Saleswomen on the phone



Enter your email address on our Newsletter Page  and get special software offers by email.

Never miss out on our special sales!

Also get the latest breaking privacy news as well as Spyware, Privacy, and Security  Software Reviews.

 

Meeting Room Discussion About Spyware


Not convinced you have Spyware? Scan your PC for free and find-out! Click Here.
 

For Navigation Help See Our Site Map And Search Engine Page

 

Visit Spy Software Solutions.Com Your Online Spy, Anti-Spy, And Security-Privacy Software Comparison Guide with Free Spyware Removal Software.

 

Testimonials

 

Contact Us



 

Privacy & Security Tips - Page 5


 

January & February, 2006

Prevent Attacks Aimed at IE and Windows

Stuart J. Johnston

From the March 2006 issue of PC World magazine
Posted Monday, January 30, 2006

Microsoft has fixed a nasty Windows security hole that could hand control of your computer to an attacker. The patch offers welcome relief, because dozens of exploits for this vulnerability have been in circulation for weeks. Download the patch from Microsoft.

The problem lies in the way the Windows graphics engine handles Windows Metafiles (WMF), particularly when those files are displayed in Microsoft's Picture and Fax Viewer. Microsoft created the WMF image file format to simplify the exchange of images between various applications. (This bug is unrelated to a WMF hole that I reported on last month.)

If you view a booby-trapped WMF file on a Web page--say, on a banner ad--or you click a link to a doctored image in an e-mail or instant message, your system could be infected, letting the hacker take over.

All Windows versions from Windows 2000 through XP are at risk. Moreover, XP and Windows Server 2003 are set to display WMF files automatically, according to security firm F-Secure. To change this default, you would need to edit the Windows Registry, a potentially risky process. You are better off installing the patch in order to display such files safely.

Two-in-One Patch for IE

Microsoft has also released a patch to take care of two dangerous holes in Internet Explorer that could leave you open to any number of diabolical actions. The flaws affect IE 5.01 through 6 running on Windows 98 SE through XP Service Pack 2. The first problem, similar to an earlier case (see "Defend Your PC Against Video Attacks"), involves IE's ability to run a type of software called a COM object, which wasn't designed to run in IE. Various Windows programs use COM objects to communicate with one another behind the scenes.

The one type of COM object that IE can run is called an ActiveX control. ActiveX controls enable IE to perform special tasks like playing a video in a browser window instead of, say, in a stand-alone media player. An attacker could take advantage of IE's ability to run this kind of COM object by creating one that, when run in IE, could commandeer your PC. You could launch an infection merely by reading an HTML e-mail message or visiting a Web page that contains the malicious COM object.

The patch for the bug described in the January column prevented all attacks Microsoft was aware of at the time, by modifying the Windows Registry to keep a set list of COM objects from running. This new patch does much the same, except that it blocks a new list of COM objects.

Exploits that take advantage of the second IE hole concern the way IE processes the JavaScript Web programming language. With the patch just mentioned, you'll be able to protect your PC. The bug had been known for months, but everyone, including Microsoft, thought it could at worst result in an IE crash. A UK-based researcher, however, discovered a way to use the flaw to take over a computer.

Another patch benefit: It blocks Sony's now-infamous copy-protection rootkit.

 
 

March & April, 2006

  • Computerworld’s recent survey of 577 subscribers
    with IT security responsibilities found that:

79% have had problems with spyware in the past 12 months. .
71% percent said they see spyware as a threat to their organizations. .
99% expressed concern that spyware might be used for identity theft. .
96% said they were concerned it could be used for industrial espionage.

  • However, like all types of malicious software, spyware is an ever moving and ever changing target. Some experts have recently seen a surge in spyware that uses rootkits (programs that allow administrator-level access to a computer) to hide from anti-spyware products.
  • Others have found a vulnerability in the Windows operating system that could allow malware to lurk undetected in long string names of the Windows Registry.
  • That is why some observers say the fight against spyware will require users to change their “anything
    goes” attitude toward their PCs and accept stringent lockdown policies, along with layered defenses that put antivirus and anti-spyware tools not only on desktops, but on SMTP and HTTP gateways, and on e-mail and file servers.


Next Page