internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Microsoft Needs a Little More Fixing
A Bumpy Week for Microsoft on the Security Side
Andy Patrizio

It's been a bumpy week for Microsoft-related security issues as the company found itself dealing with broken fixes and a new zero-day exploit. On the plus side, the software giant was at least able to address a problem in its patch distribution service.

This month's Patch Tuesday consisted of four bulletins with eight fixes, not one of which was considered a critical fix, the most important and vital of fixes, so users did have the luxury of waiting a few days before installing.

Those that did and used ZoneAlarm found their Internet was gone. ZoneAlarm is a third-party security system that includes a firewall and a check of incoming and outgoing traffic. Upon installing MS08-037, a fix for vulnerabilities in the Windows Domain Name System (DNS) that could allow for domain spoofing, ZoneAlarm would block Internet access.

Complaints began to appear on Broadband Reports and other techie sites. The problem applies to all ZoneAlarm products — the Free, Pro, AntiVirus, Anti-Spyware and Security Suite editions — which are all based on ZoneAlarm technology.

Check Point Software Technologies, makers of ZoneAlarm, posted three suggestions to fix the problem: set the firewall to medium security, uninstall the patch, or add your DNS servers to the trusted zone of the application.

A common strategy among malware writers is to wait until Patch Tuesday to see what Microsoft fixes. If Microsoft doesn't fix an exploit they've found, then they unleash their malware, knowing they are likely to have a month of free reign before the fix comes out, since Microsoft rarely issues out-of-band fixes unless they are severe.

Unleashing a Payload of Malware

So it was with a Word zero-day exploit. When the hole wasn't plugged this past Tuesday, the malware writers unleashed their payload. Fortunately, the issue is limited to just one version of the Microsoft word processor, Word 2002 (from Office XP) Service Pack 3. A specially crafted Word file could gain full access to the computer, meaning it would have as much use over the computer as a local user sitting at the keyboard.

Anti-virus vendor BitDefender was one of the first to identify the problem, as was Symantec's Security Response team. Microsoft has also acknowledged the problem. Until a fix is issued, the old rules of common sense apply: don't open an e-mail attachment from an unknown source.

The one thing that is going Microsoft's way is it fixed a problem with Windows Server Update Services (WSUS) version 3.0 and 3.0 Service Pack 1. WSUS is like Windows Update, only it is used internally by companies so employees get fixes and patches from their internal server rather than Microsoft.com.

Under specific conditions, which included having Microsoft Office 2003 installed, WSUS would not let clients detect any updates from a WSUS server. Microsoft has issued a fix that should allow for proper distribution of fixes.

News courtesy of internetnews.com

July 11, 2008

Download ZoneAlarm Security Suite Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. A Bumpy Week for Microsoft on the Security Side




internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Whitepapers and eBooks

Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
IBM Solutions Brief: Go Green With IBM System xTM And Intel
HP eBook: Simplifying SQL Server Management
IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
Microsoft PDF: Top 10 Reasons to Move to Server Virtualization with Hyper-V
Microsoft PDF: Six Reasons Why Microsoft's Hyper-V Will Overtake Vmware
Microsoft Step-by-Step Guide: Hyper-V and Failover Clustering
Intel PDF: Quad-Core Impacts More Than the Data Center
Intel PDF: Virtualization Delivers Data Center Efficiency
Go Parallel Article: PDC 2008 in Review
Microsoft PDF: Top 11 Reasons to Upgrade to Windows Server 2008
Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
  PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
Go Parallel Article: Q&A with a TBB Junkie
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
IBM eBook: The Pros and Cons of Outsourcing
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
HP eBook: Guide to Storage Networking
MORE WHITEPAPERS, EBOOKS, AND ARTICLES