| 

Google Chrome Stable Channel Update

  • Post author: Omid Farhang
  • Post published: January 25, 2010
  • Reading Time: 2 min
  • Word Count: 285 words

The stable channel has been updated to 4.0.249.78 for Windows, and includes the following features and security fixes (since 3.0): Extensions Bookmark sync Enhanced developer tools HTML5: Notifications, Web Database, Local Storage, WebSockets, Ruby support v8 performance improvements Skia performance improvements Full ACID3 pass, due to re-enabled remote font support (with added defense against bugs in operating system font libraries) HTTP byte range support New security feature: ā€œStrict Transport Securityā€ support Experimental new anti-reflected-XSS feature called ā€œXSS Auditorā€ Security Fixes: ...

Continue Reading Google Chrome Stable Channel Update

Now you too can mount your own Operation Aurora Attacks!!!

  • Post author: Omid Farhang
  • Post published: January 22, 2010
  • Reading Time: 1 min
  • Word Count: 163 words

But don’t. Please don’t!… just…. don’t!… Instead, why don’t you apply the out-of-band patch ( MS10-002 ) that Microsoft has just released…?!!! Patching remote-code-execution vulnerabilities is usually ā€œa good ideaā€ to say the least. But, considering that: Microsoft rushed to get this patch out…… ( Thank you Microsoft! ) And that, this patch addresses several Internet Explorer vulnerabilities – of which includes CVE-2010-0249 – the infamous ā€œAurora attacksā€ related vulnerability that’s well known to be making the rounds in the wild. ...

Continue Reading Now you too can mount your own Operation Aurora Attacks!!!

ā€œAuroraā€ update brief DoS

  • Post author: Omid Farhang
  • Post published: January 21, 2010
  • Reading Time: 1 min
  • Word Count: 143 words

Early this afternoon Microsoft released an out-of-band security bulletin patching the vulnerabilities in Internet Explorer. The fix has been at the top of the news since the vulnerabilities it treats are believed to have led to the compromise of Google and about 30 other companies last week in what has been called the ā€œAuroraā€ attack. The governments of France and Germany suggested that Internet users switch to a different browser until the vulnerability was fixed. ...

Continue Reading ā€œAuroraā€ update brief DoS

Microsoft will patch Internet Explorer today

  • Post author: Omid Farhang
  • Post published: January 21, 2010
  • Reading Time: 1 min
  • Word Count: 102 words

Microsoft has said it will issue an out-of-band patch today for critical vulnerabilities in Internet Explorer that allow remote execution of code. The company said yesterday it would not wait until the February ā€œPatch Tuesdayā€ to fix the vulnerabilities. The much discussed ā€œAuroraā€ vulnerabilities in IE have been held at least partially responsible for cyber attacks on Google and more then two dozen other major companies. The attacks on Google were aimed at Gmail accounts of dissidents and Google’s source code. The attacks on the other companies were aimed at stealing intellectual property. ...

Continue Reading Microsoft will patch Internet Explorer today

Plenty of Updates on Patch Tuesday

  • Post author: Omid Farhang
  • Post published: January 13, 2010
  • Reading Time: 2 min
  • Word Count: 252 words

This Black Tuesday was different as anticipated – Microsoft releases only one security bulletin, but other companies ā€œjumped inā€ and deliver updates now as well. For the windows operating systems, only one Security Bulletin was released. MS10-001 deals with a vulnerability in the decompression routines of the Embeded OpenType Font Engine. This means that especially in Windows 2000, programs like Internet Explorer, Word or PowerPoint for example which render EOT fonts can put the system at risk when viewing manipulated contents. In newer operating systems the flawed code is used differently so that Microsoft assumes that it isn’t exploitable there. ...

Continue Reading Plenty of Updates on Patch Tuesday

Do you want Bing for iPhone? There's an app for that

  • Post author: Omid Farhang
  • Post published: December 17, 2009
  • Reading Time: 3 min
  • Word Count: 553 words

Earlier this evening, Microsoft formally announced a new search app for iPhone on the Bing Community blog. The Bing app is available now from the App Store, complete with voice search. I emphasize the now because the app has a December 16 release date on the 15th. Based on a very quick, cursory look, Bing is a competent iPhone app, tapping into the kind of capabilities expected from the platform. Bing fits nicely into the App Store repertoire. I wouldn’t call the features revolutionary — Apple and Google are there already with advanced mapping and GPS — but the packaging appeals, and Microsoft manages to offer a user experience that is fairly consistent with Bing Web search. ...

Continue Reading Do you want Bing for iPhone? There's an app for that

Critical Adobe Flash Update

  • Post author: Omid Farhang
  • Post published: December 9, 2009
  • Reading Time: 1 min
  • Word Count: 81 words

It’s the second Tuesday of the month and there are important updates being released. From Microsoft, of course, but also from Adobe. There’s a critical security issue in Adobe Flash Player 10.0.32.18 and earlier. It’s important that organizations deploy these updates before the Christmas holiday reduces IT staffing. Fortunately, this patch cycle is as early as can be landing on the 8th so there’s still time to test and deploy. ...

Continue Reading Critical Adobe Flash Update