<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; windows vulnerability scanner</title> <atom:link href="http://www.ghacks.net/tag/windows-vulnerability-scanner/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>DLLHijackAuditor, Check Programs For DLL Hijack Vulnerability</title><link>http://www.ghacks.net/2010/09/06/dllhijackauditor-check-programs-for-dll-hijack-vulnerability/</link> <comments>http://www.ghacks.net/2010/09/06/dllhijackauditor-check-programs-for-dll-hijack-vulnerability/#comments</comments> <pubDate>Mon, 06 Sep 2010 14:24:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[dll]]></category> <category><![CDATA[dll hijack]]></category> <category><![CDATA[dllhijackaudit]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerability]]></category> <category><![CDATA[windows vulnerability scanner]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=33973</guid> <description><![CDATA[A new Windows vulnerability was made public in the end of August, which could allow remote code execution on a computer system. The issue is caused by programs and applications that use insecure programming practices. According to various researchers at least 40 popular applications are affected by the vulnerability. New users who want to read [...]]]></description> <content:encoded><![CDATA[<p>A new Windows vulnerability was made public in the end of August, which could allow remote code execution on a computer system. The issue is caused by programs and applications that use insecure programming practices. According to various researchers at least 40 popular applications are affected by the vulnerability.</p><p>New users who want to read up on it can open our coverage of the <a
href="http://www.ghacks.net/2010/08/26/microsoft-offers-workaround-for-remote-dll-vulnerability/">issue</a>, or <a
href="http://www.microsoft.com/technet/security/advisory/2269637.mspx">Microsoft&#8217;s Security Advisory</a>. Both offer a deeper explanation and workarounds for the issue.</p><p>The free software DLLHiJackAuditor has been designed to test software for the vulnerability. The portable program can audit any 32-bit Windows application.</p><p>The program is dead easy to use. Users need to select an application from the computer system first before they click on the start audit button to test the application.</p><div
id="attachment_33974" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/dll-hijack-vulnerability.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/dll-hijack-vulnerability-500x373.png" alt="dll hijack vulnerability" title="dll hijack vulnerability" width="500" height="373" class="size-medium wp-image-33974" /></a><p
class="wp-caption-text">dll hijack vulnerability</p></div><p>The portable software will automatically load the application, and terminate it. It will uncover any vulnerable DLLs that are found during the audit, and report those back to the user of the program.</p><p>The Exploit button becomes active if a vulnerable DLL has been found in the selected software.</p><p>Finally, it is possible to create a HTML report of the findings, which contains detailed technical information that the developer of the vulnerable application can use to fix the issue.</p><p>DLL Hijack Audit does not require any third party tools to function properly. It has in addition been designed in a way that it does not trigger antivirus or security software on the system. Finally, the program require no special privileges for auditing applications, with the exception if the target executable does).</p><p>The software program is available for download at the developer website over at <a
href="http://securityxploded.com/dllhijackauditor.php">SecurityXploded</a>. The tool can be useful for software developers, and users who want to make sure that the programs they run on their system are not affected by the security issue.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/06/dllhijackauditor-check-programs-for-dll-hijack-vulnerability/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Windows Vulnerability Scanner</title><link>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/</link> <comments>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/#comments</comments> <pubDate>Fri, 18 Apr 2008 18:35:38 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerability scanner]]></category> <category><![CDATA[windows-xp]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=3846</guid> <description><![CDATA[Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be [...]]]></description> <content:encoded><![CDATA[<p>Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be added to one of the botnets out there.</p><p>I <a
href="http://www.pspl.com/download/winvulscan.htm">discovered</a> the software Windows Vulnerability Scanner at <a
href="http://www.techmalaya.com/2008/04/18/proland-windows-vulnerability-scanner/">Tech Malaya</a> which scans a Windows NT system, that is Windows 2000, Windows XP, Windows 2003 Server or Windows Vista for security vulnerabilities. It seems to use information from the Microsoft Knowledgebase exclusively and one would assume that a system that downloaded all Windows Updates recently reveal no vulnerabilities. I let the software scan my system and it did find six critical and one important security vulnerability that had not been patched yet.</p><p>I&#8217;m not sure how this can be but was glad that the application revealed the information to me. It lists the vulnerabilities and provides links to the Microsoft website that contains information about it.</p><p><span
id="more-3846"></span><a
href='http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner.jpg'><img
src="http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner-300x218.jpg" alt="windows vulnerability scanner" title="windows vulnerability scanner" width="300" height="218" class="alignnone size-medium wp-image-3847" /></a></p><p>The Knowledgebase article at Microsoft contains a link to the download of the security patch and I did install all the patches one after the other.  An improvement would have been if the software would automatically download the patches and install them on the system, or at least those that the user selects. If you have not been to Windows Update for a while I suggest you start there and scan the system again afterwards which should fix most of the security vulnerabilities found during the first scan.</p><p><strong>Update:</strong> The developer website does not seem to be available anymore. You can download the latest version of Windows Vulnerability Scanner from software repositories such as <a
href="http://www.freewarefiles.com/Windows-Vulnerability-Scanner_program_22088.html">Freeware Files</a>. Just download the program from there and use it normally. Keep in mind though that it is not clear at this point in time if development has stopped or is still ongoing.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
