SECURE IT ALERT: QuickTime Movie Handling Vulnerability

Secure IT Alert Header

Homeland Secure IT Alert

Secure IT Alert for August 13, 2010

The following information comes courtesy of WatchGuard…

QuickTime Movie Handling Vulnerability Only Affects Windows Users

Severity: Medium

13 August, 2010

Summary:

  • These vulnerabilities affect: QuickTime 7.6.6 and earlier for Windows (Mac version is unaffected)
  • How an attacker exploits them: By enticing your user into viewing a maliciously crafted movie
  • Impact: An attacker could execute code on your user’s computer, potentially gaining control of it
  • What to do: Download and install QuickTime 7.6.7 for Windows or let Apple’s Software Update tool do it for you at your earliest convenience

Exposure:

Late Yesterday, Apple released a security update to fix a single vulnerability in the Windows version of QuickTime, their popular media player. According to Apple, the error logging component in QuickTime suffers from a buffer overflow vulnerability. By luring one of your users into viewing a maliciously crafted movie, an attacker can exploit this buffer overflow to execute code on that user’s computer, with that user’s privileges. Since most Windows users have local administrative privileges, attackers could often leverage this flaw to gain complete control of Windows machines. 

Though Apple’s QuickTime update only fixes one security flaw, it is a fairly risky one. If you use QuickTime in your network, we recommend you update it at your earliest convenience

Solution Path:

Apple has released QuickTime 7.6.7 to fix this security issue. Windows administrators who allow QuickTime in their network should download, test, and deploy the updated version at your earliest convenience. By default, Apple’s download bundles iTunes with QuickTime, but because iTunes often has security issues of its own, we recommend that you select the option of downloading QuickTime alone.

For WatchGuard Users:

You can mitigate the risk of this flaw by blocking .mov files with your WatchGuard appliance. QuickTime is primarily used to play .mov files, which is likely the type of movie file an attacker would leverage to exploit this flaw. You can use the HTTP, SMTP, and FTP proxy on some WatchGuard appliances to block files by their extension. If you want to block QuickTime movie files, the links below contain video instructions showing how to block them by extension (.mov). Keep in mind, this technique also blocks legitimate movies as well.

 

Status:

Apple has released updates to fix these issues.

References:

This alert was researched and written by Corey Nachreiner, CISSP.

If you require assistance with this or any other network security related issue in the Greenville / Upstate SC area, please call 864-990-4748 or email info@homelandsecureit.com

Homeland Secure IT Alert Footer

Homeland Secure IT Alert

1

Microsoft Windows 7 Professional for only $29.99?? No way… YES WAY! If you are a student…

Microsoft Windows 7 Professional

Microsoft Windows 7 Professional

Yes, the subject is correct! Microsoft is offering students the deal of a lifetime…   Windows 7 Professional for only $29.99!

Follow this link to get the whole scoop…  In short you must have an email address ending with .edu, or be enrolled at a college listed as eligible on that site.

There is also a link at the bottom of that page for Microsoft Office Professional Academic version for $79.95, but last I checked, that link is broken.

If you have not checked out Microsoft Windows 7 and Microsoft Office yet, you should do so using the free trials that are available, or if you happen to be a student, upgrade to both for only 100 bucks!?!  What a great deal! What a way to start out the new school year, with the latest software!

If you really need a reason to upgrade other than features and having the latest, how about security? Windows 7 Professional and Office 2010 Professional address security better than any previous version!

Students with Macs are loading Windows 7 Professional on their computers for compatibility with the latest software and requirements of colleges, giving them the best of both worlds!

If you require assistance, please email info@homelandsecureit.com or call 864-990-4748 – we can provide help in installing either of these software packages to those in the Greenville / Upstate SC area.

1

Video security / surveillance for your home may be more affordable than you think

Caught in the act thanks to a security camera

Caught in the act thanks to a security camera

Do you ever wonder what is going on at your home when you are not there? Maybe you just want to know if someone approaches your door, or if a vehicle pulls into your driveway?

Call me paranoid, but I do!  We have surrounded our home and businesses with full color, night-vision cameras that record to a DVR (Digital Video Recorder) and in the event of motion, will send alerts in email to our phones, allowing us to see what we are missing out on.

In addition to that, we can view our cameras using a supported smart phone or any computer equipped with a web browser from anywhere in the world. This has come in handy several times, such as the other day when our alarm company called and said the fire alarm was going off at our home. Talk about a scary moment, but having the ability to see that the house was not full of smoke helped set our mind at ease and to cancel the call to the fire department (before they charged us money).

We receive discounts on our home and business insurance thanks to having both premise security in the form of intrusion detection alarms with smoke/fire/glass break and video surveillance keeping a watchful eye over the property. The cost of the alarms and video security will pay for themselves in reduced insurance premiums.

Camera systems have dropped dramatically in price over the last few years allowing home owners to experience the same security as businesses.

Whether you want a single camera watching your front door, or possibly facing towards where your boat / PWC is parked, or complete 360 degree exterior protection, it is all possible! Please call us at 864-990-4748, email info@homelandsecureit.com or stop by our offices if you would like more information about what is available or to see a demonstration of an installed system!

1

SECURE IT ALERT: Microsoft August Security Bulletin Update

Secure IT Alert Header

Homeland Secure IT Alert

Homeland Secure IT Alert for Wednesday, August 11, 2010

Microsoft has updated their August Security Bulletin as of August 10, 2010…

A webcast is scheduled for 2:00 PM Eastern on August 11, 2010 – Register here

The following information was provided courtesy of US-CERT National Cyber Alert System
Technical Cyber Security Alert TA10-222A:

Systems Affected

  • Microsoft Windows
  • Microsoft Office
  • Internet Explorer
  • Microsoft .NET Framework
  • Microsoft Silverlight

Overview

Microsoft has released updates to address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft .NET Framework, and Microsoft Silverlight.

I. Description

The Microsoft Security Bulletin Summary for August 2010 describes multiple vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft .NET framework, and Microsoft Silverlight. Microsoft has released updates to address the vulnerabilities.

One of the bulletins released, MS10-046, addresses a previously identified vulnerability in the Windows Shell that is actively being exploited.

II. Impact

A remote, unauthenticated attacker could execute arbitrary code or cause a vulnerable system or application to crash.

III. Solution

Apply updates

Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for August 2010. The security bulletin describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. Administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS).

IV. References

Microsoft Security Bulletin Summary for August 2010 –http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx
Microsoft Security Bulletin MS10-046 – http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx
US-CERT Vulnerability Note VU#940193 – http://www.kb.cert.org/vuls/id/940193
Microsoft Windows Server Update Services – http://technet.microsoft.com/en-us/wsus/default.aspx


Summary:In short, apply updates to all your Microsoft Windows based systems ASAP using Microsoft Updates or WSUS.

If you require assistance with Microsoft Windows Updates or WSUS, please call us at 864-990-4748 or email info@homelandsecureit.com

Homeland Secure IT Alert Footer

Homeland Secure IT Alert

Computer Service: Operating System Not Found error may not be anything to cry over

What ever you do - don't panic!

Whatever you do - Don't panic...

It seems like once a month or so we get a phone call from someone who is freaking out over their computer not booting up…

In the case of the system giving a blank / black screen, or the even more ominous “Operating System Not Found” / “Missing operating system” message and nothing further upon boot up, you might be surprised to find that the solution is easy…

Many newer computers come from the factory with the ability to boot from external media, such as USB hard drives, flash memory sticks, card readers, smart phones such as the iPhone, digital cameras and other devices. This applies to machines running Microsoft Windows XP, Vista, 7, and even Windows Server.

I always suggest to the person with the trembling voice that they take a deep breath, and unplug anything they may have plugged into the computer since the last time it was booted up. Remove any memory cards, flash drives, USB devices, etc. Make sure there are no disks in the CD drive or floppy drive (What? Someone uses a floppy?) and then reboot.

In more cases than I could possibly remember, their machine will boot up as normal and their blood pressure will drop tremendously.

I have heard stories that unscrupulous computer service technicians will “diagnose” this problem as a faulty hard drive and charge the client for unnecessary computer repair and parts. Hopefully, if this is the case, you will not fall into that trap because you just read this post. If I saved you from a heart attack, please respond here, or buy me a coffee.

The computer can be set to NOT boot from USB devices in most cases, so if you encounter this regularly and wish to make that change, it should be possible in the BIOS. Should you require assistance with that, or your system does NOT boot up even with USB and memory devices unplugged, please give us a call at 864-990-4748 or email info@homelandsecureit.com. We offer complete computer service, repair and sales to Greenville / Upstate SC.

1

Free Trial of Microsoft Business Productivity Online Suite #cloudcomputing #bpos

Microsoft Business Productivity Online Suite

Microsoft BPOS

Are you tired of dealing with POP3 or IMAP mail from your ISP? Tired of SLOW email? Do you want to share calendars between coworkers? Do you want to see the same contacts, calendar entries and emails on your phone as you do in your Outlook on your desktop and also via a web interface? Do you want your mobile workforce to have access to the same resources you do, including public / shared calendars & contacts? Want support for your Mac, Apple iPhone, iPad, Android, Blackberry?

Then Microsoft Exchange is the way to go, however, there are costs associated with hosting your own Exchange server that are unattractive to many smaller businesses.

Fortunately there are Hosted / In-The-Cloud alternatives, such as Microsoft’s Own BPOS, the Microsoft Business Productivity Online Suite which features a Hosted Exchange server, SharePoint, Office Live Meeting and Office Communications Online. Using BPOS can eliminate the need to purchase, deploy, maintain, backup and eventually upgrade a Microsoft Windows Server with Microsoft Exchange Server. The services are hosted “in the cloud”, in a data center, where all maintenance and upgrades are maintained FOR you. No need to worry with backups either.

This solution isn’t right for everybody, but it could be the answer to your problems if you have a smaller office, a large mobile workforce, a small budget or possibly no central location to place a server at. Would you like more information? Please call us at 864-990-4748 ext 201 or email info@homelandsecureit.com to arrange for a free, no obligation consultation.

Free 30 Day BPOS Trial

Free 30 Day BPOS Trial

Optionally, you can sign up for a FREE 30 day trial of BPOS – Business Productivity Online Standard Suite – This trial includes 20 user licenses for Exchange Online, SharePoint Online, Office Live Meeting, and Office Communications Online.

Homeland Secure IT offers Hosted Microsoft Online Services including the full BPOS / Business Productivity Online Standard Suite (Exchange Online, SharePoint Online, Office Live Meeting & Office Communications Online) as well as the Business Productivity Online Deskless Worker Suite (Exchange Online & SharePoint Online), and each service individually.

If you are in the Upstate / Greenville SC area, we can assist you with configuring your Outlook to work with the Hosted Exchange Online service at your location or ours.

We also offer full remote support and phone support to clients anywhere in the United States.

Microsoft Office 2010 Home & Student Edition Features & Applications

Microsoft Office 2010

Microsoft Office Home & Student Edition

Looking to upgrade to the new Microsoft Office 2010 and don’t know which version to get? Here’s a run-down on the features and applications included in the Home & Student edition of Microsoft Office 2010. This version is well suited to the typical user who works at home and does not require Outlook, Publisher, Access, etc.  I have included a link to a comparison of all the Microsoft Office 2010 suites below, and their suggested retail price.

Products and features of Microsoft Office 2010 Home & Student Edition:

  • Rich and powerful new ways to deliver your work on your computer, Windows Mobile-based smart phone or a web browser
  • Easy-to-use Tools, customizable templates, color schemes, and photo-editing capabilities
  • Work with people from different places at the same time with the new co-authoring experience
  • More ways to access your files from almost anywhere, Office 2010 puts you in control of getting things done according to your schedule
  • Simplifies your tasks and creates amazing results

Word 2010

  • Add impact to your document with new picture-editing tools.
  • Better illustrate your ideas with diagrams by turning bullet-point lists into compelling SmartArt graphics.
  • Apply new formatting effects to your text such as shadow, bevel, glow and reflection.
  • Capture and insert screenshots directly into your document.
  • Communicate with ease in many languages with improved translation tools.

Excel 2010

  • Highlight data trends by creating data charts in a single cell with new Sparklines.
  • Find the right data quickly with new filter enhancement in PivotTable views.
  • Analyze data quickly. Highlight specific data with new and improved Conditional Formatting options.
  • Display data in a dynamic and interactive way with PivotChart views.
  • Spend less time sifting through data–use the new search filter to narrow down pertinent data to display.

PowerPoint 2010

  • Embed and edit video files directly in your presentation.
  • Set videos to fade in and out and apply a variety of video styles and formats.
  • Broadcast your presentation online with new Broadcast Slide Show.
  • Captivate your audience with new transitions and improved animations.
  • Use slide sections to navigate, organize and print your presentation.

OneNote 2010

  • Use quick filing to organize notebooks, ideal when you’re working on multiple projects.
  • Apply styles and formatting to selected text to another paragraph with the new Format Painter.
  • See results as you type with improved Search functionality and view a prioritized list of Search results.
  • Easily organize and jump between your notebooks with the improved notebook Navigation Bar.
  • Take notes while working in Word, PowerPoint or in Internet Explorer and automatically link them.

Office 2010 Home & Business adds Outlook and it’s mail features! For a comparison of Microsoft Office 2010 versions visit this link

Homeland Secure IT offers sales of the entire Microsoft Office product line, whether you need Home & Student for personal use or multiple copies of Microsoft Office Professional  for your business. We also offer installation and complete computer service and repair in the Greenville and Upstate SC area! Call 864-990-4748 ext 201 or email info@homelandsecureit.com for more information…

2

Homeland Secure IT August Giveaway – Trend Micro Internet Security 2010

We have a new giveaway for the month of August here at Homeland Secure IT!

Trend Micro Internet Security

Trend Micro Internet Security is great for business or personal use!

Last month we drew for a wireless network IP security camera, before that we gave away a Cisco Flip Mino HD video camera, and this month, we are going to give away Trend Micro Internet Security 2010, THE best anti-virus packages on the market!

Two lucky winners will receive the retail version of Trend Micro Internet Security 2010 which will protect up to 3 computers from infection by trojan, virus, spyware, grayware, and other forms of malware as well as spam!  Each package retails for $49.99. Protect your Microsoft Windows XP, Vista and Windows 7 based computers from infection!

How do you enter? That’s easy! In the “Follow Me” section on the right-hand column of our blog, enter your email address and hit “Subscribe”, you will get a daily archive of this blog first thing in the morning after that. Another option is to join our mailing list/s. You can do that by visiting http://www.HomelandSecureIT.com and hitting the “Subscribe to our mailing list” link on the right side of the page.

If you subscribe to the blog and one of our mailing lists, you get TWO chances to win, if you subscribe to our blog and both mailing lists, you get THREE chances to win when we draw for the names.

Who is eligible? Homeland Secure IT provides computer service, support, repair and sales in the Greenville / Upstate SC area, so if you are in these areas, our mailing lists are probably of interest to you and if should you win one of our drawings, we will try to deliver the item to you in person or you can pick it up at our office on Mauldin Rd. in Greenville. Those who enter from outside the Upstate area are responsible for shipping and handling of the prizes.

Homeland Secure IT employees and family members who are subscribed are also eligible, however, one of us actually won the last contest and we decided to redraw. If Greg wins, he is not giving up his prize, hahah.

Those outside the USA are not eligible unless they can come here and pick up the prize in person. This offer is void where prohibited by law.

How is the drawing done? We take all names on all lists, dump them into Microsoft Excel, run a random number generator from 1 to however many is on the list and select the corresponding name. Very low tech, but hey, it works!

We will draw for two winners of the Trend Micro Internet Security 2010 package on September 1st, 2010. Winners will be announced here on this blog, in our newsletter and via social media sites like Twitter & Facebook.

GOOD LUCK!!!!