Última actualització: 31/12/2006; 15:20:42
Quands.cat Quands.cat
 
Notes sobre seguretat informàtica.

dimarts, 26 / desembre / 2006


Ampliant el comentari anterior, el que realment cal conèixer per avaluar la seguretat de Windows no és el fet que s'hagi descobert una vulnerabilitat a Vista sinó aquesta taula que publica SANS Institute:

Affected Known Exploits Impact Known since
ISC rating(*)
clients servers
NetrWkstaUserEnum() memory allocation exhaustion
Publicly posted exploit Remote DoS ?
Dec 25th, 2006
unkown
unknown
MessageBox() / csrss double free vulnerability

CVE-2006-6696
Publicly posted PoC exploits for XP, 2003 and Vista

MSRC blog
Privilege Escalation
Dec 15th, 2006
Important
Less Urgent
Office 2004 vulnerabilities (Mac version)

Unspecified vulnerabilites fixed in a accidentally released patch. Patch has been withdrawn after being public and eventually replaced with one without security fixes.
Exposed through a patch by Microsoft.

MSRC blog #1
MSRC blog #2
unknown
Dec 12th, 2006
unknown
unknown
Word unspecified vulnerability #3

CVE-2006-6561
Publicly available exploit.

MSRC blog
Remote code execution
Dec 12th, 2006
Critical
Important
Word unspecified vulnerability #2

CVE-2006-6456
MSRC blog #1
MSRC blog #2
Used in targeted attacks
Remote code execution
Dec 10th, 2006
Critical Important
Word unspecified vulnerability #1

CVE-2006-5994
Microsoft Security Advisory 929433
MSRC blog

Used in targeted attacks
Remote code execution Dec 5th, 2006
Critical Important
RPC in Windows 2000 SP4 UPnP and SPOOLS

CVE-2006-6296
CVE-2006-3644
Multiple publicly available exploits.
DoS
Nov 16th, 2006
Less Urgent
Important
ADODB.Connection ActiveX

CVE-2006-5559
MSRC blog

Public DoS  exploit.
Remote code execution
Oct 24th, 2006
Critical
Important
Workaround: set the killbit for 00000514-0000-0010-8000-00AA006D2EA4
Microsoft Windows NAT Helper Components

CVE-2006-5614
Publicly available exploit.
DoS
Oct 20th, 2006
Less Urgent
Important
PowerPoint 2003

CVE-2006-5296
MSRC blog #1
MSRC blog #2

Publicly available exploit.
DoS
Oct 20th, 2006
Less Urgent
Less Urgent

We will update issues on this page as they evolve.
We appreciate updates

(*): ISC rating
  • We use 4 levels:
    • PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
    • Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
    • Important: Things where more testing and other measures can help.
    • Less urgent: Typically we expect the impact if left unpatched to be not that big a deal in the short term. Do not forget them however.
  • The difference between the client and server rating is based on how you use the affected machine. We take into account the typical client and server deployment in the usage of the machine and the common measures people typically have in place already. Measures we presume are simple best practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leaisure work.
  • The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threat for affected systems. The rating does not account for the number of affected systems there are. It is for an affected system in a typical worst-caserole.
  • Only the organization itself is in a position to do a full risk analysis involving the presence (or lack of) affected systems, the actually implemented measures, the impact on their operation and the value of the assets involved.


--
Swa Frantzen -- Section 66


11:02 (# Enllaç permanent) | Comentaris: | Trackback:


Tanta gràcia em fan les declaracions del tipus: «Windows Vista és el sistema més segur que hi ha» com les declaracions: «Hi ha un problema de seguretat que afecta a Windows Vista». Els dos casos són declaracions fetes des d'un total desconeixement de la seguretat informàtica i la industria del software (IMHO).

La darrera mostra: Report: More flaws found in Microsoft's Vista
Computer security researchers and hackers have found more flaws in Microsoft's Vista, the long-awaited update to the Windows operating system, according to a report Monday.

One programmer said it was possible to increase a user's privileges on all of the company's recent operating systems, including Vista, while a computer security firm said that it found five other vulnerabilities, including one error in the software code underlying the company's new Internet Explorer 7 browser

The browser flaw means that users could become infected with malicious software simply by visiting a particular Web site, according to the report.

That would make it possible for an attacker to inject rogue software into the Vista-based computer, the paper said, citing executives at Determina, a maker of software intended to protect against vulnerabilities.
 
En la meva opinió, no importa tant saber que *hi ha* problemes de seguretat; el que realment és important és saber quan de temps passa entre el descobriment del problema de seguretat (ja sigui de forma 'reglada' o través d'un 0-day) i la disponibilitat dels mecanismes necessaris per eliminar-lo, habitualment a través d'un pegat. També dono molta importància a la disponibilitat de mecanismes que facilitin una ràpida distribució del pegat.

Evidentment que cal fer tot el possible per evitar, d'entrada, l'existència de problemes de seguretat. Les mesures de prevenció són d'allò més important... però també són igualment importants les mesures de reacció davant situacions que, de forma inevitable, es produiran.

Per tant, l'important no és saber que *avui* Windows Vista té problemes de seguretat, sinó quan de temps passa abans que aquests problemes disposin d'una solució.


10:44 (# Enllaç permanent) | Comentaris: | Trackback:


  © Copyright 2000-2006 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
Wishlist
Desembre 2006
Diu Dil Dim Dim Dij Div Dis
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31            
Nov   Gen

RSS






Una imatge anomenada a_wiccac-logo.gif Creative Commons License

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter