Amazines Free Article Archive
www.amazines.com - Wednesday, April 24, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73855)
 Automotive (145712)
 Blogs (75614)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330639)
 Business News (426446)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241953)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20319)
 Dating (45908)
 EBooks (19703)
 E-Commerce (48258)
 Education (185521)
 Electronics (83524)
 Email (6438)
 Entertainment (159855)
 Environment (28973)
 Ezine (3040)
 Ezine Publishing (5453)
 Ezine Sites (1551)
 Family & Parenting (111007)
 Fashion & Cosmetics (196605)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310615)
 Fitness (106469)
 Food & Beverages (63045)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630137)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91657)
 Home Improvement (251211)
 Home Repair (46244)
 Humor (4723)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191031)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80507)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99316)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126700)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80350)
 Science & Technology (110291)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49312)
 Software (83034)
 Spiritual (23517)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308305)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11790)
 Website Design (56919)
 Website Promotion (36663)
 World News (1000+)
 Writing (35843)
Author Spotlight
DESIGNPLUZ DIGITALAGENCY

Designpluz has steadily matured from a passionate graphics design start-up, into a full service digi...more
ELLIOT CHANG

Financial analyst and author writing on economy and business. ...more
TAL BARNEA

Tal is an electrical engineer with over 25 years of expertise with hardware, software, mechanical an...more
MANMOHAN SINGH

Digital marketing professional with 8 years of experience. A good listner, Stratgist and fun loving ...more
LEMUEL ASIBAL

Lemuel Asibal is a web content writer who also ventures on writing articles and blog posts about any...more


Microsoft's reaction to flame shows seriousness of 'holy grail'hack - Uninterrupted Power Supply Ma by grehh hernjer





Article Author Biography
Microsoft's reaction to flame shows seriousness of 'holy grail'hack - Uninterrupted Power Supply Ma by
Article Posted: 07/24/2013
Article Views: 78
Articles Written: 1951
Word Count: 787
Article Votes: 0
AddThis Social Bookmark Button

Microsoft's reaction to flame shows seriousness of 'holy grail'hack - Uninterrupted Power Supply Ma


 
Business,Business News,Business Opportunities
The exploit of Microsoft's Windows Update system by thesophisticated Flame cyber espionage malware was a "significant"event in the history of Windows hacking, experts said today. And by its response, Microsoft appears to agree: It not only issuedan immediate fix just days after the malware's public unveilingwith one of its increasingly-rare "out-of-band" updates, but it hasturned its certificate-generation process upside down and willrevamp how it secures Windows updates. "It was a very significant," said Wolfgang Kandek, chief technologyofficer with Qualys, in an interview today. "It's the Holy Grail ofexploits, and until now it had only been done in research." Kandek wasn't the first to link the term "Holy Grail" with Flame:Earlier in the week, Mikko Hypponen, F-Secure's chief researchofficer and the first to announce that Flame was somehow usingWindows Update, called the feat "the Holy Grail of malware writers" and "the nightmare scenario" for antivirus researchers.

And yesterday, Alexander Gostev, who leads Kaspersky's research andanalysis team, said the Windows Update deception was "better thanany zero-day exploit ... it actually looks more like a 'god mode'cheat code." What had those researchers reaching for superlatives was the Flamemakers' theft of digital "signatures," or certificates, thatlabeled code as Microsoft's, and then the use of those certificatesto "sign" malicious files that posed as legitimate Windows updates. The combination allowed Flame to infect fully-patched Windows XP, Vista and Windows 7 PCs that were on the same networkas an already-infected system. With a complex series of operations that involves three of its manymodules, "Snack," "Munch" and "Gadget," Flame sniffs out victims,intercepts connection requests to Windows Update and serves upmalware, including a copy of Flame, that masquerades as a validupdate.

Third-party security researchers had mapped out those maneuvers andmodules, but until Microsoft's revelation that its certificates hadbeen fraudulently generated, didn't see the point. "Once they confirmed [the certificate theft], it filled in themissing puzzle pieces," Liam O Murchu, director of operations forSymantec's security response center, said in an email reply toquestions. "Without a Microsoft certificate these components didnot make sense." But it may be Microsoft's own moves since Monday, May 28, whenKaspersky Lab first released an analysis of Flame, that is the bestevidence of the hack's gravity. "You can get a pretty good idea by what Microsoft's done that theythink this is very urgent," said Kandek. "They released the patchon Sunday, even though Patch Tuesday was just a little over a weekaway." June's Patch Tuesday -- the name for Microsoft'sreligiously-scheduled security updates -- is next week.

Microsoft revoked three certificates -- those used to sign code in Flame -- on Sunday, June 3, only sixdays after Kaspersky disclosed the malware, an extremely rapidresponse for the company. The same day, Microsoft modified theTerminal Services licensing certificate authority (CA), the onehackers had exploited, so it could no longer issue code-signingcertificates of any kind. It's rare that Microsoft issues an emergency update rather thanwait for the next Patch Tuesday. Last year, Microsoft shipped only one , and that was just two days before 2011's close. In 2010,Microsoft delivered four out-of-band updates and 104 on PatchTuesdays.

On Wednesday Microsoft announced it would revamp how Windows updates are secured , saying that it would dedicate a new CA to Windows Update, ineffect unlinking the service from all other Microsoft-generatedcertificates. The update to end users and enterprises -- the latterfor WSUS, or Windows Server Update Services -- is to start reachingcustomers this week. Andrew Storms, director of security operations at nCircle Security,said that should have been how Microsoft treated Windows Updatefrom the get-go. "Windows Update should have been an entirely different[certificate] stream than anything else," said Storms. "It's justtoo darned important to have been intermingled with any other chainof trust.

For all that Microsoft has done to better their securitypractices, I'm pretty surprised they didn't think of this attackvector previously." Storms was also critical of Microsoft's vague description of theirplans to harden Windows Update. "The Windows Update team needs to describe in more detail how theyare going to fix the problem. Until then, I bet a lot of peoplewill be thinking twice about the security of Windows Update," saidStorms. Users should deploy last Sunday's certificate revocation update assoon as possible, Microsoft has said, to protect themselves frompossible copy-cat hackers.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsersand general technology breaking news for Computerworld. FollowGregg on Twitter at @gkeizer , or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@ix.netcom.com . Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Topic Center.

We are high quality suppliers, our products such as Uninterrupted Power Supply Manufacturer , Product Showcase for oversee buyer. To know more, please visits Low Frequency Online UPS.

Related Articles - Uninterrupted Power Supply Manufacturer, Product Showcase,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license