Showing posts with label patches. Show all posts
Showing posts with label patches. Show all posts

Friday, November 28, 2008

Beware nasty Mebroot trojan

Beware of malware called Sinowal (also as Mebroot) captures bank and similar data. A gang of Internet criminals have been using this and even morphing the malware to temporarily fool antivirus software.

Windows Secrets contributing editor Woody Leonhard likens Mebroot to "a parasitic operating system that runs inside Windows". [Disclaimer: I subscribe to the paid version of "Windows Secrets" newsletter. Prior to that subscribed for years to the paid version of Fred Langa's "LangaList" newsletter, which is now integrated into Brian Livingston's "Windows Secrets" newsletter. I highly recommend Windows Secrets anyone concerned about or interested in PCs.]

Leonhard says that his experience is that a lot of systems get infected with Mebroot (Sinowal) because the owners did not keep up with Adobe Reader, Adobe Flash, or Apple Quicktime security patches. You can manually check for such patches, set the apps to automatically check for updates, or (even better), install the free Secunia Personal Software Inspector (PSI) and scan for programs that need updating.

In October 2008 Brian Krebs, Washington Post, alerted readers to the "virtual heist" going on. Mebroot infects the Master Boot Record (MBR) of your PC and sends personal data to its "owners". Krebs says that the criminals have stolen over half a million credit and debit card account in the past few years.

While Symantec lists the malware's risk as low, if your data gets stolen, it won't be a little thing to you. Here are some actions Symantec and I recommend to reduce your risk of malware infections:

  • Use a firewall
  • Enforce complex passwords for all users of your computer
  • Use the lowest level access privileges.
  • Never use an Administrator-level login account as your normal one. Always login as a lower level account and then "Runas" or login as the Administrator level only as needed. Vista security is a big advance in making this type security easier. Yes, you get pop-ups to login as Administrator, but that's much better than manually running a "runas" command and you don't need to know the runas command line syntax.
  • Disable Auto-play
  • Turn off "File Sharing"
  • Turn off and remove unnecessary system services
  • Always keep your programs patched (You can use the free Secunia PSI to monitor patch status)
  • Don't open email attachments unless you were expecting them. Contact the sender separately (not by a "Reply") and see if they really did send you that email and attachment.
  • Turn off Bluetooth via Windows Control Panel if you are not using it.
  • If you really need to use Bluetooth, make sure every Bluetooth device's visibility is set to "Hidden".

Wednesday, November 26, 2008

Secunia PSI now in final form

Secunia Personal Software Inspector (PSI) is now officially out of beta and at version 1.0 (well, OK ... version 1.0.0.1). I have used versions prior to 1.0 and found them excellent. I'll be downloading, installing, and running PSI 1.0 today. I encourage you to do the same. This free software checks your programs for any updates.

While Microsoft Update (or the lesser Windows Update) does a great job, they naturally only deal with Microsoft products. Your computer has tons more programs, each of which may need a security patch, bug fix, or enhancement. Why check them all manually? Let PSI check for you. Try it; you'll like it.

To really stay on top of patches, I also use Driver Detective (not free, but very worth having).

Friday, December 28, 2007

Software Patch Inspector

Secunia's Personal Software Inspector (PSI) is now in Release Candidate 1 (RC-1).

Of ZD Net's top 10 free security utilities you should be using, they say, "Number one is the Secunia Personal Software Inspector, quite possibly the most useful and important free application you can have running on your Windows machine."
http://content.zdnet.com/2346-12691_22-95490-1.html

The latest update features an improved look plus easier use by novices, yet advanced options can be turned on.

You can even track the results of your patching. Run, don't walk, and get Secunia's PSI now!

Wednesday, October 24, 2007

Non-Microsoft security updates

Several security updates came out recently for products other than Microsoft ones, although a couple apply only if you are using Internet Explorer version 7. If you have the following software, make sure you get the patches:

  • Adobe Acrobat 8
  • Adobe Reader 8.1.1
  • Apple Quicktime 7.2
  • Mozilla Firefox 2.0.0.8

Wednesday, August 29, 2007

You need more than Windows Update

If you use Microsoft Windows, you are likely familiar with Windows Update, the free service that installs security patches, bug patches, and some enhancements to Windows. But you really need much more.

You need to get updates for other Microsoft prograns, such as Microsoft Office. You can do that by installing "Microsoft Update ".

Next, download and install the Secunia Personal Software Inspector and check for outdated programs and ones needing updates. Though in beta, it works well and is an eye-opener.

Don't put it off -- prote t your computer now!

Tuesday, August 21, 2007

Outdated programs risky

Many programs these days need updates, not just your operating system (e.g. Windows). As an example, today's Windows Secrets points to the following common programs:
  • Adobe Reader
  • Macromedia Flash
  • Apple Quicktime
  • Sun Java
  • Mozilla FireFox

Most of these programs default to checking for updates. But if you ignore the update message or if it only checks once a month, you can be way behind in plugging security holes (a.k.a. "vulnerabilities").

What can you do about that? One very big help is the free Secunia Personal Software Inspector (PSI). You can try it online first and download if it serves as an eye opener for you -- it did for me.

For one thing, I discovered old versions of Sun Java on my system. Any "point" version needs to be updated to its most recent one. For example, the only currently secure versions of Sun Java JRE are version 5 update 12 and version 6 Update 2 (also known as 1.5.0_12 and 1.6.0_02)

Wednesday, March 28, 2007

Microsoft leads patch pack

Symantec has issued its semi-annual report on Internet Security Threat Trends for the last half of 2006. One finding is that Microsoft offers patches for vulnerabilities faster than the other four vendors checked.

In decreasing order of fast response (1 = best, 5 = worst), they are:
  1. Microsoft
  2. Red Hat
  3. HP
  4. Apple
  5. Sun

Tuesday, January 02, 2007

You need more than automatic updates

Windows' "Automatic updates" only downloads "critical" updates. Windows Update and Microsoft Update, which has MS Office updates too, both have a ton of security patches plus added features you can download. The optional updates and hardware-related updates do not automatically download.

So periodically manually surf to the Update site (Windows Update or Microsoft Update) and check out the other two categories of updates -- "Software Updates [optional]" and "Hardware updates".

Update your PC clock for new DST

Here's an update listed as optional that I'd prefer to be mandatory -- update the system time to reflect the new dates for Daylight Savings Time (Microsoft Knowledgebase article 928388). In case you didn't recall, the U.S. and several other countries have decided to change the start and stop dates for DST.

Since your PC clock has the "old" rule, you really do need this update so that the system can change the time automatically when DST arrives and departs.

Wednesday, August 09, 2006

Intel Centrino Wireless driver security vulnerability

The Microsoft Windows drivers for the Intel 2200BG and 2915ABG PRO/Wireless Network Connection Hardware have a secuity vulnerability and should be patched.

How do you tell if you need this? Use Device Manager:
  1. Select the Start Button
  2. RIGHT-click on "My Computer"
  3. Select "Properties" from the pop-up menu.
  4. Select the "Device Manager" button
  5. Expand the "Network adapters" section if it's not already expanded.
  6. If either of the above adapters shows in your list, RIGHT-click on the adapter and then select "Properties"
  7. Select the "Driver" tab and note the Driver version.
The Intel site has the wireless driver patch and more details.