Showing posts sorted by relevance for query Windows 7. Sort by date Show all posts
Showing posts sorted by relevance for query Windows 7. Sort by date Show all posts

Microsoft Unveils Windows Phone 8 Codenamed “Apollo”

Microsoft Unveils Windows Phone 8 Codenamed “Apollo”

Few days ago in a report we have said that Microsoft is expected to launch it's own tablet (Microsoft Surface) while aiming to compete with iPad. Redmond based software and hardware giant just unveiled the next big step in its mobile software, Windows Phone 8 codenamed “Apollo” Windows Phone 8 brings the platform in line with other mobile OSes by adding support for muti-core processors, higher screen resolutions and newer wireless technologies like near field communication (NFC). Importantly, Microsoft has re-coded Windows Phone from the ground up for the new version. Previous versions of Windows Phone were based on Microsoft’s old mobile OS, Windows CE, but now the platform will share the same source code as the company’s coming desktop OS, Windows 8. That has big consequences for developers and consumers. For developers, it will be extremely easy to create a Windows Phone app if they already have a Windows 8 app that runs in the Metro environment (and vice versa). For consumers, it means more apps and better hardware to run them. It also has the effect of rendering every current Windows Phone obsolete, since those phones won’t be able to run the new software. They will, however, get an upgrade to Windows Phone 7 to 8. Windows Phone 8 adds support for many new hardware features. The most anticipated is support for multi-core devices, which have become common on both Android and iOS platforms. There’s also support for better screen resolutions, including 720p and 1,280 x 768 (WXGA). That’s not quite retina, but it’s better than the 800 x 480 screen of the Nokia Lumia 900, one of the current leading Windows Phones.

New Features At a Glance :-
  • Support for multi-core processors. Existing support for single core has been a major concern for some high-end users wanting faster processing ability.
  • Two new high-definition screen resolutions for the coming OS. They are 1280 x 768 and 1280 x 720.
  • Removeable micro-SD support for the first time to allow expansion of base storage.
  • A busier start screen with room for more live tiles than in Windows Phone 7.5. Today's Windows Phones have room for up to eight live tiles and WP8 will have room for up to 32 live tiles, which can be sized differently.
  • IT support. Adminstrators will see some gaps in the existing OS filled, including support for encryption and secure boot in WP8, as well as the ability to allow IT to deploy apps without going through Windows Marketplace.
  • Built-in Nokia Navteq map technology, with turn-by-turn driving instructions in many countries.
  • Full Internet Explorer 10 support with more features of HTML 5 added. Belfiore said that Windows Phone 8 with IE10 will download Web pages slightly faster than three other popular smartphones on the market.
  • Native code support, a feature seen as useful to developers eager to move their apps from iOS or Android to Windows Phone. 


-Source (Mshable & CW)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Critical Zero-Day Vulnerability In Windows 7 (Exploitable Via Apple's Safari Browser)


Highly critical Zero-day vulnerability found in Windows 7. This security flaws can be exploited via Apple Safari browser.  This was first made public via a twitter user named w3bd3vil 

"<iframe height='18082563'></iframe> causes a BSoD [blue screen of death] on win 7 x64 via Safari. Lol!"


It is reported that vulnerability affects fully patched Windows 7 Professional 64-bit and cautioned that other versions may be affected. The remotely exploitable vulnerability, caused by an error in win32k.sys, enables a hacker to run arbitrary code -- such as malware -- on a victim's machine when he or she visits a specially crafted Web page using Safari. Specifically, the Web page would simply need to contain an iFrame -- an HTML element that is typically used to pull content from other sources onto a Web page -- with an overly large "height" attribute.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Metasploit 4.2.0 Released With IPv6 Support & Virtualization Target Coverage

Metasploit 4.2.0 Released With IPv6 Support & Virtualization Target Coverage
Earlier we haev discussed many times about one of the most famous and widely used exploitation framework named Metasploit. Yet again the Rapid 7 released another updated version of Metasploit. This update brings Metasploit to version 4.2.0, adding IPv6 support and virtualization target coverage. You'll also notice a new Product News section and update notification for our weekly updates. Since the last major release (4.1.0), added 54 new exploits, 66 new auxiliary modules, 43 new post-exploitation modules, and 18 new payloads. 
Brief About Metasploit:- 
The Metasploit Framework is a penetration testing toolkit, exploit development platform, and research tool. The framework includes hundreds of working remote exploits for a variety of platforms. Payloads, encoders, and nop slide generators can be mixed and matched with exploit modules to solve almost any exploit-related task.
Module Changes:-
  •     Novell eDirectory eMBox Unauthenticated File Access
  •     JBoss Seam 2 Remote Command Execution
  •     NAT-PMP Port Mapper
  •     TFTP File Transfer Utility
  •     VMWare Power Off Virtual Machine
  •     VMWare Power On Virtual Machine
  •     VMWare Tag Virtual Machine
  •     VMWare Terminate ESX Login Sessions
  •     John the Ripper AIX Password Cracker
  •     7-Technologies IGSS 9 IGSSdataServer.exe DoS
  •     Microsoft IIS FTP Server <= 7.0 LIST Stack Exhaustion
  •     DNS and DNSSEC fuzzer
  •     CheckPoint Firewall-1 SecuRemote Topology Service Hostname Disclosure
  •     CorpWatch Company ID Information Search
  •     CorpWatch Company Name Information Search
  •     General Electric D20 Password Recovery
  •     NAT-PMP External Address Scanner
  •     Shodan Search
  •     H.323 Version Scanner
  •     Drupal Views Module Users Enumeration
  •     Ektron CMS400.NET Default Password Scanner
  •     Generic HTTP Directory Traversal Utility
  •     Microsoft IIS HTTP Internal IP Disclosure
  •     Outlook Web App (OWA) Brute Force Utility
  •     Squiz Matrix User Enumeration Scanner
  •     Sybase Easerver 6.3 Directory Traversal
  •     Yaws Web Server Directory Traversal
  •     OKI Printer Default Login Credential Scanner
  •     MSSQL Schema Dump
  •     MYSQL Schema Dump
  •     NAT-PMP External Port Scanner
  •     pcAnywhere TCP Service Discovery
  •     pcAnywhere UDP Service Discovery
  •     Postgres Schema Dump
  •     SSH Public Key Acceptance Scanner
  •     Telnet Service Encyption Key ID Overflow Detection
  •     IpSwitch WhatsUp Gold TFTP Directory Traversal
  •     VMWare ESX/ESXi Fingerprint Scanner
  •     VMWare Authentication Daemon Login Scanner
  •     VMWare Authentication Daemon Version Scanner
  •     VMWare Enumerate Permissions
  •     VMWare Enumerate Active Sessions
  •     VMWare Enumerate User Accounts
  •     VMWare Enumerate Virtual Machines
  •     VMWare Enumerate Host Details
  •     VMWare Web Login Scanner
  •     VMWare Screenshot Stealer
  •     Capture: HTTP JavaScript Keylogger
  •     Oracle DB SQL Injection via SYS.DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION
  •     Asterisk Manager Login Utility
  •     FreeBSD Telnet Service Encryption Key ID Buffer Overflow
  •     Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
  •     Java Applet Rhino Script Engine Remote Code Execution
  •     Family Connections less.php Remote Command Execution
  •     Gitorious Arbitrary Command Execution
  •     Horde 3.3.12 Backdoor Arbitrary PHP Code Execution
  •     OP5 license.php Remote Command Execution
  •     OP5 welcome Remote Command Execution
  •     Plone and Zope XMLTools Remote Command Execution
  •     PmWiki <= 2.2.34 pagelist.php Remote PHP Code Injection Exploit
  •     Support Incident Tracker <= 3.65 Remote Command Execution
  •     Splunk Search Remote Code Execution
  •     Traq admincp/common.php Remote Code Execution
  •     vBSEO <= 3.6.0 proc_deutf() Remote PHP Code Injection
  •     Mozilla Firefox 3.6.16 mChannel Use-After-Free
  •     CTEK SkyRouter 4200 and 4300 Command Execution
  •     Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
  •     Icona SpA C6 Messenger DownloaderActiveX Control Arbitrary File Download and Execute
  •     HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
  •     Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX Control
  •     Java MixerSequencer Object GM_Song Structure Handling Vulnerability
  •     MS05-054 Microsoft Internet Explorer JavaScript OnLoad Handler Remote Code Execution
  •     MS12-004 midiOutPlayNextPolyEvent Heap Overflow
  •     Viscom Software Movie Player Pro SDK ActiveX 6.8
  •     Adobe Reader U3D Memory Corruption Vulnerability
  •     Aviosoft Digital TV Player Professional 1.0 Stack Buffer Overflow
  •     BS.Player 2.57 Buffer Overflow
  •     CCMPlayer 1.5 m3u Playlist Stack Based Buffer Overflow
  •     Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
  •     McAfee SaaS MyCioScan ShowReport Remote Command Execution
  •     Mini-Stream RM-MP3 Converter v3.1.2.1 PLS File Stack Buffer Overflow
  •     MS11-038 Microsoft Office Excel Malformed OBJ Record Handling Overflow
  •     Ability Server 2.34 STOR Command Stack Buffer Overflow
  •     AbsoluteFTP 1.9.6 - 2.2.10 LIST Command Remote Buffer Overflow
  •     Serv-U FTP Server < 4.2 Buffer Overflow
  •     HP OpenView Network Node Manager ov.dll _OVBuildPath Buffer Overflow
  •     XAMPP WebDAV PHP Upload
  •     Avid Media Composer 5.5 - Avid Phonetic Indexer Buffer Overflow
  •     Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020000 Buffer Overflow
  •     HP Diagnostics Server magentservice.exe Overflow
  •     StreamDown 6.8.0 Buffer Overflow
  •     Wireshark console.lua Pre-Loading Script Execution
  •     Oracle Job Scheduler Named Pipe Command Execution
  •     SCADA 3S CoDeSys CmpWebServer <= v3.4 SP4 Patch 2 Stack Buffer Overflow
  •     Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
  •     OpenTFTP SP 1.4 Error Packet Overflow
  •     AIX Gather Dump Password Hashes
  •     Linux Gather Saved mount.cifs/mount.smbfs Credentials
  •     Multi Gather VirtualBox VM Enumeration
  •     UNIX Gather .fetchmailrc Credentials
  •     Multi Gather VMWare VM Identification
  •     UNIX Gather .netrc Credentials
  •     Multi Gather Mozilla Thunderbird Signon Credential Collection
  •     Multiple Linux / Unix Post Sudo Upgrade Shell
  •     Windows Escalate SMB Icon LNK dropper
  •     Windows Escalate Get System via Administrator
  •     Windows Gather RazorSQL Credentials
  •     Windows Gather File and Registry Artifacts Enumeration
  •     Windows Gather Enumerate Computers
  •     Post Windows Gather Forensics Duqu Registry Check
  •     Windows Gather Privileges Enumeration
  •     Windows Manage Download and/or Execute
  •     Windows Manage Create Shadow Copy
  •     Windows Manage List Shadow Copies
  •     Windows Manage Mount Shadow Copy
  •     Windows Manage Set Shadow Copy Storage Space
  •     Windows Manage Get Shadow Copy Storage Info
  •     Windows Recon Computer Browser Discovery
  •     Windows Recon Resolve Hostname
  •     Windows Gather Wireless BSS Info
  •     Windows Gather Wireless Current Connection Info
  •     Windows Disconnect Wireless Connection
  •     Windows Gather Wireless Profile
For additional information click Here. To Download Metasploit version 4.2.0 for windows & Linux click Here.

 -Source (rapid7)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Red Hat Enterprise Linux 7 Beta Arrives! Download Now And You Can Win $500

Red Hat Enterprise Linux (RHEL) 7 Arrived With Expanded Container Support, Performance Profiles, XFS As the Default Filesystem & Many More. 
We have just spent a less than a month time after the release of Red Hat Enterprise Linux 6.5 made available globally, yet again the American multinational software company, leading the world for open-source software has announced the availability of a first public beta release of Red Hat Enterprise Linux (RHEL) version 7. Based on Fedora 19 and the upstream Linux 3.10 kernel, Red Hat Enterprise Linux 7 will provide users with powerful new capabilities that streamline and automate installation and deployment, simplify management, and enhance ease-of-use, all while delivering the stability that enterprises have come to expect from Red Hat. This further solidifies Red Hat Enterprise Linux's place as the world's leading Linux platform and a standard for the enterprise of the future. Whether rolling out new applications, virtualizing environments or scaling the business with cloud, Red Hat Enterprise Linux 7 delivers the keystone to IT success. The beta release of Red Hat Enterprise Linux 7 adds value to new and existing IT projects across industries by adding key capabilities to improve critical but often cumbersome IT tasks like virtualization and storage while offering a clear pathway to the open hybrid cloudIn their official Red Hat Enterprise Linux YouTube channel, Red Hat posted a short video where you can hear what the team at Red Hat has to say about the next-generation of the world’s leading Linux platform.

Red Hat Enterprise Linux 7 Beta showcases hundreds of new features and enhancements, including: 
  • Linux Containers - Enabling applications to be created and deployed in isolated environments with allocated resources and permissions.
  • Performance Management – Using built in tools, you can optimize performance out-of-the-box.
  • Physical and Hosted In-place Upgrades - In-place upgrades for common server deployment types are now supported. Additionally, virtual machine migration from a Red Hat Enterprise Linux 6 host to a Red Hat Enterprise Linux 7 host is possible, without virtual machine modification or downtime.
  • File Systems – File systems continue to be a major focus of development and innovation.
    • XFS is now the default file system, supporting file systems up to 500TB
    • ext4 file systems are now supported to 50TB and include block sizes up to 1MB
    • btrfs file systems are now available to test
  • Networking – Enhanced networking configuration and operation. Added support for some of the latest networking standards, including:
    • 40Gb Ethernet support
    • Improved channel bonding
    • TCP performance improvements
    • Low latency socket poll support
  • Storage – Expanded support for enterprise level storage arrays. Improved scalable storage stack for deployments that are less disk intensive. Improved storage management for heterogeneous storage environments.
  • Windows Interoperability – Bridge Windows™ and Linux infrastructure by integrating SAMBA 4.1 with existing Microsoft Active Directory domains. Or, deploy Red Hat Enterprise Linux Identity Management in a parallel trust zone with Active Directory.
  • Subsystem Management – Simplified configuration and administration with uniform management tools for networking, storage, file systems, performance, identities and security. Leveraging the OpenLMI framework, enables use of scripts and APIs to automate management.
To know deeply about the hot features and enhancement of RHEL 7 beta 1, click hereI am quite sure that, after going through with the above description, all of you are very much excited to grab this brand new beta of RHEL 7. Like the previous beta release, this time also The Red Hat Enterprise Linux 7 beta has been made available to Red Hat customers, partners, and members of the public. For further information and to access the beta click here. Last but not least, with this release Red Hat also calls for an very interesting competition, where you can participate & win $500 while telling Red Hat, what interests you most in RHEL 7 beta. So what are you waiting for, lets download RHEL 7 and explore it. 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Said: Stolen SSL Certificates May Be Dangerous While Updating Your Windows


Microsoft said Sunday that a digital certificate stolen from a Dutch company could not be used to force-feed customers malware through its Windows Update service. The company's assertion came after a massive theft of more than 500 SSL (secure socket layer) certificates, including several that could be used to impersonate Microsoft's update services, was revealed by Dutch authorities and several other affected developers.

"Attackers are not able to leverage a fraudulent Windows Update certificate to install malware via the Windows Update servers,"
said Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), in a Sunday blog post. "The Windows Update client will only install binary payloads signed by the actual Microsoft root certificate, which is issued and secured by Microsoft."

Seven of the 531 certificates now known to have been fraudulently obtained by hackers in July were for the domains update.microsoft.com and windowsupdate.com, while another six were for *.microsoft.com. According to Microsoft, the certificates issued for windowsupdate.com couldn't be used by attackers because the company no longer uses that domain. (Windows Update is now at windowsupdate.microsoft.com..) However, those for update.microsoft.com -- the domain for Microsoft Update -- and the wildcard *.microsoft.com could be.

As Ness said, updates delivered via Microsoft's services are signed with a separate certificate that's closely held by the company. Without that code-signing certificate, attempts to deliver malware disguised as an update to a Windows PC would fail. Other vendors, including Apple, also sign software updates with a separate certificate. The certificates for the various Microsoft domains were issued by DigiNotar, a Dutch company that last week admitted its network had been hacked in mid-July. The company initially believed it had revoked all the fraudulent certificates, but later realized it had overlooked one that could be used to impersonate any Google service, including Gmail. DigiNotar went public only after users reported their findings to Google.
Criminals or governments could use the stolen certificates to conduct "man-in-the-middle" attacks, tricking users into thinking they were at a legitimate site when in fact their communications were being secretly intercepted. Microsoft has added its voice to the chorus from rival browser makers, notably Google and Mozilla, about the seriousness of the situation. Like its competitors, Microsoft will also permanently block all DigiNotar certificates.

"We are in the process of moving all DigiNotar owned or managed [certificate authorities] to the Untrusted Root Store, which will deny access to any website using DigiNotar certificates," said Dave Forstrom, a director in the Microsoft Trustworthy Computing group, in an emailed statement Sunday.

Forstrom did not set a date by when Microsoft would block all DigiNotar certificates, including those used by the Dutch government, which has been a major customer of the company. Google updated Chrome on Saturday to block all DigiNotar certificates, while Mozilla plans to do the same on Tuesday for Firefox.

However, Microsoft's partial ban of DigiNotar certificates -- which it instituted last week -- and the complete sanction now in the works only protects users running Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2. Customers still on Windows XP or Windows Server 2003 must wait for an update specific to those operating systems; Ness said only that that update would "be available soon."
Until that Windows XP update is available, users can protect themselves by manually deleting the DigiNotar root from the list of approved certificate-issuing authorities. 

For more information and to look at the Microsoft press release click Here 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

RecoveryFix for Windows Version - 11.01 Launched

Lepide Software, a well known name in the realm of software development organizations, has announced the launch of upgraded version of RecoveryFix for Windows 11.01. This powerful and reliable Windows data recovery software is designed to perform flawless partition recovery in cases of partition damage or when MBR, Boot Sector or File allocation table is lost or even when MFT gets corrupt. This tool effectively recovers data from the corrupt windows partitions based on FAT or NTFS operating systems and even from the reformatted partitions.

RecoveryFix for Windows enables the user to scan the damaged hard disk with its three robust scan modes: Quick Scan, Extensive Scan and File Trace. Here Quick Scan recovers the recently deleted or lost data, Extensive Scan allows you to retrieve lost, deleted, formatted and reformatted files/folders and partitions. File Trace is the slowest mode as it performs recovery from each and every sector of the hard disk.

This data recovery software is ideal software for those, who wish to recover their lost data from Windows partitions. Owing to use of this software, user can retrieve almost all the data that was lost due to voltage fluctuation, software faults, hardware failures, virus attacks etc. RecoveryFix for Windows works successfully on computers installed with Windows OS Windows versions 95 / 98 / 2000 / 2003 / 2000 / XP / Vista/ Windows7 and supports recovery of data from FAT16, FAT32, NTFS and NTFS5 file systems. For details about RecoveryFix for Windows, please visit: http://www.recoveryfix.com/recover-windows-data.html

Key Features:

1. Mentioned below are some of the key features of RecoveryFix for Windows:
2. Performs flawless data recovery from FAT and NTFS partitions
3. Integrated with Windows explorer like view to ease recovery of data from hard disk
4. Capable of recovering deleted or damaged files, folders and partitions
5. Recovers data lost due to Virus attacks, power failures, voltage fluctuations, software faults etc.
6. Restores corrupt or damaged partition tables
7. Recovers data in cases of MBR, Boot Sector or File Allocation Table damage or when MFT gets corrupt
8. Supports recovery of data from EIDE, IDE, SCSI and SATA, PAN, ZIP and USB drives

The Windows data recovery software is available with free evaluation version that allows you to scan, repair and recover the data from Windows FAT and NTFS partition. However, it limits you from saving the same. To save the data so recovered, you must purchase the full version of RecoveryFix for Windows.
 

About Recovery Fix :-

Recovery Fix is the leading brand in the field of data recovery, email recovery, file repair, email migration, backup recovery and computer monitoring. Having years of experience, RecoveryFix has become the most trusted name among both enterprise and home users. Being in the market from year 2004, the brand- RecoveryFix has the honor of launching many best-selling data recovery, email migration, email recovery, file repair and computer monitoring tools


Download RecoveryFix

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Enhanced Anti-Logger, Privacyware PC Security & Hacking Protection supported by IPv6

 


Privacyware, an innovative provider of web application firewall, pc security and security data analytics software, announced today that it has released a new version of Privatefirewall, the leading free security product for Windows PCs. The new software features full support for IPv6 and enhanced protection against critical hacking, privacy and identity theft threats.
"The frequency and magnitude of reported data theft incidents consistently reminds us of the real threat that exists as our reliance on the Internet to bank, shop, and personally or professionally interconnect continues to grow,” said Greg Salvato, chief executive officer at Privacyware. “Our new Privatefirewall release provides expanded packet inspection to support IPv6 and offers greater protection from keyboard, screen, clipboard and other logging techniques used by hackers and malware to steal private data.”
Privatefirewall employs a multi-layered security architecture that combines stateful packet inspection of inbound and outbound traffic and intelligent HIPS technologies that model and monitor system and application behavior to identify and block activity characteristic of Trojans, keyloggers, port scanning, program hijacking and zero-day threats. Privatefirewall ranks among the best performing desktop defense applications tested against the industry's most rigorous leak, general bypass, spying and termination tests.

Privatefirewall delivers four key benefits:
•Stateful inbound/outbound firewall, process monitor and behavioral monitoring technologies provide deep, proactive protection from malware and hackers for your system and personal data.

•Simple setup and operation ensures powerful out-of-box protection and peace of mind with ease.

•Elegant solution design is extremely light on system resources and won't slow down your PC.

•Unsurpassed value – Privatefirewall is available free of charge.

Key Features of this Privatefirewall Update Include:

•IPv6 packet filtering and tunneling support.

•Expanded anti-logger protection including clipboard and screenshot logging detection, driver load attempt detection and enhanced code injection monitoring.

•Improved leak, general bypass, spying and termination defense performance.

Privatefirewall provides an excellent layer of additional protection for the Windows operating system and supports 32 and 64 bit versions of Windows 7, Vista, and Server 2008/R2 as well as 32 bit versions of XP and Server 2003.

Pricing and Availability:
Privatefirewall 7 is free and available now. Visit http://www.privacyware.com to download today. Privatefirewall supports 32 and 64 bit versions of Windows 7, Vista, and Server 2008/R2 as well as 32 bit versions of XP and Server 2003. Private label and OEM licensing and integration options are also available to ISVs, ISPs and hardware and peripheral equipment vendors.

About Privacyware
:
Privacyware is an innovative provider of award-winning pc security, web application firewall and security data analytics software. Privacyware products leverage conventional and neural analytics technologies to help systems administrators, IT security and compliance personnel more effectively identify, understand and prevent malicious, unauthorized and/or deviant computing system activity. Privacyware is a member of the Microsoft Partner Network with Gold Independent Software Vendor (ISV), and Silver Business Intelligence and Data Platform Competencies.
Privacyware and ThreatSentry, Privatefirewall, and Adaptive Security Analyzer are registered trademarks of PWI, Inc. All other registered or unregistered trademarks are the sole property of their respective owners. ©2011 PWI, Inc. All rights reserved.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Metro Version Of Firefox Will Available on Windows 8

Metro Version Of Firefox Will Available on Windows 8
There are lots of addition and subtraction is going with the upcoming Microsoft Windows 8 & Windows on ARM.Microsoft's browser rivals to publicly commit to a Metro edition. Microsoft has said it will ship both Metro and traditional desktop versions of Internet Explorer 10. Metro is Microsoft's label for the touch-enabled interface at the center of both Windows 8 and WOA. Windows 8 will run Metro and traditional 32- and 64-bit Windows applications, but WOA will run only those third-party apps designed for Metro. Not only IE but also Firefox will follow the same trend. Mozilla confirms that it will build a "proof-of-concept" version of Firefox for Windows 8's Metro touch-first interface next quarter, then follow that with more functional editions later in the year. Mozilla Said:- "This proposal depends on Microsoft providing the same capabilities for Firefox as it does for IE -- running at the Medium level integrity process that allows us the full use of the Win32 API and what we need from Metro, or a set of APIs that allow Mozilla to port Gecko to the WinRT. For the purposes of this feature proposal, I'm assuming we'll get the first and we won't have to port the bulk of Gecko and instead will use the win32 dlls from within Metro."

Feature Overview:- 
  • Windows 8 contains two application environments, "Classic" and "Metro". Classic is very similar to the Windows 7 environment at this time, it requires a simple evolution of the current Firefox Windows product. Metro is an entirely new environment and requires a new Firefox front end and system integration points.
  • The feature goal here is a new Gecko based browser built for and integrated with the Metro environment.
  • Firefox on Metro, like all other Metro apps will be full screen, focused on touch interactions, and connected to the rest of the Metro environment through Windows 8 contracts.
  • Firefox on Metro will bring all of the Gecko capabilities to this new environment and the assumption is that we'll be able to run as a Medium integrity app so we can access all of the win32 Firefox Gecko libraries avoiding a port to the new WinRT API for the bulk of our code. (Though we will need to have a pan and zoom capability for content.)
  • We will need to determine if the Firefox front end on Metro will be built in XUL, C/C++, or HTML/CSS/JS (I'm assuming for now that .Net and XAML are off the table.)
  • Firefox on Metro is a full-screen App with an Appbar that contains common navigation controls (back, reload, etc.,) the Awesomebar, and some form of tabs.
  • Firefox will have to support three "snap" states -- full screen, ~1/6th screen and ~5/6th screen depending on how the user "docks" two full screen apps. Our UI will need to adjust to show the most relevant content for each size.
  • In order to provide users with access to other content, other apps, and to Firefox from other content and apps, we'll need integration with the share contract, the search contract, the settings contract, the app to app picking contract, the print contract, the play to contract, and possibly a couple more. We'll be a source for some, a target for some, and both for some.
  • We'll need to handle being suspended by the OS when out of view.
  • We may want to offer a live tile with user-centric data like friends presence or other Firefox Home information updates
  • Ideally we'd be able to create secondary tiles for Web-based apps hosted in Firefox's runtime.
For More Information Click Here


-Source (Mozilla & Computer World)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft is Making Windows 8 Compatible For Mobile Devices



The software industry's attention is riveted on Microsoft. Software developers from around the world have convened at a conference, called Build, in Anaheim, Calif., where Microsoft will unveil details about Windows 8, the next version of its cash-cow PC operating system. Windows 8 is on course to replace Windows 7 roughly a year from now.
This won't be just another upgrade. Windows 8 is nothing less than the linchpin to Microsoft's strategy for keeping Windows relevant — if not resurgent — as the shift to the post-PC computing era unfolds.
"The stakes are huge," says Charles King, principal analyst at research firm Pund-IT. "The company must play outside its comfort zone, but if Microsoft succeeds, the potential opportunities could be significant."
Microsoft declined to comment, preferring to reveal technical details at Build, says Frank X. Shaw, corporate communications vice president.
Traditional PCs remain by far the most widely used computing tools out there. The installed base of Windows desktop and laptop computers in use in homes and businesses globally exceeds 807 million and is projected to top 920 million next year, according to market researcher Gartner. Even so, Microsoft has fallen behind as consumers and workers begin to spend more time using touch tablets and smartphones to work, play and socialize. Sales of smartphones will soar 56%, to 467.6 million, this year, while sales of touch tablets will grow nearly four times, to 69.8 million this year, Gartner says.
Internet-connected mobile devices that respond to fingertip touches, instead of a mouse and keyboard or a keypad, are all the rage. The soaring popularity of Apple's iPhone and iPad touch tablet and Google Android smartphones have, in turn, spawned a burgeoning universe of graphical, touch-enabled software apps.
Microsoft, meanwhile, has scrambled to keep up in smartphones and has been left in the dust on touch tablets.
Yet, Windows and the ubiquitous Office clerical suite remain pivotal to the software giant's future, generating combined revenue of $41.23 billion and operating income of $26.4 billion in Microsoft's 2011 fiscal year, ending June 30. However, Windows revenue dipped 1% to $4.7 billion in the fourth quarter. For the fiscal year, Windows revenue fell 2% to $19 billion, while Windows operating profit dropped 6% to $12.3 billion.
Those slippages underscore the notion that "the post-PC world is about smartphones and tablets and their blazingly fast rates of innovation," says Scott Ellison, mobile industry analyst at IDC. "Microsoft needs to prove it can be more than a slow follower."




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Patches Serious 34 Vulnerabilities



In today's Patch Tuesday, Microsoft released 16 bulletins addressing 34 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, .NET, SQL, Visual Studio, Silverlight, VML and ISA. Nine of the bulletins are rated Critical, with seven rated as Important. Wolfgang Kandek, Qualys CTO, comments: "The only bulletin with a known expoit in the wild is MS11-046, a local privilege escalation flaw in the "afd.sys" driver. IT admins can check with their end-point security providers for coverage, but should include this bulletin high on their to-do lists in any case, as it is only a matter of time until we see more attackers use malware taking advantage of this exploit to gain control of your workstations."

Here are the bulletins:-

Vulnerability in OLE Automation 
This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code execution if a user visits a Web site containing a specially crafted Windows Metafile (WMF) image. In all cases, however, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to convince users to visit a malicious Web site, typically by getting them to click a link in an e-mail message or Instant Messenger request.

Vulnerability in .NET Framework and Microsoft Silverlight
This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Vulnerability in Threat Management Gateway Firewall Client 
This security update resolves a privately reported vulnerability in the Microsoft Forefront Threat Management Gateway (TMG) 2010 Client, formerly named the Microsoft Forefront Threat Management Gateway Firewall Client. The vulnerability could allow remote code execution if an attacker leveraged a client computer to make specific requests on a system where the TMG firewall client is used.

Vulnerability in Windows Kernel-Mode Drivers
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user visits a network share (or visits a web site that points to a network share) containing a specially crafted OpenType font (OTF). In all cases, however, an attacker would have no way to force a user to visit such a web site or network share. Instead, an attacker would have to convince a user to visit the web site or network share, typically by getting them to click a link in an e-mail message or Instant Messenger message.

Vulnerabilities in Distributed File System
This security update resolves two privately reported vulnerabilities in the Microsoft Distributed File System (DFS). The more severe of these vulnerabilities could allow remote code execution when an attacker sends a specially crafted DFS response to a client-initiated DFS request. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.

Vulnerability in SMB Client
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit the vulnerability, an attacker must convince the user to initiate an SMB connection to a specially crafted SMB server.

Vulnerability in .NET Framework
This security update resolves a publicly disclosed vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Cumulative Security Update for Internet Explorer
This security update resolves eleven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Vulnerability in Vector Markup Language
This security update resolves a privately reported vulnerability in the Microsoft implementation of Vector Markup Language (VML). This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows clients; and Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows servers. Internet Explorer 9 is not affected by the vulnerability.

The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Vulnerability in MHTML
This security update resolves a publicly disclosed vulnerability in the MHTML protocol handler in Microsoft Windows. The vulnerability could allow information disclosure if a user opens a specially crafted URL from an attacker's Web site. An attacker would have to convince the user to visit the Web site, typically by getting them to follow a link in an e-mail message or Instant Messenger message.

Vulnerabilities in Microsoft Excel
This security update resolves eight privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1272, CVE-2011-1273, and CVE-2011-1279. Microsoft Excel 2010 is only affected by CVE-2011-1273 described in this bulletin. The automated Microsoft Fix it solution, "Disable Edit in Protected View for Excel 2010," available in Microsoft Knowledge Base Article 2501584, blocks the attack vectors for exploiting CVE-2011-1273.

Vulnerability in Ancillary Function Driver
This security update resolves a publicly disclosed vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.

Vulnerability in Hyper-V Could
This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.

Vulnerability in SMB Server
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit this vulnerability.

Vulnerability in the Microsoft XML Editor
This security update resolves a privately reported vulnerability in Microsoft XML Editor. The vulnerability could allow information disclosure if a user opened a specially crafted Web Service Discovery (.disco) file with one of the affected software listed in this bulletin. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system.

Vulnerability in Active Directory Certificate Services Web Enrollment
This security update resolves a privately reported vulnerability in Active Directory Certificate Services Web Enrollment. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. An attacker who successfully exploited this vulnerability would need to send a specially crafted link and convince a user to click the link. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ophcrack 3.4.0 Released (Windows Password Cracker Based on Rainbow Tables)

Ophcrack 3.4.0 Released (Windows Password Cracker Based on Rainbow Tables)
After almost three years without news, here comes the version 3.4.0 of ophcrack. This will probably be the final release in the 3.x branch. It adds the support of the soon to be released XP flash and Vista eight XL tables. On Windows it also adds the support of dumping the hashes through samdump2 live using NTFS low-level access to the locked files.

Brief About Ophcrack:-
Ophcrack is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms. 

Features :-
  •  Runs on Windows, Linux/Unix, Mac OS X, ...
  • Cracks LM and NTLM hashes.
  • Free tables available for Windows XP and Vista/7.
  • Brute-force module for simple passwords.
  • Audit mode and CSV export.
  • Real-time graphs to analyze the passwords.
  • LiveCD available to simplify the cracking.
  • Dumps and loads hashes from encrypted SAM recovered from a Windows partition.
  • Free and open source software (GPL).
To Download Ophcrack 3.4.0 Installer for both Windows & Linux click Here. If you want to get the tables to crack LM Password hashes for (Windows XP, Vista & 7) click Here.  



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft offers keyboard with 128-bit encryption


Microsoft has unveiled the new Wireless Desktop 2000, a keyboard and mouse combo for $40. You can buy it now from Microsoft.com, though you should note that it requires either Windows XP (excluding Windows XP 64-bit), Windows Vista, or Windows 7. The Wireless Desktop 2000 includes Microsoft's first keyboard that features Advanced Encryption Standard (AES) 128-bit encryption – the same technology trusted by the US government to secure their wireless connections and which industry leaders consider to be one of the most secure encryption standards. AES is a unique pre-programmed 128-bit encryption key designed to help prevent your keystrokes, which are transmitted over-the-air, from being intercepted and deciphered. The keyboard also includes a pillow-textured palm rest for added comfort and caters to multitaskers with Taskbar Favorites for Windows 7.  The included Wireless Mouse 2000 features enhanced side grips, an ambidextrous design (meaning it can fit either hand), and also includes a Tilt Wheel for easy side-to-side scrolling. It uses Microsoft's BlueTrack technology, which means it can works on virtually any surface (except glass and mirrored surfaces). All of Microsoft's keyboards and mice come with a worldwide three-year limited hardware warranty.
This appears to be a decent keyboard and mice combo for the price, but the addition of encryption is puzzling. Is Microsoft trying to tap into the paranoid market?

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Why did Microsoft spend $8.5bn on Skype? (Detailed Report)


Microsoft Skype
In a bold move, Microsoft acquires Nokia and catapults itself to the top of the smartphone world. The full integration of Windows Phone 7 software into Nokia hardware will result in a better user experience for customers, a zero-fragmentation platform for developers, easier deployment of a smaller number of SKUs for retailers, and more reliable update management for carriers.
It's worked before. Microsoft's hardware/software integrated devices, Xbox and Kinect, are enjoying strong revenue growth and great margins: $1.9bn revenue last quarter, 50% more than last year, with 10% operating profit.
In a prepared statement, Microsoft CEO Steve Ballmer says:
I welcome Stephen Elop back into my executive staff. His brief leave of absence has allowed us to more fully explore the possibilities of combining the best smartphone hardware, Nokia's, with the best OS, Windows Phone 7. Google's anticompetitive Android free and open licensing practices unfairly tilted the playing field against our better product; they made it impossible for us to sell Windows Phone 7 software. Instead, we're now ready to do battle with Apple from a superior position: a stronger product carrying the Windows Everywhere flag, wider carrier distribution around the world, and more retail partners in US, Europe, and BRIC nations. With our acquisition of Nokia, we're now a $100bn company, back where we belong: at the top of the high-tech industry.
When I woke up, I heard a different story: Microsoft bought Skype for $8.5bn.
We all know Skype: free voice and video calls from computer to computer, plus paid services if you need to dial a phone. As Skype prepared for its long-awaited IPO, we got financial data from their S-1filing with the SEC. S-1s are always instructive: This is usually the first time a private company opens the kimono – and the SEC watches closely as you prepare to sell shares to widows and orphans.
The Profit & Loss statement in Skype's S-1 looks like this:
With revenue of $860m in 2010, Skype's operating profit is a modest $20m, with a net loss of $69m due to interest expenses stemming from $686m in long-term debt. Except for in 2008, when they saw a $42m profit, Skype has racked up huge losses, including $1.4bn in 2007 and $370m in 2009.
(Technically, these figures straddle two different corporate structures because of Skype's complicated history. Started in 2003 as an independent European company, Skype was acquired by eBay in 2005 for a price pegged between $2.6bn and $3.1bn. After the acquisition, eBay discovered its ownership of Skype was "encumbered": A crucial piece of Skype's technology was owned by another company, Joltid, which was essentially in the hands of Niklas Zennström, one of Skype's founders. eBay settled with Joltid for about 14% of Skype. This caused wags to say the crafty Skype founders sold the company twice – and it certainly didn't make the ex-management consultants running eBay look so sharp. In 2009, eBay sold 70% of Skype to private equity and venture investors in a transaction that valued the company at $2.75bn.)
Why did Microsoft pay $8.5bn – 10 times the company's revenue – for a business that has changed hands so many times, never made money, and comes with substantial debt? (Admittedly, the $686m debt number is manageable – for Microsoft).
One eloquent answer comes from Brad Horowitz, a partner at the Andreessen Horowitz venture firm started by Netscape's founder. Horowitz invokes the network effect: A large number of users attracts more users and so on, in a kind of gravitation well:
500,000 new registered users per day – 170 million connected users – 30 million users communicating on the Skype platform concurrently – 209 billion voice and video minutes in 2010
And he concludes:
Today, I tip my hat to an old rival, Microsoft. By acquiring Skype, Microsoft becomes a much stronger player in mobile and the clear market leader in internet voice and video communications. More importantly, Microsoft gets a team, ably led by the exceptional Tony Bates, that can compete with anyone.
Well, this is a nice encomium to the guys who transformed the venture firm's $50m investment in Skype a few months ago into a $150m payday. My own venture investor hat is tipped to MM. Andreessen and Horowitz.
But not so much to Steve Ballmer.
Looking at Microsoft's recent quarterly numbers, we see the continuation of a now old and getting older tradition: losses in the Online Services Division. Only a few weeks ago, TechCrunch wondered: When Will Microsoft's Internet Bloodbath End? Business Insider provided a vivid illustration for the problem:
In just the past 12 months, Microsoft has lost $2.5bn in its online business. They spend $2 to make $1 in revenue. Buying and "integrating" Skype will make the picture even redder.
So, again, why spend $8.5bn on Skype?
The official explanation is that Skype will be targeted at professional users. For these, Microsoft already has a product called Lync, although not many have heard of it. And they have Messenger for consumers. (Actually, it's Windows Live Messenger for Windows and Microsoft Messenger for the Mac.) I don't think it's unfair to ask how, how well, and when Microsoft's Grand Unified Messaging platform will effectively exist, and how it will be monetised.
Given Microsoft's track record, there isn't much evidence of its ability to perform such integration, nor of its ability to move a big platform forward at a competitive pace, certainly not faster than what Google seems able to do with Google Voice, Talk and Google Video for Business.
The theory must be that every Windows PC will come with "Skype inside". But that isn't much progress: There are already 170 million connected Skype users, and 500,000 new registrations everyday. And imagine how carriers will react when they see a Skype client bundled with every Windows Phone 7 device, further pushing them towards their preordained destination: dumb pipes.
Today, Skype is joyfully used in both consumer and business environments. It's not perfect, but the price is right and Skype is now a verb. The next thing we know, Microsoft will take a good if imperfect service and "improve" it by integrating it with Office or SharePoint (a good product on its own). And, at some point, Microsoft will try to make us pay for it. In more ways than one.
But, again, the history isn't there. Microsoft's ability to successfully charge for a formerly free product is lacking.
Reactions to the Skype deal have been negative, if not downright derisive. Many see the Skype acquisition as more evidence that Microsoft can't innovate, or even effectively copy and out-implement any more. One local exec asked, rhetorically, how much it'd take to re-implement Skype. $100m? $1bn? It's not a question of money. Microsoft spends tons in R&D: 15% of sales, about $9bn per year. (Apple spends 2% of revenue, less than $2bn.) Think of iTunes: it's been out there for close to 10 years and there's no iTunes clone coming out of Redmond. Microsoft has to buy what it no longer has the people or the culture to create – or copy.
David Pogue, the NY Times' tech guru, thinks this acquisition will go where so many went before: to failure by mediocrity and to poisoning by matrix management.
Ben Brooks, a Microsoft shareholder – and not the disgruntled kind – comments on the Skype deal and concludes: The Ballmer Days Are Over. Perhaps, but who can tackle the job of turning Microsoft around?
In last year's 30 May Monday Note, I wrote Ballmer had opened the "Second Envelope". He was running out of explanations: first blame your predecessor, then fire a few subordinates. Next, you're out of excuses and out the door.
Since then, a few more subordinates have decided to "spend more time with their families": CTO Ray Ozzie, who wrote a long, long farewell memo (don't do that, it doesn't make you look good); tablet executive Bill Mitchell; Bob Muglia, president of the server and tools division. We'll exclude Stephen Elop, the president of the business division who went on to rescue Nokia, as he might have left of his own volition – or of his seeing Ballmer looking for the next excuse.
Last year, I noted Microsoft's stock had been stagnant for almost 10 years. Things haven't improved since then:
In the past 12 months, Microsoft's stock has fallen by 11% while the Nasdaq climbed 25%, Google 7%, and Apple 44%.
Having run out of ideas and envelopes, is Ballmer spending $8.5bn of Microsoft's $50bn cash, its biggest acquisition so far, as a desperate tentative to keep the company, or himself, in the game?



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...