Microsoft has updated a free tool it is offering Windows users enabling them to identify and remove infections produced by a specific list of malware in order to tackle some malicious code samples that have become associated with exploits for a recently patched Windows Critical zero-day vulnerability.
A new version of the Malicious Software Removal Tool is now available for download from the Redmond company.
The malware tackled by the latest release of MSRT has already been used by attackers in the wild in exploits targeting the now notorious Windows .LNK security flaw. “Threats like Stuxnet, Vobfus, and Sality (…) have incorporated the use of the CVE-2010-2568 vulnerability fixed by the MS10-046 bulletin,” revealed Scott Wu, from the Microsoft Malware Protection Center.
“It’s clear that an increasing number of malware families are incorporating this vulnerability. Today’s MSRT release represents another step Microsoft is taking to cleanse the ecosystem of this infection vector,” Wu added.
The latest version of the Malicious Software Removal Tool has been released through Windows Update, but users can also get the tool as a standalone download. MSRT has always been available through the Microsoft Download Center, and the August 2010 update is no exception to this rule.
“We highly encourage our readers to apply all security updates to protect themselves from this and other vulnerabilities,” Wu recommended.
At the start of August 2010, the Redmond company released an out-of-band patch resolving the .LNK vulnerability. Not only was the security flaw Critical in itself but it was also being actively exploited in the wild.
“One of the threats using this vulnerability that we recently discussed is Sality. It is a virus (a.k.a file infector) and has the potential to infect many files on your computer, making the disinfection tricky and time consuming, since in many cases it must repair, not simply delete, the troubled files. Recall that MSRT is a “cleanup” tool. It does not provide Real-time protection,” Wu said.
Microsoft also provided a list with the specific malware samples tackled by MSRT following the August 2010 update:
Win32/StuxnetWin32/CplLnk Worm:Win32/Vobfus.gen!A Worm:Win32/Vobfus.gen!B Worm:Win32/Vobfus.gen!C Worm:Win32/Vobfus!dll Worm:Win32/Sality.AU Virus:Win32/Sality.AU TrojanDropper:Win32/Sality.AU
The Malicious Software Removal Tool is available for download here.
Microsoft Security Essentials is available for download here.
Source
Microsoft Warns of Attacks Targeting the Windows Service Isolation Feature
Microsoft has issued a Security Advisory designed to inform customers of the potential attacks targeting the Windows Service Isolation, a feature which is included into all supported Windows operating systems, including Windows 7 and Windows Server 2008 R2.
According to the Redmond company, a problem has been identified in the manner in which the NetworkService token can be received and leveraged in association with RPC calls, via the Windows Telephony Application Programming Interfaces (TAPI) transaction facility.
Microsoft insists that this issue does not require a security bulletin to be patched, and that customers can already access an update that will bulletproof their systems against attacks.
“Although this is not a vulnerability that requires a security update to be issued, an attacker could elevate from NetworkService to LocalSystem using the TAPI service, which runs as system,” Microsoft stated.
“An attacker must already be running with elevated privileges to exploit this issue. This service isolation was implemented as a defense-in-depth measure only and does not constitute a security boundary,” the company explained.
Evidently, customers running systems with Windows Telephony Application Programming Interfaces (TAPI) are most at risk from attacks attempting to exploit this flaw.
In this regard, they should turn to Microsoft Security Advisory (2264072) in order to gain additional information about the threat, but also get details on mitigating factors and workarounds.
At this point in time the non-security update for the Windows Telephony Application Programming Interfaces (TAPI) Vulnerability (CVE-2010-1886) is already available on the Microsoft Download Center.
“This issue affects scenarios where untrusted code is being executed within a process owned by the NetworkService account,” Microsoft said.
“In these scenarios, it is possible for an attacker to elevate from running processes as the NetworkService account to running processes as the LocalSystem account on a target server,” the company added.
“An attacker who successfully elevated to running processes as the LocalSystem account could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” the software giant said.
Source
According to the Redmond company, a problem has been identified in the manner in which the NetworkService token can be received and leveraged in association with RPC calls, via the Windows Telephony Application Programming Interfaces (TAPI) transaction facility.
Microsoft insists that this issue does not require a security bulletin to be patched, and that customers can already access an update that will bulletproof their systems against attacks.
“Although this is not a vulnerability that requires a security update to be issued, an attacker could elevate from NetworkService to LocalSystem using the TAPI service, which runs as system,” Microsoft stated.
“An attacker must already be running with elevated privileges to exploit this issue. This service isolation was implemented as a defense-in-depth measure only and does not constitute a security boundary,” the company explained.
Evidently, customers running systems with Windows Telephony Application Programming Interfaces (TAPI) are most at risk from attacks attempting to exploit this flaw.
In this regard, they should turn to Microsoft Security Advisory (2264072) in order to gain additional information about the threat, but also get details on mitigating factors and workarounds.
At this point in time the non-security update for the Windows Telephony Application Programming Interfaces (TAPI) Vulnerability (CVE-2010-1886) is already available on the Microsoft Download Center.
“This issue affects scenarios where untrusted code is being executed within a process owned by the NetworkService account,” Microsoft said.
“In these scenarios, it is possible for an attacker to elevate from running processes as the NetworkService account to running processes as the LocalSystem account on a target server,” the company added.
“An attacker who successfully elevated to running processes as the LocalSystem account could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” the software giant said.
Source
Google rumored to buy virtual currency start-up
A report Monday on TechCrunch suggests that, complementing its purchase last week of social-app manufacturer Slide, Google has made another social-networking buy: a virtual currency software company called Jambool. The start-up manufactures a product called Social Gold, which lets other sites build virtual-currency infrastructures.
A smaller purchase than Slide, TechCrunch put the price tag at about $70 million. Representatives from Jambool were not immediately available for comment.
Jambool's Social Gold was one of a number of virtual-currency start-ups that rose in the time in between the launch of Facebook's developer platform and its unveiling of its own transaction system, Facebook Credits. With Facebook now expanding the Credits system and potentially snuffing out third-party virtual-currency providers--it's been gradually winning over the most powerful social-game manufacturers on its developer platform--many of those start-ups are undoubtedly hunting for exit strategies.
Jambool's executive team had been openly critical of Facebook's e-commerce ambitions in the past.
Google runs its own PayPal-like transaction platform, Google Checkout, and may have been looking for a virtual-currency system to complement it. The tech giant, in the midst of cobbling together a social-media arsenal that won't flop like several of its past social-media projectsthe biggest social-gaming company, and may or may not be working on a full-fledged gaming product of its own. have, is rumored to be fine-tuning that strategy toward social gaming, one of the biggest runaway successes to emerge on Facebook. It's invested a hefty amount in Zynga,
Source
A smaller purchase than Slide, TechCrunch put the price tag at about $70 million. Representatives from Jambool were not immediately available for comment.
Jambool's Social Gold was one of a number of virtual-currency start-ups that rose in the time in between the launch of Facebook's developer platform and its unveiling of its own transaction system, Facebook Credits. With Facebook now expanding the Credits system and potentially snuffing out third-party virtual-currency providers--it's been gradually winning over the most powerful social-game manufacturers on its developer platform--many of those start-ups are undoubtedly hunting for exit strategies.
Jambool's executive team had been openly critical of Facebook's e-commerce ambitions in the past.
Google runs its own PayPal-like transaction platform, Google Checkout, and may have been looking for a virtual-currency system to complement it. The tech giant, in the midst of cobbling together a social-media arsenal that won't flop like several of its past social-media projectsthe biggest social-gaming company, and may or may not be working on a full-fledged gaming product of its own. have, is rumored to be fine-tuning that strategy toward social gaming, one of the biggest runaway successes to emerge on Facebook. It's invested a hefty amount in Zynga,
Source
Sandboxie 3.48
Introducing Sandboxie
Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer. Benefits of the Isolated Sandbox
- Secure Web Browsing: Running your Web browser under the protection of Sandboxie means that all malicious software downloaded by the browser is trapped in the sandbox and can be discarded trivially.
- Enhanced Privacy: Browsing history, cookies, and cached temporary files collected while Web browsing stay in the sandbox and don't leak into Windows.
- Secure E-mail: Viruses and other malicious software that might be hiding in your email can't break out of the sandbox and can't infect your real system.
- Windows Stays Lean: Prevent wear-and-tear in Windows by installing software into an isolated sandbox.
Download : Sandboxie 3.48
The Verizon iPhone Rumor Mill Keeps Churning
So you want an iPhone but you don't want to use AT&T as a service provider. It's an old story...almost as old as the iPhone itself. We've heard again and again that AT&T's exclusivity agreement with Apple was about to run out, but so far it hasn't. Well here's another rumor saying the same thing. Actually two rumors that mesh together pretty well.

First up, leaks from the hardware front. TechCrunch's Steve Cheney reports that Apple has ordered "millions of units of Qualcomm CDMA chipsets." Why is this significant? Because AT&T's network uses GSM, not CDMA, so presumably Apple is building iPhones for a network other than AT&T's. The leap to Verizon seems to be one of faith for Cheney, who says the Verizon iPhone will hit in January, but there are a lot of cellular providers around the world. How does Cheney know these chips are going into Verizon phones?
[ Get news and reviews on tech toys in ITworld's personal tech newsletter]
Well, luckily for him, we've got another data point to work with. This one comes from Electronista who reports on an AT&T SEC filing. The filing, Electronista points out, devotes "a significant section of its warnings to the risks that occur when 'exclusivity arrangements end' and tried to minimize the potential effect." The filing doesn't single out the iPhone but let's face it, their deal with Apple is the only really significant exclusivity arrangement AT&T has. (You can read the whole SEC Filing here.)
So putting the pieces together: Apple is building a CDMA device. AT&T is downplaying the loss of an unspecified exclusivity deal, implying the iPhone is going to be available on another carrier here in the U.S. Since Sprint and Verizon both use CDMA we still can't be sure which of the two carriers the new device is headed for (maybe both?) but given the relative size of the two it's a safe bet that Apple would be most interested in partnering with Verizon.
So why is Apple severing its exclusive ties with AT&T now? If I had to speculate, I'd say Android is the main reason. We keep seeing huge numbers posted for Android devices (the most recent being that 200,000 Android devices/day are being activated). Can Apple afford to restrict itself to one carrier in the face of dozens of Android phones across several carriers, including AT&T? Sooner or later Android is going to hit enough of a critical mass that app developers are going to start switching teams, and without the App Store much of the magic of the iPhone vanishes.
We've heard this rumor a lot of times and so far nothing has come of it. Let's hope this time out things are different.
Source
First up, leaks from the hardware front. TechCrunch's Steve Cheney reports that Apple has ordered "millions of units of Qualcomm CDMA chipsets." Why is this significant? Because AT&T's network uses GSM, not CDMA, so presumably Apple is building iPhones for a network other than AT&T's. The leap to Verizon seems to be one of faith for Cheney, who says the Verizon iPhone will hit in January, but there are a lot of cellular providers around the world. How does Cheney know these chips are going into Verizon phones?
[ Get news and reviews on tech toys in ITworld's personal tech newsletter]
Well, luckily for him, we've got another data point to work with. This one comes from Electronista who reports on an AT&T SEC filing. The filing, Electronista points out, devotes "a significant section of its warnings to the risks that occur when 'exclusivity arrangements end' and tried to minimize the potential effect." The filing doesn't single out the iPhone but let's face it, their deal with Apple is the only really significant exclusivity arrangement AT&T has. (You can read the whole SEC Filing here.)
So putting the pieces together: Apple is building a CDMA device. AT&T is downplaying the loss of an unspecified exclusivity deal, implying the iPhone is going to be available on another carrier here in the U.S. Since Sprint and Verizon both use CDMA we still can't be sure which of the two carriers the new device is headed for (maybe both?) but given the relative size of the two it's a safe bet that Apple would be most interested in partnering with Verizon.
So why is Apple severing its exclusive ties with AT&T now? If I had to speculate, I'd say Android is the main reason. We keep seeing huge numbers posted for Android devices (the most recent being that 200,000 Android devices/day are being activated). Can Apple afford to restrict itself to one carrier in the face of dozens of Android phones across several carriers, including AT&T? Sooner or later Android is going to hit enough of a critical mass that app developers are going to start switching teams, and without the App Store much of the magic of the iPhone vanishes.
We've heard this rumor a lot of times and so far nothing has come of it. Let's hope this time out things are different.
Source
Flash for iPhone Now Available, Thanks to Jailbreak
Adobe's Flash technology is now available for iOS devices, thanks to a new application for jailbroken iPhones and iPads. Coming from Comex, the same man who developed the browser-based JailbreakMe tool, Frash lets iPhone users view Adobe Flash content on their phones.
Frash is in its very early stages, and works with the iPhone 4, 3GS (with iOS4), third-generation iPod Touch, and iPads with the latest software (3.2.X), the developer says. To install Frash, you will also need to jailbreak your device, which can be done easily with the new Web browser-based JailbreakMe tool released last week.
Once you have jailbroken your iOS device and installed Frash (RedmondPie.com has a simple step-by-step guide), you can view Adobe Flash in Mobile Safari. Not all Flash content will work though. Frash is in the early development stages (version 0.02), so only basic Flash animations will display, mainly advertisements. Here's a video showing Frash in action on an iPhone 4.
Apple's relationship with Adobe's Flash technology on the iPhone was bumpy from the beginning. The company refused to include the technology into its mobile devices, saying that it would cripple the experience and battery life. Apple CEO Steve Jobs also explained at length in a public letter his reasons to sideline Adobe's technology.
Some iPhone users were not happy with Job's decision, and looked into getting flash on their iOS devices. Comex's Frash should keep those users happy momentarily, until a better version of the software is developed.
As for jailbreaking, the procedure came into legality two weeks ago, when the U.S. Copyright Office ruled it as an exemption of the Digital Millennium Copyright Act (DMCA). However, Apple doesn't agree with jailbreaking, and says that the procedure will void the warranty of your iOS device, meaning no free repairs in case something goes wrong. To fix that, you can always use the Restore option in iTunes.
Source
Expert: Apple is 10 years behind Microsoft in handling vulnerabilities and security issues
Attacks on Mac OS X will increase, as the threat landscape will shift away from Windows and focus on platforms that have a smaller market share, believes one of the top security experts from AVAST Software, Ondrej Vlcek CTO AVAST Software.
“I think we will be seeing more and more attacks towards Mac. Of course, it’s still a minor platform in terms of market share, currently estimated to be between 6% and 7%, compared to something like 92% or 93% for Windows. For attackers it’s much easier to focus on 90+%, but that’s changing; the market share is growing all the time,” Vlcek said.
More importantly, Vlcek noted while speaking to Softpedia, that Apple has some issues in the way it deals with the security of Mac OS X. Essentially, AVAST’s CTO revealed that Apple is now where Microsoft used to be a decade ago in terms of how the Cupertino-based company tackles vulnerabilities.
“And also as the platform is getting more popular it’s quite evident that there are a lot problems in the security of the Mac OS in general. What I mean is that Apple’s approach towards security vulnerabilities is not very fortunate. It somehow reminds me of Microsoft’s style from maybe eight, ten years ago,” he added.
AT&T's Samsung A927 Flight shows up before its premiere
The QWERTY-enabled Samsung A927 Flight II has made its way to both Samsung's and AT&T's websites even it hasn't been properly announced yet. Apparently, its premiere is just around the corner so we will get a chance to see it in flesh pretty soon.
Heavy texters will be glad to see the Samsung A927 Flight II hardware four-row side-slide QWERTY keyboard. In addition, the newbie also packs a 3-inch touchscreen of WQVGA resolution (240 x 400 pixels).
Samsung A927 Flight II
Also on board there is a 2-megapixel fixed-focus snapper which is capable of taking videos as well and a standard 3.5mm audio jack ready to accommodate your favorite headphones' plug. Thanks to the microSD card slot you can expand the inbuilt memory (of 512MB) with up to 16GB.
The phone is said to support AT&T's Mobile TV service and on top of that you get quick access to some of the most popular social networking services (such as Facebook and Twitter).
The unannounced Samsung A927 Flight II was spotted on both Samsung USA's (overview and specs sheet) AT&T's websites, however, there is still no word on the QWERTY-fied phone's official launch date or price.
Source
Google Nexus One now available, yet again, for Android devs only
If you couldn't manage to get yourself a Google Nexus One and still want to give it a try, today might be your lucky day. You only need to be a registered Android developer and to have some 529 US dollars in the piggy bank.
As you might have heard, a little while ago Google stopped selling its first own Android-running device online so from that moment on your only option for becoming an owner of the HTC-made Google Nexus One were Google's partners (operators and retailers).
Official photos of HTC Google Nexus One
But if there aren't any of those in your neighborhood, you can now go for another option: as of yesterday the Google Nexus One can be purchased from the Android Developers website since the Nexus One has just become the new Android Developer Phones (replacing the elderly ADP 2).
In order to take advantage of that new option, though, you have to be a registered Android developer. If you happen to be one, just log into your Android Developer account and follow the "Development Phones" link. By the way, the Android Developers' Nexus Ones come with the Android 2.1 on board but the ver. 2.2 update is just a few taps away.
The phones sold over there are factory unlocked (and probably rooted) and are priced at 529 US dollars (around 400 euro, so, no news here).
Source
McAfee AVERT Stinger 10.0.1.995
Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system. Stinger utilizes next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations.
How do I use Stinger?
- Download v10.1.0.995 [MD5: 4E9FA54852013EF44DE069214C839704, Build Nr: 10.1.0.995] (08/05/2010)
- When the download is complete, navigate to the folder that contains the downloaded Stinger file, and run it.
- The Stinger interface will be displayed.
- If necessary, click the Add or Browse button to add additional drives/directories to scan. By default the C: drive will be scanned.
- Click the Scan Now button to begin scanning the specified drives/directories.
- By default, Stinger will repair all infected files found.
- To enable Artemis Technology in stinger click on preferences and then select the required sensitivity level. If you select "High" or "Very High" McAfee Labs recommends that you set the "On virus detection" action to "Report only" for the first scan.
Detects and removes threats identified under the "List Viruses" icon in the Stinger application.
To enable Artemis Technology in stinger click on preferences and then select the required sensitivity level. If you select "High" or "Very High" McAfee Labs recommends that you set the "On virus detection" action to "Report only" for the first scan.
Download v10.1.0.995
How do I use Stinger?
- Download v10.1.0.995 [MD5: 4E9FA54852013EF44DE069214C839704, Build Nr: 10.1.0.995] (08/05/2010)- When the download is complete, navigate to the folder that contains the downloaded Stinger file, and run it.
- The Stinger interface will be displayed.
- If necessary, click the Add or Browse button to add additional drives/directories to scan. By default the C: drive will be scanned.
- Click the Scan Now button to begin scanning the specified drives/directories.
- By default, Stinger will repair all infected files found.
- To enable Artemis Technology in stinger click on preferences and then select the required sensitivity level. If you select "High" or "Very High" McAfee Labs recommends that you set the "On virus detection" action to "Report only" for the first scan.
Detects and removes threats identified under the "List Viruses" icon in the Stinger application.
To enable Artemis Technology in stinger click on preferences and then select the required sensitivity level. If you select "High" or "Very High" McAfee Labs recommends that you set the "On virus detection" action to "Report only" for the first scan.
Download v10.1.0.995
Subscribe to:
Posts (Atom)