Security 10918 Published by Philipp Esselbach 0

An independent security review of Microsoft's .Net framework has called the project a robust platform for enterprise and web application security.

Although Microsoft has often come under fire from the security industry in the past, joint research from security firms Foundstone and Core Security Technologies has found that the .Net framework team has addressed security with the utmost priority.

Read more

Security 10918 Published by Philipp Esselbach 0

A new computer worm that installs hacking software on infected computers hit home e-mail users hard last weekend and could spread to businesses Monday, warned antivirus experts.

Known as BadTrans.B, the worm is spreading mainly due to people's relaxed approach to security during the holiday season, said April Goostree, virus research manager for computer security company McAfee.com.

Read more

Security 10918 Published by Philipp Esselbach 0

Thanks CestLaVie for this one:

At least one antivirus software company, McAfee Corp., contacted the FBI on Wednesday to ensure its software wouldn't inadvertently detect the bureau's snooping software and alert a criminal suspect.

Read more

Security 10918 Published by Philipp Esselbach 0

A known vulnerability in Microsoft SQL server systems is being targeted by a hybrid worm that combines a distributed denial of service attack (DDoS) with the automated propagation techniques used by worms such as Code Red.

Read more

Security 10918 Published by Philipp Esselbach 0

One of the streaming media formats supported by Windows Media Player is Advanced Streaming Format (ASF). A security vulnerability occurs in Windows Media Player 6.4 because the code that processes ASF files contains an unchecked buffer.

By creating a specially malformed ASF file and inducing a user to play it, an attacker could overrun the buffer, with either of two results: in the simplest case, Windows Media Player 6.4 would fail; in the more complex case, code chosen by the attacker could be made to run on the user's computer, with the privileges of the user. The scope of this vulnerability is rather limited. It affects only Windows Media Player 6.4, and can only be exploited by the user opening and deliberately playing an ASF file. There is no capability to exploit this vulnerability via email or a web page.

Read more

Security 10918 Published by Philipp Esselbach 0

Thanks Mike for this one:

McAfee Virus Scan Corporate version 4.5.1 and consumer 6.0 and lower can delete your entire outlook express 6 (windows xp) store. If you have Internet Filtering turned on and open OE6, all your email is now gone and you can NOT recover.

A patch for 6.x is available here

Security 10918 Published by Philipp Esselbach 0

The success of attack worms like Code Red, Code Blue and Nimda prompted some industry watchers to suggest that enterprise users should reconsider their use of Microsoft's IIS Web hosting platform.

Read more