<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Security Watch</title>
<link>http://blogs.pcmag.com/securitywatch/</link>
<description>Security Watch is a resource center for everything related to tech security: the latest news, review summaries and advice on security-related topics. We show you how you can protect your online identity and keep your computer safe.</description>
<item>
<title>Are You Happy With Your Antivirus?</title>
<link>http://blogs.pcmag.com/securitywatch/2010/09/are_you_happy_with_your_antivi.php</link>
<guid isPermaLink="true" >http://blogs.pcmag.com/securitywatch/2010/09/are_you_happy_with_your_antivi.php</guid>
<description>&lt;div id=&quot;&quot;&gt;&lt;tr readability=&quot;3.8027027027027&quot;&gt;&lt;td valign=&quot;bottom&quot; readability=&quot;2.172972972973&quot;&gt;
&lt;p&gt;Thursday September 2, 2010&lt;/p&gt;


&lt;/td&gt;
&lt;/tr&gt;&lt;tr readability=&quot;10.123324396783&quot;&gt;&lt;td class=&quot;defaults&quot; readability=&quot;11.81054512958&quot;&gt;
&lt;div class=&quot;userdefaults&quot; readability=&quot;23.167903525046&quot;&gt;&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Most antivirus products run on a yearly subscription model. At the end of the year, you either re-up or start looking for a replacement. Is that anniversary coming up for you? Will you stay with the same security vendor, or are you itching for a change? Smart users keep up with the competition even when that Day of Reckoning is months away.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;It's true that quite a few significant security vendors haven't yet released their 2011 editions. Last year's &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2349865,00.asp&quot; target=&quot;_blank&quot;&gt;Norton Internet Security 2010&lt;/a&gt; is still current - until next week anyway. &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2352670,00.asp&quot; target=&quot;_blank&quot;&gt;Trend Micro Internet Security Pro (version 3)&lt;/a&gt; also gets replaced by an update next week, and &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2354297,00.asp&quot; target=&quot;_blank&quot;&gt;Spyware Doctor with AntiVirus 2010&lt;/a&gt; the following week. Updates from F-Secure, ZoneAlarm, McAfee and others are further off.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Even so, quite a few of the major and minor players have already stepped up with new and innovative versions for 2011. In &lt;a href=&quot;%20http://www.pcmag.com/article2/0,2817,2368554,00.asp&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;The Best Antivirus Software for 2011 (So Far)&lt;/strong&gt;&lt;/a&gt; I've rounded up six commercial antivirus utilities and four free ones, all with new versions from this summer. Look for new roundups as more contenders enter the ring.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;&lt;/div&gt;



&lt;/td&gt;
&lt;/tr&gt;&lt;tr readability=&quot;0&quot;&gt;&lt;td&gt;

&lt;/td&gt;
&lt;/tr&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;This entry passed through the &lt;a href=&quot;http://fivefilters.org/content-only/&quot;&gt;Full-Text RSS&lt;/a&gt; service &amp;mdash; if this is your content and you're reading it on someone else's site, please read our FAQ page at &lt;a href=&quot;http://fivefilters.org/content-only/faq.php&quot;&gt;fivefilters.org/content-only/faq.php&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://fivefilters.org&quot;&gt;Five Filters&lt;/a&gt; featured article: &lt;a href=&quot;http://medialens.org/alerts/10/100720_peace_envoy_blair.php&quot;&gt;&quot;Peace Envoy&quot; Blair Gets an Easy Ride in the Independent&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
<pubDate>Thu, 02 Sep 2010 15:15:56 +0000</pubDate>
</item>
<item>
<title>iTunes 10 Adds TV Rentals, Security Fixes</title>
<link>http://blogs.pcmag.com/securitywatch/2010/09/itunes_10_adds_tv_rentals_secu.php</link>
<guid isPermaLink="true" >http://blogs.pcmag.com/securitywatch/2010/09/itunes_10_adds_tv_rentals_secu.php</guid>
<description>&lt;div id=&quot;&quot;&gt;&lt;tr readability=&quot;6.1459143968872&quot;&gt;&lt;td valign=&quot;bottom&quot; readability=&quot;1.8910505836576&quot;&gt;
&lt;p&gt;Thursday September 2, 2010&lt;/p&gt;


&lt;/td&gt;
&lt;/tr&gt;&lt;tr readability=&quot;7.9447513812155&quot;&gt;&lt;td class=&quot;defaults&quot; readability=&quot;9.1364640883978&quot;&gt;
&lt;div class=&quot;userdefaults&quot; readability=&quot;17.803468208092&quot;&gt;&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;a href=&quot;http://www.pcmag.com/category2/0,2806,1995378,00.asp&quot;&gt;&lt;img alt=&quot;0,1468,i=241120,00.gif&quot; src=&quot;http://blogs.pcmag.com/securitywatch/assets_c/2010/09/0,1468,i=241120,00-thumb-98x82-15038.gif&quot; width=&quot;98&quot; height=&quot;82&quot; class=&quot;mt-image-left c16&quot;/&gt;&lt;/a&gt;&lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2368618,00.asp&quot;&gt;There's a new version of iTunes out to provide lots of new features and services from Apple&lt;/a&gt;, but it's got another surprise under the covers: security vulnerability fixes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;iTunes 10 for Windows includes a new version of the Webkit web browser which &lt;a href=&quot;http://support.apple.com/kb/HT4328&quot;&gt;fixes 13 security vulnerabilities&lt;/a&gt;, the same fixes &lt;a href=&quot;http://support.apple.com/kb/HT4276&quot;&gt;recently provided in Safari 5.0.1&lt;/a&gt;. Many of these are critical remote code execution vulnerabilities or information disclosure bugs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Oddly, the iTunes update says that only Windows is affected, but the CVE vulnerability descriptions (such as &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1792&quot;&gt;this one&lt;/a&gt;) say that both the Windows and OS X versions are affected. The Safari updates were also listed both for Windows and OS X. &lt;span class=&quot;c17&quot;&gt;It makes sense that iTunes for OS X is also vulnerable but not yet fixed.&lt;/span&gt; In all likelihood, the earlier fixes to Safari in OS X fixed the installation of Webkit used by iTunes on that platform.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;&lt;/div&gt;



&lt;/td&gt;
&lt;/tr&gt;&lt;tr readability=&quot;0&quot;&gt;&lt;td&gt;

&lt;/td&gt;
&lt;/tr&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;This entry passed through the &lt;a href=&quot;http://fivefilters.org/content-only/&quot;&gt;Full-Text RSS&lt;/a&gt; service &amp;mdash; if this is your content and you're reading it on someone else's site, please read our FAQ page at &lt;a href=&quot;http://fivefilters.org/content-only/faq.php&quot;&gt;fivefilters.org/content-only/faq.php&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://fivefilters.org&quot;&gt;Five Filters&lt;/a&gt; featured article: &lt;a href=&quot;http://medialens.org/alerts/10/100720_peace_envoy_blair.php&quot;&gt;&quot;Peace Envoy&quot; Blair Gets an Easy Ride in the Independent&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
<pubDate>Thu, 02 Sep 2010 13:21:06 +0000</pubDate>
</item>
<item>
<title>Snoop Dogg Says &quot;Hack is Wack!&quot;</title>
<link>http://blogs.pcmag.com/securitywatch/2010/09/snoop_dogg_says_hack_is_wack.php</link>
<guid isPermaLink="true" >http://blogs.pcmag.com/securitywatch/2010/09/snoop_dogg_says_hack_is_wack.php</guid>
<description>&lt;div readability=&quot;36.948174322733&quot;&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;a href=&quot;http://blogs.pcmag.com/securitywatch/assets_c/2010/09/Hack%20Is%20Wack%20Logo-15012.php&quot; onclick=&quot;window.open('http://blogs.pcmag.com/securitywatch/assets_c/2010/09/Hack Is Wack Logo-15012.php','popup','width=486,height=311,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false&quot;&gt;&lt;img src=&quot;http://blogs.pcmag.com/securitywatch/assets_c/2010/09/Hack%20Is%20Wack%20Logo-thumb-200x127-15012.png&quot; alt=&quot;Hack Is Wack Logo.png&quot; class=&quot;mt-image-left c16&quot; width=&quot;200&quot; height=&quot;127&quot;/&gt;&lt;/a&gt;&lt;/span&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;If you read PCMag regularly you know more than the average Jo about how to protect your computer and your personal information from all kinds of cyber-attacks. That puts you way ahead of the crowd, but you'd be even safer if &lt;em&gt;everybody&lt;/em&gt; took proper precautions. To reach a wider audience with their security message the techies at Symantec are enlisting some new help - hot rapper Snoop Dogg and &lt;em&gt;YOU&lt;/em&gt;. Yes, you can be part of their new &quot;Hack is Wack&quot; initiative by submitting your own rap video for a chance to win awesome prizes.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;The contest runs from now until September 30th at the web site &lt;a href=&quot;http://www.hackiswack.com&quot; target=&quot;_blank&quot;&gt;www.hackiswack.com&lt;/a&gt;. Use your musical skills to create a rap video on the subject of staying safe from identity theft, viruses, hack attacks, or any aspect of cybercrime. Check the HackIsWack web site for a full listing of the rules. When your video is done to perfection upload it to the site. Or, if your talent runs more to listening than rapping, visit the site to view and rate the videos.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Making a video, even a short one, takes some serious time and effort. Why would you bother? Prizes and recognition, that's why. Symantec will fly the winner and a friend to Los Angeles and put them up in a hotel for two nights. The winner will &quot;meet with Snoop's management, learn more about his business and get tips on how to make it to the top&quot;. Also included are two tickets to a Snoop Dogg concert and a shiny new laptop loaded with the &lt;a href=&quot;%20http://www.pcmag.com/article2/0,2817,2362915,00.asp&quot; target=&quot;_blank&quot;&gt;Norton Internet Security 2011&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Again, the contest ends September 30th, so get busy writing those rhymes and laying down your tracks. Once the entry period closes Symantec and Snoop's management team will select the winner, to be announced on October 20th. Will it be you?&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;This entry passed through the &lt;a href=&quot;http://fivefilters.org/content-only/&quot;&gt;Full-Text RSS&lt;/a&gt; service &amp;mdash; if this is your content and you're reading it on someone else's site, please read our FAQ page at &lt;a href=&quot;http://fivefilters.org/content-only/faq.php&quot;&gt;fivefilters.org/content-only/faq.php&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://fivefilters.org&quot;&gt;Five Filters&lt;/a&gt; featured article: &lt;a href=&quot;http://medialens.org/alerts/10/100720_peace_envoy_blair.php&quot;&gt;&quot;Peace Envoy&quot; Blair Gets an Easy Ride in the Independent&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
<pubDate>Wed, 01 Sep 2010 18:41:48 +0000</pubDate>
</item>
<item>
<title>Microsoft Updates DLL Advisory, Adds &quot;Fix It&quot; Tool</title>
<link>http://blogs.pcmag.com/securitywatch/2010/08/microsoft_updates_dll_advisory.php</link>
<guid isPermaLink="true" >http://blogs.pcmag.com/securitywatch/2010/08/microsoft_updates_dll_advisory.php</guid>
<description>&lt;div readability=&quot;61.607317073171&quot;&gt;&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;img alt=&quot;fixit.jpg&quot; src=&quot;http://blogs.pcmag.com/securitywatch/fixit.jpg&quot; width=&quot;137&quot; height=&quot;55&quot; class=&quot;mt-image-left c16&quot;/&gt;Microsoft has updated their advisories and issued a new tool for the vulnerability in many Windows apps that could lead to the unwitting execution of a malicious DLL. &lt;a href=&quot;http://blogs.pcmag.com/securitywatch/2010/08/list_of_dll_vulnerability_wind.php&quot;&gt;This story has been developing for a couple weeks now&lt;/a&gt; and this is not the last we'll hear of it.&lt;/span&gt;&lt;/p&gt;
&lt;span id=&quot;intellitxt&quot;/&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;When a Windows program loads a DLL (dynamic link library), assuming it doesn't give the specific DLL location, Windows will follow a set of rules for where to look for the file. Way down the list is the current working directory.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;a href=&quot;http://blogs.pcmag.com/securitywatch/2010/08/details_emerge_on_remote_binar.php&quot;&gt;Recent research&lt;/a&gt; has that an attacker on a network share, by inducing a user to open a data file in a vulnerable application, trigger the application to load a particular DLL. If the attacker provides a malicious DLL in the same directory as the data file, which will have been set as the current working directory by Windows, and the DLL is not in any of the higher-priority locations, then the app will load the malicious DLL. The attack also works from a server on the Internet, although firewalls will typically block it by default.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;The unfortunate situation seems to be that Microsoft will not be providing a patch of some kind which will fix the problem globally, at least not one which will go out as a critical update. The vulnerabilities are, for the most part (see below), being treated as individual vulnerabilities in specific applications. Since there could be hundreds, perhaps thousands of such applications, the potential for attacks is large.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/2269637.mspx&quot;&gt;Microsoft issued an advisory&lt;/a&gt; early this week discussing the issue and describing a tool and a set of procedures they released to help block the attack. They have now updated the advisory and added a new tool, a simplified &quot;Fix it,&quot; which automates those procedures.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;The tool previously released, described and linked to in &lt;a href=&quot;http://support.microsoft.com/kb/2264107&quot;&gt;Knowledge Base article 2264107&lt;/a&gt;, controls DLL loading through a new registry key. The KB article also describes the various settings of the registry key. The new &lt;a href=&quot;http://go.microsoft.com/?linkid=9742148&quot;&gt;Fix it&lt;/a&gt; automates those registry settings to block all DLL loading in the manner used by the attack.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Note that you still have to install the update first. It's possible this will cause incompatibilities with some non-malicious application configurations, but you'd best take those failures as a sign you should change your configuration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;Because some larger managed networks might want to deploy the update through WSUS (Windows Server Update Services) and then manage the registry settings through Active Directory, &lt;a href=&quot;For%20this%20reason,%20when%20they%20issue%20fixes%20for%20their%20own%20applications%20they%20will%20classify%20them%20as%20no%20more%20than&quot;&gt;Microsoft is working to add the update to the Windows Update catalog&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;At the same time &lt;a href=&quot;http://blogs.technet.com/b/srd/archive/2010/08/31/an-update-on-the-dll-preloading-remote-attack-vector.aspx&quot;&gt;Microsoft notes in a blog entry&lt;/a&gt; that the actual user experience for such an attack gives plenty of warnings and the user must click a lot in order for the attack to succeed. For example:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;&lt;img alt=&quot;5008.protectedmode.png-550x0.png&quot; src=&quot;http://blogs.pcmag.com/securitywatch/5008.protectedmode.png-550x0.png&quot; width=&quot;416&quot; height=&quot;256&quot; class=&quot;mt-image-none&quot;/&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id=&quot;intellitxt&quot;&gt;For this reason, when they issue fixes for their own applications they will classify them as no more than &quot;Important&quot; as opposed to &quot;Critical.&quot;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;p&gt;&lt;em&gt;This entry passed through the &lt;a href=&quot;http://fivefilters.org/content-only/&quot;&gt;Full-Text RSS&lt;/a&gt; service &amp;mdash; if this is your content and you're reading it on someone else's site, please read our FAQ page at &lt;a href=&quot;http://fivefilters.org/content-only/faq.php&quot;&gt;fivefilters.org/content-only/faq.php&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://fivefilters.org&quot;&gt;Five Filters&lt;/a&gt; featured article: &lt;a href=&quot;http://medialens.org/alerts/10/100720_peace_envoy_blair.php&quot;&gt;&quot;Peace Envoy&quot; Blair Gets an Easy Ride in the Independent&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
<pubDate>Wed, 01 Sep 2010 02:43:00 +0000</pubDate>
</item>
</channel>
</rss>