<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avira - TechBlog &#187; Internet</title>
	<atom:link href="http://techblog.avira.com/tag/internet/en/feed/en/" rel="self" type="application/rss+xml" />
	<link>http://techblog.avira.com</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 06:38:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Avira switches to new update system</title>
		<link>http://techblog.avira.com/2009/11/19/avira-switches-to-new-update-system/en/</link>
		<comments>http://techblog.avira.com/2009/11/19/avira-switches-to-new-update-system/en/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 06:30:09 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Avira AntiVir Personal]]></category>
		<category><![CDATA[Avira AntiVir Professional]]></category>
		<category><![CDATA[Avira Premium Security Suite]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1420</guid>
		<description><![CDATA[Due to the fast growing amount of malware out there in the wild our virus definition files grow fast as well. We monitored the situation with our Updates very closely. We realise that users of the free Avira AntiVir Personal had issues fetching the Updates in time recently and did come up with a few [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-513" title="antivir_ok" src="http://techblog.avira.com/wp-content/uploads/2009/01/antivir_ok.png" alt="antivir_ok" width="26" height="26" />Due to the fast growing amount of malware out there in the wild our virus definition files grow fast as well. We monitored the situation with our Updates very closely. We realise that users of the free Avira AntiVir Personal had issues fetching the Updates in time recently and did come up with a few ideas how we could solve the problem and to better satisfy the needs of our users.</p>
<p>Two of the results are getting realized today: First, we switch from our current virus definition files (called iVDF) to a new format called nVDF. iVDF consists of 4 VDF files, while nVDF uses at least 32 files &#8211; we need to transfer less data for updating our virus definitions effectively in the future.</p>
<p>This means that we need to deliver about 25 MByte to every Avira installation starting today for switching to the new update system. This might lead to some delays for some users, especially for the users of our free version Avira AntiVir Personal. Just to get an idea about what we&#8217;re talking here: More than 100.000.000 Users are trying to get the update more or less on the same day. That is more than 2.5 Petabytes (or 2,500 Terabytes) of traffic.</p>
<p>To ease the bandwidth bottleneck, we decided to additionally use a Content Delivery Network (CDN). We were first testing a CDN built up by our current Internet service provider. Shortly after activating the CDN, the redirectors &#8211; which redirect the update requests to servers close to the users location &#8211; were overloaded and couldn&#8217;t answer the requests anymore. The situation was solved a little later on, but the CDN isn&#8217;t big enough yet to spread this huge update in time. So we decided to switch to a global player in the CDN market to deliver the update.</p>
<p>We hope that the data is transfered much faster this way so also the users of free Avira AntiVir Personal can enjoy their security solution without any problems: After this Update the situation will get much better for the users of Avira AntiVir Personal.</p>
<p>N.B.: Users of commercial Avira products like Avira AntiVir Premium, Avira Premium Security Suite or Avira AntiVir Professional don&#8217;t face any of these problems as they access our servers with reserved bandwidth.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/19/avira-switches-to-new-update-system/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November Patchday: Apple starts first</title>
		<link>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/</link>
		<comments>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 06:54:02 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Patchday]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1379</guid>
		<description><![CDATA[Just a few hours before Microsoft will release Updates for its software, Apple released version 10.6.2 of Mac OS X and Security Update 2009-006, respectively. This Update fixes numerous of security issues within the Mac operating system.
You can download the Update from Apples web site or just use the updater of Mac OS X. As [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-404" title="apple_1" src="http://techblog.avira.com/wp-content/uploads/2008/12/apple_1.png" alt="apple_1" width="45" height="50" />Just a few hours before Microsoft will release Updates for its software, Apple released version 10.6.2 of Mac OS X and Security Update 2009-006, respectively. This Update <a title="About Security Update 2009-006 / Mac OS X v10.6.2" href="http://support.apple.com/kb/HT3937" target="_blank">fixes numerous</a> of security issues within the Mac operating system.</p>
<p>You can download the Update from Apples <a title="Apple Support Downloads" href="http://support.apple.com/downloads/" target="_blank">web site</a> or just use the updater of Mac OS X. As some of the vulnerabilities allow for remote code injection and execution, the Update is recommended.</p>
<p>The Apple platforms will soon be targeted with more energy by cyber criminals: Just recently hackers attacked for example Apples iPhones which are jailbreak&#8217;ed &#8211; they broke into the phone through the standard password for the SSH installation. So at least change the default passwords if you used jailbreak.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Further critical Updates</title>
		<link>http://techblog.avira.com/2009/11/06/further-critical-updates/en/</link>
		<comments>http://techblog.avira.com/2009/11/06/further-critical-updates/en/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 06:48:32 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe Shockwave Player]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1367</guid>
		<description><![CDATA[Already last week Opera released version 10.01 of its Web Browser. It closes some security holes. At least one of them can lead to code injection (for example to infect the computer with a Trojan). Users are advised to install the new version fast.
Meanwhile, the Mozilla Foundation has updated Firefox to version 3.5.5. The developers [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-946" title="opera_logo" src="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif" alt="opera_logo" width="50" height="40" />Already last week Opera released version 10.01 of its Web Browser. It closes <a title="Changelog for Opera 10.01" href="http://www.opera.com/docs/changelogs/windows/1001/" target="_blank">some</a> security holes. At least one of them can lead to code injection (for example to infect the computer with a Trojan). Users are advised to install the new version fast.</p>
<p><img class="alignleft size-full wp-image-255" title="ff_3" src="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png" alt="ff_3" width="50" height="40" />Meanwhile, the Mozilla Foundation has updated Firefox to <a title="Changelog for Firefox 3.5.5" href="http://www.mozilla-europe.org/en/firefox/3.5.5/releasenotes/" target="_blank">version 3.5.5</a>. The developers only mention stability fixes, this release doesn&#8217;t seem to fix security issues. Anyhow it is a good idea to install the update.</p>
<p><img class="alignleft size-full wp-image-1369" title="java_logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/java_logo.jpg" alt="java_logo" width="50" height="50" />There was another security Update for Sun Java. Version <a title="Java download" href="http://java.sun.com/javase/downloads/index.jsp" target="_blank">6 Update 17</a> fixes a lot of security vulnerabilities. Those flaws may lead to remote code execution, thus updating immediately is recommended.</p>
<p><img class="alignleft size-full wp-image-1372" title="adobe_shockwave_logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/adobe_shockwave_logo.png" alt="adobe_shockwave_logo" width="50" height="40" />What else? Adobe has released Shockwave Player 11.5.1.602 which also closes <a title="Adobe Security Bulletin" href="http://www.adobe.com/support/security/bulletins/apsb09-16.html" target="_blank">security holes</a> in the software which allow for remote malware injection. Users of the Shockwave Player (which is different from Adobe Flash Player) should also <a title="Adobe Shockwave Player Download" href="http://get.adobe.com/shockwave/" target="_blank">update</a> their software immediately.</p>
<p><img class="alignleft size-full wp-image-1377" title="chrome-logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/chrome-logo.png" alt="chrome-logo" width="50" height="50" />Today also Google released an update for its <a title="Google Chrome Website" href="http://www.google.com/chrome" target="_blank">Chrome</a> browser. It fixes 2 security problems which put users at risk.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/06/further-critical-updates/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worm instead of Avira Keygen</title>
		<link>http://techblog.avira.com/2009/09/22/worm-instead-of-avira-keygen/en/</link>
		<comments>http://techblog.avira.com/2009/09/22/worm-instead-of-avira-keygen/en/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 05:57:57 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Keygen]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1197</guid>
		<description><![CDATA[ On a popular Bittorrent site during the last weekend there appeared a package that allegedly contains Avira AntiVir Premium and a so called keygen. A keygen is a tiny piece of software that calculates a license number for a commercial software, for free.
Now upon starting the assumed keygen, instead of providing the user with [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-465" title="malware_warning" src="http://techblog.avira.com/wp-content/uploads/2008/12/malware_warning.png" alt="malware_warning" width="56" height="53" /> On a popular Bittorrent site during the last weekend there appeared a package that allegedly contains Avira AntiVir Premium and a so called keygen. A keygen is a tiny piece of software that calculates a license number for a commercial software, for free.</p>
<p>Now upon starting the assumed keygen, instead of providing the user with a serial number, it infects the system. It drops three files on the hard disk:<br />
&lt;%AllUsers Profile%&gt;\Local Settings\Application Data\scvhost.exe<br />
C:\Sys.exe<br />
C:\autorun.inf</p>
<p>The dropped scvhost.exe also gets added to the autorun registry keys so it gets executed after every reboot. The autorun.inf and sys.exe aren&#8217;t only created on the system hard disk, but also on all removable drives. This seems to be the spreading mechanism of the worm.</p>
<p>If you take a closer look at the malware, one thing sure catches attention. At the end you find the strings &#8220;VaQxiNe-steam=1firefox=1cookies=1sandboxie=1zonealarm=1<br />
wireshark=1anubis=1virtualpc=1keyscrambler=1startup=1usb=1task=1&#8243;. This hints that the Vaqxination toolkit got used. The construction kit has some features interesting for cybercriminals:</p>
<div id="attachment_1205" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/09/090922-Vaqxine-Screenshot.png"><img class="size-medium wp-image-1205" title="090922-Vaqxine-Screenshot" src="http://techblog.avira.com/wp-content/uploads/2009/09/090922-Vaqxine-Screenshot-300x272.png" alt="Fig. 2: The Malware Toolkit used to create the worm." width="300" height="272" /></a><p class="wp-caption-text">Fig. 2: The Malware Toolkit used to create the worm.</p></div>
<p>Further Features of the toolkit according to the advertisement of the Toolkit programmer:<br />
- Vista UAC Bypass<br />
- Run-as-admin Bypass<br />
- Fully stealth<br />
- &#8220;Legit&#8221; Windows Process<br />
- Stronger output encryption<br />
- Only 15 US-$ for the Toolkit.</p>
<p>That string seems to be the configuration that the malware creator used with the Malware Construction Kit. The features seem to work as described, for example the malware is undetectable by the Anubis sandbox system:</p>
<div id="attachment_1198" class="wp-caption alignnone" style="width: 310px"><a href="http://techblog.avira.com/wp-content/uploads/2009/09/090922-Anubis_bypass.png"><img class="size-medium wp-image-1198 " title="090922-Anubis_bypass" src="http://techblog.avira.com/wp-content/uploads/2009/09/090922-Anubis_bypass-300x228.png" alt="Fig. 1: The autorun-worm uses some anti-sandboxing tricks." width="300" height="228" /></a><p class="wp-caption-text">Fig. 1: The autorun-worm uses some anti-sandboxing tricks.</p></div>
<p>The Vaqxination Malware Construction Toolkit currently steals passwords from Firefox and Steam and also logs all keystrokes. Those log files get sent to the email account the creator has chosen before building the malware.</p>
<p>Avira detects the bogus key generator as <a title="Worm/Autorun.sxa" href="http://www.avira.com/en/threats/section/details/id_vir/4528/worm_autorun.sxa.html" target="_self">Worm/Autorun.sxa</a> with VDF version 7.01.06.18. For malware authors, keygens are a simple way to infect user PCs for a longer time already. If an antivirus solution warns from malware within such a keygen, this is nearly always a correct detection &#8211; the probability of a false positive detection is extremely low. Also the websites where such keygens usually are offered often try to infect PCs via drive-by-downloads. So be very careful when searching for software like this!</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 279px; width: 1px; height: 1px;"><span style="font-family: Tahoma;"><span style="font-size: x-large;"><span style="color: #00bfff;"><span style="font-weight: bold;">VAQXINATION v6.0</span></span></span></span></div>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/22/worm-instead-of-avira-keygen/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Holes and Updates</title>
		<link>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/</link>
		<comments>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 06:08:42 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1128</guid>
		<description><![CDATA[There is a severe security hole in Microsofts Internet Information Services (IIS) versions 5 and 6. &#8220;0-day&#8221; Exploit code is publicly available on the net. The error is within the FTP component. Thus Microsoft recommends as workaround to disable (anonymous) FTP on IIS, or to withdraw anonymous users the rights to create directories. A security [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />There is a severe security hole in Microsofts <a title="Microsofts Internet Information Services" href="http://www.microsoft.com/windowsserver2008/en/us/internet-information-services.aspx" target="_blank">Internet Information Services</a> (IIS) versions 5 and 6. &#8220;0-day&#8221; Exploit code is publicly available on the net. The error is within the FTP component. Thus Microsoft recommends as workaround to disable (anonymous) FTP on IIS, or to withdraw anonymous users the rights to create directories. A <a title="Security Advisory for IIS-FTP-hole" href="http://www.microsoft.com/technet/security/advisory/975191.mspx" target="_blank">security advisory</a> was already available but currently leads to a Bing search page. There you can see the advisory as &#8220;cached page&#8221; at least.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif"><img class="size-full wp-image-946 alignleft" title="opera_logo" src="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif" alt="opera_logo" width="40" height="33" /></a>Opera released the final <a title="Opera 10 download" href="http://www.opera.com/download/" target="_blank">version 10</a> of their Web browser. It fixes some security issues and has some new and improved features. They are listed in the <a title="Changelog for Opera 10.0" href="http://www.opera.com/docs/changelogs/windows/1000/" target="_blank">changelog</a>.</p>
<p><img class="alignleft size-full wp-image-1129" title="ooo-main-logo-col_150px" src="http://techblog.avira.com/wp-content/uploads/2009/09/ooo-main-logo-col_150px.gif" alt="ooo-main-logo-col_150px" width="100" height="30" />The <a title="OpenOffice.org project" href="http://www.openoffice.org/" target="_blank">OpenOffice.org</a> developers released OpenOffice.org 3.1.1 (<a title="OpenOffice.org 3.1.1 changelog" href="http://development.openoffice.org/releases/3.1.1.html" target="_blank">changelog</a>). This version fixes a security flaw in the Word document processing which can lead to system compromise. Users of OpenOffice.org should <a title="OpenOffice.org download" href="http://download.openoffice.org/" target="_blank">download </a>the new version and update immediatly.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/02/security-holes-and-updates/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be aware of the fraudsters</title>
		<link>http://techblog.avira.com/2009/08/03/be-aware-of-the-fraudsters/en/</link>
		<comments>http://techblog.avira.com/2009/08/03/be-aware-of-the-fraudsters/en/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 12:08:04 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[e-Crime]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Online fraud]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1067</guid>
		<description><![CDATA[If you are a German user and receive an email coming from &#8220;Virenwarndienst&#8221; with the email address  &#60;Virenwarndienst@&#60;Abzock-Webseite&#62;.info&#62; do not register there for downloading the software. This site is a price trap. The users who register there are closing a contract for 2 years where they have to pay 8 euro per month.
The text [...]]]></description>
			<content:encoded><![CDATA[<p>If you are a German user and receive an email coming from &#8220;Virenwarndienst&#8221; with the email address  &lt;Virenwarndienst@&lt;Abzock-Webseite&gt;.info&gt; do not register there for downloading the software. This site is a price trap. The users who register there are closing a contract for 2 years where they have to pay 8 euro per month.</p>
<p>The text of the email is:</p>
<p><em>&#8220;Achtung &#8211; Wichtige Virenwarnung:</em></p>
<p><em>Nach Berichten des Bundesamts für Sicherheit in der Informationstechnik (BSI) ist derzeit ein besonders gefährlicher Virus/Trojaner im Umlauf.</em></p>
<p><em>Ihr PC ist ungeschützt und damit potentiell gefährdet. Bitte laden Sie unbedingt in Ihrem eigenen Interesse einen aktuellen Virenscanner herunter.</em></p>
<p><em>Die aktuellste Version erhalten Sie direkt hier:</em></p>
<p><em>http://www.</em>&lt;Abzock-Webseite&gt;<em>.info/</em></p>
<p><em>Mit freundlichen Grüßen</em></p>
<p><em>Ihr Virenwarndienst&#8221;</em></p>
<p>It says that the German government authority for IT Security has issued a warning because a dangerous Virus/Trojan is in the wild. It then advises all users to download a security solution (note: Avira AntiVir isn&#8217;t mentioned there) in order not to endanger their computer. Once following the link in the mail and trying to download the software, the unsuspecting users are forced to register:</p>
<div id="attachment_1068" class="wp-caption alignnone" style="width: 160px"><a href="http://techblog.avira.com/wp-content/uploads/2009/08/090803-abzockseite-info.png"><img class="size-thumbnail wp-image-1068 " title="090803-abzockseite-info" src="http://techblog.avira.com/wp-content/uploads/2009/08/090803-abzockseite-info-150x150.png" alt="Fig. 1: The fraudsters need the address data in order to send bills for downloading the free software." width="150" height="150" /></a><p class="wp-caption-text">Fig. 1: The fraudsters need the address data in order to send bills for downloading the free software.</p></div>
<p>Almost nobody reads the AGB (EULA) which specifies somewhere that you are signing a contract for two years, for 8 euro per Month.</p>
<p>The users who want to obtain the free version of Avira AntiVir, called Avira AntiVir Personal, can visit the website <a title="Aviras FreeAV Homepage" href="http://www.free-av.de/" target="_blank">www.free-av.com</a> and download the software for free.</p>
<p style="text-align: right;">Sorin Mustaca<br />
Manager International Software Development</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/08/03/be-aware-of-the-fraudsters/en/feed/en/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Adobe-Patches are out</title>
		<link>http://techblog.avira.com/2009/07/31/adobe-patches-are-out/en/</link>
		<comments>http://techblog.avira.com/2009/07/31/adobe-patches-are-out/en/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 05:37:09 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Flash-Player]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Shockwave-Player]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1059</guid>
		<description><![CDATA[As announced, Adobe released the first updates for the critical security vulnerabilities in its products already. The first update is for Adobe Flash-Player &#8211; the new version 10.0.32.18 is supposed to close the security hole in the software. You can get it via Adobes web site.
During the day, Adobe wants to release further patches for [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-870" title="acrobat_logo" src="http://techblog.avira.com/wp-content/uploads/2009/05/acrobat_logo.png" alt="acrobat_logo" width="31" height="33" />As announced, Adobe <a title="Security updates available for Adobe Flash Player" href="http://www.adobe.com/support/security/bulletins/apsb09-10.html" target="_blank">released</a> the first updates for the <a title="Security flaw in Adobe PDF/Flash" href="http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/" target="_self">critical security vulnerabilities</a> in its products already. The first update is for Adobe Flash-Player &#8211; the new version 10.0.32.18 is supposed to close the security hole in the software. You can get it via Adobes <a title="Get Flash-Player at Adobe" href="http://www.adobe.com/go/getflashplayer" target="_blank">web site</a>.</p>
<p>During the day, Adobe wants to release further patches for Adobe Reader and Acrobat. Also, a <a title="Security update available for Shockwave Player" href="http://www.adobe.com/support/security/bulletins/apsb09-11.html" target="_blank">new version</a> of the Shockwave-Player is already available. Please install the updated versions as soon as possible.</p>
<p>Let me thank all the hardworking administrators out there at this place, especially the Avira admins. They have to roll out all these updates today and already had a busy week due to Microsoft&#8217;s out-of-band updates from Tuesday. Don&#8217;t forget, it&#8217;s <a title="System Administrator Appreciation Day" href="http://www.sysadminday.com/" target="_blank">System Administrator Appreciation</a> day!</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/31/adobe-patches-are-out/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Out-of-band Patches from Microsoft</title>
		<link>http://techblog.avira.com/2009/07/25/out-of-band-patches-from-microsoft/en/</link>
		<comments>http://techblog.avira.com/2009/07/25/out-of-band-patches-from-microsoft/en/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 14:52:29 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Out-of-band]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1039</guid>
		<description><![CDATA[Microsoft announced extraordinary updates for the Internet Explorer and for Visual Studio for this Tuesday to come. While the company rates the security issue in Visual Studio only as moderate, the IE-flaws &#8211; which also affect IE8 &#8211; are considered critical and allow for remote code execution.
Prepare for those updates as they are really critical [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-465" title="malware_warning" src="http://techblog.avira.com/wp-content/uploads/2008/12/malware_warning.png" alt="malware_warning" width="56" height="53" />Microsoft <a title="Microsoft Security Bulletin Advance Notification for July 2009" href="http://www.microsoft.com/technet/security/bulletin/ms09-jul-ans.mspx" target="_blank">announced extraordinary updates</a> for the Internet Explorer and for Visual Studio for this Tuesday to come. While the company rates the security issue in Visual Studio only as moderate, the IE-flaws &#8211; which also affect IE8 &#8211; are considered critical and allow for remote code execution.</p>
<p>Prepare for those updates as they are really critical and necessary if Microsoft decides to do an out-of-band release. Install them ASAP when available.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/25/out-of-band-patches-from-microsoft/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security flaw in Adobe PDF/Flash</title>
		<link>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/</link>
		<comments>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 11:37:50 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Infections]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1029</guid>
		<description><![CDATA[There are security flaws within Adobe Reader and Acrobat and the Adobe Flash Player which are getting actively exploited on the net currently. The company has published a security advisory where it announces that they are currently investigating the problem and plan an update for the 30th of July.
Avira antivirus solutions already detect the malicious [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-870" title="acrobat_logo" src="http://techblog.avira.com/wp-content/uploads/2009/05/acrobat_logo.png" alt="acrobat_logo" width="31" height="33" />There are security flaws within Adobe Reader and Acrobat and the Adobe Flash Player which are getting actively exploited on the net currently. The company has published a <a title="Security advisory for Adobe Reader, Acrobat and Flash Player" href="http://www.adobe.com/support/security/advisories/apsa09-03.html" target="_blank">security advisory</a> where it announces that they are currently investigating the problem and plan an update for the 30th of July.</p>
<p>Avira antivirus solutions already detect the malicious PDF files as EXP/Pidief.TH and the dropped malware by those documents as TR/Drop.Wmach and TR/Spy.WMach, respectively. Anyhow it is a good idea to take additional security measures until Adobe provides an update.</p>
<p>Adobe recommends to delete or rename the file authplay.dll that ships with the Reader and with Acrobat. Also, enabling Data Execution Prevention (DEP) and activating the User Access Control (UAC) in Windows Vista shall mitigate the risk according to Adobe.</p>
<p>Another solution would be using a different PDF reader and disabling Adobe PDF and Flash within the web browser via its add-ons-manager. The NoScript extension for Firefox also helps preventing Flash applications to run in the browser; it is possible that drive-by-downloads via malicious Flash applications embedded in web sites turn up soon.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/23/adobe-security-flaw-in-pdfflash/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Firefox 3.5.1 closes security hole</title>
		<link>http://techblog.avira.com/2009/07/17/firefox-3-5-1-closes-security-hole/en/</link>
		<comments>http://techblog.avira.com/2009/07/17/firefox-3-5-1-closes-security-hole/en/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 08:06:28 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1014</guid>
		<description><![CDATA[The Mozilla Foundation released Firefox 3.5.1 today. The new version fixes an issue which could get abused by web sites to inject malicious code into a victim&#8217;s computer. The vulnerability was in the Just-In-Time compiler for JavaScript which is a new feature in Firefox 3.5. Please update your Firefox to the most recent version by [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-255 alignleft" title="ff_3" src="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png" alt="ff_3" width="60" height="50" />The Mozilla Foundation released Firefox 3.5.1 today. The new version fixes an issue which could get abused by web sites to inject malicious code into a victim&#8217;s computer. The vulnerability was in the Just-In-Time compiler for JavaScript which is a new feature in Firefox 3.5. Please update your Firefox to the most recent version by clicking on &#8220;Help&#8221; and selecting &#8220;Search for updates&#8221; now.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/07/17/firefox-3-5-1-closes-security-hole/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
