Microsoft Baseline Security Analyzer 2.1.1

Monday, October 26th, 2009

To easily assess the security state of machines in an environment, Microsoft offers the free Microsoft Baseline Security Analyzer (MBSA) scan tool. MBSA includes a graphical and command line interface that can perform local or remote scans of Microsoft Windows systems. MBSA 2.1.1 builds on previous versions by adding support for ...

Sneaky Microsoft plugin puts Firefox users at risk

Friday, October 16th, 2009

An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves that browser open to attack, Microsoft's security engineers acknowledged earlier this week. One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made plug-in pushed to Firefox users ...

SSL Still Mostly Misunderstood

Saturday, October 10th, 2009

Most users ensure their Web sessions are using Secure Sockets Layer (SSL) before entering their credit card information, but less than half do so when typing their passwords onto a Web page, according to a new survey. Just what SSL does and doesn't do isn't clear to many users, and the ...

SSL trick certificate published

Wednesday, September 30th, 2009

On the Noisebridge hacker mailing list, security specialist Jacob Appelbaum has published an SSL certificate and pertinent private key that together allow web servers to avoid triggering an alert in vulnerable browsers - irrespective of the domain for which the certificate is submitted. Phishers, for example, could use the certificate ...

Exploit published for SMB2 vulnerability in Windows

Tuesday, September 29th, 2009

A fully functional exploit for the security vulnerability in the SMB2 protocol implementation has been published. It can be used to discover and attack vulnerable Windows machines remotely. By integrating the exploit into the Metasploit exploit toolkit, attackers have access to a wide range of attack options, ranging from issuing ...