internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
7-Zip

Most Popular Software Downloads
Mozilla Firefox
Microsoft Office 2010
QuickTime for Windows
Adobe Reader
Mozilla Thunderbird
Winamp
Microsoft Office 2007 Service Pack
Google Earth
Adobe Flash Player
Windows Vista Service Pack 2 (Vista SP2)
CCleaner (Crap Cleaner)

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

To Patch or Not to Patch?
Dept of Homeland Security Urges Users to Patch Severe Hole
Andy Patrizio

It seems with each monthly Patch Tuesday, some kind of disaster follows Microsoft's (Quote, Chart) batch of fixes. In this case, there may be problems with one of the patches, but the federal government is taking the unusual step of insisting this patch be installed.

Both issues surround patch KB921883, or MS06-040. The patch addresses a remote code execution vulnerability in the Windows Server Service that could allow a virus to take complete control of the affected system.

The virus would take control of the system through a buffer overflow, which in turn allows a remote procedure call to launch malicious code on the exposed system and send out all kinds of attacks.

The patch affects Windows 2000, Windows XP and Windows Server 2003.

In a rare public comment, the U.S. Department of Homeland Security issued a firm notice to Windows users to immediately apply the patch. The department warned that a successful attack could be launched similar to the Blaster and Sasser worms.

"Windows users are encouraged to avoid delay in applying this security patch. Attempts to exploit vulnerabilities in operating systems routinely occur within 24 hours of the release of a security patch," the agency said in a public advisory.

At the same time, the Windows community site ActiveWin.com reported that MS06-040 can affect encrypted Web traffic.

"It has been confirmed on several machines that this patch breaks HTTPS functions. You cannot sign in to Live.com, or access pages reliably that use certificates, (most will not work), secure communications programs fail," reads a posting on the site.

Initial responses on the site claimed this was not the case but the thread devolved into squabbling about Firefox and Linux popularity. ActiveWin did not respond to a request for elaboration by internetnews.com today.

A Microsoft said that it is still early in the August release cycle and has not been able to verify any customer reports of deployment issues at this time. As for the DHS security advisory, the spokesman said Microsoft encourages customers to deploy MS06-040 on their systems as soon as possible.

Chris Andrew, vice president of security technologies at PatchLink, called the DHS advisory "an unprecedented wake-up call that organizations are taking too long to patch. With exploits spotted in the wild the day after Patch Tuesday, the 30 day average time to patch is 29 days too long," he said in a statement to internetnews.com.

"The MS06-040 updates are not any more critical than previous patch releases," Andrew continued. "However, the emergency is that hackers are now closely following Patch Tuesday, predetermining vulnerabilities to exploit and targeting attacks on Wednesday.

With this month's crop of vulnerabilities allowing remote code execution, we could be looking at a repeat of the Zotob, Slammer or Blaster worm any moment."

News courtesy of internetnews.com

August 10, 2006

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. Dept of Homeland Security Urges Users to Patch Severe Hole





The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers