Showing posts with label Virus alerts. Show all posts
Showing posts with label Virus alerts. Show all posts

December 13, 2011

Internet Explorer more secure than Mozilla Firefox, Says Study

The Microsoft is much much happy now as they have a second position in their hands. Microsoft's Internet Explorer does a better job protecting systems from attackers who already have gained some degree of access than Mozilla's Firefox, and Google's Chrome trumps both of them, according to a new browser security study from Accuvant.

They came up with those results by analyzing the security features of the three most popular web browsers, but have decided not to employ the usual metrics: numbers of patched vulnerabilities, the severity of the flaws and the time it took for the developers to fix them.

As for the raw details, Accuvant's study didn't just focus on the sheer number of published vulnerabilities that a browser has at the time of testing. Rather, Accuvant presumed that a browser vulnerability is going to be exploited in some fashion by a third-party: The security testing, therefore, focused on the strength of a browser's anti-exploitation measures after-the-fact—"the software with the best anti-exploitation technologies is likely to be the most resistant to attack and is the most crucial consideration in browser security," Accuvant wrote.


While Google's Chrome browser won the day in Accuvant's research, the browser didn't sail through with a perfect score. Accuvant noted that Chrome, along with the other two browsers in the test, failed to adequately offer up strong enough URL blacklisting to pass Accuvant's examinations—a daily comparison of roughly 6,000 malware-related URLs against either Microsoft's URL Reporting Service or Google's Safe Browsing List.

"Gathering intelligence about malware URLs is generally performed by running honeypots and spamtraps, and harvesting URLs from malware captured in the wild. Since no authoritative source exists, it is likely that each organization gathering data is getting one part of the overall picture," Accuvant wrote. "Based on Accuvant's analysis, no party is performing this data collection comprehensively."

And while all three browsers employ address space layout randomization (ASLR), data execution prevention (DEP) and stack cookies (GS), Firefox does not implement sandboxing (the separation of running programs), plug-in security and Just-In-Time hardening (preventing javascript located on websites from compiling code that can be run on the target system).
That said, Chrome's apparent excellence in sandboxing, plug-in security, JIT hardening, and Address Space Layout Randomization, among other features, was enough to win it top honors. But Mozilla isn't letting Accuvant have the last word regarding the security of its browser.

Adobe warns of Virus Attacks on Windows


Hackers are exploiting a previously unknown flaw in Reader to attack computers running Windows, Adobe said.
A patch for the critical vulnerability in Reader and Acrobat is expected by next week, the company said in a blog post.
The vulnerability, which is being exploited in "limited, targeted attacks in the wild against Adobe Reader 9.x on Windows," could allow an attacker to take control of the system, Adobe said.
Adobe is finalizing a fix and expects to release an update for Reader and Acrobat 9.x for Windows no later than the week of December 12, according to an Adobe advisory.
"Because Adobe Reader X Protected Mode and Adobe Acrobat X Protected View would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X and Acrobat X for Windows with the next quarterly security update for Adobe Reader and Acrobat, currently scheduled for January 10, 2012," the company said. "We are planning to address this issue in Adobe Reader and Acrobat X and earlier versions for Macintosh as part of the next quarterly update scheduled for January 10, 2012. An update to address this issue in Adobe Reader 9.x for UNIX is planned for January 10, 2012."
The issue does not affect Adobe Reader for Android and Adobe Flash Player.
Adobe's advisory credited Lockheed Martin and members of the Defense Security Information Exchange with reporting the issue. Lockheed spokeswoman Jennifer Whitlow told Reuters that the problem was identified through the company's normal monitoring activities but that the company had not been penetrated in the attempted attack. The defense contractor was targeted in an attack earlier this year believed to be related to a breach at SecurID token maker RSA.

November 23, 2011

Fake "VIRUS ALERT" !

Fake Virus Alerts Floating in the Web 


Sophos is warning office workers about an unusual twist on virus alert tactic on the people. The emails warn of recent incidents of corporate data theft 7 instruct users to click on a link which is of course the actual malware payload.

DMCA.com The Techbay | All Rights Reserved.

Designed by "mintJelly"