ie8 fix

tcp

TCP flaws puts Web sites at risk

Two researchers in Sweden have found multiple flaws in the TCP stack that could lead to massive denial-of-service attacks if exploited. At present there is no workaround and there are no patches available.

The TCP stack defines a set of rules by which a computer can communicate over any network. Robert E. Lee, chief security officer for Outpost24, told CNET News, "the vendors we are in talks with seem to be taking the threat seriously."

The discovery follows a test using a port scanner called UnicornScan, which Lee and senior security researcher Jack Louis created. The tool is … Read more

Exploit targets Microsoft's latest Windows patch

If you needed further proof that you should always patch Microsoft Windows when Microsoft tells you to do so, there's an exploit that will target Windows XP and Windows Vista systems lacking Microsoft's first patch of 2008.

Security firm Immunity has provided its customers a workable exploit of the TCP/IP (Transmission Control Protocol/Internet Protocol) vulnerability. This is standard practice for subscribers to see whether their system is vulnerable to an attack. However, the presence of an exploit (even one provided under contract) increases the likelihood that someone may offer it or something like it for free … Read more

Microsoft fixes three flaws with two patches; one is critical

Microsoft on Tuesday released its January 2008 security bulletin, which includes only two updates: One is designated as "critical" by the software giant and the second one is deemed "important". Both concern the Windows operating system. There are no Microsoft Office updates this month. All Microsoft security patches for Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS08-001: Critical

Titled "Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (941644)", this bulletin affects users of Microsoft Windows 2000, XP SP2, Server 2003, and Vista, and … Read more