Posts

Showing posts with the label microsoft

Comparing Microsoft's Communication Methods

Image
Today is Microsoft Patch Tuesday, which means if you so choose you can read posts by the Microsoft Security Response Center like February 2011 Security Bulletin Release . The advisory states "we have 12 bulletins addressing 22 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and IIS (Internet Information Services). Three bulletins are rated Critical." Microsoft communicates information about these vulnerabilities using two graphics. The first is "Severity and Exploitability Index": The second is "Bulletin Deployment Priority": I'm not even going to start a discussion about why the first chart shows "risk" and then "impact" (isn't impact a component of risk?) I'm also not going to dwell about how the first column of the second chart has been "overloaded" to include only a small bit of information on the code affected, rather that prominently communicating that data in a column of its own. Instead,...

Microsoft, Explain Threats to Microsoft

Image
The Microsoft Malware Protection Center recently published their third Security Intelligence Report . The front page of the report says An in-depth perspective on software vulnerabilities and exploits, malicious code threats, and potentially unwanted software, focusing on the first half of 2007 Inside it continues: This report provides an in-depth perspective on software vulnerabilities (both in Microsoft software and third-party software), software exploits (for which there is a related MSRC bulletin), malicious software, and potentially unwanted software. The lists below summarize the key points from each section of the report... The number of disclosures of new software vulnerabilities across the industry continues to be in the thousands... Contrast that proper use of the word vulnerabilities in those excerpts with the incorrect use of the word threat in the quotes I noted in Someone Please Explain Threats to Microsoft : As you go about filling in the threat model threat list,...

Someone Please Explain Threats to Microsoft

Image
It's 2007 and some people still do not know the difference between a threat and a vulnerability. I know these are just the sorts of posts that make me all sorts of new friends, but nothing I say will change their minds anyway. To wit, Threat Modeling Again, Threat Modeling Rules of Thumb : As you go about filling in the threat model threat list, it’s important to consider the consequences of entering threats and mitigations. While it can be easy to find threats, it is important to realize that all threats have real-world consequences for the development team. At the end of the day, this process is about ensuring that our customer’s machines aren’t compromised. When we’re deciding which threats need mitigation, we concentrate our efforts on those where the attacker can cause real damage. When we’re threat modeling, we should ensure that we’ve identified as many of the potential threats as possible (even if you think they’re trivial). At a minimum, the threats we list that we chos...

Thoughts on Vista

Image
To mark the launch of Microsoft Windows Vista , CSO Online asked me to write this article . The editor titled it "Security In Microsoft Vista? It Could Happen." I think I took a balanced approach. Let me know what you think. I was pleased to see my FreeBSD reference survived the editor's review!

Thoughts on Gates Security Memo

Image
While reading Gary McGraw's great book Software Security , I had a chance to re-read the famous Bill Gates security memo of January 2002. I wasn't blogging back then, so I didn't record my reaction to it. Almost five years later, the following excerpt struck me: [E]ven more important than any of these new capabilities is the fact that it is designed from the ground up to deliver Trustworthy Computing. What I mean by this is that customers will always be able to rely on these systems to be available and to secure their information. Trustworthy Computing is computing that is as available, reliable and secure as electricity, water services and telephony. Today, in the developed world, we do not worry about electricity and water services being available. With telephony, we rely both on its availability and its security for conducting highly confidential business transactions without worrying that information about who we call or what we say will be compromised. Computing fal...

Preview: The Security Development Lifecycle

Image
Michael Howard and Steve Lipner were kind enough to send me a copy of their new book The Security Development Lifecycle . Michael's blog summarizes the book. I was surprised to see the book's CD includes a six-part security class video. That's a first for me, at least. I'm also looking forward to another Microsoft security book called Hunting Security Bugs . Michael Howard has another security book through Osborne called Designing Security Software arriving in February. Good work Michael -- push that publication date far enough away for me to catch up on my other reading . On a related note, does anyone recall learning about this? I saw it at the Microsoft Security Development Center . Microsoft India hosted a Security Shootout last March. Varun Sharma won. It's interesting to see such a promotion, and I wonder if the US will host something similar. In the future, I recommend changing the logo. Vulnerabilities in code are not "security threats...

Thoughts on Patching

Image
As I continue through my list of security notes, I thought I would share a few ideas here. I recorded these while seeing Ron Gula discuss vulnerability management at RMISC . Many people recommend automated patching, at least for desktops. In the enterprise, some people believe patches should be tested prior to rollout. This sounds like automated patching must be disabled. I'm wondering if anyoen has implemented delayed automated patching . In other words, automatic updates are enabled, but with a two or three day delay. Those two or three days give the enterprise security group time to test the patch. If everything is ok, they let the automated patch proceed. If the patch breaks something critical, they instruct the desktops to not install the patch until further orders. I think this approach strikes a good balance since I would prefer to have automated patch installation be the default tactic, not manual installation. Determining which systems are vulnerable results in im...

Tom Gallagher Responds to Blog Post

Image
Tom Gallagher, author of the forthcoming Hunting Security Bugs , sent the following in reply to my Microsoft Is Getting It post: Hello Richard. Last weekend I read your blog about Microsoft BlueHat and our security books and thought you might be interested in some more information about these topics. I joined the company almost 7 years ago. In that time, I've seen some major changes happen around how the company views security. As you are aware, the company didn't focus much on security back then. I was one of the few people at the company who did fulltime penetration testing. I worked on a small product team within Microsoft Office and was responsible for testing only it. Today things are very different. In Office's vision document for the release, the first tenet is about the importance of security. Unlike when I started, security is now the responsibility of everyone creating the software - not just the person writing the code, but also the people who design, te...

Microsoft is Getting It

Image
I learned through Slashdot that Microsoft held its third Blue Hat Security Briefings . They also have a Blue Hat Blog . Reading this article , and considering that this is the third Blue Hat, it sounds to me like Microsoft is taking security seriously. It's been over over four years since Bill Gates issued his famous security memo . What's happened since then? With Blue Hat, Microsoft is listening to the top public security researchers who are breaking Windows. Halvar Flake at Black Hat Federal 2006 says it is getting tougher to find vulnerabilities in Windows. I reported that a talk I saw on Vista at RSA 2006 impressed me. The company is incorporating good security practices like least privilege and privilege separation, already found in Unix OS' and tools. Microsoft is publishing books like Writing Secure Code, 2nd Ed , Hunting Security Bugs , and The Security Development Lifecycle . The company has a group which has the power to stop shipment of software due ...

Microsoft Says Wait One More Week

Image
I just received notice of the updated Microsoft Security Advisory on the WMF fiasco. It states: Microsoft has completed development of the security update for the vulnerability. The security update is now being localized and tested to ensure quality and application compatibility. Microsoft’s goal is to release the update on Tuesday, January 10, 2006, as part of its monthly release of security bulletins. This release is predicated on successful completion of quality testing... What’s Microsoft’s response to the availability of third party patches for the WMF vulnerability? Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006. As a general rule, it is a best practice to utilize security updates for software vulnerabilities from the original vendor of the software. With Microsoft software, Microsoft carefully reviews and tests security updates to ensure that they are of high quality an...

Windows Via Real Thin Clients

Real thin clients, like the Sun Ray 170 , don't run operating systems like Windows or Linux. I like the Sun Ray, since its Sun Ray Server Software runs on either Solaris or Red Hat Enterprise Linux. That's fine for users who want to access applications on Solaris or Linux. What about those who need Windows? I can think of four options: Run a Windows VM inside the free VMware Player on the Red Hat Enterprise Linux user's desktop. Run VMware Workstation on each user's desktop. Run VMware GSX Server on the Red Hat Enterprise Linux server running Sun Ray Server Software, and let users connect to the Windows VMs using the VMware Virtual Machine Console Run VMware ESX Server on a separate platform, and let users connect to the Microsoft VMs using the Remote Console Is anyone trying this already? Update : I noticed a similar issue appeared in the VMTN Blog .

Thoughts on Recent Microsoft Common Criteria News

Through Slashdot I hunted down this story about certain Microsoft products being awarded Common Criteria (CC) Evaluation Assurance Level (EAL) 4 Augmented with ALC_FLR.3 certification. They include: Microsoft Windows Server™ 2003, Standard Edition (32-bit version) with Service Pack 1 Microsoft Windows Server 2003, Enterprise Edition (32-bit and 64-bit versions) with Service Pack 1 Microsoft Windows Server 2003, Datacenter Edition (32-bit and 64-bit versions) with Service Pack 1 Microsoft Windows Server 2003 Certificate Server, Certificate Issuing and Management Components (CIMC) (Security Level 3 Protection Profile, Version 1.0) Microsoft Windows XP Professional with Service Pack 2 Microsoft Windows XP Embedded with Service Pack 2 Achieving this certification is important to Microsoft, because of certain laws : "[E]ffective 1 July 2002... departments and agencies within the Executive Branch shall acquire, for use on national security systems, only those COTS products or crypt...

Windows Remote Administration Options

This morning I worked with several remote administration tools on my Windows Server 2003 system. First I enabled the native Remote Desktop (aka Terminal Services) capability via My Computer -> Properties -> Remote At this point I am only letting administrator connect remotely. Since administrator can connect remotely by default once the service is activated, I didn't need to make any other changes. Once Remote Desktop is listening, it will appear active on port 3389 TCP. To access the Windows server remotely from Unix using the RDP protocol, I use Rdesktop . It's available in the FreeBSD ports tree as net/rdesktop . I like the option to change screen geometry, e.g., 'rdesktop -g 80% 192.168.2.2'. To access the RDP server from my Windows 2000 laptop, I installed the MSRDPCLI.EXE package. Next I tried RealVNC . This program has client and server components. I installed the entire package on the Windows server. Setup is fairly simple, and the server sh...

Windows Server 2003 x64 Enterprise Edition

Image
I managed to install Windows Server 2003, Enterprise x64 Edition (64-bit) trial on my Shuttle SB81P . The only component that wasn't recognized natively was the BCM5751 NetXtreme Gigabit Ethernet Controller for Desktops . I used the Windows Server 2003 (AMD x86-64) driver to get the NIC working. I'm lucky my FreeBSD dmesg output recognized this NIC accurately: bge0: mem 0xd0000000-0xd000ffff irq 16 at device 0.0 on pci1 miibus0: on bge0 brgphy0: on miibus0 brgphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX, 1000baseTX-FDX, auto bge0: Ethernet address: 00:30:1b:b6:96:75 The first time I booted Windows, I saw this message: This was an interesting take on the idea of host-centric security. Microsoft could have started with no listening services, and let an administrator decide what to enable. Instead, Microsoft starts services by default, but blocks remote access to them until they are patched. This is a step in the right direction, but I am not happy...

Plug and Play Worm in Wild

Image
The SANS ISC is reporting that a worm which exploits the Plug and Play (PnP) vulnerability described by MS05-039 is in the wild. The F-Secure Blog reports the worm is called Zotob . The Microsoft bulletin lists three mitigating factors: On Windows XP Service Pack 2 and Windows Server 2003 an attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely by anonymous users or by users who have standard user accounts. However, the affected component is available remotely to users who have administrative permissions. On Windows XP Service Pack 1 an attacker must have valid logon credentials to try to exploit this vulnerability. The vulnerability could not be exploited remotely by anonymous users. However, the affected component is available remotely to users who have standard user accounts. Firewall best practices [e.g., blocking SMB ports] and standard default firewall configurations can help ...

Trying Microsoft Update and MBSA 2.0

Image
Today while updating my Windows 2000 laptop I had the opportunity to try two new Microsoft programs. The first is the new Microsoft Update , more of a one-stop-shop for Windows patches. The second is version 2.0 of Microsoft Baseline Security Analyzer . Computerworld has some coverage, but here was my experience. When I started Windows Update, I saw the following screen. I decided to follow the "Upgrade" recommendation. After running Microsoft Update, I got these results. You can see that Microsoft Office updates and updates for other Microsoft programs are available. I think the new interface works well. Once I downloaded and installed all of the updates, I turned to the new MBSA 2.0. It doesn't look that much different, so the improvements are under the hood. I got my results following the scan of the single laptop. I don't necessarily agree with the "severe risk" assessment. I think MBSA complained because it found a FAT partition I use to share d...

Virtual Desktops on Windows

Image
I've been working in Windows more than usual recently as I push to complete my next book Extrusion Detection . I realized I really missed having multiple virtual desktops, like I do using Fluxbox or generally any UNIX windowing environment. Enter Virtual Dimension . This is an open source virtual desktop system for Windows. It works flawlessly on my Windows 2000 Professional laptop. At the right you can see the small desktop that appears when you click on a tray icon. I like being able to see small icons representing the applications active on each desktop. For example, desktop 0 is running Firefox, 1 has Adobe Reader, 2 has Putty and Wish (for Sguil), and 3 has Windows Media Player. I don't know how I coped with a single Windows desktop before using this program.

Microsoft Windows Server 2003 Trial Downloads

I'm not one to ignore free software from Microsoft, even if it's only in trial format. I saw that a beta of Windows Server 2003 R2 is available for download. You must install it on the trial version of Windows Server 2003 with Service Pack 1 (SP1); normal Windows Server 2003 SP1 will apparently not work. I registered to download R2 beta and also Windows Server 2003 SP1 . You can get them on CD as well, but that takes 4-6 weeks. I might try converting server to workstation using the provided link.

Microsoft Security Bulletins Obscure Details

Image
Today is "patch Tuesday" at Microsoft . Let's consider how easy or difficult it is to get real details on the new vulnerabilities. First we visit www.microsoft.com/security and see "Current security updates:" Get information on the latest software security updates. - Exchange Security Update - Windows Security Updates - MSN Messenger Update - Office Security Update This is nice. Where do I start? I click on the link Windows Security Updates and end up at a page titled "Windows Security Updates Summary for April 2005." This page lists five security bulletins, Security Bulletin MS05-016 through MS05-20. I can't really tell a whole lot looking at the information on this page, although the "Technical bulletin" item for each yields clues. The first security bulletin, MS05-016 says Vulnerability in Windows Shell That Could Allow Remote Code Execution (893086) . Remote code execution is always bad. Does this mean an attacker can explo...

Security Insights from Microsoft Security Architect

Image
Last night I attended the northern Virginia ISSA monthly meeting. The guest speaker was Dean Iacovelli, Security Systems Architect for the Microsoft Mid-Atlantic district. His overall theme was "beyond patching." Dean supports over 200 enterprise customers, for which he serves as "security pinata ." Several ISSA members took him to task for Microsoft's security failings, but I thought Dean was diplomatic and handled their mildly aggressive questions well. Dean said that the patching approach to security is becoming a "second or third line defense, like backups. You patch regularly but hope you don't need them." As evidence he cited the decreasing window of time between announcement of a vulnerability and release of an exploit. Patches are still the best way to fix a vulnerability in broken software, so Microsoft has been pursing multiple initiatives to improve their patches. First, Microsoft is migrating from multiple update sites (e.g., O...