ie8 fix

Consumer software and hardware

Microsoft patching zero-day Windows 7 SMB hole

Microsoft on Friday said it is working on a fix for a vulnerability in the Server Message Block file-sharing protocol in Windows 7 and Windows Server 2008 Release 2 that could be used to remotely crash a computer.

The software giant had said on Wednesday that it was looking at the bug, discovered by researcher Laurent Gaffié, who published proof-of-concept code on a blog.

"Microsoft is aware of public, detailed exploit code that would cause a system to stop functioning or become unreliable. If exploited, this [denial-of-service] vulnerability would not allow an attacker to take control of, or … Read more

Dolly Parton endorses IE 8 Web Slices

Here's a topic I never thought I'd write about: Dolly Parton, the famed country singer, has endorsed Internet Explorer 8 and its Web Slices feature on YouTube.

During a minute-long video, Parton says she "wouldn't know a gigabyte from a snake bite. But the folks over at Microsoft sure know their computers." She goes on to say Microsoft checked out her "new" Web site and "turned us on to a little thing they call Web Slices."

According to a Microsoft representative, the software giant showed Parton's Web team "the … Read more

Expert says Adobe Flash policy is risky

Updated 1:49 p.m. PST to clarify that Gmail issue was fixed and any attack would be theoretically possible but extremely difficult to accomplish.

A lax security policy in Adobe Flash puts visitors to user-generated content sites at risk, says a researcher who has found a technique exploiting the way browsers handle Flash files.

The problem stems from the origin policy of Adobe Flash, Mike Bailey, a senior security researcher at Foreground Security, said in an interview on Wednesday. "Adobe should change the way Flash Player handles the security policy so it doesn't allow arbitrary content to … Read more

Graphics showdown: 13 games for newer iPhones

Ever wondered what some of the graphical differences are in games that make use of the newer hardware in the latest versions of Apple's iPhone and iPod Touch? So were we. That's why we put together a screenshot comparison gallery of 13 games, all of which are either packing extra OpenGL ES 2.0 goodies, or that more complicated graphics modes that run a whole lot better on the beefier hardware spec.

As for our testing, we ran each title on an iPhone 3G and a third-generation iPod Touch, the latter of which packs the faster innards required … Read more

Microsoft probing Windows 7 zero-day hole

Microsoft said on Wednesday it is looking into a report of a vulnerability in Windows 7 and Server 2008 Release 2 that could be used by an attacker to remotely crash the computer.

The company is investigating claims of a "possible denial-of-service vulnerability in Windows Server Message Block (SMB)," the Microsoft spokesperson said, adding that the company was unaware of any attacks trying to exploit the hole.

The bug triggers an infinite loop on the Server Message Block (SMB) protocol used for sharing files in Windows, researcher Laurent Gaffié wrote in a posting on the Full-Disclosure mailing listRead more

Microsoft patches critical hole in Windows kernel

Microsoft on Tuesday issued six security bulletins fixing 15 vulnerabilities, including a critical patch for holes in the Windows kernel and other Windows and Office components that could allow an attacker to take control of a computer.

The critical bulletin affecting the Kernel-Mode Drivers was publicly disclosed and could be used to create a Web page with malware designed to exploit the hole on systems that visit the page, Microsoft said in a blog posting.

"MS09-065, a bug in the Windows kernel, is this month's most serious issue," said Andrew Storms, director of security operations at nCircle. &… Read more

Apple plugs holes for domain spoofing, other attacks

Apple on Monday released a large security update for Mac OS X that fixes dozens of vulnerabilities and provides protection against potential attacks exploiting a weakness in the protocol used to verify that a domain is legitimate.

There are 43 specific issues addressed in the 2009-006 update, released the same day as Mac OS X v.10.6.2.

It plugs a variety of holes for the Mac OS X v10.5.8, 10.6, 10.6.1, and Mac OS X Server v10.6 and 10.6.1, many of which could lead to arbitrary code execution and allow … Read more

Adobe's Photoshop app comes to Android

Adobe Systems on Friday introduced a new Photoshop app for Android users that lets them edit photos from their phone, as well as access their online photo collection on Photoshop.com.

The app comes just shy of a month after the release of the company's application for Apple iPhone and iPod Touch users, which quickly became the top free application in the App Store and grabbed a million downloads within a week of its release.

The version for Android shares the same, simple editing UI as the iPhone/iPod version, both of which let users make edits by sliding … Read more

Microsoft to fix holes in Windows, Office

Microsoft said on Thursday it will issue six patches next week for 15 vulnerabilities, including three critical bulletins affecting Windows and two important Office-related bulletins.

Affected software includes Windows 2000, XP, Server 2003, Vista, Server 2008, Office XP, Office 2003, 2007 Microsoft Office System, Office 2004 for Mac, and Office 2008 for Mac, the company said in an advisory.

November's Patch Tuesday is a contrast to the record number of fixes issued last month--13 bulletins for 34 vulnerabilities.

Updated 2:52 p.m. PST to correct that there will be six patches fixing 15 vulnerabilities.

Windows 7 sales outshine Vista

Judging by its initial sales, Windows 7 is certainly proving more popular than Vista.

Microsoft sold 234 percent more boxed editions of Windows 7 than it did Vista in the initial releases of both products, according to research released Thursday by NPD Group.

In actual dollars, Windows 7 has also been more successful than Vista. However, early discounts on pre-sales copies and a lack of a promotional boost behind Windows 7 Ultimate led to revenues only 82 percent greater than those of Vista.

"Ultimate was a much bigger part of what Microsoft did with Vista, whereas this time I … Read more