internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Releases Scanning Tool
Scanning Tool Available for GDI+ Vulnerability
Sean Michael Kerner

As part of Microsoft's update package released this week to patch numerous vulnerabilities, the company included the MS04-028 Enterprise Scanning Tool. The tool is intended to help enterprises identify and apply updates specific to the MS04-028 security bulletin regarding a Buffer Overrun in JPEG Processing (GDI+).

According to a Microsoft spokesperson, the company issued the new tool in response to enterprise customer feedback about difficulties in scanning and patching for MS04-28. It is not intended for use in environments where enterprises already have an update management tool like Microsoft Systems Management Server (SMS) in place.

The MS04-028 Enterprise Scanning Tool allows system admins to scan their networks to identify potentially vulnerable machines. It will then automatically apply the appropriate MS04-028 updates, which were issued Sept. 14, from a LAN (define) share. The following week, proof of concept exploits for the flaw began circulating.

The MSO4-28 bulletin describes a critical flaw of a remote code execution vulnerability when users open a JPEG (define) image file on an unpatched Windows PC. Utilizing a number of widely distributed tools, a hacker may create a JPEG that, when rendered, causes a buffer overrun and could potentially allow the intruder access to the user PC via a Trojan or other such malware (define).

Hackers know that Trojans work when unsuspecting users click or open the delivery mechanism while on unpatched PCs. That's exactly what they hope happens with the latest Trojan making the round this week, this time using the image of British soccer player David Beckham as bait.

Security researchers at Sophos and elsewhere have found thousands of instances of the Trojan bait, which claim to show Beckham in a compromising position.

The message reads, "David Beckham of Real Madrid was caught by photographers with his pants down. Early in the morning he was photographed with a Spanish hooker in a rather compromising position. Photos yet to hit the newspapers have been released here."

"Hackers and virus writers will try all kinds of tricks to entice people into downloading their malicious code," said Graham Cluley, senior technology consultant for Sophos, in a statement. "Now they are trying to suggest that England's football captain David Beckham has been playing away from home. The public's appetite for salacious gossip about the private life of the Beckhams might lead some into an unpleasant computer infection."

According to a Microsoft spokesperson, this particular attack is not exploiting any new Microsoft vulnerability, bur rather is relying on users with unpatched PCs to deploy. If users stick to the basic steps of protecting their PCs, there is less risk from these types of attacks.

"There are some really basic guidelines that customers can follow that will help protect them on the Internet from all sorts of attacks, including the Trojan that entices users with news of Beckham," the Microsoft spokesperson said. "To protect your PC, Microsoft continues to recommend that all customers follow the three prescriptive measures outlined at www.microsoft.com/protect. Windows XP SP2 already incorporates the key steps of Protect Your PC."

News courtesy of internetnews.com

October 14, 2004


Download Windows XP SP2 Now!Download

View All Microsoft Service Packs

Contents:
1. Scanning Tool Available for GDI+ Vulnerability


Additional Articles:

  • Windows XP Service Packs: What's New in XP SP2
  • Windows XP SP2 Inches Closer
  • XP SP2 Launch Price: $300 Million
  • XP SP2: Do's & Don'ts for Web Sites
  • Windows XP SP2 Comes Closer with RC2
  • August It Is for XP SP2
  • Microsoft's XP SP2 Arrives
  • Microsoft XP SP2 Blog Watch
  • XP SP2 Warning List Released
  • XP SP2 Delivery Schedule Adjusted
  • Researcher Finds Flaws in XP SP2
  • MS Releases XP SP2 App Testing Guide
  • XP SP2 Deadline Extended
  • XP SP2 Downloads Surpass 100M Mark
  • Enterprise Foot-Dragging on XP SP2
  • Windows XP SP2 Said at Risk From Heap Overflow
  • Do You SP2?
  • Windows XP Service Pack 3 Pushed Back to 2008
  • Would You Like 'XP' With That PC?
  • Vista, XP Service Pack Changes Revealed
  • Public Test for XP Service Pack 3
  • Windows XP Service Pack 3? Place Your Bets
  • Microsoft: XP Not Out to Pasture Yet
  • Get the Latest on Windows XP SP3
  • Windows XP SP3 Just Around The Corner
  • When Is a Downgrade a Good Thing?
  • No XP Service Pack 3 for You Today
  • On Again, Off Again, XP SP3 Back On
  • XP SP3 Glitch a 'Gotcha' for IE7 & IE8
  • Microsoft Just Can't Kill XP
  • Meet Microsoft's New Embedded OS: Windows XP
  • XP's 'Last Day' Less Final Than Gates'
  • Dell Finds a Way to Continue XP Sales
  • Microsoft to Begin Pushing XP SP3 to Users
  • Business PC Buyers Pick Windows XP Over Vista
  • Windows XP Gets Another Life Extension
  • XP/Vista SP Blockers to Expire as Vista Surges
  • Another Reprieve for Microsoft's XP 'Downgrades'
  • 'Mainstream' Support for XP Ends Today


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs