Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

U.S. Cloud Firms Suffer From NSA PRISM Program

CIO - For U.S. cloud providers, already working to beat back a wave of overseas policies they say tilt the playing field in favor of home-grown competitors, the revelations of the National Security Agency's PRISM electronic surveillance program have only made conditions in foreign markets tougher.

http://www.networkworld.com/news/2013/072513-us-cloud-firms-suffer-from-272197.html?source=nww_rss
NSA PRISM Progam



The media accounts of the program based on leaks by former contractor Edward Snowden have created a perception that the U.S. government has unlimited and direct access to data stored on the servers of companies like Google and Microsoft, experts said on Wednesday at a policy talk here at the Information Technology and Innovation Foundation, a D.C. think tank.

Microsoft ignores serious MSXML update issue

https://www.security.nl/artikel/46991/1/MS_ignores_XML_update_issue.html
Microsoft ignores serious MSXML update issue
July 2012, an issue was found regarding Microsoft XML Core Services (MSXML) updates. 
The process of that discovery can be seen in this forum thread, in Dutch:
http://www.security.nl/artikel/42204/1/Patch_XML_core_services_is_uit%21.html
It took a couple of days before it got clear what exactly was going on, and that turned out to be as follows:

MSXML 4.0 SP2 is no longer supported since April 2010.
See http://en.wikipedia.org/wiki/MSXML
and http://support.microsoft.com/kb/269238/en 

MSXML 4.0 SP2 is no longer supported since April 2010.
See http://en.wikipedia.org/wiki/MSXML
and http://support.microsoft.com/kb/269238/en

July's Patch Tuesday fixes Windows privilege system

On its July Patch Tuesday, Microsoft released a total of seven patch packages (bulletins). All except one of them close critical vulnerabilities. The company has closed a total of 34 holes in Windows, Internet Explorer, Office and many other products, among them the Windows kernel vulnerability that has affected the Windows privilege system for over a month.

http://www.h-online.com/security/news/item/July-s-Patch-Tuesday-fixes-Windows-privilege-system-1914459.html
Microsoft patch packages
Google security expert Tavis Ormandy discovered the kernel hole in May and didn't wait too long before disclosing details of it on the net. Shortly afterwards, an exploit followed that opens a Windows prompt at system privilege level – regardless of the user's actual privilege level. The hole, with CVE identification number CVE-2013-3660, affects all versions of Windows. 

Microsoft didn't warn its customers about the security problem ahead of the patch day despite, according to the company, the hole being exploited for targeted attacks. Talking to The H's associates at heise Security since the disclosure, Microsoft had only said that it was investigating the problem and was working on a solution. Patch bulletin MS13-053 closes further critical security holes, including an issue in the code for processing TrueType fonts, and should be installed as soon as possible.

Silent war / Cyber-conflicts

On the hidden battlefields of history’s first known cyber-war, the casualties are piling up. In the U.S., many banks have been hit, and the telecommunications industry seriously damaged, likely in retaliation for several major attacks on Iran. Washington and Tehran are ramping up their cyber-arsenals, built on a black-market digital arms bazaar, enmeshing such high-tech giants as Microsoft, Google, and Apple. With the help of highly placed government and private-sector sources, Michael Joseph Gross describes the outbreak of the conflict, its escalation, and its startling paradox: that America’s bid to stop nuclear proliferation may have unleashed a greater threat.

http://www.vanityfair.com/culture/2013/07/new-cyberwar-victims-american-business
Cyber-conflict
Cyber- conflict | Vanity Fair

Microsoft offers $100,000 USD for hackers to hack Windows 8.1

Microsoft invites hackers to break into Windows 8.1. and Internet Explorer 11. When hackers succeed to find bugs and security weakness in Windows 8.1. and Internet Explorer 11, Microsoft will give away cash up to $100,000 USD.

There are three competition categories. Each competition has different prize. The competition will begin on June 26, 2013. The first two competitions will run continiously, while the last competition is only for a month.
http://www.abcnetspace.com/2013/06/microsoft-offers-100000-usd-for-hackers.html
Microsoft competition
Microsoft competition | Abcnetspace.com

Skype Provided Backdoor Access to the NSA Before Microsoft Takeover

NSA Logo
NSA Logo
The NSA saga continues in the Redmond-based empire, this time with a new report aimed at Microsoft’s flagship VoIP platform Skype.

A report published by The New York Times and citing people who asked not to be named for obvious reasons, Skype developed its own user-monitoring system before the Microsoft acquisition in October 2011.

It appears that US intelligence agencies have insisted that local software companies must cooperate closer with the NSA, so it asked several top vendors, including Skype, to put together secret teams to develop systems that would provide them with backdoor access to users’ conversations.

The source claims that the NSA wanted “to control the process themselves” and thus skip the process of contacting the parent company and asking for details on select user accounts.

Microsoft Security Bounty Programs

Microsoft security
Microsoft security
Microsoft is now offering direct cash payments in exchange for reporting certain types of vulnerabilities and exploitation techniques.

The following programs will launch on June 26, 2013:
  • Mitigation Bypass Bounty. Microsoft will pay up to $100,000 USD for truly novel exploitation techniques against protections built into the latest version of our operating system (Windows 8.1 Preview). 
  • BlueHat Bonus for Defense. Additionally, Microsoft will pay up to $50,000 USD for defensive ideas that accompany a qualifying Mitigation Bypass submission. 
  • Internet Explorer 11 Preview Bug Bounty. Microsoft will pay up to $11,000 USD for critical vulnerabilities that affect Internet Explorer 11 Preview on the latest version of Windows (Windows 8.1 Preview).
Bounty Programs | Microsoft Security Response Center

Google researcher discloses zero-day exploit for Windows

Google security expert Tavis Ormandy has discovered a security vulnerability in Windows which can be exploited by any user on the system to obtain administrator privileges. Rather than reporting the vulnerability to Microsoft, he posted details to the Full Disclosure security mailing list in mid-May and has now published an exploit to the same mailing list.

With this latest vulnerability, Ormandy once more opted for full disclosure on the mailing list of the same name. After discovering a bug in the Windows kernel's EPATHOBJ::pprFlattenRec function, he wrote to the list: "I don't have much free time to work on silly Microsoft code" and solicited ideas on how to successfully exploit the bug. With the help of user progmboy, Ormandy then developed a privilege escalation exploit which he shared with the mailing list, noting that another exploit was already in circulation.

The Risks of Microsoft Exchange Features that Use Oracle Outside In

The WebReady and Data Loss Prevention (DLP) features in Microsoft Exchange greatly increase the attack surface of an Exchange server. Specifically, Exchange running on Windows Server 2003 is particularly easy to exploit.