Tuesday, July 14, 2009

Security Alert: Microsoft Office Web Components Zero Day

Websense Security Labs(TM) ThreatSeeker(TM) is currently tracking exploit sites related to a new zero-day vulnerability in Microsoft Office Web Components. CVE-2009-1136 has been allocated to this vulnerability. The vulnerable component is an ActiveX object used by Internet Explorer to display and publish spreadsheets, charts, and databases to the Web. Microsoft Security Advisory 973472 offers a workaround for the zero-day and further technical information can be found on Microsoft's Security Research and Defense blog.

Threatseeker has spotted the attack in an IP block from China, initally found to be serving exploits for the recent MS Msvidctl Zero Day. This new exploit is now circulating in the wild and is suspected to be integrated to Web exploit kits.

ISC also offers additional updates on this threat.

ThreatSeeker is tracking this attack and we will provide updates as new information emerges.

Websense® Messaging and Websense Web Security customers are protected against this attack.

To view the details of this alert Click here

Protected by Websense Hosted Email Security — www.websense.com

DOD seeks defense against denial of service attacks

Federal Computer Week: July 14 2009 Federal Computer Week Daily News
  • Having trouble viewing this e-mail? Click here to view as a Web page.
FCW
Daily News
7/14/2009
Daily news for IT professionals in government
SPONSORED BY
Click here
SPONSORED BY
Taiwan's accession to the WTO Government Procurement Agreement opens up unprecedented government contracting opportunities for your agency or company. Enhance the quality of your purchasing and the competitiveness of your bids by leveraging Taiwan--a global innovation leader, with top suppliers in the ICT, semiconductor, machinery, medical equipment and functional textile sectors and many more. Increase Innovation. Source Taiwan. Click here to learn more or e-mail gpa@taitra.org.tw.
HIGHLIGHTS FROM THE JULY 13 PRINT ISSUE

SPONSORED BY
newsletter sponsor advertisement
SPONSORED BY
Definitions of Cloud Computing
Exclusive Report Sponsored By: Booz Allen Hamilton

Cloud Computing offers the prospect of dramatically increasing your computing power, being able to balance workloads with demand and paying only for the services you use. Here is how a few of the leaders, including NIST, Gartner and IDC, in the Cloud Computing marketplace define Cloud.
SPONSORED MESSAGE
  • Federal Computer Week
    1105 Government Information Group
    3141 Fairview Park Drive, Suite 777
    Falls Church, VA 22042
    703-876-5100

US-CERT Current Activity - Microsoft Releases Security Advisory 973472

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Microsoft Releases Security Advisory 973472

Original release date: July 13, 2009 at 11:20 am
Last revised: July 14, 2009 at 8:37 am


Microsoft has released Security Advisory 973472 to alert users about a
vulnerability in Microsoft Office Web Components. Exploitation of this
vulnerability may allow a remote attacker to execute arbitrary code.
The advisory indicates that Microsoft is aware of attacks attempting
to exploit the vulnerability.

US-CERT encourages users and administrators to review Microsoft
Security Advisory 973472 and implement the suggested workaround.
Additionally, a Microsoft Fix it tool has been released to assist
users in mitigating the risks associated with this vulnerability.

US-CERT will provide additional information as it becomes available.

Relevant Url(s):
<http://support.microsoft.com/kb/973472>

<http://www.microsoft.com/technet/security/advisory/973472.mspx>

====
This entry is available at
http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory_973472

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSlyDvXIHljM+H4irAQL4fwf/eoIf/BPXezhC0m4JqmCOwue1HMQQrdVL
6M8PppDoLnCZAV/E+WfSM/h/JFXCHdbxssgIz5xDzxAf0xFJPS4k12gquV6EGwod
5d/8OYIvt+NtMjmKnO9My9dp0ZK0ly3+VFlPyutFuNen2PVzNn/ar7xP8BvtEMII
I2Mg5Z7PKqiKFNvxQpEQd4wLcuOVFDXh5aEp+3OfrtrtiWYU8R3/APNcfYNY4vKl
RupimLmbBtilH99biFkDiSY0xR9eCwynxsSdL2F1LDTEWymnAA4U7PT1wJOx6Qcn
ACjMYATBbgHnYHGryUp5saO5/yeCXgJgrryNvkqkzsk0ovUdHyUnxw==
=viq6
-----END PGP SIGNATURE-----

US-CERT Current Activity - Mozilla Firefox 3.5 Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Mozilla Firefox 3.5 Vulnerability

Original release date: July 14, 2009 at 8:38 am
Last revised: July 14, 2009 at 8:38 am


US-CERT is aware of reports of a vulnerability affecting Mozilla
Firefox 3.5. This vulnerability is due to an error in the way
JavaScript code is processed. Exploitation of this vulnerability may
allow an attacker to execute arbitrary code. Additionally, exploit
code is publicly available for this vulnerability.

US-CERT encourages users and administrators to disable JavaScript as
outlined in the Securing Your Web Browser document to help mitigate
the risks associated with this vulnerability.

US-CERT will provide additional information as it becomes available.

Relevant Url(s):
<http://www.us-cert.gov/reading_room/securing_browser/#Mozilla_Firefox>

====
This entry is available at
http://www.us-cert.gov/current/index.html#mozilla_firefox_3_5_vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSlyDkXIHljM+H4irAQK6twf/Sm7pk4+TDBsf5/euOy/zJ5Mn6wosrS27
8v4B3QXqJcaiTLotqOba9V+WQWLLSScViHSXNM/UBLOeWKFWS4vkfBX7U+6PxdZn
bKWedO3b6rwSfUmUns17/Nux81ARbiLJyR0pdDsT2uwfP7iUJiAGDGs+pCkYF3HO
kBQfB+6G0hB9SfC/qig82Ev6xh0AH83i5Ci3SHcOfZvHEDVIN2IZW1vypZ9kUzBJ
c1hpXl/Xw3HiLsfD5XjWkOC0LNfDLI47/GjDNHXfUQRxQxdwP0OK/5lnuGgC2DsQ
vDbK+/0nwX4VZzVZa1qvMDHBJ/tZji7McwLP4/0XRJKk9V/MDrbHPw==
=cwj1
-----END PGP SIGNATURE-----

Monday, July 13, 2009

[Lockergnome] Computer Security ~ July 13, 2009

Lockergnome
Lockergnome's Computer Security ~ July 13, 2009   



Disk Watchman: Disk Watchman is an application that monitors your hard, removable, and mapped network drive resources. It displays free and used disk space on a realtime basis. You will be able to see and be notified by e-mail/ICQ/SMS/sound when your free disk space falls short of certain values. DW contains rapid tools to find disk space reserves (backup, temporary, and duplicated files). You will be able to free up more space effectively with its intuitive and... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

SPX Instant Screen Capture: There are not too many ways you can improve your standard screen capture - or are there? SPX Instant Screen Capture gives you more built in features when it comes to getting an image from your desktop than you could have ever imagined. It improves your standard screen capturing built into Windows, and doesn't make the process any more difficult than it has to be. Anything that improves upon an already easy process has to... [Click Here to Download]

Administrivia

Tech Help and How To


Microsoft, The Ultimate Spin Doctor

Google People Love To Send Tweets

iCloud an OS that runs in your browser

Black Dimple Green Astronomy Grade Laser Pen for $15!

Creately

Pahelika: Secret Legends

Easy Time Control Free v5.2.127

Bruno Zx1

Make: Technology On Your Time Volume 16

Disable User Account Control In Windows 7

Model Trains For Beginners: A Step-by-Step Guide To Save Time & Money

Windows 7 Build 7600, Rumored to Be RTM, Already Available In Several Places

Screenjelly - Record Your Screen And Voice

VLC 1.0 Released ? Is It Really A Game Changer?

Origins of Stupidity in Government

NYC 311 Now Online

Google Map - Find Me Feature

Learn a New Language with Livemocha

One Billion Apps Downloaded

Apple Hiring a Microsoft Employee


US-CERT Current Activity - Microsoft Releases Security Advisory 973472

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Microsoft Releases Security Advisory 973472

Original release date: July 13, 2009 at 11:20 am
Last revised: July 13, 2009 at 11:20 am


Microsoft has released Security Advisory 973472 to alert users about a
vulnerability in Microsoft Office Web Components. Exploitation of this
vulnerability may allow a remote attacker to execute arbitrary code.
The advisory indicates that Microsoft is aware of attacks attempting
to exploit the vulnerability.

US-CERT encourages users and administrators to review Microsoft
Security Advisory 973472 and implement the workaround listed in the
advisory. This workaround will help mitigate the risks until a patch
or update is released by the vendor.

US-CERT will provide additional information as it becomes available.

Relevant Url(s):
<http://www.microsoft.com/technet/security/advisory/973472.mspx>

====
This entry is available at
http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory_973472

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSltYUHIHljM+H4irAQJSCQf9F/ngGKbIkkLLOgMLGZTmdP7ZAoo9lm1Q
XlhUZkcBVPegcPOoOs6ExDEgkIIFUCqZLC3DRIbwePBbuyleHIGk/ZQTP40VQBPF
wNR4GE462gDBcfY1g8JQ5Fbq2SY/wZuto6J4VioZiWEVBA/8ZG/QyNHNuDkyvfW3
dwRn4oq1TygpCviLHFc0Y1fP1qiPH63kId5v8DijKRUI+WWfmoO0LIxs+Z+8sel1
dYIEcS8D1Kf9e215AnhjUpnUD1T6PIb9dThyGbla6CiPOcjMXVmdtKe+JDqk61vj
QdTUSrSnpE+dE5MoNwDAOXvA+JRkuNbaAYVaWLDIcCxkJFQ6Bv+x7Q==
=UaY5
-----END PGP SIGNATURE-----

US-CERT Current Activity - VMware Releases Security Advisory VMSA-2009-0009 and Updates Security Advisory VMSA-2009-0008.1

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

VMware Releases Security Advisory VMSA-2009-0009 and Updates Security Advisory VMSA-2009-0008.1

Original release date: July 13, 2009 at 8:58 am
Last revised: July 13, 2009 at 8:58 am


VMware has released security advisory VMSA-2009-0009 to address
multiple vulnerabilities involving the udev, sudo, and curl packages
of the ESX Service Console. These vulnerabilities may allow an
attacker to execute arbitrary requests to an affected intranet server,
read or overwrite files, or gain elevated privileges on the affected
system.

Additionally, VMware has updated security advisory VMSA-2009-0008.1.
This advisory addresses a vulnerability in the krb5 package of the ESX
Service Console. Exploitation of this vulnerability may allow an
attacker to execute arbitrary code or cause a denial-of-service
condition.

US-CERT encourages users and administrators to review VMware security
advisories VMSA-2009-0009 and VMSA-2009-0008.1 and apply any necessary
workarounds or updates to help mitigate the risks.

Relevant Url(s):
<http://lists.vmware.com/pipermail/security-announce/2009/000061.html>

<http://lists.vmware.com/pipermail/security-announce/2009/000060.html>

====
This entry is available at
http://www.us-cert.gov/current/index.html#vmware_releases_security_advisory_vmsa3

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEUAwUBSls6LHIHljM+H4irAQKluwf3X7r3fAiT7euobfLL2+uXjoDE7T+swyCZ
UpIOsyWbODSlbQ8RB1ZfTTAt5B5SSE60kRJbBUvX6STh9ilKplUFqXCqSQO2k5GI
uRVQHKEhRWoaBR55V4yEd05sxGYyP2pQszeYz1Df5TOM2jDShvvpiLr2PUm8LOqB
9d7F8gZiNKRfvLP/Xaqkl1yZzshTW3DDURI9pZGXQc5bNkKcIeXlJh1k7+MSmMY3
KqkMb9pNMTTMK8yDvymvKdhfK7eBjhuUSqSnh32F6uY1tgimm/iOEyz955mohAmx
NNgz9zlwh8GJbTdNjkLJ0TezdVytSHdSJZ1JXjuWQbE2Dt3HbyzU
=0xjD
-----END PGP SIGNATURE-----

Cyberattacks add fuel to cybersecurity debate

Federal Computer Week: July 13, 2009 Federal Computer Week Daily News
  • Having trouble viewing this e-mail? Click here to view as a Web page.
FCW
Daily News
7/13/2009
Daily news for IT professionals in government
SPONSORED BY
newsletter sponsor advertisement
SPONSORED BY
1105 Government Information Group Special Report: Security Directives and Compliance
Sponsored by: Citrix

With federal IT security breaches on the rise, policy makers, federal oversight organizations, industry think tanks and academia are providing updates on the worst threats faced by government IT infrastructures. Government networks are targeted by foreign nations seeking intelligence, as well as criminal groups and individuals who may want to disrupt power, communication or financial systems. According to reports, fewer attacks are being used to take down an organization's entire IT system. Instead, attacks now penetrate IT systems without impairing them, primarily to siphon out sensitive information without detection. Read full article.
TOP 10 STORIES ON FCW.com

SPONSORED BY
newsletter sponsor advertisement
SPONSORED BY
1105 Government Information Group Report: Efficient Technology Solutions
Sponsored By: CDWG

Going 'Virtually' Green. Increasingly, federal audiences are beginning to show that they understand the transformational impact of virtualization on government IT operations. Because standard servers today still run at less than 30% capacity, more federal organizations are turning to virtualization to reduce their server footprint, and increase the efficiency of federal IT. This article details the range of benefits that virtualization provides from the green IT perspective. Full article here.
MORE FROM 1105 GOVERNMENT INFORMATION GROUP
  • Making Most of Stimulus Program Funding

    What must the government do to efficiently allocate ARRA funding? What steps can industry suppliers take to make the most of opportunities created by the economic stimulus package?
 
  • Future of Economic Stimulus Program

    Industry observers maintain a looming workforce shortage, lack of training, the difficulty of balancing current workloads and a lack of extensive program management expertise, are among the biggest obstacles agencies must overcome in the future, as they work to manage projects under the ARRA program.
SPONSORED MESSAGE
  • Federal Computer Week
    1105 Government Information Group
    3141 Fairview Park Drive, Suite 777
    Falls Church, VA 22042
    703-876-5100

Sunday, July 12, 2009

[Lockergnome] Computer Security ~ July 12, 2009

Lockergnome
Lockergnome's Computer Security ~ July 12, 2009   



Video Edit Magic v4.x: If you think all professional video editing software is expensive, think again. Video Edit Magic is a Windows video editing application that gives you high-end power at an entry-level price. Its drag-and-drop interface makes it easy to capture video footage onto the editing timeline and assemble a movie in mere minutes. Then add professional scene transitions, some background music, a couple of title effects, and get ready to show the world your finished masterpiece. You... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

WebGrab!: WebGrab! is a tool that allows you to quickly and easily download Web page elements such as images, html pages, Java applets, Shockwave or Director animation, and more. Unlike traditional Web browsing, WebGrab! "crawls" Web pages or FTP sites to find all downloadable files for download. Download images, audio, video, and pictures for your desktop background, or build your collection of clip art/fonts. WebGrab! helps you save time and energy. Main Features: Easily download all... [Click Here to Download]

Administrivia

Tech Help and How To


Microsoft Vows to Make Permanent Fixes

Amazon Offers Wireless Site To Buy Phones & Plans [beta]

Avoiding Trouble With Windows 7 Upgrades

Security Updates As Of July 12, 2009

Summer Philly Guitar Show - it?s Lefty Time!!!

Spire Expands Into PSUs

Microsoft VP Says Google OS Is Defensive Only

Aristocrats of 43rd St. JOE FRANKLIN and JON HAMMOND HammondCast KYOU Radio

Actor, UN Ambassador Danny Glover & Jon Hammond Pt. 4 of 4 KYOU Radio

Microsoft to Release Windows 7 by End of July

Our GM May Be Gearing For Total Failure

OUR GM May Be Gearing For Total Failure

Is All Not Sunny In Wintel ? ville? Intel On the Chrome OS Development Team

Hitachi Announces 2GB Deskstar

Google Chrome Operating System Is Kind Of An Anti-Operating System

Google - Find Creative Commons Images Using Image Search

Google Blogging For Dummies - Have You Read It?

Asus to Release Another Winner

Another Microsoft Milestone

Jane Dornacker R.I.P. KYOU Radio and KYCY Jon Hammond Hosting


Saturday, July 11, 2009

[Lockergnome] Computer Security ~ July 11, 2009

Lockergnome
Lockergnome's Computer Security ~ July 11, 2009   



Rally Racers: Fast action arcade racing at its best! Whether you are a racing game pro, or just a beginner, Rally Racers will push your driving skills to the limit. You must capture all of the flags while avoiding the road hazards and enemy cars that appear at every turn. With classic '80s styling and gameplay, you'll be looking for the quarter slot! [Download Free Trial]... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Mass Downloader: MetaProducts Mass Downloader (MD) is a Windows 9x/NT/2000/ME/XP program that allows you to download individual files (or lists of files) from the Web and FTP sites at the maximum available speed. Multiple downloading channels technology significantly decreases the time necessary to download files. MD also allows you to browse Zip archives before loading them and to choose only the desired files to download, a feature offered by no other file downloading program. It has... [Click Here to Download]

Administrivia

Tech Help and How To


Summer Philly Guitar Show - it?s Lefty Time!!!

Spire Expands Into PSUs

Microsoft VP Says Google OS Is Defensive Only

Aristocrats of 43rd St. JOE FRANKLIN and JON HAMMOND HammondCast KYOU Radio

Actor, UN Ambassador Danny Glover & Jon Hammond Pt. 4 of 4 KYOU Radio

Microsoft to Release Windows 7 by End of July

Our GM May Be Gearing For Total Failure

OUR GM May Be Gearing For Total Failure

Is All Not Sunny In Wintel ? ville? Intel On the Chrome OS Development Team

Hitachi Announces 2GB Deskstar

Google Chrome Operating System Is Kind Of An Anti-Operating System

Google - Find Creative Commons Images Using Image Search

Google Blogging For Dummies - Have You Read It?

Asus to Release Another Winner

Another Microsoft Milestone

Jane Dornacker R.I.P. KYOU Radio and KYCY Jon Hammond Hosting

Death Of XHTML 2 To The Birth Of HTML5

Gates and Schmidt Do Lunch

I Got Screwed Buying MySpace - Why Would I Buy Twitter?

Better Business Bureau Warns Of Social Network Scams


Subscribe via email

Enter your email address:

Delivered by FeedBurner