Archive for March 30th, 2010

Fix: Power options not enforcing 60 second limit in Windows 7

This article details a known power options issue with Windows 7 where the kernel does not adhere to the minimum allowed time that is set by the user in the Group Policy Management Console for… For more visit The Windows Club.

More »

Microsoft Responds to 2 Minute IE8 Hack

At the annual Pwn2Own contest, IE8 was hacked in less than two minutes on a fully-patched 64-bit Windows 7 installation by Peter Vreugdenhil who bypassed ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention). This allowed him to run any process on a computer that visited a website which launched his malicious code, as he had complete access to an interactive shell. Now Microsoft has responded to the incident, saying that IE8 has “some of the best safety and privacy features available today:” Protecting Windows customers is an absolute priority for the Internet Explorer engineering team

More »

Windows Live Wave 4 M2 Leaked

After nothing but screenshots for quite some time when it comes to Windows Live Essentials Wave 4, a build has finally been leaked (build number 15.2.2585.0122); however, it’s an old build as Windows Live Wave 4 is already on Milestone 3 (so far the latest report has been build number 15.3.2659.319), or maybe more (with messenger at build number 15.3.2649.311). Even so, here are the build numbers for this version: Messenger: 15.2.2583.119 Mail: 15.2.2583.0119 Writer: 15.2.2583.119 Photo Gallery: 15.2.2590.301 Movie Maker: 15.2.2590.0301 Family Safety: 15.2.2583.0119 Sync: 15.2.2587.0212 Bing Bar: 5.0.1411.0 To install this build (setup size is about 126MB), a user must be running either Vista SP2 with the Platform Update installed or Windows 7.

More »

Beyond Trust Reports that Admin Rights are a Security Risk

According to a report released by Beyond Trust, an astounding 90% of all vulnerabilities in Windows 7 can be reduced by eliminating administrator rights. Some of the key findings from this report show that removing administrator rights will better protect companies. Simply put the exploitation of : 100% of Microsoft Office vulnerabilities as reported in 2009 94% of Internet Explorer and 100% of Internet Explorer 8 vulnerabilities as reported in 2009 90% of critical Windows 7 vulnerabilities as reported to date 64% of all Microsoft vulnerabilities as reported in 2009 Beyond Trust These key findings show that the security feature that was to be provided by the admin rights has not worked.

More »