Hunter Strategies LLC logo

Microsoft News Tracker

What’s more interesting than observing Microsoft?

April 27, 2008

Microsoft IIS Web servers hit by widespread SQL injection attacks

Posted by David Hunter at 10:39 AM ET.

Over the last week there have been a number of reports of automated SQL injection attacks on Web sites running Microsoft’s flagship IIS Web server. The Washington Post’s Brian Krebs summarizes them nicely in Hundreds of Thousands of Microsoft Web Servers Hacked.

If there is any good news in this, it is that the server modifications so far only amount to the addition of a Javascript malware loader on site Web pages.  While this loader will infect unpatched browsers (and apparently RealPlayer and Yahoo Instant Messenger), the browser holes that it exploits are not new and patches have previously been made available. The status on RealPlayer and Yahoo IM is currently unclear.

It isn’t entirely clear whether there is actually a vulnerability in IIS or it’s just the usual problem of Web programmers not sanitizing user input, but Microsoft has issued a security advisory (951306) with workarounds.

Update: Microsoft’s Bill Sisk says that the problem is due to poor Web programming practices and not any IIS vulnerability and also that security advisory 951306 is for a different problem.


 
AddThis Social Bookmark Button

Filed under Security, Technologies, IIS, Microsoft

 

   

September 14, 2007

Windows Live Messenger rolls out mandatory upgrade to 8.1

Posted by David Hunter at 9:19 AM ET.

Anand, a Microsoft security program manager reveals via the Inside Windows Live Messenger blog that Microsoft is forcing Live Messenger users to upgrade to version 8.1 before any further usage due to a security exposure in earlier versions.

(more…)


 
AddThis Social Bookmark Button

Filed under Security, Windows Live, Windows Live Messenger, Microsoft

 

August 14, 2007

Patch Tuesday brings some Vista Gadget fixes

Posted by David Hunter at 8:04 PM ET.

It’s hard to get excited about Microsoft’s monthly Patch Tuesday since its arrival is inevitable as death and taxes, so ”Microsoft fixes 14 flaws in biggest patch day since February” isn’t much of an eyebrow raiser, but Todd Bishop points out one interesting patch for Vista Gadgets:

(more…)


 
AddThis Social Bookmark Button

Filed under OS - Client, Windows Vista, Security, Microsoft, Patch Tuesday

 

August 8, 2007

Microsoft releases jumbo Vista maintenance updates

Posted by David Hunter at 10:16 AM ET.

The two large collections of non-security Vista fixes whose existence was leaked a week ago have now been formally released by Microsoft as

(more…)


 
AddThis Social Bookmark Button

Filed under OS - Client, Windows XP, Windows Vista, Security, Beta and CTP, Microsoft, Patch Tuesday

 

July 30, 2007

Microsoft tests Vista maintenance packs

Posted by David Hunter at 7:48 PM ET.

Yesterday, news leaked that Microsoft has released two new beta maintenance packs for Windows Vista to Windows Server 2008 beta testers. They are named the “Vista Performance and Reliability Pack” and the “Vista Compatibility and Reliability Pack” and provide fixes for many of the significant non-security problems early Vista users have encountered. Speculation has it that they will be released on the next regular Patch Tuesday which is August 14.

The natural question is why isn’t this Vista Service Pack 1 and speculation abounds there too, but since at least the promised search fixes for Google apparently aren’t included, the simple answer is that Microsoft has more work to do before SP1 is ready. In the meantime, there’s no reason they shouldn’t be shipping Vista bug fixes. As for the odd venue of a Windows Server 2008 beta program, it sounds like merely an expedient way to find some beta testers since the Vista testing program has ended.


 
AddThis Social Bookmark Button

Filed under OS - Client, Windows Vista, Security, Beta and CTP, Microsoft, Patch Tuesday

 

News Search:

Recent Posts:

Daily Digest Email:

Enter your Email


Powered by FeedBlitz

Top Level Categories:

Full category list Full category list

Archives:

May 2008
S M T W T F S
« Apr    
 123
45678910
11121314151617
18192021222324
25262728293031

RSS Feed:



HunterStrat Links:

Other:


Advertisements:





 
Search Now:  
Amazon Logo

Related:


Misc:


 

Tracked by ClickAider