<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>PC &#38; Network Support Services Limited</title>
	<atom:link href="http://pcnss.co.uk/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcnss.co.uk</link>
	<description>IT Support for Home &#38; Small Business - Castle Cary, Somerset. BA7</description>
	<pubDate>Wed, 29 Jul 2009 07:26:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>IPv6: Oops, it&#8217;s on by default</title>
		<link>http://pcnss.co.uk/ipv6-oops-its-on-by-default/</link>
		<comments>http://pcnss.co.uk/ipv6-oops-its-on-by-default/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 07:24:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=441</guid>
		<description><![CDATA[Do you know whether your computers are actively using IPv6 or not? Better check, as the bad guys probably already know.
——————————————————————————————————————-
Microsoft began enabling IPv6 protocol by default with the release of Vista. That policy continued with Windows Server 2008 and will with Windows 7. Apple, Linux, and Solaris are also shipping their latest distributions with [...]]]></description>
			<content:encoded><![CDATA[<p><em>Do you know whether your computers are actively using IPv6 or not? Better check, as the bad guys probably already know.</em></p>
<p>——————————————————————————————————————-</p>
<p>Microsoft began enabling IPv6 protocol by default with the release of Vista. That policy continued with Windows Server 2008 and will with Windows 7. Apple, Linux, and Solaris are also shipping their latest distributions with IPv6 enabled.</p>
<p>Before continuing, I need to explain something. We all understand that IPv6 is important. I even mustered enough courage with Joe Klein’s (director of IPv6 security at <a href="http://www.commandinformation.com/" target="_blank">Command Information</a>) gracious help to write <a href="http://search.techrepublic.com.com/search/ipv6+and+michael+kassner.html" target="_blank">several articles</a> about it. So that’s no longer on my radar.</p>
<p><strong>What’s on my radar </strong></p>
<p>I’m not sure why, but computers are now shipping with IPv6 enabled. My guess would be that most OS developers figured IPv6 networks would be more predominate by now. Or that there’s no down side to enabling IPv6, so why wait.</p>
<p>I do know of one Microsoft service that requires IPv6. It’s called <a href="http://en.wikipedia.org/wiki/Windows_Meeting_Space" target="_blank">Windows Meeting Space</a>. It uses the peer-to-peer framework and IPv6 to setup ad hoc networks automatically.</p>
<p><strong>What numbers are we talking about</strong></p>
<p>The number of computers running IPv6 is staggering. Carolyn Duffy Marsan in a <a href="http://www.networkworld.com/news/2009/071309-rogue-ipv6.html" target="_blank">NetworkWorld article</a> quoted Joe Klein as saying:</p>
<p><em>“We’re probably talking about 300 million systems that have IPv6 enabled by default. We see this as a big risk.”</em></p>
<p>What I’m wondering, is how many of the people using the 300 million computers realize IPv6 is enabled or know what it means?</p>
<p><strong>What’s being exploited</strong></p>
<p>In a <a href="http://www.networkworld.com/news/2009/071309-ipv6-network-threat.html" target="_blank">concurrent article</a>, Marsan asked experts what they considered the most serious issues of running a dual stack comprised of IPv6 and IPv4. Here’s what they said:</p>
<ul>
<li><strong>Rogue IPv6 traffic</strong>: Attackers realize that most network administrators aren’t monitoring IPv6 traffic or they can’t. Because existing firewalls, IDS, or network management tools aren’t IPv6-aware. Therefore, an attacker can send malicious traffic to any computer running IPv6 and it will get through.</li>
<li><strong>IPv6 tunneling</strong>: Protocols such as <a href="http://en.wikipedia.org/wiki/Teredo_tunneling" target="_blank">Teredo</a> and <a href="http://en.wikipedia.org/wiki/ISATAP" target="_blank">Intra-Site Automatic Tunnel Addressing Protocol </a>(ISATAP) encapsulate IPv6 packets inside IPv4 packets. The morphed packets can easily pass through IPv4 firewalls and network address translation (NAT) equipment, defeating perimeter defenses purposed to sense and drop IPv6 packets.</li>
<li><strong>Rogue IPv6 equipment</strong>: Because IPv6 uses auto-configuration, an attacker can gain considerable control over computers running IPv6, simply by placing a rogue device capable of issuing IPv6 IP addresses on the network under attack. To make matters worse the device could have router attributes. Forcing all traffic to transit through it, allowing attackers to snoop, modify, or drop traffic at their whim.</li>
<li><strong>Built-in ICMP and multicast</strong>: Unlike IPv4, IPv6 requires <a href="http://en.wikipedia.org/wiki/Internet_Control_Message_Protocol" target="_blank">ICMP</a> and <a href="http://en.wikipedia.org/wiki/Multicast" target="_blank">multicast</a> traffic. That fact will significantly change how administrators approach network security. Right now, blocking ICMP and multicast traffic on IPv4 networks is the accepted practice. That will no longer work and complicated filtering of ICMP and multicast packets will be required to maintain some semblance of security.</li>
</ul>
<p><strong>Leave IPv6 enabled or not</strong></p>
<p><strong> </strong></p>
<p>Whether to leave IPv6 “enabled or not” is about as clear as mud. There’s the yes camp and there’s the no camp with the whole gray area in between littered with other opinions. I thought I’d let the experts introduced in Marsan’s article present their views:</p>
<p><strong> </strong></p>
<p><strong>Tim LeMaster</strong>: Director of systems engineering for Juniper’s federal group mentions:</p>
<p><em>“If you’re not prepared for IPv6, then the prudent thing to do is not to allow it into your network,” LeMaster says. “But you shouldn’t be blocking all IPv6 traffic for the next five years. You should only block it until you have a policy and understand the threats.”</em></p>
<p><strong> </strong></p>
<p><strong>Lisa Donnan</strong>: Vice president of advanced technology solutions at Command Information has a different viewpoint:</p>
<p><em>“We don’t recommend that you block IPv6 traffic. We are recommending that you do an audit and find out how many IPv6 devices and applications are on your network. If you have IPv6 traffic on your network, then you’ve got to plan, train, and implement IPv6.”</em></p>
<p><strong> </strong></p>
<p><strong>Sheila Frankel</strong>: Computer scientist in the Computer Security Division of the National Institutes of Standards and Technology (NIST) expresses a middle-ground viewpoint:</p>
<p><em>“Companies need to acquire a minimal level of expertise in IPv6, which will help protect them against threats. The other thing they should do is to take their outward-facing servers, those that are external to the corporation’s firewalls, and enable IPv6 on them. That way, customers from Asia with IPv6 addresses will be able to reach these servers and their own people will acquire expertise in IPv6. This will be a first step in the process.”</em></p>
<p>Frankel continues:</p>
<p><em>“IPv6 is coming. The best way is to face it head on and to decide you’re going to do it in the most secure manner possible.”</em></p>
<p><strong> </strong></p>
<p>As soon as I started receiving computers with IPv6 enabled, I turned the protocol off. My rational was why take a chance when it’s not necessary. Apparently, my choice is paying off, as my client’s computers aren’t vulnerable to these new exploit vectors.</p>
<p>That works for me for the time being at least. I don’t pretend to think my choice will work for everyone. From the above opinions, the only thing I do know for sure is that getting up-to-speed on IPv6 is important. As that knowledge will help you determine what’s in your network and computer systems best interest.</p>
<p><strong>How to disable IPv6</strong></p>
<p>Thankfully, disabling IPv6 is quite easy. I’ve provided links to Web sites that explain the process for several of the operating systems, if you’re so inclined:</p>
<p><a href="http://www.cyberciti.biz/tips/linux-how-to-disable-the-ipv6-protocol.html" target="_blank">Disable IPv6 in Linux</a></p>
<p><a href="http://www.home-network-help.com/disable-ipv6.html" target="_blank">Disable IPv6 in Windows Vista</a></p>
<p><a href="http://www.macosxhints.com/article.php?story=20050504161223778" target="_blank">Disable IPv6 in Mac OS X</a></p>
<p><strong>Final thoughts</strong></p>
<p>This is definitely a thorny subject and full of surprises. Just like every new and untested technological change. I can accept that. What’s hard to accept is that security once again appears not to be a main consideration. I hope it’s just a temporary oversight.</p>
<p>Original Article By Michael Kassner for Tech Republic:</p>
<p><a class="alignleft" title="IPv6: Oops, it's on by default" href="http://blogs.techrepublic.com.com/security/?p=1955&amp;tag=nl.e036" target="_blank">IPv6: Oops - it&#8217;s on by default</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/ipv6-oops-its-on-by-default/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows 7 Release To Manufacturing</title>
		<link>http://pcnss.co.uk/windows-7-release-to-manufacturing/</link>
		<comments>http://pcnss.co.uk/windows-7-release-to-manufacturing/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 11:09:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=437</guid>
		<description><![CDATA[Reading the many blogs etc here are some of the information that is currently in the wild:
    * There will be two major release dates: August 6th and October 22nd.
    * TechNet/MSDN subscribers will be able to download the English language version of Windows 7 Release To Manufacturing on [...]]]></description>
			<content:encoded><![CDATA[<p>Reading the many blogs etc here are some of the information that is currently in the wild:</p>
<p>    * There will be two major release dates: August 6th and October 22nd.<br />
    * TechNet/MSDN subscribers will be able to download the English language version of Windows 7 Release To Manufacturing on August 6th, other languages will be available by October 1st.<br />
    * General availability (GA) for everyone else will be on October 22nd.<br />
    * Microsoft Partner Program Gold/Certified Members will be able to get the English language Release To Manufacturing via the Microsoft Partner Network (MPN) Portal on August 16th. Other languages to be available by October 1st.<br />
    * Microsoft Action Pack will see the English language Release To Manufacturing by August 23rd, and remaining languages by October 1st.<br />
    * Volume License (VL) customers with an existing Software Assurance (SA) license will be able to download Windows 7 RTM in English starting August 7th through the Volume License Service Center (VLSC). Other languages will go online within a couple of weeks.<br />
    * Volume License customers without an existing SA license will have to wait until September 1st.<br />
    * OEMs will start seeing RTM images about two days after the RTM code is finalized, so that could be by the end of the week.</p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/windows-7-release-to-manufacturing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft responds to Google&#8217;s operating system</title>
		<link>http://pcnss.co.uk/microsoft-responds-to-googles-operating-system/</link>
		<comments>http://pcnss.co.uk/microsoft-responds-to-googles-operating-system/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 13:37:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[uncategorized]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=435</guid>
		<description><![CDATA[Last week, Google announced plans to release its own operating system, one that will presumably compete with Microsoft. This week, Microsoft responds with a challenge of its own.
——————————————————————————————————————-
Last week Google announced plans to release its own operating system, one based on their Cloud technology, and one intended to compete with Microsoft’s dominance in the operating [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, Google announced plans to release its own operating system, one that will presumably compete with Microsoft. This week, Microsoft responds with a challenge of its own.</p>
<p>——————————————————————————————————————-</p>
<p>Last week Google announced plans to release its own operating system, one based on their Cloud technology, and one intended to compete with Microsoft’s dominance in the operating system market. It generated a lot of comments in the discussion section, with mostly a wait and see attitude towards how it will affect those in a user support position.</p>
<p>This week, Microsoft responds with a challenge of its own. The Financial Times (on-line) reports in its headline, “Microsoft to step up Google battle.”</p>
<p>“Microsoft is set to broaden its battle with Google this week,” reports the Financial Times, “as it pushes ahead with online versions of some of its core software, including final plans for a ‘cloud’ operating system designed to extend Windows to the internet. The news comes days after Google took aim at Microsoft with the announcement of a PC operating system of its own, dubbed Chrome OS.”</p>
<p>“The rival moves point to an intensification of the battle between the technology giants, with Google trying to extend its internet platform to PCs, and Microsoft moving in the opposite direction. While Google’s PC operating system is not due to appear in new computers until the second half of 2010, Microsoft’s cloud operating system will be launched formally this year.”</p>
<p>I don’t know about you, but I’m looking at this from two perspectives.</p>
<p>First of all, as those who provide support to end users, we always try to remain a step ahead of the next generation of technology. We’d like to know what’s coming. We have to decide whether or not we’ll support it, and if so, what’s the best course of action.</p>
<p>But secondly, I must admit, I’m watching this from the seat of a spectator, not unlike at a sporting event. We see on the field before us, two titans of technology battling each other for market dominance. We all know that a lot of technology support professionals would like to see Microsoft knocked down a few notches and are critical for its reluctance to join the open source movement. Google, on the other hand, has gotten just about as big as Microsoft, but in their own niche of technology. Google, for instance, not only dominates the search engine market, but it has actually transformed itself from a noun to a verb - something not many companies have managed to pull off. (Xerox, of course, comes to mind.)</p>
<p>What’s your take on this Google versus Microsoft challenge? How does it affect your role as a user support pro?</p>
<p>And will Google eventually become a technology demon like Microsoft has become (at least in the eyes of some)? How big will it have to get, and how much of a market share will it have to gain before technology pros want to see Google knocked down a few notches? After all, the public loves rags to riches stories, like Google, but then again, they also love to see the mighty and powerful fall.</p>
<p>Article written by Joe Rosberg of Tech Republic</p>
<p>http://blogs.techrepublic.com.com/helpdesk/?p=825&#038;tag=nl.e019</p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/microsoft-responds-to-googles-operating-system/feed/</wfw:commentRss>
		</item>
		<item>
		<title>IT professionals will not drop Windows XP quietly (if ever)</title>
		<link>http://pcnss.co.uk/it-professionals-will-not-drop-windows-xp-quietly-if-ever/</link>
		<comments>http://pcnss.co.uk/it-professionals-will-not-drop-windows-xp-quietly-if-ever/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 08:07:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=432</guid>
		<description><![CDATA[In a series of poll questions, IT professionals made it quite clear that they were not interested in migrating away from Windows XP. What do the results mean for your organization?
———————————————————————–
A couple of weeks ago, Tech Republic asked a series of poll questions about Microsoft Windows XP. That single blog post lead to close to [...]]]></description>
			<content:encoded><![CDATA[<p><em>In a series of poll questions, IT professionals made it quite clear that they were not interested in migrating away from Windows XP. What do the results mean for your organization?</em></p>
<p>———————————————————————–</p>
<p>A couple of weeks ago, Tech Republic asked a series of poll questions about Microsoft Windows XP. That single blog post lead to close to 300 separate posts in the corresponding discussion thread. The poll results are very informative and definitely give us an indication about where the TechRepublic membership stands with regard to a potential operating system migration.</p>
<p>To put it politely and succinctly — most IT professionals are not looking forward to it. In fact, many are actively and passionately against the very idea.</p>
<p>Let’s take a deeper look at the results and see what we can glean with regard to the future of Windows XP.</p>
<h2>Results</h2>
<h4>Figure A</h4>
<h5><img class="alignnone" title="Figure A" src="http://i.techrepublic.com.com/gallery/317200-457-380.png" alt="" width="457" height="345" /></h5>
<p>Obviously there is a large installed base of Windows XP deployed worldwide.</p>
<h4>Figure B</h4>
<h5><img class="alignnone" title="Figure B" src="http://i.techrepublic.com.com/gallery/317201-500-331.png" alt="" width="500" height="303" /></h5>
<p>It looks like the real loser in this poll question is Windows Vista. The vast majority of respondents are either waiting for Windows 7 or planning to keep Windows XP.</p>
<p>Another interesting data point is the lack of consideration for Linux or Mac OS X. Despite what vocal and passionate proponents of those operating systems may advocate, IT professionals in the business space are only interested in Windows — at least for right now.</p>
<h4>Figure C</h4>
<h5><img class="alignnone" title="Figure C" src="http://i.techrepublic.com.com/gallery/317202-480-444.png" alt="" width="480" height="409" /></h5>
<p>Backing up the previous result is this question regarding which operating systems have been tested as a possible replacement for XP. A decent percentage of IT professionals have tested the potential of Linux, but the majority of respondents are still squarely in the Windows camp.</p>
<h4>Figure D</h4>
<h5><img class="alignnone" title="Figure D" src="http://i.techrepublic.com.com/gallery/317203-481-474.png" alt="" width="481" height="439" /></h5>
<p>While legacy applications are definitely a major consideration, they don’t seem to be the major obstacle to operating system migration.</p>
<h4>Figure E</h4>
<h5><img class="alignnone" title="Figure E" src="http://i.techrepublic.com.com/gallery/317204-477-545.png" alt="" width="477" height="510" /></h5>
<p>This is the first poll question to deal with the actual practical deployment of a new operating system. It is abundantly obvious that many IT professionals are not ready to implement a migration. Unless there is a catalyst that cannot be ignored, Windows XP is going to remain the primary operating system for many organizations for as long as it is feasible.</p>
<p>The discussion thread following the first blog post backs the response to this question. Many posters in the discussion were determined to keep Windows XP as absolutely long as they can.</p>
<h4>Figure F</h4>
<h5><img class="alignnone" title="Figure F" src="http://i.techrepublic.com.com/gallery/317205-480-507.png" alt="" width="480" height="472" /></h5>
<p>The two primary reasons Windows XP looks destined to remain a factor for some time to come is that it works and that Vista is not perceived as a viable replacement. Without some sort of catalyst to force a migration, the deployment of any operating system besides XP will be slow and methodical.</p>
<h4>Format G</h4>
<h5><img class="alignnone" title="Figure G" src="http://i.techrepublic.com.com/gallery/317206-479-452.png" alt="" width="479" height="417" /></h5>
<p>The concept of a methodical rollout is confirmed by the results of this poll question. Most IT professionals have no plans to roll out a company-wide deploy of a new operating system. Rather, new operating systems, if they are to be introduced at all into an organization, are mostly likely going to trickle in with new equipment.</p>
<h4>Figure H</h4>
<h5><img class="alignnone" title="Figure H" src="http://i.techrepublic.com.com/gallery/317207-481-390.png" alt="" width="481" height="355" /></h5>
<p>Once again, we see in the response to this poll question that operating systems other than some form of Windows are not really being considered. The implication is that IT professionals have very little interest in migrating away from Windows XP no matter what other operating system you ask them to consider.</p>
<h2>Bottom line</h2>
<p>Looking over the poll results, it leaves little doubt that the general consensus is against operating system migration until it is absolutely necessary. Windows XP is working just fine for many and, so far, no feasible or practical reason has presented itself as a catalyst that will drive IT professionals to consider a change. It looks like Windows XP is going to be around for longer than Microsoft may have suspected.</p>
<p>Original Article > <a href="http://blogs.techrepublic.com.com/window-on-windows/?p=1292&#038;tag=nl.e064" target=_"blank">IT professionals will not drop Windows XP quietly (if ever)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/it-professionals-will-not-drop-windows-xp-quietly-if-ever/feed/</wfw:commentRss>
		</item>
		<item>
		<title>10 ways to secure the Apple iPhone</title>
		<link>http://pcnss.co.uk/10-ways-to-secure-the-apple-iphone/</link>
		<comments>http://pcnss.co.uk/10-ways-to-secure-the-apple-iphone/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 12:38:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[apple]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=426</guid>
		<description><![CDATA[Learn about the many options you can leverage to increase security of the Apple iPhone. 


The Center for Internet Security (CIS) is well -known for developing security benchmarks for operating systems, applications, network devices, and now the Apple iPhone. I’ve read the iPhone benchmark and felt that TechRepublic’s 10 Things format would be the perfect [...]]]></description>
			<content:encoded><![CDATA[<p><em>Learn about the many options you can leverage to increase security of the Apple iPhone. </em></p>
<h3>
<hr size="2" /></h3>
<p>The <a href="http://www.cisecurity.org/index.html" target="_blank">Center for Internet Security</a> (CIS) is well -known for developing security benchmarks for operating systems, applications, network devices, and now the Apple iPhone. I’ve read the iPhone benchmark and felt that TechRepublic’s 10 Things format would be the perfect way for me to pass along some of their advice. The complete document can be found at the <a href="http://www.cisecurity.org/benchmarks.html" target="_blank">CIS benchmark portal</a>. So let’s make sure your iPhone is secure.</p>
<h2>1: Make sure firmware is up to date</h2>
<p>Like computer operating system software, keeping the iPhone’s firmware up to date is important in reducing the vulnerability footprint. The latest version of firmware is 2.2.1. Select Settings | General | About to determine what version the iPhone is using. If the iPhone is using an older version, follow the steps below to update the firmware:</p>
<ol>
<li>Connect the iPhone to the computer.</li>
<li>Open iTunes.</li>
<li>Select iPhone under Devices in the source list.</li>
<li>Select Check For Update.</li>
<li>Select Download And Install.</li>
</ol>
<h2>2: Disable Wi-Fi when not in use</h2>
<p>This is self-apparent, yet important enough to include in the list. Most people automatically disable Wi-Fi to conserve the battery. But knowing that disabling Wi-Fi eliminates an attack vector may be added incentive to turn Wi-Fi on only when needed. Use the following steps to disable Wi-Fi:</p>
<ol>
<li>Tap Settings.</li>
<li>Tap Wi-Fi.</li>
<li>Turn Wi-Fi off.</li>
</ol>
<h2>3: Disallow automatic association to networks</h2>
<p>By default, the iPhone retains association settings of the Wi-Fi networks it connects to, which allows the phone to automatically reconnect when within range. Automatic association isn’t recommended, as it’s easy to spoof trusted networks. Still, disallowing automatic association is kind of a pain, as doing so requires you to enter the passkey each time. I’ll leave this one up to you. To prevent automatic association use the following steps:</p>
<ol>
<li>Tap Settings.</li>
<li>Select Wi-Fi (make sure Wi-Fi is on).</li>
<li>Tap the blue arrow of the network to forget.</li>
<li>Select Forget This Network.</li>
</ol>
<h2>4: Turn Bluetooth off when not being used</h2>
<p>Features that make life easier for the user tend to make it easier for bad guys as well. Bluetooth is one such feature; it allows many conveniences, such as the use of wireless headsets and sharing information between phones. Yet attackers can also use it to <a href="http://en.wikipedia.org/wiki/Bluejacking" target="_blank">Bluejack</a> or <a href="http://en.wikipedia.org/wiki/Bluesnarfing" target="_blank">Bluesnarf</a> a phone.</p>
<p>For some reason, the iPhone isn’t set up to just turn off discovery. So the only way to prevent unwanted discovery and associations is to use the following steps to turn Bluetooth off:</p>
<ol>
<li>Pick Settings.</li>
<li>Tap General.</li>
<li>Tap Bluetooth.</li>
<li>Turn Bluetooth off.</li>
</ol>
<h2>5: Disable location services until needed</h2>
<p>Turning location services off doesn’t immediately increase security; it just prevents the user’s location from being published. I personally think disabling the service is a good idea for two reasons. First, it’s a significant battery drain. Second, disabling the service isn’t an inconvenience. It’s simple to turn the location service back on from within the application that needs positioning information. If so desired, follow the steps below to disable location services:</p>
<ol>
<li>Tap Settings.</li>
<li>Tap General.</li>
<li>Turn Location Services off.</li>
</ol>
<h2>6: Set a passcode</h2>
<p>Setting a passcode definitely increases the security of the iPhone. It makes it harder for someone to gain access to the iPhone because the phone automatically locks after a user-determined amount of inactivity. Setting a passcode is also required for feature seven to work. Use the following steps to set a passcode:</p>
<ol>
<li>Select Settings.</li>
<li>Select General.</li>
<li>Tap Passcode Lock.</li>
<li>Enter a four-digit passcode.</li>
<li>Re-enter the same passcode.</li>
</ol>
<h2>7: Erase data if too many wrong passcodes are entered</h2>
<p>After 10 wrong passcode attempts, user settings and any data stored on the iPhone will be erased if this setting is enabled. It’s a valuable feature because a four-digit passcode of just numbers will eventually be discovered, and this option ensures that any sensitive information will not get into the wrong hands. Use the following steps to turn erase data on:</p>
<ol>
<li>Select Settings.</li>
<li>Tap General.</li>
<li>Choose Passcode Lock.</li>
<li>Turn Erase Data on.</li>
</ol>
<h2>8: Erase data before returning or repairing the iPhone</h2>
<p>To some, this may be apparent, but many people don’t even think about removing sensitive data before selling or sending their phone in for repair. Use the following steps to prevent others from accessing your personal information:</p>
<ol>
<li>Select Settings.</li>
<li>Tap General.</li>
<li>Choose Reset.</li>
<li>Select Erase All Contents And Settings.</li>
</ol>
<h2>9: Disable SMS preview</h2>
<p>Even when the iPhone is locked, it’s still possible to preview a recently received text message. I immediately disabled SMS preview on my iPhone, as I do not want my text messages visible when the phone is locked. If you agree, use the following steps to turn off SMS preview:</p>
<ol>
<li>Select Settings.</li>
<li>Tap General.</li>
<li>Choose Passcode Lock.</li>
<li>Turn Show SMS Preview off.</li>
</ol>
<h2>10: Disable JavaScript and plug-ins in Safari</h2>
<p>Because the iPhone uses a fully functional Web browser, it is susceptible to all the same <a href="http://www.governmentsecurity.org/hacking_javascript" target="_blank">JavaScript </a>and <a href="http://www.clazh.com/cupertino-weve-got-a-problem-security-exploit-in-safari/" target="_blank">plug-in</a> exploits that plague normal computers. I recommend disabling JavaScript and plug-ins, but doing so breaks certain Web page characteristics. It’s yet another balancing act between security and usability. If you want to err on the side of security, use the following steps to disable both:</p>
<ol>
<li>Select Settings.</li>
<li>Tap Safari.</li>
<li>Turn JavaScript off.</li>
<li>Turn Plug-Ins off.</li>
</ol>
<h2>Final thoughts</h2>
<p>Most of the above security enhancements are intuitive, but I’ve found that unless prodded, most people don’t take advantage of them. I can’t in good conscious say that applying all of these enhancements is the only way; that’s going to be up to you. I just wanted to make sure everyone knew what was available. I also want to thank CIS again for its diligence in preparing the iPhone security benchmark.</p>
<p>Original article published by Michael Kassner of Tech Republic</p>
<p><a class="alignleft" title="10 Ways To Secure The Apple iPhone" href="http://blogs.techrepublic.com.com/10things/?p=793" target="_blank">10 Ways To Secure The Apple iPhone</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/10-ways-to-secure-the-apple-iphone/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Dangerous Microsoft DirectX vulnerability under attack</title>
		<link>http://pcnss.co.uk/dangerous-microsoft-directx-vulnerability-under-attack/</link>
		<comments>http://pcnss.co.uk/dangerous-microsoft-directx-vulnerability-under-attack/#comments</comments>
		<pubDate>Fri, 29 May 2009 13:54:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[malware]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[windows server]]></category>

		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=424</guid>
		<description><![CDATA[Microsoft today warned that hackers are using rigged QuickTime media files to exploit an unpatched vulnerability in DirectShow, the APIs used by Windows programs for multimedia support.
The company has activated its security response process to deal with the zero-day attacks has issued a pre-patch advisory with workarounds and a one-click “fix it” feature to enable [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft today warned that hackers are using rigged QuickTime media files to exploit an unpatched vulnerability in DirectShow, the APIs used by Windows programs for multimedia support.</p>
<p>The company has activated its security response process to deal with the zero-day attacks has issued a pre-patch advisory with workarounds and a one-click “fix it” feature to enable the mitigations.</p>
<p>From the <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx" target="_blank">advisory</a>:</p>
<p>Microsoft is aware of limited, active attacks that use this exploit code. While our investigation is ongoing, our investigation so far has shown that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are vulnerable; all versions of Windows Vista and Windows Server 2008 are not vulnerable.</p>
<p>An entry on the MSRC blog provides <a href="http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx" target="_blank">more details</a>:</p>
<p>The vulnerability is in the QuickTime parser in Microsoft DirectShow. An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail. While this isn’t a browser vulnerability, because the vulnerability is in DirectShow, a browser-based vector is potentially accessible through any browser using media plug-ins that use DirectShow. Also, we’ve verified that it is possible to direct calls to DirectShow specifically, even if Apple’s QuickTime (which is not vulnerable) is installed.</p>
<p>Interestingly, the vulnerable component was removed from Windows Vista and later operating systems but is still available for use in the Microsoft Windows 2000, Windows XP, and Windows Server 2003 operating systems.</p>
<p>Vulnerable Windows users should immediately consider disabling QuickTime parsing to thwart attackers.  This <a href="http://support.microsoft.com/kb/971778" target="_blank">KB article provides fix-it button</a> that automatically enables the workaround.</p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/dangerous-microsoft-directx-vulnerability-under-attack/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware of Online Drive-by Download Attacks</title>
		<link>http://pcnss.co.uk/beware-of-online-drive-by-download-attacks/</link>
		<comments>http://pcnss.co.uk/beware-of-online-drive-by-download-attacks/#comments</comments>
		<pubDate>Fri, 29 May 2009 08:39:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=422</guid>
		<description><![CDATA[Drive-by download attacks are the latest threat to plague web users. The term is used to describe malware and virus infections whereby your PC is infected simply by visiting a malicious webpage, without you actually having to click on any links in order to initiate the infection - the malicious site will download infected files [...]]]></description>
			<content:encoded><![CDATA[<p>Drive-by download attacks are the latest threat to plague web users. The term is used to describe malware and virus infections whereby your PC is infected simply by visiting a malicious webpage, without you actually having to click on any links in order to initiate the infection - the malicious site will download infected files to your PC without you even noticing. It is now becoming clear that even legitimate websites can be infected with drive-by download attacks, through an exploit called cross-site scripting, so even if you believe the website you are visiting is unlikely to be harboring viruses, and belongs to a reputable organization, it could still infect your PC. </p>
<p>One of the most prolific cross-site scripting exploits, called JSRedir-R, accounts for nearly half of all infected websites. It works by using hidden Javascript code that tries to exploit weaknesses in your web browser to infect your PC. Turning off Javascript in your browser will thwart the attack, but will also mean a great many sites that rely on Javascript no longer work. </p>
<p>To keep yourself safe, we recommend that you keep your anti-virus software up to date, and upgrade your web browser to Internet Explorer 8, which includes new security features to protect against cross-site scripting exploits. </p>
<p>You can download IE8 here >>>></p>
<p><a href="http://www.microsoft.com/windows/Internet-explorer/worldwide-sites.aspx ">Internet Explorer 8</a></p>
<p>You could also install an alternative web browser such as Firefox which you can down load here >>></p>
<p><a href="http://www.mozilla-europe.org/en/firefox/">Firefox Web Browser</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/beware-of-online-drive-by-download-attacks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows 7 RC gets its first bug, and it&#8217;s a corker!!</title>
		<link>http://pcnss.co.uk/windows-7-rc-gets-its-first-bug-and-its-a-corker/</link>
		<comments>http://pcnss.co.uk/windows-7-rc-gets-its-first-bug-and-its-a-corker/#comments</comments>
		<pubDate>Tue, 12 May 2009 16:34:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=418</guid>
		<description><![CDATA[The first documented bug in the Windows 7 Release Candidate (build 7100) is a doozy.
Yesterday, Microsoft published Knowledge Base article 970789, which provides details of a problem that affects the 32-bit (x86) English-language version of Windows 7 build 7100. The problem, in short, is that the installer incorrectly sets access control lists (ACLs) on the [...]]]></description>
			<content:encoded><![CDATA[<p>The first documented bug in the Windows 7 Release Candidate (build 7100) is a doozy.</p>
<p>Yesterday, Microsoft published <a href="http://support.microsoft.com/kb/970789" target="_blank">Knowledge Base article 970789</a>, which provides details of a problem that affects the 32-bit (x86) English-language version of Windows 7 build 7100. The problem, in short, is that the installer incorrectly sets access control lists (ACLs) on the root of the system drive. The longer version is described as follows:</p>
<p>================================</p>
<p>     In the English version of Windows 7 Release Candidate (build 7100) 32-bit Ultimate, the folder that is created as the root folder of the system drive (%SystemDrive%) is missing entries in its security descriptor. One effect of this problem is that standard users such as non-administrators cannot perform all operations to subfolders that are created directly under the root. Therefore, applications that reference folders under the root may not install successfully or may not uninstall successfully. Additionally, operations or applications that reference these folders may fail.</p>
<p>    For example, if a folder is created under the root of the system drive from an elevated command prompt, this folder will not correctly inherit permissions from the root of the drive. Therefore, some specific operations, such as deleting the folder, will fail when they are performed from a non-elevated command prompt. Additionally, the following error message appears when the operation fails:</p>
<p>    Access is denied.</p>
<p>    Furthermore, the missing security descriptor entries protect non-admin file operations directly under the root.</p>
<p>================================</p>
<p>A hotfix is available as an important update that should be delivered and installed automatically by Windows Update, assuming you have set up automatic updates. On one test system that I checked just now, the update had already been installed overnight. On two other systems, the update had been downloaded but was awaiting installation.</p>
<p>The hotfix package fixes the security descriptor of the root of the system drive, but it does not repair applications that are already installed, nor does it affect the permissions of folders that were created after the installation.</p>
<p>If you installed the x64 version of Windows 7, you are apparently unaffected by this issue.</p>
<p>If you haven’t yet installed the Windows 7 RC, it’s important to install this hotfix after you set up Windows and before you install any programs or restore any backed-up data.</p>
<p>This sounds like a pretty serious bug, and I’m surprised that it slipped through into the release candidate.</p>
<p><a href="http://blogs.zdnet.com/Bott/?p=1003&#038;tag=nl.e019" target="_blank"><br />
Original Article From ZDNet</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/windows-7-rc-gets-its-first-bug-and-its-a-corker/feed/</wfw:commentRss>
		</item>
		<item>
		<title>10 Things To Consider When Planning Windows 7 Upgrades</title>
		<link>http://pcnss.co.uk/10-things-to-consider-when-planning-windows-7-upgrades/</link>
		<comments>http://pcnss.co.uk/10-things-to-consider-when-planning-windows-7-upgrades/#comments</comments>
		<pubDate>Sun, 10 May 2009 07:49:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=412</guid>
		<description><![CDATA[By Debra Littlejohn Shinder, MVP (Enterprise Security)
Windows 7 hasn’t even been released yet, but the buzz around it indicates that many individuals are chompin’ at the bit to upgrade as soon as it hits the market.
Despite this enthusiasm, however, much has been made of a recent survey by Dimensional Research. According to the survey, 84% [...]]]></description>
			<content:encoded><![CDATA[<p><strong>By Debra Littlejohn Shinder, MVP (Enterprise Security)</strong></p>
<p>Windows 7 hasn’t even been released yet, but the buzz around it indicates that many individuals are chompin’ at the bit to upgrade as soon as it hits the market.</p>
<p>Despite this enthusiasm, however, much has been made of a recent survey by Dimensional Research. According to the survey, 84% of 1,100 IT professionals surveyed said they don’t plan to upgrade to Windows 7 in the next year, 16% do intend to upgrade in the next 12 months, and 42% expect to upgrade within 12 to 24 months. In addition, 43% said the current economic downturn is one of the reasons they will delay upgrading to Windows 7. That would seem to indicate that improvement in the economy over the next year might change the upgrade numbers. It’s also possible that this month’s discontinuation of mainstream support for Windows XP, which most of the companies are currently using on the desktop, may influence some to upgrade more quickly than they might otherwise.</p>
<p>Sooner or later, it’s likely that most home users and businesses will be upgrading from their current operating system to Windows 7. In this article, we’ll address 10 things you should keep in mind when you begin planning an upgrade to Windows 7.</p>
<p><strong>Do I need to buy new hardware?</strong></p>
<p>Many people equate upgrading the operating system to the need to buy a new computer or, at the very least, add RAM and perhaps a bigger hard drive to their present systems. That’s because traditionally, each new version of Windows has needed more disk space and memory than its predecessor.</p>
<p>Will you need to buy new hardware if you want to use Windows 7? That depends. Microsoft’s recommended hardware specifications for Windows 7 Release Candidate include a 1 GHz processor, at least 1 GB of RAM, DirectX 9.0 support, 16 GB of free disk space, and 128 MB of graphics memory (for Aero). Those requirements are pretty much the same as the published system specs for Vista Home Premium/Business/Enterprise/Ultimate (the only difference is that the Vista specs list 15 GB of disk space). Many beta testers report that Windows 7 runs faster on their low-powered machines (512 MB of RAM) than does Vista.</p>
<p><em><strong>Rule of thumb:</strong></em> If your computer is powerful enough to run Vista acceptably, it will probably run Windows 7 as well or better. If you’re currently using XP on a computer with less than 512 MB of RAM or a processor that’s slower than 800 MHz, you’ll need to upgrade your hardware.</p>
<p><strong>Can I upgrade directly from XP?</strong></p>
<p>Many folks who are still running Windows XP want to know whether they can upgrade to Windows 7 without losing all their preferences and settings. The answer is, well, sort of. Microsoft is not providing a direct upgrade path from Windows XP to Windows 7. An in-place upgrade is available only if you’re running Vista SP1 or later. If you’re running XP, even if your hardware is sufficient, you’ll have to do a clean installation of Windows 7. However, you can use the Microsoft Deployment Tool 2010, which includes the User State Migration Tool, to transfer your user settings for the desktop and applications to the new Windows 7 installation.</p>
<p><strong>Can I do a Vista in-place upgrade?</strong></p>
<p>If you’re running Windows Vista, note that you must install SP1 or SP2 before you can do an in-place upgrade to Windows 7. If you try to upgrade a Vista computer that doesn’t have a service pack installed, you&#8217;ll get a message informing you that “to upgrade to Windows 7, the computer needs to be running Vista with Service Pack 1.”</p>
<p><strong>Can I upgrade from Windows 7 beta to final release?</strong></p>
<p>Many people are currently running either the public beta of Windows 7 (build 7000) that was released in January or one of the subsequent builds that has been leaked to various peer-to-peer sites since then. Many of them are wondering whether they’ll be able to do an in-place upgrade to the RC and/or final release.</p>
<p>Microsoft has recommended that beta testers go back to Vista and upgrade from it to the final release, but that’s something many will resist. Another option is to do a clean install, but again, many folks are using Windows 7 now on their mission-critical desktops and notebooks, and they don’t want to have to start all over. In deference to them, Microsoft representatives have said that it will be possible to upgrade from the beta, but it won’t be easy; it will involve a number of steps. The installer will tell you “no” when you attempt to do an upgrade from an earlier build of Windows 7. There&#8217;s a procedure to bypass the version check so you can do the upgrade anyway.</p>
<p>Microsoft asks that you do this only if you “absolutely require” it. It’s likely that you’ll have a much more stable OS if you do a clean installation.</p>
<p><strong>Will there be driver compatibility issues?</strong></p>
<p>A big complaint about Windows Vista was driver incompatibility. Too many people upgraded their OS from XP to Vista only to find that a favorite peripheral, such as a printer or scanner, would no longer work. Vista also introduced a new display driver model, WDDM, which required video card vendors to write completely different display and video miniport drivers. And security enhancements in Vista affected how the OS handles drivers. Even though Vista was in development for five years, many hardware vendors did not have Vista drivers ready for all of their products when the OS was released.</p>
<p>Now that Vista has been out for more than two years, most hardware vendors have updated their drivers to work with it. Because Windows 7 uses the same driver models as Vista, the vast majority of hardware devices that work with Vista will work with Windows 7. For Vista drivers that won’t install on Windows 7, you can usually solve the problem by installing in Compatibility Mode. To do this, right-click the driver’s setup file, select Properties, click the Compatibility tab, enable compatibility mode, and select the appropriate operating system from the drop-down box.</p>
<p><strong>Will there be application compatibility issues?</strong></p>
<p>As with drivers, most applications that run on Windows Vista will run on Windows 7. You may need to enable Compatibility Mode on some applications, as described above. Interestingly, some applications that ran on XP and would not run on Vista will run on Windows 7. Microsoft reported in March that it had identified at least 30 old applications that will run on Windows 7 although they failed to do so on Vista. These are being referred to as “rescued applications.”</p>
<p><strong>What if I have apps that won’t run on Windows 7, even in Compatibility Mode?</strong></p>
<p>There may be some XP applications that you can’t get to run on Windows 7, even using Compatibility Mode. In the past, that might have been considered a reason not to upgrade. However, you may still be able to enjoy all the benefits of Windows 7 without giving up your favorite apps, thanks to a new compatibility feature called XP Mode. XPM is a host-based virtualization solution that will reportedly be made available at no cost to users of Windows 7 Professional, Enterprise, and Ultimate editions.</p>
<p>XPM includes a fully licensed copy of XP that runs in a virtual machine on your Windows 7 computer. This differs from just installing XP on Virtual PC or VMware. The virtualized applications appear like local applications on the Windows 7 desktop because they&#8217;re published to the Win 7 host operating system. With XPM, you will be able to run any XP application on Windows 7.</p>
<p><strong>Should I wait for Windows 7 release to buy a new computer?</strong></p>
<p>Some individual computer users may be wondering if they should wait until Windows 7 is released to buy a new computer, to ensure that the system will work with the new OS. An advantage of waiting is that after Windows 7 is released, you’ll be able to buy a computer that has it preinstalled, so you won’t need to upgrade.</p>
<p>However, if you need a new system now, there is no need to suffer with an outdated, slow, or defective system. A Vista system purchased now will in all likelihood run Windows 7 with no problems. But even though you don’t need to wait until the final release, you might want to wait until June 1 to make your purchase. Buying a Vista system after that date will make you eligible for a free Windows 7 upgrade license. (This applies to Vista Home Premium, Business, or Ultimate editions.)</p>
<p><strong>Which edition of Windows 7 should I choose?</strong></p>
<p>A big complaint about Vista is that there are too many editions to choose from. Windows XP offered only two retail editions: Professional and Home. (XP Media Center edition and Tablet PC edition were available only to OEMs.) But Vista offers a large and sometimes confusing array of options: Home Basic, Home Premium, Business, and Ultimate. (Starter is available only in “emerging markets,” and Enterprise is available only to volume licensing customers.)</p>
<p>Windows 7 will also have both Home Basic and Home Premium editions. The equivalent of Vista Business edition will revert to the Professional moniker. As far as we can tell, Enterprise and Ultimate editions will be the same, except that the former is sold only through volume licensing. There will also be a Starter edition, which will be installed on low-powered netbooks.</p>
<p>A major change is that each successive Windows 7 edition will include all features of the lower cost ones. Many Vista Business and Enterprise users were annoyed that they didn’t get Windows Media Center, DVD Maker, and other consumer-oriented features that came in Vista Home Premium. Since Home Premium couldn&#8217;t join a domain and lacked support for EFS and some other business-oriented features, if you wanted both, you had to buy Ultimate. Windows 7 Pro will include everything that’s in Windows 7 Home Premium, and Enterprise will include everything that’s in Business edition. Companies will be able to easily block the consumer features when they deploy Pro (or Enterprise) on their networks.</p>
<p>Most people will find that either Home Premium or Pro will fit their needs. If you need BitLocker or the ability to boot from a VHD, you’ll want Enterprise or Ultimate.</p>
<p><strong>What are the main reasons to upgrade to Windows 7?</strong></p>
<p>Why upgrade to Windows 7 rather than stay with Windows XP or Vista? If you’re still running XP, an important consideration is the fact that Microsoft ended mainstream support for XP on April 14. Although critical security updates will still be provided at no cost until 2014, additional support is provided only to customers who pay for a support contract with Microsoft.</p>
<p>Windows 7 also provides the improved graphical user interface (Aero) you get with Vista. Search is improved, and consumers with children will appreciate the parental controls feature. The most important reason to upgrade from XP is security; both Vista and Windows 7 provide much better security.</p>
<p>If you’re using Vista, some of the new features and functionality you’ll get with Windows 7 include a more streamlined GUI with a more functional taskbar that features Jump Lists; new and more sophisticated versions of Paint, Wordpad, and Calculator; easier windows management with snap-to docking; elimination of the sidebar (while maintaining support for gadgets); and new built-in troubleshooting tools. While Windows 7 still focuses on security, User Account Control (UAC) is far less in your face and more user-configurable than in Vista. Windows 7 also has built-in support for touch (if you have a touchscreen monitor). Keyboard fans will find a number of new keyboard shortcuts to help you avoid use of the mouse in many situations.</p>
<p>For administrators, Windows 7 offers new tools such as PowerShell v2, improved Group Policy, and VHD image management and deployment.</p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/10-things-to-consider-when-planning-windows-7-upgrades/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Internet Explorer + Google Chrome = security problem</title>
		<link>http://pcnss.co.uk/internet-explorer-google-chrome-security-problem/</link>
		<comments>http://pcnss.co.uk/internet-explorer-google-chrome-security-problem/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 15:31:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://pcnss.co.uk/?p=409</guid>
		<description><![CDATA[Security problems surrounding protocol handling and Web browsers have surfaced again — this time with Google Chrome and Microsoft’s Internet Explorer.
According to an advisory from the Google Chrome team, there’s an error in handling URLs with the  a chromehtml: protocol that could allow an attacker to run scripts of his choosing on any page [...]]]></description>
			<content:encoded><![CDATA[<p>Security problems surrounding <a href="http://blogs.zdnet.com/security/?p=362" target="_blank">protocol handling and Web browsers</a> have surfaced again — this time with Google Chrome and Microsoft’s Internet Explorer.</p>
<p>According to an advisory from the Google Chrome team, there’s an error in handling URLs with the  a <em>chromehtml:</em> protocol that could allow an attacker to run scripts of his choosing on any page or enumerate files on the local disk under certain conditions.</p>
<p><strong>[ SEE: <a title="Permanent Link to UPDATED: Command injection flaw found in IE: Or is it Firefox?" rel="bookmark" href="http://blogs.zdnet.com/security/?p=362" target="_blank">Command injection flaw found in IE: Or is it Firefox?</a> ]</strong><a title="Permanent Link to UPDATED: Command injection flaw found in IE: Or is it Firefox?" rel="bookmark" href="http://blogs.zdnet.com/security/?p=362" target="_blank"><br />
</a></p>
<p>The <a href="http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html" target="_blank">skinny</a>:</p>
<ul>
<li><em>If a user has Google Chrome installed, visiting an attacker-controlled web page in Internet Explorer could have caused Google Chrome to launch, open multiple tabs, and load scripts that run after navigating to a URL of the attacker’s choice.</em></li>
</ul>
<p>The “high severity” vulnerability affects Google Chrome versions 1.0.154.55 and earlier.</p>
<p>It can be exploited by malicious hackers to launch universal cross-site scripting (UXSS) attacks without user interaction under certain conditions.</p>
<p><strong>[ SEE: <a href="http://blogs.zdnet.com/security/?p=396" target="_blank">Mozilla caught napping on URL protocol handling flaw</a> ] </strong></p>
<p>IBM’s Roi Saltzman, the researcher credited with finding and reporting the issue to Google, has released an  <a href="http://blog.watchfire.com/files/google-chrome-advisory.doc" target="_blank">advisory</a> (word .doc) to explain the attack vectors and impact.</p>
<p>He warns that the flaw opens the door to two major attack vectors:</p>
<ul>
<li> Bypass the Same Origin Policy restrictions for any site (this has the same impact as Universal XSS)</li>
<li> Enumerate victim’s local files and directories</li>
</ul>
<p>“It is important to note that the way Internet Explorer processes URL protocol handlers is a known Achilles’ heel and has been widely used previously to attack other various applications,” Saltzman said.  Proof-of-concept code for this issue is <a href="http://blog.watchfire.com/wfblog/2009/04/google-chrome-universal-xss-vulnerability-.html" target="_blank">publicly available</a>.</p>
<p>Microsoft maintains the problems are not related to vulnerabilities in its code.</p>
]]></content:encoded>
			<wfw:commentRss>http://pcnss.co.uk/internet-explorer-google-chrome-security-problem/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
