Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Saturday, August 4, 2012

Microsoft tool shows whether apps pose danger to Windows

Attack Surface Analyzer can identify multiple classes of weaknesses introduced by newly installed programs

IDG News Service - Microsoft has released Attack Surface Analyzer 1.0, a free tool that can help system administrators, IT security professionals or software developers understand how newly installed applications can affect the security of a Windows OS.

The tool scans for classes of known security weaknesses that can be introduced by the files, registry keys, services, Microsoft ActiveX controls and other parameters created or changed by new applications.

It can identify executable files, directories, registry keys, or processes with weak access control lists (ACLs). It can also flag processes that don't mark memory regions as non-executable (NX), which could result in the bypassing of the Data Execution Prevention (DEP) Windows security feature. The tool also identifies services with fast restart times that could be attacked to bypass address space layout randomization (ASLR), as well as changes to the Windows Firewall rules or Internet Explorer security policies.

Comptia A+ Training, Comptia A+ certification

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


These and many other weaknesses that the tool identifies can facilitate various types of attacks, including some that could allow attackers to gain control of the system, execute malicious code or gain access to sensitive data.

The tool is already being used by internal product groups at Microsoft and a public beta version has been available to download since January 2011. The 1.0 stable version released on Thursday contains significant performance enhancements and bug fixes.

"Through improvements in the code, we were able to reduce the number of false positives and improve Graphic User Interface performance," the Microsoft Security Development Lifecycle (SDL) team said in a blog post. "This release also includes in-depth documentation and guidance to improve ease of use."

The tool has 32-bit and 62-bit versions and supports Windows Vista and newer versions of Microsoft's OS, including Windows 8 and Windows Server 2012 that hit the RTM (release to manufacturing) milestone on Tuesday.

Attack Surface Analyzer 1.0 is not compatible with the beta version of the tool, so existing users need to perform new "clean" system and post-application-installation scans -- known as the baseline and product scans respectively.

Attack Surface Analyzer requires .NET Framework 4 or higher present on the system in order to compare and analyze scan results. However, performing the actual scans can be done from the command line interface without .NET Framework.

Monday, June 4, 2012

Most OpenOffice users run Windows

However, Apache's download stats might not tell the whole story

Nearly 9 out of 10 downloads of the new version of OpenOffice have been for Windows machines, rather than Linux, according to recently released statistics from Apache.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


MORE LINUX: Linux Mint 13 rallies behind Gnome

Of the first 1,000,663 Sourceforge downloads of OpenOffice 3.4, 87% were Windows users, 11% were running Mac OS, and just 2% were on Linux, the team said.

A Reddit discussion, however, highlighted that these statistics could be misleading, due mostly to the fact that Linux users tend not to simply download programs from the Internet.

"Even before it was forked, how many Linux users were going to download it direct from openoffice.org instead of getting it direct from the software repository for their distribution of choice?" asked user houseofzeus.

That said, many others argued that the success of LibreOffice -- a relatively recent fork of OpenOffice -- has undercut the older product's market share across operating systems.

"The LibreOffice fork is MUCH more popular in the Linux community. I prefer it to OpenOffice.org anyways due to various improvements," wrote aliendude5300. LibreOffice's shorter load times were widely cited as the central advantage.

OpenOffice's lack of recent success, argues a recent Unixmen article, is partially due to the folding of the Oracle team that largely fueled the development of the office suite. Since OpenOffice was handed over to Apache, that organization has attempted to compete directly with the successful fork -- and, according to most, has made little headway.

For its part, Apache stated in March that it has had to spend a great deal of time migrating infrastructure over from Oracle and rework "copylefted" components to ensure that they comply with Apache's licensing policy.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Friday, May 25, 2012

Microsoft's upgrade avalanche a challenge for IT pros

In addition to the version for x86 PCs that use chips from Intel and AMD, Windows 8 will also come in a version for devices that use ARM chips. This version, now called Windows RT, will be built on the Windows 8 code base and will probably run mainly on tablets built on chips from ARM licensees Nvidia, Qualcomm and Texas Instruments.

Like Windows 8 PCs for x86/64, Windows RT devices will be able to run Metro-style applications from the Windows Store created using WinRT APIs. WinRT stands for Windows Runtime and contains the API (application programming interface) library for building Metro-style applications.

However, Windows RT hardware will not run, emulate or port existing x86/64 desktop applications. Windows RT will include desktop versions of the upcoming Office 15 applications, like Word, Excel, PowerPoint and OneNote, that have been designed for touch-based interfaces and for minimal power consumption.

Despite the broad availability of the beta version since late February, it is still too early for enterprises to be even considering adopting Windows 8, IDC's Gillen said.

MCTS Training, MCITP Trainnig
Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


"Windows 8 isn't even in Release Candidate code yet, so it's premature for most organizations to make any business decision about replacing Windows 7 with Windows 8. We need to see the finished product first," Gillen said.

Gartner's Silver believes that Windows 8 will largely be bypassed altogether, except in specific cases, such as in organizations that want to deploy Windows-based tablets to their users. It has become popular for users to come to work with their personal smartphones and tablets (mostly Android and Apple iOS devices), a trend known as "bring your own device," or BYOD. Microsoft wants to enter that party, but Windows is currently a small player in tablets and smartphones.

At hotel titan Hyatt, the work to upgrade desktops from Windows XP to Windows 7 began in 2009 and continues today. The company expects to complete the upgrade of all 34,000 desktops in North America by the end of this year.

Hyatt's CIO, Mike Blake, is very impressed with Windows 7, calling it "a great product." While not closed to Windows 8, Blake said there are still many unanswered questions about the new OS.

"I've wavered from one end of the Microsoft spectrum to the other. I was a hater and now I'm more of a proponent, and a lot of it has to do with Windows 7," he said.

Forrester also has found in its surveys that CIOs are moving their enterprises at a very quick and steady pace to Windows 7 and to Office 2010, according to Schadler. Almost 200 million copies of Office 2010 have been sold to date, according to Microsoft.

In fact, an argument can be made that Microsoft may be pushing out Windows 8 and Office 15 too close to their predecessors, and may find it is competing against itself, Osterman said.

"Unless there's something really compelling in Windows 8, I don't see the upgrade push," Osterman said. "And with Office 15, Microsoft is going to be hard-pressed to make the case for it, only because Office 2010 is so good. Microsoft has a very nice set of products on the desktop right now."
The next Office suite

Office 15 is in limited-access, early testing. A broader beta period is slated for the summer. Very little is known about technical details and improvements in the Office 15 applications at this point. What Microsoft is saying unequivocally is that Office 15 will be "the most ambitious undertaking yet for the Office Division." The revamped applications, which will also include Project and Visio, will all get new "touch-friendly" UIs on tablets and similar devices.

For now, the Office product that Hyatt's Blake is most focused on is the cloud-hosted email and collaboration suite Office 365 and its predecessor, BPOS (Business Productivity Online Suite). Hyatt is deploying BPOS and plans to later upgrade to Office 365, which was released in mid-2011 and includes online versions of Exchange, SharePoint, Office and Lync. Office 365 will be upgraded again once Office 15 is released in final form.

Coming from IBM Lotus Notes, Hyatt has experienced a significant improvement in email reliability and in employee collaboration from using BPOS.

Prior to rolling out BPOS, Hyatt's email system was down 81 times over three years, with each of those outages being 10 minutes long or more. In the 13 months since it has been using Exchange Online, Hyatt has had only three hours of downtime, he said.

Meanwhile, SharePoint Online has taken employees' ability to collaborate with each other and with customers and partners to another level, he said.

Blake, however, isn't too happy with the licensing scheme for BPOS and Office 365, which he finds too complicated, especially considering that they are subscription-based suites.

He wishes the Microsoft suites would be licensed and billed in the "all inclusive" model of rival Google Apps. The Google suite costs $50 per user, per year, or, alternatively, $5 per user, per month. Hyatt almost picked Google Apps over BPOS, ultimately deciding against it in large part due to users' historical familiarity with the Outlook email client. "It was almost a coin toss between the two," Blake said.

Instead, Office 365 has multiple versions at different prices with different mixes of components, and as Hyatt looks ahead at transferring to it from BPOS, Blake finds the licensing scenario annoyingly complex, calling the many versions of Office 365 "crazy" and "foolish."

"With Google Apps, it doesn't matter how many trips to the buffet you make, you're good to go. Microsoft on the other hand segments the salad bar, the starches, the meat, and you have to say, 'did I remember the meat? The starch?' And if you forgot the salad, then you need to pay another license fee for that," Blake said.
Explorer and Windows Phone

In development along with Windows 8 is the next version of the browser, IE 10, which, according to Microsoft, is designed to be "edge-to-edge fast" with "less browser and more Web." It will offer two different interface experiences -- Metro-style and traditional Windows desktop. IE10 is being designed to take advantage of hardware acceleration features; supports HTML5, CSS3 and other Web standards broadly; and will be more secure than its predecessors, Microsoft has said.

Also relevant for enterprise IT executives is the next major version of the Windows Phone OS, which hasn't been officially announced but is said to be code-named Apollo. Some speculate it will be called Windows Phone 8 and that it will provide more code and application consistency with the desktop and server OSes than has existed up to now.

Whatever enhancements are present in Windows Phone 8, Microsoft finds itself -- much as in the tablet market -- as an underdog. At the end of last year's third quarter, Android held 52.5% of the worldwide mobile operating system market, while Microsoft ended in sixth place with 1.5%, according to Gartner. In the U.S., as of the end of February of this year, Android had 50.1% of the smartphone OS market, while Microsoft had almost 4%, according to comScore.

When Microsoft does talk in detail about the next major version of Windows Phone, there are two major areas CIOs should focus on, according to Avi Greengart, an analyst with Current Analysis.

The first area is the phone IT security and management controls that will be available to IT departments via Windows server products.

While Windows Phone 7 and 7.5 are in general more advanced than their predecessor, Windows Mobile 6.5, the latter gave IT staffers more administration controls over phones, Greengart said.

"If I was a CIO, I'd be asking for a more detailed road map on what is and isn't supported before I'd commit to deploy Windows Phone," Greengart said.

The other major issue is the level of application compatibility. "There will be some compatibility. The question is how much," Greengart said.

Microsoft recently said in a blog post that "today's Windows Phone applications and games will run on the next major version of Windows Phone."

The company also said that "all" of Windows Phone developers' programming skills "are transferable to building applications for Windows 8, and in many cases, much of your code will be transferable as well."

MCTS Training, MCITP Trainnig
Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, May 10, 2012

Microsoft security patches include fixes for Word, Office, Windows

In its May "Patch Tuesday," Microsoft released seven bulletins covering 23 vulnerabilities

Microsoft has fixed 23 vulnerabilities in its software products, including several considered critical, the company said on Tuesday in its monthly security patch report.

The most mortiyfing moments in network security history

The security holes, included in seven bulletins, affect Office, Windows, .Net Framework and Silverlight, and in the worst-case scenarios could give attackers control of affected systems, including the ability to run malicious code remotely on them.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


The first critical bulletin covers a vulnerability in Microsoft Office that could allow attackers to execute remote code on compromised systems. For that to happen, users would have to open an infected rich-text format (RTF) file. If successful, the exploit would give attackers the same usage rights as the current user.

The issue is labeled critical for all supported editions of Microsoft Word 2007. It is rated "important" -- the second highest severity level in Microsoft's four-level scale -- for all supported editions of Word 2003, Office 2008 for Mac and Office for Mac 2011, as well as all supported versions of Office Compatibility Pack. The security hole was privately reported to Microsoft.

The second critical bulletin involves 10 vulnerabilities in Office, Windows, .NET Framework, and Silverlight, seven of which were privately reported to the company. The most dangerous vulnerability would let attackers run code remotely on an affected user's machine if the user opens an infected document or is tricked into visiting a malware-laden webpage with embedded TrueType font files.

The problem is rated critical for all supported editions of Windows, .Net Framework 4 (except when installed on Windows editions for Itanium chips); and Silverlight 4 and 5. It's considered important for Office 2003, Office 2007 and Office 2010.

Commenting on this bulletin in a separate blog post, Jonathan Ness, from the Microsoft Security Response Center Engineering team, said that since fixing a vulnerability five months ago that was being exploited by the Duqu malware through malicious Office documents, Microsoft found that the problematic Microsoft code, win32k.sys, was in other products as well.

Fixing the vulnerabilty, an insufficient bounds check within the font parsing subsystem of win32k.sys, in the newly-discovered places led Microsoft to include several products in this bulletin and consolidate a variety of other fixes in it, according to Ness.

The third critical bulletin covers two privately-reported vulnerabilities in .Net Framework that could open the door for attackers to execute code remotely on the infected machine with the same level of rights as the affected user. For the exploit to be successful, users would need to visit an infected webpage using a browser that can run XAML Browser Applications (XBAPs).

This security update is considered critical for all supported editions of the Microsoft .NET Framework on all supported editions of Microsoft Windows.

The four bulletins labeled important include one that covers six Office vulnerabilities that could allow remote code execution if users open an infected Office file. This fix is considered important for all supported editions of Excel 2003, Excel 2007, Office 2007, Excel 2010, Office 2010, Office 2008 for Mac, and Office for Mac 2011, as well as for supported versions of Excel Viewer and Office Compatibility Pack.

Another important bulletin addresses one vulnerability in Visio Viewer 2010 that could give attackers the ability to execute malicious code remotely if users open an infected Visio file.

The third bulletin tagged as important deals with two security holes in Windows, including one affecting the TCP/IP component that could allow an attacker that logs on to a system to upgrade his user access privileges by running a specially crafted application. This hole is considered important for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

The final bulletin also involves Windows, specifically its Windows Partition Manager and a vulnerability that could let an attacker who gains access to a system to run a malicious application to elevate his user access privileges. The attacker needs to have valid credentials to access the system, and must log on manually on the affected machine. This issue is considered important for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

Users who have their machines set up to receive Microsoft's software patches automatically don't need to do anything. The fixes will be installed on their computers automatically. The updates can also be manually downloaded at the Microsoft Update and Windows Update sites.

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com