in the Security Advisories.  There is, however, a very lengthy list of Bug Fixes for version 7.

What's New

  • Drastically improved memory handling for certain use cases
  • Added a new rendering backend to speed up Canvas operations on Windows systems
  • Bookmark and password changes now sync almost instantly when using Firefox Sync
  • The 'http://' URL prefix is now hidden by default
  • Added support for text-overflow: ellipsis
  • Added support for the Web Timing specification
  • Enhanced support for MathML
  • The WebSocket protocol has been updated from version 7 to version 8
  • Added an opt-in system for users to send performance data back to Mozilla to improve future versions of Firefox
  • Fixed several stability issues
  • Fixed several security issues

The upgrade to Firefox 7 will be offered through the browser update mechanism.  However, as the upgrade includes critical security updates, it is recommended that the update be applied as soon as possible.  To get the update now, select Help, About Firefox, Check for Updates.

References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Wednesday, September 21, 2011

Microsoft Removes Gold Certified Partner Over Telephone Scam Claims

As illustrated in this topic on the Microsoft Answers forum, the issue of fake tech support telephone calls has been a problem for over two years.  The scams appeared to have originated in the U.K., spread to Australia, followed by Canada and the United States.

Although reports in various forum topics have pointed fingers at other vendors, in the instant case, the finger was pointing at "Comantra" who was a Microsoft Gold Certified Partner. 

Comantra, like other vendors, was said to have cold-called people, implying that they represent Microsoft.  After convincing the call recipients that the errors seen in Event Viewer on Windows are dangerous, the technicians would attempt to convince the people to allow the technicians to have remote access to their computer.  Repairs, of course, required a credit card charge.

About Microsoft Gold Certified and Certified Partners

It is important to understand that being a Microsoft Partner, in any shape, whether Certified or Gold Certified, does not mean that the company represents Microsoft.  Rather, it merely means that the company has met the requisite requirements, has paid the requisite fee and has earned the appropriate Partner Points for the Partner level.  The requirements for both Microsoft Gold Certified and Microsoft Certified Partners are fully described at the eHow.com references below.

In addition to the above, Microsoft Gold Certified Partners must employ a minimum number of Microsoft certified professionals, meet the certification and sales requirements and submit competency-specific customer referrals.

Microsoft Certified Partners additionally complete one of three requirements (i.e. employ or employ by contract at least two Microsoft Certified Professionals, with three customer references approved by Microsoft or product software that Microsoft has tested and approved or hardware that a Microsoft authorized testing vendor has approved.)

How to handle telephone scams

If you receive a call from someone claiming to be representing Microsoft or Microsoft tech support, just hang up!  Microsoft does not make unsolicited calls.

In the event you have been taken in by one of the fake tech support calls, it is strongly recommended that you take the following steps:
  • Change the passwords or PINs on your computer and your online accounts.
  • Place a fraud alert on your credit reports.
  • If you know of any accounts that were accessed or opened fraudulently, close those accounts.
  • Routinely review your bank and credit card statements monthly for unexplained charges or inquiries that were not initiated by you.

People in Australia, Canada, U.K. and U.S. appear to have been hardest hit by telephone tech support scams.  The links below have additional information and resources.

References


Microsoft References


History


Articles illustrative of the on-going telephone scam problem:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...