Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, June 25, 2011

PSA: Browser Plugin Updates

Posted on 10:46 AM by Unknown

As I prepare my notes for one to two GSD posts on recent rogue-security product malware-purges from heavily infected systems, I’m going to offer a brief public service announcement.

In both cases, a review of the logs generated and collected during the incident responses strongly suggests to me that both infections occurred during innocent web-surfing when the users unknowingly landed on maliciously seeded pages that took advantage of exploitable code in their older versions of Java.

While probably not the specific exploit they encountered, these YouTube videos do illustrate how the process can work.

  • Java CVE-2010-4452 - YouTube
  • CVE-2010-4452 : Oracle Java Applet2ClassLoader Remote Code Execution Exploit - YouTube

For more in-depth illustration and analysis of the problem, take a look at these security posts.

  • Not Just Another Analysis of Scareware - Security Braindump
  • Vulnerabilities in a Flash - WhiteHat Security Blog

Patch it like a hobo

Trying to guide Dad though all the hoops on how to check his Windows (Vista) system early for latest versions of these most popular browser plugins has been quite challenging.  Not only do you you have to go confirm the current version you are running (either through the control panel or from the providers’ websites) but then you have to navigate through the download and install process, often trying to avoid an offered “bonus” software product installation in the process.

So, although at work I download such update packages directly from the provider’s source for security reasons, at home and in recommendations to family and friends, I usually just point them to the specific updated package as found on the FileHippo.com Plugins Downloads site.  It’s just easier that way.

  • Adobe Air -- FileHippo mirror site.
  • Flash Player-- FileHippo mirror site. (be sure to get both the IE “ActiveX” and the “Non-IE” versions)
  • Shockwave Player-- FileHippo mirror site.
  • Java Runtime Environment-- FileHippo mirror site. (if you run x64, grab and install both the x32 and x64 versions)

If you do want to go the “official source only” path, then here you go.

Adobe - Flash Player - This page will tell you what version of Flash you are running and what the latest versions are.

Troubleshoot Flash Player installation | Windows - Links to both the update page as well as the direct manual download links for most current level of both versions; Flash Player 10 ActiveX and Flash Player 10 Plugin.

Adobe - Test Adobe Shockwave Player - this page will play and display a Shockwave file which then tells you your currently installed version of Shockwave.  Write it down then…

…go to this page Adobe - Adobe Shockwave Player to see what the latest version actually is.  If this one is newer, download and install (just watch out for the offered “bonus” software install and uncheck the box if you don’t want it.

To confirm you have the freshest Java beans, pop over to this Verify Java Version page and see what fortune you get.  Need an update?  Well then my bedraggled friend, stop in at All Java Downloads to pick from the buffet.  You likely will be focusing on the Windows 32-bit and 64-bit versions.

I haven’t mentioned it, but Adobe Acrobat also is almost ubiquitously found on Windows systems and it also must be keep updated to avoid the worst of the PDF-related exploit issues out there.

Updates galore

This past month saw a banner crop of security patches and updates both to the Windows operating system environment as well as many popular Windows browser plugins.  Hopefully everyone who needs these applied them to their systems.  Adobe in particular has become more of a responsible citizen by changing the updating in their products to now do “auto-check” for updates. Oracle has been including a Java-update check service in their product for some time now.

It’s my personal experience that while these auto-update features do work, sometimes they don’t offer an available update for some time.  And when in the case of Java they are sitting quietly in the system tray as an indicator icon, it is easy to overlook.  Adobe at least throws the notice in your face.

I understand and acknowledge the challenges for many home-users in keeping informed and notified of these updates. Heck, it’s hard enough to get some home users to even care about patching third-party systems.

That said, as anyone who has either been a victim of a browser drive-by malware infection, or the guy or gal who had to spend many, many hours cleaning uncle Bob’s unpatched PC to save their system and Uncle Bob’s sanity again, it’s too serious to not keep an eye out and patch these browser plugins as soon as they get released.

  • Adobe Ships Security Patches, Auto-Update Feature -- Krebs on Security
  • Flash Player Patch Fixes Zero-Day Flaw -- Krebs on Security
  • Patch Tuesday part two – Adobe patches Reader, Flash and more -- Naked Security
  • Adobe releases patches -- ISC Diary post
  • Java Patch Plugs 17 Security Holes -- Krebs on Security
  • Microsoft Patches Fix 34 Security Flaws -- Krebs on Security
  • IE 9.0.1 Available via Windows Update -- IEBlog
  • ISC Diary | Microsoft June 2011 Black Tuesday Overview -- ISC Diary
  • Patch Tuesday – June 2011 – 16 bulletins, 9 critical -- Naked Security
  • Microsoft Security Bulletin Summary for June 2011 - Microsoft TechNet

Patch on Mr. Adams!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in browsers, security, software, viruses | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ▼  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ▼  June (6)
      • Anti-Malware Tools of Note
      • Skirmish 2: A Rouge Security Software battle
      • Skirmish 1: A Rouge Security Software battle
      • PSA: Browser Plugin Updates
      • GSD Blog Template Reboot
      • Finally! Time to Post! New material list
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile