3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender...

16
  • date post

    19-Dec-2015
  • Category

    Documents

  • view

    223
  • download

    4

Transcript of 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender...

Page 1: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
Page 2: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

• 3 Patches – x bugs addressed

• Affecting Kernel, SChannel, DNS/WINS

• Other updates, MSRT, Defender Definitions, Junk Mail Filter

• 3 Security Patches - 1 Critical, 2 Important– MS09-006 – Kernel (GDI via EMF or WMF image) , Remote

Execution– MS09-007 – SChannel, Allows Spoofing

“Customers are only affected when the public key component of the certificate used for authentication has been obtained by the attacker through other means.”

– MS09-008 – DNS/WINS (WPAD and ISATAP registration), Allows Spoofing

Patch Tuesday

Page 3: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

• Apple 2009-001– 55 fixes– Some reports of broken Perl

• Mac OS X xnu nel memory disclosure

• Telent FreeBSD 7.0– Exploit on milw0rm

• Yet another Adobe Reader bug– PoC on milw0rm

• …and Flash Player

• Gmail CSRF

• BlackBerry Activex component

• Opera / Winamp / Excel

Holes / Patches

Page 4: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
Page 5: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Hacking • MS ponies up 250K confiker bounty

• Air Force claims tool can id “bad” torrents…mean while back at the ranch

• Maxwell AFB cuts external connection

• MS09-002 exploits seen in the wild– Sourcefire release home brew patched .dll

• MS release autorun patch

• Rumors of Windows 7 DRM badness

• TrapCall service bypasses CallerID blocking

• VMWare demos dual OS phone (simultaneous ops)

Page 6: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
Page 7: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Games

• Sega cuts jobs

• Quake Live– Open beta feb 24

Page 8: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Corp. Hell• Metasploit to offer services

• Novell Launches Moonlight (silverlight for linux)

• Leak of Windows 7 Beta

• Palm drops PalmOS for WebOS

• FaceBook changes TOS and changes back

• Twitter is master of downtime

• Symantec takes down server after the SQL Injection that did not happen

• X-Box cuts gay subscriptions

• Linux Foundation buys linux.com

• Gmail Outage

Page 9: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Papers

• "Security Assessment of the Transmission Control Protocol (TCP)“– UK - Centre for the Protection of National Infrastructure

• Fortify code review of NIST SHA-3 contestants

• MS Gazelle – secure web browser

• Summary of Metasploit DDoS

Page 10: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Film / Music• 6th season of Futurama

• Netflix to launch streaming only plan

Page 11: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

WTF

• Wisconsin download tax

• Solar power hits $1 a watt

• Diebold logs are crap

Page 12: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

Legal

• PirateBay in Court

• All your RFID are belong to felons• Senate Bill 125 - felony for anyone to

possess, read or capture the personally identifying RFID information of others without their consent

• Internet Saftey Act of 2009

Page 13: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

• Debian 5.0

• PcapParser

• Ratproxy 1.5.4

• dragonflybsd 2.2

• D ported to Mac

• Safari 4

• OSSEC 2.0

• Qt 4.5

Updates

Page 14: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

CON Events• BlackHat DC• Kaminsky / DNSSEC

• Militarized cyberspace

• New XSS

• Fun with Facial Biometrics

• SSL Strip

• CanSecWest (5 days)• Pwn2Own – Laptop and Mobile devices

• DefCon CFP

Page 15: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

• SOURCE Boston, 11 - 13 Mar / Boston MA• http://www.sourceboston.com/

• CarolinaCon 4, 28 - 29 Mar / Chapel Hill NC• http://www.carolinacon.org/

• Notacon 5, 4 - 6 Apr / Cleveland OH• http://www.notacon.org/

• Hack In The Box, 20-23 Apr / Dubai• http://conference.hitb.org/hitbsecconf2009dubai/

• ToorCon Seattle, 18 – 20 Apr / Seattle• http://seattle.toorcon.org/2008/about.php

• Trooper 08, 23 – 24 Apr / Munich • http://www.troopers08.org/content/

• Interop, 27 Apr - 2 May / Las Vegas NV• http://www.interop.com/lasvegas/

• Layerone, 17 – 18 May / Pasadena CA• http://layerone.info

• DallasCon 2008, TBD / Dallas , TX• http://www.dallascon.com

• MS BlueHat Spring 2008, May 2 2008 / Redmond WA• http://www.microsoft.com/technet/security/bluehat/

Page 16: 3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,

All images scavenged without permission

All images scavenged without permission