<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BITS &#187; Virus</title>
	<atom:link href="http://www.bitsofws.com/index.php/Local%20News/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bitsofws.com</link>
	<description>Business Information Technology Services of Winston-Salem</description>
	<lastBuildDate>Wed, 28 Jul 2010 12:25:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Critical Updates For Microsoft Office</title>
		<link>http://www.bitsofws.com/index.php/2010/02/09/critical-updates-for-microsoft-office/</link>
		<comments>http://www.bitsofws.com/index.php/2010/02/09/critical-updates-for-microsoft-office/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 00:03:18 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2010/02/09/critical-updates-for-microsoft-office/</guid>
		<description><![CDATA[Malicious Office Documents Cause Security Woes 

Exposure:
Today, Microsoft released two security bulletins describing seven vulnerabilities found in components that ship with Microsoft Office XP and 2003 for Windows, and Office 2004 for Mac. These bulletins do not affect the more current versions of Office, such as 2007 Microsoft Office System or Microsoft Office 2008 for [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Malicious Office Documents Cause Security Woes </strong></h3>
<h5><strong></strong></h5>
<h5>Exposure:</h5>
<p>Today, Microsoft released two security bulletins describing seven vulnerabilities found in components that ship with Microsoft Office XP and 2003 for Windows, and Office 2004 for Mac. These bulletins do not affect the more current versions of Office, such as 2007 Microsoft Office System or Microsoft Office 2008 for Mac. </p>
<p>The vulnerabilities affect different versions of Office to varying degrees. Though the seven vulnerabilities differ technically, and affect two different Office components, they share the same scope and impact. By enticing one of your users into downloading and opening a maliciously crafted Office document, an attacker can exploit any of these vulnerabilities to execute code on a victim&#8217;s computer, usually inheriting that user&#8217;s level of privileges and permissions. If your user has local administrative privileges, the attacker gains full control of the user&#8217;s machine.</p>
<p>According to Microsoft&#8217;s bulletins, an attacker can exploit these flaws using many different types of Office documents. In one bulletin, Microsoft specifically states PowerPoint documents are vulnerable. However, they also mention any &quot;Office file&quot; in their other alert. Therefore, we recommend you beware of<strong> all </strong>unexpected Office documents.</p>
<p>If you&#8217;d like to learn more about each individual flaw, drill into the &quot;Vulnerability Details&quot; section of the security bulletins listed below:</p>
<ul>
<li>&#160;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-003.mspx">MS10-003</a><strong></strong>: Multiple PowerPoint Code Execution Vulnerabilities, rated Important </li>
<li>&#160;<a href="http://www.microsoft.com/technet/security/bulletin/MS10-004.mspx">MS10-004</a><strong></strong>: Microsoft Office MSO.DLL Code Execution Vulnerability, rated Important </li>
</ul>
<h5>Solution Path</h5>
<p>Microsoft has released patches for Office to correct all of these vulnerabilities. You should download, test, and deploy the appropriate patches throughout your network immediately, or let the Microsoft Automatic Update feature do it for you.</p>
<p><strong><a href="http://www.microsoft.com/technet/security/bulletin/ms10-003.mspx">MS10-003</a></strong><strong>:</strong></p>
<ul>
<li>&#160;<a href="http://www.microsoft.com/downloads/details.aspx?familyid=47553f45-fa10-40e5-8267-9d42ff560a62&amp;displaylang=en">Office XP w/SP3</a></li>
<li>&#160;<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7c985595-00c5-44b8-81c3-59d9967220f8&amp;displaylang=en">Office 2004 for Mac</a></li>
</ul>
<p><strong><a href="http://www.microsoft.com/technet/security/bulletin/MS10-004.mspx">MS10-004</a></strong>:</p>
<p><strong>PowerPoint update for:</strong></p>
<ul>
<li>&#160;<a href="http://www.microsoft.com/downloads/details.aspx?familyid=cfc697b4-2ceb-4030-86c5-be9bc8bfd07c&amp;displaylang=en">Office XP w/SP3</a></li>
<li>&#160;<a href="http://www.microsoft.com/downloads/details.aspx?familyid=2291ae24-fa39-4ad8-a7d0-12726b68ad96&amp;displaylang=en">Office 2003 w/SP3</a></li>
<li>&#160;<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7c985595-00c5-44b8-81c3-59d9967220f8&amp;displaylang=en">Office 2004 for Mac</a></li>
</ul>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office&amp;bodytext=Malicious%20Office%20Documents%20Cause%20Security%20Woes%20%20%20%20%20Exposure%3A%20%20Today%2C%20Microsoft%20released%20two%20security%20bulletins%20describing%20seven%20vulnerabilities%20found%20in%20components%20that%20ship%20with%20Microsoft%20Office%20XP%20and%202003%20for%20Windows%2C%20and%20Office%202004%20for%20Mac.%20Thes" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office&amp;notes=Malicious%20Office%20Documents%20Cause%20Security%20Woes%20%20%20%20%20Exposure%3A%20%20Today%2C%20Microsoft%20released%20two%20security%20bulletins%20describing%20seven%20vulnerabilities%20found%20in%20components%20that%20ship%20with%20Microsoft%20Office%20XP%20and%202003%20for%20Windows%2C%20and%20Office%202004%20for%20Mac.%20Thes" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;t=Critical%20Updates%20For%20Microsoft%20Office" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office&amp;annotation=Malicious%20Office%20Documents%20Cause%20Security%20Woes%20%20%20%20%20Exposure%3A%20%20Today%2C%20Microsoft%20released%20two%20security%20bulletins%20describing%20seven%20vulnerabilities%20found%20in%20components%20that%20ship%20with%20Microsoft%20Office%20XP%20and%202003%20for%20Windows%2C%20and%20Office%202004%20for%20Mac.%20Thes" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Critical%20Updates%20For%20Microsoft%20Office&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2010%2F02%2F09%2Fcritical-updates-for-microsoft-office%2F&amp;title=Critical%20Updates%20For%20Microsoft%20Office&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=Malicious%20Office%20Documents%20Cause%20Security%20Woes%20%20%20%20%20Exposure%3A%20%20Today%2C%20Microsoft%20released%20two%20security%20bulletins%20describing%20seven%20vulnerabilities%20found%20in%20components%20that%20ship%20with%20Microsoft%20Office%20XP%20and%202003%20for%20Windows%2C%20and%20Office%202004%20for%20Mac.%20Thes" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2010/02/09/critical-updates-for-microsoft-office/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Laden Emails Abound</title>
		<link>http://www.bitsofws.com/index.php/2009/11/18/virus-laden-emails-abound/</link>
		<comments>http://www.bitsofws.com/index.php/2009/11/18/virus-laden-emails-abound/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 19:20:05 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/11/18/virus-laden-emails-abound/</guid>
		<description><![CDATA[I am seeing around a two dozen or more virus laden emails a day right now all with the same general subject lines such as:
“payment request from &#34;Qualcomm&#34; or “payment request from &#34;Google&#34;” or “Your Credit Balance is over its limit”

These all contain a backdoor Trojan in the attachment so again and again I remind [...]]]></description>
			<content:encoded><![CDATA[<p>I am seeing around a two dozen or more virus laden emails a day right now all with the same general subject lines such as:</p>
<blockquote><p>“payment request from &quot;Qualcomm&quot; or “payment request from &quot;Google&quot;” or “Your Credit Balance is over its limit”</p>
</blockquote>
<p>These all contain a backdoor Trojan in the attachment so again and again I remind everyone to not click those attachments you get in email. I like that “transaction inspector module”, they are always looking for something that will just make people click away, well DON’T! </p>
<p><a href="http://www.bitsofws.com/wp-content/uploads/2009/11/image81.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.bitsofws.com/wp-content/uploads/2009/11/image_thumb69.png" width="448" height="239" /></a></p>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound&amp;bodytext=I%20am%20seeing%20around%20a%20two%20dozen%20or%20more%20virus%20laden%20emails%20a%20day%20right%20now%20all%20with%20the%20same%20general%20subject%20lines%20such%20as%3A%20%20%20%20%20%E2%80%9Cpayment%20request%20from%20%26quot%3BQualcomm%26quot%3B%20or%20%E2%80%9Cpayment%20request%20from%20%26quot%3BGoogle%26quot%3B%E2%80%9D%20or%20%E2%80%9CYour%20Credit%20Balance%20is%20" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound&amp;notes=I%20am%20seeing%20around%20a%20two%20dozen%20or%20more%20virus%20laden%20emails%20a%20day%20right%20now%20all%20with%20the%20same%20general%20subject%20lines%20such%20as%3A%20%20%20%20%20%E2%80%9Cpayment%20request%20from%20%26quot%3BQualcomm%26quot%3B%20or%20%E2%80%9Cpayment%20request%20from%20%26quot%3BGoogle%26quot%3B%E2%80%9D%20or%20%E2%80%9CYour%20Credit%20Balance%20is%20" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;t=Virus%20Laden%20Emails%20Abound" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound&amp;annotation=I%20am%20seeing%20around%20a%20two%20dozen%20or%20more%20virus%20laden%20emails%20a%20day%20right%20now%20all%20with%20the%20same%20general%20subject%20lines%20such%20as%3A%20%20%20%20%20%E2%80%9Cpayment%20request%20from%20%26quot%3BQualcomm%26quot%3B%20or%20%E2%80%9Cpayment%20request%20from%20%26quot%3BGoogle%26quot%3B%E2%80%9D%20or%20%E2%80%9CYour%20Credit%20Balance%20is%20" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Virus%20Laden%20Emails%20Abound&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F18%2Fvirus-laden-emails-abound%2F&amp;title=Virus%20Laden%20Emails%20Abound&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=I%20am%20seeing%20around%20a%20two%20dozen%20or%20more%20virus%20laden%20emails%20a%20day%20right%20now%20all%20with%20the%20same%20general%20subject%20lines%20such%20as%3A%20%20%20%20%20%E2%80%9Cpayment%20request%20from%20%26quot%3BQualcomm%26quot%3B%20or%20%E2%80%9Cpayment%20request%20from%20%26quot%3BGoogle%26quot%3B%E2%80%9D%20or%20%E2%80%9CYour%20Credit%20Balance%20is%20" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/11/18/virus-laden-emails-abound/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Security Flaws in Adobe Shockwave Player</title>
		<link>http://www.bitsofws.com/index.php/2009/11/05/five-security-flaws-in-adobe-shockwave-player/</link>
		<comments>http://www.bitsofws.com/index.php/2009/11/05/five-security-flaws-in-adobe-shockwave-player/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 21:48:22 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/11/05/five-security-flaws-in-adobe-shockwave-player/</guid>
		<description><![CDATA[



Severity: High
5 November, 2009
Summary:
§ This vulnerability affects: Adobe Shockwave Player 11.5.1.601 and earlier, running on Windows and Macintosh computers 
§ How an attacker exploits it: By enticing your users to visit a website containing a malicious Flash file 
§ Impact: An attacker can execute code on your computer, potentially gaining control of it 
§ What [...]]]></description>
			<content:encoded><![CDATA[<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td>
<h3>Severity: High</h3>
<p>5 November, 2009</p>
<h5>Summary:</h5>
<p>§ <strong>This vulnerability affects</strong>: Adobe Shockwave Player 11.5.1.601 and earlier, running on Windows and Macintosh computers </p>
<p>§ <strong>How an attacker exploits it</strong>: By enticing your users to visit a website containing a malicious Flash file </p>
<p>§ <strong>Impact</strong>: An attacker can execute code on your computer, potentially gaining control of it </p>
<p>§ <strong>What to do</strong>: Download and install the latest version of Adobe Shockwave Player </p>
<h5>Exposure:</h5>
<p>Adobe Shockwave Player displays interactive, animated web content called <a href="http://en.wikipedia.org/wiki/Adobe_Shockwave">Shockwave (.SWF) files</a>. According to Adobe, Shockwave Player is installed on some 450 million PCs. </p>
<p>In a <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">security bulletin</a> released late Tuesday, Adobe warned of critical vulnerabilities that affect Adobe Shockwave Player 11.5.1.601 for Windows and Macintosh (as well as all earlier versions). Adobe&#8217;s bulletin refers to five <a href="http://cve.mitre.org/">CVE</a> numbers, which suggests that their update fixes five security vulnerabilities. The bulletin doesn&#8217;t describe the flaws in much technical detail. However, it does warn that if an attacker can entice one of your users to visit a malicious website containing specially crafted <a href="http://en.wikipedia.org/wiki/Adobe_Shockwave">Shockwave (SWF)</a> content, he could exploit this unspecified vulnerability to execute code on that user&#8217;s computer, with that user&#8217;s privileges. If your Windows users have local administrator privileges, an attacker could exploit this flaw to gain full control of their PC.</p>
<p>If you deploy Adobe Shockwave throughout your network, we recommend you download and install the latest version as soon as you can. </p>
<h5>Solution Path</h5>
<p>Adobe has released a new version of Shockwave Player, version 11.5.2.602. If you use Adobe Flash in your network, we recommend you <a href="http://get.adobe.com/shockwave/">download</a> and deploy this updated player as soon as possible.</p>
<h5>Status: </h5>
<p>Adobe has released a Shockwave Player update to fix these vulnerabilities.</p>
<h5>References: </h5>
<p>§ <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">Adobe Security Bulletin</a></p>
<p>This alert was researched and written by Corey Nachreiner, CISSP.</p>
<hr align="center" size="1" width="90%" noshade="noshade" /></td>
</tr>
</tbody>
</table>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player&amp;bodytext=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Severity%3A%20High%20%20%20%20%20%20%20%20%20%205%20November%2C%202009%20%20%20%20%20%20%20%20%20%20Summary%3A%20%20%20%20%20%20%20%20%20%20%C2%A7%20This%20vulnerability%20affects%3A%20Adobe%20Shockwave%20Player%2011.5.1.601%20and%20earlier%2C%20running%20on%20Windows%20and%20Macintosh%20computers%20%20%20%20%20%20%20%20%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20it" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player&amp;notes=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Severity%3A%20High%20%20%20%20%20%20%20%20%20%205%20November%2C%202009%20%20%20%20%20%20%20%20%20%20Summary%3A%20%20%20%20%20%20%20%20%20%20%C2%A7%20This%20vulnerability%20affects%3A%20Adobe%20Shockwave%20Player%2011.5.1.601%20and%20earlier%2C%20running%20on%20Windows%20and%20Macintosh%20computers%20%20%20%20%20%20%20%20%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20it" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;t=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player&amp;annotation=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Severity%3A%20High%20%20%20%20%20%20%20%20%20%205%20November%2C%202009%20%20%20%20%20%20%20%20%20%20Summary%3A%20%20%20%20%20%20%20%20%20%20%C2%A7%20This%20vulnerability%20affects%3A%20Adobe%20Shockwave%20Player%2011.5.1.601%20and%20earlier%2C%20running%20on%20Windows%20and%20Macintosh%20computers%20%20%20%20%20%20%20%20%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20it" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F11%2F05%2Ffive-security-flaws-in-adobe-shockwave-player%2F&amp;title=Five%20Security%20Flaws%20in%20Adobe%20Shockwave%20Player&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Severity%3A%20High%20%20%20%20%20%20%20%20%20%205%20November%2C%202009%20%20%20%20%20%20%20%20%20%20Summary%3A%20%20%20%20%20%20%20%20%20%20%C2%A7%20This%20vulnerability%20affects%3A%20Adobe%20Shockwave%20Player%2011.5.1.601%20and%20earlier%2C%20running%20on%20Windows%20and%20Macintosh%20computers%20%20%20%20%20%20%20%20%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20it" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/11/05/five-security-flaws-in-adobe-shockwave-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infected? I Didn&#8217;t Load Anything</title>
		<link>http://www.bitsofws.com/index.php/2009/10/17/infected-i-didnt-load-anything/</link>
		<comments>http://www.bitsofws.com/index.php/2009/10/17/infected-i-didnt-load-anything/#comments</comments>
		<pubDate>Sat, 17 Oct 2009 22:04:34 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Antivirus 2009]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/10/17/infected-i-didnt-load-anything/</guid>
		<description><![CDATA[I’ve had so many people get infected with variations of AntiVirus 2009 and each one has said they never loaded anything or “I don’t visit bad sites.” Well here is a perfect example of why what you think you did and what you actually did are not always the same when it comes to the [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve had so many people get infected with variations of AntiVirus 2009 and each one has said they never loaded anything or “I don’t visit bad sites.” Well here is a perfect example of why what you think you did and what you actually did are not always the same when it comes to the web.</p>
<p>In this case I pulled up a site I think most would consider “safe”, The Christian Science Monitor. However within that page was a redirect to another server located in Germany owned by a guy in Norway. Of course the infected server I was being redirected to could easily be a legit site which has been hacked or a site setup to specifically try to distribute malware and in this case I suspect the latter as no website actually exist on that server. As to the source of the infection my bet is one of the Flash banners on the primary site was the source of the redirect and just one more reason to disable plug ins whenever possible. Instead of a hacker needing to attack Christian Science Monitor all they have to do is go after the company offering up the advertising banners or even sign up as an advertiser.</p>
<p><a href="http://www.bitsofws.com/wp-content/uploads/2009/10/image3.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.bitsofws.com/wp-content/uploads/2009/10/image_thumb3.png" width="624" height="363" /></a></p>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything&amp;bodytext=I%E2%80%99ve%20had%20so%20many%20people%20get%20infected%20with%20variations%20of%20AntiVirus%202009%20and%20each%20one%20has%20said%20they%20never%20loaded%20anything%20or%20%E2%80%9CI%20don%E2%80%99t%20visit%20bad%20sites.%E2%80%9D%20Well%20here%20is%20a%20perfect%20example%20of%20why%20what%20you%20think%20you%20did%20and%20what%20you%20actually%20did%20are%20n" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything&amp;notes=I%E2%80%99ve%20had%20so%20many%20people%20get%20infected%20with%20variations%20of%20AntiVirus%202009%20and%20each%20one%20has%20said%20they%20never%20loaded%20anything%20or%20%E2%80%9CI%20don%E2%80%99t%20visit%20bad%20sites.%E2%80%9D%20Well%20here%20is%20a%20perfect%20example%20of%20why%20what%20you%20think%20you%20did%20and%20what%20you%20actually%20did%20are%20n" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;t=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything&amp;annotation=I%E2%80%99ve%20had%20so%20many%20people%20get%20infected%20with%20variations%20of%20AntiVirus%202009%20and%20each%20one%20has%20said%20they%20never%20loaded%20anything%20or%20%E2%80%9CI%20don%E2%80%99t%20visit%20bad%20sites.%E2%80%9D%20Well%20here%20is%20a%20perfect%20example%20of%20why%20what%20you%20think%20you%20did%20and%20what%20you%20actually%20did%20are%20n" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F17%2Finfected-i-didnt-load-anything%2F&amp;title=Infected%3F%20I%20Didn%26rsquo%3Bt%20Load%20Anything&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=I%E2%80%99ve%20had%20so%20many%20people%20get%20infected%20with%20variations%20of%20AntiVirus%202009%20and%20each%20one%20has%20said%20they%20never%20loaded%20anything%20or%20%E2%80%9CI%20don%E2%80%99t%20visit%20bad%20sites.%E2%80%9D%20Well%20here%20is%20a%20perfect%20example%20of%20why%20what%20you%20think%20you%20did%20and%20what%20you%20actually%20did%20are%20n" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/10/17/infected-i-didnt-load-anything/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warning New Virus Attack</title>
		<link>http://www.bitsofws.com/index.php/2009/10/15/warning-new-virus-attack/</link>
		<comments>http://www.bitsofws.com/index.php/2009/10/15/warning-new-virus-attack/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 12:31:03 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/10/15/warning-new-virus-attack/</guid>
		<description><![CDATA[I’ve seen a number of these hitting a less than public email address so that tells me there are probably a large number being sent out. Typical grammar issues abound in the subject and body, the alert came from and was emailed to the same address and of course included something you are suppose to [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve seen a number of these hitting a less than public email address so that tells me there are probably a large number being sent out. Typical grammar issues abound in the subject and body, the alert came from and was emailed to the same address and of course included something you are suppose to run. Well do run, run away that is, Delete, Delete, Delete.</p>
<p>&#160;</p>
<p><a href="http://www.bitsofws.com/wp-content/uploads/2009/10/image2.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.bitsofws.com/wp-content/uploads/2009/10/image_thumb2.png" width="472" height="221" /></a></p>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack&amp;bodytext=I%E2%80%99ve%20seen%20a%20number%20of%20these%20hitting%20a%20less%20than%20public%20email%20address%20so%20that%20tells%20me%20there%20are%20probably%20a%20large%20number%20being%20sent%20out.%20Typical%20grammar%20issues%20abound%20in%20the%20subject%20and%20body%2C%20the%20alert%20came%20from%20and%20was%20emailed%20to%20the%20same%20address%20a" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack&amp;notes=I%E2%80%99ve%20seen%20a%20number%20of%20these%20hitting%20a%20less%20than%20public%20email%20address%20so%20that%20tells%20me%20there%20are%20probably%20a%20large%20number%20being%20sent%20out.%20Typical%20grammar%20issues%20abound%20in%20the%20subject%20and%20body%2C%20the%20alert%20came%20from%20and%20was%20emailed%20to%20the%20same%20address%20a" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;t=Warning%20New%20Virus%20Attack" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack&amp;annotation=I%E2%80%99ve%20seen%20a%20number%20of%20these%20hitting%20a%20less%20than%20public%20email%20address%20so%20that%20tells%20me%20there%20are%20probably%20a%20large%20number%20being%20sent%20out.%20Typical%20grammar%20issues%20abound%20in%20the%20subject%20and%20body%2C%20the%20alert%20came%20from%20and%20was%20emailed%20to%20the%20same%20address%20a" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Warning%20New%20Virus%20Attack&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F10%2F15%2Fwarning-new-virus-attack%2F&amp;title=Warning%20New%20Virus%20Attack&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=I%E2%80%99ve%20seen%20a%20number%20of%20these%20hitting%20a%20less%20than%20public%20email%20address%20so%20that%20tells%20me%20there%20are%20probably%20a%20large%20number%20being%20sent%20out.%20Typical%20grammar%20issues%20abound%20in%20the%20subject%20and%20body%2C%20the%20alert%20came%20from%20and%20was%20emailed%20to%20the%20same%20address%20a" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/10/15/warning-new-virus-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QuickTime Security Issue &#8211; Again</title>
		<link>http://www.bitsofws.com/index.php/2009/09/09/quicktime-security-issue-again/</link>
		<comments>http://www.bitsofws.com/index.php/2009/09/09/quicktime-security-issue-again/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 01:35:13 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[QuickTime]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/09/09/quicktime-security-issue-again/</guid>
		<description><![CDATA[QuickTime Falls Prey to Malicious Movies and Images 
Severity: Medium
9 September, 2009
Summary:
§ These vulnerabilities affect: QuickTime for OS X or Windows 
§ How an attacker exploits them: By enticing your user to click a malicious link or view a maliciously-crafted movie or image 
§ Impact: An attacker could execute code on your user&#8217;s computer, potentially [...]]]></description>
			<content:encoded><![CDATA[<h3>QuickTime Falls Prey to Malicious Movies and Images </h3>
<h5>Severity: Medium</h5>
<p>9 September, 2009</p>
<h5>Summary:</h5>
<p>§ <strong>These vulnerabilities affect:</strong> QuickTime for OS X or Windows </p>
<p>§ <strong>How an attacker exploits them:</strong> By enticing your user to click a malicious link or view a maliciously-crafted movie or image </p>
<p>§ <strong>Impact:</strong> An attacker could execute code on your user&#8217;s computer, potentially gaining control of it </p>
<p>§ <strong>What to do:</strong> Download and install QuickTime 7.6.4 for Windows or OS X (or use Apple&#8217;s Software Update tool) </p>
<h5>Exposure:</h5>
<p>Today, Apple released a <a href="http://support.apple.com/kb/HT3859">security update</a> to fix four vulnerabilities in QuickTime, their popular media player for both Windows and Macintosh OS X. The vulnerabilities differ technically, but all involve various <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow">buffer overflow</a> or memory corruption vulnerabilities. They also share the same scope and impact. By luring one of your users into viewing a maliciously crafted movie or image file, an attacker can exploit one of the four QuickTime flaws to execute code on that user&#8217;s computer (or, less worrisome, crash QuickTime). Some of the files susceptible to this attack include <a href="http://en.wikipedia.org/wiki/MPEG-4">MPEG-4</a>, <a href="http://en.wikipedia.org/wiki/H.264">H.264</a>, and <a href="http://en.wikipedia.org/wiki/FlashPix">FlashPix</a>. These vulnerabilities can be exploited on Windows and OS X computers, with differing results. Attackers exploiting these flaws only gain the privilege of the logged in user. OS X separates normal users privileges from root or administrative privileges. So an attacker will not gain complete control of OS X machines with these flaws. However, most Windows users have local administrative privileges. So an attacker could potentially leverage these flaws to gain complete control of Windows machines. </p>
<h5>Solution Path:</h5>
<p>Apple has released <a href="http://www.apple.com/quicktime/download/">QuickTime 7.6.4</a> to fix these security issues. Windows and OS X administrators should <a href="http://www.apple.com/quicktime/download/">download</a>, test, and deploy the appropriate update as soon as possible. By default, Apple&#8217;s download bundles iTunes with QuickTime, but because iTunes often has security issues of its own, we recommend that you select the option of downloading QuickTime alone.</p>
<h5>For All Users:</h5>
<p>Because QuickTime handles so many different media types (many of which are essential for doing business today), trying to block exploitable file types using your firewall may not be the best way to support your organization&#8217;s mission. Instead, your best solution is to download and install Apple&#8217;s fixes.</p>
<h5>Status:</h5>
<p>Apple has released updates to fix these issues.</p>
<h5>References:</h5>
<p>§ <a href="http://support.apple.com/kb/HT3859">Apple&#8217;s September QuickTime advisory</a></p>
<p>This alert was researched and written by Corey Nachreiner, CISSP.</p>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again&amp;bodytext=QuickTime%20Falls%20Prey%20to%20Malicious%20Movies%20and%20Images%20%20%20Severity%3A%20Medium%20%209%20September%2C%202009%20%20Summary%3A%20%20%C2%A7%20These%20vulnerabilities%20affect%3A%20QuickTime%20for%20OS%20X%20or%20Windows%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20them%3A%20By%20enticing%20your%20user%20to%20click%20a%20malicious%20link%20or" title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again&amp;notes=QuickTime%20Falls%20Prey%20to%20Malicious%20Movies%20and%20Images%20%20%20Severity%3A%20Medium%20%209%20September%2C%202009%20%20Summary%3A%20%20%C2%A7%20These%20vulnerabilities%20affect%3A%20QuickTime%20for%20OS%20X%20or%20Windows%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20them%3A%20By%20enticing%20your%20user%20to%20click%20a%20malicious%20link%20or" title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;t=QuickTime%20Security%20Issue%20-%20Again" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again&amp;annotation=QuickTime%20Falls%20Prey%20to%20Malicious%20Movies%20and%20Images%20%20%20Severity%3A%20Medium%20%209%20September%2C%202009%20%20Summary%3A%20%20%C2%A7%20These%20vulnerabilities%20affect%3A%20QuickTime%20for%20OS%20X%20or%20Windows%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20them%3A%20By%20enticing%20your%20user%20to%20click%20a%20malicious%20link%20or" title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=QuickTime%20Security%20Issue%20-%20Again&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F09%2F09%2Fquicktime-security-issue-again%2F&amp;title=QuickTime%20Security%20Issue%20-%20Again&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=QuickTime%20Falls%20Prey%20to%20Malicious%20Movies%20and%20Images%20%20%20Severity%3A%20Medium%20%209%20September%2C%202009%20%20Summary%3A%20%20%C2%A7%20These%20vulnerabilities%20affect%3A%20QuickTime%20for%20OS%20X%20or%20Windows%20%20%20%C2%A7%20How%20an%20attacker%20exploits%20them%3A%20By%20enticing%20your%20user%20to%20click%20a%20malicious%20link%20or" title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/09/09/quicktime-security-issue-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zero Day Vulnerability in Microsoft DirectX 9</title>
		<link>http://www.bitsofws.com/index.php/2009/05/29/zero-day-vulnerability-in-microsoft-directx-9/</link>
		<comments>http://www.bitsofws.com/index.php/2009/05/29/zero-day-vulnerability-in-microsoft-directx-9/#comments</comments>
		<pubDate>Fri, 29 May 2009 12:12:36 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/05/29/zero-day-vulnerability-in-microsoft-directx-9/</guid>
		<description><![CDATA[Today, Microsoft released a security advisory warning of a serious unpatched DirectX vulnerability, which attackers have already begun exploiting on the Internet. The vulnerability affects DirectX 9.0 (and earlier versions) running on Windows 2000, XP and Server 2003 computers. It does not seem to affect DirectX 10 running on Windows Vista or Server 2008 computers.]]></description>
			<content:encoded><![CDATA[<h3>Zero Day Vulnerability in Microsoft DirectX 9 </h3>
<h5>Severity: High</h5>
<p>28 May, 2009</p>
<h5>Summary:</h5>
<p>§ <strong>This vulnerability affects</strong>: Microsoft DirectX 9.0 and earlier versions (does not affect DirectX 10)&#160;&#160; </p>
<p>§ <strong>How an attacker exploits it</strong>: By enticing your users into downloading and playing a malicious Quicktime movie, or into visiting a malicious web page </p>
<p>§ <strong>Impact</strong>: An attacker can execute code on your computer, potentially gaining control of it </p>
<p>§ <strong>What to do</strong>: Implement the workarounds described in the Solution Path section of this alert</p>
<h5>Exposure:</h5>
<p>Today, Microsoft released a <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx">security advisory</a> warning of a serious unpatched DirectX vulnerability, which attackers have already begun exploiting on the Internet. The vulnerability affects DirectX 9.0 (and earlier versions) running on Windows 2000, XP and Server 2003 computers. It does not seem to affect DirectX 10 running on Windows Vista or Server 2008 computers. </p>
<p>Since Microsoft just learned about this flaw, they don&#8217;t describe it in much technical detail. They only say the flaw involves the way DirectShow (a component of DirectX) handles specially crafted Quicktime files. However, the advisory does tell how attackers can leverage the flaw. By enticing one of your users into downloading and opening a malicious Quicktime movie, or into visiting a malicious web page, an attacker can exploit this vulnerability to execute code on a victim&#8217;s computer, inheriting that user&#8217;s level of privileges and permissions. If your user has local administrative privileges, the attacker gains full control of the user&#8217;s machine. </p>
<p>With attackers actively exploiting this vulnerability in the wild, it poses a significant threat to Windows 2000, XP, and Server 2003 users. We recommend you implement the workarounds described below to mitigate the risk of this dangerous zero day attack.</p>
<h5>Solution Path:</h5>
<p>Microsoft has not had time to release a full patch for this zero day vulnerability. However, they have released a <a href="http://support.microsoft.com/kb/971778">&quot;Fix it&quot; workaround</a> that will disable DirectX&#8217;s ability to handle Quicktime files. If you don&#8217;t mind disabling Quicktime file handling in Windows, we recommend you apply this &quot;Fix it&quot; workaround until Microsoft releases their final patch. The workarounds described below can also help mitigate the risk of this zero day vulnerability:</p>
<p>1. <strong>Inform your users of this vulnerability. </strong>Advise them to remain wary of unsolicited Quicktime (.mov) movies. If they don&#8217;t absolutely need to view a Quicktime movie, and don&#8217;t fully trust the entity it came from, they should avoid watching it until Microsoft releases a patch. </p>
<p>2. <strong>Use up-to-date antivirus (AV) software.</strong> AV companies are sure to release signatures that detect these malicious Quicktime files. Make sure to update your AV regularly.</p>
<p>3. <strong>Use a gateway device, like your Firebox, to block Quicktime files. </strong>If your users can&#8217;t download Quicktime files, this exploit won&#8217;t affect them. Unfortunately, doing this blocks legitimate Quicktime files as well. Nonetheless, depending on your business needs, you may still consider blocking Quicktime files until Microsoft releases a patch.</p>
<p>We will update this alert when Microsoft releases a patch.</p>
<h6>Courtesy of WatchGuard</h6>
<div class="wlWriterHeaderFooter" style="margin:0px; padding:0px 0px 0px 0px;"><!-- Begin TwitThis (http://twitthis.com/) --><br />
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script><br />
<script type="text/javascript">
</script></p>
<p><a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a></p>
<p><!-- /End --></div>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209&amp;bodytext=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20serious%20unpatched%20DirectX%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20DirectX%209.0%20%28and%20earlier%20versions%29%20running%20on%20Windows%202000%2C%20XP%20and%20Server%202003%20computers.%20It%20does%20not%20seem%20to%20affect%20DirectX%2010%20running%20on%20Windows%20Vista%20or%20Server%202008%20computers." title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209&amp;notes=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20serious%20unpatched%20DirectX%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20DirectX%209.0%20%28and%20earlier%20versions%29%20running%20on%20Windows%202000%2C%20XP%20and%20Server%202003%20computers.%20It%20does%20not%20seem%20to%20affect%20DirectX%2010%20running%20on%20Windows%20Vista%20or%20Server%202008%20computers." title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;t=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209&amp;annotation=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20serious%20unpatched%20DirectX%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20DirectX%209.0%20%28and%20earlier%20versions%29%20running%20on%20Windows%202000%2C%20XP%20and%20Server%202003%20computers.%20It%20does%20not%20seem%20to%20affect%20DirectX%2010%20running%20on%20Windows%20Vista%20or%20Server%202008%20computers." title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F05%2F29%2Fzero-day-vulnerability-in-microsoft-directx-9%2F&amp;title=Zero%20Day%20Vulnerability%20in%20Microsoft%20DirectX%209&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20serious%20unpatched%20DirectX%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20DirectX%209.0%20%28and%20earlier%20versions%29%20running%20on%20Windows%202000%2C%20XP%20and%20Server%202003%20computers.%20It%20does%20not%20seem%20to%20affect%20DirectX%2010%20running%20on%20Windows%20Vista%20or%20Server%202008%20computers." title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/05/29/zero-day-vulnerability-in-microsoft-directx-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zero Day Excel Vulnerability Spreading in the Wild</title>
		<link>http://www.bitsofws.com/index.php/2009/02/24/zero-day-excel-vulnerability-spreading-in-the-wild/</link>
		<comments>http://www.bitsofws.com/index.php/2009/02/24/zero-day-excel-vulnerability-spreading-in-the-wild/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 03:48:19 +0000</pubDate>
		<dc:creator>JamesB</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.bitsofws.com/index.php/2009/02/24/zero-day-excel-vulnerability-spreading-in-the-wild/</guid>
		<description><![CDATA[Today, Microsoft released a security advisory warning of a very serious unpatched Excel vulnerability, which attackers have already begun exploiting on the Internet. The vulnerability affects all current versions of Excel for Windows and Mac, as well as the Microsoft Excel Viewer and the Office Compatibility Packs.]]></description>
			<content:encoded><![CDATA[<p>Today, Microsoft released a <a href="http://www.microsoft.com/technet/security/advisory/968272.mspx">security advisory</a> warning of a very serious unpatched Excel vulnerability, which attackers have already begun exploiting on the Internet. The vulnerability affects all current versions of Excel for Windows and Mac, as well as the Microsoft Excel Viewer and the Office Compatibility Packs. </p>
<p>Since Microsoft just learned about this flaw, they don&#8217;t describe it in much detail. They only describe how attackers exploit it. By enticing one of your users into downloading and opening a maliciously crafted Excel document (.xls), an attacker can exploit this vulnerability to execute code on a victim&#8217;s computer, usually inheriting that user&#8217;s level of privileges and permissions. If your user has local administrative privileges, the attacker gains full control of the user&#8217;s machine. </p>
<p>With attackers actively exploiting this vulnerability in the wild, it poses a critical risk to Microsoft Office and Excel users. Microsoft hasn&#8217;t had time to patch the flaw yet, but they plan to do so in the future. Until then, we recommend you implement the workarounds described below to mitigate the risk of this dangerous zero day attack.</p>
<h5>Solution Path</h5>
<p>Microsoft has not had time to release a patch for this zero day vulnerability. However, the workarounds described below should mitigate the risk of attacks currently circulating in the wild.</p>
<p>§ <strong>Inform your users of this vulnerability. </strong>Advise them to remain wary of unsolicited Excel (.xls) documents arriving via email. If they don&#8217;t absolutely need the document, and don&#8217;t trust the entity it came from, they should avoid opening it until Microsoft releases a patch. </p>
<p>§ <strong>Use antivirus (AV) software and make sure it&#8217;s up to date.</strong> Some AV companies already have signatures that detect these malicious Excel files. Other AV companies will surely follow. </p>
<p>§ <strong>Use the Microsoft Office Isolated Conversion Environment (MOICE) to open untrusted Excel document.&#160; </strong><a href="http://support.microsoft.com/kb/935865">MOICE</a> is a Microsoft add on that provides a special environment which allows you to more securely open Word, Excel, and PowerPoint binary format files. For more details on using it, see the &quot;Suggested Actions&quot; section of&#160; Microsoft&#8217;s <a href="http://www.microsoft.com/technet/security/advisory/968272.mspx">security advisory</a>. </p>


<!-- Begin TwitThis script (http://twitthis.com/) -->
<div style="text-align:left;">
<script type="text/javascript" src="http://s3.chuug.com/chuug.twitthis.scripts/twitthis.js"></script>
<script type="text/javascript">
<!--
document.write('<a href="javascript:;" onclick="TwitThis.pop();"><img src="http://s3.chuug.com/chuug.twitthis.resources/twitthis_grey_72x22.gif" alt="TwitThis" style="border:none;" /></a>');
//-->
</script>
</div>
<!-- /End -->




Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild&amp;bodytext=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20very%20serious%20unpatched%20Excel%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20all%20current%20versions%20of%20Excel%20for%20Windows%20and%20Mac%2C%20as%20well%20as%20the%20Microsoft%20Excel%20Viewer%20and%20the%20Office%20Compatibility%20Packs." title="Digg"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild&amp;notes=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20very%20serious%20unpatched%20Excel%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20all%20current%20versions%20of%20Excel%20for%20Windows%20and%20Mac%2C%20as%20well%20as%20the%20Microsoft%20Excel%20Viewer%20and%20the%20Office%20Compatibility%20Packs." title="del.icio.us"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;t=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild" title="Facebook"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild" title="Mixx"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild&amp;annotation=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20very%20serious%20unpatched%20Excel%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20all%20current%20versions%20of%20Excel%20for%20Windows%20and%20Mac%2C%20as%20well%20as%20the%20Microsoft%20Excel%20Viewer%20and%20the%20Office%20Compatibility%20Packs." title="Google Bookmarks"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild&amp;body=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F" title="email"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="" title="Pownce"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/" title="Pownce" alt="Pownce" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild" title="Reddit"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild" title="StumbleUpon"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F" title="Technorati"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.bitsofws.com%2Findex.php%2F2009%2F02%2F24%2Fzero-day-excel-vulnerability-spreading-in-the-wild%2F&amp;title=Zero%20Day%20Excel%20Vulnerability%20Spreading%20in%20the%20Wild&amp;source=BITS+Business+Information+Technology+Services+of+Winston-Salem&amp;summary=Today%2C%20Microsoft%20released%20a%20security%20advisory%20warning%20of%20a%20very%20serious%20unpatched%20Excel%20vulnerability%2C%20which%20attackers%20have%20already%20begun%20exploiting%20on%20the%20Internet.%20The%20vulnerability%20affects%20all%20current%20versions%20of%20Excel%20for%20Windows%20and%20Mac%2C%20as%20well%20as%20the%20Microsoft%20Excel%20Viewer%20and%20the%20Office%20Compatibility%20Packs." title="LinkedIn"><img src="http://www.bitsofws.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.bitsofws.com/index.php/2009/02/24/zero-day-excel-vulnerability-spreading-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
