Search This Blog

Thursday, November 01, 2007

Microsoft plots ambitious SOA roadmap; Microsoft continues pursuit of software pirates

Network World

Microsoft News Alert




Network World's Microsoft News Alert, 11/01/07

Microsoft plots ambitious SOA roadmap, 10/30/07: Microsoft Tuesday laid out an ambitious SOA roadmap around a set technologies code-named Oslo that will be blended into its middleware, development, and management tools and some of its emerging enterprise online services.

Microsoft continues pursuit of software pirates, 10/31/07: Microsoft Wednesday continued its efforts to stop people from pirating or using pirated versions of its software.

Facebook chooses Microsoft over Google, 10/24/07: Facebook will sell a $240 million minority stake to Microsoft, which as part of the deal will also expand the advertising services it provides to the social networking phenom, the companies said Wednesday in a statement.

Enterprise WLAN Gear: From A to Z.

From buying tips to peer discussions. From case studies to market trends. Network World's newly enhanced Enterprise WLAN Gear Buyer's Guide has everything you need to stay current, research technology, compare products and implement solutions - all in one convenient location.

Click here to go to the Enterprise WLAN Gear Buyer's Guide now.

Microsoft and open-source backers: best 'frenemies' forever, 10/25/07: Ballmer's statement that Linux "uses our intellectual property"-- along with follow-up claims by Microsoft executives that they had found violations of 235 patents in Linux and other open-source software -- caused a sudden refrosting of what had been a slowly thawing relationship between the company and the open-source community.

Microsoft to buy Thai health software vendor, 10/29/07: Microsoft Monday said it has agreed to buy a Thai software vendor that specializes in hospital administration applications, and plans to sell the software in emerging markets.

Four sentenced in Microsoft fraud scheme, 10/26/07: The U.S. Attorney’s Office says that four people were sentenced to prison and required to make $40 million in restitution for a scheme to defraud Microsoft into giving them software discounts by pretending to be academic institutions.

Microsoft opens up virtualization API, 10/25/07: Microsoft has announced that a key API of its hypervisor technology will be open sourced.

Today on Microsoft Subnet: Wal-Mart begins selling $198 Linux computer loaded with links to Google Apps. Michael Dortch shudders over the three faces of Microsoft: Why does is it compete against itself in the SMB unified communications market?  Microsoft Subnet blogger Alex Lewis continues his quest to find the gPhone. Google appears to be in discussions with HTC and LG. John Obeto gloats that there is trouble in ODF city, and Sue Hanley explains how, when rolling out SharePoint, you can learn a lot from the social networking sites.

Editor's note: Starting the week of Nov. 12, subscribers to the HTML version of this newsletter will notice some enhancements to the layout that will provide you with easier and clearer access to a wider range of resources at Network World. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:

Senior Editor John Fontana covers Microsoft for Network World.

Julie Bort edits Microsoft Subnet

Microsoft Subnet: The independent voice of Microsoft customers



BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

WindowSecurity.com - Monthly Article Update

WindowSecurity.com - Monthly Article Update

Hi Security World,

New articles added to WindowSecurity.com last month:

Title: Controlling Resource Permissions
Author: Derek Melber
Link: http://www.WindowSecurity.com/articles/Controlling-Resource-Permissions.html
Summary: Controlling permissions on network resources.

Title: Nessus Security Scanner - Voted WindowSecurity.com Readers' Choice Award Winner - Security Scanner Software Category
Author: Admin
Link: http://www.WindowSecurity.com/news/WindowSecurity-Readers-Choice-Award-Security-Scanner-Software-Category-Nessus-Sep07.html
Summary: Nessus Security Scanner was selected the winner in the Security Scanner Software category of the WindowSecurity.com Readers' Choice Awards. GFI LANguard NSS and Retina Network Security Scanner Protection were first runner-up and second runner-up.

Title: Group Policy related changes in Windows Server 2008 - Part 1: What are Starter GPOs?
Author: Jakob H. Heidelberg
Link: http://www.WindowSecurity.com/articles/Group-Policy-related-changes-Windows-Server-2008-Part1.html
Summary: This article series will focus on the Group Policy related features which will bring both easier manageability and better security.

Title: Web Application Hacking vs the IDS
Author: Don Parker
Link: http://www.WindowSecurity.com/articles/Web-Application-Hacking-vs-IDS.html
Summary: The world of web application hacking is an enormous one, and also one that is constantly changing. Just how well does your IDS fare against it?

Title: Privacy - Keeping your information confidential
Author: Ricky M. Magalhaes
Link: http://www.WindowSecurity.com/articles/Privacy-Keeping-information-confidential.html
Summary: Important tips on keeping your information confidential when using the net.

Title: Prepare for MPACK
Author: Derek Melber
Link: http://www.WindowSecurity.com/articles/Prepare-MPACK.html
Summary: Insight into a new high tech attack that is running around the Internet also known as MPACK.

Title: Protect Public Computers with Windows SteadyState, Part 1
Author: Jakob H. Heidelberg
Link: http://www.WindowSecurity.com/articles/Protect-Public-Computers-Windows-SteadyState-Part1.html
Summary: This article series will focus on "Windows SteadyState" – a completely free toolkit from Microsoft that helps administrators take control of shared access computers running Windows XP.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowSecurity.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsecurity.com

Copyright © WindowSecurity.com 2007. All rights reserved.

Social engineering in penetration testing: Planning

Network World

Security Strategies




Network World's Security Strategies Newsletter, 11/01/07

Social engineering in penetration testing: Planning

By M. E. Kabay

In the two preceding columns, (Oct. 25 and Oct. 30) John Orlando discussed the ethical dimensions of social engineering in penetration testing. Today I want to look at how to use social engineering effectively for penetration testing.

I have long believed and taught that social engineering can be useful for security testing, but only with careful preparation.

The first and most obvious warning is that bad penetration testing in general is pointless unless the organization has implemented the best available security measures it can manage. Why bother testing security if even a simple vulnerability analysis or common sense assessment shows gaping holes? A penetration test of obviously flawed security is a waste of time and money.

Webcast: Get the latest on NAC

Learn the latest on Network Access Control in Network World's Perspectives Editorial Webcast. Discover how IT professionals can leverage this hot security technology in their networks, while also learning about key management areas that have not yet been perfected.

To learn more click here.

In a Network World column published in 2000, I pointed out that deception techniques should be used only with a great deal of preparation of the staff. When preparing for a penetration test that involves social engineering, everyone in the organization should be thoroughly trained to understand the techniques of social engineering before beginning the tests.

The key points were as follows (from my article):
* The entire organization can prepare for social engineering simulations as a team; no one is subjected to attempted deception without knowing that the experience was part of a training and awareness exercise.
* Even if someone falls for a trick, the emotional effect is far less than if the same error occurred without preparation.

I think that preparing staff for the onslaught of skilled social engineers has many benefits. We can frame the exercises as a form of game or contest: who will be the best at spotting the confidence tricksters? Who will be quickest to foil their nefarious plans?

Role-playing games are an excellent way of changing beliefs, attitudes and behavior: having staff members take up the roles of social engineer and defender - and then reversing roles - is not only amusing, but it also has a long-term effect on people’s perceptions. It’s much easier to remember a social interaction we’ve experienced personally than to pay attention to abstract words. We can even turn the event into an opportunity for a good deal of fun and laughter, making security and secure behavior a positive experience instead of the usual drudgery.

Moreover, in addition to risk avoidance (reducing the likelihood of hurt feelings, frustration and anger), solid preparation can result in increased vigilance at all times. Once staff members are sensitized to the social engineering tricks they’ve experienced in role-playing games, they are more likely to recognize them in strangers. Having practiced alerting the security team to apprehended breaches, they will find it easier to take the initiative later when they spot real breaches.

In my next column, I’ll finish with this topic (for now) by discussing approaches to handling cases of successful social engineering.

Editor's note: Starting Tuesday, Nov, 13, this newsletter will be renamed "Security Strategies Alert." Subscribers to the HTML version of this newsletter will notice some enhancements that will provide access to more resources relevant to IT security. You will still receive M. E. Kabay's analysis of this topic, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.


  What do you think?
Post a comment on this newsletter

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:

M. E. Kabay, PhD, CISSP-ISSMP is Program Director of the Master of Science in Information Assurance and CTO of the School of Graduate Studies at Norwich University in Northfield, Vt. Mich can be reached by e-mail and his Web site.



ARCHIVE

Archive of the Security Strategies Newsletter.


BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Recovering from disasters

Network World

Unified Communications




Network World's Unified Communications Newsletter, 11/01/07

Recovering from disasters

By Michael Osterman

The horrible fires in Southern California over the past week, Hurricane Katrina, the blackout in the northeast several years ago, the tornadoes that hit the Midwest every year, a faulty RAID controller and the occasional rat that chews through electrical cabling can knock out e-mail service for hours or days or even weeks at a time. While the situation is critical when e-mail service is unavailable, unified communications will make the issue much worse when both telephony and e-mail share a centralized infrastructure.

The consequences of an outage can be very damaging. A study we did recently found that one in five organizations estimates they could lose up to a half million dollars in the event of a major e-mail outage. Aside from the monetary impact, there is the damage to an organization’s reputation, the damage to its brand and the inability for its employees to be as productive as they otherwise could be.

In general, the faster the recovery time, the more expensive the solution. Systems that provide hot standby e-mail systems or mirroring usually provide rapid recovery, but are typically expensive. Electronic vaulting or journaling, on the other hand, while less expensive, provide recovery times that might not be acceptable. What organizations need, therefore, is a system that provides the best of both worlds.

Enterprise WLAN Gear: From A to Z.

From buying tips to peer discussions. From case studies to market trends. Network World's newly enhanced Enterprise WLAN Gear Buyer's Guide has everything you need to stay current, research technology, compare products and implement solutions - all in one convenient location.

Click here to go to the Enterprise WLAN Gear Buyer's Guide now.

In planning a disaster recovery solution, organizations need to answer several questions: How much e-mail data loss is acceptable following a disaster? How much time between the beginning of an e-mail service loss and e-mail recovery is acceptable? What quantifiable or other benefits would there be in speeding up the recovery process?

We will be hosting a Webinar this week on the topic of disaster recovery and will be discussing one company’s offerings focused on disaster recovery in Exchange environments. You can sign up for this no-charge Webinar here.

Editor's note: Starting Tuesday, Nov, 13, this newsletter will be renamed "Unified Communications Alert." Subscribers to the HTML version of this newsletter will notice some enhancements that will provide you with access to more resources relevant to unified communications. You will still receive Michael Osterman's analysis of this market, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.


  What do you think?
Post a comment on this newsletter

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:

For webinars or research on messaging, or to join the Osterman Research market research survey panel, go here. Osterman Research helps organizations understand the markets for messaging and directory related offerings. To e-mail Michael, click here.



ARCHIVE

Archive of the Unified Communications Newsletter.


BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Streamcore emphasizes WAN visibility and reporting

Network World

Network Optimization




Network World's Network Optimization Newsletter, 11/01/07

Streamcore emphasizes WAN visibility and reporting

By Ann Bednarz

WAN application performance is one of those IT areas that are of interest not only to IT staff but also to business managers, since application delivery is so closely tied to employee productivity. But the metrics IT managers are interested in monitoring may differ -- not surprisingly -- from those business managers want to track.

To satisfy different reporting tastes, Streamcore this week unveiled StreamAccess, a set of tools designed to help customers deliver relevant statistical data on network and application performance to both IT personnel and business unit managers. The tools are geared for enterprise users of Streamcore’s application acceleration and performance management products, as well as service providers that want to pass along WAN monitoring capabilities to their customers.

StreamAccess lets IT build customized Web portals for different groups or individuals to view WAN data reports. Technical staff at a multinational company might want to view the service status of all T-1 links, around the world, from a specific service provider, for example, while business staff in a specific division might want to see network metrics pertaining only to their division, says Eric Jeux, Streamcore’s CEO. “We make it really easy to match the metrics and measures you get with the various business activities,” he says.

Executive Guide "Data Center Decisions"

Download our new Executive Guide "Data Center Decisions" to sharpen your competitive edge. This guide offers tips on dealing with server consolidation, virtualization, management, cooling and power issues.

Click Here for More Information

StreamAccess also helps with charge-back processes by allowing companies to quantify and present bandwidth consumption by each business unit. “Each business unit can have a view of what it is using, and how it is using the network,” Jeux says.

StreamAccess is part of the company’s StreamSense management platform, which combines monitoring features with provisioning and configuration tools that let users control the resources dedicated to business applications. StreamSense tracks performance indicators such as response times, number of sessions and traffic volume analysis. For example, it can determine which country consumes the most data center bandwidth, what business unit has the most users on the ERP system, or what group is experiencing the worst application response times.

A key capability of StreamSense is that is combines business reporting and troubleshooting with automated application performance controls, Jeux says. If an IT manager isn’t using the same tool to both measure and control application conditions, there can be disconnect between the two activities. “You never really know if you’re measuring what you’re doing,” he says.

StreamSense also includes rights-management capabilities so enterprises and service providers can control users’ access to management data and provisioning controls.

Other network optimization players also have been working to improve their monitoring and management wares. For example, Exinda Networks in May unveiled Service Delivery Point, a Web-based application for centrally configuring and monitoring its WAN optimization gear. 

Editor's note: Starting Monday, Nov, 12, this newsletter will be renamed "Network Optimization Alert." Subscribers to the HTML version of this newsletter will notice some enhancements that will provide you with access to more resources relevant to network optimization. You will still receive Ann Bednarz's analysis of this market, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.


  What do you think?
Post a comment on this newsletter

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:

Ann Bednarz is an associate news editor at Network World responsible for editing daily news content. She previously covered enterprise applications, e-commerce and telework trends for Network World. E-mail Ann.



ARCHIVE

Archive of the Network Optimization Newsletter.


BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Abandoning wired links becomes more plausible with 802.11n gear

Network World

Product Test and Buyer's Guide




Product Test and Buyer's Guide, 11/01/07

By Christine Burns

As part of Network World’s recently published list of the networking industry’s all-time greatest arguments, Senior Editor John Cox contends that there are indeed IT people acting in their right minds who are exchanging their dedicated 100Mbps and Gigabit wired Ethernet connections for shared wireless ones.

College IT departments, in addition to wiring all their dorm rooms with high-speed connections, also have to supply students with WLAN access as their main mode of access to campus applications, libraries and labs, and the Internet.

Cox argues that this wired/wireless debate is heating up in the business world as well for two reasons. First, new software and silicon now let vendors build WLAN functions directly into Ethernet switches. The infrastructure will handle both wired and wireless access with integrated security and management. Second, and more dramatically, vendors such as Meru and Cisco are now releasing next generation Wi-Fi gear based on the draft 802.11n standard. Users can expect to see shared throughput of 150M to 200Mbps to start and well over 300Mbps in premium equipment soon.

Wireless LAN Security: A to Z

From buying tips to peer discussions. From case studies to market trends. Network World's newly enhanced Wireless Security Buyer's Guide has everything you need to stay current, research technology, compare products and implement solutions - all in one convenient location.

Visit the Wireless LAN Security Buyer's Guide now.

In the newly revamped Enterprise Wireless LAN Buyer’s Guide, you can tap into a wealth of information on which WLAN players are considered the strongest in this field, on how to best implement wireless technology and products on a wide-scale basis, and how the more than 60 products listed in this guide compare on everything from port density on the wired side to 802.11n support on the wireless one.

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:
Christine Burns is the Executive Editor of Testing. She can be reached at cburns@nww.com

BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Immaturity hurting NAC adoption

Network World

Security: Network Access Control




Network World's Security: Network Access Control Newsletter, 11/01/07

Immaturity hurting NAC adoption

By Tim Greene

The largest corporations are drawing back from NAC until it is more mature, according to the latest security survey by TheInfoPro.

According to the study, the percentage of Fortune 1000-sized businesses with NAC in place has been dropping over the past 18 months from 35% to 26%.

“They said NAC didn’t work with their infrastructure, so they will wait until they upgrade their infrastructure to support NAC or wait for a different solution that works better with older infrastructure gear,” says Bill Trussell, TIP’s Managing Director of Information Security Research. “Rather than abandoning NAC completely, they say they are moved it into their longer term planning.”

Webcast: Get the latest on NAC

Learn the latest on Network Access Control in Network World's Perspectives Editorial Webcast. Discover how IT professionals can leverage this hot security technology in their networks, while also learning about key management areas that have not yet been perfected.

To learn more click here.

TIP conducts surveys with 221 end users from firms with $1.4 billion or more in revenue every six months. Each user is prequalified and as part of their jobs make network planning, vendor-selection and purchasing decisions, Trussell says. Each interview lasts an hour to an hour and a half.

The firm tries to reach all the same respondents from one survey to the next, and gets between 80% and 85% repeaters, says Trussell. The dip in respondents that have NAC installed could be due to the shift in respondents, he says. But historical survey results for new technologies show that when they are solidly in adoption phase, they have not dipped in this fashion, he says.

The reason businesses are taking out NAC is that the gear doesn’t meet their initial expectations for how easy it would be to install. “It’s certainly a lot slower than what the origin concept was,” he says. “They thought it would be, you roll it out, you plug it in, and it works.”

These same businesses have shifted what they expect from NAC as well, he says. Initially, most respondents wanted it to  ensure compliance with enterprise security policies on endpoints, but management of guest-user access is now the most commonly cited reason for using NAC.

Editor's note: Starting Tuesday, Nov, 13, this newsletter will be renamed "Security: Network Access Control Alert." Subscribers to the HTML version of this newsletter will notice some enhancements that will provide you with access to more resources relevant to IT security. You will still receive Tim Greene's analysis of this market, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.


  What do you think?
Post a comment on this newsletter

MOST-READ STORIES:
1. Networking's 50 greatest arguments
2. Microsoft plots ambitious SOA roadmap
3. Google's social networking power move
4. IT pros share their horror stories
5. Is Fibre Channel dead?
6. Podcast: Real-life scary security stories
7. Attack code for Kodak bug in Windows
8. Cisco certifications: All you need to know
9. Top 20 Firefox extensions
10. Cisco's profits: 5 trends worth watching

FEATURED BUYER'S GUDIE:
Network Access Control


Contact the author:

Tim Greene is a senior editor at Network World, covering network access control, virtual private networking gear, remote access, WAN acceleration and aspects of VoIP technology. You can reach him at tgreene@nww.com.



ARCHIVE

Archive of the Security: Network Access Control Newsletter.


BONUS FEATURE

90% of IT Managers are leaving their company at risk for a DNS ATTACK. Get the tools and resources you need to keep your DNS healthy and secure. Run a DNSreport on your domain today - 56 critical tests run in 8 seconds.

Visit www.dnsreport.com to learn more. (apply coupon NWW2007NLA for a 25% membership discount)


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

WindowsNetworking.com - Monthly Article Update

WindowsNetworking.com - Monthly Article Update

Hi Security World,

New articles and tutorials added to WindowsNetworking.com last month:

Title: Office Communications Server 2007: Hands-On (Part 3)
Author: Ted Wallingford
Link: http://www.WindowsNetworking.com/articles_tutorials/Office-Communications-Server-2007-Hands-On-Part3.html
Summary: Find out how to install, configure, and begin using Office Communications Server in this hands-on introduction.

Title: Symantec Backup Exec System Recovery - Voted WindowsNetworking.com Readers' Choice Award Winner - Data Recovery
Author: Site Admin
Link: http://www.WindowsNetworking.com/news/WindowsNetworking-Readers-Choice-Award-Data-Recovery-Symantec-Backup-Exec-System-Recovery-Sept07.html
Summary: Symantec Backup Exec System Recovery was selected the winner in the Data Recovery category of the WindowsNetworking.com Readers' Choice Awards. GetDataBack and Active@ File Recovery Enterprise were first runner-up and second runner-up.

Title: Group Policy Extensions in Windows Vista and Windows Server 2008, Part 4
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Group-Policy-Extensions-Windows-Vista-Windows-Server-2008-Part4.html
Summary: This article continues the series by discussing more User Account Control settings.

Title: Multi-Core CPUs
Author: Russell Hitchcock
Link: http://www.WindowsNetworking.com/articles_tutorials/Multi-Core-CPUs.html
Summary: Topics related to the adoption of multi-core CPUs.

Title: Networking Basics: Part 13 - Creating Groups
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Networking-Basics-Part13.html
Summary: This article continues the Networking for Beginners series by introducing the concept of security groups.

Title: Windows Server 2008 - First Look
Author: David Davis
Link: http://www.WindowsNetworking.com/articles_tutorials/Windows-Server-2008-First-Look.html
Summary: In this review of Windows Server 2008, we take a look at the features and benefits of Microsoft's newest and most advanced server Operating System. What is new, why should you try it out, and how can it help you?

Title: Deploying Data Protection Manager 2007 (Part 2)
Author: Anderson Patricio
Link: http://www.WindowsNetworking.com/articles_tutorials/Deploying-Data-Protection-Manager-2007-Part2.html
Summary: How to install Agents and add disks to the DPM Storage Pool and a high-level overview of the five areas in the DPM Administrator Console.

Title: Working With Network Monitor (Part 5)
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Working-Network-Monitor-Part5.html
Summary: This article concludes the Working with Network Monitor series by showing you how to extract readable data from a captured packet.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowsNetworking.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@WindowsNetworking.com

Copyright © WindowsNetworking.com 2007. All rights reserved.

ISAserver.org - Monthly Article Update

ISAserver.org - Monthly Article Update

Hi Security World,

New articles added to ISAserver.org last month:

Title: Configuring the ISA Firewall to Support Certificate-Based EAP-TLS Authentication (Part 1)
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Configuring-ISA-Firewall-Support-Certificate-Based-EAP-TLS-Authentication-Part1.html
Summary: How to configure the ISA Firewall to Support Certificate-Based EAP-TLS Authentication.

Title: GFI WebMonitor Voted ISAserver.org Readers' Choice Award Winner - Monitoring & Administration
Author: Site Admin
Link: http://www.ISAserver.org/news/ISAserver-Readers-Choice-Award-Monitoring-Administration-GFI-WebMonitor-Aug07.html
Summary: GFI WebMonitor was selected the winner in the Monitoring & Administration category of the ISAserver.org Readers' Choice awards. SurfControl Web Filter and WebSense Enterprise were runner-up and second runner-up respectively.

Title: Creating a DNS Infrastructure to Support Exchange Server 2003
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Creating-DNS-Infrastructure-Support-Exchange-Server-2003.html
Summary: DNS troubleshooting in relation to configuring remote access to Microsoft Exchange Servers using ISA Server 2004.

Title: Questions and Answers About the ISA 2006 Firewall
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Questions-Answers-ISA-2006-Firewall.html
Summary: General questions and answers about the ISA Firewall.

Title: Why Upgrade to ISA 2006 Firewalls?
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Why-Upgrade-ISA-2006-Firewalls.html
Summary: Top reasons to upgrade to ISA 2006 Firewalls.

Title: Configuring the 2006 ISA Firewall to Support Password Changes
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Configuring-2006-ISA-Firewall-Support-Password-Changes.html
Summary: How to configure the 2006 ISA Firewall to Support Password Changes.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
ISAserver.org is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@isaserver.org

Copyright © ISAserver.org 2007. All rights reserved.

[NT] IPSwitch IMail Server IMail Client Buffer Overflow

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

IPSwitch IMail Server IMail Client Buffer Overflow
------------------------------------------------------------------------


SUMMARY

The <http://www.ipswitch.com/purchase/products/imail_server.asp> IMail
Client "is provided for those who are administering IMail Server on the NT
workstation on which IMail Server is installed. It is useful for reading
the 'root' mailbox, working with seldom-used accounts, and testing.".
Secunia Research has discovered a vulnerability in the IMail Client, which
potentially can be exploited by malicious people to compromise a user's
system.

DETAILS

Vulnerable Systems:
* IMail Client version 9.22 included with IPSwitch IMail Server version
2006.22

The vulnerability is caused due to a boundary error within the IMail
Client when processing emails containing multipart MIME data. This can be
exploited to cause a data segment-based buffer overflow via an overly long
"boundary" parameter (more than 212 bytes).

Solution:
The vendor recommends users to delete the IMail Client application, which
will be removed from the next major release of the IPSwitch IMail Server.

Time Table:
24/09/2007 - Vendor notified.
25/09/2007 - Vendor response.
30/10/2007 - Public disclosure.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4345>
CVE-2007-4345


ADDITIONAL INFORMATION

The information has been provided by Secunia Research.
The original article can be found at:
<http://secunia.com/secunia_research/2007-81/>

http://secunia.com/secunia_research/2007-81/

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[UNIX] McAfee E-Business Server Auth Packet Handling Buffer Overflow

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

McAfee E-Business Server Auth Packet Handling Buffer Overflow
------------------------------------------------------------------------


SUMMARY

"http://www.mcafee.com/us/enterprise/products/encryption/ebusiness_server.html secures batch processes and protects sensitive company data and network traffic with 128-bit encryption and authentication, everywhere it is accessed, transferred, and stored". Secunia Research has discovered a vulnerability in McAfee E-Business Server, which can be exploited by malicious people to compromise a vulnerable system.

DETAILS

Vulnerable Systems:
* McAfee E-Business Server for Linux version 8.1.1

Immune Systems:
* E-Business Server version 8.5.3 for Solaris
* E-Business Server version 8.1.2 for Linux, HP-UX, AIX

The vulnerability is caused due to an integer overflow within the
e-Business administration utility service when parsing authentication
packets. This can be exploited to cause a heap-based buffer overflow via a
specially crafted authentication packet with an overly large length value.

Successful exploitation allows execution of arbitrary code.

Solution:
Install E-Business Server 8.5.3 for Solaris, or install E-Business Server
8.1.2 for Linux, HP-UX, AIX.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2957>
CVE-2007-2957


ADDITIONAL INFORMATION

The information has been provided by Secunia Research.
The original article can be found at:
<http://secunia.com/secunia_research/2007-69/>

http://secunia.com/secunia_research/2007-69/

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[UNIX] CUPS IPP Tags Memory Corruption Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

CUPS IPP Tags Memory Corruption Vulnerability
------------------------------------------------------------------------


SUMMARY

" <http://www.cups.org/> CUPS provides a portable printing layer for
UNIX-based operating systems. It was developed by Easy Software Products
and is now owned and maintained by Apple Inc. to promote a standard
printing solution. It is the standard printing system in Mac OS X and most
Linux distributions". Secunia Research has discovered a vulnerability in
CUPS, which can be exploited by malicious people to compromise a
vulnerable system.

DETAILS

Vulnerable Systems:
* CUPS version 1.3.3

The vulnerability is caused due to a boundary error within the
"ippReadIO()" function in cups/ipp.c when processing IPP (Internet
Printing Protocol) tags. This can be exploited to overwrite one byte on
the stack with a zero by sending an IPP request containing specially
crafted "textWithLanguage" or "nameWithLanguage" tags.

Successful exploitation allows execution of arbitrary code.

Time Table:
16/10/2007 - Vendor notified.
22/10/2007 - vendor-sec notified.
31/10/2007 - Public disclosure.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4351>
CVE-2007-4351


ADDITIONAL INFORMATION

The information has been provided by Secunia Research.
The original article can be found at:
<http://secunia.com/secunia_research/2007-76/>

http://secunia.com/secunia_research/2007-76/

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[UNIX] Perdition IMAP Proxy str_vwrite Format String Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Perdition IMAP Proxy str_vwrite Format String Vulnerability
------------------------------------------------------------------------


SUMMARY

<http://www.vergenet.net/> Perdition is "a fully featured POP3 and IMAP4
proxy server. It is able to handle both SSL and non-SSL connections and
redirect users to a real-server based on a database lookup". Perdition
IMAPD is affected by a format string bug in one of its IMAP output-string
formatting functions. The bug allows the execution of arbitrary code on
the affected server. A successful exploit does not require prior
authentication.

DETAILS

Vulnerable Systems:
* Perdition Mail Retrieval Proxy version 1.17 and prior

Immune Systems:
* Perdition Mail Retrieval Proxy version 1.17.1

Vulnerability details:
1.) In certain situations, the IMAP-Tag (first part of IMAP-command) is
copied into a character buffer without validation. This buffer is then
ultimately passed to vsnprintf() as a format string.

2.) Before the call to vsnprintf, a validation of the format string is
performed as a protection against format string injection.

>From str.c:
++++++++++++++++++++++++++++++++++++
168: static const char *__str_vwrite(io_t * io, const flag_t flag,
169: const size_t nargs, const char *fmt, va_list ap,
170: int *bytes)
171: {
(...)
186: fmt_args = 0;
187: for (place = 0; fmt[place] != '\0'; place++) {
188: if (fmt[place] == '%')
189: fmt[place + 1] == '%' ? place++ : fmt_args++;
190: }
191: if (fmt_args != nargs) {
(...)
195: VANESSA_LOGGER_DEBUG_UNSAFE("nargs and fmt mismatch: "
196: "%d args requested, %d args in format",
197: nargs, fmt_args);
198: return (NULL);
199: }
200:
201: *bytes = vsnprintf(__str_write_buf, STR_WRITE_BUF_LEN - 2, fmt,
ap);
++++++++++++++++++++++++++++++++++++

In line 187-191, the actual number of format identifiers is compared to
supposed number given in the parameter nargs. This check can however be
bypassed by injecting a null-byte in the end of the IMAP-tag. The
null-byte cuts of the rest of the string (with the original format
identifiers intended by the programmer). Therefore it is possible to
inject 'nargs' arbitrary format identifiers within the IMAP tag. In
practice, only a single format identifier can be controlled by the
attacker. This is not very nice to exploit, however arbitrary code
execution is still possible. For example, multiple successive
single-byte-writes on a global function pointer can be used to gain
control of the instruction pointer. Due to the nature of the
vulnerability, a good exploit can bypass most OS security features
(non-exec-stack, ASLR, etc.) as well as compiler features (stack
canaries,...).

Proof-of-Concept
The following can be used to test for the vulnerability:
perl -e 'print "abc%n\x00\n"' | nc perdition.example.com 143

Vendor status:
Vendor notified: 2007-10-12
Vendor response: 2007-10-12
Patch available: 2007-10-31


ADDITIONAL INFORMATION

The information has been provided by <mailto:research@sec-consult.com>
Bernhard Mueller.
The original article can be found at:
<http://www.sec-consult.com/300.html> http://www.sec-consult.com/300.html

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[NT] Macrovision InstallShield Update Service ActiveX Unsafe Method Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Macrovision InstallShield Update Service ActiveX Unsafe Method
Vulnerability
------------------------------------------------------------------------


SUMMARY

<http://www.macrovision.com/products/installation/installshield.htm>
MacroVision InstallShield is "an installer solution utilized by many
software vendors in order to ensure that their products are delivered and
setup properly on the end-user systems. InstallSheild includes support for
an optional component called the 'Update Service'. This service allows
vendors to notify clients of product patches and updates, and allow them
to be easily installed". Remote exploitation of an unsafe method
vulnerability in Macrovision InstallShield Update Service allows attackers
to execute arbitrary code with the privileges of the currently logged-in
user.

DETAILS

Vulnerable Systems:
* Macrovision InstallShield Update version 5.01.100.47363, and
6.0.100.60146

The Update Service is implemented as an ActiveX control with the following
properties:

CLSID: E9880553-B8A7-4960-A668-95C68BED571E
File: C:\Windows\Downloaded Files\isusweb.dll
Version: 5.01.100.47363, and 6.0.100.60146

This control is marked "safe for scripting". Several methods within this
control can be utilized by attackers to download and launch arbitrary
executables.

Analysis:
Exploitation allows attackers to execute arbitrary code with the
privileges of the currently logged-in user. In order for exploitation to
occur, users would be required to have a vulnerable version of the
software installed and be lured to a malicious site. Even though the
update control does display an interface, no additional interaction is
required in order for exploitation to occur.

Since this control is marked "safe for scripting", it can be launched from
a web page without warning dialogs. While it is possible for an alert user
to determine what is occurring and cancel the installation, the window of
opportunity is small and based solely upon the time required for the
system to complete the download.

Workaround:
Administrators can set the kill-bit for the vulnerable ActiveX control
with the following .reg file. This will prevent the control from loading
within Internet Explorer.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX
Compatibility\{E9880553-B8A7-4960-A668-95C68BED571E}]
"Compatibility Flags"=dword:00000400

Vendor response:
Macrovision has addressed this vulnerability by releasing updated versions
of their FlexNet and InstallShield products. They report that the new
versions are no longer marked as "safe for scripting". For more
information, consult the following URL:
<http://www.macrovision.com/promolanding/7660.htm>

http://www.macrovision.com/promolanding/7660.htm

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5660>
CVE-2007-5660

Disclosure timeline:
09/24/2007 - Initial vendor notification
09/24/2007 - Initial vendor response
10/31/2007 - Coordinated public disclosure


ADDITIONAL INFORMATION

The information has been provided by iDefense Labs.
The original article can be found at:
<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618>

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[NT] Symantec Altiris Deployment Solution TFTP/MTFTP Service Directory Traversal Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Symantec Altiris Deployment Solution TFTP/MTFTP Service Directory
Traversal Vulnerability
------------------------------------------------------------------------


SUMMARY

<http://www.altiris.com/Products/DeploymentSolution.aspx> Symantec
Altiris Deployment Solution is "an automated OS deployment solution that
is used for deploying and managing servers, desktops, and notebooks from a
central location". Remote exploitation of a directory traversal
vulnerability in Symantec's Altiris Deployment Solution products could
allow attackers to gain read access to arbitrary files hosted on the
Altiris server.

DETAILS

Vulnerable Systems:
* Altiris Deployment Solution for Windows version 6.8 (pxemtftp.exe

version 6.8.8297.48)

Immune Systems:
*

Altiris Deployment Solution includes a tftp/mtftp server within its
optional PXE server component which suffers from a directory traversal
condition. The server runs with SYSTEM level privileges and allows
unauthenticated attackers to download any file on the system.

Analysis:
Exploitation allows attackers to read arbitrary files from the server
machine. The tftp/mftp daemon runs with SYSTEM level privileges, so any
file readable by SYSTEM with a known file path can be downloaded without
authentication.

Workaround:
If the PXE server component is not required in your environment it should
be disabled.

Vendor response:
Symantec Altiris has addressed this vulnerability by releasing a HotFix.
More information is available in Symantec's advisory at the following URL:
<http://www.symantec.com/avcenter/security/Content/2007.10.31.html>

http://www.symantec.com/avcenter/security/Content/2007.10.31.html

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3874>
CVE-2007-3874

Disclosure timeline:
07/13/2007 - Initial vendor notification
07/16/2007 - Initial vendor response
10/31/2007 - Public disclosure


ADDITIONAL INFORMATION

The information has been provided by iDefense Labs.
The original article can be found at:
<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=619>

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=619

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

[TOOL] Bunny The Fuzzer

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Bunny The Fuzzer
------------------------------------------------------------------------


SUMMARY

DETAILS

Bunny uses automatically generated C-level instrumentation to focus on
runtime inputs observed to trigger new control flow paths or interesting
parameter variations - and to bail out early on dead-end fuzzing routes.

This notably improves flow path coverage and overall quality of the
fuzzing process.

The tool is designed to maintain a near-native execution speed, and
requires virtually no setup, even when dealing with complex and large
codebases. This is probably a major improvement over previous closed loop
solutions.

The software should be reasonably stable, though some bugs might still
need to be ironed out.


ADDITIONAL INFORMATION

The information has been provided by <mailto:lcamtuf@dione.cc> Michal
Zalewski.
To keep updated with the tool visit the project's homepage at:
<http://code.google.com/p/bunny-the-fuzzer/wiki/BunnyDoc>

http://code.google.com/p/bunny-the-fuzzer/wiki/BunnyDoc

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.