<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Armor</title>
	<atom:link href="http://www.informationarmor.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.informationarmor.com</link>
	<description>Protecting Your Data. A public service from Arizona IT Management LLC</description>
	<lastBuildDate>Tue, 22 Jun 2010 16:27:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security Updates 20100622</title>
		<link>http://www.informationarmor.com/2010/06/22/security-updates-20100622/</link>
		<comments>http://www.informationarmor.com/2010/06/22/security-updates-20100622/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 16:24:20 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=107</guid>
		<description><![CDATA[Opera 10.54 Released for Windows The web browser Opera has released an update to address multiple security issues when used on Windows platforms. There are five listed security fixes, four of which have no details given. We advise customers that use this web browser to update as soon as possible. http://www.opera.com/docs/changelogs/windows/1054/ Apple Quietly Includes Anti-Malware [...]]]></description>
			<content:encoded><![CDATA[<p>Opera 10.54 Released for Windows The web browser Opera has released an update to address multiple security issues when used on Windows platforms. There are five listed security fixes, four of which have no details given. We advise customers that use this web browser to update as soon as possible.</p>
<ul>
<li><a href="http://www.opera.com/docs/changelogs/windows/1054/">http://www.opera.com/docs/changelogs/windows/1054/</a></li>
</ul>
<p>Apple Quietly Includes Anti-Malware in latest OS X update While Apple products have had a reputation for eluding malware and virus threats, time might be catching up with them. Apple quietly added some Anti-Malware functionality to the latest update for Mac OS X 10.6.4. This is a proactive move by Apple to help maintain their reputation in being safe from malware.</p>
<ul>
<li><a href="http://www.notebooks.com/2010/06/21/apple-alters-mac-os-x-malware-protection/">http://www.notebooks.com/2010/06/21/apple-alters-mac-os-x-malware-protection/</a></li>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/06/18/apple-secretly-updates-mac-malware-protection/">http://www.sophos.com/blogs/gc/g/2010/06/18/apple-secretly-updates-mac-malware-protection/</a></li>
<li><a href="http://www.9to5mac.com/apples_secret_security_patch">http://www.9to5mac.com/apples_secret_security_patch</a></li>
</ul>
<p>Week In Review for June 14 &#8211; June 20, 2010 AlertCon Lowered For MS Windows Help Alert The Threat Level, raised to AlertCon 2 to draw awareness to the Microsoft Windows Help Center Protocol Handler vulnerability, has been lowered to AlertCon 1. Although exploitation continues, our analysts are seeing minimal traffic associated with that vulnerability. We assert that vigilance should be maintained and advise continued monitoring for attacks that exploit this weaknesses.</p>
<ul>
<li><a href="http://xforce.iss.net/XpuDetails.do?xpu=75&amp;ver=XPU%2030.061">http://xforce.iss.net/XpuDetails.do?xpu=75&amp;ver=XPU%2030.061</a></li>
<li> <a href="http://www.iss.net/security_center/reference/vuln/HTML_MS_HelpCenter_CMD_Exec.htm">http://www.iss.net/security_center/reference/vuln/HTML_MS_HelpCenter_CMD_Exec.htm</a></li>
<li><a href="http://www.sophos.com/blogs/sophoslabs/?p=10045">http://www.sophos.com/blogs/sophoslabs/?p=10045</a></li>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/06/15/tavis-ormandy-pleased-website-exploits-microsoft-zeroday/">http://www.sophos.com/blogs/gc/g/2010/06/15/tavis-ormandy-pleased-website-exploits-microsoft-zeroday/</a></li>
<li> <a href="http://www.microsoft.com/technet/security/advisory/2219475.mspx">http://www.microsoft.com/technet/security/advisory/2219475.mspx</a></li>
<li> <a href="http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx">http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx</a></li>
<li> <a href="http://blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspx">http://blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspx</a></li>
<li> <a href="http://seclists.org/fulldisclosure/2010/Jun/205">http://seclists.org/fulldisclosure/2010/Jun/205</a></li>
<li><a href="https://www.metasploit.com/redmine/projects/framework/repository/revisions/9483/entry/modules/exploits/windows/browser/ms10_xxx_helpctr_xss_cmd_exec.rb">https://www.metasploit.com/redmine/projects/framework/repository/revisions/9483/entry/modules/exploits/windows/browser/ms10_xxx_helpctr_xss_cmd_exec.rb</a></li>
</ul>
<p>Sophisticated Flash Player Attack in Circulation IBM X-Force has received a report of a sophisticated attack occurring in the wild targeting a vulnerability in Flash Player (CVE-2010-1297). This issue was disclosed earlier this month and the current attack involves placing a specially-crafted Flash file within a PDF file. The IBM signature PDF_Swf_Detected is detecting this attack. As a conservative measure, customers may want to set this signature to blocking. While this change may also block legitimate traffic, this type of traffic (a Flash file embedded in a PDF file) is not commonly seen.</p>
<p>Apple iTunes 9.2 Released, Addresses Several Security Issues Apple has released iTunes 9.2 in preparation for the release of iPhone 4 next week. This updated release also addresses three security issues all of which have the potential to be exploited to allow arbitrary code execution. This update is available through Apple&#8217;s website or through the update tool provided in iTunes itself.</p>
<ul>
<li><a href="http://support.apple.com/kb/HT4220">http://support.apple.com/kb/HT4220</a></li>
</ul>
<p>Remote Root Level Vulnerability Found in Samba The Samba team has announced a new memory vulnerability that allows remote root level access. This only impacts older versions of Samba (Versions 3.0.x &#8211; 3.3.12), with versions higher then 3.4.0 not being vulnerable. We are advising customers using Samba to verify which version(s) are in production and updating accordingly.</p>
<p><a href="http://www.samba.org/samba/security/CVE-2010-2063">http://www.samba.org/samba/security/CVE-2010-2063</a></p>
<p>New IBM XPU Addresses Latest MS Vulnerability (CVE-2010-1885) IBM has released an XPU and a Protection Alert to address the Microsoft Windows Help Center vulnerability that currently has the AlertCon raised to Level 2. Due to the ease of exploitability we urge customers to upgrade to this XPU as soon as possible to detect this latest threat.</p>
<ul>
<li><a href="https://portal.mss.iss.net/mss/xftas/alertAdvisory/details.mss?alertAdvisoryId=3407">https://portal.mss.iss.net/mss/xftas/alertAdvisory/details.mss?alertAdvisoryId=3407</a></li>
<li> <a href="http://xforce.iss.net/XpuDetails.do?xpu=75&amp;ver=XPU%2030.061">http://xforce.iss.net/XpuDetails.do?xpu=75&amp;ver=XPU%2030.061</a></li>
<li> <a href="http://www.iss.net/security_center/reference/vuln/HTML_MS_HelpCenter_CMD_Exec.htm">http://www.iss.net/security_center/reference/vuln/HTML_MS_HelpCenter_CMD_Exec.htm</a></li>
</ul>
<p>Writeups on Facebook Password Reset Spam Spammers are starting to leverage the pervasiveness of social networking and social media forums. There have been several writeups on the use of spam in the form of e-mails that look like they are coming from Facebook notifying users to reset their passwords. Links in these emails often contain malware in various forms. The best defense comes in the form of user education and the use of updated Anti-Virus/Anti-Malware software.</p>
<ul>
<li><a href="http://www.sophos.com/blogs/gc/g/2010/06/15/reset-facebook-password-spam-promotes-pharmacy-websites/">http://www.sophos.com/blogs/gc/g/2010/06/15/reset-facebook-password-spam-promotes-pharmacy-websites/</a></li>
<li> <a href="http://www.zdnet.com/blog/security/facebook-password-reset-spam-is-bredolab-botnet-attack/4724">http://www.zdnet.com/blog/security/facebook-password-reset-spam-is-bredolab-botnet-attack/4724</a></li>
<li> <a href="http://www.pcworld.com/businesscenter/article/191847/facebook_users_targeted_in_massive_spam_run.html">http://www.pcworld.com/businesscenter/article/191847/facebook_users_targeted_in_massive_spam_run.html</a></li>
</ul>
<p> Apple Releases Security Update Bundle for Mac OS X 10.6 Apple has released a security update for Mac OS X 10.6 that addresses 23 separate vulnerabilities, many of which allow remote execution capability. This update is available through the Apple Downloads site or through the Software Update tool. PLEASE NOTE: This update includes an older version of Adobe&#8217;s Flash Player that has some security vulnerabilities. If users have already upgraded to the latest version, then the older version will not be installed. We encourage customers running on this platform to apply these updates and verify their version of Adobe Flash Players soon as possible.</p>
<p><a href="http://support.apple.com/kb/HT4188">http://support.apple.com/kb/HT4188</a></p>
<p><a href="http://support.apple.com/downloads/">http://support.apple.com/downloads/</a></p>
<p> <a href="http://blogs.adobe.com/psirt/2010/06/apple_security_update_2010-004.html">http://blogs.adobe.com/psirt/2010/06/apple_security_update_2010-004.html</a></p>
<p> PHP 0day Vulnerability A presentation at the SyScan conference has made a PHP vulnerability public that allows remote attackers to execute arbitrary code via unserialized user input. Few details are currently available outside of the conference presentation. The PHP vulnerability is currently unpatched. We will continue investigating and provide more information as it becomes available.</p>
<p><a href="http://twitter.com/i0n1c/status/16447867829">http://twitter.com/i0n1c/status/16447867829</a></p>
<p><a href="https://bugzilla.redhat.com/show_bug.cgi?id=605641">https://bugzilla.redhat.com/show_bug.cgi?id=605641</a></p>
<p>US Supreme Court Rules on Employer/Employee privacy case In a case where a local police department searched an employee&#8217;s text messages, the court ruled that the employee&#8217;s work provided phone and the data associated with it did not have an expectation to privacy. The unanimous ruling provides some clarity on the issue of privacy in the workplace with regards to electronic communications. We advise customers to review their corporate policies with legal counsel to verify their privacy statements are current with this ruling. http://www.latimes.com/news/nationworld/nation/la-na-court-worker-texting-20100618,0,7772406.story http://www.infolawgroup.com/2010/06/articles/workplace-privacy/quon-us-supreme-court-rules-against-privacy-on-employerissued-devices/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/06/22/security-updates-20100622/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday for Microsoft</title>
		<link>http://www.informationarmor.com/2010/06/07/patch-tuesday-for-microsoft/</link>
		<comments>http://www.informationarmor.com/2010/06/07/patch-tuesday-for-microsoft/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 15:36:44 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=105</guid>
		<description><![CDATA[Microsoft&#8217;s June Security Advance Notification Microsoft is planning to release ten bulletins addressing 34 vulnerabilities on Tuesday, June 8th. The bulletins are rated as follows: 3 &#8220;Critical&#8221; and 7 &#8220;Important&#8221;. The affected software includes: Windows, Microsoft Office, and Internet Explorer. Additionally, Microsoft plans to address the issues highlighted in Security Advisories 983438 and 980088. We [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Microsoft&#8217;s June Security Advance Notification </strong><br />
Microsoft is planning to release ten bulletins addressing 34 vulnerabilities on Tuesday, June 8th. The bulletins are rated as follows: 3 &#8220;Critical&#8221; and 7 &#8220;Important&#8221;. The affected software includes: Windows, Microsoft Office, and Internet Explorer. Additionally, Microsoft plans to address the issues highlighted in Security Advisories 983438 and 980088. We encourage our customers to review the vendor&#8217;s Advance Notification and associated blog post.<br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx " target="_blank">http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx </a><br />
<a href="http://blogs.technet.com/b/msrc/archive/2010/06/03/june-2010-security-bulletin-advance-notification.aspx " target="_blank">http://blogs.technet.com/b/msrc/archive/2010/06/03/june-2010-security-bulletin-advance-notification.aspx </a></p>
<p><strong>Mobile Malware </strong><br />
Reports have surfaced this week indicating that Samsung&#8217;s S8500 Wave handsets were shipped with a malware-infected microSD card. Reportedly, some German models of this device are affected. Once the device is connected to the computer, it automatically installs a Trojan using a file called &#8220;slmvsrv.exe.&#8221;</p>
<p>While this is an example of a mobile device being shipped with malware, there are ways that attackers can utilize different functionality to distribute their malware. For instance, the Multimedia Message Service (MMS) can be used as a vector for sending malware to unsuspecting victims. Many mobile phones and PDAs available today are capable of communicating via Bluetooth, a protocol designed for short range communication between electronic devices. Simple social engineering attacks have effectively convinced Bluetooth users to pair their devices with complete strangers, giving them unrestricted access to data on the victim&#8217;s phone. Additionally, many modern mobile phones and PDAs now run robust, feature-rich operating systems and offer the same or similar applications as PCs. Individuals increasingly use them to store personal data and conduct financial transactions which gives attackers more incentive to find and exploit vulnerabilities in the software.</p>
<p>Several major security vendors now provide security applications and anti-virus software for mobile users. Cellular service providers also offer some protection to their customers automatically by scanning for specific types of malicious code as data traverses the network. Bluetooth should be disabled while not in use and should never respond to unsolicited connection attempts. Although the level of mobile attacks is currently relatively low, it is still important for organizations to be aware of the potential threat.<br />
<a href="http://www.engadget.com/2010/06/02/samsung-wave-shipping-with-infected-microsd-card/ " target="_blank">http://www.engadget.com/2010/06/02/samsung-wave-shipping-with-infected-microsd-card/ </a><br />
<a href="http://www.f-secure.com/weblog/archives/00001959.html " target="_blank">http://www.f-secure.com/weblog/archives/00001959.html </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/06/07/patch-tuesday-for-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Internet</title>
		<link>http://www.informationarmor.com/2010/05/27/the-internet/</link>
		<comments>http://www.informationarmor.com/2010/05/27/the-internet/#comments</comments>
		<pubDate>Thu, 27 May 2010 15:45:29 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Wardriving]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=103</guid>
		<description><![CDATA[A New Phishing Attack We were intrigued when looking at the demo of what has been dubbed &#8216;tabnabbing&#8217;, a new type of phishing attack discovered by Aza Raskin from Mozilla. Different from the more contemporary phishing attacks that generally lure victims directly to the malicious phishing page through emails and links, this attack could load [...]]]></description>
			<content:encoded><![CDATA[<p><strong>A New Phishing Attack</strong><br />
We were intrigued when looking at the demo of what has been dubbed &#8216;tabnabbing&#8217;, a new type of phishing attack discovered by Aza Raskin from Mozilla. Different from the more contemporary phishing attacks that generally lure victims directly to the malicious phishing page through emails and links, this attack could load a malicious phishing page in the background while the user is browsing another tab. For example, a user could be enticed to visit what is an apparently normal web page, not a phishing page. When the user&#8217;s browser is interrogated, a phishing page for a service the user has actually visited could be opened. However, this would happen in the background and a user may not notice at all and might unwittingly enter details into the malicious page. How this works is probably best explained by the proof of concept page provided by Raskin which, currently, is no longer publicly available. Another demonstration page created by Aviv Raff and based on a mockup of the Brian Krebs blog article on tabnabbing is also available (see links below).</p>
<p>The issue appears to affect all major browsers, though results vary between browsers and operating systems. The remediation for this issue would be to completely disable Javascript in the browser. The Raff demo is notable in that it can work against Firefox, even with the popular Noscript add-on installed. We do suggest readers familiarize themselves with this issue.<br />
<a href="http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/" target="_blank">http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/</a><br />
<a href="http://avivraff.com/research/phish/article.php?406707075 " target="_blank">http://avivraff.com/research/phish/article.php?406707075 </a></p>
<p><strong>Wardriving and Open Wireless Networks</strong><br />
Stories about the number of unprotected wireless networks used to be common place but it has been some years now since WPA and then WPA2 have become prevalent. WPA2 is relatively easy to setup and provides a good level of encryption and authentication. So, we were somewhat surprised to read the results of a wardriving exercise conducted by the state police in various regional centers across Queensland, Australia. The results have led to the police estimating that some fifty percent of the wireless internet connections in Queensland of having no or minimal security settings enabled, no password, or still have the default password on their wireless device. Perhaps more disturbing is a comment from Detective Superintendent Brian Hay of the Queensland state police, &#8220;We know that the crooks are out there, scanning the environment and identifying these vulnerable networks, plotting them and then selling the information.&#8221;</p>
<p>Open wireless systems present many dangers and while we consider the results of the wardriving exercise would reflect largely on domestic wireless systems, these same systems may well be used by corporate employees when working from home. While we would expect most remote access systems to be encrypted or utilize a VPN for access, corporate resources or information might still be exposed. We suggest that at the business level, staff are made aware of the dangers of using open wireless systems and we urge all people who have wireless access points in their homes or businesses to verify that their systems are configured to operate in a secure manner.<br />
<a href="http://www.couriermail.com.au/news/technology/half-of-wireless-networks-unsecured-in-queensland/story-e6frep1o-1225870268562 " target="_blank">http://www.couriermail.com.au/news/technology/half-of-wireless-networks-unsecured-in-queensland/story-e6frep1o-1225870268562 </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/05/27/the-internet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>April Patches and Updates</title>
		<link>http://www.informationarmor.com/2010/04/14/april-patches-and-updates/</link>
		<comments>http://www.informationarmor.com/2010/04/14/april-patches-and-updates/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 16:07:39 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=100</guid>
		<description><![CDATA[1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP Service (MS10-024 CVE-2010-0024) Microsoft Windows SMTP Service and Microsoft Exchange are vulnerable to a denial of service, caused by the improper handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer Protocol component. As SMTP services are often exposed to the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP  Service (MS10-024 CVE-2010-0024)</strong><br />
Microsoft Windows SMTP Service and  Microsoft Exchange are vulnerable to a denial of service, caused by the improper  handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer  Protocol component. As SMTP services are often exposed to the Internet and email  is usually considered a business critical function, the business impact of this  vulnerability is more significant than for typical Denial of Service issues.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx</a></p>
<p><strong>2. Microsoft DirectShow Remote Code Execution (MS10-026  CVE-2010-0480)</strong><br />
Microsoft Windows is vulnerable to a stack-based  buffer overflow, caused by improper bounds checking by the MPEG Layer-3 audio  codecs when handling malicious files. The vulnerable MPEG Layer-3 audio codecs  are the MPEG Layer-3 Audio Codec for Microsoft DirectShow. Successful  exploitation of this issue would provide an attacker with complete control over  the endpoint target. The use of malicious media files like images and movies has  been prevalent in the past years.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx</a></p>
<p><strong>Adobe Reader and Acrobat Security Update</strong><br />
Adobe has  addressed multiple critical vulnerabilities affecting Adobe Reader 9.3.1 (and  earlier versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and  earlier versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier  versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and  Macintosh. The most severe of these issues could allow a remote attacker to  execute arbitrary code on a vulnerable system. Refer to the &#8220;Solution&#8221; section  of the Adobe Security Bulletin for information on remediating these issues.<br />
<a title="http://www.adobe.com/support/security/bulletins/apsb10-09.html" href="http://www.adobe.com/support/security/bulletins/apsb10-09.html"> http://www.adobe.com/support/security/bulletins/apsb10-09.html</a><br />
<strong><br />
Microsoft April 2010 Security Release</strong><br />
Microsoft released  eleven security bulletins today. There are five rated Critical, five rated  Important and one rated Moderate. We encourage our customers to apply the  patches and IBM product coverage where applicable. Please, review the break-down  below.<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Critical</strong><br />
<strong>Microsoft Security Bulletin MS10-019: Vulnerabilities in Windows  Could Allow Remote Code Execution (981210)</strong><br />
Vulnerabilities in  Windows Authenticode Verification could allow a remote attacker execute  arbitrary code on a vulnerable system.<br />
CVE-2010-0486<br />
CVE-2010-0487<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-020: Vulnerabilities in SMB Client  Could Allow Remote Code Execution (980232)</strong><br />
Multiple vulnerabilities  affecting Microsoft Windows could allow remote code execution. Successful  exploitation can occur if an attacker can convince a user to initiate an SMB  connection to a specially crafted SMB server.<br />
CVE-2009-3676<br />
CVE-2010-0269<br />
CVE-2010-0270<br />
CVE-2010-0476<br />
CVE-2010-0477<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-025: Vulnerability in Microsoft  Windows Media Services Could Allow Remote Code Execution (980858)</strong><br />
A  remote code execution vulnerability affects Windows Media Services running on  Microsoft Windows 2000 Server. The Windows Media Unicast Service fails to  properly handle specially crafted transport information packets. On Microsoft  Windows 2000 Server Service Pack 4, Windows Media Services is an optional  component and is not installed by default.<br />
CVE-2010-0478<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-026: Vulnerability in Microsoft MPEG  Layer-3 Codecs Could Allow Remote Code Execution (977816)</strong><br />
<strong>2. Microsoft DirectShow Remote Code  Execution (MS10-026 CVE-2010-0480)</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-027: Vulnerability in Windows Media  Player Could Allow Remote Code Execution (979402)</strong><br />
The Windows Media  Player ActiveX control is affected by a remote code execution vulnerability.<br />
CVE-2010-0268<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Important</strong><br />
<strong>Microsoft Security Bulletin MS10-021: Vulnerabilities in Windows  Kernel Could Allow Elevation of Privilege (979683)</strong><br />
This bulletin  addresses two vulnerabilities in Microsoft Windows, the most severe of which  could allow elevation of privilege. In order to exploit these vulnerabilities,  an attacker must have valid logon credentials and be able to log on locally.<br />
CVE-2010-0236<br />
CVE-2010-0237<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-022: Vulnerability in VBScript  Scripting Engine Could Allow Remote Code Execution (981169)</strong><br />
A  vulnerability affecting VBScript on Microsoft Windows could allow remote code  execution. This vulnerability requires user interaction and cannot be exploited  on Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2.<br />
CVE-2010-0483<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-023: Vulnerability in Microsoft  Office Publisher Could Allow Remote Code Execution (981160)</strong><br />
Microsoft Office Publisher is vulnerable to a remote code execution issue.  An attacker could exploit this issue by creating a specially crafted Publisher  file and sending it in an email or hosting it on a Web site.<br />
CVE-2010-0479;  IBM Product Coverage: CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-024: Vulnerabilities in Microsoft  Exchange and Windows SMTP Service Could Allow Denial of Service  (981832)</strong><br />
<strong>1. Denial  of Service Conditions in Microsoft Exchange and Microsoft SMTP Service</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-028: Vulnerabilities in Microsoft  Visio Could Allow Remote Code Execution (980094)</strong><br />
Vulnerabilities in  Microsoft Office Visio could allow remote code execution if a user opens a  specially crafted Visio file.<br />
CVE-2010-0254; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
CVE-2010-0256; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Moderate</strong><br />
<strong>Microsoft Security Bulletin MS10-029: Vulnerability in Windows  ISATAP Component Could Allow Spoofing (978338) </strong><br />
A spoofing  vulnerability exists in the Microsoft Windows IPv6 stack which could allow an  attacker to impersonate an address to bypass edge or host firewalls.  CVE-2010-0812<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/04/14/april-patches-and-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Internet Explorer Vulnerability</title>
		<link>http://www.informationarmor.com/2010/04/07/microsoft-internet-explorer-vulnerability/</link>
		<comments>http://www.informationarmor.com/2010/04/07/microsoft-internet-explorer-vulnerability/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 15:50:19 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=98</guid>
		<description><![CDATA[New Exploit Code for Microsoft Internet Explorer Vulnerability Exploit code has surfaced for one of the vulnerabilities in MS10-018, the out-of-cycle bulletin released by Microsoft on March 30. This bulletin addresses multiple vulnerabilities in Internet Explorer including a 0-day vulnerability that was being exploited earlier this month. This most recent exploit code which has been [...]]]></description>
			<content:encoded><![CDATA[<p><strong>New Exploit Code for Microsoft Internet Explorer Vulnerability</strong><br />
Exploit code has surfaced for one of the vulnerabilities in MS10-018, the out-of-cycle bulletin released by Microsoft on March 30. This bulletin addresses multiple vulnerabilities in Internet Explorer including a 0-day vulnerability that was being exploited earlier this month. This most recent exploit code which has been released targets a different vulnerability covered by this same update. Customers that have not done so already should apply this cumulative update.<br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx</a></p>
<p><a href="http://www.metasploit.com/redmine/projects/framework/repository/revisions/9018/entry/modules/exploits/windows/browser/ms10_018_ie_tabular_activex.rb">http://www.metasploit.com/redmine/projects/framework/repository/revisions/9018/entry/modules/exploits/windows/browser/ms10_018_ie_tabular_activex.rb</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/04/07/microsoft-internet-explorer-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Vulnerabilities</title>
		<link>http://www.informationarmor.com/2010/03/17/new-vulnerabilities/</link>
		<comments>http://www.informationarmor.com/2010/03/17/new-vulnerabilities/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:23:06 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[SpamAssassin]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/2010/03/17/new-vulnerabilities/</guid>
		<description><![CDATA[Vulnerability in HP Broadcom Integrated NIC Management Firmware A potential vulnerability has been identified and reported with some HP PCs with Broadcom Integrated NIC Firmware. The vulnerability could be remotely exploited to execute arbitrary code. This vulnerability is reported in 1.x versions prior to 1.40.0.0, and 8.x versions prior to 8.08. This vulnerability references CVE-2010-0104 [...]]]></description>
			<content:encoded><![CDATA[<p>Vulnerability in HP Broadcom Integrated NIC Management Firmware<br />
A potential vulnerability has been identified and reported with some HP PCs with Broadcom Integrated NIC Firmware. The vulnerability could be remotely exploited to execute arbitrary code. This vulnerability is reported in 1.x versions prior to 1.40.0.0, and 8.x versions prior to 8.08. This vulnerability references CVE-2010-0104 and CERT VU#512705. Please see the vendor&#8217;s advisory for details on affected hardware and a list of impacted machine models. Users are recommended to upgrade to the latest firmware available from the vendor, currently 1.40.0.0 for the 1.x series or 8.08 for the 8.x firmware. HP advisory HPSBGN02511 SSRT100022.</p>
<p>http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471</p>
<p>http://secunia.com/advisories/39003/</p>
<p>Spamassassin Milter Plugin Remote Root Exploit<br />
An exploit has been published to the mailing list &#8220;Full Disclosure&#8221; for a 0-day attack against the Spamassassin Milter Plugin. Spamassassin is a popular OpenSource spam filtering system. Successful exploitation results in remote root access to vulnerable systems. A preliminary patch for the flaw has been published to the project site. Mitigation recommendations include not running the milter (mail filter) plugin as root and not using the -x option. Users should implement the mitigations and patch vulnerable systems as soon as possible. Upgrades should be preformed as soon as official updates are made available. </p>
<p>http://isc.sans.org/diary.html?storyid=8434</p>
<p>http://www.securityfocus.com/bid/38578/info</p>
<p>http://seclists.org/fulldisclosure/2010/Mar/140</p>
<p>http://savannah.nongnu.org/bugs/index.php?29136</p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/03/17/new-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft</title>
		<link>http://www.informationarmor.com/2010/03/09/microsoft/</link>
		<comments>http://www.informationarmor.com/2010/03/09/microsoft/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 22:16:26 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=95</guid>
		<description><![CDATA[As a reminder, Microsoft is planning to release two security bulletins today, March 9, 2010. Both bulletins carry a maximum severity rating of important and the issues addressed could lead to remote code execution. The first bulletin applies to various versions of Windows XP, Vista and Windows 7 and is rated as important for all [...]]]></description>
			<content:encoded><![CDATA[<p>As a reminder, Microsoft is planning to release two security bulletins today,  March 9, 2010. Both bulletins carry a <strong>maximum severity rating of importan</strong>t and  the issues addressed could lead to remote code execution. The first bulletin  applies to various versions of Windows XP, Vista and Windows 7 and is rated as  important for all affected versions. The second bulletin applies to various  Office releases and components for Windows and Mac and is also rated as  important for all affected versions.<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/03/09/microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bridal Scam</title>
		<link>http://www.informationarmor.com/2010/03/09/bridal-scam/</link>
		<comments>http://www.informationarmor.com/2010/03/09/bridal-scam/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 22:15:27 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[awareness]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=93</guid>
		<description><![CDATA[We would also like to draw our readers&#8217; attention to interesting media articles on a scam, with something of a twist. The scam involved a purported bridal convention in Boston, which would be held at a convention center, and even claimed part of the profits from the event would be donated to earthquake victims in [...]]]></description>
			<content:encoded><![CDATA[<p>We would also like to draw our readers&#8217; attention to interesting media articles  on a scam, with something of a twist. The scam involved a purported bridal  convention in Boston, which would be held at a convention center, and even  claimed part of the profits from the event would be donated to earthquake  victims in Haiti. It appears there are many victims of this scam including a  significant number of wedding industry vendors and an estimated 5,000  individuals who bought tickets to attend. The scam came to light when an  executive from the company who owns the convention center found the Web site  promoting the event, which he knew was not booked at the center, and notified  authorities. It appears the scam used radio, social networking, tweets, facebook  and the scammer&#8217;s Web site to promote the event.<br />
<a title="http://blogs.findlaw.com/injured/2010/03/bridal-no-show-the-boston-bridal-show-scam.html" href="http://blogs.findlaw.com/injured/2010/03/bridal-no-show-the-boston-bridal-show-scam.html">http://blogs.findlaw.com/injured/2010/03/bridal-no-show-the-boston-bridal-show-scam.html</a><br />
<a title="http://www.boston.com/news/local/massachusetts/articles/2010/03/02/advertised_bridal_show_a_scam_fbi_police_say/?page=1" href="http://www.boston.com/news/local/massachusetts/articles/2010/03/02/advertised_bridal_show_a_scam_fbi_police_say/?page=1">http://www.boston.com/news/local/massachusetts/articles/2010/03/02/advertised_bridal_show_a_scam_fbi_police_say/?page=1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/03/09/bridal-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP server 2.2.15</title>
		<link>http://www.informationarmor.com/2010/03/09/apache-http-server-2-2-15/</link>
		<comments>http://www.informationarmor.com/2010/03/09/apache-http-server-2-2-15/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 22:14:19 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=90</guid>
		<description><![CDATA[Apache has released HTTP Server version 2.2.15, which addresses a number of security exposures in prior versions of the HTTP server. Of particular note is the updating of the OpenSSL library to 0.9.8m which addresses the renegotiation issues outlined in CVE-2009-3555. At the time of writing, the links to the complete changelog and downloads for [...]]]></description>
			<content:encoded><![CDATA[<p>Apache has released HTTP Server version 2.2.15, which addresses a number of  security exposures in prior versions of the HTTP server. Of particular note is  the updating of the OpenSSL library to 0.9.8m which addresses the renegotiation  issues outlined in CVE-2009-3555. At the time of writing, the links to the  complete changelog and downloads for 2.2.15 were not visible on the Apache Web  site, however, we urge users to apply this latest vendor update as soon as  possible.<br />
<a title="http://mail-archives.apache.org/mod_mbox/www-announce/201003.mbox/&lt;4B92BC77.8050401@apache.org&gt;" href="http://mail-archives.apache.org/mod_mbox/www-announce/201003.mbox/%3C4B92BC77.8050401@apache.org%3E">http://mail-archives.apache.org/mod_mbox/www-announce/201003.mbox/%3C4B92BC77.8050401@apache.org%3E</a><br />
<a title="http://httpd.apache.org/download.cgi" href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>Proof of concept code exploiting a vulnerability (CVE-2010-0425) in the Apache  HTTP server version 2.2.14, mod_isapi, was published to a well known Web site.  Notes in the code state that the exploit may need to be run several times to  achieve successful spawning of a shell however &#8211; a success rate of 70% is  reported. Also mentioned in the code is that, if DEP is enabled (Windows  platforms) for the Apache process, the result may be a denial of service  condition. As CVE-2010-0425 is one of those noted as addressed in the above  2.2.15 release, we again suggest updating as soon as possible.<br />
<a title="http://www.exploit-db.com/exploits/11650" href="http://www.exploit-db.com/exploits/11650">http://www.exploit-db.com/exploits/11650</a><br />
<a title="http://securityreason.com/wlb_show/WLB-2010030028" href="http://securityreason.com/wlb_show/WLB-2010030028">http://securityreason.com/wlb_show/WLB-2010030028</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/03/09/apache-http-server-2-2-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blackhat SEO</title>
		<link>http://www.informationarmor.com/2010/03/09/blackhat-seo/</link>
		<comments>http://www.informationarmor.com/2010/03/09/blackhat-seo/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 22:13:16 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[seo]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=88</guid>
		<description><![CDATA[Recent assessments have discussed many of the Search Engine Optimization (SEO) scams currently in circulation. In a blog post published on Friday, X-Force analysts note how scammers are not only exploiting real news events, but they are also creating their own news to gain profits through affiliate programs. Our researchers warn, &#8220;you can&#8217;t always trust [...]]]></description>
			<content:encoded><![CDATA[<p>Recent assessments have discussed many of the Search Engine Optimization (SEO)  scams currently in circulation. In a blog post published on Friday, X-Force  analysts note how scammers are not only exploiting real news events, but they  are also creating their own news to gain profits through affiliate programs. Our  researchers warn, &#8220;you can&#8217;t always trust the hosts that search engines point  to.&#8221; We encourage our customers to ensure their anti-virus software is  up-to-date and to enable blacklisting on browsers that support it, such as the  &#8216;Block reported attack sites&#8217; setting in Firefox.<br />
<a title="http://blogs.iss.net/archive/CreatingNewsForBlack.html" href="http://blogs.iss.net/archive/CreatingNewsForBlack.html">http://blogs.iss.net/archive/CreatingNewsForBlack.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/03/09/blackhat-seo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
