<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avira - TechBlog &#187; Exploits</title>
	<atom:link href="http://techblog.avira.com/tag/exploits/en/feed/en/" rel="self" type="application/rss+xml" />
	<link>http://techblog.avira.com</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 06:38:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Safari fixes and SMB vulnerability (Update)</title>
		<link>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/</link>
		<comments>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 06:54:26 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1395</guid>
		<description><![CDATA[Apple just released their web browser Safari in version 4.0.4 &#8211; both for Mac OS X and for Windows. Previous versions have some serious security vulnerabilities which can lead to remote code execution, crashes or to information disclosure, for example. More details can be found in Apples security advisory.
Just after the November patchday this week [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-404 alignleft" title="apple_1" src="http://techblog.avira.com/wp-content/uploads/2008/12/apple_1.png" alt="apple_1" width="45" height="50" />Apple just released their web browser Safari in version 4.0.4 &#8211; both for Mac OS X and for Windows. Previous versions have some serious security vulnerabilities which can lead to remote code execution, crashes or to information disclosure, for example. More details can be found in Apples <a title="About the security content of Safari 4.0.4" href="http://support.apple.com/kb/HT3949" target="_blank">security advisory</a>.</p>
<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />Just after the November patchday this week new reports about an issue with Microsofts SMB implementation in Windows 7 and Windows Server 2008 popped up. Rob VandenBrink of the <a title="Windows 7 / Windows Server 2008 R2 Remote SMB Exploit" href="http://isc.sans.org/diary.html?storyid=7573" target="_blank">Internet Storm Center</a> took the publicly available exploit code, fixed a line of code &#8211; et voilà, a machine with Windows 7 or Server 2008 connecting to this faked server instantly freezes. There are no reports yet about Microsoft investigating this issue.</p>
<p><strong>Update</strong>: Microsoft has released a <a title="Vulnerability in SMB Could Allow Denial of Service" href="http://www.microsoft.com/technet/security/advisory/977544.mspx" target="_blank">security advisory</a> this weekend where the company explains that it investigates the reports and is preparing a patch.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe fixes Reader and Acrobat</title>
		<link>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/</link>
		<comments>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 06:21:45 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1307</guid>
		<description><![CDATA[Not only Microsoft released a bunch of patches to close security holes in their products, but also Adobe now ships updated software to fix several vulnerabilities in Adobe Reader and Acrobat which already get attacked with specially prepared PDF documents to take over control of vulnerable computers &#8211; Avira AntiVir protects its users and detects [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-870" title="acrobat_logo" src="http://techblog.avira.com/wp-content/uploads/2009/05/acrobat_logo.png" alt="acrobat_logo" width="31" height="33" />Not only Microsoft released a <a title="TechBlog: Microsoft closes 34 Security Holes" href="http://techblog.avira.com/2009/10/14/microsoft-closes-34-security-holes/en/" target="_self">bunch of patches</a> to close security holes in their products, but also Adobe now ships updated software to fix several vulnerabilities in Adobe Reader and Acrobat which already <a title="Avira issues a warning on harmful PDF files" href="http://www.avira.com/en/security_news/harmful_pdf_files.html" target="_blank">get attacked</a> with specially prepared PDF documents to take over control of vulnerable computers &#8211; Avira AntiVir protects its users and detects the currently circulating exploit PDF as Exp/Pidief.xam.</p>
<p>Users of Adobe Reader and Acrobat with earlier versions than the new 9.2 are advised to install the updated software immediately to protect themselves from the attacks; Adobe rates the vulnerabilities as critical. New versions of Reader are available for <a title="Adobe Reader Update for Windows" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Windows" target="_blank">Windows</a>, <a title="Adobe Reader Update for Mac" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Macintosh" target="_blank">Mac</a> and <a title="Adobe Reader Update for Unix" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Unix" target="_blank">Unix</a>. Further links for updates for different Acrobat versions are listed in Adobes <a title="Security Advisory for Adobe Reader and Acrobat" href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">security advisory</a>.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft closes 34 Security Holes</title>
		<link>http://techblog.avira.com/2009/10/14/microsoft-closes-34-security-holes/en/</link>
		<comments>http://techblog.avira.com/2009/10/14/microsoft-closes-34-security-holes/en/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 05:26:18 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Microsoft Patchday]]></category>
		<category><![CDATA[SMBv2]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1297</guid>
		<description><![CDATA[Just as announced last Friday, Microsoft ships updates for plenty of products and closes 34 security holes. Many of them are rated critical which means that attackers can infiltrate vulnerable systems remotely.
The patches affect the Windows operating systems starting from Windows 2000 up to the brand new Windows 7. The vulnerable software is a lengthy [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />Just as announced last Friday, Microsoft ships updates for plenty of products and closes 34 security holes. Many of them are rated critical which means that attackers can infiltrate vulnerable systems remotely.</p>
<p>The patches affect the Windows operating systems starting from Windows 2000 up to the brand new Windows 7. The vulnerable software is a lengthy list too: Internet Explorer, Media Player, Office from XP up to 2007, .Net runtimes, SQL server, Visual Studio 2003 up to 2008, Visual FoxPro, Report Viewer, the antivirus solution Forefront and Silverlight 2.</p>
<p>As the patches deal with critical security vulnerabilities which in some cases are already abused (like the FTP hole in IIS) it is advised to install them ASAP.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/14/microsoft-closes-34-security-holes/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FastFlux-Malware leading to FakeAV (Update)</title>
		<link>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/</link>
		<comments>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/#comments</comments>
		<pubDate>Fri, 02 Oct 2009 05:30:23 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1245</guid>
		<description><![CDATA[Our researchers found a malicious JavaScript link embedded to the headlines and thread titles in some forums as well as on other web sites after a user notified us about possible issues with a particular forum. The scripts resulted in slowing down forum access which raised suspicion, so we started to analyse what was going [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-465" title="malware_warning" src="http://techblog.avira.com/wp-content/uploads/2008/12/malware_warning.png" alt="malware_warning" width="56" height="53" />Our researchers found a malicious JavaScript link embedded to the headlines and thread titles in some forums as well as on other web sites after a user notified us about possible issues with a particular forum. The scripts resulted in slowing down forum access which raised suspicion, so we started to analyse what was going on.</p>
<p>In those forums there were links embedded in the posts which lead to a JavaScript on a Russian website. A google search with the URL revealed that already more than 100 web pages, especially forums, got infected with that malicious link &#8211; the infection rate is increasing fast. Later another URL with the malware script was identified, which Google reported on more than 16.000 obviously infected web pages.</p>
<div id="attachment_1261" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Encrypted_JS.png"><img class="size-medium wp-image-1261" title="091001-Encrypted_JS" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Encrypted_JS-300x117.png" alt="Fig. 1: The JavaScript is encrypted and obfuscated in several layers." width="300" height="117" /></a><p class="wp-caption-text">Fig. 1: The JavaScript is encrypted and obfuscated in several layers.</p></div>
<p>The JavaScript is trying to exploit several vulnerabilities to silently install malware on affected users&#8217; computers. Among these are exploits for Microsoft Video ActiveX Control Vulnerability (CVE-2008-0015), Microsoft Internet Explorer XML Parsing Vulnerability (CVE-2008-4844), Microsoft Internet Explorer Malformed CSS Memory Corruption Vulnerability (CVE-2009-0076) and some PDF exploits for Firefox and the Internet Explorer. All these exploits are already known and security updates are available. The malware writers obviously assume that a lot of Internet users do not update their systems.</p>
<div id="attachment_1263" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Decrypting_JavaScript.png"><img class="size-medium wp-image-1263" title="091001-Decrypting_JavaScript" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Decrypting_JavaScript-300x167.png" alt="Fig. 2: Decrypting the JavaScript needed some brute force, too." width="300" height="167" /></a><p class="wp-caption-text">Fig. 2: Decrypting the JavaScript needed some brute force, too.</p></div>
<p>That malicious JavaScript is hosted on a fast-flux&#8217;ed domain &#8211; the Internet addresses to which the embedded link points resolves to different locations every few minutes (fast flux as abbreviation from fast fluctuation, see <a title="Wikipedia article on fast flux servers" href="http://en.wikipedia.org/wiki/Fast_flux" target="_blank">Wikipedia</a>). So it doesn&#8217;t help to take down one server as there are plenty of them. Usually infected computers serve the malware.</p>
<div id="attachment_1260" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-fastflux_hosts.png"><img class="size-medium wp-image-1260" title="091001-fastflux_hosts" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-fastflux_hosts-300x245.png" alt="Fig. 2: The domain the JavaScript was loaded from was a fastflux'ed domain." width="300" height="245" /></a><p class="wp-caption-text">Fig. 3: The domain the JavaScript was loaded from was a fastflux&#39;ed domain.</p></div>
<p>The servers are GeoIP-aware. Trying to access them directly with an IP from Deutsche Telekom network resulted in an &#8220;access denied&#8221;, while using a proxy in the USA made the bots deliver the malware.</p>
<div id="attachment_1262" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Shellcode_functions.png"><img class="size-medium wp-image-1262" title="091001-Shellcode_functions" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-Shellcode_functions-300x233.png" alt="Fig. 3: The shellcode in the JavaScript finally leads to a FakeAV infection." width="300" height="233" /></a><p class="wp-caption-text">Fig. 4: The shellcode in the JavaScript finally leads to a FakeAV infection.</p></div>
<p>But this malware &#8211; Avira detects it <a title="TR/FraudPack.ams" href="http://www.avira.com/en/threats/section/details/id_vir/4529/tr_fraudpack.ams.html" target="_blank">TR/FraudPack.ams</a> &#8211; is just another downloader. It is encrypted with some layers as well.</p>
<div id="attachment_1266" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Crypter_Greetings.png"><img class="size-medium wp-image-1266" title="091001-FakeAV_Crypter_Greetings" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Crypter_Greetings-300x72.png" alt="Fig. 5: The crypter author sends out greetings to Sunbelt." width="300" height="72" /></a><p class="wp-caption-text">Fig. 5: The crypter author sends out greetings to Sunbelt.</p></div>
<p>One of the encryption layers contains greetings to the company Sunbelt.</p>
<div id="attachment_1265" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Downloader_Strings.png"><img class="size-medium wp-image-1265" title="091001-FakeAV_Downloader_Strings" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV_Downloader_Strings-300x228.png" alt="Fig. 4: Contents of the FakeAV downloader svcst.exe. " width="300" height="228" /></a><p class="wp-caption-text">Fig. 6: Contents of the FakeAV downloader svcst.exe. </p></div>
<p>It accesses a set of &#8220;double fast-flux&#8217;ed&#8221; domains to fetch the actual malware, a FakeAV and a ftp password stealer which sends the data to guest books on the Internet. These are detected by Avira with generic detection as <a title="TR/Crypt.ZPACK.Gen" href="http://www.avira.com/en/threats/section/details/id_vir/4487/tr_crypt.zpack.gen.html" target="_blank">TR/Crypt.ZPACK.Gen</a> and as <a title="TR/FakeAV.RK" href="http://www.avira.com/en/threats/section/details/id_vir/4530/tr_fakeav.rk.html" target="_blank">TR/FakeAV.RK</a>, while the password uploader gets detected as <a title="TR/Downloader.Gen" href="http://www.avira.com/en/threats/section/details/id_vir/3907/tr_downloader.gen.html" target="_blank">TR/Downloader.Gen</a>.</p>
<div id="attachment_1264" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV.png"><img class="size-medium wp-image-1264" title="091001-FakeAV" src="http://techblog.avira.com/wp-content/uploads/2009/10/091001-FakeAV-300x244.png" alt="Fig. 5: The FakeAV disguises itself as Antivirus Pro 2010." width="300" height="244" /></a><p class="wp-caption-text">Fig. 7: The FakeAV disguises itself as Antivirus Pro 2010.</p></div>
<p>The WebGuard of the Avira Premium and Professional blocks the URLs from where the malicious JavaScript is included and also the malware download URLs. Avira AntiVir also protects users from the downloaded malware.</p>
<p>(Article updated on 6th October to add more details about the malware.)</p>
<p style="text-align: right;">Emanuel Somosan<br />
Moritz Kroll<br />
Engine R&amp;D</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/02/fastflux-malware-leading-to-fakeav/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit for SMBv2 hole in Vista publicly available</title>
		<link>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/</link>
		<comments>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 17:01:32 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[SMBv2]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1237</guid>
		<description><![CDATA[10 days ago first exploit code for the security vulnerability in the SMBv2 protocol appeared in the underground. Today working exploit code for the open source penetration testing framework Metasploit was released. Therewith it is possible for the cybercriminals to produce malware which infects vulnerable systems &#8211; Windows Vista, Windows Server 2008 and Windows 7 [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" /><a title="TechBlog: SMBv2 Exploit Code released" href="http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/" target="_self">10 days</a> ago first exploit code for the security vulnerability in the SMBv2 protocol appeared in the underground. Today working exploit code for the open source penetration testing framework Metasploit was released. Therewith it is possible for the cybercriminals to produce malware which infects vulnerable systems &#8211; Windows Vista, Windows Server 2008 and Windows 7 up to Release Candidate 1.</p>
<p>Now administrators should take countermeasures if they haven&#8217;t done so yet. Microsoft doesn&#8217;t provide a patch to solve the issue, but offers a &#8220;<a title="Microsoft Knowledgebase Article with Fix-it-for-me-tool" href="http://support.microsoft.com/kb/975497" target="_blank">1-click-tool</a>&#8221; which disables SMBv2 services on the affected systems. This can have a small performance impact. Another suggested solution by Microsoft is to block traffic to the TCP Ports 139 and 445 &#8211; which would disable Windows Network Sharing altogether.</p>
<p>We&#8217;re constantly monitoring the malware scene &#8211; if malware using this attack vector appears we can protect our customers very fast. Anyhow it is a good idea to implement the workaround with the Fix-it-for-me-tool.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMBv2 Exploit Code released</title>
		<link>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/</link>
		<comments>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 04:31:56 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[SMBv2]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1168</guid>
		<description><![CDATA[Microsoft acknowledged a security hole in its SMBv2 implementation in Windows Vista, Server 2008 and Windows 7 up to the Release Candidate. With injecting specially prepared network packets attackers obviously are able to take complete control over affected computers.
Now a security company released an exploit for this vulnerability for their exploit framework for penetration testing. [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" />Microsoft acknowledged a <a title="Microsoft Security Advisory (975497): Vulnerabilities in SMB Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/advisory/975497.mspx" target="_blank">security hole</a> in its SMBv2 implementation in Windows Vista, Server 2008 and Windows 7 <a title="Tweet from Jonathan Ness" href="http://twitter.com/jness/statuses/3856921104" target="_blank">up to</a> the Release Candidate. With injecting specially prepared network packets attackers obviously are able to take complete control over affected computers.</p>
<p>Now a security company released an exploit for this vulnerability for their exploit framework for penetration testing. It should work for Windows Vista and Server 2008. Also, the open source framework Metasploit is said to release a reliable exploit soon.</p>
<p>So it is just a matter of time until malware exploiting the SMBv2 vulnerability will appear in the wild. The security hole could be used by a worm for example. Microsoft has no patch ready, but advises to implement one of the following workarounds:</p>
<p>- Disable SMBv2 support. The Redmond company also provides a <a title="&quot;Fix-it-for-me&quot; tool for disabling/enabling SMBv2" href="http://support.microsoft.com/kb/975497" target="_blank">&#8220;Fix-it-for-me&#8221;</a> tool which will do this for the user. There is also a tool for enabling SMBv2 again.</p>
<p>- Block access to the TCP ports 139 and 445.</p>
<p>While the latter completely disables network shares for windows, the first solution should only have a small performance impact. Administrators might be advised best to disable the SMBv2 support in their LANs until Microsoft releases a patch so that no worm can spread through this security hole.</p>
<p>We&#8217;re monitoring the malware scene very closely so we can provide updated detections for appearing worms or similar malware for this vulnerability if necessary.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Patchday Reloaded</title>
		<link>http://techblog.avira.com/2009/09/10/microsoft-patchday-reloaded/en/</link>
		<comments>http://techblog.avira.com/2009/09/10/microsoft-patchday-reloaded/en/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 09:51:08 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Microsoft Patchday]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1151</guid>
		<description><![CDATA[Now that didn&#8217;t happen for a while: Microsoft updated one of the security bulletins from Tuesday. It deals with a security flaw in TCP/IP networking. The first version of the bulletin mentioned Windows 2000, Vista, Server 2003 and Server 2008 as affected. The updated version also mentions Windows XP as affected.
Consequently, all Windows XP users [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" />Now that didn&#8217;t happen for a while: Microsoft updated one of the <a title="MS09-048: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx" target="_blank">security bulletins</a> from Tuesday. It deals with a security flaw in TCP/IP networking. The first version of the bulletin mentioned Windows 2000, Vista, Server 2003 and Server 2008 as affected. The updated version also mentions Windows XP as affected.</p>
<p>Consequently, all Windows XP users should run Windows Update again (as soon as the patch is available for XP, it currently isn&#8217;t) &#8211; though the impact of the error isn&#8217;t as critical as in Vista or Server 2008, where it allows for remote code execution. In Windows XP it is possible to cause a Denial of Service (DoS) condition with sending manipulated network packets to the unpatched computer.</p>
<p>Update: Microsoft updated the bulletin once more. Now it states &#8220;By default, Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows XP Professional x64 Edition Service Pack 2 do not have a listening service configured in the client firewall and are therefore not affected by this vulnerability.&#8221; So an update won&#8217;t be available any time soon &#8211; if at all, because in the default installation no service is listening on the network interface.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/10/microsoft-patchday-reloaded/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Security Bulletins for Windows flaws</title>
		<link>http://techblog.avira.com/2009/09/09/5-security-bulletins-for-windows-flaws/en/</link>
		<comments>http://techblog.avira.com/2009/09/09/5-security-bulletins-for-windows-flaws/en/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 05:51:09 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Microsoft Patchday]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1145</guid>
		<description><![CDATA[As announced last Friday, Microsoft released 5 security bulletins &#8211; all dealing with critical flaws within the Windows operating systems. Affected are Windows XP to Windows Vista and Server 2008.
The security holes can be abused by hackers to compromise Windows installations remotely. Microsoft expects that exploits for these holes appear soon, so it is advised [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" />As announced last Friday, Microsoft released <a title="Microsoft Overview of September 2009 Black Tuesday" href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx" target="_blank">5 security bulletins</a> &#8211; all dealing with critical flaws within the Windows operating systems. Affected are Windows XP to Windows Vista and Server 2008.</p>
<p>The security holes can be abused by hackers to compromise Windows installations remotely. Microsoft expects that exploits for these holes appear soon, so it is advised to install the patches as soon as possible!</p>
<p>Patches for the recently discovered SMB2 flaws within Vista and Windows 7 (only up to RC1 though) aren&#8217;t ready yet. Also missing are updates that fix the vulnerabilities in the FTP component of the Internet Information Services.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/09/5-security-bulletins-for-windows-flaws/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Holes and Updates</title>
		<link>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/</link>
		<comments>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 06:08:42 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1128</guid>
		<description><![CDATA[There is a severe security hole in Microsofts Internet Information Services (IIS) versions 5 and 6. &#8220;0-day&#8221; Exploit code is publicly available on the net. The error is within the FTP component. Thus Microsoft recommends as workaround to disable (anonymous) FTP on IIS, or to withdraw anonymous users the rights to create directories. A security [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />There is a severe security hole in Microsofts <a title="Microsofts Internet Information Services" href="http://www.microsoft.com/windowsserver2008/en/us/internet-information-services.aspx" target="_blank">Internet Information Services</a> (IIS) versions 5 and 6. &#8220;0-day&#8221; Exploit code is publicly available on the net. The error is within the FTP component. Thus Microsoft recommends as workaround to disable (anonymous) FTP on IIS, or to withdraw anonymous users the rights to create directories. A <a title="Security Advisory for IIS-FTP-hole" href="http://www.microsoft.com/technet/security/advisory/975191.mspx" target="_blank">security advisory</a> was already available but currently leads to a Bing search page. There you can see the advisory as &#8220;cached page&#8221; at least.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif"><img class="size-full wp-image-946 alignleft" title="opera_logo" src="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif" alt="opera_logo" width="40" height="33" /></a>Opera released the final <a title="Opera 10 download" href="http://www.opera.com/download/" target="_blank">version 10</a> of their Web browser. It fixes some security issues and has some new and improved features. They are listed in the <a title="Changelog for Opera 10.0" href="http://www.opera.com/docs/changelogs/windows/1000/" target="_blank">changelog</a>.</p>
<p><img class="alignleft size-full wp-image-1129" title="ooo-main-logo-col_150px" src="http://techblog.avira.com/wp-content/uploads/2009/09/ooo-main-logo-col_150px.gif" alt="ooo-main-logo-col_150px" width="100" height="30" />The <a title="OpenOffice.org project" href="http://www.openoffice.org/" target="_blank">OpenOffice.org</a> developers released OpenOffice.org 3.1.1 (<a title="OpenOffice.org 3.1.1 changelog" href="http://development.openoffice.org/releases/3.1.1.html" target="_blank">changelog</a>). This version fixes a security flaw in the Word document processing which can lead to system compromise. Users of OpenOffice.org should <a title="OpenOffice.org download" href="http://download.openoffice.org/" target="_blank">download </a>the new version and update immediatly.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates from Microsoft available</title>
		<link>http://techblog.avira.com/2009/08/12/updates-from-microsoft-available/en/</link>
		<comments>http://techblog.avira.com/2009/08/12/updates-from-microsoft-available/en/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 04:40:21 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1093</guid>
		<description><![CDATA[As announced before the weekend, Microsoft now released 9 security bulletins. The patches related to those bulletins close overall 19 security holes in Windows, Microsoft Office, Visual Studio, ISA- and BizTalk-Server, RDP client for Mac and the  .Net framework.
According to the exploitability index of Microsoft, exploit code is likely to appear for all but [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png"><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" /></a>As announced before the weekend, Microsoft now <a title="Microsoft Security Bulletin Summary for August 2009" href="http://www.microsoft.com/technet/security/bulletin/ms09-aug.mspx" target="_blank">released 9</a> security bulletins. The patches related to those bulletins close overall 19 security holes in Windows, Microsoft Office, Visual Studio, ISA- and BizTalk-Server, RDP client for Mac and the  .Net framework.</p>
<p>According to the exploitability index of Microsoft, exploit code is likely to appear for all but one of those vulnerabilities. Therefore it is recommended to install the updates as soon as possible.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/08/12/updates-from-microsoft-available/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
