KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:


Search in KezNews.com:







Should Microsoft downgrade Vista vulnerabilities?

The man who wrote the book on Microsoft's highly rated SDL (Security Development Lifecycle) believes buffer-related security vulnerabilities found in Windows Vista should be downgraded because of back-up mitigations built into the operating system.
windows - comments - 12.3.2007

New Round of Vista SP1 and XP SP3 Vulnerabilities

Microsoft is cooking patches for a new round of vulnerabilities impacting its Windows client and operating systems and Server software, including Windows Vista Service Pack 1 and Windows XP Service Pack 3.
windows - comments - 4.7.2008

Microsoft delivers two patches for three vulnerabilities; Plugs Vista hole

Microsoft on Tuesday delivered one “critical” addressing two vulnerabilities in XP and Vista and one “important” vulnerability in Windows 2000, XP and Windows Server 2003.
windows - comments - 8.1.2008

Windows 7 RTM Safe from Vista and XP Critical Vulnerabilities

When it launched Windows Vista back in January 2007, Microsoft made sure to emphasize added security as part of the Wow.
download - comments - 12.8.2009

Microsoft Patches Critical Vista SP1 and XP SP3 Vulnerabilities

It's patching time yet again for Microsoft, as the software giant made available no less than eight security bulletins on December 9, 2008, designed to plug vulnerabilities in a range of products including Windows Vista Service Pack 1 and Windows XP Service Pack 3.
windows - comments - 10.12.2008

New Security Solutions Live in Time for Vista SP1 and XP SP3 Vulnerabilities

October 14 was synonymous not only with the availability of a new release out of the Microsoft monthly patch cycle but also with the introductions of a couple of new security from the Redmond company: the Microsoft Active Protections Program (MAPP) and Exploitability Index.
download - comments - 15.10.2008

Microsoft Patches 23 Vulnerabilities

As part of its monthly security update cycle, Microsoft on Tuesday released a dozen security bulletins. Nine of them are tagged critical, the company's highest severity rating. The alerts give details of 20 flaws in Windows and three in Office, all of which Microsoft has now fixed.
microsoft - comments - 9.8.2006

Should Microsoft start paying for vulnerabilities?

Hackers are starting to agitate for Microsoft to start paying for information on security flaws found in its software products.
microsoft - comments - 16.3.2007

ActiveX Is Vulnerable to Attacks Even Without Vulnerabilities

Internet Explorer users are vulnerable to attacks targeting ActiveX, even when ActiveX is vulnerability-free, claims security company Symantec.
microsoft - comments - 11.8.2008

Windows XP SP3 Gets Its First Taste of Vulnerabilities

The third and final service pack for Windows XP is not even out the door, and security company Symantec has already warned of a security vulnerability impacting XP SP3.
windows - comments - 7.4.2008

Microsoft drops 6 bulletins, fixing 11 vulnerabilities

Microsoft’s Patch Tuesday train arrived today with six bulletins covering at least 11 vulnerabilities, most carrying the company’s highest severity rating.
microsoft - comments - 11.7.2007

Microsoft Patch Tuesday Fixes 10 Vulnerabilities

As expected, yesterday Microsoft rolled out five "critical" and three "important" patches for Windows Server 2008, Vista, Office, Internet Explorer and other software as part of its regularly scheduled Patch Tuesday release.
microsoft - comments - 9.4.2008

How to Install Vista Language Packs MUI on all versions of Vista + video tutorial

Microsoft Windows Vista Home Basic, Vista Home Premium, and Vista Business versions of the Microsoft licensing restrictions can only preserve a language!
download - comments - 23.9.2008

The Vista Built-in Super Administrator Account Has Survived in Vista SP1

Windows Vista Service Pack 1 is designed to evolve the RTM version of the latest Windows client from Microsoft, made available in November 2006 to business customers, and in January 2007 to the general consumers.
windows - comments - 15.2.2008

Vista SP1 Is Out, XP SP3 Old News, the Pink Edition of Vista Is In

Windows Vista Service Pack 1 is now nothing more than water under the bridge, now that the service pack was released to manufacturing on February 4, 2008, shipping to general users on March 18.
windows - comments - 27.3.2008

Tell Hasta la Vista to XP - Time to Upgrade to Vista SP1

Like it or not, this is the right time not only to upgrade to Windows Vista Service Pack 1 but also to tell hasta la vista to Windows XP.
windows - comments - 30.6.2008

Instant Change Vista Product ID with Vista ProductID Changer

In past we have reviewed number of application to recover product key like Product Key Finder, WinGuggle, Windows product Key Finder.
download - comments - 1.11.2009

Vista SP1 RC1 Flies Past Vista RTM and Windows XP SP2

Despite the fact that Microsoft has expressed its official position regarding testing Windows Vista Service Pack 1 ahead of its finalization, there is simply too much of a hunger for the service pack.
windows - comments - 27.12.2007

Vista SP1 Won't Resolve the 4 GB RAM Limitation of 32-bit Windows Vista

32-bit Windows operating systems, and Windows Vista makes no exception whatsoever to this rule, are limited in terms of the amount of system memory that can be addressed to no more than 4 GB.
windows - comments - 4.1.2008

Vista Loader 2.1.3 - Windows Vista Activator 2008 Support SP1 with No Boot String

Vista Loader is one of the most successful Vista activation crack available to date, second only to physical modify (hardmod) the BIOS to include SLIC table to make BIOS Vista activation-compliant.
download - comments - 15.5.2008

x64 Vista SP2 JPG Rendering Performance Inferior to x86 Vista SP2's

The JPG rendering process on 64-bit flavors of Windows Vista Service Pack 2 is inferior to that on the 32-bit variants of the operating system.
windows - comments - 10.6.2009

Microsoft to Kill the Grace Timer and OEM BIOS Windows Vista Cracks with Vista SP1

With the advent of Windows Vista, cracks also became available being designed to bypass the activation process of the operating system.
windows - comments - 4.12.2007

New Vista OEM Activation Hack - Vista Boot by gkend

Thanks to Steve Jobs for this article on his blog and to our forum members to clecha, Nighthief and fitterphil120 for most of the findings. One again the “Chinese” come up with a new method to trick out the Vista Activation. We have seen Softmode and VistaLoader, however “ Vista Boot by gkend” does promise even more.
download - comments - 21.5.2007

Windows Vista on Super Nintendo, As Real As Vista on PSP

We're puzzled and confused... How can a console that's at least ten times less powerful than the acclaimed PSP cope with Windows Vista's requirements?
windows - comments - 15.8.2007

Vista RTM vs. Vista SP1 - Office 2007 benchmarking

Enough with benchmarking the OS - let’s see if Office 2007 is any faster on Vista SP1.
windows - comments - 26.2.2008

Microsoft Says Vista SP1 Needs to Speak the Same Language as Vista RTM

Microsoft says that Windows Vista Service Pack 1 needs to speak the same language as the RTM version of the latest Windows client. Otherwise there's no game.
windows - comments - 2.4.2008

Vista SP1 to Cure the Vista RTM Wow Hangover

When Windows Vista was unleashed in January 31, 2008, Microsoft was promising performance, security, innovation, all wrapped up under an umbrella of a Wow user experience.
windows - comments - 11.4.2008

Vista-For-Free coupon with Vista ready PC's

Microsoft and the world's leading PC vendors have reached an agreement to promote the long-awaited Vista OS by offering PC buyers worldwide a free upgrade coupon, as a way of encouraging them to buy a Vista-capable PC as early as possible, according to market sources, citing information leaked from Taiwan-based PC makers.
windows - comments - 11.10.2006

Can Vista SP1 help polish Vista’s tarnished image?

Call it complaining. Call it whining. The end result is the same: Windows Vista’s image is tarnished. And it’s corroding more and more rapidly as the weeks are going on. Thanks to pacpis for this news.
windows - comments - 21.8.2007

Vista SP1 Features the Same Sins as Windows Vista

Windows Vista Service Pack 1 comes with the same sins as Windows Vista. The service pack is not even out the door, and is already putting users at risk.
windows - comments - 16.1.2008

Four New Browser Vulnerabilities Surface

Four new unpatched vulnerabilities have been published for Internet Explorer and Firefox, with two coming for each browser...
betanews.com - 05.06.2007

Top 14 VoIP vulnerabilities

How are VoIP networks weak and vulnerable to attack and catastrophic failure? Securing VoIP Networks, the new book by Peter Thermos and Ari Takanen, looks at VoIP infrastructure and analyzes its vulnerabilities much as the Open Web Application Security Project did for Web-related vulnerabilities and Mitre did with its Common Weakness Enumeration dictionary for software. And its about human failings, too, not just technology problems.



Here are the top VoIP vulnerabilities explained in Securing VoIP Networks...




winbeta.org - 02.10.2007

Vista Security Report Raises More Doubts Than It Relieves

A status report released yesterday by the director of Microsoft's Security Technology Unit contends that, over the first six months of its shelf life, Windows Vista was proven more secure than its competitors during their first six months, and more secure than Windows XP after its debut, by virtue of the sole fact that fewer Vista vulnerabilities were entered into the National Vulnerability Database...
betanews.com - 22.06.2007

WabiSabiLabi may close 0day auction site

WabiSabiLabi may shut down its online marketplace for security vulnerabilities, focusing instead on the line of OneShield unified threat management (UTM) appliances it developed with Italian defense company EuroTech.

Last year, WabiSabiLabi opened an online auction site for unpatched security vulnerabilities, also called 0days. The company's stated aim was to provide a market that would allow independent security researchers to earn a living from the vulnerabilities they discover. To prevent vulnerabilities from ending up in the hands of criminals, only qualified buyers are permitted to use the WabiSabiLabi auction site.

While security companies routinely pay researchers for vulnerabilities and then keep this information under wraps, some believe researchers should first disclose such vulnerabilities to vendors free and, when a patch is released, make details of the vulnerability publicly available, a practice known in the security community as ethical disclosure.

Read full story.....
neowin.net - 30.10.2008

Apple Fixes 50 Vulnerabilities in Mac OS, iPhone

Apple released a bevy of patches for the Macintosh operating system, as well as its first patch for the iPhone late Tuesday. Almost fifty separate vulnerabilities have been fixed as a result...
betanews.com - 01.08.2007

Microsoft better at patching XP than Vista?

A Microsoft security executive released data Thursday showing that, six months after shipping Windows Vista, his company has left more publicly disclosed Vista bugs unpatched than it did with Windows XP. In total, Microsoft has patched 12 out of 27 disclosed Vista vulnerabilities in the six months after it first shipped last November. During XP's first six months, Microsoft's security team patched 36 out of 39 known bugs. The data was published by Jeff Jones, a Microsoft security strategy director, who said that overall, Vista was doing better than XP. "Windows Vista continues to show a trend of fewer total and fewer high-severity vulnerabilities at the six month mark compared to its predecessor product, Windows XP," he wrote.

Jones didn't address the larger number of unpatched vulnerabilities, but he did note most of the unpatched Vista bugs were not critical. Microsoft had left only one high-severity Vista vulnerability unpatched during the period. At the end of XP's first six months, there were two high-severity bugs that were unpatched. Microsoft patched 23 high-severity XP bugs during its first six months, compared with only one high-severity Vista flaw. Jones argued that Vista had a lower number of vulnerabilities than competitive operating system products such as Red Hat Enterprise Linux and Mac OS X.


neowin.net - 23.06.2007

Hackers will feed on Vista in 2008, says McAfee

Microsoft Corp. will face more than 40 vulnerabilities in Windows Vista next year, as the operating system climbs past the 10% market-share milestone and malware authors really start to find flaws, a McAfee Inc. analyst said today.



"Most of the current malware has ignored Vista," said Craig Schmugar, a threat researcher at McAfee's Avert Lab -- but that's not because the operating system has been frustratingly secure. In fact, Schmugar argued, Vista has been a worthwhile target in the first year of its release.



"These people make their living writing malware or attacking users," he said. "They're driven by financial motivation, and only when market share has an impact will they really work on Vista."



At some point in 2008, Vista will own a tenth of the desktop operating system market, Schmugar predicted. The milestone should mark the beginning of concerted efforts by attackers to root out vulnerabilities in the newer operating system. "Although the huge market share that XP has means will still be profitable there for years to come, Vista at 10% will put it on their radar," he said.




winbeta.org - 27.11.2007

H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk

This report looks at all of the vulnerabilities fixed by Apple, Microsoft, Red Hat and Ubuntu during the first half of 2008. At the vendor level, the report examines all vulnerabilities as well as Days of Risk (DoR) associated with those vulnerabilities. The report further drills down to examine just those issues affecting the commonly installed desktop operating system components.




winbeta.org - 27.10.2008

Adobe Patches Flash Vulnerabilities

Adobe this week fixed critical vulnerabilities within its Flash Player that could allow an attacker to take control of an affected system. According to a company advisory, all current versions of Flash 9, 8 and 7 are affected by the problem, which relates to not validating certain input...
betanews.com - 12.07.2007

Security vuln auction site pulls in research

A controversial marketplace for security exploits and vulnerabilities said it has exceeded expectations with the submission of more than 150 vulnerabilities in its first two months of operations.



WabiSabiLabi encourages security researchers to sell their findings to vetted buyers. Herman Zampariolo, chief exec of WSLabi which runs the WabiSabiLabi marketplace, said that the quality of the submitted vulnerabilities is as important as their quantity.



Vulnerabilities on the marketplace have had selling prices ranging between 100 to 15,000 euros each. So far 1,000 sellers (researchers) have registered on the site.




winbeta.org - 13.10.2007

Microsoft Patches Multiple Excel Flaws

Microsoft rolled out two patches for vulnerabilities as part of its monthly Patch Tuesday effort, fixing six vulnerabilities in Microsoft Office, and a less significant but still dangerous flaw within Windows. Primarily affected by the problems is Excel...
betanews.com - 15.03.2006

Patch Tuesday: MS Fixes Glitches in IE, Multimedia, Vista

Microsoft released seven security bulletins that addressed 11 vulnerabilities on its Dec. 11 Patch Tuesday. Of those, three bulletins containing seven client-side vulnerabilities are rated as critical and affect nearly all major Microsoft operating systems: 2000, XP, 2003 and Vista. " The more alarming vulnerabilities are those in Windows Media Format Runtime and Internet Explorer, since a successful exploit could occur when a user visits a malicious Web page or when viewing a malicious e-mail. Neither issue requires any further interaction by the victim to exploit, compounding the problem, " Ben Greenbaum, senior research manager for Symantec Security Response, said in a release.

Of the vulnerabilities patched was an issue in which a Macrovision driver incorrectly handled configuration parameters, allowing an attacker to take complete control of a vulnerable system and install programs, view, change or delete data, or create new accounts with full user rights, Microsoft said in its advisory MS07-067. Another important security advisory, MS07-066, involves a vulnerability in the Windows kernel that affects Vista. The flaw is an elevation of privilege vulnerability in the way that Vista's Windows kernel processes certain access requests. The vulnerability could lead to an attacker taking complete control of a target system.


neowin.net - 12.12.2007

5,198 Linux, Windows OS Flaws in 2005

The United States Computer Emergency Readiness Team released its year-end summary of computer vulnerabilities. While Windows is regarded as the most insecure operating system, the US-CERT found four times as many vulnerabilities specifically related to Unix and Linux...
betanews.com - 04.01.2006

Apple releases seven QuickTime fixes

Apple has patched seven vulnerabilities in the latest version of QuickTime affecting the Windows and MacOS X versions of the media player software. Each of the vulnerabilities affects users of MacOS 10.3.9, 10.4.9 and 10.5 as well as Windows XP and Vista. Six of the vulnerabilities could allow attackers to remotely execute code on the targeted machine.


neowin.net - 09.11.2007

US Treasury says IRS still hasn't fixed vulnerabilities in tax processing systems

Vulnerabilities in two IRS computer systems -- including the one developed to replace all existing tax processing systems at the agency -- were known and repeatedly raised, but not addressed, during the nine-year development process...
betanews.com - 18.10.2008

Microsoft Issues 5 Critical Patches

November's Patch Tuesday has brought with it five "critical" patches correcting 11 security vulnerabilities, along with an "important" fix for two vulnerabilities related to Novell's NetWare. Among the list of patches is one for a highly publicized flaw in Microsoft's XML Core Services component...
betanews.com - 15.11.2006

Mozilla Releases Hacker Tools

Mozilla is beginning to give away programs used by both the good guys and the bad guys to discover critical program vulnerabilities.

The programs, called fuzzers, have so far been for internal use only. Fuzzers poke at programs in search of vulnerabilities that can arise when an application receives data it doesn't expect.



Programmers and security researchers use them to identify vulnerabilities that they can then fix, or warn people about. Online crooks use them to find holes that they can attack.



At the BlackHat conference today, Mike Shaver of Mozilla said the open-source tools are primarily meant to help other programmers discover holes in their own software...
winbeta.org - 03.08.2007

Microsoft Patches 7 Critical Vulnerabilities

As part of its Patch Tuesday updates this week, Microsoft corrected 10 vulnerabilities in Windows and Office, 7 of which were deemed "critical." Three critical flaws were fixed in Excel that could allow for remote code execution, while one was fixed in Windows 2000 and Server 2003...
betanews.com - 11.07.2007

92% of Windows vulnerabilities can only occur on Administrator accounts

You know how everyone always says it's safer to run as a "Restricted" or "Standard" level user account?

Well, this is why. According to John Moyer, the CEO of BeyondTrust Corp., 92% of critical security vulnerabilities in Windows, IE, and Office can only be exploited when running as an Administrator user.

That's right, only 8% of critical vulnerabilities affect standard user accounts.

"This speaks to what enterprises should be doing," Moyer said. "Clearly, eliminating administrative rights can close the window of opportunity of attack."

Of the 154 bugs published and patched by Microsoft in 2008, critical or not, 69% would have been blocked or their impact reduced by configuring users to run without administrative rights, said the company.

When BeyondTrust looked at the vulnerabilities patched for Microsoft's browser, Internet Explorer (IE), and its application suite, Office, it found that 89% of the former and 94% of the latter could have been stymied by denying users administrative privileges...
jcxp.net - 04.02.2009

Microsoft Plans Six Security Updates, Two For Windows Vista

Gearing up for next week's Patch Tuesday release, Microsoft announced on Thursday that it's preparing six security updates -- four of them for critical bugs.

One security update actually can patch multiple vulnerabilities so it's unclear at this point how many flaws next week's releases will fix. Microsoft, though, did announce in its Security Bulletin Advance Notification that each of the four critical updates will affect Windows software, while only one affects Internet Explorer. Another one will address issues in Outlook Express, as well as Windows Mail.

One critical vulnerability affects Windows Mail in Windows Vista and Windows Vista x64 edition. There another patch for Windows Vista that's rated "moderate"...
winbeta.org - 08.06.2007