Showing posts sorted by relevance for query Windows 7. Sort by date Show all posts
Showing posts sorted by relevance for query Windows 7. Sort by date Show all posts

Microsoft Plugs Internet Explorer Security Hole (Which was Exposed in A Contest)


Microsoft last week patched the last vulnerability in Internet Explorer (IE) used by a researcher in March to win $15,000 at the
The company had patched IE twice before to quash bugs exploited by Stephen Fewer of Harmony Security to bring down IE8 on Windows 7 at Pwn2Own. For his efforts, Fewer was awarded a cash prize of $15,000 and a Sony notebook.

Microsoft internet explorer Fewer chained three exploits , each for a different vulnerability, to bypass IE's sandbox, called "Protected Mode," and compromise IE8. Pwn2Own sponsor HP Tipping Point called the feat "impressive" at the time.
Microsoft patched the third IE bug in a multiple-flaw update to its browser, part of a 13-bulletin collection .
Although Microsoft credited Fewer in the MS11-057 bulletin for reporting the third vulnerability, it said the bug wasn't a security flaw. "Yes, this update addresses a Protected Mode bypass issue, publicly referenced as CVE-2011-1347," Microsoft said in response to an FAQ query, "Does this update contain any non-security related changes to functionality?"
At Pwn2Own, Fewer used the bypass bug to escape Protected Mode so he could circumvent the browser's sandbox, which allowed him to add a file to the machine, a task that mimicked a hacker's insertion of malware.

Fewer confirmed that last week's IE update fixed the final flaw he used at Pwn2Own.
"Yes MS11-057 patches the final bug, the protected mode bypass, that I used in my Pwn2Own exploit, the other two being a use-after-free which was patched in MS11-018 and an information leak patched in MS11-050," Fewer said today in an email reply to questions.

Earlier Flaws Addressed

MS11-018 and MS11-050 were the designations of the April and June bulletins, respectively, that patched the two other vulnerabilities he reported to Microsoft via Tipping Point's bug bounty program.
According to Aaron Portnoy, manager of TippingPoint security research team and the company's Pwn2Own organizer, Tuesday's IE update wraps up patching for the 2011 contest.
During Pwn2Own, Microsoft said that IE9, the browser that launched shortly after Fewer's hack, did not contain the bugs he exploited.
Including Tuesday's update, IE9 has been patched twice since its March launch. Of the August bugs Microsoft acknowledged as security issues, one was reported by Fewer.
"Yes, I have been doing some research into IE9 and actually my first IE9 vulnerability was also patched this Tuesday as part of MS11-057," Fewer said, referring to a separate bug he was credited with this week.
That flaw, dubbed "CVE-2011-1964," was reported via TippingPoint to Microsoft in May, and was ranked critical for IE9 when run on Vista or Windows 7.
Fewer wouldn't commit to taking on IE9 at next year's Pwn2Own, but he left the door open to a repeat performance. "I don't have any plans as of yet for next year's competition, but if I have a few new bugs handy closer to the time, who knows?"
August's security updates, including MS11-057 for IE, can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

-News Source (PC-World)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security firm exploits Chrome zero-day to hack browser, escape sandbox


 French security company Vupen said today that it's figured out how to hack Google's Chrome by sidestepping not only the browser's built-in "sandbox" but also by evading Windows 7's integrated anti-exploit technologies.
Google said it was unable to confirm Vupen's claims.
"The exploit ... is one of the most sophisticated codes we have seen and created so far, as it bypasses all security features including ASLR/DEP/Sandbox," said Vupen in a blog post Monday. "It is silent (no crash after executing the payload), it relies on undisclosed ('zero-day') vulnerabilities and it works on all Windows systems."
Vupen posted a video demonstration of its exploit on YouTube.
According to Vupen, its exploit can be served from a malicious Web site. If a Chrome user surfed to such a site, the exploit executes "various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox at Medium integrity level."
Vupen used the Windows Calculator only as an example: In an actual attack, the "calc.exe" file would be replaced by a hacker-made payload.
Historically, Chrome has been the most difficult browser to hack, primarily because of its sandbox technology, which is designed to isolate Chrome from the rest of the machine to make it very difficult for a hacker to execute attack code on the PC.
For example, Chrome has escaped unscathed in the last three Pwn2Own hacking contests, an annual challenge hosted by the CanSecWest conference in Vancouver, British Columbia, and sponsored by HP TippingPoint's bug bounty program.
Last March, a team from Vupen walked away with a $15,000 cash prize afterhacking Safari, the Apple browser that, like Chrome, is built on the open-source WebKit browser engine.
But no one took on Chrome at 2011's Pwn2Own, even though Google had offered a $20,000 prize to the first researcher who hacked the browser and its sandbox.
The Vupen attack code also bypassed Windows 7's ASLR (address space layout randomization) and DEP (data execution prevention), two other security technologies meant to make hackers' jobs tougher.
Vupen said it would not publicly release details of the exploit, or the unpatched bug(s) in Chrome. "This code and the technical details of the underlying vulnerabilities will not be publicly disclosed," said Vupen. "They are shared exclusively with our Government customers as part of our vulnerability research services."
Last year, Vupen changed its vulnerability disclosure policies when it announced it would no longer report bugs to vendors, but instead would reveal its research only to paying customers.
Other security experts reacted today to the news of one or more Chrome zero-days, and to Vupen's practice of providing details only to its clients.
"I suppose that means we have a known Chrome 0-day floating around. That's fun," said Jeremiah Grossman, CTO of WhiteHat Security, in a Twitter message today.
"That also means for that the [government] is outbidding Google for bug bounties," Grossman added in a follow-up tweet.
"For now, the [government] still has more money than Google," chimed in Charlie Miller, the only researcher who has won cash prizes at four straight Pwn2Own contests.
Google, like rival browser maker Mozilla, runs a bounty program that pays independent researchers for reporting flaws in Chrome. Last month, Google paid out a record $16,500 in bounties for bugs it patched in a single update. In the first four months of 2011, Google spent more than $77,000 on bug bounties.
Google cited Vupen's policy of not reporting flaws as the reason it could not verify the French firm's assertions.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Researcher Figure-out Yet Another Java Hole That Puts 1 Billion Users at Risk

Researcher Figure-out Yet Another Java Hole That Puts 1 Billion Users at Risk

Just as Oracle is ramping up for the September 30 start of JavaOne 2012 in San Francisco yet again another critical Java vulnerability has been spotted in the wild.  The Polish security researcher Adam Gowdiak has found another vulnerability in Java that could allow an attacker to bypass the sandbox. This newly discovered security hole has effected all latest versions of Oracle Java SE software. According to Security Explorations researcher Adam Gowdiak, who sent the email to the Full Disclosure Seclist, this Java exploit affects one billion users of Oracle Java SE software.” So far the researcher were able to successfully exploit the vulnerability and achieve a complete Java security sandbox bypass 
in the environment of Java SE 5, 6 and 7. Researcher could only claim such an impact with reference to Java 7 environment (the 
Apple QuickTime attack relying on Issues 15 and 22 is the only exception here). 





The following Java SE versions were verified to be vulnerable:

  • Java SE 5 Update 22 (build 1.5.0_22-b03)
  • Java SE 6 Update 35 (build 1.6.0_35-b10)
  • Java SE 7 Update 7  (build 1.7.0_07-b10)


All tests were successfully conducted in the environment of a fully patched Windows 7 32-bit system and with the following web browser applications:

  • Firefox 15.0.1
  • Google Chrome 21.0.1180.89
  • Internet Explorer 9.0.8112.16421 (update 9.0.10)
  • Opera 12.02 (build 1578)
  • Safari 5.1.7 (7534.57.2)
So far there are no reports that the vulnerability is being exploited for attacks. Oracle has not said whether or when it will close the vulnerability. Here we want to remind the very recent history, when several zero day vulnerability was found in all the version of java, which was added on BlackHole Exploit kit. Later Oracle released a patch to close the security hole. 








SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Ending Support for Windows Mobile 6.x

Earlier this week, Microsoft announced Windows 7.1 Mango, their latest and greatest software. Well, amidst all the fanfare, the company also quietly revealed the end of support for the older Windows Mobile 6.x software, a move which will be taking place on July 15th.

This means that several things will be going down on the 15th, here are the specifics:
  • “App Submission and Management. On July 15, 2011, we will no longer be accepting new Windows Mobile 6.x applications or application updates. In addition, it will no longer be possible to modify prices, metadata, or other information. However, you will still be able to remove your apps by contacting support.
  • App Distribution. Even though app submission will stop on July 15, users will still be able to purchase and download your Windows Mobile 6.x applications through the Windows Marketplace for Mobile.
  • App Reporting. Sales and download reports will continue to be available for your Windows Mobile 6.x applications through the App Hub after July 15.
  • Developer Payouts. Developer payouts will continue to be processed in accordance with the provisions of the Windows Phone Marketplace Application Provider Agreement.”
In short, the marketplace will still be available post-July 15th but Microsoft will no longer be accepting applications for the dated software. So, if you’ve been toting a Windows Mobile 6.x device around, it might be time to start thinking about making the upgrade to Windows Phone 7, especially now that developers are being forced to abandon ship.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Said, Our Security is Stronger than Sony & RSA, also We are not Vulnerable to DDoS


Microsoft's John Howie claims Microsoft security is stronger than Sony and RSA which were hacked due to "rookie mistakes." The software giant also released Volume 10 of its Security Intelligence Report.

Uh-oh. There's nothing quite like throwing down the gauntlet and virtually taunting hackers to prove a proud boast is false. In what some attackers might consider a dare,  John Howie, Microsoft's senior director in the Online Services Security & Compliance (OSSC) team, basically claimed that Microsoft sites are unhackable and can't be DDoSed.
According to Microsoft, "rookie mistakes" by Sony and security firm RSA caused the corporations to be brought down by hackers. Howie told Computing News that Sony was coded badly and failed to patch its servers. "These are rookie mistakes," Howie said.  In regards to the breach at RSA, Howie stated, "RSA got hacked because someone got socially engineered and opened a dodgy email attachment. A rookie mistake."
Howie added, "At Microsoft we have robust mechanisms to ensure we don't have unpatched servers. We have training for staff so they know how to be secure and be wise to social engineering. We have massively overbuilt our internet capacity, this protects us against DoS attacks. We won't notice until the data column gets to 2GB/s, and even then we won't sweat until it reaches 5GB/s. Even then we have edge protection to shun addresses that we suspect of being malicious."
In other Microsoft security news, after analyzing 600 million computers worldwide, Microsoft released Volume 10 of its Security Intelligence Report. It  focuses on malware, software vulnerability disclosures, vulnerability exploits, and related trends. The majority of all vulnerabilities in 2010 were vulnerabilities in applications versus operating systems or web browsers. Exploiting Java vulnerabilities topped the list of exploitation categories over generic HTML/scripting exploits, operating system exploits, and document exploits. Adobe Acrobat and Reader accounted for the highest number of document format exploits. Windows 7 and Windows Server 2008 R2 had the lowest operating system infection rate for both client and server platforms. 64-bit versions of Windows 7 which "appeal to a more technically savvy audience than their 32-bit counterparts" have the lowest infection rates.
In regard to malicious websites, phishers targeted gaming sites in the first half of 2010 but then targeted social networks. Yet the "number of active sites targeting gaming sites remained relatively high during the second half of the year, which suggests that more campaigns may be coming."
According to the SIR [PDF] Global Threat Assessment graph below, in the 4th quarter of 2010, the most common threat in the USA  was miscellaneous Trojans which affected 38.6% of all cleaned computers. This was down from 43.8% in the 3rd quarter. The second most common threat was Adware which affected 28.3% of all cleaned computers and was up from 23% in the third quarter. "Miscellaneous Potentially Unwanted Software" was the third most common threat in the U.S. and affected 24.6% of cleaned computers. The MSRT detected malware on 11.6 of every 1,000 computers scanned in U.S. in 4Q10 giving the States "a CCM score of 11.6, compared to the 4Q10 average worldwide CCM of 8.7."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

critical Chrome bugs has been patched


Google on Tuesday patched several vulnerabilities in Chrome, including two a French security company said could be used to bypass the browser's anti-exploit technology.
But Chrome 11.0.696.71, which Google rolled out yesterday to users via its automatic update mechanism, does not patch the flaw that Vupen researchers said earlier this month could be exploited on Windows 7. Tuesday's security update was the second for the Chrome "stable" build -- the most polished version of the browser -- this month. Google fixed four vulnerabilities in the update, including two rated "critical," the category typically reserved for bugs that may let an attacker escape Chrome's "sandbox." Google has patched five critical bugs so far this year. One of the remaining pair of flaws was ranked "high" -- and got the researcher who reported it a $1,000 bug bounty -- while the other was labeled "low" on Google's four-step threat scoring system. The two critical vulnerabilities were credited to Google's own security engineers. Although Google declined to confirm that the two most serious bugs could be used by attackers to break out of the Chrome sandbox, and thus plant malicious code on the computer, French security firm Vupen said that that was likely. "The vulnerabilities fixed today and related to GPU and blob handling are a typical example of critical vulnerabilities that can affect Chrome and can be exploited to execute arbitrary code outside the sandbox," said Chaouki Bekar, Vupen's CEO and head of research, in an email reply to questions. Still unpatched, said Bekar, is the bug or bugs that Vupen said its researchers found, then figured out how to exploit, earlier this month. "The recent flaws we discovered in Chrome, including the sandbox bypass, remain unpatched and our exploit code works with version 11.0.696.71, too," said Bekar. Those vulnerabilities made news earlier this month when Vupen announced it had hacked Chrome by sidestepping not only the browser's built-in sandbox but also by evading Windows 7's integrated anti-exploit technologies. Within days, several Google engineers denied that the bugs Vupen exploited were in Chrome itself, claiming instead that the French firm leveraged a flaw in Adobe's Flash, which Google bundles with Chrome. Chrome has been resistant to attack, primarily because of its sandbox technology, which is designed to isolate the browser from the rest of the machine, making it very difficult for a hacker to execute code on the computer. For example, Chrome has escaped unscathed in each of the last three Pwn2Own hacking contests, an annual challenge hosted by the CanSecWest conference in Vancouver, British Columbia, and sponsored by HP TippingPoint's bug bounty program. No other browser included in Pwn2Own has matched Chrome's record at the contest. On Tuesday, Google spokesman Jay Nancarrow declined to comment further about the Vupen exploit claims, and referred to previous statements that Google was unable to investigate the bugs because Vupen would not share details of the flaws. Last year, Vupen announced a change in its vulnerability disclosure policies, saying it would no longer report bugs to vendors -- as do many researchers -- but would reveal its work only to paying customers. According to Web measurement company Net Applications, Chrome accounted for 11.9% of all browsers used last month, putting Google's program in third place behind Microsoft's Internet Explorer, with 55.1%, and Mozilla's Firefox, with 21.6%. Chrome 11 can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Windows Phone App Analyser By David Rook aka SecurityNinja

 Windows Phone App Analyser By David Rook aka SecurityNinja
David Rook, (aka SecurityNinja) has officially released Windows Phone App Analyser. Version 1.0 of the application allows for the evaluation of Windows Phone 7 .xap files and supports the automatic decompilation of the .dll files within them. The tool is inspired by static security analysis tool Agnitio, also from Security Ninja, and presents a tree view of the contents of the .xap file allowing manual review of the files; clicking on .dll files decompiles them to .cs files for viewing or passing to an automated review using CAT.NET or FxCop
The Windows Phone App Analyser also allows researchers to run Microsoft's own Capabilities Detection tool which works out what capabilities the app uses and allows comparison with the app's manifest declarations. 

Key Features Of Windows Phone App Analyser :- 
  • Analyse Windows Phone application source code from a security point of view.
  • Automatically decompile Windows Phone .xap application to easily analyse the original source code
  • Launch and review results from third party scanning tools (CAT.NET, FxCop and the capabilities detection tool).
Features such as keyword editor, store paths to scanning tools so you don’t have to browse to them, option to automatically execute automated scans etc., will be included in the next couple of releases. 

For detailed information & to download Windows Phone App Analyser Click Here

 

 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Oracle Released Emergency Update to Patch Java 0day (CVE-2012-4681)

Oracle Released Emergency Update to Patch Java 0day (CVE-2012-4681)

Zero-day vulnerabilities in Java, which was on the spotlight for last few days; takes a new direction. Several security firms have already declared that, this newly found Java exploit had been added to Blackhole, a popular hacker's tool that bundles numerous exploits and tries each in turn until it finds one that will work against a personal computer. As expected  Oracle has released an emergency update to address those zero-day vulnerabilities. This Security Alert addresses security issues CVE-2012-4681 (US-CERT Alert TA12-240A and Vulnerability Note VU#636312) and two other vulnerabilities affecting Java running in web browsers on desktops. These vulnerabilities are not applicable to Java running on servers or standalone Java desktop applications. They also do not affect Oracle server-based software.
These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages this vulnerability. Successful exploits can impact the availability, integrity, and confidentiality of the user's system.
In addition, this Security Alert includes a security-in-depth fix in the AWT subcomponent of the Java Runtime Environment.
Due to the severity of these vulnerabilities, the public disclosure of technical details and the reported exploitation of CVE-2012-4681 "in the wild," Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible.

Supported Products Affected

Security vulnerabilities addressed by this Security Alert affect the products listed in the categories below.  Please click on the link in the Patch Availability column or in the Patch Availability Table to access the documentation for those patches.
Affected product releases and versions:
Java SEPatch Availability
JDK and JRE 7 Update 6 and beforeJava SE
JDK and JRE 6 Update 34 and beforeJava SE

Patch Availability Table and Risk Matrix

Java SE fixes in this Security Alert are cumulative; this latest update includes all fixes from previous Critical Patch Updates and Security Alerts.

Patch Availability Table

Product GroupRisk MatrixPatch Availability and Installation Information
Oracle Java SEOracle JDK and JRE Risk Matrix

Also Java 7 Update 7 is now available to download for Windows (32- and 64-bit), Linux (32- and 64-bit), Mac OS X (64-bit), Solaris x86 (32- and 64-bit) and Solaris SPARC (32- and 64-bit). JDKs with the updated Java runtimes are also available. Users with Java installed on their systems, whatever operating system, should install the updates as soon as possible because malicious software that uses the vulnerability is already in circulation. For detailed information click here






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Security Essentials is on the first place in North America



Microsoft (17.07 percent), AVG (15.63 percent), and Symantec (14.47 percent) were found to be the top three antivirus vendors in North America, according to the latest quarterly antivirus market share report released by OPSWAT. Microsoft increased its market share from OPSWAT's previous antivirus report to surpass Symantec and become the North American leader. AVG held steady in the second position, and Symantec fell to third.
Worldwide, the top three antivirus vendors detected were Avast (12.37 percent), AVG (12.37 percent), and Avira (12.29 percent). Microsoft was fourth (11.24 percent), followed by ESET Software (9.98 percent).
The software company analyzed more than 43,000 opt-in reports from endpoints worldwide. The reports, generated by OPSWAT's AppRemover and Am I OESIS OK? tools, utilize the detection capabilities of the OESIS Framework to list the applications installed on the endpoint computer. The full 8-page document, titled Q2 2011 Antivirus and Instant Messenger Market Share Report, includes data on the leading antivirus vendors and products in North America and worldwide, Windows OS usage in North America and worldwide, instant messaging market share worldwide, and instant messaging usage in North America and Europe.
The rest of the data wasn't too surprising: Windows 7 usage continues to increase in North America and worldwide, showing a steady trend away from Windows Vista. In both North America and worldwide, Windows XP remains the dominant Windows operating system. The top three worldwide IM applications are Windows Live Messenger, Skype, and Yahoo! Messenger. The report does not, however, account for Web-based instant messaging services such as Google Chat or Facebook. This is because it only looks at installed applications, and those services run in the browser.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Social-Engineer Toolkit (SET) 3.0 Codenamed #WeThrowBaseballs Released

Social-Engineer Toolkit (SET) 3.0 Codenamed #WeThrowBaseballs Released
Earlier we have discussed many times about Social Engineer Toolkit also known as SET. Yet again the developer officially released the updated version of Social Engineer Toolkit Version 3 codename “#WeThrowBaseballs”. According to the developer- This release has been one of the most challenging ones thus far with the largest changelog, code rehaul, and features. Earlier all the version ware made for Unix & Linux platform in this release they have also made SET available for Windows Platform. 
Features:- 
1. Support for Windows – Tested on XP, Windows 7, and Windows Vista. Note that the Metasploit-based payloads to not work yet – when SET detects Windows they will not be shown only RATTE and SET Shell
2. New attack vector added – QRCode Attack – Generates QRCodes that you can direct to SET and perform attacks like the credential harvester and Java Applet attacks
3. Improved A/V avoidance on the SETShell and better performance. I’ve also fixed the non-encrypted communications when AES was not installed
4. Added a number of improvements and enhancements to all aspects of SET including major rehauls of the coding population and moved from things like subprocess.Popen(“mv etc.”) to shutil.copyfile(“etc”)
5. Rehauled SET Interactive Shell and RATTE to support Windows
6. New Metasploit exploits added to SET

Official change log and rest of other details can be found on the blog post of the developer. To Download Social Engineer Toolkit 3.0 Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Admits to More Windows Phone Update Problems


Yet another problem has cropped up preventing some Windows Phone 7 users from getting two software updates, adding a new chapter to the update saga that started in February.
Microsoft acknowledged that some Samsung Focus owners in the U.S. haven't yet received notification that the updates are available for them. "They're looking into the situation, but I'm afraid there's not much to report yet," wrote Michael Stroh, a Microsoft employee who is answering questions posted to the comments section on the Windows Phone blog.
On another Microsoft forum, some Focus users who haven't received the updates noticed that they have a more recent build version of the phone. While people with version REV 1.3 have gotten the updates, some of those with REV 1.4 haven't.
In addition, Stroh said that Microsoft has stopped sending updates to the Omnia 7, a phone available in Europe. "The team discovered a technical issue with the update package for this model. The work of fixing and testing the package is nearly done, and the team hopes to resume update deliveries soon," he wrote.
These are the latest issues to plague Microsoft as it tries to send out new software to Windows Phone 7 handsets. Microsoft started in February by pushing out software designed to make the update process smoother. It pulled that update shortly after because it made some Samsung phones unusable.
The company then delayed the first update of substance, known as NoDo, which adds the capability to cut and paste, to try to avoid similar problems. It is now pushing out both pieces of software simultaneously.
In the U.S., the software is being delivered to all phones except the HTC Surround, according to astatus page from Microsoft about the process. The updates are being delivered in most international markets as well.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Oracle Released Java 7 update 10 With Security Enhancements & Bug Fixes

Oracle Released Java 7 update 10 With Security Enhancements & Bug Fixes 

This is the third time in a year when Oracle has updated the standard edition of Java platform. This release includes new security controls in addition to a bug fix and updated timezone data. This latest update also contains a number of security enhancements and is now certified for Mac OS X 10.8 and Windows 8. The security enhancements include the ability to disable any Java application from running in the browser and the ability to set a desired level of security for unsigned applets, Java Web Start applications, and embedded JavaFX applications. While keeping in mind the last security issues with Java, in the press release of this Java update Oracle said "if the JRE is deemed expired or insecure, additional security warnings are displayed. In most of these dialogs, the user has the option to block running the app, to continue running the app, or to go to java.com to download the latest release."

Security Feature Enhancements

The JDK 7u10 release includes the following enhancements:
  • The ability to disable any Java application from running in the browser. This mode can be set in the Java Control Panel or (on Microsoft Windows platform only) using a command-line install argument.
  • The ability to select the desired level of security for unsigned applets, Java Web Start applications, and embedded JavaFX applications that run in a browser. Four levels of security are supported. This feature can be set in the Java Control Panel or (on Microsoft Windows platform only) using a command-line install argument.
  • New dialogs to warn you when the JRE is insecure (either expired or below the security baseline) and needs to be updated.

Bug Fixes

Notable Bug Fixes in JDK 7u10

The following are some of the notable bug fixes included in JDK 7u10.
Area: java command

Description: Wildcard expansion for single entry classpath does not work on Windows platforms.

The Java command and Setting the classpath documents describe how the wildcard character (*) can be used in a classpath element to expand into a list of the .jar files in the associated directory, separated by the classpath separator (;).
This wildcard expansion does not work in a Windows command shell for a single element classpath due to the Microsoft bug described in Wildcard Handling is Broken.
See 7146424.
For a list of other bug fixes included in this release, see JDK 7u10 Bug Fixes page. 

The updated Java Development Kit and Java Runtime Environment are available to download from the Oracle site. 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

TeamViewer 7 Finally Available For Linux


TeamViewer 7 for Windows was released about a month ago now the Ver 7 is available for Linux though its a beta release. TeamViewer is an application for remote control, desktop sharing and file transfer between computers, great for meetings, presentations, support and more. It runs on Windows, Mac OSX, Linux (even though it comes in a .deb or .rpm, it uses Wine which comes bundled with it) as well as Android or iPhone. The application is free for personal use only.

What is New In TeamViewer 7 :- 
  • Enhanced multi-monitor support
  • An integrated screenshot tool
  • Record presentations
  • Save connection settings per Computer (store individual connection settings for each computer in your Computers & Contacts list) - see the first screenshot in the post
  • Instant meeting (you can start your meeting even before adding any participants - ideal for preparation and testing)
  • Scheduled meetings
  • Mobile participation via Android / iOS client
  • File Box (make files available for download during meeting)

To Download TeamViewer 7 Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Security Bulletin (March 2012) Closed Critical RDP Security Hole

Microsoft Security Bulletin (March 2012) Closed Critical RDP Security Hole 

Microsoft released March 2012 Security bulletins to close a total of seven security holes in its products. Among them one Critical-class, four Important and one Moderate – addressing seven issues in Microsoft Windows, Visual Studio, and Expression Design. According to Microsoft (MS12-020) remote code execution vulnerability has been found in RDP (Remote Desktop Protocol).
The first of these is a "critical-class" issue in RDP that could be exploited by an attacker to remotely execute arbitrary code on a victim's system. Although RDP is disabled by default, many users enable it so they can administer their systems remotely within their organizations or over the Internet. All supported versions of Windows from Windows XP Service Pack 3 to Windows 7 Service Pack 1 and Windows Server 2008 R2 are affected. As the issue was reported to company by the Zero Day Initiative (ZDI), Microsoft says that it has yet to see any active attacks exploiting these in the wild, but warns that, "due to the attractiveness of this vulnerability to attackers", it anticipates "that an exploit for code execution will be developed in the next 30 days". Because of this it recommends that installing the updates should be made a priority. 
Microsoft has also provided a workaround and a no-reboot "Fix it" tool that enables Network-Level Authentication (NLA) to mitigate the problem. A second "moderate-class" denial-of-service (DoS) which can cripple an RDP server was also fixed.
A brief overview of all of these updates, including descriptions about each of the vulnerabilities, can be found in Microsoft's Security Bulletin Summary for March 2012.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Remote Code Execution Vulnerability In TCP/IP


A remote code execution vulnerability has been discovered in the Microsoft Windows TCP/IP stack. This vulnerability occurs when Windows processes a continuous flow of specially crafted UDP packets. An attacker could exploit this vulnerability by sending a continuous flow of specially crafted UDP packets to a closed port on a target system, resulting in an integer overflow. Successful exploitation could allow attackers to run arbitrary code with kernel mode privileges. This could allow attackers to install programs; view, change, or delete data; or create new accounts with full user rights.

Affected System:-
  • Microsoft Windows Vista
  • Microsoft Windows 7
  • Microsoft Windows Server 2008
 For more information click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Is Ubuntu 11.04 Beating Apple's Mac OS X?

Welcome to Ubuntu 11.04


Canonical yesterday released the final version of Ubuntu Linux 11.04. For quite some time Ubuntu will get a new release twice per year - one in April and one in October. As usual with updated distributions, the release comes with updated software. In this case however, the software responsible for the appearance of the desktop was changed. While previous Ubuntu releases relied on Gnome as a desktop manager, with 11.04 Ubuntu makes the switch to the Unity desktop environment.

Before we come to the new desktop in more detail, lets mention some of the general updates the operating system received. The kernel got updated to the latest Linux 2.6.38. Recently there have been reports that this version exhibits higher power consumption, which is detrimental for mobile systems. However, it should be noted that the bug responsible for this has already been in previous versions as well. Currently this is under investigation by kernel developers. Canonical promised to release a patch to the kernel once the problem is resolved. Other major software has been updated as well. Most notably Firefox comes in the most recent release number four. OpenOffice.org has been replaced by LibreOffice 3.3.2.

Regarding Unity it should be noted that it requires 3D acceleration, which is dependent on the availability of a suitable graphics driver. Using AMD and Intel graphics you can start right away, since open source drivers for their graphic cards / chipsets are available and included in the LiveCD. People with nVidia hardware first have to install the proprietary driver offered by the manufacturer which is not redistributed with Ubuntu. That rules out testing Unity from the LiveCD though, an installation is required. If 3D acceleration is not available, the classic Gnome interface known from previous Ubuntu releases is employed.



As with every Linux operating system, navigation through multiple applications is a breeze
As with every Linux operating system, navigation through multiple applications is a breeze

Though the current iteration in Ubuntu has a few back draws, some of the features remind us of Windows 7. The overview of the windows would also be nice to see if the application is not the active one. Though in this case a click will simply activate all windows of the application. Also the launcher cannot be easily changed in position or appearance. The program for customizing it isn't even installed by default. The program needed for that is called "Advanced Desktop Effects Settings". That being said even with that program I had a hard time customizing Unity.

Personally I'd like to have smaller symbols and move the launcher to the bottom of the screen. Probably because I'm used to working on Windows. But as a neutral argument, consider one of the common widescreen displays. There you have way more screen real estate in the horizontal than in the vertical dimension. On high widescreen resolutions you can even get away with big icons if they are aligned horizontally.

When you want to launch one of the less frequently used programs (i.e. you have not pinned it to the launcher), you may click on the Ubuntu symbol in the top left or at the magnifying glass with the plus in it named "Applications". This opens the dashboard where both installed and downloadable applications are listed. Navigating needs getting used to there. Generally the dashboard is categorized both in types of programs and whether its installed or not. The intent of the developers is probably to use the search box, but if you don't know what you are looking for it can be a bit of a hassle..

Control Center by Unity User Interface for Ubuntu 11.04


Control Center in Ubuntu 11.04 is very functional and smoothly animated

In general for experienced Ubuntu users like I would characterize myself the new interface definitely has a learning curve. For new users it probably depends. Unity works very well if you continuously use a small number of the same applications most of the time. Some of its functionality is very intuitive, in other areas it needs some polish. If you can't stand Unity, it's possible to revert to the classic Gnome desktop (or KDE if you prefer Kubuntu) by changing the Login Screen settings. Speaking of settings, while the applets can also be found via the dashboard, this is not very intuitive. Thankfully, if you invoke the menu of the power off symbol to the top right, the last entry called "System Settings" opens up a dialog similar to the Windows control panel. All available configuration applets can be accessed from there.

Conclusion
Overall I think the brave step by Canonical to change the whole desktop experience of Ubuntu might pay off in the long run. Some usability tests conducted with less experienced users showed, that basic tasks could be accomplished very easily since the buttons for the web browser or word processing are very prominent on the new launcher. Long term Ubuntu users might be initially turned off by the new interface. I'd suggest to give it a try. If you don't like it, simply revert to Gnome 2 or even install the more modern Gnome 3 interface (or whatever you prefer). That being said Unity requires some more polish in some regards. We have outlined some things we noticed in our short testing, that didn't feel natural or were a bit confusing.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...