Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, February 18, 2013

ForSec/Sysadmin Super Linkfest

Posted on 3:47 PM by Unknown

Yes indeed. I have been super-busy at home and work of late. Though the material keeps rolling in daily, my ability to get it out has been hampered a bit with “real-life” commitments.

So I’m taking advantage of a lull in the storm to dump my link hopper for your enjoyment and my reference.

Grab some snacks, make sure your wireless mouse is fed up on batteries and cheese, and settle in for some serious linkage dumping.

The Java/Flash Patch Cycle

In a sign of just how long it has been since I posted (and the activity that has transpired since mid-January) I submit the following. Note sarcasm attached.

  • Java 0-Day patched as Java 7 U 11 released - ISC Diary
  • Oracle patches widespread Java zero-day bug in just three (days, that is) - Ars Technica (Java 7.11). Hurray! Patched & Secure!
  • Security experts on Java: Fixing zero-day exploit could take 'two years' - ZDNet. Umm. So I’m not patched after patching?
  • Critical Java vulnerabilities confirmed in latest version - Ars Technica. Snap.
  • Java’s new “very high” security mode can’t protect you from malware - Ars Technica. So the point is, what exactly, Oracle? 
  • Another day, another Java security failure - Ed Bott.
  • Oracle releases emergency patches for Java - The H Security: News and Features - Yea! See it didn’t take Oracle ‘two-years’ to patch Java after all! Hurray!
  • Mozilla pulling plug on auto-running nearly all plugins - The H Security: News and Features.
  • Firefox will block by default nearly all plugins - HelpNet Security. Umm. Mozilla? Do you know something the rest of us don’t on those patched plugins?
  • Zero-Day Vulnerabilities Found in Adobe Flash Player - TrendLabs Security Intelligence Blog.  And not be left outdone in publicity, Adobe Flash steps up with new vulnerabilities. Time to patch.
  • Adobe issues emergency Flash update for attacks on Windows, Mac users - Ars Technica
  • Research & Analysis of Zero-Day & Advanced Targeted Threats: LadyBoyle comes to town with a new exploit - Malware Intelligence Lab from FireEye - Flash exploit in action.
  • Thanks, Adobe. Protection for critical zero-day exploit not on by default - Ars Technica - Now what? For crying-out-loud Adobe, I’ve got to enable some exploit protections manually? How the friggin’ are non-tech users to know and keep up with this? Sheesh.
  • Mitigate the Adobe Reader/Acrobat XI Vulnerability - F-Secure Weblog : News from the Lab
  • Adobe Acrobat and Reader Security Update Planed this Week - ISC Diary.  Really? Is this another one I need to manually activate or will you activate it for me this time?
  • Java Archive Downloads - Java SE 7 - get your Java 7 SE downloads in all their prior versions
  • Java Downloads for All Operating Systems - Java SE 7 - get your latest version here (currently 7.13).
  • Java Runtime Environment 6 Downloads - Java SE 6 - Get your latest version for Java 6 here (currently 6.39).
  • JavaFX Download for JDK6 - You may or may not need this. But if you do need JavaFX you can get the latest here.
  • Where can I get the latest version of Java 6? - Java. Umm. So Oracle seems to be saying they are pulling public download support for future versions of Java 6. Other sites will mirror older versions, but the pickings are about to get thin. Hopefully if you are running Java SE, you can jump to 7 if you haven’t already done so.
Java SE 6 End of Public Updates
After February 2013, Oracle will no longer post updates of Java SE 6 to its public download sites. Existing Java SE 6 downloads already posted as of February 2013 will remain accessible in the Java Archive on Oracle Technology Network. Developers and end-users are encouraged to update to more recent Java SE versions that remain available for public download
  • Adobe Flash Player Distribution - Adobe. Get your latest exe/msi version downloads here.
  • Shockwave Player Distribution Downloads - Adobe. Get your latest exe version downloads here.

So where does that leave us?

Remove Java? I doubt it. - Malware Analysis Blog. I did!

I actually have decided to remove Java SE from our home systems. I do like to run some Java apps but that is pretty rare so I will install, run, de-install Java as needed. Small price for system security.

In a bit of irony, shortly before drafting this blog-post statement, Lavie brought me her iPhone and iPod and told me she sent me a link to a band she follows. As a hard-core fan, she was treated to a free download of some tracks from the artist’s portfolio. She needed these added to her devices. When I followed the link to download the tracks on our system, I was presented with a dialog box to install Java SE. Turns out their download manager app uses Java SE. Nice.  Install, download files, de-install Java again. I did notice it linked to the Java 7.13 bits. That’s something.

Sadly, I can’t get away with doing the same at work. We run a non-current release version of Java 6 “standard” at work. If you are running Java 7 automated auditing reports tattle on you and you either have to justify your use of Java 7 or it will be auto-uninstalled and roll-back to the standard level of Java 6.

Sweet baby Jebus.

For home users who are non-technical (or are and just don’t have the time to follow the web-browser plugin patching game) I recommend popping in once a week to the Qualys BrowserCheck on each of their installed web-browsers. Maybe that way you can catch and patch dated versions fairly easily.

Why the Patching Fuss?

Failure to patch and run current versions of Java/Flash/<insert plugin-here> (not to mention your OS) could lead the following headaches and pubic shame and liability.

  • Facebook engineers compromised by Java zero-day - The H Security: News and Features
  • Facebook computers compromised by zero-day Java exploit - Ars Technica
  • Facebook Hacked, Mobile Dev Watering Holes, and Mac Malware - F-Secure Weblog : News from the Lab
  • Employees targeted with fake DocuSign "confidential message" - Help Net Security
  • Chinese Hackers Infiltrate New York Times Computers - NYTimes.com

And you thought having someone guess your Yahoo password and use it to send spam was a headache.

Not software-based, but Amazon users are exploited also…

Saw these links this past week. Fascinating.

  • Chasing an active Social Engineering Fraud at Amazon Kindle - Scott Hanselman
  • Two-for-one: Amazon.com’s Socially Engineered Replacement Order Scam - HTMList.com, A Web Development Blog by Synapse Studios

For the ForSec Crew

OMG! What an amazing number of posts and material from our ForSec experts! Especially timely after all these latest Java patching dramas we have been enjoying lately.

  • Java, Timelines, and Training - Windows Incident Response Blog
  • BinMode: Parsing Java *.idx files, pt trios - Windows Incident Response Blog
  • Why "BinMode"? BinMode: Parsing Java *.idx files, pt. deux - Windows Incident Response Blog
  • BinMode: Parsing Java *.idx files - Windows Incident Response Blog
  • BinMode - Windows Incident Response Blog
  • Java IDX Sample Files from Java Spearphishing Attack from SANS FOR508 - SANS Computer Forensics and Incident Response blog.
  • Extracting ZeroAccess from NTFS Extended Attributes - Journey Into Incident Response blog
  • Detecting Extended Attributes (ZeroAccess) and other Frankenstein’s Monsters with HMFT - hexacorn blog
  • Beyond good ol’ Run key, Part 3 - hexacorn blog
  • Links for Toolz - Journey Into Incident Response blog
  • Deobfuscating Potentially Malicious URLs - Part 1- Open Security Research blog
  • Attributing Potentially Malicious URLs - Part 2 - Open Security Research blog
  • Evaluating Potentially Malicious URLs - Part 3 - Open Security Research blog
  • Interesting Malware in Email Attempt - URL Scanner Links - If the OSR links above wet your appetite, this GSD post has some additional related resources you might be interested in.
  • Tips on Malware Analysis from Jake Williams - Lenny Zeltser On Information Security blog. Link to three posts regarding malware analysis.
  • There Are Four Lights: The Forensic Scanner - Windows Incident Response Blog
  • What is PALADIN Forensic Software? - Sumuri - the free forensic liveCD is now released at version 4.0.
  • CAINE 4.0 codename "Pulsar" is cooking. It’s not hear yet but the CAINE liveCD distro is in works now as well
  • Apple Hates Forensicators - Forensic 4cast
  • Got a PC problem? Try OSForensics 2.0 - Betanews - Nice review on OSForenics. I find it helpful for sysadmin support duties as well. OSForensics - Download

We pause for a PSA…

  • Yes, that PC cleanup app you saw on TV at 3am is a waste - Ars Technica

Network News of Late

  • CapLoader 1.1 Released - NETRESEC Blog
  • Analyzing 85 GB of PCAP in 2 hours - NETRESEC Blog
  • Extracting Metadata from PcapNG files - NETRESEC Blog
  • Wireshark releases v1.8.5 and 1.6.13 - ISC Diary
  • Wireshark - Download
  • Wireshark - Wireshark 1.8.5 Release Notes
  • Connect OpenVPN - OpenVPN for iOS
  • URL Snooper - Mouser Software at DonationCoder.com
  • WAN Circuit Topologies - Packet Life
  • Security alert for D-Link routers - The H Security: News and Features
  • More Wi-Fi devices with security holes - The H Security: News and Features
  • Microsoft Message Analyzer Beta 2 is released (build 5950)! - MessageAnalyzer blog

Tools, Utilities and Treats for the SysAdmins

  • Undelete Navigator Is A File Recovery Tool With Better Browsing - AddictiveTIps blog
  • Kickass Undelete - a free, open source file recovery tool for Windows - Version 1.3 beta
  • FreeRecover - SourceForge.net
  • Recuva v1.45 - Piriform
  • Comodo Rescue Disk for Windows - Download Rescue Disk Software
  • COMODO Rescue Disk (CRD) v2.0.261647.1 is formally released - Comodo
  • COMODO Rescue Disk 2.0 combats even deeply embedded malware - BetaNews
  • LSoft Technologies - Freeware products
  • RKill terminates malware processes - BetaNews
  • RKill Download - bleepingcomputer
  • Remove malware from an already-infected PC with Malwarebytes Chameleon - Softwarecrew
  • Chameleon - Malwarebytes
  • Updates: Pendmoves v1.2, Process Explorer v15.3, Sigcheck v1.91, Zoomit v4.42 - Sysinternals
  • Updates: Autoruns v11.41, Handle v3.51, Movefile v1.01, Procdump v5.13, Sigcheck v1.9 - Sysinternals
  • Update: Autoruns v11.42 - Sysinternals
  • DISM GUI 3.5 Released - Mike's Blog
  • JavaRa 2.1 - SingularLabs - Tool to assist with removal of Java from Windows systems.
  • MemTest86 now maintained by PassMark Software - BetaNews
  • Outlook 2013 deprecated features and components - Outlook Blog
  • WSUS Offline Update - Update Microsoft Windows and Office without an Internet connection

Bits and Pieces

  • Information about ComboFix being infected and what you should do - Bleeping Computer. From time to time I have recommended or posted links to ComboFix tool to remove certain malware infections. It appears a particular release version of ComboFix was compromised. the latest version is clean but I thought it would be good to note this thread for the curious or concerned.
  • Universal Plug and Pray - F-Secure Weblog : News from the Lab
  • Exposed UPNP Devices - ISC Diary
  • ScanNow for Universal Plug and Play (UPnP) - Rapid7. Download and install this tool to check your network for potential UPnP issues. Only be aware it does require Java SE installation as a pre-requisite…so that may bring it’s own issues to the table. If in doubt, install Java SE and this tool. Run both to audit/assess. Make your notes….then uninstall.
  • Universal Plug and Play Check by Rapid7 - online version of the tool to check your router for issues. Limited features.
  • Comodo - free security products for home users.
  • Search & Browse The History Of All Web Browsers On A PC From One Place - AddictiveTips
  • My Computer Tweaker: Massive Collection Of Windows Registry Tweaks  - AddictiveTips
  • Control Panel - My Computer Tweake - by ~KeybrdCowboy on deviantART
  • New: UNetbootin Portable 583 (create bootable Linux USB drives) Released - PortableApps.com
  • New: Smart Deblur Portable 1.27 (sharpen out of focus and blurry images) Released - PortableApps.com
  • Spybot - Search & Destroy: The Simple, Yet Effective Route For Cleaning Your PC Of Malware - MakeUseOf blog review.
  • Spybot - Search & Destroy Portable - PortableApps.com

Enjoy.

-- Claus Valca

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in anti-virus software, boot-cd's, forensics, Link Fest, malware tools, Microsoft, networking, NFAT, security, software, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ▼  February (7)
      • Threats, Updates, and iOS App struggles
      • ForSec/Sysadmin Super Linkfest
      • In Setting up a new Windows 8 System…
      • …and an alternative solution is confirmed
      • …in which a problem with a new Dell system is addr...
      • Too Many Bits, Bytes and Tech?
      • …you’re getting warmer!
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile