<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; windows security</title>
	<atom:link href="http://www.ghacks.net/tag/windows-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 10 Nov 2009 01:33:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Assess Windows Security State With Microsoft Baseline Security Analyzer</title>
		<link>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/</link>
		<comments>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 17:48:16 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Microsoft Baseline Security Analyzer]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=17830</guid>
		<description><![CDATA[Microsoft updated their Microsoft Baselines Security Analyzer software recently to make the software compatible with Windows 7 and Windows Server 2008 R2. The concept of the program remains unchanged: To offer system administrators and end users a comfortable way of assessing the security state of a Windows computer system. Microsoft Baseline Security Analyzer can assess [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/09/windows_software.jpg" alt="windows software" title="windows software" width="128" height="128" class="alignleft size-full wp-image-16120" />Microsoft updated their Microsoft Baselines Security Analyzer software recently to make the software compatible with <a href="http://windows7news.com/">Windows 7</a> and Windows Server 2008 R2. The concept of the program remains unchanged: To offer system administrators and end users a comfortable way of assessing the security state of a Windows computer system. Microsoft Baseline Security Analyzer can assess the security state for local and remote computer systems.</p>
<p>System administrators can select a known computer name or enter an IP address and port during configuration of the analyzer. It is furthermore possible to select the multi-scan option which allows the admin to specify an IP range for the scan. Various options are provided in the configuration menu that basically configure the depth of the scan. It will by default check for Windows administrative vulnerabilities, weak passwords, IIS administrative vulnerabilities, SQL administrative vulnerability and security updated with addition options selectable for advanced usage.</p>
<p><span id="more-17830"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/10/microsoft_baseline_security_analyzer1-500x375.jpg" alt="microsoft baseline security analyzer" title="microsoft baseline security analyzer" width="500" height="375" class="alignnone size-medium wp-image-17842" /></p>
<p>The security assessment report will then display if security risks have been found during the scan. These risks will be displayed in an overview at the top of the report which gives an option to quickly look over the findings of the software program. Each section outlines what the program scanned, gives details about the results and offers solutions to correct the issues that were found.</p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/10/security_scan-500x257.jpg" alt="security scan" title="security scan" width="500" height="257" class="alignnone size-medium wp-image-17843" /></p>
<p>To give one basic example. If the program finds that security updates are missing it will display those missing updates with options to download them right away. Microsoft Baseline Security Analyzer is a free download for all Microsoft operating systems since Windows 2000 including Windows XP, Windows Vista and Windows 7. The program is <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b1e76bbe-71df-41e8-8b52-c871d012ba78&#038;displaylang=en">available</a> for 32-bit and 64-bit editions.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-baseline-security-analyzer/" title="Microsoft Baseline Security Analyzer" rel="tag">Microsoft Baseline Security Analyzer</a>, <a href="http://www.ghacks.net/tag/security-update/" title="security update" rel="tag">security update</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2007/12/21/security-and-privacy-complete-2/" title="Security and Privacy Complete (December 21, 2007)">Security and Privacy Complete</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/" title="Microsoft Security Essentials Leaks (June 17, 2009)">Microsoft Security Essentials Leaks</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/" title="Microsoft Security Essentials Final Announced (September 22, 2009)">Microsoft Security Essentials Final Announced</a> (10)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Essentials Final Announced</title>
		<link>http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/</link>
		<comments>http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 22:55:55 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[antivirus software]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft security essentials]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=16563</guid>
		<description><![CDATA[Microsoft Security Essentials is a free security software that is being developed by Microsoft. The security software was released as a limited beta to users in the United States, Brazil and China. It was (actually still is) possible to download the beta from download portals like Betanews without experiencing limitations. That&#8217;s what many users did [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft Security Essentials is a free security software that is being developed by Microsoft. The security software was released as a limited beta to users in the United States, Brazil and China. It was (actually still is) <a href="http://www.ghacks.net/2009/06/29/download-microsoft-security-essentials/">possible</a> to download the beta from download portals like Betanews without experiencing limitations. That&#8217;s what many users did and most seemed to have been pleased with the performance of the security software. </p>
<p>Several updates of Microsoft Security Essentials were released since then and it was rumored that Microsoft aimed for a October 22 release to give <a href="http://windows7news.com/">Windows 7</a> users a chance to use the final version of the software program. </p>
<p><span id="more-16563"></span>The announcement that Microsoft Security Essentials would be released in the coming weeks was spread to all beta participants who received an email that informed them of an upgrade and the projected release in the coming weeks.</p>
<blockquote><p>The final version of Microsoft Security Essentials will be released to the public in the coming weeks. If you are running the older version of the beta (1.0.1407.0), we encourage you to upgrade to a newer version of the beta (1.0.1500.0).</p></blockquote>
<p>The announcement does not explicitly mention the Windows 7 release date but it seems pretty obvious that Microsoft Security Essentials final will be released around the time of the Windows 7 release. Users who want to test Microsoft Security Essentials right now can do so by following the links posted above. The final version will be <a href="http://www.microsoft.com/security_essentials/default.aspx">published</a> at Microsoft&#8217;s Security Essentials website.</p>

	Tags: <a href="http://www.ghacks.net/tag/antivirus/" title="antivirus" rel="tag">antivirus</a>, <a href="http://www.ghacks.net/tag/antivirus-software/" title="antivirus software" rel="tag">antivirus software</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-security-essentials/" title="microsoft security essentials" rel="tag">microsoft security essentials</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/" title="Microsoft Security Essentials Leaks (June 17, 2009)">Microsoft Security Essentials Leaks</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/06/23/microsoft-security-essentials-beta-now-available/" title="Microsoft Security Essentials Beta Now Available (June 23, 2009)">Microsoft Security Essentials Beta Now Available</a> (11)</li>
	<li><a href="http://www.ghacks.net/2009/06/29/download-microsoft-security-essentials/" title="Download Microsoft Security Essentials (June 29, 2009)">Download Microsoft Security Essentials</a> (10)</li>
	<li><a href="http://www.ghacks.net/2009/06/27/antivirus-software-microsoft-security-essentials-tested/" title="Antivirus Software Microsoft Security Essentials Tested (June 27, 2009)">Antivirus Software Microsoft Security Essentials Tested</a> (18)</li>
	<li><a href="http://www.ghacks.net/2009/03/25/norton-security-scan/" title="Norton Security Scan (March 25, 2009)">Norton Security Scan</a> (17)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>New Security Vulnerability Affects Windows Operating Systems</title>
		<link>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/</link>
		<comments>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 20:18:15 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=16177</guid>
		<description><![CDATA[Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are Windows Vista, Windows Server 2008 and the <a href="http://windows7news.com/">Windows 7</a> Release Candidate.</p>
<p>Operating systems that are not affected include Windows XP, Windows 7 final and Windows Server 2003. No patch is currently available to fix the vulnerability. Microsoft has published workarounds to protect the operating system from possible attacks. </p>
<p><span id="more-16177"></span></p>
<blockquote><p>Disable SMB v2</p>
<p>To modify the registry key, perform the following steps:</p>
<p>Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the &#8220;Changing Keys And Values&#8221; Help topic in Registry Editor (Regedit.exe) or view the &#8220;Add and Delete Information in the Registry&#8221; and &#8220;Edit Registry Data&#8221; Help topics in Regedt32.exe.</p>
<p>1. Click Start, click Run, type Regedit in the Open box, and then click OK.<br />
2. Locate and then click the following registry subkey:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services<br />
3. Click LanmanServer.<br />
4. Click Parameters.<br />
5. Right-click to add a new DWORD (32 bit) Value.<br />
6. Enter smb2 in the Name data field, and change the Value data field to 0.<br />
7. Exit.<br />
8. Restart the &#8220;Server&#8221; service by performing one of the following:<br />
- Open up the computer management MMC, navigate to Services and Applications, click Services, right-click the Server service name and click Restart. Answer Yes in the pop-up menu.<br />
- From a command prompt and with administrator privileges, type net stop server and then net start server.</p>
<p>Impact of workaround. Host will not be able to communicate using SMB2.</p></blockquote>
<blockquote><p>Block TCP ports 139 and 445 at the firewall</p>
<p>These ports are used to initiate a connection with the affected component. Blocking TCP ports 139 and 445 at the firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability. Microsoft recommends that you block all unsolicited inbound communication from the Internet to help prevent attacks that may use other ports. For more information about ports, see TCP and UDP Port Assignments.</p>
<p>Impact of Workaround: Several Windows services use the affected ports. Blocking connectivity to the ports may cause various applications or services to not function. Some of the applications or services that could be impacted are listed below:</p>
<p>• Applications that use SMB (CIFS)<br />
• Applications that use mailslots or named pipes (RPC over SMB)<br />
• Server (File and Print Sharing)<br />
• Group Policy<br />
• Net Logon<br />
• Distributed File System (DFS)<br />
• Terminal Server Licensing<br />
• Print Spooler<br />
• Computer Browser<br />
• Remote Procedure Call Locator<br />
• Fax Service<br />
• Indexing Service<br />
• Performance Logs and Alerts<br />
• Systems Management Server<br />
• License Logging Service</p></blockquote>
<p>Users that are running one of the operating systems that are affected by the vulnerability are encouraged to use one of the workarounds to protect their computer systems. More information are available at the Microsoft Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">page</a>.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/operating-system/" title="operating system" rel="tag">operating system</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-vulnerability/" title="windows vulnerability" rel="tag">windows vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/12/04/windows-vista-editions-do-you-know-the-differences/" title="Windows Vista Editions &#8211; Do you know the differences ? (December 4, 2006)">Windows Vista Editions &#8211; Do you know the differences ?</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/06/03/windows-7-to-launch-october-22/" title="Windows 7 To Launch October 22 (June 3, 2009)">Windows 7 To Launch October 22</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/22/windows-7-released/" title="Windows 7 Released (October 22, 2009)">Windows 7 Released</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/06/25/windows-7-price-upgrades-and-preorders/" title="Windows 7 Price, Upgrades And Preorders (June 25, 2009)">Windows 7 Price, Upgrades And Preorders</a> (15)</li>
	<li><a href="http://www.ghacks.net/2008/05/12/windows-7-features-video/" title="Windows 7 Features Video (May 12, 2008)">Windows 7 Features Video</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Updates August 2009</title>
		<link>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/</link>
		<comments>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 10:09:08 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security bulletin]]></category>
		<category><![CDATA[microsoft security updates]]></category>
		<category><![CDATA[microsoft updates]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows updates]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=15276</guid>
		<description><![CDATA[Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A summary of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A <a href="http://www.microsoft.com/technet/security/Bulletin/ms09-aug.mspx">summary</a> of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. Users who operate Microsoft operating systems or Microsoft products should install the security patches as soon as possible to protect their system from possible exploits.</p>
<p>Affected operating systems include Windows Vista, Windows XP, Windows Server 2003 and 2008, Windows 2000 but not <a href="http://windows7news.com/">Windows 7</a>. Downloads are available from the usual locations including automatic updates, Windows Update, Microsoft Update or by following the links in the security bulletins below.</p>
<p><span id="more-15276"></span>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=128110">MS09-043</a> Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)
<p>This security update resolves several privately reported vulnerabilities in Microsoft Office Web Components that could allow remote code execution if a user viewed a specially crafted Web page. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=157861">MS09-044</a> Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)
<p>This security update resolves two privately reported vulnerabilities in Microsoft Remote Desktop Connection. The vulnerabilities could allow remote code execution if an attacker successfully convinced a user of Terminal Services to connect to a malicious RDP server or if a user visits a specially crafted Web site that exploits this vulnerability. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155974">MS09-039</a> Vulnerabilities in WINS Could Allow Remote Code Execution (969883)
<p>This security update resolves two privately reported vulnerabilities in the Windows Internet Name Service (WINS). Either vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system version. Only customers who manually install this component are affected by this issue.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155975">MS09-038</a> &#8211; Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)
<p>This security update resolves two privately reported vulnerabilities in Windows Media file processing. Either vulnerability could allow remote code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=158695">MS09-037</a> Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)
<p>This security update resolves several privately reported vulnerabilities in Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155977">MS09-041</a> Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)
<p>This security update resolves a privately reported vulnerability in the Windows Workstation Service. The vulnerability could allow elevation of privilege if an attacker created a specially crafted RPC message and sent the message to an affected system. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to a vulnerable system in order to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155979">MS09-040</a> Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)
<p>This security update resolves a privately reported vulnerability in the Windows Message Queuing Service (MSMQ). The vulnerability could allow elevation of privilege if a user received a specially crafted request to an affected MSMQ service. By default, the Message Queuing component is not installed on any affected operating system edition and can only be enabled by a user with administrative privileges. Only customers who manually install the Message Queuing component are likely to be vulnerable to this issue.</p>
</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=157296">MS09-036</a> Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)
<p>This security update addresses a privately reported Denial of Service vulnerability in the Microsoft .NET Framework component of Microsoft Windows. This vulnerability can be exploited only when Internet Information Services (IIS) 7.0 is installed and ASP.NET is configured to use integrated mode on affected versions of Microsoft Windows. An attacker could create specially crafted anonymous HTTP requests that could cause the affected Web server to become non-responsive until the associated application pool is restarted. Customers who are running IIS 7.0 application pools in classic mode are not affected by this vulnerability.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=157140">MS09-042</a> Vulnerability in Telnet Could Allow Remote Code Execution (960859)
<p>This security update resolves a publicly disclosed vulnerability in the Microsoft Telnet service. The vulnerability could allow an attacker to obtain credentials and then use them to log back into affected systems. The attacker would then acquire user rights on a system identical to the user rights of the logged-on user. This scenario could ultimately result in remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with </li>
</ul>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security-bulletin/" title="microsoft security bulletin" rel="tag">microsoft security bulletin</a>, <a href="http://www.ghacks.net/tag/microsoft-security-updates/" title="microsoft security updates" rel="tag">microsoft security updates</a>, <a href="http://www.ghacks.net/tag/microsoft-updates/" title="microsoft updates" rel="tag">microsoft updates</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-updates/" title="windows updates" rel="tag">windows updates</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/12/stop-restart-now-restart-later-dialog-after-windows-updates/" title="Stop Restart Now Restart Later Dialog After Windows Updates (August 12, 2009)">Stop Restart Now Restart Later Dialog After Windows Updates</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/" title="Microsoft Security Updates October 2009 Online (October 13, 2009)">Microsoft Security Updates October 2009 Online</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/" title="Microsoft Patch Day March 2009 (March 10, 2009)">Microsoft Patch Day March 2009</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Essentials Leaks</title>
		<link>http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/</link>
		<comments>http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 17:12:23 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[microsoft security essentials]]></category>
		<category><![CDATA[morro]]></category>
		<category><![CDATA[windows antivirus]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=13643</guid>
		<description><![CDATA[Microsoft&#8217;s own product testing guidelines seem at the same time the major problem why so many Microsoft products leak to the Internet. We have seen numerous Windows 7 builds hit the web only days after they have been build by Microsoft. The latest product to leak was codenamed Morro and renamed Microsoft Security Essentials in [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />Microsoft&#8217;s own product testing guidelines seem at the same time the major problem why so many Microsoft products leak to the Internet. We have seen numerous <a href="http://windows7news.com/">Windows 7</a> builds hit the web only days after they have been build by Microsoft. The latest product to leak was codenamed Morro and renamed Microsoft Security Essentials in the last days. Microsoft Security Essentials is a free antivirus program and not a security suite. Microsoft is offering other products like the Windows Firewall, <a href="http://www.ghacks.net/2009/05/29/windows-defender/">Windows Defender</a> or <a href="http://www.ghacks.net/2009/04/26/the-10-best-windows-backup-software-programs/">Windows backup</a> for that.</p>
<p>The security software requires a genuine Windows operating system which is checked during installation. The leak is available for 32-bit and 64-bit editions of Windows XP, Windows Vista and Windows 7 and can be downloaded from various P2P networks already.</p>
<p><span id="more-13643"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/06/microsoft_security_essentials7-500x386.jpg" alt="microsoft security essentials" title="microsoft security essentials" width="500" height="386" class="alignnone size-medium wp-image-13644" /></p>
<p>Microsoft Security Essentials comes with a basic interface that can be used to scan the computer system for malicious software. Options are available to run a scheduled scan and exclude files, filetypes and processes from the scan. It is yet unclear as to how effective the security software is. It will probably take some time until the first comparisons are published.</p>
<p>Microsoft Security Essentials is loading two processes into computer memory after execution. The first is called msseces.exe and uses roughly 8 Megabytes of computer memory, the second on the other hand &#8211; called MsMpEng.exe &#8211; uses 40 Megabytes by default which can rise to 60 when it becomes active.</p>

	Tags: <a href="http://www.ghacks.net/tag/antivirus/" title="antivirus" rel="tag">antivirus</a>, <a href="http://www.ghacks.net/tag/microsoft-security-essentials/" title="microsoft security essentials" rel="tag">microsoft security essentials</a>, <a href="http://www.ghacks.net/tag/morro/" title="morro" rel="tag">morro</a>, <a href="http://www.ghacks.net/tag/windows-antivirus/" title="windows antivirus" rel="tag">windows antivirus</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/27/antivirus-software-microsoft-security-essentials-tested/" title="Antivirus Software Microsoft Security Essentials Tested (June 27, 2009)">Antivirus Software Microsoft Security Essentials Tested</a> (18)</li>
	<li><a href="http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/" title="Microsoft Security Essentials Final Announced (September 22, 2009)">Microsoft Security Essentials Final Announced</a> (10)</li>
	<li><a href="http://www.ghacks.net/2009/06/23/microsoft-security-essentials-beta-now-available/" title="Microsoft Security Essentials Beta Now Available (June 23, 2009)">Microsoft Security Essentials Beta Now Available</a> (11)</li>
	<li><a href="http://www.ghacks.net/2009/06/29/download-microsoft-security-essentials/" title="Download Microsoft Security Essentials (June 29, 2009)">Download Microsoft Security Essentials</a> (10)</li>
	<li><a href="http://www.ghacks.net/2009/10/03/how-to-download-microsoft-security-essentials/" title="How To Download Microsoft Security Essentials (October 3, 2009)">How To Download Microsoft Security Essentials</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Patches for June 2009</title>
		<link>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</link>
		<comments>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 22:45:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[office patches]]></category>
		<category><![CDATA[office update]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</guid>
		<description><![CDATA[Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office.
The easiest way to download and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> and Microsoft Office.</p>
<p>The easiest way to download and install the patches is by pointing the Internet Explorer web browser to <a href="http://update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&#038;&#038;thankspage=5">Microsoft Update</a> which will automatically detect and install the available patches for the computer system. Other possibilities include downloading the security patches from <a href="http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&#038;freetext=security%20update">Microsoft Download Center</a> from where they are available as well.</p>
<p><span id="more-13419"></span>Six vulnerabilities have been rated as critical, three as important and one as moderate. Critical security vulnerabilities can usually be exploited for remote code execution meaning it is essential to fix these vulnerabilities quickly. You can follow the links below for additional information about each vulnerability.</p>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=151361">MS09-018</a> &#8211; Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150860">MS09-019</a> &#8211; Cumulative Security Update for Internet Explorer (969897)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=150568">MS09-020</a> &#8211; Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=147294">MS09-021</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=141786">MS09-022</a> &#8211; Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=143550">MS09-023</a> &#8211; Vulnerability in Windows Search Could Allow Information Disclosure (963093)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=128104">MS09-024</a> &#8211; Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150248">MS09-025</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150174">MS09-026</a> &#8211; Vulnerability in RPC Could Allow Elevation of Privilege (970238)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=147416">MS09-027</a> &#8211; Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)</li>
</ul>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/office-patches/" title="office patches" rel="tag">office patches</a>, <a href="http://www.ghacks.net/tag/office-update/" title="office update" rel="tag">office update</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/" title="Microsoft updates two critical security patches (April 24, 2008)">Microsoft updates two critical security patches</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/" title="Microsoft Security Patches September 2009 (September 9, 2009)">Microsoft Security Patches September 2009</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Updates April 2009</title>
		<link>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/</link>
		<comments>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 11:25:15 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[microsoft update]]></category>
		<category><![CDATA[microsoft-office]]></category>
		<category><![CDATA[microsoft-windows]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[office updates]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/</guid>
		<description><![CDATA[Microsoft releases security bulletins once a month that outline new security updates and patches for Microsoft products. The security updates for April 2009 list a total of eight vulnerabilities for various Microsoft applications including Microsoft Windows and Microsoft Office. Six of the eight patches affect various Microsoft operating systems. Windows XP and Windows Server 2003 [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft releases security bulletins once a month that outline new security updates and patches for Microsoft products. The security updates for April 2009 list a total of eight vulnerabilities for various Microsoft applications including Microsoft Windows and Microsoft Office. Six of the eight patches affect various Microsoft operating systems. Windows XP and Windows Server 2003 face three critical, two important and one moderate security vulnerability while Windows Vista and Windows Server 2008 bring it to two critical, one important and one moderate vulnerability. Below is a list of links that point to all eight Microsoft Security Bulletins. These bulletins contain extensive information about the vulnerabilities including the systems affected.</p>
<p><span id="more-12027"></span>
<ul>
<li>Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-009.mspx">968557</a>)</li>
<li>Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-010.mspx">960477</a>)</li>
<li>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/Bulletin/ms09-011.mspx">961373</a>)</li>
<li>Vulnerabilities in Windows Could Allow Elevation of Privilege (<a href="http://www.microsoft.com/technet/security/Bulletin/ms09-012.mspx">959454</a>)</li>
<li>Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-013.mspx">960803</a>)</li>
<li>Cumulative Security Update for <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> (<a href="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx">963027</a>)</li>
<li>Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (<a href="http://www.microsoft.com/technet/security/Bulletin/MS09-015.mspx">959426</a>)</li>
<li>Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-016.mspx">961759</a>)</li>
</ul>
<p>The easiest way to update is by visiting Windows Update or Microsoft Update. Please read our <a href="http://www.ghacks.net/2009/04/13/windows-update-fix/">Windows Update Fix</a> article if Windows Update is not working properly on your computer system. Alternatives are so called offline updates like <a href="http://www.ghacks.net/2008/01/21/update-windows-with-offline-update/">Offline Update</a>, <a href="http://www.ghacks.net/2007/08/20/autopatcher-august-2007-released/">Autopatcher</a> or <a href="http://www.ghacks.net/2007/02/11/update-windows-without-microsoft/">Update Windows Without Microsoft</a>.</p>
<p>It is recommended to update the computer system as soon as possible to close the vulnerabilities.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-update/" title="microsoft update" rel="tag">microsoft update</a>, <a href="http://www.ghacks.net/tag/microsoft-office/" title="microsoft-office" rel="tag">microsoft-office</a>, <a href="http://www.ghacks.net/tag/microsoft-windows/" title="microsoft-windows" rel="tag">microsoft-windows</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/office-updates/" title="office updates" rel="tag">office updates</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/security-updates/" title="security updates" rel="tag">security updates</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/" title="Windows Security Updates September 2008 (September 10, 2008)">Windows Security Updates September 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/" title="Microsoft August 2008 Security Updates (August 13, 2008)">Microsoft August 2008 Security Updates</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/" title="January 2009 Microsoft Security Bulletin (January 14, 2009)">January 2009 Microsoft Security Bulletin</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/05/windows-vista-service-pack-2-rc-download/" title="Windows Vista Service Pack 2 RC Download (March 5, 2009)">Windows Vista Service Pack 2 RC Download</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Conficker Worm Detection And Removal</title>
		<link>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/</link>
		<comments>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:17:48 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker c]]></category>
		<category><![CDATA[conficker removal]]></category>
		<category><![CDATA[conficker worm]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worm cleaner]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/</guid>
		<description><![CDATA[By now you might have heard about the latest worm that is plaguing Internet users world wide. It goes by the name of Conficker (or Downadup)and comes in the variants A,B and C with c being the most evolved variant. To put it simple: Conficker uses a Windows vulnerability that was discovered in September 2008 [...]]]></description>
			<content:encoded><![CDATA[<p>By now you might have heard about the latest worm that is plaguing Internet users world wide. It goes by the name of Conficker (or Downadup)and comes in the variants A,B and C with c being the most evolved variant. To put it simple: Conficker uses a Windows vulnerability that was discovered in September 2008 and a patch was released by Microsoft that fixed it. The first worm that used the vulnerability was discovered in November 2008. </p>
<p>Conficker C will initiate a number of processes on infected host systems including opening a random port which is being used in the distribution process of the worm. The worm will then patch the security hole on the computer system that allowed it to attack the system in first place. This prevents other viruses from exploiting the vulnerability while keeping a backdoor open for newer variants of the Conficker worm. The worm will block certain strings from being accessed on the Internet. Domain names making use of those strings cannot be accessed unless the IP is used to do so. Among the strings are various security companies like microsoft, panda or symantec but also generic strings like defender, conficker or anti-. This is to prevent users from accessing websites that contain information and removal instructions about the worm.</p>
<p>While this is surely a nuisance for the user it does mean that the worm itself is not harming the user system in any way other than the methods described above. The real danger comes from the updating mechanism of Conficker C. The worm will try to retrieve new instructions on April 1, 2009. A very sophisticated updating mechanism has been implemented by the author. The worm will generate a list of 50K domain names and append a list of 116 top level domains to them. It will then select 500 randomly from the list and try to connect to them. If new instructions are found on one of the urls it will download them and execute them on the computer system. This process will be repeated every 24 hours.</p>
<p><span id="more-11564"></span>The easiest way of detection is by accessing a site like microsoft.com or symantec.com and comparing the results with accessing the site using the IP addresses (207.46.197.32 and 206.204.52.31). While this usually gives a good indication it is better to check the computer system with tools that have been specifically designed to detect and remove the Conficker variants.</p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/03/conficker_removal-500x167.jpg" alt="conficker removal" title="conficker removal" width="500" height="167" class="alignnone size-medium wp-image-11563" /></p>
<p>A few tools that can be used to detect and remove Conficker variants are <a href="http://download.eset.com/special/EConfickerRemover.exe">ESET Conficker Removal Tool</a>, <a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">Downadup from F-Secure</a> or KidoKiller by Kaspersky.</p>
<p>Excellent information about Conficker detection and removal instructions are available at <a href="http://isc.sans.org/diary.html?storyid=5860">Sans.org</a>.</p>

	Tags: <a href="http://www.ghacks.net/tag/conficker/" title="conficker" rel="tag">conficker</a>, <a href="http://www.ghacks.net/tag/conficker-c/" title="conficker c" rel="tag">conficker c</a>, <a href="http://www.ghacks.net/tag/conficker-removal/" title="conficker removal" rel="tag">conficker removal</a>, <a href="http://www.ghacks.net/tag/conficker-worm/" title="conficker worm" rel="tag">conficker worm</a>, <a href="http://www.ghacks.net/tag/downadup/" title="downadup" rel="tag">downadup</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a>, <a href="http://www.ghacks.net/tag/worm/" title="worm" rel="tag">worm</a>, <a href="http://www.ghacks.net/tag/worm-cleaner/" title="worm cleaner" rel="tag">worm cleaner</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/" title="Test Possible Conficker Infection In Your Web Browser (April 6, 2009)">Test Possible Conficker Infection In Your Web Browser</a> (5)</li>
	<li><a href="http://www.ghacks.net/2007/12/21/security-and-privacy-complete-2/" title="Security and Privacy Complete (December 21, 2007)">Security and Privacy Complete</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/" title="Microsoft Security Essentials Leaks (June 17, 2009)">Microsoft Security Essentials Leaks</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Windows Process Blocker SPKiller</title>
		<link>http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/</link>
		<comments>http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 17:21:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[block files]]></category>
		<category><![CDATA[block processes]]></category>
		<category><![CDATA[block services]]></category>
		<category><![CDATA[process blocker]]></category>
		<category><![CDATA[spkiller]]></category>
		<category><![CDATA[windows process]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/</guid>
		<description><![CDATA[We reviewed a Windows process blocker just a few days ago which could be used to automatically kill processes after they are executed on the computer system. The main problem of the application were the notification popups that appeared in the Windows System Tray whenever a process or application got blocked. A hard to tame [...]]]></description>
			<content:encoded><![CDATA[<p>We reviewed a <a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/">Windows process blocker</a> just a few days ago which could be used to automatically kill processes after they are executed on the computer system. The main problem of the application were the notification popups that appeared in the Windows System Tray whenever a process or application got blocked. A hard to tame application like <a href="http://www.ghacks.net/2008/12/28/googleupdateexe/">googleupdate.exe</a> could cause a notification every other second or so which could be really annoying as there was no obvious way to disable the notifications in the review copy.</p>
<p>SPKiller is a similar application that can block processes and services in the Windows operating system. The installation itself requires more work than the usual double-click on a setup file. The installation will simply place the files of the program in a directory on the computer&#8217;s hard drive. The user has to click on InstallService.bat to install the Windows Service. After that the Service needs to be started in the Windows Services Overview.</p>
<p>The Windows Process and Services blocker is configured with a simply XML file that is located in the program&#8217;s installation directory. The configuration is not more complicated than editing a text document. It is made up of three sections that are of importance to the user. The first is called CycleTime and defines the interval in milliseconds that the running services and processes are checked. ServiceNames contains a list of Windows Services that should be blocked if running while ProcessNames does the same for Windows processes.</p>
<p><span id="more-11394"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/03/windows_process_blocker1-500x276.jpg" alt="windows process blocker" title="windows process blocker" width="500" height="276" class="alignnone size-medium wp-image-11393" /></p>
<p>The configuration file contains a few example services and processes mainly from McAfee but also Radia in the ServiceNames configuration and annoying processes like GoogleToolbarNotifier or AppleMobileDeviceService in the ProcessNames listing. </p>
<p><a href="http://www.zandozan.com/blog/?p=4">SPKiller</a> works well as a process blocker in Windows especially since it blocks both processes and services on the computer system.</p>

	Tags: <a href="http://www.ghacks.net/tag/block-files/" title="block files" rel="tag">block files</a>, <a href="http://www.ghacks.net/tag/block-processes/" title="block processes" rel="tag">block processes</a>, <a href="http://www.ghacks.net/tag/block-services/" title="block services" rel="tag">block services</a>, <a href="http://www.ghacks.net/tag/process-blocker/" title="process blocker" rel="tag">process blocker</a>, <a href="http://www.ghacks.net/tag/spkiller/" title="spkiller" rel="tag">spkiller</a>, <a href="http://www.ghacks.net/tag/windows-process/" title="windows process" rel="tag">windows process</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2007/08/26/process-lasso-a-process-manager/" title="Process Lasso a Process Manager (August 26, 2007)">Process Lasso a Process Manager</a> (3)</li>
	<li><a href="http://www.ghacks.net/2007/12/21/security-and-privacy-complete-2/" title="Security and Privacy Complete (December 21, 2007)">Security and Privacy Complete</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/" title="Microsoft Security Essentials Leaks (June 17, 2009)">Microsoft Security Essentials Leaks</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/09/22/microsoft-security-essentials-final-announced/" title="Microsoft Security Essentials Final Announced (September 22, 2009)">Microsoft Security Essentials Final Announced</a> (10)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows Process Blocker</title>
		<link>http://www.ghacks.net/2009/03/18/windows-process-blocker/</link>
		<comments>http://www.ghacks.net/2009/03/18/windows-process-blocker/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 08:16:49 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[block processes]]></category>
		<category><![CDATA[monitor processes]]></category>
		<category><![CDATA[network administration]]></category>
		<category><![CDATA[process blocker]]></category>
		<category><![CDATA[process lasso]]></category>
		<category><![CDATA[process manager]]></category>
		<category><![CDATA[windows network]]></category>
		<category><![CDATA[windows process]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows services]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=11287</guid>
		<description><![CDATA[The Windows application Process Blocker has been designed to provide system administrators and computer technicians with a security tool that can be easily distributed on a computer network to prevent unauthorized program starts. The program is currently in beta stage and has not completed the goal yet but it comes with a functional feature set [...]]]></description>
			<content:encoded><![CDATA[<p>The Windows application Process Blocker has been designed to provide system administrators and computer technicians with a security tool that can be easily distributed on a computer network to prevent unauthorized program starts. The program is currently in beta stage and has not completed the goal yet but it comes with a functional feature set that makes it interesting for many users.</p>
<p>Monitored Windows processes get killed at the moment after they are started instead of being blocked outright so that even a start is not possible anymore. A few small scripts can slip through at the moment because of this behavior as it takes some time to recognize a newly launched application and send the kill command to the computer system.</p>
<p>Process Blocker uses a simple text file that is placed in the same installation directory as the main application. This text file contains names of executables that are not allowed to be launched on a computer system. The program itself is added as a Windows Service to the system which has to be restarted after making changes to the text file.</p>
<p><span id="more-11287"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/03/windows_process_blocker.jpg" alt="windows_process_blocker" title="windows_process_blocker" width="255" height="168" class="alignnone size-full wp-image-11303" /></p>
<p><a href="http://www.processblocker.com/">Process Blocker</a> will display a user notification in the Windows System Tray whenever a process has been blocked by the service. A similar application that provides a better user experience is the process manager <a href="http://www.ghacks.net/2007/08/26/process-lasso-a-process-manager/">Process Lasso</a>. The developers of Process Blocker on the other hand are not even halfway through their roadmap. The next step will move the management of processes from the text file to a Group Policy administrative template. Other planned features are killing processes and applications using its crc (in case they get renamed) or full path, recording process errors and information in Windows Event log, allowing users to only run applications from specified folders (e.g. program files and Windows) and changing process killing to process execution prevention.</p>

	Tags: <a href="http://www.ghacks.net/tag/block-processes/" title="block processes" rel="tag">block processes</a>, <a href="http://www.ghacks.net/tag/monitor-processes/" title="monitor processes" rel="tag">monitor processes</a>, <a href="http://www.ghacks.net/tag/network-administration/" title="network administration" rel="tag">network administration</a>, <a href="http://www.ghacks.net/tag/process-blocker/" title="process blocker" rel="tag">process blocker</a>, <a href="http://www.ghacks.net/tag/process-lasso/" title="process lasso" rel="tag">process lasso</a>, <a href="http://www.ghacks.net/tag/process-manager/" title="process manager" rel="tag">process manager</a>, <a href="http://www.ghacks.net/tag/windows-network/" title="windows network" rel="tag">windows network</a>, <a href="http://www.ghacks.net/tag/windows-process/" title="windows process" rel="tag">windows process</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-services/" title="windows services" rel="tag">windows services</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2007/08/26/process-lasso-a-process-manager/" title="Process Lasso a Process Manager (August 26, 2007)">Process Lasso a Process Manager</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/07/01/windows-services-manager/" title="Windows Services Manager (July 1, 2009)">Windows Services Manager</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/12/30/vista-services-optimizer/" title="Vista Services Optimizer (December 30, 2008)">Vista Services Optimizer</a> (5)</li>
	<li><a href="http://www.ghacks.net/2007/12/21/security-and-privacy-complete-2/" title="Security and Privacy Complete (December 21, 2007)">Security and Privacy Complete</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/18/windows-process-blocker/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Day March 2009</title>
		<link>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/</link>
		<comments>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 17:26:36 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[microsoft security bulletin]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[spoofing]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=11081</guid>
		<description><![CDATA[Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including [...]]]></description>
			<content:encoded><![CDATA[<p>Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including Windows 2000. This means the popular operating systems Windows XP and Vista are affected as well as Windows Server 2003 and 2008.</p>
<p>One security vulnerability has a critical rating for all affected operating systems while the other two are rated important by Microsoft&#8217;s security research team. </p>
<p>Details about the Security Bulletins can be found by following these links: Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/MS09-006.mspx">MS09-006</a>, <a href="http://www.microsoft.com/technet/security/bulletin/MS09-007.mspx">MS09-007</a> or <a href="http://www.microsoft.com/technet/security/bulletin/MS09-008.mspx">MS09-008</a>. Another possibility is to <a href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx">access</a> the Security Bulletin Summary at Microsoft Technet.</p>
<p>The vulnerabilities fix one remote code execution vulnerability and two spoofing vulnerabilities on the affected Windows operating systems:</p>
<ul>
<li>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</li>
<li>Vulnerability in SChannel Could Allow Spoofing</li>
<li>Vulnerabilities in DNS and WINS Server Could Allow Spoofing</li>
</ul>
<p><span id="more-11081"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-patch-day/" title="microsoft patch day" rel="tag">microsoft patch day</a>, <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/microsoft-security-bulletin/" title="microsoft security bulletin" rel="tag">microsoft security bulletin</a>, <a href="http://www.ghacks.net/tag/patch-day/" title="patch day" rel="tag">patch day</a>, <a href="http://www.ghacks.net/tag/remote-code-execution/" title="remote code execution" rel="tag">remote code execution</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/spoofing/" title="spoofing" rel="tag">spoofing</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-vulnerabilities/" title="windows vulnerabilities" rel="tag">windows vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/" title="New Security Vulnerability Affects Windows Operating Systems (September 9, 2009)">New Security Vulnerability Affects Windows Operating Systems</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/" title="Microsoft Security Updates August 2009 (August 12, 2009)">Microsoft Security Updates August 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/" title="Microsoft Security Patches July 2009 (July 15, 2009)">Microsoft Security Patches July 2009</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Network Security Software Bothunter</title>
		<link>http://www.ghacks.net/2008/12/18/network-security-software-bothunter/</link>
		<comments>http://www.ghacks.net/2008/12/18/network-security-software-bothunter/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 07:31:53 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[bothunter]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[computer network]]></category>
		<category><![CDATA[Computer Security Software]]></category>
		<category><![CDATA[network scanner]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[network security software]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=9149</guid>
		<description><![CDATA[Bot networks are still a huge threat on the Internet. They are usually established with the use of computer worms that exploit old and new security vulnerabilities. A network security software like Bothunter can be helpful in determining if a computer network has been compromised. It does so by analysing the communication in the local [...]]]></description>
			<content:encoded><![CDATA[<p>Bot networks are still a huge threat on the Internet. They are usually established with the use of computer worms that exploit old and new security vulnerabilities. A network security software like Bothunter can be helpful in determining if a computer network has been compromised. It does so by analysing the communication in the local network.</p>
<p>The software has been designed to discover communication patterns that are typical for malware infected computers. While Bothunter has been designed as a network security software that can analyze the traffic of the network it can also be used to analyze a single computer or basic home network.</p>
<p><a href="http://www.bothunter.net/">Bothunter</a> is supplied as a Linux or Windows version. The Linux version comes as a installation but also in form of a live CD that can be used from any computer that is capable of booting from CD and compatible with Ubuntu Linux.</p>
<p><span id="more-9149"></span><img src="http://www.ghacks.net/wp-content/uploads/2008/12/network_security_software-500x276.jpg" alt="network security software" title="network security software" width="500" height="276" class="alignnone size-medium wp-image-9150" /></p>
<p>Bothunter needs some configuration in the beginning. Most home users will only need to enter the local network IP which they can discover this way:</p>
<blockquote><p>Click the Windows desktop Start Menu, Control Panel, Network Connections.   Find the local area connection that is &#8220;Connected&#8221;. Double click the connected network icon.  Click the Support Tab.  Your IP address will be listed.</p></blockquote>
<p>Optional data like the IP address of SMTP servers or DNS servers can be entered if they are used in the computer network. Home users usually leave these information blank. The only other information needed is the network adapter that should be used to scan and analyse the computer network.</p>
<p>Once that is done the network security software will scan the computer network in two minute intervals and display any potential bot infection in the interface.</p>

	Tags: <a href="http://www.ghacks.net/tag/bothunter/" title="bothunter" rel="tag">bothunter</a>, <a href="http://www.ghacks.net/tag/botnet/" title="botnet" rel="tag">botnet</a>, <a href="http://www.ghacks.net/tag/computer-network/" title="computer network" rel="tag">computer network</a>, <a href="http://www.ghacks.net/tag/computer-security-software/" title="Computer Security Software" rel="tag">Computer Security Software</a>, <a href="http://www.ghacks.net/tag/network-scanner/" title="network scanner" rel="tag">network scanner</a>, <a href="http://www.ghacks.net/tag/network-security/" title="network security" rel="tag">network security</a>, <a href="http://www.ghacks.net/tag/network-security-software/" title="network security software" rel="tag">network security software</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/" title="Computer Security Software ESET SysInspector (November 8, 2008)">Computer Security Software ESET SysInspector</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2009/08/07/use-wireshark-to-track-your-network-behavior/" title="Use Wireshark to track your network behavior (August 7, 2009)">Use Wireshark to track your network behavior</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/18/network-security-software-bothunter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday December 08</title>
		<link>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/</link>
		<comments>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/#comments</comments>
		<pubDate>Wed, 10 Dec 2008 21:06:27 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft patchday]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8835</guid>
		<description><![CDATA[Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.
The easiest way to install the patches is by downloading and installing the security patches at Windows Update which [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.</p>
<p>The easiest way to install the patches is by downloading and installing the security patches at <a href="http://www.update.microsoft.com">Windows Update</a> which provides access to all security updates even for users who run a non legit version of Windows.</p>
<p>Microsoft did also release a new version of the Windows Malicious Software Removal Tool which is now able to detect two new families of malware (Win32/FakeXPA and Win32/Yektel)</p>
<p><span id="more-8835"></span>
<ul>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx">MS08-070</a>: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx">MS08-071</a>: Vulnerabilities in GDI Could Allow Remote Code Execution (956802) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx">MS08-072</a>: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx">MS08-073</a>: Cumulative Security Update for Internet Explorer (958215) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx">MS08-074</a>: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx">MS08-075</a>: Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx">MS08-076</a>: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807) which is rated &#8220;Important&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-077.mspx">MS08-077</a>: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175) which is rated &#8220;Important&#8221;</li>
</ul>
<p>Windows users should install the updates as soon as possible to secure their computer system.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-patchday/" title="microsoft patchday" rel="tag">microsoft patchday</a>, <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/patch-tuesday/" title="patch tuesday" rel="tag">patch tuesday</a>, <a href="http://www.ghacks.net/tag/vulnerabilities/" title="vulnerabilities" rel="tag">vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/" title="Microsoft Patch Tuesday November 08 (November 12, 2008)">Microsoft Patch Tuesday November 08</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/" title="Microsoft Security Patches September 2009 (September 9, 2009)">Microsoft Security Patches September 2009</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Ghacks Christmas Giveaway: Sandboxie</title>
		<link>http://www.ghacks.net/2008/12/06/ghacks-christmas-giveaway-sandboxie/</link>
		<comments>http://www.ghacks.net/2008/12/06/ghacks-christmas-giveaway-sandboxie/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 10:00:24 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[ghacks Christmas giveaway]]></category>
		<category><![CDATA[sandboxed]]></category>
		<category><![CDATA[sandboxie]]></category>
		<category><![CDATA[security-software]]></category>
		<category><![CDATA[virtual environment]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8763</guid>
		<description><![CDATA[Sixth day of the Ghacks Christmas Giveaway. We have handed out licenses to some very popular software appplications such as Newsbin Pro, MediaMonkey Gold or Kaspersky Internet Security in the last days. Today&#8217;s application is Sandboxie, a security software program that can run selected applications in a closed environment on the computer. Sandboxie is compatible [...]]]></description>
			<content:encoded><![CDATA[<p>Sixth day of the Ghacks Christmas Giveaway. We have handed out licenses to some very popular software appplications such as Newsbin Pro, MediaMonkey Gold or Kaspersky Internet Security in the last days. Today&#8217;s application is <a href="http://www.sandboxie.com/">Sandboxie</a>, a security software program that can run selected applications in a closed environment on the computer. Sandboxie is compatible with 32-bit editions of Windows XP, Windows Vista or Windows Server 2003 and can also be run on Windows 2000.</p>
<p>The software developer is providing access to a <a href="http://www.sandboxie.com/index.php?DownloadSandboxie">free version of Sandboxie</a> on his website which has a few limitations compared to the commercial version. </p>
<p>As the name suggests Sandboxie makes use of the concept of so called sandboxes (also called virtual environments by some). The main advantage of running applications in a sandbox is that everything that happens in there stays in there. If you land on a website that uses a 0-day browser exploit to download and launch malicious code on your computer you can rest assured that the rest of the system &#8211; that is the part outside of the sandbox &#8211; will not be affected by the virus. And the sandbox itself can simply be cleared so that the malicious software has no means of affecting the computer system.</p>
<p><span id="more-8763"></span>To make it even more visual: Sandboxie acts as a border that is impenetrable for applications that get started inside. Many of these applications usually interact with other system components, say a web browser that is storing cache on the hard drive or storing new bookmarks on the computer. Every attempt to interact with the computer system will be intercepted by Sandboxie and emulated so that the application &#8220;thinks&#8221; that everything is ok. </p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2008/12/sandboxie-500x340.jpg" alt="" title="sandboxie" width="500" height="340" class="alignnone size-medium wp-image-8764" /></p>
<p>These changes on the other hand are not permanently and once the application or the sandbox have been terminated they are gone. But don&#8217;t worry: Sandboxie is still providing the means to save data that has been created or downloaded into the sandbox. Think of a document that you are downloading from a website, you might want to keep it even after the browser session closes.</p>
<p>It is possible to configure resource access rights for files running in the sandbox. These are left blank on purpose by default but it would be possible to allow the web browser Firefox to access its bookmarks file directly so that bookmarks get stored permanently. (There is an option in Sandboxie&#8217;s settings that allows direct access to the bookmarks of Opera, Firefox and Internet Explorer and another setting for email clients. </p>
<p>The installation runs through without problems or user interaction. The system is ready to run applications in the sandbox right after installation. Sandboxie integrates itself in the right-click context menu (Run Sandboxed) and it is also possible to drag and drop applications into the program interface to run them sandboxed. </p>
<p>The control interface is listing the programs that are running in the sandbox. This is helpful because there is virtually no way of telling if it is running in a Sandbox by looking at the program window. </p>
<p>The commercial version of Sandboxie introduces several interesting and helpful features. It makes it possible to run multiple sandboxes on a computer system. This can be useful to launch set of tools in different sandboxes which is great to isolate programs further.</p>
<p>The Forced Folders and Forced Programs options become available after registration.</p>
<p><strong>Forced Folders:</strong></p>
<p>This options allows you to select folders (this can also be a drive letter) and force all applications starting from there to run in sandboxed mode. Some useful applications for this are CD / DVD drives or a downloads folder for Internet downloads.</p>
<p><strong>Forced Programs:</strong></p>
<p>Allows the user to select files that should always be run in sandboxed mode. This is very useful to make sure that an application is always running in the sandbox without having to launch it that way at every program start. </p>
<p>The developer of <a href="http://www.sandboxie.com/">Sandboxie</a> was nice enough to give us six licenses of his security software program. You should know the drill by know. Just leave a comment letting us know what you think / like about the program and you are eligible to win a copy of it.</p>

	Tags: <a href="http://www.ghacks.net/tag/ghacks-christmas-giveaway/" title="ghacks Christmas giveaway" rel="tag">ghacks Christmas giveaway</a>, <a href="http://www.ghacks.net/tag/sandboxed/" title="sandboxed" rel="tag">sandboxed</a>, <a href="http://www.ghacks.net/tag/sandboxie/" title="sandboxie" rel="tag">sandboxie</a>, <a href="http://www.ghacks.net/tag/security-software/" title="security-software" rel="tag">security-software</a>, <a href="http://www.ghacks.net/tag/virtual-environment/" title="virtual environment" rel="tag">virtual environment</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/" title="Computer Security Software ESET SysInspector (November 8, 2008)">Computer Security Software ESET SysInspector</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/03/20/windows-registry-watcher/" title="Windows Registry Watcher (March 20, 2009)">Windows Registry Watcher</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2009/05/29/windows-defender/" title="Windows Defender (May 29, 2009)">Windows Defender</a> (11)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/06/ghacks-christmas-giveaway-sandboxie/feed/</wfw:commentRss>
		<slash:comments>123</slash:comments>
		</item>
		<item>
		<title>Computer Security Software ESET SysInspector</title>
		<link>http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/</link>
		<comments>http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/#comments</comments>
		<pubDate>Sat, 08 Nov 2008 08:14:44 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Computer Security Software]]></category>
		<category><![CDATA[eset sysinspector]]></category>
		<category><![CDATA[risk level]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security analysis]]></category>
		<category><![CDATA[security-software]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8152</guid>
		<description><![CDATA[Scanning a computer system with a computer security software like ESET SysInspector can reveal security related problems in short time. Those security software programs are by far not the all-knowing and -seeing eye but they provide an in depth analysis of a computer system that can be used to find some of problematic files that [...]]]></description>
			<content:encoded><![CDATA[<p>Scanning a computer system with a computer security software like ESET SysInspector can reveal security related problems in short time. Those security software programs are by far not the all-knowing and -seeing eye but they provide an in depth analysis of a computer system that can be used to find some of problematic files that could be a security risk.</p>
<p><a href="http://www.eset.com/download/sysinspector.php">ESET SysInspector</a> does that by scanning the computer&#8217;s hard drive and Registry. It assigns a risk level to every item that has been analyzed which ranges from fine (1) to risky (9) with three always bundled together. Risk levels 1 to 3 are assigned to files that have passed the check, 4-6 for unknown files and 7-9 for files that have been identified as being risky. The different levels are also colored differently (from green to red) to make identification as quickly as possible.</p>
<p>The computer security software will build a report that provides access to eight different categories including Running Processes, Network Connections or Important Registry Files. Each category is displayed in the color of the item with the highest risk level that it contains. That&#8217;s excellent for identifying the highest risks with one glance without having to look at the actual items at that time.</p>
<p><span id="more-8152"></span><img src="http://www.ghacks.net/wp-content/uploads/2008/11/computer_security_software-500x286.jpg" alt="" title="computer security software" width="500" height="286" class="alignnone size-medium wp-image-8153" /></p>
<p>Opening a category can reveal subcategories or items. Each item is (again) listed in a color that depicts its risk level. Some categories can contain dozens of items and the risk level slider at the top helps reducing the amount of items displayed by selecting a minimum risk level to be displayed. Every item with a lower risk level will be hidden from the display so that the system administrator can concentrate on the higher risk items.</p>
<p>A higher risk level does not necessarily mean that an item is dangerous. That would be subject to further analysis. ESET SysInspector is providing some tools and shortcuts for this. A right-click on an item will open a context menu with options to open the path in the Windows Registry or to open the file&#8217;s location on the computer&#8217;s hard drive. There is also the possibility to perform an online search using the default web browser and the Google search engine.</p>
<p>A set of reports can be created that contain various level of information. One interesting feature is the ability to compare logs which can give additional clues on system changes in a time period.</p>

	Tags: <a href="http://www.ghacks.net/tag/computer-security-software/" title="Computer Security Software" rel="tag">Computer Security Software</a>, <a href="http://www.ghacks.net/tag/eset-sysinspector/" title="eset sysinspector" rel="tag">eset sysinspector</a>, <a href="http://www.ghacks.net/tag/risk-level/" title="risk level" rel="tag">risk level</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-analysis/" title="security analysis" rel="tag">security analysis</a>, <a href="http://www.ghacks.net/tag/security-software/" title="security-software" rel="tag">security-software</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/16/secure-windows-services-configuration/" title="Secure Windows Services Configuration (March 16, 2009)">Secure Windows Services Configuration</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/12/06/ghacks-christmas-giveaway-sandboxie/" title="Ghacks Christmas Giveaway: Sandboxie (December 6, 2008)">Ghacks Christmas Giveaway: Sandboxie</a> (123)</li>
	<li><a href="http://www.ghacks.net/2009/03/20/windows-registry-watcher/" title="Windows Registry Watcher (March 20, 2009)">Windows Registry Watcher</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</title>
		<link>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 08:38:16 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7632</guid>
		<description><![CDATA[It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not [...]]]></description>
			<content:encoded><![CDATA[<p>It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not releasing them because they release them in one package on one day.</p>
<p>Microsoft released a batch of eleven security patches for various operating systems and products yesterday which are available by visiting Windows Update or Microsoft Technet which contains in depths information about the affected products and the security vulnerabilities.</p>
<p>The patches fix four critical, six important and 1 moderate security vulnerability:</p>
<p><span id="more-7632"></span>	</p>
<ul>
<li>Vulnerability in Active Directory Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128125">957280</a>)</li>
<li>Cumulative Security Update for <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> (<a href="http://go.microsoft.com/fwlink/?LinkID=128060">956390</a>)</li>
<li>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=125712">956695</a>)</li>
<li>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=124653">956416</a>)</li>
</ul>
<ul>
<li>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=125709">956803</a>)</li>
<li>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=121738">954211</a>)</li>
<li>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=120829">953155</a>)</li>
<li>Vulnerability in SMB Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=127994">957095</a>)</li>
<li>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=128103">956841</a>)</li>
<li>Vulnerability in Message Queuing Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128102">951071</a>)</li>
</ul>
<ul>
<li>Vulnerability in Microsoft Office Could Allow Information Disclosure (<a href="http://go.microsoft.com/fwlink/?LinkId=128145">957699</a>)</li>
</ul>
<p>It is highly recommended to update the products as soon as possible to protect the system from this attacks.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/office/" title="office" rel="tag">office</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/patch-day/" title="patch day" rel="tag">patch day</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/11/29/watch-three-webcasts-get-vista-and-office-for-free/" title="Watch three webcasts get vista and office for free (November 29, 2006)">Watch three webcasts get vista and office for free</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Protect Protects Windows Files</title>
		<link>http://www.ghacks.net/2008/08/18/system-protect-protects-windows-files/</link>
		<comments>http://www.ghacks.net/2008/08/18/system-protect-protects-windows-files/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 08:45:43 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[file protection]]></category>
		<category><![CDATA[security-software]]></category>
		<category><![CDATA[system protect]]></category>
		<category><![CDATA[system security]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6252</guid>
		<description><![CDATA[System Protect can protect custom files and folders as well as system files in Windows. By default all files and folders that are necessary to run the operating system are protected by the security application. Protected in this case means that deleting and modifying protected files is denied to the user. This setting can be [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.system-protect.com/">System Protect</a> can protect custom files and folders as well as system files in Windows. By default all files and folders that are necessary to run the operating system are protected by the security application. Protected in this case means that deleting and modifying protected files is denied to the user. This setting can be changed in the program&#8217;s options to allow system changes on the user requests which is for example helpful during system updates.</p>
<p>An access denied window pops up when the user or system tries to delete or modify a protected system file. This popup notification can be removed in the options as well.</p>
<p>Besides protecting important system files System Protect can also protect custom files and folders that have been selected by the user. This is done by adding those files and folders to the Custom Protection tab in the software program&#8217;s settings.</p>
<p><span id="more-6252"></span><img src="http://www.ghacks.net/wp-content/uploads/2008/08/system_protect-499x373.jpg" alt="system protect" title="system protect" width="499" height="373" class="alignnone size-medium wp-image-6250" /></p>
<p>Information about files and folders that are protected are stored in a database that gets regularly updated just like the virus definition file of a antivirus software. That&#8217;s a good way of keeping up with system changes initiated by Microsoft and other software vendors.</p>
<p>System Protect is compatible with Windows XP 32-bit and 64-bit editions as well as Windows Vista 32-bit editions.</p>

	Tags: <a href="http://www.ghacks.net/tag/file-protection/" title="file protection" rel="tag">file protection</a>, <a href="http://www.ghacks.net/tag/security-software/" title="security-software" rel="tag">security-software</a>, <a href="http://www.ghacks.net/tag/software/" title="software" rel="tag">software</a>, <a href="http://www.ghacks.net/tag/system-protect/" title="system protect" rel="tag">system protect</a>, <a href="http://www.ghacks.net/tag/system-security/" title="system security" rel="tag">system security</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/20/windows-registry-watcher/" title="Windows Registry Watcher (March 20, 2009)">Windows Registry Watcher</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/09/15/which-programs-should-i-run-to-scan-a-computer-for-malicious-software/" title="Which Programs Should I Run To Scan A Computer For Malicious Software? (September 15, 2008)">Which Programs Should I Run To Scan A Computer For Malicious Software?</a> (13)</li>
	<li><a href="http://www.ghacks.net/2008/12/06/password-protect-applications/" title="Password Protect Applications (December 6, 2008)">Password Protect Applications</a> (9)</li>
	<li><a href="http://www.ghacks.net/2008/12/06/ghacks-christmas-giveaway-sandboxie/" title="Ghacks Christmas Giveaway: Sandboxie (December 6, 2008)">Ghacks Christmas Giveaway: Sandboxie</a> (123)</li>
	<li><a href="http://www.ghacks.net/2008/11/08/computer-security-software-eset-sysinspector/" title="Computer Security Software ESET SysInspector (November 8, 2008)">Computer Security Software ESET SysInspector</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/18/system-protect-protects-windows-files/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft August 2008 Security Updates</title>
		<link>http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/</link>
		<comments>http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 22:50:00 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows updates]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6106</guid>
		<description><![CDATA[Microsoft has just released the security patches of the August 2008 Patch Day, a total of eleven updates for various Microsoft operating systems and products that are recommended updates. Six of the eleven updates are critical updates while the remaining five are classified as important.
The easiest way to obtain those updates would be to head [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has just released the security patches of the August 2008 Patch Day, a total of eleven updates for various Microsoft operating systems and products that are recommended updates. Six of the eleven updates are critical updates while the remaining five are classified as important.</p>
<p>The easiest way to obtain those updates would be to head over to <a href="http://go.microsoft.com/fwlink/?LinkID=40747">Windows Updates</a> and install them directly from there. This option is only valid if <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> is used to open the website.</p>
<p>Users who prefer to download the patches manually can <a href="http://www.microsoft.com/downloads/results.aspx?DisplayLang=en&#038;nr=20&#038;freetext=security+update&#038;sortCriteria=date">head</a> over to the Microsoft Download Center and download the patches from there for their operating system. The following is a list of the security updates that have been made available:</p>
<p><span id="more-6106"></span>
<ul>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-041.mspx">MS08-041</a> – Critical &#8211; Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-042.mspx">MS08-042</a> – Important &#8211; Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-043.mspx">MS08-043</a> – Critical &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-044.mspx">MS08-044</a> – Critical &#8211; Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (924090)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-045.mspx">MS08-045</a> &#8211; Critical &#8211; Cumulative Security Update for Internet Explorer (953838)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-046.mspx">MS08-046</a> – Critical &#8211; Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-047.mspx">MS08-047</a> – Important &#8211; Vulnerability in IPsec Policy Processing Could Allow Information Disclosure (953733)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx">MS08-048</a> &#8211; Important &#8211; Security Update for Outlook Express and Windows Mail (951066)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-049.mspx">MS08-049</a> – Important &#8211; Vulnerabilities in Event System Could Allow Remote Code Execution (950974)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-050.mspx">MS08-050</a> – Important &#8211; Vulnerability in Windows Messenger Could Allow Information Disclosure (955702)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-051.mspx">MS08-051</a> – Critical &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)</li>
</ul>
<p>As you can see a wide variety of Microsoft software programs and operating systems is affected.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-updates/" title="security updates" rel="tag">security updates</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-updates/" title="windows updates" rel="tag">windows updates</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/06/11/microsoft-security-updates-for-june-2008/" title="Microsoft Security Updates for June 2008 (June 11, 2008)">Microsoft Security Updates for June 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/02/27/february-2008-security-releases-iso-image/" title="February 2008 Security Releases ISO Image (February 27, 2008)">February 2008 Security Releases ISO Image</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/03/26/windows-xp-service-pack-3-release-candidate-2-refresh/" title="Windows XP Service Pack 3 Release Candidate 2 Refresh (March 26, 2008)">Windows XP Service Pack 3 Release Candidate 2 Refresh</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/03/09/windows-update-error-services-not-running/" title="Windows Update Error services not running (March 9, 2008)">Windows Update Error services not running</a> (16)</li>
	<li><a href="http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/" title="Windows Security Updates September 2008 (September 10, 2008)">Windows Security Updates September 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Vulnerability Scanner</title>
		<link>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/</link>
		<comments>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 18:35:38 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows vulnerability scanner]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3846</guid>
		<description><![CDATA[Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be [...]]]></description>
			<content:encoded><![CDATA[<p>Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be added to one of the botnets out there.</p>
<p>I <a href="http://www.pspl.com/download/winvulscan.htm">discovered</a> a software Windows Vulnerability Scanner at <a href="http://www.techmalaya.com/2008/04/18/proland-windows-vulnerability-scanner/">Tech Malaya</a> which scans a Windows NT system, that is Windows 2000, Windows XP, Windows 2003 Server or Windows Vista for security vulnerabilities. It seems to use information from the Microsoft Knowledgebase exclusively and one would assume that a system that downloaded all Windows Updates recently reveal no vulnerabilities. I let the software scan my system and it did find six critical and one important security vulnerability that had not been patched yet.</p>
<p>I&#8217;m not sure how this can be but was glad that the application revealed the information to me. It lists the vulnerabilities and provides links to the Microsoft website that contains information about it. </p>
<p><span id="more-3846"></span><a href='http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner.jpg'><img src="http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner-300x218.jpg" alt="windows vulnerability scanner" title="windows vulnerability scanner" width="300" height="218" class="alignnone size-medium wp-image-3847" /></a></p>
<p>The Knowledgebase article at Microsoft contains a link to the download of the security patch and I did install all the patches one after the other.  An improvement would have been if the software would automatically download the patches and install them on the system, or at least those that the user selects. If you have not been to Windows Update for a while I suggest you start there and scan the system again afterwards which should fix most of the security vulnerabilities found during the first scan.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-vulnerability-scanner/" title="windows vulnerability scanner" rel="tag">windows vulnerability scanner</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/" title="Microsoft Security Updates May 2008 (May 16, 2008)">Microsoft Security Updates May 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>No Password securer than weak password ?</title>
		<link>http://www.ghacks.net/2008/03/06/no-password-securer-than-weak-password/</link>
		<comments>http://www.ghacks.net/2008/03/06/no-password-securer-than-weak-password/#comments</comments>
		<pubDate>Thu, 06 Mar 2008 12:15:24 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[nt-passwords]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2008/03/06/no-password-securer-than-weak-password/</guid>
		<description><![CDATA[According to Digital Inspiration that's the case if you are using Windows XP because leaving the password blank makes it impossible to connect to the computer remotely. The link given in the article which points to the Password Strength &#038; Password Security page at Microsoft.com is unfortunately not available at this point.]]></description>
			<content:encoded><![CDATA[<p>According to Digital Inspiration that&#8217;s the case if you are using Windows XP because leaving the password blank makes it impossible to connect to the computer remotely. The link given in <a href="http://www.labnol.org/software/tutorials/blank-windows-password-secure-computer-internet-attacks/2517/">the</a> article which points to the Password Strength &#038; Password Security page at Microsoft.com is unfortunately not available at this point.</p>
<p>It is however still accessible through <a href="http://209.85.129.104/search?q=cache:bnBV6SPw9n8J:www.microsoft.com/protect/yourself/password/create.mspx+www.microsoft.com/protect/yourself/password/create.mspx&#038;hl=en&#038;ct=clnk&#038;cd=1&#038;lr=lang_en&#038;client=firefox-a">Google Cache</a> and the article indeed contains a paragraph entitled The &#8220;blank password&#8221; option. The blank password is only more secure than a weak password like 1234 which can be easily guessed by a brute force attack. The article recommends this only if the location is physically secure.</p>
<p>While this might be a sound advice for some it is in my opinion way better to choose a secure password instead of none. It could be an option for the forgetful.</p>
<p><span id="more-3435"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/nt-passwords/" title="nt-passwords" rel="tag">nt-passwords</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/07/10/yahoo-widget-position-restorer/" title="Yahoo Widget Position Restorer (July 10, 2008)">Yahoo Widget Position Restorer</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/01/29/wpf-performance-fix-for-windows-vista-and-xp/" title="WPF Performance Fix for Windows Vista and XP (January 29, 2008)">WPF Performance Fix for Windows Vista and XP</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/06/windows-xp-default-internet-browser-per-user-profile/" title="Windows XP: Default Internet Browser Per User Profile (March 6, 2009)">Windows XP: Default Internet Browser Per User Profile</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/03/06/no-password-securer-than-weak-password/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
