Monday, June 6, 2011

A note to various print driver and PDF print driver developers

A short rant:

I and my clients are NOT going to withhold service packs and critical security patches for modern Windows clients (read: Windows 7 x64 SP1) just so your poorly written print drivers will install and run in a stable manner. Crashing the print spooler service leaving all installed printers unusable without a reset is not acceptable.

I'm looking at you Adobe PDF and Nova PDF . . .

Instead, we will look for compatible substitutes from your competitors. Once we change to those alternates, it's highly unlikely that we will EVER return to your products in the future.

Get it right, or lose our business!

'nough said.

Saturday, April 2, 2011

Protect your company - Colorado has almost zero protections against someone editing your state business records

Update January 26, 2012: Colorado now has the option to lock down business registrations.

Almost zero . . .

In the State of Colorado the principle/owner of a business can create a corporation online, file amendments, corrections to contact information and annual reports.

It's nice to have that ability online, and the fee's for filing over the Internet are substantially lower than filing by paper.

But, and this is a HUGE BUT: there is no way to password protect your ability to alter your records.

This was exposed half a year ago, one very good write up about the problem was posted on ComputerWorld: Colorado warns of major corporate ID theft scam (Link pops a new tab or window.)

Seems like a good time to revisit the problem given my feelings about a potential scam snail mail solicitation received today.

So what should a business owner or principle do to protect their corporate ID in Colorado?

Buried within the sage but overly general advice on protecting your business posted by the Colorado Secretary of State is the one thing you can do to be notified when your corporate record is altered: add your email to their notification list.

Here are the steps:

1) Get thee to http://www.sos.state.co.us/pubs/business/ProtectYourBusiness/protectyourbusiness.htm

2) Click the left upper link offering to "Subscribe to E-mail Notification Services"

3) Click the first link under the heading: "E-mails specific to a business organization record" entitled "Click here to subscribe to e-mail notification regarding a specific record"

4) This brings you to a search page, you can either enter your state ID, or search on your business name. After entering your search criteria, click the Search button.

5) Click the ID Number of YOUR business from the list after doing the search.

6) This brings you to a summary page of the business record. Find and click the link at the bottom that states: "Subscribe to E-mail Notification Regarding this Record"

7) Enter a valid email address and click the Subscribe button.

8) Within the hour (after I tried this it took about 50 minutes) you should receive an email from the Colorado Department of State (entity.subscribe@sos.state.co.us) confirming the subscription.

. . .

This is just WEAK. Complex steps to subscribe, no real security. No way to verify anyone's identity. Oh sure, it's a felony to misrepresent yourself on the states website, but since when has that stopped the criminals?

Corporate Controllers Unit - Scam Smelling Snail Mail

Scam? Spam? Both? I got some snail mail today from an organization calling themselves "Corporate Controllers Unit" or the initials "CCU" offering a very expensive service: for the low low fee of $225 per year they will file my company's annual report with the state where I do business.

This report costs me about 10 minutes of time and a $10 fee when I file directly with the state.

The envelope looks like an official mailing. So does the letter inside, filled with legalese threatening dire things unless you file on time. Thankfully the fine print at the very bottom lets you know it's "just" a solicitation.

Couple of other clues. The organization uses a PO Box. A search on the web does not find any contact info, but it does bring up about six pages of the same couple of articles touting their service via spam blogs. Someone hired a blackhat SEO agent to market their stuff.

My advice: save your money and your sanity. Companies should file directly with the state as they have in the past.

My suspicion: this might be an attempt to steal your companies ID.

Update: This smells more like a scam the more I don't see . . . let me explain:

I cannot find anything on this company at all, other than the aforementioned spam blogs re-posting the same few articles over and over. No contact info, no phone, no web site, just the PO Box. And I think my Google-Fu is pretty darn good, thank you. If it was out there, I would have found it by now.

Other than the comments below, I've gotten calls from two of my clients and one of my business partners asking my opinion - they also received one of these in the mail today.

Update 2: Remember I said 6 pages of search results? That was 4 hours ago. Something fishy is up, because the returned results as of this update (8:30 PM Saturday night) presents over 29 pages now, and except for this blog the results are all the same couple of articles over and over on different odd domain sites.

Update 3: Denver Channel 9 posted this article at 7:27 AM MDT Monday April 4.
State warns of potentially misleading letters (from Corporate Controllers Unit)

Update 4: Denver Post finally listed an article with more information, including a quote from the Attorney General that this is most likely a scam.
"Gessler warns businesses, non-profits of "deceptive mail solicitation" (from Corporate Controllers Unit)



.

Thursday, January 20, 2011

Multiple Java Updates Installed == Vulnerable!

Update: We're now up to version 7.5 . . . and Oracle has added a page in the Java site to assist with removing old versions.

Over the last year security researchers have been tracking a major rise in the use of Java exploits to plant malware on unsuspecting users.  Many of them have blamed security vulnerabilities in IE or (pick your browser) . . . and truth be told that's still going on too.  But the big surprise is that Java exploits are eclipsing "plain jane" browser exploits, across all browsers and in some cases across platforms.

Bottom line: many Java exploits go after vulnerabilities that have been patched. Since Java runs on a wide variety of platforms, this makes it a very serious vector. You should stay alert for and accept automatic Java updates. You should remove old Java versions as they allow older - vulnerable - Java scripts to run even when you are patched to the most current version.  You should also check the Java test page to make sure the latest version installed successfully.

Not to put too fine a point here:  Java Updates are notorious for leaving previous versions on your system instead of upgrading in place.  Those old Java versions are alive and vulnerable until they are removed.

Worse, many times the Java setup or update process offers end users some form of crapware:  additional toolbars, "free" virus scans, etc.  I personally recommend that during any install - of any plugin (and I include Adobe products etc here) that you watch for these unneeded add-ons and UNcheck them during installation. If you allow every update of every plugin you use to install these extra craplets, your system will quickly be bogged down to a slow, sad mess. 

Action Steps:

1) Check in Control Panel:  Add/Remove Programs (Windows XP) or Uninstall a Program (Windows 7) for older Java or J2SE or Java Runtime versions and remove ALL of them.  You'll gain back on average around 120MB of disk space per outdated version removed.  And you'll close some serious holes in your security.

Example of multiple old Java versions.
Get rid of them!

2) The current Java version as of this writing is "Java 6 Update 23"   That should be the ONLY version you have listed in "Remove Programs." You can install the latest version of Java:  www.java.com

What you want to see.
Only one Java, and it's the most recent version.

3) Test your installation: http://www.java.com/en/download/testjava.jsp

Oh hey there!
I passed, or did I?

Note that this test only reports the latest working version installed on your system.  It does not reveal whether your system has older versions still installed.  For that see Step 1 above . . .

A note on x86 versus 64-bit:  If you - like most people - use a 32-bit browser when running a true 64-bit operating system, then you only need to install the 32-bit version of Java.  In fact I recommend that if you see a 64-bit version of Java in your "Remove Programs" window, you zap it away.

Additional reading:

http://itmanagement.earthweb.com/secu/article.php/3921441/Cisco-Java-Attacks-on-the-Rise-As-Spam-Declines.htm


http://blogs.technet.com/b/mmpc/archive/2010/10/18/have-you-checked-the-java.aspx

Wednesday, December 15, 2010

Bad Outlook 2007 Update KB-2412171 -- December 2010 Microsoft Patch Day

January 11, 2011 Update:  This patch has been re-released under the same KB number.  If you previously installed this patch you should update it again.  See http://support.microsoft.com/kb/2412171 for more information.



Bug Summary:
After installing patch KB-2412171 for Outlook 2007 SP2 delivered via Microsoft Updates on Tuesday, December 14 2010; several problems on multiple machines began happening.

UPDATE: Pass the salt please -- Outlook team at Microsoft admits to the bad patch.  (Which TOTALLY rocks, would sure like to see more ownership from team MS when problems come out of Redmond.)

  1. Performance while loading Outlook, or clicking any email folder/sub-folder or changing views was extremely sluggish, even on high performance workstations.
  2. Auto-archive options were missing entirely from the Properties page for any folder, also missing from the Mailbox Cleanup tool. (See screen-shots)
  3. Additionally severe system instability when certain other plug-ins are installed and running: the Franklin Covey Plan Plus for Outlook version 6 in particular began crashing badly.
  4. Users of Comcast and AT&T email services have reported that sending/receiving breaks with this patch.  Error 0x800CCC18 indicating SPA not working.
  5. Some users of outsourced Exchange services have also reported that outgoing emails fail to leave their Outbox.

Tested systems: Windows 7 x64 Professional and Ultimate, running Office 2007 Professional and/or Ultimate. Office 2007 Service Pack 2 installed. Tested with and without AntiVirus running - AV was not a factor. Also tested with the Franklin plug-in removed: which solved the more severe crashing but did not solve the performance issues.



Note that AutoArchive is missing entirely from the patched Outlooks MailBox Cleanup UI, it should be between those two blank lines.
















This is what that UI window should look like.

















Fix this problem by removing KB-2412171.

This patch can be removed safely. (Note:  Microsoft has removed their page for this patch - which I had linked to in the original article. This hopefully means a fixed version is coming very soon.  In the mean time, here are the steps to remove this patch from your system.)

1) Close Outlook and any related applications (such as Google Calendar Sync).
2) Open Control Panel >> Add / Remove (or Uninstall) Programs.
3) Click Show Windows Updates or View Installed Updates (depends on your Windows version.)
4) Locate the Outlook update KB-2412171 and remove/uninstall it.
5) Normally a reboot is not required, but if you are prompted to -- wait until you complete the further steps below.

Additionally, I recommend you block this update on systems that have not yet been patched, or block it after removing it so you don't get slammed again.

1) Force a check for updates.
2) Updates should display KB-2412171 as available.
3) Un-check KB-2412171, then right click (in Windows 7) and hide it.  In IE (Windows XP) Uncheck the first box next to the update, then check the box below to hide it.

That should solve the problems for now.  I recommend you check back later - when a fixed version is released I will make a point of announcing it here.

New: Microsoft has removed the KB article for this patch from their website as of sometime this afternoon December 16.  They also appear to have removed the patch from Automatic updates.  If you manually remove this patch as described above to correct problems, you should not have to "hide" the update to prevent it from reinstalling. It will simply not be on the list anymore when you refresh available updates.

Tuesday, August 24, 2010

Critical New (yet old) DLL Loading Vulnerability likely won't be fixed via Microsoft Update

Short summary: To continue to provide backward compatibility for older (poorly written) applications, Microsoft will likely not patch what may become one of the most dangerous vulnerabilities in Windows. It effects all versions, even the newest Windows 7 and Windows Server 2008 R2 operating systems. System administrators must manually test and patch each system according to what critical applications are used - to prevent business critical systems from breaking completely - or risk infection.

For a decent analysis on what the problem is, and why Microsoft likely won’t be releasing a hot fix via Windows Update see this article:
ars technica : Windows DLL-loading security flaw puts Microsoft in a bind


A Microsoft KB article was released last night announcing a mitigation fix available to system admins. The process includes adding a new REG key and installing a hotfix that enables that key on the OS.
Restrict the DLL search path algorithm (Machine Global, Application Specific, WebDAV or Remote Folders) KB2264107

Please note that if you intend to deploy this fix you will need to manually apply the patch to each system and import a reg key.

Test all business critical apps on this patch before you deploy widely!

In my opinion Microsoft should bite the bullet on this in favor of security – this is potentially one of the most dangerous exploits we shall see this decade. Expect rampant virus infections very soon on un-patched systems. The catch-22 is that deploying this fix will likely break older 3rd party software that used dangerous DLL calling methods. (No names, but there were some big companies that did this right up until last year - “financial software” cough cough.)

Thursday, May 27, 2010

Tabnabbing - new phishing technique

Ever walk away from your computer, or change focus to a different application for a while and forget where you were surfing?

Might want to be careful. A new phishing proof of concept that affects Firefox, Chrome, IE 8 and most other browsers that support simple scripting and tabs might fool you into thinking you were about to log onto your email account -- or your bank!

It's called Tabnabbing, and a malicious site might use it to change the information on a web page to something that looks like your bank, Gmail account, or even a gaming account log in page. (Hit that link above to see more info as well as a harmless working demo of the technique.)

Quote:

How The Attack Works

1. A user navigates to your normal looking site.

2. You detect when the page has lost its focus and hasn’t been interacted with for a while.

3. Replace the favicon with the Gmail favicon, the title with “Gmail: Email from Google”, and the page with a Gmail login look-a-like. This can all be done with just a little bit of Javascript that takes place instantly.

4. As the user scans their many open tabs, the favicon and title act as a strong visual cue—memory is malleable and moldable and the user will most likely simply think they left a Gmail tab open. When they click back to the fake Gmail tab, they’ll see the standard Gmail login page, assume they’ve been logged out, and provide their credentials to log in. The attack preys on the perceived immutability of tabs.

5. After the user has entered their login information and you’ve sent it back to your server, you redirect them to Gmail. Because they were never logged out in the first place, it will appear as if the login was successful.

/quote

You know the drill by now: inform your friends, parents, siblings, co-workers and make sure that official looking log in page to which you're about to respond is one YOU pulled up - not one that just happened to be there when you got back from that bio-break.

UPDATE: If you use Firefox with NoScript, version 1.9.9.81 of said NoScript includes an experimental tabnabbing blocker.

Monday, April 5, 2010

PDF's are the new vector for malware - and now PDF worms are coming

I've ranted in the recent past about PDF vulnerabilities based on exploitable holes or embedded javascript.

Now comes the real warning about the near future:  A built-in feature inherent to the PDF format can be used to run arbitrary code on your machine . . . without using javascript or any actual vulnerabilities.  The only mitigation is that Adobe at least asks the user if code might be run -- but some tricky social hacking can still cause unaware users to click OK on the wrong box.

Worse, another growing competitor to Adobe: Foxit PDF, does not even warn the user that code is about to be invoked.  It just quietly lets the code run without any user interaction!

For a YouTube video demo of this nasty feature in action:
PDF: Launch a Command

For a downloadable test to try your luck with your favorite third party PDF reader see:
Escape from PDF credit to Didier Stevens.

And for the extension of this logic towards the inevitable PDF driven worm, see:
Are PDF's Wormable?

YouTube Video: PDF Worm Demo - No JavaScript Required

The authors are not releasing the method, but I can tell you that once the concept is released, which it has been, someone on the wrong side will figure it out soon enough.

Adobe, Foxit and other PDF reader providers need to look into this ASAP.

Edit: Thanks to theweaselking in the comment below -- Foxit Reader has an update that will change the behavior to match Adobe's product in this scenario. If you use Foxit make sure you've accepted the latest updates.

Of course - I would rather have three changes from both companies.

1) Make the message that asks the user for permission immutable.

2) Give us an option to turn off the third party viewer feature entirely -- just like we can turn off JavaScript in the Preferences. Such calls from within a PDF would be totally ignored.

3) Bonus! How about fixing Adobe and Foxit so they run properly as a Low Integrity Process in Vista and Windows 7 (and Windows Server 2008 / R2.) Mandatory Integrity Control in Win 7 and Vista works very well as another barrier to malware by forcing high risk processes to run at lower permissions than the OS. Unfortunately many popular utilities that should be considered high risk do not take advantage of this feature.

Thursday, March 18, 2010

"We're suing you" spam technique tries to get you to open infected attachments

It's my understanding (but I'm not a legal expert) that if you were actually being served as a defendant in ANY legal action, you would be getting physical paper delivered to you one way or another.

Email legal summons? I don't think so.

Real law firm, fake spam email, real virus. See the Wall Street Journal article.

This might also be construed as a denial of service on the actual law firms phone lines . . . I can't imagine the pain those guys must be feeling as their phone rings off the hook.

Tuesday, February 23, 2010

Dear NVidia . . .

I don't want your stupid PhysX driver, nor do I want your "3D Vision Discover Driver."

Please give me the option during a driver update to not install those components in the first place.

At least I can uninstall them separately after the fact, but it's extra work for me and my clients. (And usually a second reboot before I can get back to work.)

Signed,
- meh