How to Prepare for Microsoft Certifications Earning a Microsoft Certification could be the beginning or continuation of an enduring career that will include the strengthening of their technical skills, collaboration with other professionals ...

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

50% discount on Microsoft Certifications to ... Hello guys, Prometric is providing for students a 50% discount on Microsoft certifications. The promotion is valid until June 30, 2010. For more details visit the ...

Readmore

Book - Administration and Maintenance Environment ... Hello people, For those who are preparing for the exam 70-290 book Administration and Maintenance Environment Microsoft Windows Server 2003 is a great material. I recommend.

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

twitter

Twitter Facebook

Why Microsoft Launches All Months Security Patches and Updates?

Category: Security Bulletin , Safety

Hello people,

As you know most users of Microsoft systems, every second Tuesday of each month Microsoft releases security patches, critical updates, etc.. But does everyone understand because Microsoft releases monthly security patches?

Unfortunately many companies take days and / or even months to apply patches that fix the vulnerability found s. Generally, the vulnerabilities allow an attacker to execute remote code and get control of the system with administrative permissions.

Continue Reading

Firefox 3.6.3 fixes critical flaw

Category: Security

The Mozilla Foundation is distributing a fix for a flaw in the Firefox 3.6 browser, which could allow remote code execution on the user machine.

In a post pulicado on the afternoon of Thursday (1/4), the site of development of Mozilla , the organization explains that earlier versions of the browser were not affected by the bug, but recommends that all users upgrade to the new Firefox 3.6.3 as soon as possible.

On March 18, Mozilla confirmed the existence of a critical vulnerability in the newest version of Firefox, and said he would release the patch later this month. Until then, the partial solution was available in a beta version of Firefox 3.6.2.

"We strongly recommend that all Firefox users upgrade to this latest release," Mozilla said. "If you already have Firefox 3.6, you will receive an automatic update notification within 24 to 48 hours. This update can also be applied manually by selecting "Check for Updates ..." from the Help menu, "said the statement.

Firefox 3.6.3 is also available for download at http://www.firefox.com for the operating systems Windows, Linux and Mac

Source: http://idgnow.uol.com.br/seguranca/2010/04/02/firefox-3-6-3-corrige-falha-critica/

End of Daylight Saving Time

Category: Security , Windows Server 2003 , Windows Server 2008 , Windows Server 2008 R2 , Windows Vista , Windows XP

header h verao Término do Horário de Verão
Set the DST in Windows

According to the Decree No. 6558 of September 8, 2008, published in the Official Gazette, from 0:00 pm on October 18 (Sunday), 2009, entered into force Daylight Savings Time in Brazil, lasting until the February 21, 2010, applies to the South, Southeast and Central Oeste.Com order to avoid inconvenience to you, Microsoft offers tips here on how to make manual changes to correctly reflect the start and end of Time Summer on your computer .

Important recommendations from Microsoft:

  • Install Windows Update December. Users who already have the latest update does not need to do this installation. If Windows Update does not have this on their machines, ensure that the following hotfix installed: KB 976098.
  • See the recording of the event "Summer Time in Brazil (2009/2010) - How to prepare" via Webcast. In this webcast will be shown how to avoid possible impacts of the end of Daylight Saving Time in Windows, Exchange and Outlook.
  • Customers who require technical assistance in Daylight Saving Time 2009/2010 can contact your Technical Account Manager or directly with Microsoft support, by sending an email through the " Contact Us "or by phone (11) 4706 - Capital Region for 0900 and Sao Paulo or 0800 761 7454 for other regions of the country.

CAUTION: Always install the latest Windows Update to ensure your best experience with the Windows platform.

Our technical staff and service is available to support them in case of doubt the information listed above.

Here's how to keep your computer ready to receive the correct DST 2009/2010 as well as other important updates
For Windows Vista or Windows 7

  1. Run Windows Update from the Start button:
    update01 Término do Horário de Verão
  2. Click View available updates in the text to select which optional updates, beyond the important, you want to install. Then click the Install Updates button and follow the next instructions in the wizard.
    update02 Término do Horário de Verão
  3. On the same screen, click Change Settings to set a frequency automatic installation of updates.

For Windows XP

  1. Click the Start button -> All Programs -> Windows Update or visit HTTP :/ / update.microsoft.com .
    update03 Término do Horário de Verão
  2. Express Click to install high priority updates or Custom button to review other optional updates. Follow these instructions in the wizard.
    update04 Término do Horário de Verão
  3. Accept the suggestion to turn on automatic updates if you have not performed this procedure.
    update05 Término do Horário de Verão

Source: http://www.microsoft.com/brasil/windows/verao.mspx

Microsoft fixes 15 flaws, including malicious critical bug

Category: Security

Microsoft released today (10/11) a bundle of patches for 15 vulnerabilities s Windows systems and Windows Server and applications of Excel and Word, including one that will probably be exploited quickly by hackers.

None affect the new operating system Windows 7 .

The 15 flaws fixed by six security updates released today represent less than half the record for the package last month that Microsoft patched 34 bugs in 13 separate bulletins.

Of the 15 holes today, three were classified as "critical" by Microsoft. The remaining 12 were considered "important", which is the level immediately prior to the system of four levels of classification adopted by the company.

Bug Priority
Experts agree that users should focus first the MS09-065. This update, which is a critical, affects all versions of Windows still entitled to support, with the exception of Windows 7 and Windows Server 2008 R2.

"The vulnerability of the core of Windows is by far the most important," said Andrew Storms, director of security operations at nCircle Network Security.

"This gap can use Internet Explorer as an attack vector, and this is one case where the user will not be notified or prompted. This scenario is quite a drive-by attack. "

Richie Lai, who is director of vulnerability research at security company Qualys, agreed. "Anyone running Internet Explorer (IE) is at risk here, even though the flaw is not in the browser, but in kernel mode driver Win32k."

In a three
Storms and Lai refers to a bug marked critical in MS09-065, which is actually a trio of vulnerabilities .

According to Microsoft, the Windows kernel improperly interprets sources like Embeded OpenType (EOT), which are a compact form of fonts designed for web pages. EOT fonts can also be used in Word and PowerPoint.

Thus, the hackers also could launch malicious attacks by attaching documents to Word and PowerPoint to e-mail, which would mistakenly opened by users.

As an alternative to applying the fix, users can easily block the most likely attacks by disabling IE's support for embedded fonts. "It's a low-impact," explains Lai. "The worst that can happen is that some sites might look ugly."

But His advice would still leave PCs open to attack via malicious Word documents and PowerPoint, an issue that Microsoft also made in the security bulletin.

Error-free
As Windows 7 and Windows Server 2008 R2 are not the target of MS09-065, Storms and Lai assumed that Microsoft caught the bug before it wrapped up the final code, or RTM (Release To Manufacturing) system operating, and only now taken steps to plug the gaps in Windows 2000, XP and Vista and Server 2003 and 2008.

"It's likely that Windows 7 Release Candidate (RC) is vulnerable," said Storms, noting that Microsoft's policy of not providing security updates for previous versions of an operating system after the final version is released.

"That's why you do not see Microsoft patching Windows 7 RC or Beta," said Storms. "Anyone who has run the RC should take heed and upgrade to the RTM."

But while Storms speculated that Microsoft knew the EOT font flaw was a security issue and waited until now to patch older Windows Lai defends the thesis that until recently Microsoft had no idea that the problem also reached earlier than Windows 7.

"I think they fixed this bug as part of the code sanitization during the development cycle (Windows 7). Only recently it became public, and then they fixed the other Windows. "

Public recognition
Microsoft recognizes that information about the EOT vulnerability became public before the patch released today.

"Our initial report was provided through responsible disclosure, the vulnerability was later disclosed publicly by an independent entity," says the notice that accompanied the report.

Storms thinks hackers will exploit the vulnerability of EOT quickly.

"It's something that deserves to be followed in the weeks to come, not only because of its novelty, but also because it can be exploited through IE, which is an easy path, as well as through Word and PowerPoint documents," he said.

Microsoft also issued critical updates for Vista and Server 2008 and Windows Server 2000.

In the latter, the problem is a bug in the implementation of the License Logging Server, a tool originally designed to help manage client-access licenses server (CAL).

Storms recommends that users of these systems urgently implement the fix, even if the machines are probably well protected.

"Windows 2000 Server has the logging server enabled as default, but such systems are usually behind multiple firewalls, and people that run Windows 2000 know that it is an older version and will act accordingly."

Windows and Mac
Excel and Word also received updates today. Eight vulnerabilities were addressed in MS09-067 for Excel and Word in the MS09-068. Both updates also affect Issues Office 2004 and Office 2008 for Mac

"These are the type of file format vulnerabilities we've seen many times in the past," said Storms, then remembering that the bugs ruin the older binary formats and not the new XML-based formats that debuted in Office 2007 Windows and Office 2008 for Mac

The security updates this month can be downloaded and installed via Microsoft Update and Windows Update, as well as through Windows Server Update Services.

Vulnerability Analysis

Category: Articles , Security

Hello people,

I just posted the article Vulnerability Analysis , which aims to demonstrate how to make a Vulnerability Analysis in computing environment quickly and easily.

To read the complete article visit the link below:

http://www.guiacissp.com.br/index.php/analise-de-vulnerabilidade/

Continue Reading

Installing Service Pack 2 on Windows Server 2008

Category: Articles , TechNet WIKI , Windows Server 2008

Goal

This article aims to demonstrate how to install Service Pack 2 on Windows Server 2008 quickly and easily.

Applies to

  • Windows Server 2008 all versions.

Read the full article at: http://social.technet.microsoft.com/wiki/contents/articles/2423.aspx

Luciano Lima
[Enterprise Security MVP] - [MCSA Security] - [Security MCSE]


www.guiamcitp.com.br
www.ticlassificados.com (New)

Adobe warns of serious flaw in Flash and promises fix

Category: Security

Committed to PDF files sent by e-mail or malicious Web sites can exploit flaw in component of the Flash and Reader.

The American company software Adobe Systems Inc. acknowledged a critical vulnerability that affects Reader and Flash programs and could expose Internet users to attack. The company said on Wednesday (22/7), the United States, which will distribute the correction between days 30 and 31 July.

According to security experts, the problem was detected seven months ago. In a security advisory posted on its website , Adobe confirmed that there is a vulnerability in the critical current versions of Flash Player (v9.0.159.0 and v10.0.22.87) for Windows operating systems, Mac OS and Linux as well as the component 'authplay.dll' built-in Adobe Reader and Acrobat v9.x for Windows, Mac OS and Unix.

The component 'authplay.dll' has the function of interpreter between Flash content embedded in PDF file format, Adobe, and is present on any machine equipped with Reader and Acrobat software.

The company said it will fix all versions of Flash on June 30, as well as Reader and Acrobat until July 31.

Until a patch is released, Adobe says that users can delete or rename the component 'authplay.dll', or disable the rendering of Flash to avoid attacks by corrupted files in PDF. The company also recommended that users be cautious in access to suspicious sites.

The site's Emergency Response Center of the United States (US-CERT), part of the Department of National Security of the country, issued instructions to clear the affected component of Flash on Windows machines, Mac OS and Linux.

According to security companies, committed documents in PDF format have been exploited by attackers and targeted attacks using malicious sites.

"The PDF is only a vehicle for the attack," explained the development manager of security firm Symantec, Marc Rossi. "But you do not need Flash or Reader on your system," commented Rossi. He said it was possible to exploit the flaw through a Flash content posted on a website.

The number of flaws exploited in attacks is still low, according to Rossi. However, the expert indicates that the threat can grow using e-mails with corrupted files in PDF. "When the code accesses the system - especially on Windows machines - it connects to a site to download a file like a Trojan horse on the compromised system.

The chief researcher for security company Purewire, noted that the flaw in Flash was recorded in the database of bugs in Adobe's 31 December 2008, but the actual malicious code that has exploited the vulnerability was recently created on July 9.

Attacks on unpatched Windows bug will increase, says Symantec

Category: Security

The exploitation of a vulnerability in Windows 2000, XP and Server 2003 has been added to a new kit for online attacks, the company warned of Symantec security products.

The bug in DirectShow component that Microsoft discovered a month ago, has been widespread among crackers, which means that attacks will increase soon, said Symantec researcher Liam Murchu.

The bug has been exploited in phishing sites. When the victim is redirected to a malicious URL that hosts the DirectShow attack code, files with the extension. Avi files are downloaded to the victim's system, allowing for later downloading and installing a Trojan horse, the victim's PC.

Microsoft has not released a fix for the problem, although attacks that exploit the bug has been tracked since May. The company's next correction should take place July 14.

Meanwhile, Microsoft's recommendation is to disable QuickTime, Apple's media player, which has a flaw in the analysis of the DirectShow component of DirectX.

pixel Ataques a bug não corrigido do Windows vão aumentar, diz Symantec