Ramblings of an old Doc

A really HUGE Update is coming on Tuesday!

17  patches are coming: 8 rated “Critical” and 9 rated “Important” with fixes for 64 documented vulnerabilities across Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, .NET Framework and GDI+.

From Pete Voss’s Technet Blog:

 

“This month we'll be closing some issues that Microsoft has already previously spoken to, including the SMB Browser (Critical) issue publicly disclosed Feb. 15. Microsoft assessed the situation and reported that although the vulnerability could theoretically allow Remote Code Execution, that was extremely unlikely.  To this day, we have seen no evidence of attacks.

We are also planning a fix for the MHTML vulnerability in Windows, rated Important. We alerted people to this issue with Security Advisory 2501696 (including a Fix-It that fully protected customers once downloaded) back in late January. In March, we updated the advisory to let people know we were aware of limited, targeted attacks.

The bulletin release scheduled for the second Tuesday of the month, April 12, at approximately 10 a.m. PDT.”

Voss didn’t address the vulnerabilities discovered in the “Pwn2Own” contest.

People, please get the updates and patches. Also, please update your Programs: Stardock’s, and others…. This is an important key to your security, and a fast, reliable computer.


Comments (Page 5)
6 PagesFirst 3 4 5 6 
on Apr 11, 2011

I got the sneak peak of the bug fixes (I am on that MS list).  And was flummoxed! I am glad MS is fixing all of them, and still marvel that so many still get through.  I understand that the millions of lines of code are hard to debug, but what are the QA people getting paid to do?  I guess the immediacy of needing to get things out the door still trumps the QA.

on Apr 11, 2011

Campaigner


I used the onlinescan and it found quite a few outdated programs.

 
SUN JAVA JRE has two versions installed now....doesn't it uninstall older versions itself??       Strange program. No update available....

Quicktime (which I only installed to view some video thing)

ActiveX 10...Flashplayer I think...

 
Deleting End of Life programs is just paranoid. Does that include freeware and old games as well?

Well,just a few things:

1)If the online scan detected a few outdated progs,it's better to download PSI and make a full scan(online one is partial).

2)About Java:is good to know that is NECESSARY to uninstall the running JAVA before installing the updated version.The new version,with fixed vulnerabilities,is just "added" to the old one,but doesn't fix his vulnerabilities.So,the best thing to do is to unistall all JAVA progs,cleaning the registry(CCleaner,Wise Registry Cleaner..),and then install the last version(Update 24).

3)About other outdated progs,if you check,PSI itself will show you the available updates.

4)Hackers knows about end-of-life progs,making specific searches.These progs are no more supported,so it can be easy to release a virus or malware to attack them(mostly it depends from their popularity;more people are using them,higher is the risk),and there will be no any patch from vendors.In short:only hackers are "WORKING" on end-of-life progs,no vendors anymore.

 

on Apr 11, 2011

One thing with Secunia PSI is that with some things...even after it tells you there is an update...and you install the update...and then do a scan again...it comes up as not being updated again...gets annoying.

 

kona0197
Norton and McAfee are both far more bloated than AVG.

I never understand this...I've used Norton for the last 8 years and have never seen any bloat on my pc...in fact I don't even know it's installed half the time.

on Apr 11, 2011

Ask Jafo about Norton and it's problems WebGizmos.

on Apr 11, 2011

inthebloodofeden
only hackers are "WORKING" on end-of-life progs,no vendors anymore.

Yeah ...... but after awhile you learn not to do certain things. Like when I'm working in PS its usually when I'm not online with the WLAN turned off. If the doors closed they can't get in and don't say there are always 'Windows' either. lol

on Apr 11, 2011

kona0197
Ask Jafo about Norton and it's problems WebGizmos.

Don't have to....works just fine for me.

on Apr 11, 2011

WebGizmos
I never understand this...I've used Norton for the last 8 years and have never seen any bloat on my pc...in fact I don't even know it's installed half the time.

Web....yes, 8 years of bliss.

My [and millions of others'] dramas were with Norton2002 [9 years] as/when it disabled MS BITS efficiently preventing Windows Updates.

The 'cure' was a choice of very extensive registry hacking and dll replacements OR the PHYSICAL reinstall of SP1 [or 2...can't recall which].

Note 'physical' as with BITS screwed you weren't gonna get it as an online update.

The NEXT step was to permanently AVOID anything 'Norton'.

Now, Kaspersky simply WORKS as it [or any AV/wall] SHOULD....

on Apr 11, 2011

Gwenio1



Quoting Campaigner,
reply 57
SUN JAVA JRE has two versions installed now....doesn't it uninstall older versions itself??       Strange program. No update available....


Likely something installed a second copy without detecting what was already there, and now the updates only apply to one of them.

Just FYI there is a 32 bit Java and a 64 bit Java. Some programs need one or the other. Could be why you are seeing two versions!

on Apr 12, 2011



Yeah ...... but after awhile you learn not to do certain things. Like when I'm working in PS its usually when I'm not online with the WLAN turned off. If the doors closed they can't get in and don't say there are always 'Windows' either. lol

Correct;of course that's a good way to be safe.Or,if you have Kaspersky Internet Security installed on your machine,you can open PS in Kaspersky "Safe Run for Applications" mode.Same for IE8;just now,I'm using IE8 in Kaspersky "Safe Run for Websites" mode(best thing ever).

Frankief


Just FYI there is a 32 bit Java and a 64 bit Java. Some programs need one or the other. Could be why you are seeing two versions!

I don't think Campaigner was talking about this kind of issue(x32/x64 versions).He mentioned OLDER VERSIONS(very common issue with Java!)

Main point is this:when you install a Java update,the new version it's just ADDED to the older one,is not REPLACING it.That's the way Java works.Of course progs will use the updated version,but the previous one vulnerabilities are still in the system,a possible "target" for hackers(besides,Java is a very popular application).So,a good rule is to manually uninstall the running Java before installing the new version.

on Apr 12, 2011

inthebloodofeden
Main point is this:when you install a Java update,the new version it's just ADDED to the older one,is not REPLACING it.That's the way Java works.Of course progs will use the updated version,but the previous one vulnerabilities are still in the system,a possible "target" for hackers(besides,Java is a very popular application).So,a good rule is to manually uninstall the running Java before installing the new version.

Good advice I think. Never knew that Java did the ad-on rather than overlay thing. I always thought, like some apps, a little house keeping, would be in order. you know like clean out what's being replaced. Going to keep this in mind for the next one.

on Apr 12, 2011


My [and millions of others'] dramas were with Norton2002 [9 years] as/when it disabled MS BITS efficiently preventing Windows Updates.

The 'cure' was a choice of very extensive registry hacking and dll replacements OR the PHYSICAL reinstall of SP1 [or 2...can't recall which].

Note 'physical' as with BITS screwed you weren't gonna get it as an online update.

The NEXT step was to permanently AVOID anything 'Norton'.

Now, Kaspersky simply WORKS as it [or any AV/wall] SHOULD....

Count me in as one of the millions you speak of.  Although I am open to giving them another chance now (just not for pay - if they want to give me a free trial, I will accept the challenge).

on Apr 12, 2011

You said there would be many updates to install. I checked this morning. Only one for me and it was for Windows Defender.

on Apr 12, 2011

The bulletin release scheduled for the second Tuesday of the month, April 12, at approximately 10 a.m. PDT.”

Kona0197 I don't think the updates are available yet.

on Apr 12, 2011

Available at noon, per Voss's blog.

on Apr 12, 2011

Downloading updates now. 

6 PagesFirst 3 4 5 6