<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EPC's Computer Recyling Blog &#187; microsoft</title>
	<atom:link href="http://blog.epcusa.com/tag/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.epcusa.com</link>
	<description>A blog about EPC, computer recycling, data security, and other IT related mess</description>
	<lastBuildDate>Thu, 22 Jul 2010 15:49:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Another Internet Explorer Vulnerability (&#8230;sigh)</title>
		<link>http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/</link>
		<comments>http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 22:18:14 +0000</pubDate>
		<dc:creator>Brian Wahoff</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[core security]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[windows 2000]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://blog.epcusa.com/?p=424</guid>
		<description><![CDATA[Well, here we are again. A few weeks after Microsoft pushed out a critical patch to all versions of Internet Explorer, Jorge Luis Alvarez Medina, a security consultant with Core Security Technologies provided details of another attack against the beleaguered browser. This time, an attacker &#8220;may be able to access files with an already known [...]


Related posts:<ol><li><a href='http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/' rel='bookmark' title='Permanent Link: Tech News &#8211; Internet Explorer 8 Edition'>Tech News &#8211; Internet Explorer 8 Edition</a> <small>Internet Explorer 8 Released. Improvements include: Smart Address Bar, Tab...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/' rel='bookmark' title='Permanent Link: Microsoft asks users to abandon IE6, kinda'>Microsoft asks users to abandon IE6, kinda</a> <small>Much has been written about the recent hack targeting Google,...</small></li>
<li><a href='http://blog.epcusa.com/2009/09/10-very-annoying-system-defaults/' rel='bookmark' title='Permanent Link: 10 very annoying system defaults'>10 very annoying system defaults</a> <small>I was reading 10 seriously annoying default configurations at TechRepublic...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.epcusa.com/wp-content/uploads/2010/02/cyber_crime.jpg"><img class="alignnone size-full wp-image-425" title="cyber_crime" src="http://blog.epcusa.com/wp-content/uploads/2010/02/cyber_crime.jpg" alt="" width="520" height="194" /></a>Well, here we are again. A few weeks after Microsoft pushed out a <a href="http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/">critical patch to all versions of Internet Explorer</a>, Jorge Luis Alvarez Medina, a security consultant with Core Security Technologies provided details of <a href="http://blogs.zdnet.com/security/?p=5385&amp;tag=trunk;content">another attack against the beleaguered browser</a>. This time, an attacker &#8220;may be able to access files with an already known file name and location.&#8221; If that sounds a bit scary, it should. It falls into a class of attacks called &#8220;Local File Disclosure&#8221;  and can be exploited by sending the victim to a malicious site at attempts to access files stored on your computer. The attacks leverage different design features of Internet Explorer that can be combined to do serious damage. Secunia has rated this as &#8220;<a title="Moderately  critical. Critical Level 3 of 5." href="http://secunia.com/advisories/about/">Moderately critical</a>&#8220;<span id="more-424"></span></p>
<p>So what versions are vulnerable this time? Basically all versions of IE on Windows 2000, Windows XP, and Windows 2003 Server (with <a href="http://go.microsoft.com/fwlink/?LinkId=92039">Enhanced Security  Configuration</a> disabled). Protected Mode &#8211; a feature of Internet Explorer on Vista, Windows 7, and Windows 2008, prevents the attack from succeeding.</p>
<p>The <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Microsoft Security Advisory (980088)</a> does contain a few workarounds for those stuck on a vulnerable platform:</p>
<ul>
<li>Disable Active Scripting for the Internet Zone</li>
<li>Enable Network Protocol Lockdown for the file:// protocol (Windows XP only)</li>
</ul>
<p>So far there are no known attacks in the wild, but we recommend that you take steps to protect your computers if using a vulnerable version.</p>
<p>Resources:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Microsoft&#8217;s Advisory</a></li>
<li><a href="http://secunia.com/advisories/38416/">Secunia&#8217;s Advisory</a></li>
</ul>


<p>Related posts:<ol><li><a href='http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/' rel='bookmark' title='Permanent Link: Tech News &#8211; Internet Explorer 8 Edition'>Tech News &#8211; Internet Explorer 8 Edition</a> <small>Internet Explorer 8 Released. Improvements include: Smart Address Bar, Tab...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/' rel='bookmark' title='Permanent Link: Microsoft asks users to abandon IE6, kinda'>Microsoft asks users to abandon IE6, kinda</a> <small>Much has been written about the recent hack targeting Google,...</small></li>
<li><a href='http://blog.epcusa.com/2009/09/10-very-annoying-system-defaults/' rel='bookmark' title='Permanent Link: 10 very annoying system defaults'>10 very annoying system defaults</a> <small>I was reading 10 seriously annoying default configurations at TechRepublic...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft asks users to abandon IE6, kinda</title>
		<link>http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/</link>
		<comments>http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 15:07:37 +0000</pubDate>
		<dc:creator>Brian Wahoff</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[dep]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.epcusa.com/?p=384</guid>
		<description><![CDATA[Much has been written about the recent hack targeting Google, but somewhat lost in the shuffle is that the attack specifically targets Internet Explorer 6 on Windows 2000 and Windows XP. Based on their analysis of the attack, Microsoft&#8217;s Security Research and Defense blog urges users to upgrade to a newer platform or enable DEP [...]


Related posts:<ol><li><a href='http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/' rel='bookmark' title='Permanent Link: Another Internet Explorer Vulnerability (&#8230;sigh)'>Another Internet Explorer Vulnerability (&#8230;sigh)</a> <small>Well, here we are again. A few weeks after Microsoft...</small></li>
<li><a href='http://blog.epcusa.com/2009/09/10-very-annoying-system-defaults/' rel='bookmark' title='Permanent Link: 10 very annoying system defaults'>10 very annoying system defaults</a> <small>I was reading 10 seriously annoying default configurations at TechRepublic...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/' rel='bookmark' title='Permanent Link: Tech News &#8211; Internet Explorer 8 Edition'>Tech News &#8211; Internet Explorer 8 Edition</a> <small>Internet Explorer 8 Released. Improvements include: Smart Address Bar, Tab...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-thumbnail wp-image-386" title="ie6_small" src="http://blog.epcusa.com/wp-content/uploads/2010/01/ie6_small1-150x150.jpg" alt="ie6_small" width="150" height="150" />Much has been written about the <a href="http://arstechnica.com/tech-policy/news/2010/01/furious-google-throws-down-gauntlet-to-china-over-censorship.ars">recent hack targeting Google</a>, but somewhat lost in the shuffle is that the attack specifically targets Internet Explorer 6 on Windows 2000 and Windows XP. Based on their analysis of the attack, Microsoft&#8217;s Security Research and Defense blog urges users to upgrade to a newer platform or enable DEP (only available on Windows XP Service Pack 2 or later).</p>
<p>In their blog post, <em><a href="http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx">Assessing risk of IE 0day vulnerability</a></em>, Microsoft outlines the potential impact on the main OS and browser combinations.</p>
<table border="1">
<tbody>
<tr>
<td></td>
<td><strong>Windows 2000</strong></td>
<td><strong>Windows XP</strong></td>
<td><strong>Windows Vista</strong></td>
<td><strong>Windows 7</strong></td>
</tr>
<tr>
<td><strong>Internet Explorer 6</strong></td>
<td bgcolor="red">Exploitable</td>
<td bgcolor="red">Exploitable (current exploit effective for code execution)</td>
<td>N/A<br />
(Vista ships with IE7)</td>
<td>N/A<br />
(Windows 7 ships with IE <img src='http://blog.epcusa.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> </td>
</tr>
<tr>
<td><strong>Internet Explorer 7</strong></td>
<td>N/A<br />
(IE 7 will not install on Windows 2000)</td>
<td bgcolor="yellow">Potentially exploitable (current exploit does not currently work due to memory layout differences in IE 7)</td>
<td bgcolor="green">IE Protected Mode prevents current exploit from working.</td>
<td>N/A<br />
(Windows 7 ships with IE <img src='http://blog.epcusa.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> </td>
</tr>
<tr>
<td><strong>Internet Explorer 8</strong></td>
<td>N/A<br />
(IE 8 will not install on Windows 2000)</td>
<td bgcolor="green">DEP enabled by default on XP SP3 prevents exploit from working.</td>
<td bgcolor="green">IE Protected Mode + DEP enabled by default prevent exploit from working.</td>
<td bgcolor="green">IE Protected Mode + DEP enabled by default prevent exploit from working.</td>
</tr>
</tbody>
</table>
<p>In spite of this, Microsoft still has <a href="http://arstechnica.com/microsoft/news/2009/08/microsoft-dropping-support-for-ie6-is-not-an-option.ars">no plans to drop support for IE6</a>, leaving it up to the individual to upgrade if they desire. Because of this, there are still many major corporations that have not yet upgraded from this now ancient browser &#8211; IE 7 was released over 3 years ago.</p>
<p>Even though this event is likely to not change their behavior, if upgrading the operating system is not an option, they should at least consider deploying <a href="http://www.mozilla.com/">Firefox</a> and the awesome extension <a href="https://addons.mozilla.org/en-US/firefox/addon/1419">IE Tab</a> for those times when they just have to use Internet Explorer.</p>
<p>Also &#8211; Google doesn&#8217;t get a free pass here. How is it that the maker of the <a href="http://www.pcworld.com/article/186486/chrome_browser_secure.html?tk=rss_news">most secure browser</a> still has workstations running IE6?</p>


<p>Related posts:<ol><li><a href='http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/' rel='bookmark' title='Permanent Link: Another Internet Explorer Vulnerability (&#8230;sigh)'>Another Internet Explorer Vulnerability (&#8230;sigh)</a> <small>Well, here we are again. A few weeks after Microsoft...</small></li>
<li><a href='http://blog.epcusa.com/2009/09/10-very-annoying-system-defaults/' rel='bookmark' title='Permanent Link: 10 very annoying system defaults'>10 very annoying system defaults</a> <small>I was reading 10 seriously annoying default configurations at TechRepublic...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/' rel='bookmark' title='Permanent Link: Tech News &#8211; Internet Explorer 8 Edition'>Tech News &#8211; Internet Explorer 8 Edition</a> <small>Internet Explorer 8 Released. Improvements include: Smart Address Bar, Tab...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Tech News &#8211; Internet Explorer 8 Edition</title>
		<link>http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/</link>
		<comments>http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 12:25:44 +0000</pubDate>
		<dc:creator>Brian Wahoff</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Quick Links]]></category>
		<category><![CDATA[diebold]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security tools]]></category>

		<guid isPermaLink="false">http://blog.epcusa.com/?p=70</guid>
		<description><![CDATA[Internet Explorer 8 Released. Improvements include: Smart Address Bar, Tab Groups, and Find in Page is now a task bar (finally). Microsoft Support Flooded with Complaints after IE 8 released. Top issues reported include: website printing, image positioning, slow boot times, and a bug dragging images into Facebook. Microsoft Released new security assesment tool. The [...]


Related posts:<ol><li><a href='http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/' rel='bookmark' title='Permanent Link: Another Internet Explorer Vulnerability (&#8230;sigh)'>Another Internet Explorer Vulnerability (&#8230;sigh)</a> <small>Well, here we are again. A few weeks after Microsoft...</small></li>
<li><a href='http://blog.epcusa.com/2009/04/tech-news-seesmic-desktop-edition/' rel='bookmark' title='Permanent Link: Tech News: Seesmic Desktop Edition'>Tech News: Seesmic Desktop Edition</a> <small>Seesmic Desktop Beta available: Thanks to the great video podcast,...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/' rel='bookmark' title='Permanent Link: Microsoft asks users to abandon IE6, kinda'>Microsoft asks users to abandon IE6, kinda</a> <small>Much has been written about the recent hack targeting Google,...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><img src="/wp-content/uploads/2009/03/ie8-logo-150x150.png" alt="Internet Explorer 8 released" align="right" /></p>
<ul>
<li><a href="http://arstechnica.com/microsoft/news/2009/03/mix09-internet-explorer-8-released-progress-unmistakable.ars">Internet Explorer 8 Released</a>. Improvements include: Smart Address Bar, Tab Groups, and Find in Page is now a task bar (finally).</li>
<li><a href="http://www.gadgetell.com/tech/comment/microsoft-flooded-with-complaints-after-ie-8-release/">Microsoft Support Flooded with Complaints after IE 8 released</a>. Top issues reported include: website printing, image positioning, slow boot times, and a bug dragging images into Facebook.</li>
<li><a href="http://www.theregister.co.uk/2009/03/20/microsoft_crash_tool/">Microsoft Released new security assesment tool</a>. The new tool, dubbed <a href="http://www.codeplex.com/msecdbg">!exploitable Crash Analyzer</a>, is considered a &#8220;game changer&#8221; by Dan Kaminsky, a well-known security researcher.</li>
<li><a href="http://www.securitypronews.com/insiderreports/insider/spn-49-20090318InsidersThoughtToHackRussianATMs.html">Insiders hacked Russian ATMs?</a> Diebold released a software patch to Opteva line after it was discovered that several machines were infected by a card skimming trojan.</li>
<li><a href="http://www.pcworld.com/businesscenter/article/161718/diebold_admits_voting_machine_flaw.html">Diebold admits flaw in voting machines that causes vote tallies to be lost</a>. Admission called a &#8220;disturbing revelation&#8221; by security auditor.</li>
</ul>


<p>Related posts:<ol><li><a href='http://blog.epcusa.com/2010/02/another-internet-explorer-vulnerability-sigh/' rel='bookmark' title='Permanent Link: Another Internet Explorer Vulnerability (&#8230;sigh)'>Another Internet Explorer Vulnerability (&#8230;sigh)</a> <small>Well, here we are again. A few weeks after Microsoft...</small></li>
<li><a href='http://blog.epcusa.com/2009/04/tech-news-seesmic-desktop-edition/' rel='bookmark' title='Permanent Link: Tech News: Seesmic Desktop Edition'>Tech News: Seesmic Desktop Edition</a> <small>Seesmic Desktop Beta available: Thanks to the great video podcast,...</small></li>
<li><a href='http://blog.epcusa.com/2010/01/microsoft-asks-users-to-abandon-ie6-kinda/' rel='bookmark' title='Permanent Link: Microsoft asks users to abandon IE6, kinda'>Microsoft asks users to abandon IE6, kinda</a> <small>Much has been written about the recent hack targeting Google,...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.epcusa.com/2009/03/tech-news-internet-explorer-8-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
