Votre meilleure source d'information et nouvelles environ secrets, Vista et matériel sur l'Internet

14 août 2007

Vous passez en revue actuellement les articles de Logiciel compatible de Vista de MS Windows écrit dessus 14 août 2007.

Écrivez les programmes avec le bloc-notes

J'avais employé le virus d'essai d'EICAR pour examiner différents produits d'anti-virus.

Le virus d'essai d'EICAR est une corde simple que vous pouvez coller dans le bloc-notes et économiser comme test.exe… puis si tout fonctionne correctement votre popup de volonté d'AntiVirus et vous dire qu'il a trouvé un virus.

Est c'à ce qu'il ressemble :

X5O ! P%@AP [4 \ PZX54 (P^) 7CC) 7} $EICAR-STANDARD-ANTIVIRUS-TEST-FILE ! $H+H*

Pour être honnête je n'avais pas vraiment regardé soigneusement ce dossier. Je l'avais employé pendant des années pour vérifier que l'anti-virus travaillait correctement.

Jusqu'à aujourd'hui - j'ai accidentellement exécuté l'essai. J'ai fait arrêter mon anti-virus et je l'ai exécuté de la ligne de commande. J'ai pensé qu'il était juste une corde aléatoire des caractères… mais c'est un programme fonctionnel ! Il a fait écho de nouveau à moi « EICAR-STANDARD-ANTIVIRUS-TEST-FILE ! »

Ainsi j'ai recherché et ai découvert que c'était un programme soigneusement ouvré de langage d'assemblage. Il a été conçu pour avoir seulement des op-codes de langage d'assemblage qui pourraient être représentés par les caractères d'ASCII standard. Si vous êtes intéressé… voici le code d'assemblée :

BRUIT HACHE
XOR HACHE, 214F
POUSSÉE HACHE
ET HACHE, 4140
POUSSÉE

Cliquez pour continuer de lire « écrivent des programmes avec le bloc-notes »

Écrit par Steve Wiseman dessus 14 août 2007 avec aucuns commentaires.
Lisez plus d'articles dessus logiciel.

Liens de Web d'ITsVISTA : 14 août 2007

Cliquez pour continuer de lire « des liens de Web d'ITsVISTA : 14 août 2007 "

Written by Joe on August 14th, 2007 with no comments.
Read more articles on DRM and PR and RAM and Review and Drivers and ATI and Security and Video and News and software.

Windows Media Player Flaw Lets Attackers “Skin†You

Severity: Medium

14 August, 2007

Summary:

Today, Microsoft released a bulletin describing two security vulnerabilities affecting Windows Media Player. By enticing one of your users into viewing a maliciously crafted skin file for Windows Media Player, an attacker could execute code on your user’s computer, potentially gaining complete control of it. If your users listen to or view media via Windows Media Player, you should download, test, and deploy the appropriate Microsoft patches as quickly as possible.

Exposure:

Windows Media Player (WMP) is the popular multimedia playback application that ships with Windows. WMP supports the use of skins, sets of scripts, art, media, and text files that create a new appearance for the media player.

In a bulletin released today as part of Patch Day, Microsoft describes two vulnerabilities that affect WMP 7, 9, 10, and 11. Though the vulnerabilities differ technically, they both involve WMP skin files, and have the same scope and impact. If an attacker can entice one of your users into viewing a maliciously crafted WMP skin, he could exploit either flaw to execute code on your user’s system, with your user’s privileges. If that user had local administrative privileges, the attacker gains complete control of that user’s

Click to continue reading "Windows Media Player Flaw Lets Attackers “Skin†You"

Written by bardissi on August 14th, 2007 with no comments.
Read more articles on Network Infrastructure and Windows Media Player and Microsoft and Non-Profit Technology and Home Computer Support and Windows XP and Business Computer Support and Windows Vista.

Critical MS Excel Vulnerability Affects PC and Mac

Severity: High

14 August, 2007

Summary:

Today, Microsoft released a security bulletin describing a vulnerability affecting Excel for Windows and Mac. If an attacker can entice one of your users into opening a maliciously-crafted Excel document, he can execute code on your user’s machine, possibly gaining complete control of it. If your company uses vulnerable versions of Microsoft Office or Excel, you should download, test and deploy Microsoft’s patches as soon as possible.

Exposure:

Microsoft’s security bulletin describes a new flaw affecting Microsoft Excel 2000, XP, and 2003 for Windows; and Excel 2004 for Mac. Excel doesn’t properly validate a particular index value in an Excel Workspace. Opening a specially crafted Excel worksheet could trigger this flaw and cause memory corruption vulnerability.

By enticing one of your users into opening a such a maliciously crafted Excel document, an attacker could exploit this flaw to execute code on your user’s system, with your user’s privileges. If your user has local administrative privileges, an attacker would gain complete control of his or her computer. To get your user to open the booby-trapped Excel file, the attacker might host it on a web site or send it via e-mail.

Solution Path

Microsoft has released patches correcting this

Click to continue reading "Critical MS Excel Vulnerability Affects PC and Mac"

Written by bardissi on August 14th, 2007 with no comments.
Read more articles on Network Infrastructure and Microsoft and Mac and Apple and Non-Profit Technology and Home Computer Support and Office 2007 and Windows XP and Business Computer Support and Windows Vista.

Internet Explorer Update: Two Patches Plug Four Critical Holes

Severity: High

14 August, 2007

Summary:

Today, Microsoft released two security bulletins describing four vulnerabilities in Internet Explorer. By tricking one of your users into visiting a maliciously crafted Web page or into opening a maliciously crafted HTML email, an attacker could exploit any of these new vulnerabilities to execute code on your user’s computer, with your user’s privileges. In the worst case, the attacker could gain complete control of the victim computer. If you use Internet Explorer in your network, you should download, test, and deploy the appropriate Internet Explorer patches immediately.

Exposure:

In two security bulletins (MS07-045 and MS07-050) released today as part of their monthly patch update, Microsoft describes four vulnerabilities in Internet Explorer (IE) versions 5.01, 6.0, and 7. Microsoft rates all four of the vulnerabilities “Critical” and each vulnerability affects all current versions of Windows, including Vista, to some extent.

The vulnerabilities fall into two general categories:

  1. Problems with interpreting .css files
  2. Improper input validation on several ActiveX controls

All of the vulnerabilities share the same repercussions. If an attacker can trick one of your users into visiting a specially crafted web page, he can exploit any of these flaws to execute code on your user’s computer, with your

Click to continue reading "Internet Explorer Update: Two Patches Plug Four Critical Holes"

Written by bardissi on August 14th, 2007 with no comments.
Read more articles on Network Infrastructure and Microsoft and Non-Profit Technology and Home Computer Support and Office 2007 and Business Computer Support and Windows Vista.

From Graphics to Gadgets, Critical Flaws Affect Windows

Severity: High

14 August, 2007

Summary:

Today, Microsoft released four security bulletins describing vulnerabilities that affect Windows and components shipping with it. A remote attacker could exploit the worst of these flaws to execute code on your Windows PC, potentially gaining complete control of it. For a table briefly summarizing which vulnerabilities affect which versions of Windows, see Microsoft’s Security Bulletin Summary for August and expand the section, “Affected Software and Download Location.” If you manage a Windows network, you should download, test, and deploy the appropriate Windows patches throughout your network as soon as possible.

Exposure:

Microsoft’s four security bulletins detail vulnerabilities found in, or affecting, components of Windows. Each vulnerability affects different versions of Windows to a different extent. The summary below lists the vulnerabilities from highest to lowest severity.

MS07-046:Graphics Device Interface (GDI) Remote Code Execution Vulnerability

The Graphics Device Interface (GDI) that ships with all current versions of Windows suffers from an unspecified “code execution vulnerability” involving the way the GDI handles specially crafted images. By enticing one of your users into opening and viewing a malicious image (for example, one from a web site or attached to an email), an attacker could exploit this

Click to continue reading "From Graphics to Gadgets, Critical Flaws Affect Windows"

Written by bardissi on August 14th, 2007 with no comments.
Read more articles on Network Infrastructure and Microsoft and Non-Profit Technology and Home Computer Support and Office 2007 and Business Computer Support and Windows Vista.

« Older articles

No newer articles