Sunday, August 17, 2008
Thursday, August 14, 2008
WSUS Blocking: A Real Problem, Microsoft Says
Microsoft's conclusion? It confirmed that the WSUS blocking issue really is a problem after all. The company recommends that IT shops affected by the problem install an update. A description of the problem and link to get the update can be accessed here (Knowledge Base Article 954960).
The update only applies to users of System Center Essentials and System Center Configuration Manager 2007. Those products are the only ones that use WSUS, according to Microsoft's Knowledge Base Article.
The fix to the blocking problem was originally provided on August 1 via the Microsoft Download Center. However, Microsoft revised its Knowledge Base Article yesterday simply to alert users that the update is now available via Microsoft Update. Those who got the update on August 1 don't have to reinstall it.
While the blocking issue seems to be a security issue, that's something that the technicians at Microsoft vigorously contend.
"In this case, Microsoft is communicating an issue that affects your ability to perform updates, including security updates," the Knowledge Base Article states. "Therefore, this advisory does not address a specific security vulnerability; rather, it addresses your overall security."
So it's not a software security issue in the sense of fixing software that's innately insecure. However, if left unfixed, the WSUS problem can wreak havoc by leaving Office 2003 unpatched.
Microsoft Remedies Windows Server Update Glitch
New PLAYSTATION 3 system software updates on the way
Apple ships massive Mac OS X 10.4 security upgrade
SQL Injection Attacks on the Rise
Why SQL injection attacks and why now?
"An emerging theme for threats [in July] seems to be new variations on old attack methods," said Mark Sunner, chief security analyst for MessageLabs, in a statement. "Following on from June, Web-based malware continues to be a treacherous threat and organizations would be smart to build their Web security defenses in preparation for what could be on the horizon."
If July was any indication, more SQL injection, cross-site scripting and other familiar attacks could be on the horizon.
SQL injection vulnerabilities are the very stuff of low-hanging fruit. They're almost certainly widespread, stemming as they do from design trade-offs, development deadlines, functional requirements, a lack of imagination or developer indifference.
They're also easy to test for, security experts said, in part because of a bevy of free, publicly available testing tools, including a plug-in for the popular Firefox Web browser. Consequently, researchers said, the onus is on development teams to proactively identify and patch SQL injection flaws before attackers -- using, in some cases, the same tools -- beat them to it.
"The root cause is unvalidated input, which can lead to SQL injection, among other things, including cross-site scripting, passive manipulation, and other things," said a CISSP with a prominent consulting and services firm who asked to remain anonymous. "The point is that there are tools out there [such that] if you point them to a Web site, they will try [injecting SQL into] every Web site they can find. There's even a Firefox extension."
That's part of the rub, according to this CISSP. "This is just one of several tools designed for site designers to scan their own Web sites. But that's part of the problem: It's freely available and anyone can use it -- the bad guys can use it just as easily as the developers themselves."
How does a SQL injection vulnerability become a reality? This CISSP -- who, in a former career, logged almost a decade as a software engineer -- said it's a question of dueling pressures. "Developers are under pressure to release software that fulfills functional requirements. Security requirements are generally not part of functional requirements. The No. 1 rule is to release the software that does its job by this date. If you can't do anything else, do that," he said. "The way we'd like to see development going is you'd like to have a security guy involved from the beginning. You'd like to have developers knowing or caring enough, or having time [enough], to test these things themselves."
Not that attackers are foregoing innovation altogether, of course. According to MessageLabs, spammers are ceaselessly innovative. They'd previously exploited Google's hosted applications (i.e., Google Docs, Google Pages and Google Calendar) to disseminate spam, for example. Last month, spammers were targeting Google's "Sites" feature, which lets them build URLs (derived from Web pages consisting of random letters and numbers) that are more difficult to block using conventional anti-spam tools.
"Google Sites is yet another way that spammers have programmatically defeated CAPTCHA [Completely Automated Public Turing Test to Tell Computers and Humans Apart] mechanisms, a validation technique that is designed to defend against automated sign-up tools frequently used by spammers by requiring the user to enter a string of letters," Sunner said. "While Google Sites spam accounts for only 1 percent of all spam currently, we anticipate that this technique's popularity will rival that of its predecessors, Google Docs, Calendar and Pages spam. If this is the case, then we may see spam levels increase in the months ahead."
CAL gets a visit from spammers
Microsoft Advisory Targets SQL Injection Attacks
VMware's Updates Cause Problems, CEO Apologizes
The company issued an initial knowledge base article (KB 1006716) yesterday about the problem, which causes licenses to expire on the patched machines, along with other associated difficulties. VMware plans to provide additional information on the matter by revising its KB 1006716 bulletin in the future, according to the company's VMTN blog.
VMware's CEO, Paul Maritz, released a letter yesterday, apologizing to customers and explaining the problem.
"When the time clock in a server running ESX 3.5 or ESXi 3.5 Update 2 hits 12:00AM on August 12th, 2008, the released code causes the product license to expire," Maritz wrote. "The problem has also occurred with a recent patch to ESX 3.5 or ESXi 3.5 Update 2."
Users of those products that applied Update 2 will see a number of problems with their virtual machines, including power off/on problems, machines stuck in suspend mode and an inability to migrate using VMotion.
VMotion is the function that lets users move their virtual machines from one physical server to another.
VMware has issued two express patches (one for ESX 3.5 and the other for ESXi 3.5) for those who applied the updates. Those who haven't applied the ESX 3.5 Update 2 patch should refrain from doing so if they downloaded it before August 12, 2008, according to KB 1006716.
The company plans to issue a full replacement for Update 2 in the next day or so, according to Maritz. He added that this Update 2 replacement "should be used by customers who want to perform fresh installs of ESX or ESXi."
Maritz explained the VMware failed to disable some code in the final release of Update 2 for both products and that the company's quality assurance process failed to catch it. He said that the company is engaged in a "self-examination" process to avoid such problems in the future.
A VMware security blog said that the update problem is not related to an ESX security exploit issue. It's a license time out problem, so it doesn't mean that systems running ESX were compromised by an attack.
It's not clear how extensive the damage has been, although VMware in Australia, which reported first on the problem because of time zone progression, apparently knew of few incidents, according to one report.
Wednesday, August 13, 2008
Microsoft Virtualization Launch Planned for Fall 2008
The Bellevue-based event will draw Microsoft execs to speak, with a keynote address by Bob Muglia, senior vice president of Microsoft's server and tools business, and Kevin Turner, Microsoft's CEO.
Microsoft has a complete line of virtualization products, in various stages of release, so there's some speculation about what Microsoft may announce at the September event. Microsoft has already released to manufacturing (RTM) its Hyper-V virtualization solution, which is part of Windows Server 2008.
The company's System Center Virtual Machine Manager 2008 solution was released as a public beta in April, with expectations for an RTM release in the second half of 2008. Given that schedule, it seems likely that Microsoft will announce the RTM status of Virtual Machine Manager 2008 at this event. The Virtual Machine Manager 2008 is designed to help IT administrators manage Windows Server 2008, Microsoft Virtual Server and systems using VMware's virtualization solution.
Another piece of the puzzle is Microsoft's Kidaro acquisition, which provided Microsoft with technology for desktop virtualization. Microsoft announced the acquisition of Kidaro in March with the idea that it will be part of the Microsoft Desktop Optimization Pack for Software Assurance customers. Kidaro's technology promises to let IT professionals create software images for desktop PCs that also allow individual users to run their own software concurrently, without conflicts.
Microsoft has said that it will ship Kidaro's technology under the "Microsoft Enterprise Desktop Virtualization" (MED-V) name. At its virtualization product launch event, Microsoft has a session called "Client-Hosted Virtualization With MED-V," which presumably will discuss the integration of Kidaro's technology.
The company also plans to talk about its "Microsoft Application Virtualization" solution, formerly known as SoftGrid, at the event. This software, which, among other things, allows applications to bypass conflicts caused by using shared resources, is currently available as version 4.5 in beta release.
Microsoft plans to make its Microsoft Application Virtualization product generally available in the third quarter of 2008 as part of the "Microsoft Desktop Optimization Pack and Microsoft Application Virtualization CAL for Terminal Services," according to the company's SoftGrid Web site. With that timeline, the general availability of this product might also be announced at this launch event.
Veteran Microsoft watcher Mary-Jo Foley speculated in her All About Microsoftblog that Microsoft might talk about application virtualization via streaming methods of delivery. The idea is that Microsoft could make a license change that could enable Microsoft apps to compete against hosted applications provided by Google.
In addition to this Bellevue event, Microsoft is planning to announce additional U.S. launch event sites to talk about its virtualization products, according to Microsoft's GetVirtualNow Web site.
Installing And Using OpenVZ On CentOS 5.2
Citrix To Enhance Virtualization Interop
Installing And Using OpenVZ On Fedora 9