<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Arizona IT Management &#187; threats</title>
	<atom:link href="http://www.azitmgmt.com/tag/threats/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.azitmgmt.com</link>
	<description>Delivering Affordable Professional Solutions</description>
	<lastBuildDate>Sun, 15 Aug 2010 19:53:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Phishing and Wardriving</title>
		<link>http://www.azitmgmt.com/2010/05/phishing-and-wardriving/</link>
		<comments>http://www.azitmgmt.com/2010/05/phishing-and-wardriving/#comments</comments>
		<pubDate>Thu, 27 May 2010 15:49:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[Wardriving]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=358</guid>
		<description><![CDATA[Phishing and Wardriving are coming back around. Please read this article and familiarize yourselves. http://www.informationarmor.com/2010/05/27/the-internet/]]></description>
			<content:encoded><![CDATA[<p>Phishing and Wardriving are coming back around. Please read this article and familiarize yourselves.</p>
<p><a href="http://www.informationarmor.com/2010/05/27/the-internet/">http://www.informationarmor.com/2010/05/27/the-internet/</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/05/phishing-and-wardriving/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacks, Exploits and Patches</title>
		<link>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/</link>
		<comments>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/#comments</comments>
		<pubDate>Wed, 12 May 2010 15:47:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=351</guid>
		<description><![CDATA[Widespread Web Site Attacks Reported Following the reports of high profile web sites like syfy.com and php-nuke.org being compromised, another widespread attack on web servers has been reported. The attacks compromise sites running WordPress and other popular blog software. The attack mechanism is not yet known, but clients should ensure that the latest WordPress version [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Widespread Web Site Attacks Reported</strong><br />
Following the reports of high profile web sites like syfy.com and php-nuke.org being compromised, another widespread attack on web servers has been reported. The attacks compromise sites running WordPress and other popular blog software. The attack mechanism is not yet known, but clients should ensure that the latest WordPress version is installed. Sites using shared hosting are especially susceptible as compromise of a neighboring site often spreads to the remaining virtual hosts. We also encourage clients to review their sites for signs of infection and take appropriate remediation steps. In particular, clients should look for modifications made to html source pages as well as database table changes.<br />
<a href="http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html" target="_blank"> http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html</a><br />
<a href="http://www.psychcomp.com/syfycom-hosts-malware/" target="_blank"> http://www.psychcomp.com/syfycom-hosts-malware/</a><br />
<a href="http://twitter.com/lordparody/status/13600067003" target="_blank"> http://twitter.com/lordparody/status/13600067003</a><br />
<a href="http://www.sophos.com/blogs/sophoslabs/?p=9585" target="_blank"> http://www.sophos.com/blogs/sophoslabs/?p=9585</a></p>
<p><strong>Microsoft Outlook Express Exploit</strong><br />
Exploit code has been made publicly available that triggers a vulnerability in Microsoft Outlook Express and Windows Mail. The integer overflow vulnerability could allow a remote attacker to execute arbitrary code, although the attacker would need to control the mail server being used by the victim. At this time, there is no known vendor patch available.<br />
<a href="http://www.exploit-db.com/exploits/12564" target="_blank"> http://www.exploit-db.com/exploits/12564</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816" target="_blank"> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816</a></p>
<p><strong>Microsoft&#8217;s May Security Patches</strong><br />
As a reminder, Microsoft will be issuing their May security release later today. The two scheduled bulletins will address remote code execution vulnerabilities in Windows and Office. We will update the assessment when more details are available.<br />
<a href="http://www.microsoft.com/technet/security/Bulletin/MS10-may.mspx" target="_blank"> http://www.microsoft.com/technet/security/Bulletin/MS10-may.mspx</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>April Patches and Updates</title>
		<link>http://www.azitmgmt.com/2010/04/april-patches-and-updates/</link>
		<comments>http://www.azitmgmt.com/2010/04/april-patches-and-updates/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 16:09:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=337</guid>
		<description><![CDATA[1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP Service (MS10-024 CVE-2010-0024) Microsoft Windows SMTP Service and Microsoft Exchange are vulnerable to a denial of service, caused by the improper handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer Protocol component. As SMTP services are often exposed to the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP  Service (MS10-024 CVE-2010-0024)</strong><br />
Microsoft Windows SMTP Service and  Microsoft Exchange are vulnerable to a denial of service, caused by the improper  handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer  Protocol component. As SMTP services are often exposed to the Internet and email  is usually considered a business critical function, the business impact of this  vulnerability is more significant than for typical Denial of Service issues.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx</a></p>
<p><strong>2. Microsoft DirectShow Remote Code Execution (MS10-026  CVE-2010-0480)</strong><br />
Microsoft Windows is vulnerable to a stack-based  buffer overflow, caused by improper bounds checking by the MPEG Layer-3 audio  codecs when handling malicious files. The vulnerable MPEG Layer-3 audio codecs  are the MPEG Layer-3 Audio Codec for Microsoft DirectShow. Successful  exploitation of this issue would provide an attacker with complete control over  the endpoint target. The use of malicious media files like images and movies has  been prevalent in the past years.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx</a></p>
<p><strong>Adobe Reader and Acrobat Security Update</strong><br />
Adobe has  addressed multiple critical vulnerabilities affecting Adobe Reader 9.3.1 (and  earlier versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and  earlier versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier  versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and  Macintosh. The most severe of these issues could allow a remote attacker to  execute arbitrary code on a vulnerable system. Refer to the &#8220;Solution&#8221; section  of the Adobe Security Bulletin for information on remediating these issues.<br />
<a title="http://www.adobe.com/support/security/bulletins/apsb10-09.html" href="http://www.adobe.com/support/security/bulletins/apsb10-09.html"> http://www.adobe.com/support/security/bulletins/apsb10-09.html</a><br />
<strong><br />
Microsoft April 2010 Security Release</strong><br />
Microsoft released  eleven security bulletins today. There are five rated Critical, five rated  Important and one rated Moderate. We encourage our customers to apply the  patches and IBM product coverage where applicable. Please, review the break-down  below.<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Critical</strong><br />
<strong>Microsoft Security Bulletin MS10-019: Vulnerabilities in Windows  Could Allow Remote Code Execution (981210)</strong><br />
Vulnerabilities in  Windows Authenticode Verification could allow a remote attacker execute  arbitrary code on a vulnerable system.<br />
CVE-2010-0486<br />
CVE-2010-0487<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-020: Vulnerabilities in SMB Client  Could Allow Remote Code Execution (980232)</strong><br />
Multiple vulnerabilities  affecting Microsoft Windows could allow remote code execution. Successful  exploitation can occur if an attacker can convince a user to initiate an SMB  connection to a specially crafted SMB server.<br />
CVE-2009-3676<br />
CVE-2010-0269<br />
CVE-2010-0270<br />
CVE-2010-0476<br />
CVE-2010-0477<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-025: Vulnerability in Microsoft  Windows Media Services Could Allow Remote Code Execution (980858)</strong><br />
A  remote code execution vulnerability affects Windows Media Services running on  Microsoft Windows 2000 Server. The Windows Media Unicast Service fails to  properly handle specially crafted transport information packets. On Microsoft  Windows 2000 Server Service Pack 4, Windows Media Services is an optional  component and is not installed by default.<br />
CVE-2010-0478<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-026: Vulnerability in Microsoft MPEG  Layer-3 Codecs Could Allow Remote Code Execution (977816)</strong><br />
<strong>2. Microsoft DirectShow Remote Code  Execution (MS10-026 CVE-2010-0480)</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-027: Vulnerability in Windows Media  Player Could Allow Remote Code Execution (979402)</strong><br />
The Windows Media  Player ActiveX control is affected by a remote code execution vulnerability.<br />
CVE-2010-0268<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Important</strong><br />
<strong>Microsoft Security Bulletin MS10-021: Vulnerabilities in Windows  Kernel Could Allow Elevation of Privilege (979683)</strong><br />
This bulletin  addresses two vulnerabilities in Microsoft Windows, the most severe of which  could allow elevation of privilege. In order to exploit these vulnerabilities,  an attacker must have valid logon credentials and be able to log on locally.<br />
CVE-2010-0236<br />
CVE-2010-0237<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-022: Vulnerability in VBScript  Scripting Engine Could Allow Remote Code Execution (981169)</strong><br />
A  vulnerability affecting VBScript on Microsoft Windows could allow remote code  execution. This vulnerability requires user interaction and cannot be exploited  on Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2.<br />
CVE-2010-0483<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-023: Vulnerability in Microsoft  Office Publisher Could Allow Remote Code Execution (981160)</strong><br />
Microsoft Office Publisher is vulnerable to a remote code execution issue.  An attacker could exploit this issue by creating a specially crafted Publisher  file and sending it in an email or hosting it on a Web site.<br />
CVE-2010-0479;  IBM Product Coverage: CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-024: Vulnerabilities in Microsoft  Exchange and Windows SMTP Service Could Allow Denial of Service  (981832)</strong><br />
<strong>1. Denial  of Service Conditions in Microsoft Exchange and Microsoft SMTP Service</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-028: Vulnerabilities in Microsoft  Visio Could Allow Remote Code Execution (980094)</strong><br />
Vulnerabilities in  Microsoft Office Visio could allow remote code execution if a user opens a  specially crafted Visio file.<br />
CVE-2010-0254; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
CVE-2010-0256; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Moderate</strong><br />
<strong>Microsoft Security Bulletin MS10-029: Vulnerability in Windows  ISATAP Component Could Allow Spoofing (978338) </strong><br />
A spoofing  vulnerability exists in the Microsoft Windows IPv6 stack which could allow an  attacker to impersonate an address to bypass edge or host firewalls.  CVE-2010-0812<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/04/april-patches-and-updates/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top Tips for Twenty Ten</title>
		<link>http://www.azitmgmt.com/2010/02/top-tips-for-twenty-ten/</link>
		<comments>http://www.azitmgmt.com/2010/02/top-tips-for-twenty-ten/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 17:07:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[essentials]]></category>
		<category><![CDATA[location awareness]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[Solutions]]></category>
		<category><![CDATA[stay safe online]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=260</guid>
		<description><![CDATA[Rules of Social Networking Pay attention to what you post and upload. Social networking is public. Consider images, videos, and information you publish You shouldn’t publish your address, date of birth, etc. Use a nick-name that only your friends know. Choose your friends with care. Do not accept friend requests from people you do not [...]]]></description>
			<content:encoded><![CDATA[<h3>Rules of Social Networking</h3>
<p><strong>Pay attention to what you post and upload. Social networking is public.</strong></p>
<ul>
<li>Consider      images, videos, and information you publish</li>
<li>You      shouldn’t publish your address, date of birth, etc.</li>
<li>Use a      nick-name that only your friends know.</li>
</ul>
<p><strong>Choose your friends with care. </strong></p>
<ul>
<li>Do not      accept friend requests from people you do not know</li>
<li>Verify      all your contacts</li>
</ul>
<p><strong>Protect your work and environment and avoid reputation risk</strong></p>
<ul>
<li>When      joining a social networking site use your personal e-mail address</li>
<li>Be      careful how you portray your company online</li>
<li>Do not      mix your business contacts with your friend contacts</li>
</ul>
<p><strong>Protect your mobile phone and the information saved on it from any physical intrusion</strong></p>
<ul>
<li>Do not      let anyone see your profile or personal information without consent</li>
<li>Do not      leave your phone unattended</li>
<li>Do not      save your passwords on your mobile phone</li>
<li>Use      the security features available on your mobile phone</li>
</ul>
<p><strong>Turn off Location Aware Services</strong></p>
<ul>
<li>Twitter,      Google Buzz, Foursquare and new Smart-phones will publish your location      when you post an announcement. Letting the entire world know you aren’t      home. See the website <a href="http://pleaserobme.com/">http://pleaserobme.com/</a></li>
<li>Instead      of using a GPS to mark your home location, have your GPS set home to a      familiar landmark near your home, such as a corner store. If a thief      breaks into your car, not only do they know you aren’t home, but they      will have access to your garage door opener and turn by turn directions to      your front door.</li>
</ul>
<p><strong>When Planning Vacation</strong></p>
<ul>
<li>Do not      post dates and times you will be away, rather write posts as a journal of      events that have happened so it’s a surprise that you were gone for a      period of time.</li>
</ul>
<p><span style="font-size: small;"><br />
</span><strong>Anti-Phishing Flow Chart<img src="http://www.azitmgmt.com/wp-content/uploads/2010/02/antiphishing.png" alt="" width="600" /></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/02/top-tips-for-twenty-ten/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you sure you&#8217;re safe?</title>
		<link>http://www.azitmgmt.com/2010/01/are-you-sure-youre-safe/</link>
		<comments>http://www.azitmgmt.com/2010/01/are-you-sure-youre-safe/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 19:42:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=63</guid>
		<description><![CDATA[Holidays are the times when spammers and other anarchist types send malware related emails to everybody. Just because the holidays are now officially over, doesn&#8217;t mean your organization is safe. Many employees take vacation and the danger still exists in their mailbox awaiting for them to open. Email administrators may see an increase in infections [...]]]></description>
			<content:encoded><![CDATA[<p>Holidays are the times when spammers and other anarchist types send malware related emails to everybody. Just because the holidays are now officially over, doesn&#8217;t mean your organization is safe. Many employees take vacation and the danger still exists in their mailbox awaiting for them to open. Email administrators may see an increase in infections the week after a long holiday. Apply the best security practices and maintain up-to-date software updates and patches as well as anti-virus signatures. User education is also key in mitigating this threat.</p>
<p>With the new year&#8230; new decade upon us, let&#8217;s work together to accomplish something. Something awesome. Something amazing. Something that will make your customers go WOW! Something that will make your staff more productive, regardless of where they are. Let&#8217;s enable and empower them to be able to securely work on anything, from anywhere.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/01/are-you-sure-youre-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS and Symantec Alert Management System</title>
		<link>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/</link>
		<comments>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 17:20:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[iis]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=61</guid>
		<description><![CDATA[A vulnerability was recently reported in Microsoft IIS. Microsoft has since completed its investigation and &#8220;found that there is no vulnerability in IIS.&#8221; However, &#8220;there is an inconsistency in IIS 6 only in how it handles semicolons in URLs. It’s this inconsistency that the claims have focused on, saying this enables an attacker to bypass [...]]]></description>
			<content:encoded><![CDATA[<p>A vulnerability was recently reported in Microsoft IIS. Microsoft has since completed its investigation and &#8220;found that there is no vulnerability in IIS.&#8221; However, &#8220;there is an inconsistency in IIS 6 only in how it handles semicolons in URLs. It’s this inconsistency that the claims have focused on, saying this enables an attacker to bypass content filtering software to upload and execute code on an IIS server.&#8221; The issue only impacts IIS servers that are set up to allow both &#8220;write&#8221; and &#8220;execute&#8221; privileges on the same directory, which is not the default configuration for IIS. This issue can be mitigated through proper Web server configuration and Web application development best practices, including proper validation of user submitted file names, and by configuring Web server software so that it will not execute scripts or applications in directories where user uploaded files are stored. We would also like to note that an exploit targeting Microsoft IIS has been made publicly available. We encourage our customers to refer to the Microsoft Security Response Center (MSRC) blog post for additional information.<br />
<a href="http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx" target="_blank">http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx</a><br />
<a href="http://www.exploit-db.com/" target="_blank">http://www.exploit-db.com/</a></p>
<p>We would also like to inform our customers that a report has surfaced indicating there has been &#8220;an increase in probes to port 12174.&#8221; Our analysts have also observed an increase in activity on this port. Reportedly, these probes are targeting a vulnerability in the Intel LANDesk Common Base Agent (CBA) which is used by the Symantec Alert Management System. An attacker could exploit this issue by sending a specially-crafted packet to TCP Port 12174 and execute arbitrary code on the vulnerable system. The Alert Management System 2 (AMS2) is a component of the Symantec System Center console, Symantec AntiVirus Server, and of the Symantec AntiVirus Central Quarantine Server. To mitigate against this threat, ensure the Symantec Alert Management Systems running in your environment are up-to-date.<br />
<a href="http://isc.sans.org/diary.html?storyid=7834" target="_blank">http://isc.sans.org/diary.html?storyid=7834</a><br />
<a href="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02" target="_blank">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Threats</title>
		<link>http://www.azitmgmt.com/2009/12/adobe-threats/</link>
		<comments>http://www.azitmgmt.com/2009/12/adobe-threats/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 15:31:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=39</guid>
		<description><![CDATA[Adobe is indicating they have received reports of active exploitation of a 0day vulnerability affecting Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). We encourage our clients to use caution when opening PDF files. Links to malicious documents can easily be sent through spam or through links on seemingly non-malicious Web sites. We also [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe is indicating they have received reports of active exploitation of a 0day vulnerability affecting Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). <strong>We encourage our clients to use caution when opening PDF files</strong>. Links to malicious documents can easily be sent through spam or through links on seemingly non-malicious Web sites. We also recommend referring to the Adobe PSIRT blog for the latest information on this threat.<br />
<span title="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html"><a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_blank">http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html</a></span><br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214 " target="_blank"><span title="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214</span> </a></p>
<p>Some of the common predictions are: increased attacks targeting <strong>Microsoft 7 platforms and smartphones</strong>, more tailored and targeted attacks and continued targeting of <strong>social networking sites to distribute malware and obtain information</strong>. We have seen attackers become increasingly sophisticated over the years and their attacks harder to detect. And if you&#8217;re not technically savy? Script kiddies have professionally produced products readily available to them on the Internet. In other words, be prepared for another cyber threat filled environment in 2010.<br />
<a href="http://securitylabs.websense.com/content/Blogs/3509.aspx " target="_blank"><span title="http://www.f-secure.com/weblog/archives/00001835.html">http://www.f-secure.com/weblog/archives/00001835.html</span><br />
<span title="http://securitylabs.websense.com/content/Blogs/3509.aspx">http://securitylabs.websense.com/content/Blogs/3509.aspx</span> </a><br />
<a href="http://blog.trendmicro.com/trend-micro-2010-future-threat-report/ " target="_blank"><span title="http://blog.trendmicro.com/trend-micro-2010-future-threat-report/">http://blog.trendmicro.com/trend-micro-2010-future-threat-report/</span> </a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/adobe-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
