QuickTime 0day for Vista and XP

Friday, April 25th, 2008

A remote vulnerability exists in the QuickTime player for Windows XP and Vista (latest service packs). Other versions are believed to be affected as well. For now, no details will be released regarding the method of exploitation. Because we are an information security think tank and because we encounter some very ...

Tactical Forensics Platform

Thursday, April 24th, 2008

Earlier I wrote about my proposed Tactical Network Security Monitoring Platform. Today I finally sat down and installed the operating systems I need on this system to create a portable tactical forensics and investigation platform. I did not want to use my main work laptop for this sort of work ...

Linux: Windows Made Hard

Monday, April 21st, 2008

For the past few months, we've shown how Linux has emerged from its early murky reputation of being cool to have but impractical to use. And there's no question it's refreshing to use an entire desktop system with nary a Microsoft or Apple product. But as some of our readers ...

Windows XP Service Pack 3 RTM Screenshots

Monday, April 21st, 2008

Microsoft released Windows XP SP3 to manufacturing today: Check out the first XP SP3 RTM screenshots! Click here for the screenshots...

Details of privilege escalation hole in Windows

Monday, April 21st, 2008

In a security alert last week, Microsoft reported a vulnerability which allows local users and users signed on with access to an Internet Information Server (IIS) or MS SQL server to escalate their privileges. Server operators such as hosting providers who allow user code to be executed, for example on ...

Vulnerability in Windows Could Allow Elevation of Privilege

Friday, April 18th, 2008

Microsoft is investigating new public reports of a vulnerability which could allow elevation of privilege from authenticated user to LocalSystem, affecting Windows XP Professional Service Pack 2 and all supported versions and editions of Windows Server 2003, Windows Vista, and Windows Server 2008. Customers who allow user-provided code to run ...

Windows Vista One Year Vulnerability Report

Thursday, April 17th, 2008

Windows Vista shipped to business customers on the last day of November 2006, so the end of November 2007 marks the one year anniversary for supported production use of the product. This paper analyzes the vulnerability disclosures and security updates for the first year of Windows Vista and looks at ...

Hacker releases working GDI-bug attack code

Wednesday, April 16th, 2008

Security researchers on Monday spotted malicious code that triggers a critical vulnerability in the Chinese version of Windows 2000, and warned users of other editions to expect attacks. Symantec confirmed that the proof-of-concept code publicly posted to the milw0rm.com site earlier in the day successfully attacks Chinese editions of Windows 2000 ...

Windows XP SP3 Release Dates

Tuesday, April 15th, 2008

With Service Pack 3 for Windows XP just over the horizon, we've managed to get our hands on the internal schedule for the release of the highly anticipated update to the aging operating system. As you can see in the list below, most of the stages will occur before the ...

How to simulate “No to all” when copying in Windows XP

Monday, April 14th, 2008

Ever had to copy a bunch of files from one location on your local hard drive to another place with a lot of files with the same name? Well there are really only two options that you have when there are files with the same name: either replace the destination ...