<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>Computer Security</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/" />
   <link rel="self" type="application/atom+xml" href="http://blog.emerson.edu/Computer_Security/atom.xml" />
   <id>tag:blog.emerson.edu,2009:/Computer_Security//10</id>
   <updated>2009-02-03T20:18:08Z</updated>
   <subtitle>Technology information for the Emerson Community with a focus on security and safe computing practices.</subtitle>
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.14</generator>


<entry>
   <title>Hiatus (and a suggestion)</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2009/02/hiatus_and_a_suggestion.html" />
   <id>tag:blog.emerson.edu,2009:/Computer_Security//10.3711</id>
   
   <published>2009-02-03T19:08:51Z</published>
   <updated>2009-02-03T20:18:08Z</updated>
   
   <summary>I think a full-time security administrator should be able to write at least 3 posts every week, if not every day. I&apos;ve always had a lot of roles to fill, but being a Banner system administrator is really a full...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[I think a full-time security administrator should be able to write at least 3 posts every week, if not every day.  I've always had a lot of roles to fill, but being a Banner system administrator is really a full time job in and of itself.  Last year I was only able to write two posts from January through April, and I think this Winter (of much discontent) will be even busier with Banner and OneCard projects.  So don't expect to find any regular updates here for a while.

There is another great source of IT Security information I encourage everyone to read, the <a href="https://www.sans.org/newsletters/ouch/">SANS 'Ouch!' Newsletter</a>.  I rely on the <a href="http://isc.sans.org/">SANS Internet Storm Center</a> for updates that are often very technical in nature, but Ouch! is geared toward all users and is only published once a month.  You can <a href="https://www.sans.org/newsletters/ouch/current_ouch.php">view the current issue</a> on the web or have it e-mailed to you each month.

]]>
      
   </content>
</entry>

<entry>
   <title>Critical Update for Internet Explorer</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/12/critical_update_for_internet_e.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.3502</id>
   
   <published>2008-12-18T13:45:02Z</published>
   <updated>2008-12-18T13:52:27Z</updated>
   
   <summary>Yesterday, Microsoft released an &quot;Out-of-Band&quot; Security Update to fix a critical vulnerability in Internet Explorer. This vulnerability can be exploited by visiting a maliciously crafted web site, but does not necessarily require a user to download any files or click...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Yesterday, Microsoft released an "Out-of-Band" Security Update to fix a critical vulnerability in Internet Explorer. This vulnerability can be exploited by visiting a maliciously crafted web site, but does not necessarily require a user to download any files or click a link inside that infected site.  It is estimated that over one million computers have been infected worldwide, which is why Microsoft has released this patch off of their normal cycle.

Emerson College computers should get the update this morning, if they haven't already.  I would highly recommend that all Windows users patch their home systems as soon as possible. For more information on patching and keeping your computer safe, please see: <a href="http://www.emerson.edu/helpdesk/services/maintenance/Windows-Maintenance.cfm">http://www.emerson.edu/helpdesk/services/maintenance/Windows-Maintenance.cfm</a>
]]>
      
   </content>
</entry>

<entry>
   <title>Security Updates for Mac OS</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/12/security_updates_for_mac_os.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.3501</id>
   
   <published>2008-12-18T13:39:50Z</published>
   <updated>2008-12-18T13:44:52Z</updated>
   
   <summary>Apple has released Security Update 2008-008 / Mac OS X v10.5.6 earlier this week. It fixes a number of vulnerabilities, so if you have patched yet, it is time to run Software Update....</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Apple has released <a href="https://support.apple.com/kb/HT3338">Security Update 2008-008 / Mac OS X v10.5.6</a> earlier this week.  It fixes a number of vulnerabilities, so if you have patched yet, it is time to run Software Update.]]>
      
   </content>
</entry>

<entry>
   <title>Is it Patch Tuesday already?</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/12/is_it_patch_tuesday_already.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.3367</id>
   
   <published>2008-12-10T19:50:17Z</published>
   <updated>2008-12-10T19:57:43Z</updated>
   
   <summary>Yes, on Tuesday, Microsoft released a number of updates for Windows and Office (including Office for Mac). All of them are critical for your home and office computers, so patch now (if you haven&apos;t already). For more information about patching...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Yes, on Tuesday, Microsoft released a number of updates for Windows and Office (including Office for Mac).  All of them are critical for your home and office computers, so patch now (if you haven't already).  For more information about patching and keeping your computers up to date, see my first <a href="http://blog.emerson.edu/Computer_Security/2006/11/patch_tuesday_1.html">Patch Tuesday</a> posting.]]>
      
   </content>
</entry>

<entry>
   <title>Java Updates</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/12/java_updates.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.3285</id>
   
   <published>2008-12-08T16:49:54Z</published>
   <updated>2008-12-08T16:57:15Z</updated>
   
   <summary>Sun has just released an update which fixes numerous vulnerabilities in a number of different versions of Java. Some of the vulnerabilities patched are quite serious, such as allowing a remote hacker to execute code on your computer. Java is...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Sun has just released an update which fixes numerous vulnerabilities in a number of different versions of Java.  Some of the vulnerabilities patched are quite serious, such as allowing a remote hacker to execute code on your computer.  Java is a little tricky because installing a new version doesn't necessarily remove an old one, and some software relies on old versions of Java.  That makes it difficult to give blanket advice, but I definitely support updating, even if you can't remove an older version.

For more information:
<ul>
	<li><a href="http://java.com/en/download/installed.jsp">Check your version of Java</a></li>
	<li><a href="http://jdl.sun.com/webapps/getjava/BrowserRedirect?locale=en&host=java.com">Doanload Java</a></li>
	<li><a href="http://www.java.com/en/download/faq/5000070400.xml">Removing Older Versions</a></li>
</ul>]]>
      
   </content>
</entry>

<entry>
   <title>A big week for software updates</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/11/a_big_week_for_software_update.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.2711</id>
   
   <published>2008-11-14T16:26:09Z</published>
   <updated>2008-11-14T16:36:06Z</updated>
   
   <summary>It has been a big week for software updates. First, Microsoft released three important updates on their Patch Tuesday. A couple of my machines prompted me to run Flash Player updates this week. Mozilla patched a large number of vulnerabilities...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      It has been a big week for software updates.  First, Microsoft released three important updates on their Patch Tuesday.  A couple of my machines prompted me to run Flash Player updates this week.  Mozilla patched a large number of vulnerabilities in Firefox (and other products, such as Thunderbird).  And Apple has released an update of their Safari web browser for Mac and Windows.  Make sure your computers are up to date.

      
   </content>
</entry>

<entry>
   <title>More Reasons to Worry About the Economy</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/10/more_reasons_to_worry_about_th.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.2429</id>
   
   <published>2008-10-26T14:36:37Z</published>
   <updated>2008-10-26T15:28:11Z</updated>
   
   <summary>This is a simple idea, but it is still worrisome. Malware writers look for any opportunity they can to attack people. With news of financial markets declining and bank consolidation, security research shows an increase in spam and phishing activity....</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[This is a simple idea, but it is still worrisome.  Malware writers look for any opportunity they can to attack people.  With news of financial markets declining and bank consolidation, <a href="http://arstechnica.com/news.ars/post/20081023-malware-writers-ratchet-up-attacks-as-stock-market-tanks.html">security research</a> shows an increase in spam and phishing activity.  It's not a new idea; we've seen floods of attacks after any sort of natural disaster or other major news events.  This time they are playing to people's fears about their banks and investments.

The advice remains the same.  Be very cautious with your e-mail and especially don't click any link in a suspicious message.  You should always be able to get to your bank's web site by typing in the URL; you should never have to click a link in a message.

  


]]>
      
   </content>
</entry>

<entry>
   <title>Emergency Microsoft Patch!</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/10/emergency_microsoft_patch.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.2408</id>
   
   <published>2008-10-23T17:59:38Z</published>
   <updated>2008-10-23T18:33:04Z</updated>
   
   <summary>Microsoft has just released an &quot;Out-of-Band&quot; Security Update to fix a critical vulnerability in a process known as Remote Procedure Call (RPC). This vulnerability could be exploited when one computer connects to a Windows Computer or Server with a commonly...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Microsoft has just released an "Out-of-Band" Security Update to fix a critical vulnerability in a process known as Remote Procedure Call (RPC).  This vulnerability could be exploited when one computer connects to a Windows Computer or Server with a commonly used protocol.  According to the <a href="http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx">Microsoft Security Bulletin</a>, "It is possible that this vulnerability could be used in the crafting of a wormable exploit."  There are currently limited, small scale attacks happening on the Internet, however, the potential exists for a wide-spread worm attack.  For those reasons, Microsoft chose not to wait until the next Patch Tuesday (November 11), but instead to release it immediately, which is a rare step for them.

Given the potential for a worm-like attack, we plan to patch all Windows Servers tomorrow morning.  I would highly recommend that all Windows users patch their home systems as soon as possible.  For more information on patching and keeping your computer safe, please see:  <a href="http://www.emerson.edu/helpdesk/services/maintenance/Windows-Maintenance.cfm">http://www.emerson.edu/helpdesk/services/maintenance/Windows-Maintenance.cfm</a>]]>
      
   </content>
</entry>

<entry>
   <title>Many Microsoft Updates</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/10/many_microsoft_updates.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.2350</id>
   
   <published>2008-10-15T15:59:36Z</published>
   <updated>2008-10-15T16:02:36Z</updated>
   
   <summary>Yesterday Microsoft released a number of critical patches for both servers and desktop computers. I highly recommend patching your Windows computers as soon as possible. We updated Emerson&apos;s servers this morning....</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      Yesterday Microsoft released a number of critical patches for both servers and desktop computers.  I highly recommend patching your Windows computers as soon as possible.  We updated Emerson&apos;s servers this morning.
      
   </content>
</entry>

<entry>
   <title>Catching Up</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/09/catching_up.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.2165</id>
   
   <published>2008-09-25T19:47:18Z</published>
   <updated>2008-09-25T20:14:36Z</updated>
   
   <summary>I know for the me the past month has mostly been a blur, as the start of the school year often will be. So I&apos;m trying to catch up a little on the important security news and I think I...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[I know for the me the past month has mostly been a blur, as the start of the school year often will be.  So I'm trying to catch up a little on the important security news and I think I can basically summarize the past two months in three bullet points:
<ol>
	<li><strong>PATCH EVERYTHING</strong>:  Windows, MacOS, Firefox, iTunes, Office, QuickTime, Flash Player, Adobe Reader, Java, and any other software you might have.  Everything in that list has released security updates recently and you should make sure you are up to date.  For help figuring out how to update your software, see <a href="http://blog.emerson.edu/Computer_Security/2007/10/">this post from about a year ago</a>.</li>
	<li><strong>Beware of Scams</strong>:  Microsoft has been working to cleanup infected computers that are part of bot-nets.  So the criminals have been working extra hard to infect new computers.  A common means of infection involves setting up malicious web sites and getting people to visit them by sending spam.  Especially popular right now are greeting card scams--where it looks like someone sent you an e-card and when you go to view it they infect your computer.  Also be weary of any emails with outrageous subject lines that seem like current events, solicitations for victims of recent hurricanes or other storms, or anything about a US financial institution.
</li>
	<li><strong>Don't use Google Chrome</strong>:  For those of you who have not heard, Google has released a new web browser, called <em>Chrome</em>.  This is still a beta software product, and has already been found to have a number of security vulnerabilities.  I will offer the same advice I offered when Apple released Safari for Windows:  Don't use beta web browsers on a production machine.  Don't install Chrome on any computer that you rely on for day to day work.  If you have a test machine (with no important data on it), that is the only place I would consider safe for this browser at this time.
</li>
</ol>
OK, I think that covers the biggest IT security news.  I'll try to keep the updates coming a little more frequently.]]>
      
   </content>
</entry>

<entry>
   <title>Patch your Windows</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/07/patch_your_windows.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.1802</id>
   
   <published>2008-07-09T12:39:52Z</published>
   <updated>2008-07-09T12:46:28Z</updated>
   
   <summary>Microsoft has released a handful of updates as part of this month&apos;s Patch Tuesday. There are a few interesting ones, including something related to DNS that affects servers and clients. As usual, I recommend patching as soon as possible. For...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Microsoft has released a handful of updates as part of this month's Patch Tuesday.  There are a few interesting ones, including something related to DNS that affects servers and clients.  As usual, I recommend patching as soon as possible.  For more info and analysis, see the <a href="http://isc.sans.org/diary.html?storyid=4684">SANS Internet Storm Center</a>.]]>
      
   </content>
</entry>

<entry>
   <title>Patch your Mac</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/07/patch_your_mac_2.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.1794</id>
   
   <published>2008-07-01T12:23:01Z</published>
   <updated>2008-07-01T12:27:47Z</updated>
   
   <summary>I feel like I write this a lot, but it&apos;s time to patch your Mac. Apple has released Security Update 2008-004, Mac OS X v10.5.4, and Safari 3.1.2 for Mac OS X v10.4.11. More info at http://support.apple.com/kb/HT1222....</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[I feel like I write this a lot, but it's time to patch your Mac.  Apple has released Security Update 2008-004, Mac OS X v10.5.4, and Safari 3.1.2 for Mac OS X v10.4.11.  More info at <a href="http://support.apple.com/kb/HT1222">http://support.apple.com/kb/HT1222</a>.
]]>
      
   </content>
</entry>

<entry>
   <title>Mac Security</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/06/mac_security.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.1793</id>
   
   <published>2008-06-29T19:46:08Z</published>
   <updated>2008-06-29T19:55:52Z</updated>
   
   <summary>One of the misconceptions I frequently try to change is the idea that Macs can&apos;t get viruses. There is no arguing that the number of attacks against MacOS is tiny in comparison to Windows and even Unix/Linux systems. But just...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[One of the misconceptions I frequently try to change is the idea that Macs can't get viruses.  There is no arguing that the number of attacks against MacOS is tiny in comparison to Windows and even Unix/Linux systems.  But just because there has never been a massive attack against the Mac doesn't mean there never will be.  I offer this <a href="http://blog.intego.com/2008/06/24/can-snow-leopard-save-mac-os-x-from-malware/">post from Intego.com</a> as further evidence that Mac users can not be complacent.  Good security is not the same thing as perfect security.
]]>
      
   </content>
</entry>

<entry>
   <title>Firefox 3 is here!</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/06/firefox_3_is_here.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.1785</id>
   
   <published>2008-06-20T13:25:10Z</published>
   <updated>2008-06-20T14:03:41Z</updated>
   
   <summary>Firefox 3 was released on Tuesday as Mozilla attempted to set a world record for most downloads in one day. From what I have heard, it was downloaded more than 8 million times in the first 24 hours. I was...</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Firefox 3 was released on Tuesday as Mozilla attempted to set a world record for most downloads in one day.  From what I have heard, it was downloaded more than 8 million times in the first 24 hours.  I was one of those millions, and have installed the browser on one of my computers.  So far, the results are good.

Firefox 3 has refined and streamlined its design; along with some notable performance enhancements.  One of the cool new features is that the location bar has expanded functionality, and is unofficially being referred to as "the awesome bar."  As you type, it searches your bookmarks and recently visited sites for any possible matches.  There are also a number of great improvements in the security area.  For more information on this new version, see the <a href="http://en-us.www.mozilla.com/en-US/firefox/3.0/releasenotes/">Release Notes</a>.

For more information and to download Firefox, visit <a href="http://www.mozilla.com">www.mozilla.com</a>.

]]>
      
   </content>
</entry>

<entry>
   <title>Update for Safari on Windows</title>
   <link rel="alternate" type="text/html" href="http://blog.emerson.edu/Computer_Security/2008/06/update_for_safari_on_windows.html" />
   <id>tag:blog.emerson.edu,2008:/Computer_Security//10.1784</id>
   
   <published>2008-06-20T13:22:57Z</published>
   <updated>2008-06-20T13:25:04Z</updated>
   
   <summary>Apple has released a patch for its Safari web browser for Windows. I don&apos;t recommend using Safari on Windows at all, but if you do be sure to update. More info at: http://support.apple.com/kb/HT2092....</summary>
   <author>
      <name>Adam Travis</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.emerson.edu/Computer_Security/">
      <![CDATA[Apple has released a patch for its Safari web browser for Windows.  I don't recommend using Safari on Windows at all, but if you do be sure to update.  More info at: <a href="http://support.apple.com/kb/HT2092">http://support.apple.com/kb/HT2092</a>.
]]>
      
   </content>
</entry>

</feed>
