Tag: Security
Microsoft released no less than eight security bulletins for the various supported releases of Windows client and server operating systems, including for the latest service packs of Windows Vista and Windows XP. Out of the total of patch packages impacting Windows, half feature a maximum severity rating of Critical, with the remaining four being rated as Important. The security updates are available through Windows Update since August 11, 2009, and customers are advised to deploy the patches as soon as possible in order to bulletproof their systems against attacks.
“Of note, Microsoft released MS09-043 to help protect customers from attacks on the Office Web Components vulnerability previously addressed by Security Advisory 973472. I also wanted to let you know that MS09-037 addresses five privately reported vulnerabilities in Microsoft Active Template Library (ATL). Security Advisory 973882 has been updated with a reference to MS09-037. Additionally, Microsoft has released Security Advisory 973811 to include a non-security update that enables new protection technology on the Windows platform,” revealed Christopher Budd, security response communications lead for Microsoft. Read More»
Posted in Windows Vista, Windows XP | No Comments »
Whether you’re dealing with users in your work environment or kids at home, being able to control what applications a user can use can prevent a lot of hassle and headaches. Windows 7 includes a new tool, called AppLocker, that lets you do just this by creating a policy to specify exactly what applications a user is allowed to run.
To access this feature, click start and enter Gpedit.msc. Then navigate to Computer Configuration | Windows Settings | Security Settings | Application Control Policies. Expand the Application Control Policies node and highlight AppLocker.
Here you can configure Executable Rules, Windows Installer Rules, and Script Rules. For example, highlight the Executable Rules node and right-click to select Create New Rule. You can then create a rule allowing or denying access to an executable based on such criteria as the file path or publisher.
And in case you’re in a hurry, AppLocker will let you apply default or automatic rules. There are a lot of options exposed in AppLocker—too many to cover in a short tip—so you’ll have to play around with it some to get a better idea of just how much this tool can do. Read More»
Posted in Windows 7 | No Comments »
You can see whether your current passwords you do use more than one, right? are rated “strong” by using Microsoft’s online Password Checker. I bet you’ll be unpleasantly surprised by the results.
The three keys to strong passwords are length, randomness, and use of different types of characters. Each additional character multiplies the potential combinations a brute-force attack must try.
Random passwords use upper- and lower-case letters, numbers, and symbols. When at least three of these four categories are used, an eight-character password should suffice in most instances. According to the FrontLine security site, such a password would take a century or more to crack by a hacker using a single PC. The eight-character standard is also the minimum the Microsoft Password Checker deems “strong.” Of course, the more characters in your password, the safer you’ll be.
If you wish to create your own password, use a sentence or phrase you can recall easily and then tweak it for each account. Read More»
Posted in Computer | No Comments »
The disclosure of a back door allowing bad guys to repeatedly guess Gmail passwords should remind us all to protect our accounts with long and strong character strings.
There’s a straightforward way to protect your online accounts use signin phrases that are easy for you to remember but hard for others to guess.
The latest vulnerability affecting Gmail accounts was recently revealed by security researcher Vicente Aguilera DĂaz in a posting on the Full Disclosure security list. (Aguilera previously revealed a Gmail flaw known as session-riding, which Google subsequently fixed, as reported by WS contributing editor Scott Spanbauer)
According to Aguilera’s new security alert, Google allows anyone with a Gmail account to guess another Gmail user’s password 100 times every two hours, or 1,200 times per day. No “captcha” keeps hacker bots from guessing passwords in this way. Worst of all: If a hacker controls, say, 100 Gmail accounts, 120,000 guesses can be made per day. Because Gmail accounts are free, many hackers control far more than 100 accounts, of course. Read More»
Posted in Internet, Software | No Comments »
If you find yourself with very long startup times after upgrading to Firefox 3.5 (from say 10 seconds to the order of minutes), you may be experimenting a bug due to a change in how Firefox 3.5 gets the randomness it needs for security purposes on Windows.
The procedure involves scanning some temporary folders looking for bits normally added by OS and other applications operations. Firefox 3.5 looks for more files and deeper (more subfolders) for increased randomness, but it has led to unexpected results for users with too many temporary folders or files resulting in slow startups.
Try builds are still being generated with fixes to this bug, but users report a noticeable improvement after deleting their temporary folders and Internet Temporary Files (generated by Internet Explorer).
To clean temporary folders, check and delete all files [you can, some may be in use] from these:
Read More»
Posted in Firefox | 2 Comments »
If you are are the sole user of your computer and are annoyed by the Ubuntu login window during every startup, it is better to remove it. Removing the login window will not actually remove the login password, but it will just skip the step during system startup.
Note: Make sure that you do not remove the login window on a public computer.
To remove it, first go to Login Window utility from System > Administration > Login Window.
You can also load it by pressing Alt + F2 and typing gksu /usr/sbin/gdmsetup in Run Application box.
This will open the Login Window Preferences window. Now, to enable auto login, go to Security tab and check Enable Automatic Login and enter user name for your system. You can also set delay in auto login by checking Enable Timed Login and selecting time in seconds. If you enable it, your system will wait for specified number of second before logging you. Read More»
Posted in Linux | No Comments »
Come June 23rd, 2009, Microsoft will open up codename Morro, its upcoming free security solution designed to replace Windows Live OneCare 2.0, to the public. The Redmond company offered official confirmation that codename Morro had been rebranded as Microsoft Security Essentials, and that the first Beta for version 1.0 was ready to debut next week. Access to Microsoft Security Essentials 1.0 Beta will be granted to testers in the United States, Brazil and Israel, the software giant informed. The information provided by Microsoft comes after screenshots of Morro made it into the wild, followed by the actual bits, leaked a couple of days ago.
“The Microsoft Security Essentials Beta will be made publicly available in Brazil, Israel and the U.S. starting June 23 at about 9am PDT from www.microsoft.com/security_essentials, and general availability is scheduled for later this calendar year,” a Microsoft spokesman told pctipsbox. Read More»
Posted in Software | 1 Comment »
Many Pctipsbox readers use Firefox because it suffers from fewer security holes than IE and most people don’t need .NET features so I’m publishing in my free column today the following steps to remove Assistant 1.0 from Firefox:
Step 1. Check whether the .NET Framework Assistant is installed. You may or may not have Assistant 1.0, even if you installed .NET Framework 3.5 SP1, so check this first. In Firefox, pull down the Tools menu and select Add-ons. In the Add-ons dialog box that appears, if you don’t see .NET Framework Assistant, the add-on is not installed. In that case, you don’t need to do anything further (except close the dialog box).
Step 2. Remove or disable the add-on. If you do find the extension, I recommend that you remove it to reduce your vulnerability to possible security flaws. Choose one of the options shown below.
• Best option: Install the Microsoft fix. On May 6, with little publicity, Microsoft posted an update for .NET Framework 3.5 SP1. Installing this update enables Firefox’s Uninstall button for the add-on. To install the official update, visit Microsoft’s download page. Read More»
Posted in Firefox | 2 Comments »
Put a “Pin Up” of the Folders You Use Most.
Windows® 7 allows you to “pin up” the folders you use most on your taskbar. Simply hold your mouse over the
favorite folder, right click, and drag it onto the taskbar. Windows 7 automatically pins itself to the Explorer Jump List. To open the folder, right click on the Explorer icon and select the folder you want.
Double-Up Your Windows.
When working within an application, sometimes you just want more of a good thing. To open another window of the same application (assuming the app can run more than one instance), simply hold
Shift and click the taskbar icon. You can also middle-click your third mouse button for the same result.
Clear, Crisp Display—It’s In Your Control.
Windows 7 makes it easy for you to adjust your display settings, making text and images easier to view in all the various locations where you work on your computer. Your laptop display may look fine at work but a little dark at home. Adjust the text and image settings easily with two snappy applets: ClearType Text Tuning and Display Color Calibration. Run cttune.exe and dccw.exe, or look them up in the Control Panel. Read More»
Posted in Windows 7 | No Comments »