• HAPPY NEW YEAR!!!

    H A P P Y   N E W   Y E A R   A N D   A L L   T H E   B E S T   F O R   2 0 0 6   !

    Hopefully you will stay with us and perhaps we will see some more comments and feedbacks from you as well... ;-)

    Urs & Roger

     

  • Update on WMF 0day

    Just for your information: We released an advisory regarding the WMF 0day tonight. You can find it here: http://www.microsoft.com/technet/security/advisory/912840.mspx

    Roger

  • Windows Server 2003 Security Guide 2.0 is Live

    Besides the 0day there is some good news as well. Today (you see we are working during Christmas time J) we published V2 of the Windows Server 2003 Security Guide covering SP1

    If can be found here: http://www.microsoft.com/downloads/details.aspx?FamilyId=8A2643C1-0685-4D89-B655-521EA6C7B4DB&displaylang=en

    This is the best document on how to harden Windows Server 2003 SP1 in different roles

    Roger

  • The Black Hats Don't Sleep

    Well, I hope you enjoyed Christmas as much as I do and additionally I hope that you have the opportunity to have a few days off.

    But it seems that the bad guys have too much time as well. There are reports that there is a 0day out there attacking a vulnerability in Microsoft Windows WMF Handling. We are aware of it and it is under investigation at the moment. Here you can find some information about it:
    MELANI: http://www.melani.admin.ch/newsticker/00072/index.html?lang=en&PHPSESSID=5f98437d926027b133d27ab41e1f6748
    Secunia: http://secunia.com/advisories/18255/
    SANS: http://isc.sans.org/diary.php?storyid=975

    F-Secure, one of our VIA (Virus Information Alliance) partners, has some good information on this from an attack perspective: http://www.f-secure.com/weblog/archives/archive-122005.html#00000753

    Several AV-vendors including Symantec, Trendmicro, McAfee, and F-Secure have already updated their signature – therefore you should as well

    Roger

  • The Social Engineering Story of the Year

    You probably know those mails that tell you that a legal investigation has been started against you because child pornography has been found on your computer. When you open the attachement, a trojan will be installed.

    Well, those kind of mails sometimes have a good side: A child pornographer turned himself in to the police in Germany after having received such a mail.....

    Read the whole story: http://news.yahoo.com/s/nm/20051220/wr_nm/crime_germany_worm_dc

    Viruses are not always bad :-)

    Merry Christmas

    Roger