security web
PLEASE PLEASE HELP I can not open a security web page it keeps coming up web
page not found I am using windows xp if that helps many thanks in advance
Lynnette Tag: vbv Tag: 51962
MS04-011 on DELL CPxJ corrupts video?
Running NT4 SP6a after installing the patch, the video is
corrupted and will only run using the default VGA drivers.
Removing / reinstalling drivers doesn't fix. the only way
to get it to work is by removing the patch.
This is a DELL Lattitude CPxJ, NT4, SP6a, ATI Rage
Mobility video.
Please help! Tag: vbv Tag: 51954
MSSQL Stack Overflow?
Hi:
My Norton Firewall blocks this message numerous times a
day. B4 this same companies were blocked with another
message having to do with backdoor ports. anyone having
similar problems, and should i be concerned. ? Should I
restore my computer back a month or so? Thx Tag: vbv Tag: 51952
AVOID THESE LIKE THE PLAGUE!
If you need to protect your computer from malware
(unwanted pop-ups from software installed on your
computer, browser/homepage hijackings, dialers,
keyloggers, etc.), then please get Ad-Aware, Spybot Search
& Destroy and some others; they are REPUTABLE!
However, do NOT get the following; they are programs that
SAY they will protect you, but have been found by various
websites/individuals to actually HARM your computer!
Notice some have similar names to the REPUTABLE programs
like the fantastic Ad-Aware, Spybot, SpywareBlaster, etc.
So...
AVOID THESE LIKE THE PLAGUE:
Spy Wiper
AdWare Remover Gold
BPS Spyware Remover
Online PC-Fix SpyFerret
SpyBan
SpyBlast
SpyGone
SpyHunter
SpyKiller
SpyKiller Pro
SpywareNuker
TZ Spyware-Adware Remover
SpyAssault
InternetAntiSpy
Virtual Bouncer
AdProtector
SpyFerret
SpyGone
SpyAssault
Pal Spyware Remover
NoAdware
Spyware Killa
Scanspyware
ALSO: XP Antispy is LEGIT, however, their former domain
was taken over by someone who's pushing a dialer and
trying to pass it off as XP Antispy. My suggestion: avoid
XP Antispy for now to be on the safe side! You never know
which one you are getting!
If anyone else has anything to add to the list, feel free
but make sure it deserves the "recognition" (in other
words, don't put it here because you "don't like it"; put
it here because a reputable researcher found it to be bad).
And please, send this list to all your friends/co-workers
so the word spreads about these programs that will do
NOTHING but harm your computer and betray your trust. Tag: vbv Tag: 51927
Manually installed patches do not show up
1) When I Download&Save updates/patches for our current
corporate configuration (Office 97, and Outlook2K) and
manually install them (successfully) When I check using
the automatic install, M/S say's that these
patches/updates need to be installed.
What's going on? Do I have to use the automatic installer
from the internet for every client PC ? Tag: vbv Tag: 51922
lsass.exe, problems after applying ms04-11
Hello,
I had several calls concerning the patch ms04-11 needed
for the sasser. There are articles about the problems
related to it, but nothing's talking about printers
malfunctioning. Anybody had similar problems? I asked
the local support people to reinstall the printers with
the drivers to see if the problem persists. Tag: vbv Tag: 51916
Sasser: How critical is "not critical"
From
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
Are Windows 98, Windows 98 Second Edition, or Windows Millennium Edition
critically affected by any of the vulnerabilities that are addressed in this
security bulletin?
No. None of these vulnerabilities are critical in severity on Windows 98, on
Windows 98 Second Edition, or on Windows Millennium Edition.
Any comment welcome. Tag: vbv Tag: 51915
Help with MS Baseline Security Analyzer
I am somewhat confused by the results of a scan I just ran with the MS
Baseline Security Analyzer. It is telling me that two security updates
are out of date and 3 could not be confirmed as follows:
MSXML 3 lacks the latest service pack SP 4
MSXML 4 lacks the latest service pack SP 2
MS)#-008
MS03-030
MS03-051
Yet when I run Windows Update it tells me there are no critical
updates to be installed? Exactly what are the MSXML service packs and
what do they do? Where can they be found to download?
Can some kind soul explain what is happening and should I attempt to
download and install the above updates even though Windows Update
doesn't recognize the need?
Thanks for any assistance.
Frank Tag: vbv Tag: 51914
Possible security threat - Passport and Sympatico.ca users
If you receive the following email, you may be at risk
from a malicious attack if you follow the instructions
contained within. Can anyone verify the validity of this
email?:
---------------------------
-----Original Message-----
From: Microsoft .NET Passport
[mailto:PPMSVCMG@PASSPORT.NET]
Sent: May 5, 2004 12:15 AM
To:
Subject: Important message from Microsoft .NET Passport -
action
required
Hello :
This is an important message from Microsoft concerning
the Microsoft .NET Passport account associated with your
sympatico.ca e-mail address.
Both Microsoft and Bell Canada are committed to
simplifying your online experience. Therefore we are
taking efforts to ensure that active Bell Sympatico
Internet customers can continue to use the .NET Passport
that is associated with their sympatico.ca e-mail
address.
Since there is a Passport account associated to your
Sympatico e-mail address, we ask that you please verify
that you are the user of the Passport account and that
you give consent to Bell Canada to manage your
Microsoft .NET Passport account. It's a quick and easy
process to verify your account.
Instructions on how to verify your account are below, as
well as some important questions and answers.
To verify your Passport account:
1. In your Web browser, type passport.net in the
Address bar and press Enter.
2. On the Passport home page, click the Sign In
button, and sign in to your Passport account.
3. Follow the instructions to verify your e-mail
address.
If you did not register the Passport using this e-mail
address, or if you do not agree to give Bell Canada
consent to manage your Passport account, take no action,
and we will disable the Passport account 20 days from the
date this message was sent. This will have no affect on
your Sympatico subscription or sympatico.ca e-mail
address.
To request additional help from Passport Customer
Support, click
http://register.passport.net/contactus.srf?LC=1033.
Important Questions and Answers
What is a .NET Passport account?
Microsoft .NET Passport is a service that enables you to
sign in to multiple services, such as MSN Messenger or
Hotmail, with a single e-mail address and password. For
more information, visit the Passport home page at
http://www.passport.net.
I don't have a Passport account. Why am I seeing this
message?
Another person may have created a Passport account with
your current sympatico.ca e-mail address (such as a
family member, or an individual who had the e-mail
address before you). This does not mean that the user has
access to your e-mail messages or any other personal
information - it simply means that they have used the e-
mail address as a sign-in name for their Passport account.
If this is the case, you can ignore this e-mail message
and do nothing, and 20 days from the date this message
was sent, we will disable the user from using your e-mail
address as their Passport sign-in name.
What does it mean to give consent to Bell Canada to
manage my sympatico.ca .NET Passport?
As the owner of the sympatico.ca domain, Bell Canada
assigns sympatico.ca e-mail addresses. In addition,
sympatico.ca is now a 'sponsored domain' which is
associated with a special kind of .NET Passport where
Bell Canada will ensure only Bell Sympatico Internet
customers can obtain sympatico.ca .NET Passports.
What happens if I don't verify my e-mail address or give
Sympatico consent to manage my Passport account?
After 20 days from the date this e-mail message was sent,
if you have not yet verified your e-mail address with
Passport, you will no longer be able to sign in to any
Passport participating site until you change the e-mail
address in your Passport account.
In addition, you will lose data associated with your
Passport sign-in e-mail address, such as your MSN
Messenger contact list.
No matter what your decision is, your existing Sympatico
subscription and e-mail account will not be affected.
Only your Passport account will be affected.
ADDITIONAL INFORMATION:
Passport is committed to protecting your privacy. We
encourage you to review the Passport privacy statement
at:
http://www.passport.net/privacypolicy.asp
To request additional help from Passport Customer
Support, click
http://register.passport.net/contactus.srf?LC=1033
Please do not reply to this message; it was sent from an
unmonitored e-mail address and we are unable to respond
to any replies. Tag: vbv Tag: 51913
SUS require admin previlegies on client to install
No, that's right, I do not want the users to be admins.
But if the not are admins, no security patches from the
SUS server will be installed.
Solution?
<- Christer ->
>-----Original Message-----
>Christer wrote:
>> Is it possible to install security patches from a SUS
>> server without having admin previlegies on the client?
>>
>> Today all XP users are administrators on there own
>> computers to get updates from the SUS server installed.
>
>If you want the best from SUS, you want the end users to
NOT be admins.
>
>--
><- Shenan ->
>-- Tag: vbv Tag: 51912
Re: Problems with installing Security patch Q837009
Hi Bill,
Thanks for the reply post!
Having looked at the version installed in Help (as you suggested) it shows
version 6.00.280.1123. This would mean that I am running OE6 with IE
version 6.0.2800.1106.xpsp2.030422-1633.
Do either of these versions have flaws that make them incompatible? Both
are updated via Microsoft Official Updates site and I have no problems
updating from the site. My problem seems to come when installing individual
patches...
alba.
"Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
news:%23mrP3EkMEHA.2532@TK2MSFTNGP10.phx.gbl...
When you go to Help, about, in Outlook Express--what version number is
displayed?
It is possible to be running Outlook Express 5.x and IE 6, because of a flaw
in the upgrade process. It is important to fix this because the older OE
has some bugs which are not getting patched.
"alba" <alba1314@ntlworld.com> wrote in message
news:%23Tg4bTgMEHA.3944@tk2msftngp13.phx.gbl...
I am running Windows XP Pro and Internet Explorer 6, along with Outlook
Express 6 and am having problems installing Security patch Q837009.
Each time I try to install the patch I get a Microsoft Internet Explorer
Update message telling me that Outlook Express 6.0 needs to be installed -
Surely OE6 is part of IE6 and therefore installs when Windows is installed??
I have tried to download OE 6.0 as a separate download from IE and on trying
to install it I am told that I have a newer version already on my PC!
This is not the first time that I have experienced problems with installing
patches relating to Outlook Express - The problem seems to occur whenever I
download and install individual patches. Whenever I download and install
patches using Critical Updates on the Microsoft Update site, I don't seem to
have this problem.
Can anyone advise why this happens?
alba.
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.677 / Virus Database: 439 - Release Date: 04/05/2004 Tag: vbv Tag: 51910
Sasser virus
I read alot about this Vasser worm or virus and that
Microsoft has a patch for it. I run Windows update and
there are no updates available for my system. Windows ME.
I then check my install history for updates and the patch
for this Sasser MS835732 does not show as being installed.
I have Works Suite 2000.
Should I manually install this patch or just forget about
it. I don't appear to be infected.
Thanks Tag: vbv Tag: 51908
Scanning tool?
I wanted to ask everyone in the group what they are using to track trends
caused by for example the sasser worm. Is anyone using a tool that can track
machines that are trying to spam segments of a network or at least could
send notifications of a pattern?
TIA... Tag: vbv Tag: 51906
** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.05.05
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
I'm getting an LSASS error message, and/or I have the Sasser virus.
1) Run anti-virus that is configured to download the latest updates every
week or even every day. www.grisoft.com is free anti-virus.
2) You also need to install all the patches for your system software from
http://windowsupdate.microsoft.com, starting with the MS04-011 patch.
Microsoft generally releases security patches on the second Tuesday of more
or less every month.
3) Once you're infected, you may need to download and run a free Sasser
virus removal tool such as the Stinger tool from www.McAfee.com or the free
tool from http://www.microsoft.com/security/incident/sasser.asp
4) You're not running a firewall, or your firewall isn't protecting you.
Running a firewall would have protected you from this. Free firewall
software is available from www.kerio.com, www.zonealarm.com and/or
www.sygate.com
5) You need to do ALL of these things, or you won't have much success.
You should also make sure you get the latest Microsoft patches monthly and
anti-virus updates at least weekly.
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: vbv Tag: 51903
Accesing data from a slaved hard drive
Hi
We have a little problem - a customer's system no longer
boots up and he needs the data from it (No backups- of
course). We are trying to put it onto another system as a
slave drive (like with 95/98/ME) but windows will not
allow access -displays 'Access Denied' when you try and
open the customers personal data.
My question is - is there any way round this? Or is the
data no effectivly lost.
(Just for info - the HDD and data is fine, it just won't
boot!)
Thanks In Advance
Jamie Tag: vbv Tag: 51902
SUS require admin previlegies on the client
Is it possible to install security patches from a SUS
server without having admin previlegies on the client?
Today all XP users are administrators on there own
computers to get updates from the SUS server installed.
Regards,
Christer Johansson Tag: vbv Tag: 51895
Office/Active Directory Compatibility?
I run a network with 40 machines, at the moment we have an
older version of office (2000) running on a Win 2000
server driven network and a mixture of 2000 and XP
workstations.
Although the active directory lets me set options on win
explorer to limit access to files and folders the settings
do not apply to the explorer plug-in built into office.
This allows staff to browse other area of the netwok
wihout permissions.
If I upgrade to office 2003 will there be a better
integration with active directory, or are there any other
ways of securing the office explorer?
Mnay Thanks
Dave Tag: vbv Tag: 51894
CA Enterprise SCEP-Add on
Hi
I have a CA Enterprise (2003) in a 2003 Active Directory Domain. I have installed the SCEP-Add on to enroll a certificate to a PIX 525 (Ver. 6.32). When I make a request, from the PIX console, to enroll a certificate, it is rejected by the CA with this message: denied by policy module
I had read that there is a different configuration with "SCEP-Add on" in a CA Enterprise. I need to kno
which are the steps needed to configure SCEP-Add on in a CA Enterprise. The "SCEP-Add on" release note tells that these steps are described in Windows 2003 Resource Kit Documentation, but i didn't found them
Thanks in advanc
Paolo Tag: vbv Tag: 51891
secedit
I'm using secedit to configure file system and registry ACL
If the number of entry is more than 8 (or the lenght of string is more than...), for example
[Registry Keys]
"MACHINE\SOFTWARE\ORACLE",2,"D:P(A;CI;GA;;;SY)(A;CI;GA;;;BA)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1140)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1142)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1143)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1144)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1145)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1146)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1152)(A;CI;GRGX;;;S-1-5-21-602162358-1606980848-1708537768-1153)(A;CI;GRGX;;;S-1-5-21-515967899-152049171-725345543-1022)(A;CI;GRGX;;;S-1-5-21-515967899-152049171-725345543-1020)
secedit return the following erro
Error 87: the parameter is incorrect
I must configure ACL for the specified users or group (I can't use the generic group Authenticated Users)
than I must use the SID rapresentation (not default user/group) and normally, is more than 8
Do You have an idea to solve my problem
Thank
Rita Tag: vbv Tag: 51889
"835732" upd.problem
Hi !
After applying the "835732" security update my title bars
and the "start bar"(at the bottom) goes black ?
I'm using XP pro sp1.
Why is this, and what do i do to remedy this problem ?
(lucky for me i did a "ghost" backup before updating)
Michael Tag: vbv Tag: 51888
SpywareBlaster
Hello everyone.
I have Ad-Aware (can't recommend this enough) and the free
version is great at scanning for spyware/malware and
getting rid of some of them AFTER the fact,
but I want to get something that can stop from getting
them BEFORE they even have a chance to get on my computer.
I've been doing my "research" and homework online about
various programs like this and I read about SpywareBlaster
(by JavaCool).
If someone can recommend which is the best, I'd appreciate
it. Again, I have noticed SpywareBlaster but I want one or
more opinions to make a final decision. I did this before
I got any anti-spyware programs as well and came up with
Ad-Aware, Spybot Search & Destroy, and some others, but
based on "word of mouth," I chose Ad-Aware and I've never
been happier.
Hopefully, you guys can help me in making the final
decision regarding programs that protects one in real time
against spyware.
Thanks in advance! Tag: vbv Tag: 51886
AppName: mshta.exe AppVer: 6.0.2600.0 ModName: unknown
The following error message displays whenever I click on "change the way users log on or off" from Control Panel: Microsoft (R) HTML Application host has encountered a problem and needs to close. We are sorry for the inconvenience
(the "For more information about this error. click here" message returns the following detail"
AppName: mshta.exe AppVer: 6.0.2600.0 ModName: unknown ModVer: 0.0.0.0 Offset: 00000000
> Subject: AppName: mshta.exe AppVer: 6.0.2600.0 ModName: unknown 4/27/2004 11:09 AM > PST By: Richard (search by author) In: microsoft.public.windowsxp.setup_deployment
>> To resolve the behavior, type the following commands in
> the Run dialog box:
> sfc /purgecach
> sfc /scanno
I performed the operations above and checked the ( \\windows\system32\mshta.exe & \\windows\system32\dllcache\mshta.exe file directory version properties after the operations had completed. File version results were: Microsoft, 6.00.2600.0000 (xpclient.010817-1148, etc.) for each file and rebooted my system. I still recieve the error. I click upon the "change the way users log on or off" link from the Control Panel's "User Accounts" page and the error response comes back with the very same message I identified in the subject line. I would welcome suggestions that anyone might have. Thanks Tag: vbv Tag: 51884
This page contains both secure and nonsecure items
I'm on a trusted site and when I go from one page to
another. I get this warning
"This page contains both secure and nonsecure items. Do
you want to display thee nonsecure?" It must always
choose yest to go to next page.
Is there a setting that I can change so this warning
doesn't pop up>
Thanks/Mike Tag: vbv Tag: 51882
MSN issues
HELP!!!! I can not log on to my passport account and I
can not connect to any of my secure servers. I have went
to the update site for Microsoft and when it scans my
computer for updates I get an error. HELP!!! Tag: vbv Tag: 51881
Outlook disconnect
When attempting to open new mails we get disconnected.I
have recently started receiving an undeliverable message
from daemon@mailer.This started shortly after our home
page was hijacked.I did run cw shredder and that corrected
the homepage issue .Did I possibly delete something from
my start up list that may have created this problem? or is
something else going on? Any input will be greatly
appreciated. Tag: vbv Tag: 51880
blocking spam with blank "From" using outlook express
I regularly get spam where the "From" is blank, sometimes the "Subject" is blank. I've tried forwarding these spam emails as attachments to my ISP (Comcast) to block, with limited success. Outlook Express seems to require a domain name in order to block email. I've never opened one of these or tried looking at Properties out of fear I'll catch a virus. Is there any way to block all email that arrives with no "From" information displayed? Tag: vbv Tag: 51872
security permissions for windows 2003 server
Hi there,
I need to write up information related to windows 2003
security. However I don't have much win2k3 experience, I
would like to find out information as stated below...
1. Define native Server security
2. Security Auditing
3. What services, minimum, are required to be running
Please advise me asap if you have some information..
Thanks in advance and I look forward to hearing from you.
Regards,
Fred Tag: vbv Tag: 51866
UPDATE: Product Support Services - W32.SASSER WORM RELATING TO MS04-011
UPDATE (05/04/2004):
- This alert is being updated to advise you of an update to Microsoft
Security Bulletin MS04-011. This update details additional workaround steps
which customers can take to protect against the LSASS vulnerability
(CAN-2003-0533). This is the vulnerability which is exploited by the Sasser
worm and its variants. Customers who have not yet deployed the security
update for MS04-011 can evaluate implementing this new workaround to protect
against the Sasser worm and its variants.
- In addition, Microsoft has updated the cleanup tool for W32.Sasser.worm
to remove the C and D variants of the Sasser worm. The Sasser removal tool
now removes Sasser A, B, C and D. The updated removal tool is located at
http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en
and is documented in Knowledge Base article KB841720
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720.
What is this alert?
- Microsoft has been made aware of a worm identified as "W32.Sasser.worm"
and it is currently circulating on the Internet. The worm exploits the
Local Security Authority Subsystem Service (LSASS) vulnerability fixed in
Microsoft Security Update MS04-011 on April 13, 2004.
- Microsoft encourages customers to protect themselves against this worm by
installing Microsoft Security Bulletin MS04-011
<www.microsoft.com/technet/security/bulletin/ms04-011.mspx> immediately.
- Customers who have enabled the Windows XP Firewall are protected from the
vector this worm attacks, which is TCP Port 139. Most third party firewalls
also block this attack vector by default.
If you have any questions regarding the security updates or its
implementation after reading the above listed bulletin you should contact
Product Support Services in the United States at 1-866-PCSafety
(1-866-727-2338). International customers should contact their local
subsidiary.
Thank you,
Microsoft PSS Security Team
--
Regards,
Jerry Bryant - MCSE, MCDBA
Microsoft IT Communities
Get Secure! www.microsoft.com/security
This posting is provided "AS IS" with no warranties, and confers no rights. Tag: vbv Tag: 51863
browser redirect
My browser gets redirected to an obnoxious search engine "The best search engine". I can't get it to stop. I've tried to reset my internet options and have Google as my default home page. Any suggestions on how to get rid of it would be appreciated. Tag: vbv Tag: 51855
PopupEliminator and spyware?
Hey guys and gals, I'm thinking about downloading
PopupEliminator (by SurfSecret Software). I've heard good
things about it.
Looks like a good program to stop annoying and invasive
pop-ups, BUT...I want to make sure I'm not adding spyware
along with it. (Some programs that are suppose to protect
you from spyware, such as SpyBan, SpyHunter, SpyGone,
etc., actually PUT more spyware on your computer).
Call me paranoid but I just wanted to make sure. Tag: vbv Tag: 51848
nachi
a friends pc has nachi virus which avg can not remove he
can not stop online long enough to down load any patches
or fixes because the virus reboots his pc Tag: vbv Tag: 51841
Do I really need this ??
Hello :
I am just your everyday email sender and not into much
else .
Do I really need THIS ; Microsoft .NET Framework version
1.1
Download size: 23.1 MB, 1 hour 16 minutes
The .NET Framework is a component of the Windows
operating system. For developers, the .NET Framework
makes it easy to rapidly create powerful software that
maximizes performance, scalability, opportunities for
integration, reliability, security,
Regards
Bill Davis Tag: vbv Tag: 51838
Salary Negot.
I'm thinking around 70K.
What is the going rates today for a Security position?
What are the best salary negot. techniques?
What if I walk in with a higher salary than expected?
a) walk out and think about it for a later meeting.
Thanks,
T. Tag: vbv Tag: 51834
Error 53 when installing KB835732
I am receiving an error 53 from the installation of K835732 anyone know why? I am having trouble finding the error codes on it
Thanks in advanced
Matt Tag: vbv Tag: 51829
iexplorer
I put zone alarm firewall up. spy-bot said I had a hole
in ie and told me to go to mirosoft for a ie patch. I
did. I found a patch it suggested but it's 2yrs. old. I
just bought this computer from gateway. should this
version not already have this update patch? I looked up
the version i have of xp and it has some patches included
Q330994,q822925,q824145,q832894.the patch it says I need
(spy-bot) is q319182. i can't find if these updates
include this patch. My computer keeps locking up and i
cannot go to any pages after about 1/2 hr of use. Does
anyone have any suggestions? Thanks very much in advance,
Holly Tag: vbv Tag: 51825
Password Complexity
I'm running 03 Enterprise that is a DC. I'll have two
types of users on it. Users that will actually log onto
computers on the network; Users that will only have an
account for an exchange mailbox.
So what I would like to do is have seperate password
complexity requirements for these users. Can I do this?
I know how to change the requirements under Domain
Security Policy, but is there way to create another
security policy and apply it to a serperate OU? Tag: vbv Tag: 51824
microsoft.public.security.crypto newsgroup is now live!
We now have a dedicated newsgroup to address/discuss cryptography related
issues (capi1, capi2, capimon, cert,etc). I encourage you to post all crypto
related issues in the new "microsoft.public.security.crypto" newsgroup.
Thanks
Raj
--
Rajkumar Mohanram [MSFT]
Windows Core Security
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
--------------------- Tag: vbv Tag: 51822
Problems with installing Security patch Q837009
I am running Windows XP Pro and Internet Explorer 6, along with Outlook
Express 6 and am having problems installing Security patch Q837009.
Each time I try to install the patch I get a Microsoft Internet Explorer
Update message telling me that Outlook Express 6.0 needs to be installed -
Surely OE6 is part of IE6 and therefore installs when Windows is installed??
I have tried to download OE 6.0 as a separate download from IE and on trying
to install it I am told that I have a newer version already on my PC!
This is not the first time that I have experienced problems with installing
patches relating to Outlook Express - The problem seems to occur whenever I
download and install individual patches. Whenever I download and install
patches using Critical Updates on the Microsoft Update site, I don't seem to
have this problem.
Can anyone advise why this happens?
alba.
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.676 / Virus Database: 438 - Release Date: 03/05/2004 Tag: vbv Tag: 51816
StrongNameIdentityPermission does not working with WinForm
I'm invoking the same Dll from Console application and WinForm application
Both signed with SrongName.
the class that I'm invoking is protected with StrongNameIdentityPermission
Demand
and hear is what happened:
the console application pass the demand but the WinForm failed
i had try to union the StrongNameIdentityPermission blob with the mscorlib
StrongName
but it still behave is the same way.
Do someone know to solve this issue ????
TNX
Bnaya Eshet Tag: vbv Tag: 51813
HELP - StrongNameIdentityPermission does not work on WinForm
I calling the same DLL (which is protected by StrongNameIdentityPermission)
Once from console application and
The second time from WinForm
Both WinForm and the Console are signing with the same StrongName.
But the Console pass the permission Demand and the WinForm failed.
I had tried to union the WinForm Strong Name with mscorlib StrongName
But its still crashing.
Does any one has any idea???
TNX Tag: vbv Tag: 51811
Software Update Services Server Synch Problem
We have been successfully using the MS SUS server to
update all the clients in our domain for almost a year.
Suddenly, in the middle of February the system stopped
being able to pull down the synch. Whether it is
manually run or on auto run, we get the same error
message: "Failed to generate the list of files to
synchronize. (Error 0x80070003: The system cannot find
the path specified.)".
The only article I can find talks about having used
TweakUI to have changed the path of Program Files - which
we didn't do (I'd never use that program on a server!).
Anyone having a similar problem
This is a critical issue because of the current worm.
Norton Enterprise is protecting us now, but I'd feel a
whole lot better if I could update the desktops.
Greg Tag: vbv Tag: 51807
CertServices 2003 - Web Enrollment and Key Archival
We have a new certificate template with Key Archival enabled, and this
can be used via the Certificate Web Enrollment pages to successfully
get a certificate with archive key.
I want to make the certrqbi.asp page issue these certificates to users
as a default, to stop them having to go via the advanced request form.
I thought this might be as easy as forcing
XEnroll.GenKeyFlags|=CRYPT_EXPORTABLE;, but this still gets a denied
by policy module error (Private Key missing).
In short - has anyone already written a page to issue
Key-archivable-certificates based on the web enrollment basic request,
or should I start picking through certrqbi.asp in more detail?
Any advice much appreciated,
Richard Tag: vbv Tag: 51803
Instructions for removing Sasser infection and patching affected machines
Instructions for patching and cleaning vulnerable Windows 2000 and
Windows XP systems:
Vulnerable Windows 2000 and Windows XP machines may have the LSASS.EXE
process crash every time a malicious worm packet targets the vulnerable
machine which can occur very shortly after the machine starts up and
initializes the network stack.
When cleaning a machine that is vulnerable to the Sasser worm it is
necessary to first prevent the LSASS.EXE process from crashing, which in
turn causes the machine to reboot after a 60 second delay. This reboot
cannot be aborted on Windows 2000 platforms using the Shutdown.exe or
psshutdown.exe utilities and can interfere with the downloading and
installation of the patch as well as removal of the worm.
1. To prevent LSASS.EXE from shutting down the machine during the
cleaning process:
a. Unplug the network cable from the machine
b. If you are running Windows XP you can enable the built-in
Internet Connection Firewall using the instructions found here: Windows XP
http://support.microsoft.com/?id=283673 and then plug the machine back
into the network and go to step 2.
c. If you are running Windows 2000, you won't have a built-in
firewall and must use the following work-around to prevent LSASS.EXE from
crashing.
This workaround involves creating a read-only file named 'dcpromo.log'
in the "%systemroot%\debug" directory. Creating this read-only file will
prevent the vulnerability used by this worm from crashing the LSASS.EXE
process.
i. NOTE: %systemroot% is the variable that contains the
name of the Windows installation directory. For example if Windows was
installed to the "c:\winnt" directory the following command will create a
file
called dcpromo.log in the c:\winnt\debug directory. The following commands
must be typed in a command prompt (i.e. cmd.exe) exactly as they are written
below.
1. To start a command shell, click Start and then click run and
type 'cmd.exe' and press enter.
2.Type the following command:
echo dcpromo >%systemroot%\debug\dcpromo.log
For this workaround to work properly you MUST make the file
read-only by typing the following command:
3. attrib +R %systemroot%\debug\dcpromo.log
2. After enabling the Internet Connection Firewall or creating the
read-only dcpromo.log you can plug the network cable back in and you must
download
and install the MS04-011 patch from the MS04-011 download link for the
affected machines operating system before cleaning the system. If the
system is
cleaned before the patch is installed it is possible that the system
could get re-infected prior to installing the patch.
a. Here is the URL for the bulletin which contains the links to the
download location for each patch:
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx
b. If your machine is acting sluggish or your Internet connection
is slow you should use Task Manager to kill the following processes and
then try downloading the patch again (press the Ctrl + Alt + Del keys
simultaneously and select Task Manager):
i. Kill any process ending with '_up.exe' (i.e. 12345_up.exe)
ii. Kill any process starting with 'avserv' (i.e. avserve.exe,
avserve2.exe)
iii. Kill any process starting with 'skynetave' (i.e. skynetave.exe)
iv. Kill hkey.exe
v. Kill msiwin84.exe
vi. Kill wmiprvsw.exe
1. Note there is a legitimate system process called 'wmiprvse.exe'
that does NOT need to be killed.
c. allow the system to reboot after the patch is installed.
3. Run the Sasser cleaner tool from the following URL:
a. For the on-line ActiveX control based version of the cleaner you
can run it directly from the following URL:
http://www.microsoft.com/security/incident/sasser.asp
b. For the stand-alone download version of the cleaner you can
download it from the following URL:
http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4FC3-90D4-9FA42D14CC17&displaylang=en
4. Determine if the machine has been infected with a variant of the
Agobot worm which can also get on the machine using the same method as the
Sasser worm.
a. To do this run a full antivirus scan of your machine after
ensuring your antivirus signatures are up to date.
b. If you do NOT have an antivirus product installed you can visit
HouseCall from TrendMicro to perform a free scan using the following
URL:
http://housecall.trendmicro.com/
If you have any questions regarding the security updates or its
implementation after reading the above listed bulletin you should
contact Product Support Services in the United States at 1-866-PCSafety
(1-866-727-2338). International customers should contact their local
subsidiary. Tag: vbv Tag: 51796
823559
Have Windows 98 and I keep getting a message to install
update 823559. Have done it numerous times but it keeps
telling me to install it. Any suggestions Tag: vbv Tag: 51786