• Follow us on Twitter
    • Subscribe to our RSS Feed
    • Search Site

    • Home
    • About
    • Services
    • Contact

    You are here: Jorge Orchilles / 2010 / March

    Archive for month: March, 2010

    Out of band Microsoft patch for Internet Explorer

    Permalink
    30 Mar 2010 / 0 Comments / in Security/by Jorge Orchilles

    Microsoft released a cumulative security update which resolves nine privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. So patch now!

    The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights as reported earlier today.

    This security update is rated critical for all supported releases of Internet Explorer:
    Internet Explorer 5.01
    Internet Explorer 6 SP1
    Internet Explorer 6 on Windows clients
    Internet Explorer 7
    Internet Explorer 8 on Windows clients.
    For Internet Explorer 6 on Windows servers, this update is rated Important. And for Internet Explorer 8 on Windows servers, this update is rated Moderate.

    The security update addresses these vulnerabilities by modifying the way that Internet Explorer verifies the origin of scripts and handles objects in memory, content using encoding strings, and long URL.

    Till next time,
    Jorge Orchilles

    Windows 7 is safer as a standard user

    Permalink
    30 Mar 2010 / 0 Comments / in IT, Security/by Jorge Orchilles

    This should be common sense and not require a whole research paper but Beyond Trust released a study stating that Windows 7 is safer when using it as a standard user.

    I highlighted this fact in my book but would like to share the results of the study as well:


    Microsoft and their partners regularly identify new security vulnerabilities in Microsoft software. In 2009 Microsoft published nearly 75 security bulletins documenting and providing patches for nearly 200 vulnerabilities. By examining all of the published Microsoft vulnerabilities in 2009 and all of the published Windows 7 vulnerabilities to date, this report quantifies the continued effectiveness of removing administrator rights at mitigating vulnerabilities in Microsoft software.
    Key findings from this report show that removing administrator rights will better protect companies against the exploitation of:

    • 90% of Critical Windows 7 vulnerabilities reported to date
    • 100% of Microsoft Office vulnerabilities reported in 2009
    • 94% of Internet Explorer and 100% of IE 8 vulnerabilities reported in 2009
    • 64% of all Microsoft vulnerabilities reported in 2009
    So please, use a standard user for day to day use like most Mac and *nix users do!

    South Florida OWASP Meeting 3/31/2010

    Permalink
    30 Mar 2010 / 0 Comments / in Security/by Jorge Orchilles

    I am looking forward to the South Florida OWASP meeting and hanging out with the local InfoSec people tomorrow Wednesday March 31, 2010 at 6pm at Nova Southeastern University Carl DeSantis Building Room 1124.

    The presentation is titled: Adon’t be an Adobe victim: An overview of how recent Adobe-related flaws affect your web application by Josh Stabiner. The talk will examine recent threats posed by PDF and Flash vulnerabilities to web applications and users. It will also examine ways to mitigate the potential threats to organizations due to these vulnerabilities.
    Josh Stabiner is a manager in Ernst & Young’s Advanced Security Center specializing in attack and penetration advisory services. He manages and executes assessments of web applications, external, internal and wireless networks, as well as physical security and social engineering.
    Hope to see you there,
    Jorge Orchilles

    Final edits in! Microsoft Windows 7 Administrator’s Reference

    Permalink
    23 Mar 2010 / 0 Comments / in IT/by Jorge Orchilles

    Today I turned in the final revisions and edits to my first book coming out in the end of April: Microsoft Windows 7 Administrator’s Reference! If you are a Windows power user or system administrator or want to be one this is the book for you!

    It is available for pre-order and purchase at:
    • Amazon
    • Syngress Publishing
    • Elsevier
    Writing a book and getting it published is a long journey but I can say I am one step closer to making this dream a reality.
    Till next time,
    Jorge Orchilles
    Page 1 of 212

    Categories

    • IT
    • Security
    • Videos

    Latest Videos

    • BackTrack 4 R2 – Technical Workshop for South Florida ISSAFebruary 21, 2011, 10:52 pm
    • Virtual Machine Escape by NSA (video)February 16, 2011, 5:06 pm
    • Cracking WEP with aircrack-ngApril 21, 2010, 12:57 pm
    Popular
    • Windows 7 and VMWare vSphere Client 4July 30, 2009, 5:03 am
    • Windows 7 Security VideoSeptember 21, 2009, 9:35 pm
    • Protected: SSL Renegotiation Denial of ServiceMarch 13, 2011, 9:40 am
    • BackTrack 4 R2 – Technical Workshop for South Florida...February 21, 2011, 10:52 pm
    Recent
    • Teaching SANS Security 560: Network Penetration Testing...August 18, 2011, 12:05 pm
    • NTFS on Apple OS XApril 18, 2011, 6:57 pm
    • SSL Renegotiation DOS FAQApril 6, 2011, 10:04 am
    • Browser SecurityApril 4, 2011, 2:55 pm
    Comments
    • [...] - Especificaciones de cifrado - Protocolo SSL/TLS...March 13, 9:40 am by DoS sobre renegociación SSL/TLS (CVE-2011-1473) | El rincón de dan1t0
    • [...] - Especificaciones de cifrado - Protocolo SSL/TLS...March 13, 9:40 am by DoS sobre renegociación SSL/TLS (CVE-2011-1473) | BugBlog
    • [...] Frequently Asked Questions related to SSL Renegotiation...March 13, 9:40 am by SSL Renegotiation DOS FAQ ‹ Jorge Orchilles
    • [...] Frequently Asked Questions [...]April 6, 10:04 am by SSL Renegotiation Denial of Service ‹ Jorge Orchilles
    Tags
    2008 3479 Action Center Apple AppLocker AT&T BackTrack BitLocker Blackhat Browser Chrome Denial of Service Emerging Threats Facebook Firefox HTTPS IE 8 IE9 Internet Explorer Keynote Mac OS X Management Microsoft Nessus nmap NTFS Passwords Penetration Testing Presentation Privacy R2 Security Service Pack 1 SP1 SSL SSL Renegotiation Talks U-Verse UAC Video Virtualization Vulnerability Assessment Windows 7 Windows Server XP Mode

    Archives

    • August 2011
    • April 2011
    • March 2011
    • February 2011
    • October 2010
    • September 2010
    • August 2010
    • April 2010
    • March 2010
    • January 2010
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • February 2009
    686Follower

    Search

    © Copyright - Jorge Orchilles - Design by: hellodmcs
    • scroll to top
    • Follow us on Twitter
    • Subscribe to our RSS Feed