1 min
Metasploit
Free Microsoft Virtual Machines for Testing
I am often asked how security professionals and students can safely test
security software. My usual response is, they should create a virtual lab with
diverse operating systems for testing. The problem that many encounter is they
don't have licenses available to install the operating systems.
During my creating and testing the Metasploit Javascript Keylogger
[/2012/02/21/metasploit-javascript-keylogger], I came across free virtual
machines from Microsoft that are sure to be useful to securit
2 min
Microsoft
Microsoft Patch Tuesday - November 2011
November's Microsoft Patch Tuesday contains four bulletins: one “critical”, two
“importants”, and one “moderate”. The majority of these bulletins relate to
Microsoft's later versions of the OS, implying that the flaws they address were
possibly introduced with Windows Vista. Generally more vulnerabilities are found
in earlier versions of the OS, so this month is unusual.
The critical bulletin – MS11-083 – is a TCP/IP based, specifically UDP,
vulnerability which affects Vista, Windows 7, Server
2 min
Microsoft
Microsoft September 2011 Patch Tuesday
This month, Microsoft issued five bulletins to address 15 vulnerabilities. All
of these bulletins are rated “important”; however, while there are no “critical”
bulletins this month, organizations should not downplay the vulnerabilities
being addressed. It's easy for organizations to gain a false sense of security
during a light patch month and sometimes an attitude of complacency towards
non-critical vulnerabilities is evident.
“Important” vulnerabilities may not give attackers the full roo
1 min
Microsoft
August Patch Tuesday
Yesterday was Microsoft Patch Tuesday, with 13 bulletins issued to address 22
vulnerabilities. Of these, only two are rated “critical”; the first of which –
MS11-057 – is the latest Internet Explorer cumulative patch. Until this one is
patched, we'd recommend limiting your use of Internet Explorer to only visiting
trusted sites and remember that it's never a good idea to click on suspect or
unknown links. If users are still concerned, they may want to consider using one
of the alternate browser
2 min
Microsoft
April Patch Tuesday Round-Up
LOTS of patches from Microsoft this week...
This week's Patch Tuesday was pretty significant, with a record-tying 17
bulletins that patch a record 64 vulnerabilities, 15 more than the previous
largest-ever set in October 2010. As usual, the Rapid7 team was all over it,
monitoring the threat and trying to help out where possible.
This month's bulletin addresses vulnerabilities across Microsoft Windows,
Microsoft Office, Internet Explorer, Visual Studio, .NET Framework and GDI .
There are seve
3 min
Microsoft
Visualizing Microsoft Security Bulletin Supersedence
I've always been a very visual person. As a young child, I had an interesting
ability to be able to subconsciously scan the landscape and immediately pick out
things that were out of place. On my way to work or otherwise driving around
town, my eyes are scanning the passenger's, rear-view and driver's side mirrors
every few seconds looking for things that make driving around Los Angeles
perilous.
When it comes to complex problems related to security, or even just things that
may present obst
3 min
Microsoft
November Microsoft Patch Tuesday Roundup
Time once again for this month's summary of the latest Microsoft Security
updates …
6 updates, with 15 vulnerabilities covered. Here's the breakdown:
MS09-063: Rated Critical. Potential Remote Code Execution via Memory Corruption
in Web Services on Devices API, covering 1 vulnerability: CVE-2009-2512.
Important to note that this one only affects Windows Vista and Server 2008. Also
important to note that attackers must be on the local subnet to exploit this
vulnerability, so it would either b
4 min
Microsoft
October Microsoft Patch Tuesday Roundup
Time for this month's summary of the latest Microsoft Security updates …
13 advisories, with 34 vulnerabilities covered. Here's the breakdown:
MS09-050: Rated Critical. Potential Remote Code Execution and Denial of Service
in SMBv2, covering 3 vulnerabilities: CVE-2009-2526 (Infinite Loop DoS),
CVE-2009-2532 (Command Value Remote Code Exec), and CVE-2009-3103 (Negotiation
Remote Code Exec). Important to note that this one was listed as a DoS on NVD
while Metasploit and others were insisting
1 min
Microsoft
October Microsoft Patch Tuesday Preview
Wow, because the number of bulletins affecting the number of Windows versions is
pretty staggering. Windows is taking the most lumps this month.
Wow, because Windows7 makes its debut in the monthly dance with 5 updates
(although only the IE update is critical)
Wow, because Bulletin 13 alone affects the following products across the
Microsoft universe:
- Windows 2000 SP4
- Windows XP (SP2 and SP3)
- Windows Server 2003 SP2
- Windows Vista & Vista SP1
- Windows 2008
- Office XP
-