Home
Resources
Training
About Us
eStore
<a href="http://www.isdecisions.com/en/software/userlock/?xtor=SEC-230"><img src="http://www.isdecisions.com/images/pubs/Randy/userlock.gif" alt="UserLock" border="0" /></a>

>

resources > newsletter > archive > issue #47

 

 

 

 

 

 

 

Latest Blog: WinReporter 4.0 Makes It Easy to Assess Attack Surface

 

Ultimate Windows Security Newsletter:

Issue #47, 06/12/07

This month we get an interesting mix of security patches from Microsoft.  None of these are at the “the sky is falling!” level of severity and all of the patches are Workstation/Terminal Server focused; if you are a server only admin you can probably relax provided you don’t engage in end-user activities such as web browsing or working with documents or email while logged on at the server.  I think you are prudent to conduct full testing before any deployment.  Several of the patches might be altogether avoidable depending on your environment including MS07-034 (Windows Mail and Outlook Express) as well as MS07-032 (Windows Vista only patch).   Exploit details are public for 2 of the bulletins but due to other mitigating factors noted in the chart below I’m not recommending accelerated testing.

No time to decode event logs? Get served with the events that matter, in real time!
GFI EventsManager is the solution for centralized event log management & reporting. Boasting the most advanced event processing & filtering rules in the industry, this tool acts as an early-warning system for failures & alerts on possible security breaches. Get to know what's really happening on your network.

KB #

Exploit Type

Product

Principle type of systems exposed

Exploit details public? / Being exploited?

Comprehensive, practical workaround available?

MS severity rating

Vulnerable
Windows or
Office versions

Notes

Randy’s recommendation

2000

XP

2003

Vista/ 2007

MS07-031 - 935840

Arbitrary code

Windows

Workstations & Terminal Servers

No/No

No

Critical

Denial of Service only

YES

Denial of Service only

No

Mostly likely even on XP to cause denial of service instead of arbitrary code execution

Patch after testing

MS07-033 -
933566

Arbitrary code

Internet Explorer

Workstations & Terminal Servers

Yes/No

No

Critical

Yes

Yes

Yes

Yes

6 different vulnerabilities

Only one is public and risk is limited to spoofed web pages

Patch after testing

MS07-034 -
929123

Arbitrary code

Outlook Express and Windows Mail

Workstations & Terminal Servers

Yes/No

Mixed

Critical

No

Yes - Important

Yes - Moderate

Yes – Critical

4 different vulnerabilities with varying severity depending on OS

Patch after testing or prevent users from using Windows Mail and Outlook Express

MS07-035 -
935839

Arbitrary code

Windows

Workstations & Terminal Servers

No/No

Yes

Critical

Yes

Yes

Yes

No

Patch after testing unless exploit details become public, then patch ASAP

MS07-030 -
927051

Arbitrary code

Visio

Workstations & Terminal Servers

No/No

No

Important

?

Yes

Yes

No

Patch after testing unless exploit details become public, then patch ASAP or block Visio files at perimeter

MS07-032 -
931213

Information Disclosure

Windows Vista

Workstations

No/No

No

Moderate

No

No

No

Yes

Mostly an issue for shared workstations or environments where end-users lack administrator authority on their workstations

Patch after testing if an issue for your environment

Logging in Depth – Secure, Comply, Save – with EventTracker Complete Event Management
EventTracker software improves network security with centralized event log monitoring, security events correlation, host based intrusion detection and security beyond firewall. It provides unattended enterprise-wide event log management for millions of events a day.


Later this month I’m presenting a special training webinar on PCI compliance and how to automate a large portion of the activities associated with PCI DSS.

Exploiting Log Management and Vulnerability Scanning to Comply with PCI DSS


If your company accepts credit cards you are affected by the Payment Card Industry’s Data Security Standard.  Do you have a handle on the most laborious activities required by PCI DSS?  PCI requires you to “Track and monitor all access to network resources and cardholder data.”  In this webinar commissioned by GFI Events Manager and LANGuard, Randy Franklin Smith will provide an overview of PCI DSS’s 12 requirements and then dive into the details of Requirements 10 and 11.  While discussing Requirement 10 (Track and monitor all access to network resources and cardholder data) you will identify the key log sources you need to monitor in a Windows-centric network.  Randy will then discuss Requirement 11 (Regularly test security systems and process) and identify opportunities to automate these quarterly tests.  You will also learn how effective log management reporting tool can help you comply with 3 other PCI DSS requirements.  Then??? from GFI will demonstrate how GFI has designed Events Manager to collect these varied log files into a central database for easy monitoring and tracking.  You’ll learn about Events Manager’s agent less architecture and determine if its right for you and you’ll take home key compliance points from Randy Franklin Smith that you can use no matter what log management solution you use.  You will also learn about GFI’s network vulnerability scanner, LANGuard and how GFI has updated both tools with specific features to facilitate PCI compliance.


Additional Links

A
D
V