Three-year-old Office patch stymies most attacks

Users running Microsoft Office can stump nearly three-fourths of all known attacks targeting the suite by applying just one three-year-old patch, according to recently published data. The flaw was fixed in the MS06-027 security update issued. Almost three-out-of four attacks - 71% of all those spotted in the first half of 2009 - exploited a vulnerability in Word that was patched in June 2006, Microsoft said in its bi-annual security intelligence report, released Monday.

The second-most popular exploit, with a 13% share, aimed at a bug that was quashed in March 2008, Microsoft said. The 2006 update patched Word 2000, Word 2002 and Word 2003, while the 2008 fix affected Excel 2000, Excel 2002, Excel 2003 and Excel 2007. Microsoft made the point that patching Office was as important as keeping Windows up-to-date with security fixes. "The majority of Office attacks observed in [the first half of 2009], 55.5%, affected Office program installations that had last been updated between July 2003 and June 2004," the company said in its report. "Most of these attacks affected Office 2003 users who had not applied a single service pack or other security update since the original release of Office 2003 in October 2003." Unfortunately, users are far less likely to update Office than they are to patch Windows. The flaw was one of seven patched by the MS08-014 update. According to Microsoft's data, the median amount of time since the last Office update was an amazing 5.6 years, compared to just 1.2 years since the last Windows update. "Users can keep Windows rigorously up to date and still face increased risk from exploits unless they also update their other programs regularly," Microsoft warned. They do what's required of them," he continued, hinting that they often do little more than that. "Windows' security has a high profile, and so they're patching Windows.

Wolfgang Kandek, the chief technology officer at security vendor Qualys, echoed Microsoft's take on Office patching patterns. "We see the same in our data," Kandek said. "People just don't patch Office, and when they do, they patch it much slower than Windows." That especially holds true in the enterprise. "This is a major security hole in the enterprise," Kandek said. "IT admins are not focusing on Office as they are on Windows. I don't think they're looking at Office, to tell you the truth." Qualys obtains its data from PCs that it manages for its clients, most of which are companies. Office 2007 SP2 hit the street in April 2009. Nine out of 10 Office exploits in the first half of 2009 involved a Trojan downloader, or backdoor malware. "These kinds of threats allow attackers to access compromised systems later to install more malware," Microsoft said. One way to stay up-to-date without patching every month is to apply the infrequent service packs that Microsoft issues for Office. "If the Office 2003 RTM users in the sample had installed SP3 [Service Pack 3] and no other security updates, they would have been protected against 98% of observed attacks," Microsoft said. "Likewise, Office 2007 RTM users would have been protected from 99% of attacks by installing SP2." Microsoft delivered Office 2003 SP3 in September 2007, fixing more than 450 bugs in the application suite, and adding other security measures, including file blocking of older formats, a move that confused users well into the following year. Microsoft urged Office customers to use the Microsoft Update service, a superset of the better-known Windows Update that pushes patches for Windows and Office.

Office was last patched Oct. 13 when Microsoft unveiled a record number of security updates and fixed flaws. Here, too, Kandek was stumped by Microsoft's practice of offering two separate update services. "I'm not sure why that's the way they do it," he said, speaking of Microsoft's providing Office updates to consumers and small businesses only through Microsoft Update. "I don't see why they simply can't replace Windows Update with Microsoft Update, and patch everything." Microsoft offers Office, as well as Windows patches, to businesses that use its Windows Server Update Services (WSUS) patch management system. The security intelligence report can be downloaded from Microsoft's site in PDF or XPS document formats.

AMD graphics chip shortage hitting PC vendors

An offshore Advanced Micro Devices Inc. foundry is having trouble ramping up on production of a new 40-nanometer graphics processing unit, forcing PC makers to delay shipments of desktop and laptop computers, AMD confirmed today. He added that the foundry is in full production but so far yields are below expectation. The Taiwan Semiconductor Manufacturing Company Ltd. (TSMC) is struggling to get up to speed manufacturing AMD's 5800 series, 40-nm GPUs (graphics processing units), according to Jim McGregor, an analyst at In-Stat.

Matt Davis, a spokesman for AMD, confirmed to Computerworld that TSMC is having issues in ramping up production of the chips. It's just a matter of trying to get TSMC to a point where they can yield. He added that it's not clear how far behind the foundry is on production expectations. "The design is sound. They're feeling the manufacturing crunch," said Davis. "We're a little bitter under yield but we're working back into a manufacturing schedule we want for these parts. They're getting a huge swing on this. TSMC can only kick them out so fast at this point." Davis said that PC vendors are being affected but declined to say how many vendors are feeling the pinch or which ones. "It's the end of the whip," he added. "[The vendors] are going to have a hard time." Davis also said AMD is working with TSMC on the issue and hopes to have production up to speed by year's end. "They haven't been producing these chips for long, so you'd expect some ramp issues," said McGregor. "AMD is being affected because these are great parts and they're getting a lot of demand.

When you have more demand for a product than expected and lower yields than expected, you get the perfect storm." McGregor said AMD has a little time to get manufacturing in line before PC vendors start looking for greener pastures and turn to a graphics chip from rival Nvidia . "It's not something you can move away from overnight," said McGregor. "They're set up for that GPU. They could switch over to Nvidia but it would take some effort. It will all depend on how bad the shortage gets." Dan Olds, principal analyst at Gabriel Consulting Group, said that if projections of slow tech sales, especially of high-end products, hold true, AMD should survive the production slowdown rather well. They could switch. If the economy was strong, and buyers were clamoring for desktops and laptops, a production slowdown would significantly hurt the struggling AMD . "If the problem goes on long enough, or gets worse, it may prompt system vendors to reexamine their decision or hedge with products using other suppliers," said Olds, who added that he expects AMD to rectify the problem soon. "It's not unusual to see low yields when a chip is shrunk to a smaller process. I would expect to see yields rise over time as the glitches get fixed, but that doesn't do AMD much good right now." But most of these problems are ironed out well before the product is introduced into the market, which ensures that there will be enough supply to handle demand.

NASA watching “perfect storm” of galactic cosmic rays

Astronauts and satellite integrated circuits are at most risk of an ongoing tempest of galactic cosmic rays that scientists say is at an all-time high. Cosmic rays cause showers of particles when they hit Earth's atmosphere but they pose their greatest health hazard, radiation, to astronauts in space. According to NASA's Goddard Space Flight Center, galactic cosmic rays come from outside the solar system and are made up of subatomic particles accelerated to almost light speed by distant supernova explosions.

They aren't too healthy for satellites either as a single cosmic ray can disable the unit if one hits an unlucky integrated circuit, NASA said. "In 2009, cosmic ray intensities have increased 19% beyond anything we've seen in the past 50 years," said Richard Mewaldt of Caltech in a release. "The increase is significant, and it could mean we need to re-think how much radiation shielding astronauts take with them on deep-space missions." Network World Extra:  Top 10 cool satellite projects 10 NASA space technologies that may never see the cosmos   NASA says the surge is being caused by what it calls a "solar minimum," a deep lull in solar activity that began around 2007 and continues today. Right now solar activity is as weak as it has been in modern times, setting the stage for what Mewaldt calls "a perfect storm of cosmic rays." Mewaldt also says the solar wind is flagging. "Measurements by the Ulysses spacecraft show that solar wind pressure is at a 50-year low, so the magnetic bubble that protects the solar system is not being inflated as much as usual." A smaller bubble gives cosmic rays a shorter-shot into the solar system. Researchers have long known that cosmic rays go up when solar activity goes down. Once a cosmic ray enters the solar system, it must "swim upstream" against the solar wind. Still the Earth is in no great danger from the cosmic bombardment. Solar wind speeds have dropped to very low levels in 2008 and 2009, making it easier than usual for a cosmic ray to proceed, he stated.

The planet's atmosphere and magnetic field combine to form a formidable shield against space radiation, NASA points out. The study, conducted by the National Academy of Sciences noted that besides emitting a continuous stream of plasma called the solar wind, the sun periodically releases billions of tons of matter called coronal mass ejections. Earlier this year a NASA-funded study looked to show some of the first clear economic data that quantifies the risk extreme weather conditions in space have on the Earth. These immense clouds of material, when directed toward Earth, can cause large magnetic storms in the magnetosphere and upper atmosphere, NASA said. One of the driving reasons for the study is that the sun, as we mentioned above, is currently near the minimum of its 11-year activity cycle but solar storms will increase in frequency and intensity toward the next solar maximum, expected to occur around 2012. Such space weather can impact the performance and reliability of space-borne and ground-based technological systems, NASA said.

Keep Your Passwords Private--and Handy--With LastPass

This fall, more than 20,000 stolen usernames and passwords for such Webmail providers as AOL, Gmail, Hotmail, and Yahoo appeared on Pastebin.com, a programmer's Website. Dixon removed the stolen info, which Microsoft and some security researchers theorize was gathered through phishing attacks. The Webmaster, Paul Dixon, wrote that "for reasons unknown," some "miscreants" posted the data on his site. A researcher at ScanSafe argues that the data may have come from password-stealing malware, not phishing.

They also want access to your Webmail. Either way, crooks clearly aren't after only bank accounts and other financial log-ins. But why? After her Hotmail account was hacked, every message she sent included an unwelcome advertisement. A friend of mine was recently hit by a scam, and her experience helps answer that question.

Crooks have also begun using stolen Webmail and Facebook accounts to send pleas supposedly from a victim to friends or contacts. Don't Pass the Password To guard against password thieves, I use LastPass. Some bogus messages claim the sender is stranded overseas and needs an urgent wire transfer of funds. The tool offers a free password-managing add-on for Firefox on Windows, Linux, or Mac OS X; Internet Explorer on Windows; and Safari on Mac OS X. An add-on for Google Chrome is under development. And because you don't type your password, keylogger malware can't capture your keystrokes and nab your password. LastPass fills in your username and password for verified sites that match a real URL; phishing scams that use similar but fake Web addresses won't deceive it.

Other apps, like Password Hash, offer similarly worth­while protection, but LastPass stores all of your data on its servers (using 256-bit AES encryption) as well as on your PC. Since the company never has the software decryption key or your password, nobody at LastPass can get to your info. Even without the add-on, you can log in to LastPass's site to get to your information. Because your data is stored centrally, you can use the add-on with any browser, log in with your LastPass master account info, and access all of your passwords. That means you should create a fairly complex master password for the LastPass site, but it also means you have a de facto backup if your PC goes kaput. For instance, it normally keeps you logged in to your LastPass account for two weeks, even if you close and re-open the browser; to prevent someone from sitting at your desk and accessing your accounts, click Preferences and check Automatically logoff after idle. Instant Entry The handy add-on can automatically log you in to sites and can fill in forms, but for better security you should change some of its default settings.

I set mine to log off my LastPass account after an hour. You can enable this when the add-on automatically asks if you want to save a newly entered password. It's also smart to require a password reprompt for sensitive accounts; the app will ask for your master password before filling in the username and password, even if you're already logged in. LastPass offers applications for the iPhone, BlackBerry and other mobile devices, too, but those will cost you $12 per year.

Check Point tackles Web 2.0 apps and social-site widget control

Soon businesses that run Check Point security tools will be able to understand how thousands of Web applications and Web 2.0 widgets are used, giving executives better control over what employees do with their computers at work. 12 tips for safe social networking The company is developing a software blade that customers can buy to address use of social Web sites and Web applications. With the blade, due out next year, businesses could see not only that employees use Facebook, but also whether they are participating in Facebook groups or playing games available through the site, for example. Check Point has licensed extensive libraries from FaceTime that identify 4,500 Web applications and more than 50,000 Web 2.0 widgets.

Or they could keep an eye on applications that do file transfers, Check Point says. Initially, Check Point plans to incorporate the libraries in a blade that is just a monitoring tool, but later it will incorporate them in a firewall to create an access-control blade that can enforce restrictions on the use of applications and widgets. Business use of Web 2.0 sites brings its own security concerns and can run afoul of regulations from governmental agencies and business consortiums. Later still, the company says it will incorporate the libraries into IPS and QoS blades. For instance, customers might buy firewall, intrusion-detection system and antispam software blades and run them on a single hardware chassis.

Under Check Point's software blade architecture announced earlier this year, customers can buy individual security tools to create packages of custom security features. Before, Check Point sold monolithic multi-function unified threat management platforms that might include more functions than customers wanted. The libraries support FaceTime's own Unified Security Gateway product.

Gmail, Yahoo Mail join Hotmail; passwords exposed

Google's Gmail and Yahoo's Mail were also targeted by a large-scale phishing attack, perhaps the same one that harvested at least 10,000 passwords from Microsoft's Windows Live Hotmail, according to a report by the BBC. Microsoft , for its part, said late yesterday that it had blocked all hijacked Hotmail accounts, and offered tools to help users who had lost control of their e-mail. The BBC also said it has seen a list of some 20,000 hijacked e-mail accounts; the list included accounts from Gmail, Yahoo Mail, AOL, Comcast and EarthLink. Gmail was the target of what Google called a large-scale phishing campaign, the company told the BBC . "We recently became aware of an industry-wide phishing scheme through which hackers gained user credentials for Web-based mail accounts including Gmail accounts," a Google spokesperson told the news network. The latter two are major U.S. Internet service providers. "As soon as we learned of the attack, we forced password resets on the affected accounts," the Google spokesperson also told the BBC. "We will continue to force password resets on additional accounts when we become aware of them." Neither Google's or Yahoo's U.S. representatives responded to e-mails from Computerworld seeking confirmation that their Gmail and Yahoo Mail services were targeted by phishers, or answers to questions about how many accounts had been compromised and what the firms are doing to help users.

Late Monday, Microsoft said it was blocking access to all the accounts whose details had been posted on the Web last week. "We are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts," the company said on its Windows Live blog . Microsoft posted an online form where users who have been locked out of their accounts can verify their identity and reclaim control, and also pointed users to a support page from October 2008 that spells out steps users can take if they think their accounts have been hijacked. Neowin.net, the site that first reported the Hotmail account hijacking early Monday, today added that it had seen the same list of compromised accounts as the BBC. "Neowin can today reveal that more lists are circulating with genuine account information and that over 20,000 accounts have now been compromised," said the Windows enthusiast site . "[The] new list contains e-mail accounts for Gmail, Yahoo, Comcast, EarthLink and other third-party popular Web mail services." Microsoft has acknowledged that log-on credentials for "several thousand" Hotmail accounts had been obtained by criminals, probably through a phishing attack that had duped users into divulging their usernames and passwords. After a slump earlier this year, phishing attacks are on the upswing, according to the Anti-Phishing Working Group (APWG). Its most recent data - for the first half of 2009 ( download PDF ) - noted that the number of unique phishing-oriented Web sites had surged to nearly 50,000 in June, the largest number since April 2007 and the second-highest total since the industry association started keeping records. Yesterday, Dave Jevans, the chairman of APWG, called the Hotmail phishing attack one of the largest ever, but cautioned that the usernames and passwords may have been harvested over several months, and not by a single, defined attack.

Users nervous about Oracle's acquisition of MySQL

The European Union is not the only one antsy about Oracle taking possession of the open source MySQL database should the commercial database giant's merger with Sun Microsystems get final approval. On its Web site, Oracle merely notes that "MySQL will be an addition to Oracle's existing suite of database products." "I wish that Oracle would broadcast its intentions a little bit more" on the Sun acquisition, says Duane Kimble, a Linux technologist who works in the banking industry. So are MySQL users. (The E.U.'s executive arm has held up approval of the merger, fearing that Oracle's acquisition of MySQL could reduce competition in the database market, as well as harm the open source nature of MySQL. Sun's stockholders and the U.S. Justice Department have approved Oracle's $7.4 billion acquisition of Sun.) "We've got a fair number of databases and Web applications that use those databases in MySQL. If Oracle does something that sort of makes it look like MySQL's days are numbered or something is going to change that we don't like, we'll probably look at alternatives," says Ernest Joynt, a contractor for the National Oceanic and Atmospheric Administration. [ Relive Sun's storied history in InfoWorld's slideshow "The rise and fall of Sun Microsystems." | Learn why attendees at the JavaOne conference were skeptical of Oracle's buyout of Sun. ] Anand Babu Periasamy, CTO of clustered storage technology company Gluster, expresses doubts that Oracle would add enterprise capabilities to MySQL. "I hope that they will retain MySQL. [But] I am doubtful [that] they will ever improve MySQL to take it mid-enterprise level, but at least it will help them compete with Microsoft SQL Server on the low end," he says. (Gluster uses MySQL for its Web site operations.) Thus far, Oracle has said little about its intentions for MySQL and declined to discuss the issue with InfoWorld. For him, Oracle's ownership of MySQL is a specific cause for caution.

His firm has begun looking at other enterprise-scale open source databases such as EnterpriseDB's Postgres database in case it has to replace MySQL. Standing to reap a harvest from unease about the Oracle-MySQL pairing are open source database vendors EnterpriseDB and Ingres. MySQL users start looking at alternatives A key issue is that Oracle is a main competitor to MySQL, notes Timothy Dion, CTO of mobile and Web apps builder Sensei. "I'm very concerned about what that means," he says. EnterpriseDB, which builds its products on the PostgreSQL open source database, has been hearing from concerned MySQL users, says Larry Alston, EnterpriseDB's vice president of product management and marketing. "They're telling us that they're nervous" about the future of MySQL, he says. Doubts remain over the fate of other Sun technologies Users remain concerned over the fate of other Sun technologies such as Java and Solaris, not just of MySQL. "We are rethinking our Solaris deployments," says Linux technologist Kimble. "We are moving swiftly toward more of an AIX and Linux environment, depending on the size or the scale of the project." Although Kimble notes it is "too early to say whether we'll move off [Solaris] or not," he does say his employer is rethinking its Solaris commitment: "Certainly, we're not going full-bore with Solaris as we were before the merger." Kimble does see a positive side to the Sun acquisition: "I think it kind of simplifies the platform offering somewhat. Ingres also sees opportunities. "The phones ring a lot," says Ingres CEO Roger Burkhardt. Oracle is a strong company and if they keep Sun Java, which I'm sure is what they bought [Sun] for, I think it will make Java a better product." But Bryce Pier is not so sure.

Another large company buying another large company reduces competition," he says. The senior systems engineer at Target sees no benefits of the buyout - at least not yet. "I'm not really certain that it's going to be good for anybody. Pier expects the acquisition to cause Target to move away from Solaris to Red Hat's Linux over time. Oracle, said Craig Muzilla, Red Hat's vice president for middleware, was very active in the Java Community Process for updating Java and has strived for openness in Java. "We don't see anything from Oracle that [would indicate that] they would do anything" that would differ with the past, he said. One reason is the uncertainty: "We're just not sure what Oracle's commitment is going to be to the Java stack and to maintaining it as an open source project." Another is Oracle's reputation for extracting revenues from customers: "We certainly fear that all of the subscription fees are going to change for everything from Sun." At its recent conference, Red Hat sought to reassure customers about the continued openness of Java-based JBoss technology, which Red Hat owns, now that Oracle is buying Java founder Sun.