Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Why Billgates would Decide to Sell Off Microsoft?





Letter from Banta Singh to Mr. Bill Gates

Subject: Problems with my new computer

Dear Mr. Bill Gates,

We have bought a computer for our home and we have found some problems, which I want to bring to your notice:

1. There is a button 'start' but there is no 'stop' button. We request you to check this.

2. One doubt is whether any “re-scooter” is available in system? I find only “re-cycle”, but I own a scooter at my home.

3. There is 'Find' button but it is not working properly. My wife lost the door key and we tried a lot trace the key with this 'find' button, but was unable to trace. Please rectify this problem.

4. My child learnt 'Microsoft word' now he wants to learn 'Microsoft sentence', so when you will provide that?

5. I bought computer, CPU, mouse and keyboard, but there is only one icon which shows 'My Computer': when you will provide the remaining items?

6. It is surprising that windows says 'MY Pictures' but there is not even a single photo of mine. So when will you keep my photo in that.

7. There is 'MICROSOFT OFFICE' what about 'MICROSOFT HOME' since I use the PC at home only.

8. You provided 'My Recent Documents'. When you will provide 'My Past Documents'?

9. You provide 'My Network Places'. For God sake please do not provide 'My Secret Places'. I do not want to let my wife know where I go after my office hours.

Regards,

Banta

Last one to Mr. Bill Gates:

Sir, how is it that your name is Gates but you are selling WINDOWS?

Microsoft confirms 17-year-old Windows vulnerability





Microsoft confirms 17-year-old Windows vulnerability



One day after a Google security researcher released code to expose a flaw that affects



every release of the Windows NT kernel — from Windows NT 3.1 (1993) up to and including



Windows 7 (2009) — Microsoft dropped a security advisory to acknowledge the issue and



warn of the risk of privilege escalation attacks.



Microsoft warns that a malicious hacker could exploit this vulnerability to run arbitrary code



in kernel mode. For an attack to be successful, the attacker must have valid logon



credentials.



The flaw does not affect Windows operating systems for x64-based and Itanium-based



computers, Microsoft said.



According to Tavis Ormandy, the Google researcher who released the flaw details,



Microsoft was notified about the issue in June 2009. After waiting several months and not



seeing a patch, he decided it was in the best interest of everyone to go public.



As an effective and easy to deploy workaround is available, I have concluded that it is in the



best interest of users to go ahead with the publication of this document without an official



patch. It should be noted that very few users rely on NT security, the primary audience of



this advisory is expected to be domain administrators and security professionals.



Ormandy’s advisory includes instructions for temporarily disabling the MSDOS and



WOWEXEC subsystems to prevent an attack from functioning. This can be done via Group



Policy.



The mitigation in Microsoft’s advisory mirrors the advice from Ormandy.



If you believe you may be affected, you should consider applying the workaround

described below.



Temporarily disabling the MSDOS and WOWEXEC subsystems will prevent the attack

from functioning, as without a process with VdmAllowed, it is not possible to

access NtVdmControl() (without SeTcbPrivilege, of course).



The policy template "Windows Components\Application Compatibility\Prevent

access to 16-bit applications" may be used within the group policy editor to

prevent unprivileged users from executing 16-bit applications. I'm informed

this is an officially supported machine configuration.



Administrators unfamiliar with group policy may find the videos below

instructive. Further information is available from the Windows Server

Group Policy Home



http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx

MORE & SOURCES:



http://blogs.zdnet.com/security/?p=5307&tag=nl.e589
http://seclists.org/fulldisclosure/2010/Jan/341
http://www.microsoft.com/technet/security/advisory/979682.mspx

Microsoft fixes 17 year old bug !!





A 17-year-old bug in Windows will be patched by Microsoft in its latest security update.

The February update for Windows will close the loophole that dates from the time of the DOS operating system.

First appearing in Windows NT 3.1, the vulnerability has been carried over into almost every version of Windows that has appeared since.

The monthly security update will also tackle a further 25 holes in Windows, five of which are rated as "critical".

Home hijack

The ancient bug was discovered by Google security researcher Tavis Ormandy in January 2010 and involves a utility that allows newer versions of Windows to run very old programs.

Mr Ormandy has found a way to exploit this utility in Windows XP, Windows Server 2003 and 2008 as well as Windows Vista and Windows 7.

The patch for this vulnerability will appear in the February security update. Five of the vulnerabilities being patched at the same time allow attackers to effectively hijack a Windows PC and run their own programs on it.



STAYING SAFE ONLINE

Use security software that can tackle viruses and spyware

Use a firewall

Apply operating system updates as soon as they become available

Be suspicious of unsolicited e-mails bearing attachments

Keep your browser up to date

As well as fixing holes in many versions of Windows, the update also tackles bugs in Office XP, Office 2003 and Office 2004 for Apple Macintosh machines.

The bumper update is not the largest that Microsoft has ever released. The security update for October 2009 tackled a total of 34 vulnerabilities. Eight of those updates were rated as critical - the highest level...



http://news.bbc.co.uk/1/hi/technology/8499859.stm