Showing posts with label patch. Show all posts
Showing posts with label patch. Show all posts

Friday, March 13, 2015

Are you FREAKed out yet?


So maybe you heard about the latest round of security nightmares that plague what everyone thought was secure web traffic.

A few months back it was a serious security flaw in OpenSSL known as HeartBleed that sent webmasters scrambling.  Then came a left field sucker punch when it was discovered that all an attacker needed to do to compromise your entire server (not just a website) was to insert some code that a BASH prompt would respond to. 

Encryption be damned if you have root access to the server!

Which brings us to the latest security gaffe, otherwise known as a Freak attack...

This one has its roots in the earliest implementations of web security.  Back in the days when the U.S. government was so paranoid about not being able to clandestinely snoop on your encrypted communications that they enforced a ban on strong encryption ( aka: stuff they couldn't break.) It was deemed "export-grade" encryption which was just a fancy name for "weak."

They did it by forcing SSL to downgrade its encryption bit strength when traffic left the U.S. thus allowing easy surveillance of all "suspicious" (meaning all) traffic.

Well, as we know from the Snowden leaks there's not much need to worry about borders anymore.  The U.S. has monitoring bases worldwide now.  Besides, the juicy fruit of of the spy game is gathered from far less hardened sources these days.  Just bug a German chancellor's phone and you've got all the dirt you need on the EU.

But let's get back to the problem at hand. 

There are still remnants of this "backdoor" in SSL and because of it millions of websites are vulnerable to compromise using relatively simple "man in the middle" attacks that utilize the facilities of weak encryption still present in SSL implementations.

The worst part is that the problem exists on both the client (aka: your browser) and server sides.  A compromised client and a compromised server are a marriage made in heaven. 

So what's the solution?  Pretty much the same as always.  Keep abreast of security news and patch, patch, patch!  Which is why there were so many Internet Explorer security patches this week.  Open SSL will have a patch available too.

If you'd like to dig a little deeper the following site will let you test both your browser and your favorite SSL secured websites.



Do it now.

Friday, September 26, 2014

FIX your BASH already! Correcting the BASH shellshock vulnerability

By now you've heard that just about every 'Nix box on the planet is vulnerable to a flaw in the BASH shell that allows code insertion regardless of your level of access.  Worse, it's been that way for 25 years!

Ok, so that's a problem but what's the solution?

It's actually pretty simple...

First you test, then you patch, then you test again.  I've provided some command line snippets you can use on your Red Hat or Debian based Linux distros.  The testing command is almost universal the patch commands are more system specific.  Regardless, you need to get this done ASAP as less than 24 hours after its discovery there were already active bots scanning the net looking to exploit the vulnerability.

The command snippets you need are below as well as a video showing the update process.  The following link had the most complete information I've found if you want to know more.

https://www.digitalocean.com/community/tutorials/how-to-protect-your-server-against-the-shellshock-bash-vulnerability

You've got what you need, now go to it!



()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()()

Testing command (at a shell prompt or terminal session)

env VAR='() { :;}; echo Bash is vulnerable!' bash -c "echo Bash Test"


Bash updates:

Debian/Ubuntu-

sudo apt-get update && sudo apt-get install --only-upgrade bash

CentOS/Red Hat

sudo yum update bash



Wednesday, August 20, 2014

Microsoft's Bloody Tuesday

Originally published on Kupeesh as Fear and Loathing of a Microsoft Patch



Poor Microsoft, it's been a tough couple of years for the software giant as it's gone through management upheavals, a failed operating system and a lackluster foray into the mobile market.

It seems they just can't catch a break...

That doesn't preclude them, however, from breaking things.

Case in point.  Last week's round of "Patch Tuesday" updates was filled to the brim with security and operating system fixes that millions of Windows PC's dutifully installed via automatic updates.

Normally keeping an operating system up to date is a good idea if you want to keep the bad guys out of your stuff.  But what do you do when the supposed good guys blow up your computer?

That's a question thousands of Windows users are asking as they now find themselves between the rock of Internet security threats and the hard place of a botched update.  

Even longtime Microsoft watchers like Paul Thurott (Windows Weekly, Winsupersite) can only answer with, "That's a tough one."

The patch causing so much trouble is a seemingly innocuous update to the Russian Ruble currency symbol in the windows font library (KB 2970228).  Apparently some users are experiencing everything from screwed up fonts to Blue Screens of Death (BSOD) after its installation.  As a workaround Microsoft is currently advising users to remove it and 3 other updates (KB2982791,KB2975719,KB2975331) that contain the offending code.  In addition, the download description pages for the affected update patches have had their download links removed while Microsoft, "investigates the issue."

Windows 7 and 8 are arguably the most robust operating systems Microsoft has ever produced.  So the return of the BSOD nemesis from the days of Windows XP is going to raise some eyebrows.  BSOD's only arise when a core operating system function has failed beyond recovery.  

That's something we thought we left behind when the house of cards that was Windows XP finally shuffled off the stage.  So with so much progress, how could Microsoft allow an obviously unvetted update to be distributed on platforms from Server 2003 to Windows 8.1.

Yes I know, Microsoft, unlike Apple, doesn't control every variant of hardware that runs their software.  But it's for exactly that reason that one would think their update policy would err on the side of caution.  That goes double in a week that also saw major outages of the company's Azure cloud services.

Instead Microsoft seems bent on releasing new products (patches included) like automakers release new cars.  But operating systems aren't Chevy's and rushing new products to market always leaves something to be desired.  Just ask GM about taking shortcuts in a process for proof.

So what's the answer when a strategy of "rapid release" seems to rule the day.  Unfortunately it's "Caveat Emptor," Buyer Beware.  Microsoft appears committed to shooting out software patches and asking questions later.  So for now, you may just want to switch those automatic updates to "manual" and wait a week after Patch Tuesday to install those non-critical updates.


In this case the cure was worse than the disease.

Thursday, January 16, 2014

Dealing with the latest Java Security update for your legacy apps

Java's gotten a bad rap lately and with good reason.  It's got so many security holes that it triggered an alert last year from Homeland Security.  Since then we've been getting pretty regular updates from the folks over at Oracle.

If you happen to administer networking equipment, especially Cisco branded devices, you've no doubt run into issues that come with Java updates.  If you have to manage different generations of networking equipment, for example, there's not doubt you have to maintain multiple versions of Java to manage them.

The latest Java security update for Java, 1.7.0_51, has finally made good on a threat.  It's activated functionality that effectively blocks any Java applet that doesn't have the "security manifest" parameters enabled.

That can leave you dead in the water.  Except, if you know how to work around it.  The video below shows you how to set an exclusion for trusted connections and applets.

Remember, this is only for connections and applets that you have complete trust in.