Showing posts sorted by date for query Windows 7. Sort by relevance Show all posts
Showing posts sorted by date for query Windows 7. Sort by relevance Show all posts

Researcher Figure-out Yet Another Java Hole That Puts 1 Billion Users at Risk

Researcher Figure-out Yet Another Java Hole That Puts 1 Billion Users at Risk

Just as Oracle is ramping up for the September 30 start of JavaOne 2012 in San Francisco yet again another critical Java vulnerability has been spotted in the wild.  The Polish security researcher Adam Gowdiak has found another vulnerability in Java that could allow an attacker to bypass the sandbox. This newly discovered security hole has effected all latest versions of Oracle Java SE software. According to Security Explorations researcher Adam Gowdiak, who sent the email to the Full Disclosure Seclist, this Java exploit affects one billion users of Oracle Java SE software.” So far the researcher were able to successfully exploit the vulnerability and achieve a complete Java security sandbox bypass 
in the environment of Java SE 5, 6 and 7. Researcher could only claim such an impact with reference to Java 7 environment (the 
Apple QuickTime attack relying on Issues 15 and 22 is the only exception here). 





The following Java SE versions were verified to be vulnerable:

  • Java SE 5 Update 22 (build 1.5.0_22-b03)
  • Java SE 6 Update 35 (build 1.6.0_35-b10)
  • Java SE 7 Update 7  (build 1.7.0_07-b10)


All tests were successfully conducted in the environment of a fully patched Windows 7 32-bit system and with the following web browser applications:

  • Firefox 15.0.1
  • Google Chrome 21.0.1180.89
  • Internet Explorer 9.0.8112.16421 (update 9.0.10)
  • Opera 12.02 (build 1578)
  • Safari 5.1.7 (7534.57.2)
So far there are no reports that the vulnerability is being exploited for attacks. Oracle has not said whether or when it will close the vulnerability. Here we want to remind the very recent history, when several zero day vulnerability was found in all the version of java, which was added on BlackHole Exploit kit. Later Oracle released a patch to close the security hole. 








SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Issues 'fix it' To Close Internet Explorer 0-day Vulnerability

Microsoft Issues 'fix it' To Close Internet Explorer 0-day Vulnerability 

Last few days the whole cyber world have gone through with so many drama of Internet Explorer's security bug, as researchers have unveiled four active exploits of a zero-day vulnerability in the browser. As expected the software giant Microsoft has released an emergency fix to get rid of these major security issues. Microsoft released a “fix it” tool for a critical security flaw in most versions of Internet Explorer 6, 7, 8 and 9  that hackers have been exploiting to break into Windows systems. The company said it expects to issue an official patch (MS12-063) for the vulnerability on Friday, Sept. 21. "While we have only seen a few attempts to exploit this issue, impacting an extremely limited number of people, we are taking this proactive step to help ensure Internet Explorer customers are protected and able to safely browse online," said Yunsun Wee, director of Microsoft Trustworthy Computing in a statement. The zero-day in IE 6-9 is a use-after-free memory corruption vulnerability, similar to a buffer overflow, that would enable an attacker to remotely execute code on a compromised machine. The original exploit payload dropped the PoisonIvy remote access Trojan (RAT) via a corrupted Flash movie file. The latest payload discovered dropped the PlugX RAT via the same corrupted Flash movie, Blasco said. He also said the new exploits are the work of the Chinese hacker group Nitro, the same group behind a pair of Java zero-day exploits disclosed in August.

Blasco also said the new exploits appear to be targeting defense contractors in the United States and India.
Microsoft recommended several workarounds Tuesday morning before announcing its intention to send out a FixIt.
  • Setting Internet and local Internet security zone settings to high, which would block ActiveX Controls and Active Scripting in both zones
  • Configure IE to prompt the user before running Active Scripting, or disable Active Scripting in both zones
  • Use of Microsoft's Enhanced Mitigation Experience Toolkit provides mitigations as well, and would not impact website usability, as both of the first two options might.
Microsoft also said that IE running on Windows Server 2003, 2008 and 2008R2 runs in a restricted mode that mitigates the vulnerability. Outlook, Outlook Express and Windows Mail also open HTML messages in a restricted zone, mitigating the vulnerabilty but should a user click a link in a message, they could still be vulnerable to exploit.





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Oracle Released Emergency Update to Patch Java 0day (CVE-2012-4681)

Oracle Released Emergency Update to Patch Java 0day (CVE-2012-4681)

Zero-day vulnerabilities in Java, which was on the spotlight for last few days; takes a new direction. Several security firms have already declared that, this newly found Java exploit had been added to Blackhole, a popular hacker's tool that bundles numerous exploits and tries each in turn until it finds one that will work against a personal computer. As expected  Oracle has released an emergency update to address those zero-day vulnerabilities. This Security Alert addresses security issues CVE-2012-4681 (US-CERT Alert TA12-240A and Vulnerability Note VU#636312) and two other vulnerabilities affecting Java running in web browsers on desktops. These vulnerabilities are not applicable to Java running on servers or standalone Java desktop applications. They also do not affect Oracle server-based software.
These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages this vulnerability. Successful exploits can impact the availability, integrity, and confidentiality of the user's system.
In addition, this Security Alert includes a security-in-depth fix in the AWT subcomponent of the Java Runtime Environment.
Due to the severity of these vulnerabilities, the public disclosure of technical details and the reported exploitation of CVE-2012-4681 "in the wild," Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible.

Supported Products Affected

Security vulnerabilities addressed by this Security Alert affect the products listed in the categories below.  Please click on the link in the Patch Availability column or in the Patch Availability Table to access the documentation for those patches.
Affected product releases and versions:
Java SEPatch Availability
JDK and JRE 7 Update 6 and beforeJava SE
JDK and JRE 6 Update 34 and beforeJava SE

Patch Availability Table and Risk Matrix

Java SE fixes in this Security Alert are cumulative; this latest update includes all fixes from previous Critical Patch Updates and Security Alerts.

Patch Availability Table

Product GroupRisk MatrixPatch Availability and Installation Information
Oracle Java SEOracle JDK and JRE Risk Matrix

Also Java 7 Update 7 is now available to download for Windows (32- and 64-bit), Linux (32- and 64-bit), Mac OS X (64-bit), Solaris x86 (32- and 64-bit) and Solaris SPARC (32- and 64-bit). JDKs with the updated Java runtimes are also available. Users with Java installed on their systems, whatever operating system, should install the updates as soon as possible because malicious software that uses the vulnerability is already in circulation. For detailed information click here






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

SQL Server 2008 R2 Service Pack 2 (SP2) Released & Available To Download

SQL Server 2008 R2 Service Pack 2 (SP2) Released & Available To Download

The software giant Microsoft announced the availability of SQL Server 2008 R2 Service Pack 2 (SP2). SQL Server 2008 R2 SP2 contains fixes to issues that have been reported through customer feedback platforms and Hotfix solution provided in SQL Server 2008 R2 SP1 Cumulative Update 1 thru to Cumulative Update 5. Service Pack 2 also includes supportability enhancements and issues that have been reported through Windows Error Reporting system. The update fixes several bugs with the product, most notably a problem that could cause a deadlock of the server when synchronising database logs to another server. A bug that prevented users of the JDBC Driver to connect to the server when using JRE 6 update 29, or later, was also fixed. A problem where users receive "incorrect results" when running "a complex query" which contains joins and aggregate functions and uses the DISTINCT statement has been fixed, but Microsoft is not offering any further details on it. Other patches correct false error reports, fix problems with the server's update install mechanism and more.
Both the Service Pack and Feature Pack updates are available for download on the Microsoft Download Center. As part of the continued commitment of Microsoft to software excellence for the customers, this upgrade is free and doesn't require an additional service contract. Microsoft SQL Server 2008 R2 SP2 also addresses a few key customer requests:

  • Reporting Services Charts Maybe Zoomed & Cropped 
    Customers using Reporting Services on Windows 7 may sometime find charts are zoomed in and cropped. To work around the issue some customers set ImageConsolidation to false.
  • Batch Containing Alter Table not Cached 
    In certain situations with batch files containing the alter table command, the entire batch file is not cached.
  • Collapsing Cells or Rows, If Hidden Render Incorrectly 
    Some customers who have hidden rows in their Reporting Services reports may have noticed rendering issues when cells or rows are collapsed. When writing a hidden row, the Style attribute is opened to write a height attribute. If the attribute is empty and the width should not be zero.
Customers are highly encouraged to stay on a supported service pack to ensure they are on the latest and most secure version of SQL Server 2008 R2. The Service Pack is freely available for download from Microsoft's Download Center. We would like to share with you that, earlier in this year Microsoft has released SQL Server 2012 , and the Evaluation edition of SQL Server 2012 is also freely available to download from Microsoft. 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft's Windows 8 Will Be Available On October 26

Microsoft's Windows 8 Will Be Available On October 26

The final countdown of Windows 8 begins as software giant Microsoft announced that they will start selling Windows 8 from coming October 26, a little more than three months from now. This release will be first stable one of Windows 8, earlier we got three pre-release version of Windows 8 -Consumer Preview, Developer Preview & Release Preview. Windows 8 is Designed to work on both PCs and tablet computers, So far Windows 8 is Microsoft's best hope for competing with devices. According to official blog of Windows Steam - "Steven Sinofsky announced at Microsoft’s annual sales meeting that customers will be able to get Windows 8 – whether in upgrade fashion or on a new PC – starting on October 26thEarlier this month at the Microsoft Worldwide Partner Conference, Tami Reller told attendees Windows 8 would be available in October. But now everyone has a specific date to mark on their calendars."
The Oct. 26 date is also significant to users now running Windows XP, Vista or Windows 7, as it marks the debut of the $39.99 upgrade to Windows 8. The price is a dramatic discount from other Windows upgrade. All users who upgrade will receive Windows 8 Pro, the more advanced of the two retail editions. Microsoft has also tied the launch of its Windows RT operating system, and its first-ever tablet, dubbed "Surface" to the debut of Windows 8. It does have some wiggle room, however, for the tablet, because it has said that the device would go on sale around the time of Windows 8's release. Microsoft officials have not said how much the promised System Builder SKU will be for those who want to build their own PCs. They also have not said whether a full, non-upgrade version will be available via retail and how much it will cost.













SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Unveils Windows Phone 8 Codenamed “Apollo”

Microsoft Unveils Windows Phone 8 Codenamed “Apollo”

Few days ago in a report we have said that Microsoft is expected to launch it's own tablet (Microsoft Surface) while aiming to compete with iPad. Redmond based software and hardware giant just unveiled the next big step in its mobile software, Windows Phone 8 codenamed “Apollo” Windows Phone 8 brings the platform in line with other mobile OSes by adding support for muti-core processors, higher screen resolutions and newer wireless technologies like near field communication (NFC). Importantly, Microsoft has re-coded Windows Phone from the ground up for the new version. Previous versions of Windows Phone were based on Microsoft’s old mobile OS, Windows CE, but now the platform will share the same source code as the company’s coming desktop OS, Windows 8. That has big consequences for developers and consumers. For developers, it will be extremely easy to create a Windows Phone app if they already have a Windows 8 app that runs in the Metro environment (and vice versa). For consumers, it means more apps and better hardware to run them. It also has the effect of rendering every current Windows Phone obsolete, since those phones won’t be able to run the new software. They will, however, get an upgrade to Windows Phone 7 to 8. Windows Phone 8 adds support for many new hardware features. The most anticipated is support for multi-core devices, which have become common on both Android and iOS platforms. There’s also support for better screen resolutions, including 720p and 1,280 x 768 (WXGA). That’s not quite retina, but it’s better than the 800 x 480 screen of the Nokia Lumia 900, one of the current leading Windows Phones.

New Features At a Glance :-
  • Support for multi-core processors. Existing support for single core has been a major concern for some high-end users wanting faster processing ability.
  • Two new high-definition screen resolutions for the coming OS. They are 1280 x 768 and 1280 x 720.
  • Removeable micro-SD support for the first time to allow expansion of base storage.
  • A busier start screen with room for more live tiles than in Windows Phone 7.5. Today's Windows Phones have room for up to eight live tiles and WP8 will have room for up to 32 live tiles, which can be sized differently.
  • IT support. Adminstrators will see some gaps in the existing OS filled, including support for encryption and secure boot in WP8, as well as the ability to allow IT to deploy apps without going through Windows Marketplace.
  • Built-in Nokia Navteq map technology, with turn-by-turn driving instructions in many countries.
  • Full Internet Explorer 10 support with more features of HTML 5 added. Belfiore said that Windows Phone 8 with IE10 will download Web pages slightly faster than three other popular smartphones on the market.
  • Native code support, a feature seen as useful to developers eager to move their apps from iOS or Android to Windows Phone. 


-Source (Mshable & CW)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Flamer/Skywiper Stuxnet- Newly Found Cyber-Weapon Discovered By Iran National CERT (MAHER)

Flamer/Skywiper Stuxnet- Newly Found Cyber-Weapon Discovered by Iran National CERT (MAHER)

After "Duqu" now The Iranian Computer Emergency Response Team (MAHER) claims to have discovered a new targeted Stuxnet attacking the country's internal system. This newly found Stuxnet have been dubbed Flame (also known as Flamer or Skywiper). The name “Flamer” comes from one of the attack modules, located at various places in the decrypted malware code. In fact this malware is a platform which is capable of receiving and installing various modules for different goals. At the time of writing, none of the 43 tested anti viruses could detect any of the malicious components. Nevertheless, a detector was created by Maher center and delivered to selected organizations and companies in first days of May. 

Key Features of “Flamer” :-
  • Distribution via removable medias
  • Distribution through local networks
  • Network sniffing, detecting network resources and collecting lists of vulnerable passwords
  • Scanning the disk of infected system looking for specific extensions and contents
  • Creating series of user’s screen captures when some specific processes or windows are active
  • Using the infected system’s attached microphone to record the environment sounds
  • Transferring saved data to control servers
  • Using more than 10 domains as C&C servers
  • Establishment of secure connection with C&C servers through SSH and HTTPS protocols
  • Bypassing tens of known antiviruses, anti malware and other security software
  • Capable of infecting Windows Xp, Vista and 7 operating systems
  • Infecting large scale local networks

For additional information about "Flamer" click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ophcrack LiveCD 3.4.0 Released (Free Windows Password Cracker)

Ophcrack LiveCD 3.4.0 Released (Free Windows Password Cracker)
After the release Ophcrack 3.4.0 both Windows & Linux installer now the developer at Ophcrack has released the new LiveCD includes the latest version of Ophcrack 3.4.0. This edition of Ophcrack is built on Slitaz 4.0, the latest version of this great LiveCD. Christophe Lincoln from Slitaz helped us to enhance the scripts for partitions and tables detection. A new ncurses interface is also available to help users look for tables on other drives or interact with ophcrack.
Finally a LiveCD without tables has been released as well for users that already downloaded or bought tables. The directory containing the table files must be placed inside another directory called tables in order for ophcrack to find them automatically. 

Features:-

  • Runs on Windows, Linux/Unix, Mac OS X, ...
  • Cracks LM and NTLM hashes.
  • Free tables available for Windows XP and Vista/7.
  • Brute-force module for simple passwords.
  • Audit mode and CSV export.
  • Real-time graphs to analyze the passwords.
  • LiveCD available to simplify the cracking.
  • Dumps and loads hashes from encrypted SAM recovered from a Windows partition.
  • Free and open source software (GPL).

To Download Ophcrack 3.4.0 Live CD Click Here.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ophcrack 3.4.0 Released (Windows Password Cracker Based on Rainbow Tables)

Ophcrack 3.4.0 Released (Windows Password Cracker Based on Rainbow Tables)
After almost three years without news, here comes the version 3.4.0 of ophcrack. This will probably be the final release in the 3.x branch. It adds the support of the soon to be released XP flash and Vista eight XL tables. On Windows it also adds the support of dumping the hashes through samdump2 live using NTFS low-level access to the locked files.

Brief About Ophcrack:-
Ophcrack is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms. 

Features :-
  •  Runs on Windows, Linux/Unix, Mac OS X, ...
  • Cracks LM and NTLM hashes.
  • Free tables available for Windows XP and Vista/7.
  • Brute-force module for simple passwords.
  • Audit mode and CSV export.
  • Real-time graphs to analyze the passwords.
  • LiveCD available to simplify the cracking.
  • Dumps and loads hashes from encrypted SAM recovered from a Windows partition.
  • Free and open source software (GPL).
To Download Ophcrack 3.4.0 Installer for both Windows & Linux click Here. If you want to get the tables to crack LM Password hashes for (Windows XP, Vista & 7) click Here.  



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Red Hat Announced Beta of Red Hat Enterprise Linux (RHEL) 6.3

Red Hat Announced Beta of Red Hat Enterprise Linux 6.3
Just over four months after the release of Red Hat Enterprise Linux (RHEL) 6.2, developer at RedHat has made a beta of version of RHEL 6.3 available. This beta includes a broad set of updates to the existing feature set and also provides rich new functionality particularly in the areas of virtualization, scalability, storage, file systems, and security. As always, the Red Hat Enterprise Linux 6.3 beta delivers new hardware enablement made possible by our strong relationships with our strategic hardware partners. This beta release has been designed for optimized performance, scalability, and reliability to cater to the diverse workloads running in physical, virtual and cloud environments.

Key Features in the Red Hat Enterprise Linux 6.3 Beta:-
Virtualization-
  • A new tool called Virt-P2V that facilitates the conversion of physical Windows or Red Hat Enterprise Linux systems into virtual images to be deployed as KVM guests inside Red Hat Enterprise Linux or Red Hat Enterprise Virtualization.
  • Stronger compliance with Payment Card Industry Data Security Standards (PCI-DSS), including the ability to perform secure wipes of virtual machine disks.
  • The ability to perform live volume resizing, improving the overall availability of virtualized guests.
Scalability-
  • The maximum number of virtual CPUs (vCPUs) has been increased from 64 to 160, which lets you run larger CPU-intensive workloads on the Red Hat Enterprise Linux platform. VMware ESX 5.0 currently support 32 vCPUs.
  • The maximum supported memory configuration for KVM guests has been increased from 512GB to 2TB.
File Systems-
  • GFS2 enhancements that create faster read-write capabilities for specific use cases.
  • Support of O_Direct in FUSE (Filesystem in User Space), which can provide improved performance for certain workloads.
  • Simplified configuration and administration for the file system. Integration of automount capability with System Security Services Daemon (SSSD) provides centralized management of configuration data and the ability to improve performance through caching and load balancing. (This feature is a Technology Preview.)
Storage-
  • Red Hat Enterprise Linux 6.3 provides full support for Fibre Channel over Ethernet (FCoE) Target. This feature, which was previously provided as a Technology Preview, allows customers to present their Red Hat Enterprise Linux servers as FCoE storage devices. This feature complements the FCoE Initiator support that was delivered in Red Hat Enterprise Linux 6.0.
  • The Logical Volume Manager (LVM) now provides support for RAID levels 4, 5, and 6. (Previously, support for these RAID levels was provided through the MD subsystem.) This expanded LVM RAID support simplifies overall storage administration by consolidating all management functions, such as creating volumes, resizing volumes, deploying RAID, taking snapshots, etc., into a single interface. (This feature is a Technology Preview.)
  • The LVM now provides the ability to create thin provisioned logical volumes. Previously, storage was allocated when the volume was created, and needed to be monitored for space consumption and expanded manually. In Red Hat Enterprise Linux 6.3, storage is allocated as required, allowing volumes to expand up to the requested size on demand without intervention. (This feature is a Technology Preview.)
Security-
  • Availability of a two-factor authentication mechanism, enhancing the overall security available to lock down Red Hat Enterprise Linux environments and enabling compliance with industry standards such as PCI-DSS.
  • Expansion of the Advanced Encryption Standard (AES) to provide particular benefits for system performance on multi-processor machines.
Identity Management-
  • With native support for netgroups and the services map in System Security Services Daemon (SSSD), Red Hat Enterprise Linux servers can be integrated into centralized systems -- such as Active Directory -- to manage system users.
  • The addition of an automembership plug-in streamlines the administration of new users and hosts when they are added into the Identity Management system by automatically placing them into a predefined set of groups, speeding user and host provisioning.
  • Performance improvements through session data caching, which lowers the overall load on authentication servers.
Hardware Enablement-
  • Software bandwidth management for USB 3.0 for select Intel platforms is now available.
  • Compiler optimization for Intel Xeon E5 processor family, which improves the result of string operations, is now included.
  • Improvements to memory and I/O breakpoint execution operations within compiler tools are now included.
Developer Tools-
  • With the introduction of OpenJDK 7, customers can develop and test with the latest version of open source Java.
To Download Red Hat Enterprise Linux 6.3 Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Announced Three Editions of Windows 8 Along With Key Features

Microsoft Announced Three Editions of Windows 8 Along With Key Features

Earlier we have discussed on Consumer Preview Windows 8 & Windows 8 Developer Preview. Now In the official blog post Microsoft Windows Communications Manager Brandon LeBlanc Microsoft announced three editions of its upcoming Windows 8 platform: Windows 8, Windows 8 Pro and Windows RT, which was previously known at Windows on ARM, or WOA. According to Brandon LeBlanc’s post, Windows 8 Pro will include everything in Windows 8 along with advanced features such as encryption, virtualization, PC management and domain connectivity. Windows 8 Pro users will also be able to purchase Windows Media Center as a cheaper add-on. Microsoft recommends Windows 8 (the entry-level, limited functionality edition) for home use. As usual, this edition does not include BitLocker hard drive encryption, EFS file encryption or the ability to boot from a VHD. It is also not possible to access it using Remote Desktop (host). Computers running this edition are also unable to join domains and can't be managed using group policies. All these functions are reserved for Windows 8 Pro, as is the Hyper-V client for desktop visualization

Key Features:- 

Feature name Windows 8 Windows 8 Pro Windows RT
Upgrades from Windows 7 Starter, Home Basic, Home Premium
x
x
Upgrades from Windows 7 Professional, Ultimate x
Start screen, Semantic Zoom, Live Tiles x x x
Windows Store x x x
Apps (Mail, Calendar, People, Messaging, Photos, SkyDrive, Reader, Music, Video) x x x
Microsoft Office (Word, Excel, PowerPoint, OneNote) x
Internet Explorer 10 x x x
Device encryption x
Connected standby x x x
Microsoft account x x x
Desktop x x x
Installation of x86/64 and desktop software x x
Updated Windows Explorer x x x
Windows Defender x x x
SmartScreen x x x
Windows Update x x x
Enhanced Task Manager x x x
Switch languages on the fly (Language Packs) x x x
Better multiple monitor support x x x
Storage Spaces x x
Windows Media Player x x
Exchange ActiveSync x x x
File history x x x
ISO / VHD mount x x x
Mobile broadband features x x x
Picture password x x x
Play To x x x
Remote Desktop (client) x x x
Reset and refresh your PC x x x
Snap x x x
Touch and Thumb keyboard x x x
Trusted boot x x x
VPN client x x x
BitLocker and BitLocker To Go x
Boot from VHD x
Client Hyper-V x
Domain Join x
Encrypting File System x
Group Policy x
Remote Desktop (host) x

Announcing the Windows 8 Editions:-  
"First, Windows 8 is the official product name for the next x86/64 editions of Windows.
For PCs and tablets powered by x86 processors (both 32 and 64 bit), we will have two editions: Windows 8 and Windows 8 Pro. For many consumers, Windows 8 will be the right choice. It will include all the features above plus an updated Windows Explorer, Task Manager, better multi-monitor support and the ability to switch languages on the fly (more details on this feature can be found in this blog post),which was previously only available in Enterprise/Ultimate editions of Windows. For China and a small set of select emerging markets, we will offer a local language-only edition of Windows 8.
Windows 8 Pro is designed to help tech enthusiasts and business/technical professionals obtain a broader set of Windows 8 technologies. It includes all the features in Windows 8 plus features for encryption, virtualization, PC management and domain connectivity. Windows Media Center will be available as an economical “media pack” add-on to Windows 8 Pro. If you are an enthusiast or you want to use your PC in a business environment, you will want Windows 8 Pro.
Windows RT is the newest member of the Windows family – also known as Windows on ARM or WOA, as we’ve referred to it previously. This single edition will only be available pre-installed on PCs and tablets powered by ARM processors and will help enable new thin and lightweight form factors with impressive battery life. Windows RT will include touch-optimized desktop versions of the new Microsoft Word, Excel, PowerPoint, and OneNote. For new apps, the focus for Windows RT is development on the new Windows runtime, or WinRT, which we unveiled in September and forms the foundation of a new generation of cloud-enabled, touch-enabled, web-connected apps of all kinds.  For more details on WOA, we suggest reading this blog post which shares more detail on how we have been building Windows 8 to run on the ARM architecture..."



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Closing Support for Windows XP & Office 2003 in 2 Years

Microsoft Closing Support for Windows XP & Office 2003 in 2 Years

Bad news for Windows XP lovers, Microsoft declared that they will officially end support for Windows XP and Office 2003 in two years--on April 8, 2014, to be exact. Additionally, mainstream support for Windows Vista ends Tuesday. That means the few Vista users that are out there will be charged on a per-incident basis for support going forward. 
"If you still have some PCs running Windows XP and Office 2003, now would be a good time to start migrating them to Windows 7 and Office 2010," said Stella Chernyak, a marketing director in Microsoft's Windows group. "Windows XP and Office 2003 were great software releases in their time, but the technology environment has shifted. Technology continues to evolve and so do people's needs and expectations. Modern users demand technologies that fit their personal workstyle and allow them to stay productive anywhere anytime, while businesses have an ever increasing need to protect data and ensure security, compliance and manageability" - she added. 
But there's a large amount of users still using XP up to SP3, and not everyone will be happy about having to upgrade. And enterprise deployment can take anywhere between 18 to 32 months from business case through full deployment, so those who want to stick with Windows and Office should begin planning, well, now. The company recommends switching to Windows 7 and Office 2010 rather than waiting for Windows 8. Microsoft wants to facilitate that migration and is thus offering a free download of the Microsoft Deployment Toolkit. It will assist with new deployments of Windows 7, Windows Server 2008 R2, Windows Vista, Windows XP, Windows Server 2008, and Microsoft Office products.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Mozilla Put Older & Vulnerable Versions of Java Into Firefox Blocklist

Mozilla Put Older & Vulnerable Versions of Java Into Firefox Blocklist

In the official blog post Mozilla confirmed that they have blacklisted unpatched versions of the Java plug-in from Firefox on Windows in order to protect its users from attacks that exploit known vulnerabilities in those versions. "The February 2012 update to the Java Development Kit (JDK) and Java Runtime Environment (JRE) included a patch to correct a critical vulnerability that can permit the loading of arbitrary code on an end-user’s computer. This vulnerability—present in the older versions of the JDK and JRE—is actively being exploited, and is a potential risk to users. To mitigate this risk, we have added affected versions of the Java plugin for Windows (Version 6 Update 30 and below as well as Version 7 Update 2 and below) to Firefox’s blocklist. A blocklist entry for the Java plugin on OS X may be added at a future date. Mozilla strongly encourages anyone who requires the JDK and JRE to update to the current version as soon as possible on all platforms. Affected versions of the Java plugin will be disabled unless a user makes an explicit choice to keep it enabled at the time they are notified of the block being applied."- Said Mozilla
Unlike Google's Chrome browser, which has a feature specifically aimed at disabling outdated plug-ins, Firefox relies on Mozilla developers deciding which plug-ins pose a risk to users. However, users retain the choice of preventing those plug-ins from being disabled. The Firefox blocklist has rarely been used to disable plug-ins from big software vendors like Oracle, but precedents do exist. In October 2009, Mozilla decided to add Microsoft's Windows Presentation Foundation (WPF) plug-in to the Firefox blocklist after Microsoft revealed that it had a vulnerability.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Security Bulletin (March 2012) Closed Critical RDP Security Hole

Microsoft Security Bulletin (March 2012) Closed Critical RDP Security Hole 

Microsoft released March 2012 Security bulletins to close a total of seven security holes in its products. Among them one Critical-class, four Important and one Moderate – addressing seven issues in Microsoft Windows, Visual Studio, and Expression Design. According to Microsoft (MS12-020) remote code execution vulnerability has been found in RDP (Remote Desktop Protocol).
The first of these is a "critical-class" issue in RDP that could be exploited by an attacker to remotely execute arbitrary code on a victim's system. Although RDP is disabled by default, many users enable it so they can administer their systems remotely within their organizations or over the Internet. All supported versions of Windows from Windows XP Service Pack 3 to Windows 7 Service Pack 1 and Windows Server 2008 R2 are affected. As the issue was reported to company by the Zero Day Initiative (ZDI), Microsoft says that it has yet to see any active attacks exploiting these in the wild, but warns that, "due to the attractiveness of this vulnerability to attackers", it anticipates "that an exploit for code execution will be developed in the next 30 days". Because of this it recommends that installing the updates should be made a priority. 
Microsoft has also provided a workaround and a no-reboot "Fix it" tool that enables Network-Level Authentication (NLA) to mitigate the problem. A second "moderate-class" denial-of-service (DoS) which can cripple an RDP server was also fixed.
A brief overview of all of these updates, including descriptions about each of the vulnerabilities, can be found in Microsoft's Security Bulletin Summary for March 2012.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Internet Explorer & Firefox Also Became Victim To Hackers At Pwn2Own

Internet Explorer (IE 9) & Firefox 10.0.2 Also Became Victim To Hackers At Pwn2Own
At Pwn2Own contest the web-browsers are getting hacked in a series. First it was the turn of Google Chrome where Sergey Glazunov, a Russian security researcher has earned $60,000 by demonstrating how he could waltz past the security sandbox in Google's Chrome browser to run unauthorized code on fully-patched Windows 7 computers. Then the time came for Microsoft's Internet Explorer. A team from a French security firm managed to hack IE 9 on a fully patched Windows 7 SP1 machine. The group from Paris-based Vupen Security brought down IE9 running on Windows 7 by exploiting a pair of previously-unknown "zero-day" bugs that bypassed the operating system's defensive technologies to execute attack code, allowing that code to escape from IE's "Protected Mode," the browser's limited-rights anti-exploit system. They managed to bypass the browser's DEP and ASLR protection with a 0-day heap overflow vulnerability, and then used a separate memory corruption bug to break out of its Protected Mode, which is effectively a sandbox. According to VUPEN founder Chaouki Bekrar, these particular flows have existed in previous incarnations of the browser - all the way back to IE 6 - and will very likely work on the upcoming IE 10.
Then the turn of Firefox came. Mozilla’s Firefox is the latest browser to fall victim to hackers at this year’s Pwn2Own hacker contest. Two researchers working together – Willem Pinckaers and Vincenzo Iozzo — exploited a single zero-day vulnerability in the latest Firefox 10.0.2 on a fully patched Windows 7 SP1 PC to cart off a $30,000 cash prize.


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

After Google Chrome Hack Sergey Glazunov Earnd $60,000 At Pwnium Contest

Sergey Glazunov, A Security Researcher Earn $60,000 At Pwnium After Google Chrome Hack

Sergey Glazunov, a Russian security researcher has earned $60,000 by demonstrating how he could waltz past the security sandbox in Google's Chrome browser to run unauthorized code on fully-patched Windows 7 computers. Glazunov discovered a remote code execution vulnerability in Chrome, that could be used by malicious hackers and cyber criminals to install and run code on innocent users' computers, just by them visiting a website. Glazunov, who is no stranger to reporting bugs in Chrome, won his substantial reward as part of the Pwnium competition run by Google at the CanSecWest conference in downtown Vancouver.
Senior Vice President of Google Chrome and Apps, Sundar Pichai, confirmed the successful hack on his Google+ page. Now that the hack is known throughout the developer world, Pichai understandably said, “Congrats to long-time Chromium contributor Sergey Glazunov who just submitted our first Pwnium entry. Looks like it qualifies as a “Full Chrome” exploit, qualifying for a $60k reward. We’re working fast on a fix that we’ll push via auto-update. This is exciting; we launched Pwnium this year to encourage the security community to submit exploits for us to help make the web safer. We look forward to any additional submissions to make Chrome even stronger for our users.”



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...