Microsoft will distribute Internet Explorer 7 as a high-priority update via Automatic Updates soon after the final version is released for Windows XP, planned for the fourth quarter of 2006.
/Gill
Friday, July 28, 2006
Sunday, July 16, 2006
Hands On: How to Install Windows Vista Beta
July 12, 2006 (Computerworld) -- Microsoft last month made Windows Vista Beta 2 publicly available for download or delivery on DVD via its Windows Vista Consumer Preview Program (CPP). The CPP closed to new registrations on June 30, and it appears Microsoft will not reopen it when Vista Release Candidate 1 arrives, but all registered CPP users will be offered RC1 as well.
What's the best way to install and test Windows Vista? There are three main ways to do so gracefully. There are also one or two tricks of the trade.
Read the rest of the guide..
What's the best way to install and test Windows Vista? There are three main ways to do so gracefully. There are also one or two tricks of the trade.
Read the rest of the guide..
Saturday, July 15, 2006
Phishing Attack Defeats Two-Factor Authentication
from: The SANS Institute [NewsBites@sans.org]
(13 & 10 July 2006)
Phishers are targeting Citibank Citibusiness customers using a man-in-the-middle attack to exploit people's trust in two-factor authentication. The scheme, if successful, would provide the phishers with Citibank Citibusiness customers' names and passwords in addition to temporary passwords generated by security tokens. The scheme passes on the customers' entered information to the legitimate site to see if it authentic. In a real-time attack scenario, the temporary passwords could be used before they expire. The phony site has reportedly been shut down.
http://www.vnunet.com/vnunet/news/2160250/phishers-crack-two-factor
http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs_2factor_1.html
(13 & 10 July 2006)
Phishers are targeting Citibank Citibusiness customers using a man-in-the-middle attack to exploit people's trust in two-factor authentication. The scheme, if successful, would provide the phishers with Citibank Citibusiness customers' names and passwords in addition to temporary passwords generated by security tokens. The scheme passes on the customers' entered information to the legitimate site to see if it authentic. In a real-time attack scenario, the temporary passwords could be used before they expire. The phony site has reportedly been shut down.
http://www.vnunet.com/vnunet/news/2160250/phishers-crack-two-factor
http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs_2factor_1.html
Legendary hacker and author Kevin Mitnick has produced a whitepaper
Legendary hacker and author Kevin Mitnick has produced a whitepaper in which he details several scenarios in which social engineering exposed significant vulnerabilities that lead to corporate attacks.
People who have read Kevin's books and who like his style of writing will also enjoy the paper. What I find most valuable about this paper is that Mitnick remains neutral in his approach when he outlines his "Best Practices" approach to protection. He does a thorough analysis of various techniques and methodologies for mitigating risk and locking down endpoints, while allowing users enough flexibility to perform their jobs.
People can download the whitepaper in PDF format from www.appsense.com/mitnick
It's a good read, I would recommend it for anyone security inclined even if you just download it and save it for a rainy day :o)
resource:security-basics@securityfocus.com
People who have read Kevin's books and who like his style of writing will also enjoy the paper. What I find most valuable about this paper is that Mitnick remains neutral in his approach when he outlines his "Best Practices" approach to protection. He does a thorough analysis of various techniques and methodologies for mitigating risk and locking down endpoints, while allowing users enough flexibility to perform their jobs.
People can download the whitepaper in PDF format from www.appsense.com/mitnick
It's a good read, I would recommend it for anyone security inclined even if you just download it and save it for a rainy day :o)
resource:security-basics@securityfocus.com
Saturday, July 08, 2006
The Depressing State Of Computer Security
From WServerNews.com newsletter.
Perhaps you know Roger Grimes. He's an InfoWorld Test Center Contributing Editor, Writes for WinITPro Mag, and is a Foundstone Ultimate Hacking instructor/consultant teaching Windows, Linux, Unix, and Solaris security.
His column this week was as depressing as it was interesting. He puts all his 10 fingers smack in the middle of many sore spots.
It was revealing and entertaining to read his admittedly gloomy perspective on security, but he did say that next week's column will point to some solutions. In the mean time, read this and get yourself trained as an IT security specialist. There will be a lot of work for -years- to come !
Perhaps you know Roger Grimes. He's an InfoWorld Test Center Contributing Editor, Writes for WinITPro Mag, and is a Foundstone Ultimate Hacking instructor/consultant teaching Windows, Linux, Unix, and Solaris security.
His column this week was as depressing as it was interesting. He puts all his 10 fingers smack in the middle of many sore spots.
It was revealing and entertaining to read his admittedly gloomy perspective on security, but he did say that next week's column will point to some solutions. In the mean time, read this and get yourself trained as an IT security specialist. There will be a lot of work for -years- to come !
Friday, July 07, 2006
Thursday, June 29, 2006
How can I add root certs to my Windows Mobile 5.0 device?
and ...
OEMs or mobile operators provide certificate installers.
MSFP Deployment Guide.
adding root certs
adding root certs
OEMs or mobile operators provide certificate installers.
MSFP Deployment Guide.
adding root certs
adding root certs
Wednesday, June 28, 2006
Microsoft details unified communications road map
Main items include:
Microsoft Office Communications Server 2007, which is Microsoft's new name for its Live Communications Server. It will include voice-over-IP call management, as well as audio-, video- and webconferencing and instant messaging communication with and across software applications and devices.
Microsoft plans to release its Office Communicator 2007, a unified communications client that works with Communications Server 2007 to provide enterprise VoIP through a softphone. Microsoft also announced Office Live Meeting, which includes audio and video capabilities for conferencing from a PC and is due out at about the same time.
A new product: Office RoundTable.
Microsoft Exchange Server 2007 is also expected for release in late 2006 or early 2007, and Microsoft Speech Server 2007 will be available in late 2006
Partnerships with other communications vendors and includes plans for IP desktop phones that run Communicator software. The vendors named were Polycom Inc., LG-Nortel Co. Ltd. and Thomson Telecom. Microsoft also announced interoperability with or partnerships with Hewlett-Packard Co., Siemens AG and Motorola Inc.
/Gill
Microsoft Office Communications Server 2007, which is Microsoft's new name for its Live Communications Server. It will include voice-over-IP call management, as well as audio-, video- and webconferencing and instant messaging communication with and across software applications and devices.
Microsoft plans to release its Office Communicator 2007, a unified communications client that works with Communications Server 2007 to provide enterprise VoIP through a softphone. Microsoft also announced Office Live Meeting, which includes audio and video capabilities for conferencing from a PC and is due out at about the same time.
A new product: Office RoundTable.
Microsoft Exchange Server 2007 is also expected for release in late 2006 or early 2007, and Microsoft Speech Server 2007 will be available in late 2006
Partnerships with other communications vendors and includes plans for IP desktop phones that run Communicator software. The vendors named were Polycom Inc., LG-Nortel Co. Ltd. and Thomson Telecom. Microsoft also announced interoperability with or partnerships with Hewlett-Packard Co., Siemens AG and Motorola Inc.
/Gill
Tuesday, June 27, 2006
Microsoft offers online tests of Office 2007
Microsoft for the first time allows you to test pre-release/beta software without you having to download it first :)
Office components offered include:
Microsoft Office Access 2007
Microsoft Office Excel 2007
Microsoft Office InfoPath 2007
Microsoft Office OneNote 2007
Microsoft Office Outlook 2007
Microsoft Office Outlook 2007 with Business Contact Manager
Microsoft Office Outlook Web Access
Microsoft Office PowerPoint 2007
Microsoft Office Project Professional 2007
Microsoft Office Publisher 2007
Microsoft Office SharePoint Designer 2007
Microsoft Office Visio 2007
Microsoft Office Word 2007
Microsoft Windows SharePoint Services
Microsoft Office Project Server 2007 (coming soon)
Microsoft Office SharePoint Server 2007
Go ahead. Click http://www.microsoft.com/office/preview/beta/testdrive.mspx.
Office components offered include:
Microsoft Office Access 2007
Microsoft Office Excel 2007
Microsoft Office InfoPath 2007
Microsoft Office OneNote 2007
Microsoft Office Outlook 2007
Microsoft Office Outlook 2007 with Business Contact Manager
Microsoft Office Outlook Web Access
Microsoft Office PowerPoint 2007
Microsoft Office Project Professional 2007
Microsoft Office Publisher 2007
Microsoft Office SharePoint Designer 2007
Microsoft Office Visio 2007
Microsoft Office Word 2007
Microsoft Windows SharePoint Services
Microsoft Office Project Server 2007 (coming soon)
Microsoft Office SharePoint Server 2007
Go ahead. Click http://www.microsoft.com/office/preview/beta/testdrive.mspx.
Sunday, June 25, 2006
Firefox, iTunes, Skype Top Most Dangerous List
No wonder i don't use most of them.... and here is Sukhdev telling me to get Skype.
Friday, June 16, 2006
Analysis: Look for change at Microsoft after Gates
'You can't help but see some level of change,' says one analyst.
Microsoft outlines post-Gates transition plans
Gates will step aside in two years; Ray Ozzie named chief software architect
Reports of Excel 0-Day (NEW)
from SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System.
Reports of Excel 0-Day (NEW)
Published: 2006-06-16,Last Updated: 2006-06-16 06:02:01 UTC by Scott Fendley (Version: 1)
Microsoft has received a report of a new 0-day vulnerability involving Excel. They are currently investigating this issue and will issue more information on workarounds as it becomes available. They are currently blogging about it at http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx so check that site for more information as it becomes available.In the meantime, we continue to recommend the same defenses we recommended with the Word 0-day from last month located at http://isc.sans.org/diary.php?storyid=1347. These very general best practices should help alleviate the danger until Microsoft releases a patch or more specific workarounds.
Reports of Excel 0-Day (NEW)
Published: 2006-06-16,Last Updated: 2006-06-16 06:02:01 UTC by Scott Fendley (Version: 1)
Microsoft has received a report of a new 0-day vulnerability involving Excel. They are currently investigating this issue and will issue more information on workarounds as it becomes available. They are currently blogging about it at http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx so check that site for more information as it becomes available.In the meantime, we continue to recommend the same defenses we recommended with the Word 0-day from last month located at http://isc.sans.org/diary.php?storyid=1347. These very general best practices should help alleviate the danger until Microsoft releases a patch or more specific workarounds.
Saturday, May 27, 2006
Sunday, May 21, 2006
Article on Password cracking tools for SQL Server
Kevin Beaver has a quick article on Password Cracking tools for SQL Server. Here is the summary
Tools:
1. SQLPing2 and SQLRecon from sqlsecurity.com
2. Cain and Abel
3. NGSSoftware's NGSSQLCrack
4. Application Security's AppDetective
Word(password) Dictionaries
http://packetstormsecurity.nl/Crackers/wordlists
ftp://ftp.ox.ac.uk/pub/wordlists
ftp://ftp.cerias.purdue.edu/pub/dict
http://www.outpost9.com/files/WordLists.html
http://www.elcomsoft.com/prs.html#dict
/Gill
Tools:
1. SQLPing2 and SQLRecon from sqlsecurity.com
2. Cain and Abel
3. NGSSoftware's NGSSQLCrack
4. Application Security's AppDetective
Word(password) Dictionaries
http://packetstormsecurity.nl/Crackers/wordlists
ftp://ftp.ox.ac.uk/pub/wordlists
ftp://ftp.cerias.purdue.edu/pub/dict
http://www.outpost9.com/files/WordLists.html
http://www.elcomsoft.com/prs.html#dict
/Gill
Microsoft SQL Server I/O subsystem requirements for the tempdb database
Finally some best practices for performance guide for tempDB on MS SQL.
/Gill
/Gill
Guide to Computer Security Log Management
Guide to Computer Security Log Management
(http://csrc.nist.gov/publications/drafts/DRAFT-SP800-92.pdf).
(http://csrc.nist.gov/publications/drafts/DRAFT-SP800-92.pdf).
Friday, May 19, 2006
ADModify.NET: Workspace Home
Overview
ADModify.NET is a tool primarily utilized by Exchange and Active Directory administrators to facilitate bulk user attribute modifications. See http://blogs.technet.com/exchange/archive/2004/08/04/208045.aspx for launch details
ADModify.NET is a tool primarily utilized by Exchange and Active Directory administrators to facilitate bulk user attribute modifications. See http://blogs.technet.com/exchange/archive/2004/08/04/208045.aspx for launch details
Subscribe to:
Posts (Atom)