MY PROFILE | PRIVACY 
Vol. 14, #49 - Nov 23, 2009 - Issue #754
Read This Issue. Lots Of Good Stuff.

  1. Editor's Corner
    • Read This Issue. Lots Of Good Stuff.
    • "How's Your AV Behavin'" - Survey Results & Winners
    • Quotes Of The Week
  2. Admin Toolbox
    • Admin Tools We Think You Shouldn't Be Without
  3. Webinars & Seminars
    • VIPRE Enterprise Product Demonstration - 11/24
    • LIVE SEMINAR: Malware Protection without Impact to Production & System Performance, 12/3 in Alpharetta, Georgia.
    • VIPRE Email Security for Exchange Product Demonstration - 12/1
    • Kiss Your Antivirus Bloatware Goodbye: A Look at VIPRE Enterprise - 12/8
    • Affordable, Enterprise Email Archiving - 12/15
    • Podcast: Cloud Management Pricing And Licensing
  4. Tech Briefing
    • Cray Jaguar Takes Top Supercomputer Spot from IBM Roadrunner
    • Microsoft Testing Excel For Supercomputers
    • How Windows XP Mode Eliminates Compatibility Issues In Windows 7
    • How To Find And Remove Lingering Objects In Active Directory
    • Smartphones On Wi-Fi Vulnerable To Security Attack
    • Google Chrome OS: Rounding Up The Rumors
    • Microsoft Unveils Office 2010 Public Beta
  5. Windows Server News
    • The Best Free Virtualization Tools
    • Microsoft Touts Groundbreaking 'clip-on' For Active Directory
    • Top Five Sharepoint Challenges And Solutions
  6. Third Party News
    • A Reseller's Experience With VIPRE
    • This Week's List Of Multi-Platform Network Vulnerabilities
  7. WServerNews Fave Links
    • This Week's Links We Like. Tips, Hints And Fun Stuff.
  8. WServerNews - Product of the Week
    • Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!
Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!

The independent Tolly Group said in their September 2009 Anti-virus Performance Test Report: "Consumes up to 38% and 45% less memory, and offers up to 2.6x and 3.6x scanning speed compared to Symantec and McAfee." It's clearly time to kiss your antivirus bloatware goodbye. Sunbelt built VIPRE Enterprise; a completely new technology combining corporate antivirus plus an enterprise antispyware solution for total endpoint security designed by admins for admins. And that means EASY DEPLOYMENT. Click on the 'Request Info' tab and ask for a quote now:
http://www.wservernews.com/091123-VIPRE-Enterprise


Editor's Corner

Read This Issue. Lots Of Good Stuff.

When I saw the Table of Content this time, that was exactly the thought I had, "Wow, there is a lot of good stuff in this issue!" so that's why I took that as the title. Heads-up: next week we will skip the newsletter because of Thanksgiving, but on Thursday you will get a short issue with an exceptional Black Friday deal on VIPRE. When you see it, you'll immediately understand it's a no-brainer. It's a great opportunity to give the gift of security to friends and family. Have a great Turkey Day!

"How's Your AV Behavin'" - Survey Results & Winners

Here are the results of our antivirus survey last week. Thanks for answering! We got about 500 responses. We did some in-house slicing and dicing of the data. To start off, we removed VIPRE, and all other products except Symantec, McAfee, Trend, AVG and ESET (the top 5 after VIPRE was removed).

The responses are interesting. Here is the executive summary:
  • Among those 5, Symantec and Trend have the highest rate of infection (the most number of instances of infection in the past six months), followed by McAfee, AVG and ESET.
  • McAfee and Symantec have the highest level of admins disappointed with performance
  • The majority of admins (58.2%) stated that they were understaffed.
  • The majority of admins (56.6%) felt that the problem with Endpoint protection had gotten "worse".
If we add VIPRE to this list, (yes, I'm unashamedly tooting our own horn here) it shows that Sunbelt customers reported the best performance of their antivirus products, and lower rates of infection over the past six months than Symantec, McAfee, Trend or AVG.

If you want to see how your antivirus product stacked up against VIPRE or any of these other products, just shoot me an email.

Here are the 5 winners of the VIPRE Home Site License, they have received their License Key.

Joshua Mathews at americanpad
Mike Wirshup at Unisys
Jason Gurtz at Npumail
Vicky Spelshaus at Uwc.edu
Joe Tinney at Nevermind Designs

Quotes Of The Week

"We only have one future, and it will be made of our dreams, if only we have the courage to challenge convention." -- Soichiro Honda

"Only those who dare to fail greatly can ever achieve greatly." -- Robert Kennedy




Warm regards, and thank you for being a WServerNews subscriber. No trees were killed in the sending of this message, but a large number of electrons were terribly inconvenienced. Please tell your friends about us. They can subscribe here:
http://www.wservernews.com/091123-Subscribe

PS: Did you know this newsletter has a sister publication for XP users called WXPnews? You can subscribe here, and tell your friends:
http://www.wservernews.com/091123-WXPNews

PPS: And now we have our new Win7News! You can subscribe here, and tell your friends:
http://www.wservernews.com/091123-Win7News

Hope you enjoy this issue of WServerNews! Warm regards, Stu Sjouwerman  |   Email me: [email protected]

50% Discount On 1-Year Consulting License For Vulnerability Scanner

Your costumer's networks are open to attacks if they are not scanning for network vulnerabilities and patching them. Sunbelt Network Security Inspector (SNSI) helps you find the holes. The SNSI Consulting License Program is designed to assist you in delivering world-class professional services to customers. The Consulting License is for security consultants that travel to multiple sites for performing vulnerability assessments. Now through December 31st, Sunbelt is offering the SNSI Consulting License for $795 for a 1-year license subscription, a 50% discount off list price! Take advantage of this offer. Click to request your quote. Use the 'Request Walkthrough' tab:
http://www.wservernews.com/091123-SNSI
<

Admin Toolbox

Admin Tools We Think You Shouldn't Be Without

Let end-users reset their AD Passwords from the web, GINA and SharePoint. All the features you've been dreaming of and costs much less than the others: Extra 25% off now for all Sunbelt Newsletter readers and free eval:
http://www.wservernews.com/091123-Password-Reset

Unlock the power of log data with EventTracker. Improve operations & security. Free Trial!
http://www.wservernews.com/091123-EventTracker

Over 6.7 million desktops use Desktop Authority every day. Find out why. Download a 30 day trial for a chance to win $1,000!:
http://www.wservernews.com/091123-Desktop-Authority

Top 10 Windows tools for IT pros. No Windows geek or PC support pro should be without these must-have utilities -- they're all free, and deserve your consideration for a place in your PC support and diagnostics toolkit.
http://www.wservernews.com/091123-Windows-Tools


Webinars & Seminars

VIPRE Enterprise Product Demonstration - 11/24

Want total malware protection without the bloat? Join us for a look at VIPRE Enterprise and learn how Sunbelt started with a blank slate to design a new, next-generation antivirus and antispyware technology to deal with today's complex malware in the most comprehensive, highly efficient manner.

When: Tuesday, November 24, 2009, 11:00 AM (EDT) Please register here:
http://www.wservernews.com/091123-VIPRE-Demo


LIVE SEMINAR: Malware Protection without Impact to Production & System Performance, 12/3 in Alpharetta, Georgia.

Join Sunbelt Software and Mike Osterman, president and founder of Osterman Research, Inc. for an informative seminar that examines the current malware landscape and the economic and performance impact of malware infections on your organization. Learn why a new approach to malware protection is required to better protect your users and your data - all without the performance and resource headaches of many traditional enterprise antivirus products. Also see a live product demonstration of VIPRE Enterprise!

Thursday, December 3rd in Alpharetta, GA:
http://www.wservernews.com/091123-Protecting-Desktops


VIPRE Email Security for Exchange Product Demonstration - 12/1

Securing your Exchange Server is key to protecting your enterprise environment from spam, viruses, phishing, and other messaging threats. In this product demonstration, learn how the new version of VIPRE Email Security for Exchange (formerly Ninja Email Security) can help protect your network and cut your Exchange admin time in half with this powerful, policy-based email security product.

Tuesday, December 1, 2009, 2:00pm - 2:30pm EST
http://www.wservernews.com/091123-VIPRE-Email-Security


Kiss Your Antivirus Bloatware Goodbye: A Look at VIPRE Enterprise - 12/8

Want total malware protection without the bloat? Join us for a look at VIPRE Enterprise and learn how Sunbelt started with a blank slate to design a new, next-generation antivirus and antispyware technology to deal with today's complex malware in the most comprehensive, highly efficient manner.

Tuesday, December 8, 2009, 2:00pm - 3:00pm EST
http://www.wservernews.com/091123-Goodbye-Bloatware


Affordable, Enterprise Email Archiving - 12/15

Exchange performance is suffering. Your users complain about email storage and don't want any quotas. Your CEO requires legal compliance. Want a high-end, feature-rich, admin-friendly product that solves all these issues at a very affordable price? Then don't miss this Sunbelt Exchange Archiver? webinar.

Tuesday, December 15, 2009, 2:00pm - 3:00pm EST
http://www.wservernews.com/091123-Email-Archiving


Podcast: Cloud Management Pricing And Licensing

While managing and monitoring your cloud computing services is essential to securing data and maintaining performance levels, deciding which management provider to use is complicated. This expert podcast discusses the cost details and licensing structures associated with cloud management tools and software. Available now:
http://www.wservernews.com/091123-Cloud-Management


Tech Briefing

Cray Jaguar Takes Top Supercomputer Spot from IBM Roadrunner

After more than a year as the world's fastest supercomputer, IBM's Roadrunner system was knocked down to the second spot by Cray's Jaguar. Cray's XT5 system got a boost when the computer maker swapped out the quad-core AMD Opterons for the six-core "Istanbul" chips, ramping up the power to more than 224,256 AMD cores producing 1.75 petaflops under Linux: Sun and SGI also were represented in the top 10 of the Top500 list of the fastest systems. Story at eWEEK:
http://www.wservernews.com/091123-Supercomputer


Microsoft Testing Excel For Supercomputers

At a key supercomputing conference on Monday, Microsoft released a test version of its Excel spreadsheet redesigned to run on powerful clusters of servers. By engineering Excel to run better on such clusters, Microsoft said that customers are seeing spreadsheets that normally would take weeks to calculate now run in a few hours. The software maker also released a beta version of Windows HPC Server 2008 R2--the latest version of Windows Server designed to run in high-performance compute clusters.

Microsoft has taken the standard version of Excel 2010 and combined it with new Windows HPC Server 2008 R2 technology, allowing Excel to run on the cluster. The final version of Excel compute cluster and Win HPC Server 2008 R2 is expected to be ready in summer 2010. The capability has been in development for about 18 months. More at CNET:
http://www.wservernews.com/091123-Excel-for-Supercomputers


How Windows XP Mode Eliminates Compatibility Issues In Windows 7

Many IT managers are burdened with supporting old desktop operating systems and the hardware associated with them. While budgetary constraints sometimes prohibit the deployment of new, more often than not, older operating systems are kept in place because line-of-business applications function only on older OSes and hardware. In this expert tip, learn about Windows XP Mode, a new feature that virtually - and seamlessly - emulates Windows XP and its associated hardware on a Windows 7 PC: (Email Registration Required)
http://www.wservernews.com/091123-XP-Mode


How To Find And Remove Lingering Objects In Active Directory

Some of the biggest annoyances for any Active Directory administrator are odd little things called lingering objects. These have existed since Windows 2000 Server and will probably never go away completely, although Microsoft has worked to give us some great tools to get rid of them and protect our domain controllers. Learn how to troubleshoot the issue with a little AD housecleaning: (Email Registration Required)
http://www.wservernews.com/091123-Lingering-Objects


Smartphones On Wi-Fi Vulnerable To Security Attack

A new report from a mobile security vendor details how the most popular smartphones, including the iPhone, are vulnerable to man-in-the-middle attacks, carried out via public Wi-Fi connections. The plethora of new smartphone users means the potential for online bad guys wanting to crack smartphone security measures is drastically increasing. Compromised smartphones could be used in the future to target and bring down wireless carrier's cellular networks via DDoS attacks. More:
http://www.wservernews.com/091123-WIFI-Smartphones


Google Chrome OS: Rounding Up The Rumors

Google is expected to preview the Chrome OS on Thursday. It's been a few months since Google fired a shot across Microsoft's bow, when they announced their Linux-based OS. The Web-centric OS targets the always-connected, and will integrate OS and Browser. Or so they tell us. Google's focus has been on providing a speedy, simple, heavily web-oriented and secure OS that likely will lean heavily on cloud computing.

Lots of speculation has been going around about this lightweight, open-source OS aimed mainly at netbooks. Some of the facts:
  • Expected to arrive in the second half of 2010,
  • Will run on higher-end PCs as well
  • Acer, Asus, Hewlett Packard, Lenovo and Intel are in on the act
  • Will run on x86 and ARM processors, and all of Chrome's Web Apps will work not only on the new OS but also on any standards-based browser.
Easy for developers: create one single app and it works Chrome OS, Mac, Windows, or other Linux flavors. Google released it to open source for developers, but said end users will not be able to use the Web OS until late 2010. During a demo, Google's Sundar Pichai showed how Chrome OS booted up on an Asus Eee PC netbook in 7 seconds, with 3 more seconds to log onto an app.

Chrome OS has the look and feel of the Chrome Web browser, which has 40 million regular users. Google said its reference architecture, whose components are still apparently being spec'd, won't support hard drives, only solid-state memory, (which explains the fast boot times) and will demand a somewhat larger form factor than today's notebooks to provide for a full-sized keyboard and touchpad. Its connectivity will be Wi-Fi. More at:
http://www.wservernews.com/091123-Chrome-OS


Microsoft Unveils Office 2010 Public Beta

Computerworld reported that Microsoft launched its first public beta of Office 2010, posting the preview for download on its Web site. The download is for Office Professional Plus 2010, a feature-laden edition that will be available only to enterprises and organizations that purchase licenses in volume when the final suite ships next year. Office Professional Plus includes Word, Excel, Outlook, PowerPoint, OneNote, Access, Publisher, InfoPath, SharePoint Workspace -- formerly called Groove -- and Communicator.

The 32-bit version of the English-language suite runs 685MB, while the 64-bit edition tips the scales at 750MB. Users who download Office 2010 Beta are provided with a 25-character product key to activate the preview. As a defensive surprise, something called Outlook Social Connector has been added to Office 2010 to display feeds from social networking sites in Outlook starting with LinkedIn. Users won't have to abandon Outlook to (social) network:
http://www.wservernews.com/091123-Office-2010-Beta


Windows Server News

The Best Free Virtualization Tools

While it's easy to find free virtualization products, it's difficult to find solid, free virtualization software that isn't just "demoware." To help sort the wheat from the chaff on free VMware virtualization tools, this guide explores the best tools and their capabilities and provides additional reviews of some of the top freeware: (Email Registration Required)
http://www.wservernews.com/091123-Virtualization-Tools


Microsoft Touts Groundbreaking 'clip-on' For Active Directory

This week, at the Professional Developers Conference, Microsoft will pass out beta code week it hopes will define the next evolution of directories. The code is so early-stage it does not have an official name, although internally Microsoft calls it Next Generation Active Directory (NGAD).

They hope the beta code will define the next evolution of directories. It's a modular add-on that is built on a database and designed to add querying capabilities and performance never before possible in a directory.

NGAD is not a replacement for Active Directory but a "clip-on" that provides developers a single programming API for building access controls into apps that can run either internally, on devices, or on Microsoft's Azure cloud operating system. Get the whole story at InfoWorld:
http://www.wservernews.com/091123-ActiveDirectory-Clip-on


Top Five Sharepoint Challenges And Solutions

Having some issues with SharePoint? It happens. This issue of the expert SharePoint E-Zine describes some of SharePoint's most common problems and provides the fixes to solve them. Plus, get some pointers on how to manage external data access as part of your governance plan, and weigh the pros and cons of SharePoint social computing: (Registration Required)
http://www.wservernews.com/091123-SharePoint-Challenges


Third Party News

A Reseller's Experience With VIPRE

Joe DePucci sent us this: "Just wanted to let you know that I've recently become a VIPRE software reseller. I really don't sell anything I do not believe in or have tested. So, I have a nice story that has made me a believer.

I've recently repaired a laptop that was infected with oh, I'd say about 15 varieties of the trojan downloader. I was not able to boot up in safe mode (BSOD) so had to boot up in normal mode. Well if you have any experience in removing viruses/malware/spyware you would know that system restore did not work, nor was I able to gain control of the desktop, could not install any removal tools, etc.

I pulled the drive and connected it via a USB-2 adapter cable it to my recently purchased windows 7 premium laptop with VIPRE. I ran a scan on that drive and BAM- one trojan after another was quarantined. I simply went to the manage screen and deleted the threats. When the scan was complete I installed drive and was able to finish the job with some other utilities and tools which are just a personal preference. Without VIPRE I do not believe I would of been able to repair the laptop without reloading it.

I am also a firm believer that Norton and McAfee Internet security suites have a leak, as every system I've had to repair has had either/or installed on them. Additionally I do like the low overhead and simplicity of the GUI of VIPRE. -- Thanks, Joe DePucci

This Week's List Of Multi-Platform Network Vulnerabilities

SNSI uses the latest Mitre Common Vulnerabilities and Exposures (CVE) list of computer incidents. It also contains the latest SANS/FBI top 20 vulnerability list. SNSI also uses the latest CERT, CIAC Microsoft and FedCIRC (Department of Homeland Security) advisories.

New Checks:
S11 Virtual Desktop Infrastructure may make insecure LDAP connections - Solaris  
S154 Kernel patch induced hang - Solaris 8 - 9  
H80 Sun Java JRE Multiple Vulnerabilities - HP-UX 11  
H84 OpenView Network Node Manager Vulnerability - HP-UX 11  
L122 Libvorbis runtime libraries Ogg file format error - RHE  
L123 Silc-toolkit multple format string & encode.c vulnerabilities - SuSE  
L124 Open-iscsi discovery predictable name flaw - SuSE  
L125 Openswan asn1_length function X.509 handling error - SuSE  
L126 Mutt embedded NUL character handling X.509 error - SuSE  
L127 OpenLDAP embedded NUL character handling X.509 error - SuSE  
L128 Cyrus-imapd SIEVE script crafting weakness - SuSE  
L129 Java-1.6.0-openjdk multiple vulnerabilities Aug 2009 - SuSE  
L130 Postgresql multiple access violation errors - SuSE  
L131 Java-1.4.2 malformed XML & CPU consumption errors - SuSE  
L132 Wireshark OpCUA dissector memory consumption error - SuSE  
L133 FreeRadius attribute validation vulnerability - SuSE  
L134 Dovecot SIEVE script crafting weakness - SuSE  
L135 PHP dba_replace/openssl_apply/& exif_read_data errors - SuSE  
L136 Newt textbox.c dialog box request weakness - SuSE  
L137 Rubygem-activepack escape code in form helpers error - SuSE  
L138 Rubygem-actionsupport escape code in form helpers error - SuSE  
L139 Samba share restriction bypass & oplock break errors - SuSE  
L140 PhpMyAdmin PDF schema flaw & MySQL crafted name error - SuSE  
L141 ViewVC view parameter & illegal printing of names/values flaws- SuSE  
L142 Cyrus-imapd SIEVE script crafting weakness - SuSE  
L143 Neon \0 character & recursion during entity expansion flaws - CentOS  
L144 Apache2-mod_jk HTTP arbitrary request weakness - SuSE  
L145 Expat update position function flaw - SuSE  
L146 XPDF multiple integer overflow errors Nov 2009 - SuSE  
L147 NSPR floating point conversion update Nov 2009 - SuSE  
L148 IBM Java 6 Service Release 6 security update - SuSE  
L149 Apache multiple vulnerabilities Sept 2009 - MDV  
L150 Firefox multiple security update Nov 2009 - SuSE  
L151 Wireshark dissector NULL pointer dereference error - MDV  
L152 SquidGuard sgLog.c long URL with many slashes weakness- MDV  
L153 Firefox/XulRunner/NSPR multiple security update Nov 2009 - MDV  
L154 Apache SSL/TLS renegotiation handshake flaw- MDV  
L155 GIMP ReadImage weakness via BMP width/height values - MDV  
L156 FFmpeg lavf demuxer GIF file & signedness in fourxm flaw- MDV  
L157 Xine qt_error parse & 4xm movie file demuxer errors - MDV  
L158 Apache-conf HTTP TRACE per default flaw - MDV  
L159 Wget NULL character handling in X.509 certificates - RHE  
L160 Kernel swiotlb jumbo frames & other flaws - RHE  
M11 Safari WebKit/ColorSync/XML Vulnerabilities  
M25 MS Office 2004 Word/Excel Multiple Vulnerabilities - Mac OS X  
M26 MS Office 2008 Word Excel Multiple Vulnerabilities - Mac OS X  
M27 MS Office Open XML Format Converter Multiple Vulnerabilities - Mac OS X  
S10 VirtualBox Guest Additions Vulnerability  
S132 Pidgin/Gaim OSCAR/MSN Libpurple Vulnerabilities - Solsris 10  
S179 CUPS Web Interface Vulnerabilities - OpenSolaris  
S221 TCP Sockets Vulnerability - OpenSolaris  
S238 Emulex Driver Regression - Solaris 10/OpenSolaris  
W1979 Google Chrome Same Origin Bypass vulnerability  
W2878 Citrix Online Plugin SSL/TLS Vulnerability  
W3120 Apple Safari WebKit/XML/ColorSync Vulnerabilities - XP/W2K3/Vista/W2K8  
W3131 GIMP BMP and PSD file load Plug-in vulnerability  
 
Updated Checks S92 SSHd may incorrectly represent AES192/AES256 - Solaris 10 S337 Kernel / SCSI tape drives may induce panic - Solaris 9 W1142 Anti-virus signature outdated - McAfee W1986 Anti-virus signature outdated - Symantec W1999 Anti-virus signature outdated - Trend Micro W2067 Anti-virus signature outdated - F-Secure W2070 Anti-virus signature outdated - CA eTrust W3696 Windows TCP/IP stack errors - W2K/XP M76 ClamXav / ClamAV signatures not the latest - Mac OS X M80 Virex signature file out of date - Mac OS X S33 ClamAV signatures not updated - Solaris S54 Libpng image file handling vulnerability - Solaris 8 - 10 S351 Kernel IP/STREAMS memory management issues - Solaris 7 ^10 W2012 Anti-virus signature outdated - Avast! 4 W2013 Anti-virus signature outdated - AVG 8 - W2K/XP/W2K3 W2056 Anti-virus signature outdated - Norman
Sunbelt Network Security Inspector version 2.0.2670.0 Definition Set 205 was released November 20, 2009. Sunbelt Software recommends you download the new SNSI Vulnerability Update Definitions 205, scan, and patch your machines today. To get the latest SNSI version, visit:
http://www.wservernews.com/091123-SNSI


WServerNews Fave Links

This Week's Links We Like. Tips, Hints And Fun Stuff.



WServerNews - Product of the Week

Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!

The independent Tolly Group said in their September 2009 Anti-virus Performance Test Report: "Consumes up to 38% and 45% less memory, and offers up to 2.6x and 3.6x scanning speed compared to Symantec and McAfee." It's clearly time to kiss your antivirus bloatware goodbye. Sunbelt built VIPRE Enterprise; a completely new technology combining corporate antivirus plus an enterprise antispyware solution for total endpoint security designed by admins for admins. And that means EASY DEPLOYMENT. Click on the 'Request Info' tab and ask for a quote now:
http://www.wservernews.com/091123-VIPRE