Computer,internet,download,opinion,informations

Google

Sunday, June 24, 2007

CryptoExpert 2007 Lite 7.05

Platform Windows 2000, Windows XP
Type freeware
Manufacturer SecureAction Research, LLC
Size 2.06MB
Free Download

CryptoExpert creates encrypted virtual disks and these disks are visible as usual disks with drive letters (for example, G:, H:, Z:, i.e. with any drive letter that isn't in use by other system devices).

The data stored on a CryptoExpert disk is stored in the container file. A container is a file, so it is possible to backup a container, move or copy it to other disk (CD-ROM or network, for instance) and continue to access your encrypted data using CryptoExpert.

Any free drive letter (or chosen letter) in the system may be used to mount and to open an encrypted file-container for access.

When your virtual disk is opened, you can read and write data as if it were a conventional removable disk.

You can do anything with a CryptoExpert virtual drive that you can do with a normal hard drive, but with CryptoExpert, the encrypted volumes require password authentication before the files become accessible.

Labels:

RootkitRevealer 1.71

Platform Windows 2000, Windows XP, Windows Vista
Type
freeware
Manufacturer Microsoft
Size
225Kb
Free download

Advanced rootkit detection utility. It runs on Windows NT 4 and higher and its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. RootkitRevealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and HackerDefender (note: RootkitRevealer is not intended to detect rootkits like Fu that don't attempt to hide their files or registry keys). If you use it to identify the presence of a rootkit please let us know!

The reason that there is no longer a command-line version is that malware authors have started targeting RootkitRevealer's scan by using its executable name. We've therefore updated RootkitRevealer to execute its scan from a randomly named copy of itself that runs as a Windows service. This type of execution is not conducive to a command-line interface. Note that you can use command-line options to execute an automatic scan with results logged to a file, which is the equivalent of the command-line version's behaviour.

Labels:

Saturday, June 23, 2007

Ad-Aware 2007 Free 7.0.1.4

Platform Windows 2000, Windows XP
Type
freeware
Manufacturer Lavasoft
Size
17.3MB
Free download

This free utility scans your PC to identify and remove any adware or spyware components.

For the uninitiated, adware or spyware is unwanted software that can be installed on your PC, either with other software or when you visit websites (cookies etc).

They can track your surfing habits, push aggressive advertising at you, and generally abuse your privacy.

This new version completely overhauls the scanning engine, which results in more accurate scanning methods and an all-new program architecture. This new version now supports the detection of embedded malware, including known and emerging threats.

The new TrackSweep module will control privacy by erasing tracks left behind while surfing the web through Internet Explorer, Firefox, and Opera, with one easy click.

You decide exactly what is scanned on your PC, from a single folder to the complete system. Files larger than a specified size can be skipped, making for a quicker scan. Flagged components can be quarantined, letting you restore them if their removal causes problems.

Note that the free version is for personal-use only. This is not Vista-ready.

Labels:

Friday, June 15, 2007

Microsoft Malicious Software Removal Tool 1.30

Platform Windows 2000, Windows XP
Type
freeware
Manufacturer
Microsoft
Size
4.6MB
Free download

Security must be becoming an important issue for Microsoft, as this is the second release in almost as many days, coming hot on the heels of its AntiSpyware software.

Download this small tool and your PC will be scanned and checked for malicious software. Should any be found it is automatically removed, and a full report displayed on-screen at the end of the scan.

A new version of this tool will be released every second Tuesday of the month, and the download link above takes you to the Microsoft download page to ensure you get the most up-to-date version.

You must have administrator access in order to run this software on your PC.

Labels:

Tuesday, May 01, 2007

Avant Browser 11.5 beta 3


Platform Windows 98, Windows NT, Windows 2000, Windows XP
Type
freeware
Manufacturer
Anderson Che
Size
1.8MB
Free download

Internet Explorer might come bundled with Windows but it lacks many features. A number of these can be found in Avant Browser.

Avant Browser is a quick download even for dial-up users. The interface is very similar to Internet Explorer, but open some of the menus and the differences are quickly obvious.

It is possible to deactivate different parts of a web page, such as pictures, sounds and flasgh animations. If you have a slow connection, this can make a huge difference.

Avant Browser can also block advertisements (including pop-ups), translate web pages, display web pages in full screen mode, and has full support for skins.

Any favorites or recently viewed pages from Internet Explorer can be easily imported, making migrating to this browser a doddle.

This is the third beta release of the forthcoming 11.5.


Labels: ,

Monday, April 30, 2007

Latest Apple update fixes 25 flaws


Apple has released its fifth security update of the year, covering 25 vulnerabilities in 20 Mac OS X components.

Fifteen of the vulnerabilities could allow an attacker to execute malicious code, but no working exploits have been reported for any of the attacks so far.

Three of the remote code execution vulnerabilities lie within Kerberos, a network security component developed by MIT. Apple credits the MIT Media Lab with reporting all three vulnerabilities.

Other fixes were for the Libinfo component and the LoginWindow software, which contained two flaws allowing users to bypass the authentication screen.

Apple's iChat video chat component received a fix for a vulnerability that could allow an attacker to remotely execute code on a user's system through a malformed video chat request.

The update also addresses a vulnerability in AirPort which could allow remote execution in several legacy systems. None of Apple's latest Mac Pro, iMac or MacBook systems is affected by the flaw.

The vulnerability is also unrelated to the pair of flaws patched earlier this month in the 802.11n AirPort systems.

The update is the second largest Apple has issued this year. The company released a security update last month containing 30 patches in 22 applications.

Labels:

Sunday, February 18, 2007

Five fixes in latest Apple patch
Apple has issued a security update containing five patches for vulnerabilities disclosed during January's Month of Apple Bugs (MoAB) project.

Of the five flaws fixed in the update, only one is rated as a 'high' risk by the US Computer Emergency Response Team (US-CERT).

The high-level risk is a vulnerability in iChat, Apple's instant messaging app, that could allow an attacker to execute code when a user views a specially crafted URL string sent through an instant message.

Three of the five vulnerabilities targeted iChat, including two that could be used to cause an application crash. Each of these vulnerabilities were rated as 'low' by US-CERT.

The remaining two fixes were for components in Mac OS X. A flaw in Finder allowed for arbitrary code execution when a specially crafted disk image was opened. This vulnerability only affected versions 10.4.x, according to Apple.

Another flaw, which targeted the UserNotificationCenter component, could be exploited to elevate user privileges. Both vulnerabilities were rated as 'medium' threats.

This latest round of patches is the second issued by Apple in 2007. The company issued a fix in January for a vulnerability in the Mac and Windows versions of QuickTime that allowed remote code execution.

All of the vulnerabilities patched this year by Apple have been credited to the MoAB project, which aimed to disclose a new vulnerability every day in January.

The project was run by a pair of security researchers to raise awareness of security issues and improve the quality of security software for MacOS X.

Labels:

Tuesday, December 12, 2006

Experts warn of Media Player vulnerability

A newly discovered security vulnerability in Windows Media Player has prompted security firms to warn users to remain extra vigilant and alter the way they handle a certain type of file.

According to a Microsoft security advisory, an attacker could use a specially crafted Media Player .asx file to gain control of a user's system and remotely execute malware.

The file could be placed in an HTML file, causing it to be automatically launched by the user's web browser.

Microsoft has confirmed the vulnerability and said that it is investigating the issue.

Secunia has given the vulnerability a rating of 'highly critical', the security firm's second highest alert level.

Originally disclosed on 22 November, and thought to cause only a denial-of-service attack, security research firm eEye now believes that exploit code could be written for the vulnerability.

EEye suggests that users can mitigate the threat by changing the default application to load .asx files.

WatchGuard security analyst Corey Nachreiner, however, believes that users should not panic over the vulnerability.

In a posting to WatchGuard's newswire feed entitled 'Unpatched Windows Media Player vulnerability announced; world fails to end,' Nachreiner downplays the immediate urgency of the flaw.

"While I do not doubt eEye's findings, there is a big difference between a flaw assumed to allow code execution and one confirmed to allow code execution, " he said.

Nachreiner pointed out that the Media Player vulnerability does not pose as serious a threat to users as the currently unpatched and active Word exploit.

The analyst still recommends users to follow eEye's steps to mitigate the effect of the vulnerability.

Labels:

Word flaw left out of Patch Tuesday

Microsoft will not be including a fix for the recently discovered Word vulnerability in its scheduled security update on 12 December.

The software giant has admitted that its next 'Patch Tuesday' update will not address a recently discovered vulnerability in Word that is currently being exploited.

A Microsoft spokesman told vnunet.com that the company is still investigating the matter.

Although the fix is not currently included in the December security update, the spokesman said that Microsoft has not ruled out releasing a separate fix before the next monthly release in January 2007.

The Word vulnerability, which affects at least nine Mac and PC versions of Word and Microsoft Works, has been given the highest possible alert rating of 'extremely critical' by security firm Secunia.

The exploit could allow an attacker to remotely execute malware on a user's system. Security firm F-Secure advises users not to open or save any Word files that come from untrusted sources or arrive unexpectedly from trusted sources.

Microsoft's update due on 12 December fixes five vulnerabilities in Windows, some of which are listed as 'critical', the company's highest security rating.

A fix for Visual Studio that addresses 'critical' vulnerabilities will also be included. As a single Microsoft security bulletin can address several versions of the same application, the security rating for a vulnerability will often differ between releases.

Labels:

Tuesday, November 28, 2006

New exploit published for Mac OS X

A security researcher has posted proof-of-concept code for a 'highly critical' vulnerability in Apple's OS X operating system.

The exploit targets a component used to run Apple's .dmg disk images files. The .dmg format is commonly used to compress programs for download and is similar to the .iso format used in Windows.

A security researcher using the initials 'LMH' posted details about the vulnerability as part of the Month of Kernel Bugs project.

The author claimed that the exploit could easily be executed in Apple's Safari web browser through a specially crafted .dmg file launched when a user visits a web page.

According to LMH, the threat can be mitigated in Safari by disabling a setting in the browser's preference panel that reads 'Open 'safe' files after downloading.'

Disabling the setting will prevent .dmg files, images, movies and PDF files from automatically opening after they have been downloaded.

Security firm Secunia rates the vulnerability as 'highly critical', its second-highest threat level. It is the highest alert level given to a Mac OS X vulnerability since the publication of an official Apple security update in early October.

Labels:

Sunday, November 12, 2006

Six Security Bulletins Update Next Week (141106)

Microsoft is planning to release six security bulletins next Tuesday as part of the company's monthly security patch cycle.

Each bulletin covers one or more software vulnerabilities. Five affect the Windows operating system. The maximum severity rating for these bulletins is 'critical'.

The software giant also plans to issue one bulletin covering Microsoft XML Core Service that is rated 'critical'. This is likely to cover a flaw that surfaced earlier this week in the XMLHTTP 4.0 ActiveX Control component of the technology.

Security researchers have detected a limited number of attacks targeting the vulnerability in the wild. The bug could allow an attacker to take control of a system by luring users to a specially crafted website.

Both the XML Core Service and Windows patches require a system restart.

In addition to the security bulletins, Microsoft also is preparing to issue two high-priority non-security updates.

Microsoft issues security updates on a monthly cycle on the second Tuesday of each month. The company provides early notification on the Thursday before the release to allow systems administrators to prepare for the event.

*Windows hit by 'extremely critical' zero-day flaw
* Consumer Vista to launch on 30 January

Labels:

Windows hit by 'extremely critical' zero-day flaw

Microsoft has issued a warning about a new exploit in all Windows versions except Windows 2003 that is actively being exploited by attackers.

The flaw affects a part of the Microsoft XML Core Services 4.0, referred to as the XMLHTTP 4.0 ActiveX Control.
Attackers could exploit the flaw to take control of a system by luring victims to a specially crafted website or a page on a social service such as MySpace.

Microsoft is currently investigation the flaw. The company will decide whether a security update is released as part of its patch cycle on the second Tuesday of each month or as an out-of-cycle update.

* Microsoft Security Advisory (927892)

Labels:

Google accidentally sends out e-mail worm

Google on Tuesday inadvertently sent the Kama Sutra e-mail worm to the 50,000 subscribers of a Google Video e-mail group.

Three messages were posted Tuesday evening to an e-mail list that sends out alerts about additions to the Google Video blog. "Some of these posts may have contained a virus called W32/Kapser.A@mm--a mass-mailing worm," Google said in a note on its Web site

apologizing for the incident.

W32/Kapser.A is better known as the Kama Sutra worm. Some antivirus companies raised an alarm about the threat in February, but it ultimately shriveled. Kama Sutra was designed to overwrite files on infected computers on a specific date. However, the worm, which spread under the guise of pornographic content, caused virtually no damage.

Google advises people who may have received the worm in e-mail or downloaded it from the group's Web site to run an antivirus program to remove it. The company is taking steps to make sure it doesn't make the same mistake again, it said.

The Google Video e-mail group is open to anyone. It had 50,025 subscribers as of Wednesday afternoon. The contents are advertised as interesting and fun videos from Google Video.

Google has had several mishaps lately. Its corporate blog has been hacked and, at one point, the company also accidentally deleted its official blog.

Labels:

Dref-N email worm promises breaking news

A new email worm is using bogus news headlines to lure users into opening its payload, security firm Sophos has warned.

The emails contain links to headlines such as the 'outbreak of nuclear war' and the 'death' of George W Bush and Vladimir Putin to allow hackers to infect computers and steal information.

The Dref-N worm arrives attached to emails with subject lines such as 'White house news!', 'Incredible news' or 'ATTN TO EVERYBODY!', and tries to dupe recipients by claiming that the attachment contains details of a major global news story.

Opening the attached file disables the Windows firewall and allows hackers to gain access to the PC in order to spy on or steal data.

Sophos said that the text of the email could include any of the following:

'3rd Glogal War Just Started!!! Read more in file!'
'Nuclear War in Russia! Read news in file!'
'President Bush DEAD! Read attached file!'
'Putin and Bush starts NUCLEAR WAR! Check the file!'
'Nuclear WAR in USA! Read attached file!'

'GLOBAL NUCLEAR WAR JUST STARTED! News in file.'
'President Putin dead! Read more in attached file!'

Labels:

'Macarena' virus hits Apple Mac OS X'

Security experts have detected a virus that targets Apple's Mac OS X systems.

Although largely harmless, researchers are referring to OSX.Macarena as a "wake up call to Mac users".

Symantec has classified the virus as a level-one 'very low' threat, as it lacks a 'payload' or any sort of malicious instructions other than simply to replicate itself.

The security firm said that, once OSX.Macarena is launched, it infects every file located in the same folder. At the time this article was written, Symantec confirmed that there were fewer than 50 confirmed cases of infection..

Labels:

Monday, October 30, 2006

Spoofing bug found in IE 7

IE 7, released last week, allows a Web site to display a pop-up that can contain a spoofed Web address, security monitoring company Secunia said Wednesday. An attacker could exploit this weakness to trick people into believing they are on a trusted Web site when in fact they are viewing a malicious page, Secunia said in an alert.

"This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions," Secunia said. The company has created a demonstration that shows a Microsoft Web address in the pop up window, but displays content from Secunia.

Labels:

Tuesday, October 03, 2006

Apple patches Mac OS X vulnerabilities

Apple has released a security update that fixes 15 different vulnerabilities in Mac OS X.

The update has been classified by security firm Secunia as 'highly critical', its second highest alert level, owing to the danger of remote code execution on unpatched systems.

Among the vulnerabilities is a flaw in the CFNetwork component used by Apple's Safari browser that could allow unauthenticated SSL sites to appear as authenticated.

This could leave a user vulnerable to fraudulent sites that would be presented as secure.

Fixes for Adobe Flash Player which Secunia has listed as 'highly critical' are also included in the update. The vulnerabilities could allow attackers to execute code remotely via a specially crafted .swf file.

Other fixes address vulnerabilities in PICT and jpeg2000 image handling components and several LoginWindow flaws.

The Mac OS X 10.4.8 update is for users with a version of MacOS X 10.4 or Mac OS X 10.4 server already installed. Security Update 2006-006 is for users running Mac OS X 10.3.9 and Mac OS X Server.

The security fix comes one week after Apple released a patch for vulnerabilities in its AirPort wireless networking components.

Labels:

Saturday, August 26, 2006

Because of a risk of fire, Apple Computer is recalling 1.8 million batteries that use Sony's battery cell technology, which also was at the root of Dell's historic recall last week.

The Mac maker's recall, while not as large as Dell's, affects users of its iBook G4 and PowerBook G4 laptop models sold between October 2003 and August 2006, according to the Consumer Products Safety Commission. Users are advised to remove the batteries immediately and store them in a safe place.

Apple said it has gotten nine reports of batteries overheating, including two cases in which users reported minor burns and property damage. However, it says no serious injuries have been reported.

"These lithium ion batteries can overheat, posing a fire hazard to consumers," the Consumer Product Safety Commission said in a press release Thursday. Additional information can be found at Apple Web page for the recall.


Apple's recall involves 1.1 million batteries sold in the United States and an additional 700,000 sold overseas online and through retail stores and resellers. The recall is the second-biggest safety recall ever in the U.S. electronics industry, after Dell.

Labels:

Microsoft has released patches for its forthcoming Windows Vista operating system, which is currently in beta.

The two patches are necessary because Vista is subject to the same security holes addressed in other Microsoft products during the huge patch delivered on 8 August.

The patches fix critical vulnerabilities in Internet Explorer and the Windows kernel as detailed in Microsoft Security Bulletins MS06-042 and MS06-051.

Security patches are not normally issued for beta software, because no one is supposed to be using it in a critical environment. But Microsoft has issued patches for Vista before.

The patch, rated 'critical', covered a similar WMF flaw that hit the company's other operating systems a week earlier.

The vulnerability was in the Graphics Rendering Engine and could allow an attacker to gain control of a target machine.

Labels:

Saturday, August 19, 2006

Phishers target Google Gmail users

IT security experts warned today of a "widespread phishing email campaign" that tries to swindle unwary recipients by pretending to offer a cash prize from Gmail, Google's popular free email service.

The emails claim that the recipient has been randomly selected for a $500 cash prize, and that the money can be paid automatically if they click on the embedded web link. Part of the email reads as follows:

'You won $500! Gmail congratulates you!
CONGRATULATIONS!
YOU WON $500!
Gmail gives members random cash prizes. Today, your account is randomly selected as the one of 12 top winners accounts who will get cash prizes from us. Please click the link below and follow instructions on our web site. Your money will be paid directly to your e-gold, PayPal, StormPay or MoneyBookers account.'

The embedded link takes users to a web page saying that there has been a problem sending the payment. They are then asked to enter their bank details and pay a membership fee of $8.60.

"Of course this email wasn't really sent by the folks at Gmail, and the $500 cash prize doesn't exist. Anyone tempted to try and collect it is in danger of walking straight into a trap set by these fraudsters," said Graham Cluley, senior technology consultant at Sophos.

"People need to learn that there is no such thing as a free lunch, and be much more wary of unsolicited email communications whoever they may appear to come from."

Sophos revealed in a survey earlier this year that 58 per cent of people receive at least one phishing email every day.

Labels: