Vol. 14, #49 - Nov 23, 2009 - Issue #754
|
Read This Issue. Lots Of Good Stuff.
|
- Editor's Corner
- Read This Issue. Lots Of Good Stuff.
- "How's Your AV Behavin'" - Survey Results & Winners
- Quotes Of The Week
- Admin Toolbox
- Admin Tools We Think You Shouldn't Be Without
- Webinars & Seminars
- VIPRE Enterprise Product Demonstration - 11/24
- LIVE SEMINAR: Malware Protection without Impact to Production &
System Performance, 12/3 in Alpharetta, Georgia.
- VIPRE Email Security for Exchange Product Demonstration - 12/1
- Kiss Your Antivirus Bloatware Goodbye: A Look at VIPRE Enterprise - 12/8
- Affordable, Enterprise Email Archiving - 12/15
- Podcast: Cloud Management Pricing And Licensing
- Tech Briefing
- Cray Jaguar Takes Top Supercomputer Spot from IBM Roadrunner
- Microsoft Testing Excel For Supercomputers
- How Windows XP Mode Eliminates Compatibility Issues In Windows 7
- How To Find And Remove Lingering Objects In Active Directory
- Smartphones On Wi-Fi Vulnerable To Security Attack
- Google Chrome OS: Rounding Up The Rumors
- Microsoft Unveils Office 2010 Public Beta
- Windows Server News
- The Best Free Virtualization Tools
- Microsoft Touts Groundbreaking 'clip-on' For Active Directory
- Top Five Sharepoint Challenges And Solutions
- Third Party News
- A Reseller's Experience With VIPRE
- This Week's List Of Multi-Platform Network Vulnerabilities
- WServerNews Fave Links
- This Week's Links We Like. Tips, Hints And Fun Stuff.
- WServerNews - Product of the Week
- Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!
|
|
Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!
The independent Tolly Group said in their September 2009 Anti-virus Performance
Test Report: "Consumes up to 38% and 45% less memory, and offers up to 2.6x and
3.6x scanning speed compared to Symantec and McAfee." It's clearly time to kiss
your antivirus bloatware goodbye. Sunbelt built VIPRE Enterprise; a completely
new technology combining corporate antivirus plus an enterprise antispyware
solution for total endpoint security designed by admins for admins. And that
means EASY DEPLOYMENT. Click on the 'Request Info' tab and ask for a quote now:
http://www.wservernews.com/091123-VIPRE-Enterprise
|
|
 |
Editor's Corner |
|
Read This Issue. Lots Of Good Stuff.
When I saw the Table of Content this time, that was exactly the thought I had,
"Wow, there is a lot of good stuff in this issue!" so that's why I took that
as the title. Heads-up: next week we will skip the newsletter because of
Thanksgiving, but on Thursday you will get a short issue with an exceptional
Black Friday deal on VIPRE. When you see it, you'll immediately understand
it's a no-brainer. It's a great opportunity to give the gift of security
to friends and family. Have a great Turkey Day!
"How's Your AV Behavin'" - Survey Results & Winners
Here are the results of our antivirus survey last week. Thanks for answering!
We got about 500 responses. We did some in-house slicing and dicing of the
data. To start off, we removed VIPRE, and all other products except Symantec,
McAfee, Trend, AVG and ESET (the top 5 after VIPRE was removed).
The responses are interesting. Here is the executive summary:
- Among those 5, Symantec and Trend have the highest rate of infection (the
most number of instances of infection in the past six months), followed by
McAfee, AVG and ESET.
- McAfee and Symantec have the highest level of admins disappointed
with performance
- The majority of admins (58.2%) stated that they were understaffed.
- The majority of admins (56.6%) felt that the problem with Endpoint
protection had gotten "worse".
If we add VIPRE to this list, (yes, I'm unashamedly tooting our own horn here)
it shows that Sunbelt customers reported the best performance of their
antivirus products, and lower rates of infection over the past six months
than Symantec, McAfee, Trend or AVG.
If you want to see how your antivirus product stacked up against VIPRE or
any of these other products, just shoot me an email.
Here are the 5 winners of the VIPRE Home Site License, they have received
their License Key.
Joshua Mathews at americanpad
Mike Wirshup at Unisys
Jason Gurtz at Npumail
Vicky Spelshaus at Uwc.edu
Joe Tinney at Nevermind Designs
Quotes Of The Week
"We only have one future, and it will be made of our dreams, if only we have
the courage to challenge convention." -- Soichiro Honda
"Only those who dare to fail greatly can ever achieve greatly."
-- Robert Kennedy
Warm regards, and thank you for being a WServerNews subscriber. No trees
were killed in the sending of this message, but a large number of electrons
were terribly inconvenienced. Please tell your friends about us.
They can subscribe here:
http://www.wservernews.com/091123-Subscribe
PS: Did you know this newsletter has a sister publication for XP users
called WXPnews? You can subscribe here, and tell your friends:
http://www.wservernews.com/091123-WXPNews
PPS: And now we have our new Win7News! You can subscribe here, and tell
your friends:
http://www.wservernews.com/091123-Win7News
|
|
50% Discount On 1-Year Consulting License For Vulnerability Scanner
Your costumer's networks are open to attacks if they are not scanning for
network vulnerabilities and patching them. Sunbelt Network Security Inspector
(SNSI) helps you find the holes. The SNSI Consulting License Program is
designed to assist you in delivering world-class professional services to
customers. The Consulting License is for security consultants that travel
to multiple sites for performing vulnerability assessments. Now through
December 31st, Sunbelt is offering the SNSI Consulting License for $795 for
a 1-year license subscription, a 50% discount off list price! Take advantage
of this offer. Click to request your quote. Use the 'Request Walkthrough' tab:
http://www.wservernews.com/091123-SNSI
|
|
<
 |
Webinars & Seminars |
|
VIPRE Enterprise Product Demonstration - 11/24
Want total malware protection without the bloat? Join us for a look at VIPRE
Enterprise and learn how Sunbelt started with a blank slate to design a new,
next-generation antivirus and antispyware technology to deal with today's
complex malware in the most comprehensive, highly efficient manner.
When: Tuesday, November 24, 2009, 11:00 AM (EDT) Please register here:
http://www.wservernews.com/091123-VIPRE-Demo
LIVE SEMINAR: Malware Protection without Impact to Production &
System Performance, 12/3 in Alpharetta, Georgia.
Join Sunbelt Software and Mike Osterman, president and founder of Osterman
Research, Inc. for an informative seminar that examines the current malware
landscape and the economic and performance impact of malware infections on
your organization. Learn why a new approach to malware protection is required
to better protect your users and your data - all without the performance and
resource headaches of many traditional enterprise antivirus products. Also
see a live product demonstration of VIPRE Enterprise!
Thursday, December 3rd in Alpharetta, GA:
http://www.wservernews.com/091123-Protecting-Desktops
VIPRE Email Security for Exchange Product Demonstration - 12/1
Securing your Exchange Server is key to protecting your enterprise environment
from spam, viruses, phishing, and other messaging threats. In this product
demonstration, learn how the new version of VIPRE Email Security for Exchange
(formerly Ninja Email Security) can help protect your network and cut your
Exchange admin time in half with this powerful, policy-based email security
product.
Tuesday, December 1, 2009, 2:00pm - 2:30pm EST
http://www.wservernews.com/091123-VIPRE-Email-Security
Kiss Your Antivirus Bloatware Goodbye: A Look at VIPRE Enterprise - 12/8
Want total malware protection without the bloat? Join us for a look at VIPRE
Enterprise and learn how Sunbelt started with a blank slate to design a new,
next-generation antivirus and antispyware technology to deal with today's
complex malware in the most comprehensive, highly efficient manner.
Tuesday, December 8, 2009, 2:00pm - 3:00pm EST
http://www.wservernews.com/091123-Goodbye-Bloatware
Affordable, Enterprise Email Archiving - 12/15
Exchange performance is suffering. Your users complain about email storage
and don't want any quotas. Your CEO requires legal compliance. Want a high-end,
feature-rich, admin-friendly product that solves all these issues at a very
affordable price? Then don't miss this Sunbelt Exchange Archiver? webinar.
Tuesday, December 15, 2009, 2:00pm - 3:00pm EST
http://www.wservernews.com/091123-Email-Archiving
Podcast: Cloud Management Pricing And Licensing
While managing and monitoring your cloud computing services is essential to
securing data and maintaining performance levels, deciding which management
provider to use is complicated. This expert podcast discusses the cost
details and licensing structures associated with cloud management tools
and software. Available now:
http://www.wservernews.com/091123-Cloud-Management
|
 |
Tech Briefing |
|
Cray Jaguar Takes Top Supercomputer Spot from IBM Roadrunner
After more than a year as the world's fastest supercomputer, IBM's
Roadrunner system was knocked down to the second spot by Cray's Jaguar.
Cray's XT5 system got a boost when the computer maker swapped out the
quad-core AMD Opterons for the six-core "Istanbul" chips, ramping up the
power to more than 224,256 AMD cores producing 1.75 petaflops under Linux:
Sun and SGI also were represented in the top 10 of the Top500 list of
the fastest systems. Story at eWEEK:
http://www.wservernews.com/091123-Supercomputer
Microsoft Testing Excel For Supercomputers
At a key supercomputing conference on Monday, Microsoft released a test
version of its Excel spreadsheet redesigned to run on powerful clusters
of servers. By engineering Excel to run better on such clusters, Microsoft
said that customers are seeing spreadsheets that normally would take weeks
to calculate now run in a few hours. The software maker also released a
beta version of Windows HPC Server 2008 R2--the latest version of Windows
Server designed to run in high-performance compute clusters.
Microsoft has taken the standard version of Excel 2010 and combined it
with new Windows HPC Server 2008 R2 technology, allowing Excel to run on
the cluster. The final version of Excel compute cluster and Win HPC Server
2008 R2 is expected to be ready in summer 2010. The capability has been
in development for about 18 months. More at CNET:
http://www.wservernews.com/091123-Excel-for-Supercomputers
How Windows XP Mode Eliminates Compatibility Issues In Windows 7
Many IT managers are burdened with supporting old desktop operating systems
and the hardware associated with them. While budgetary constraints sometimes
prohibit the deployment of new, more often than not, older operating systems
are kept in place because line-of-business applications function only on
older OSes and hardware. In this expert tip, learn about Windows XP Mode,
a new feature that virtually - and seamlessly - emulates Windows XP and
its associated hardware on a Windows 7 PC: (Email Registration Required)
http://www.wservernews.com/091123-XP-Mode
How To Find And Remove Lingering Objects In Active Directory
Some of the biggest annoyances for any Active Directory administrator are
odd little things called lingering objects. These have existed since Windows
2000 Server and will probably never go away completely, although Microsoft
has worked to give us some great tools to get rid of them and protect our
domain controllers. Learn how to troubleshoot the issue with a little AD
housecleaning: (Email Registration Required)
http://www.wservernews.com/091123-Lingering-Objects
Smartphones On Wi-Fi Vulnerable To Security Attack
A new report from a mobile security vendor details how the most popular
smartphones, including the iPhone, are vulnerable to man-in-the-middle attacks,
carried out via public Wi-Fi connections. The plethora of new smartphone
users means the potential for online bad guys wanting to crack smartphone
security measures is drastically increasing. Compromised smartphones could
be used in the future to target and bring down wireless carrier's cellular
networks via DDoS attacks. More:
http://www.wservernews.com/091123-WIFI-Smartphones
Google Chrome OS: Rounding Up The Rumors
Google is expected to preview the Chrome OS on Thursday. It's been a few
months since Google fired a shot across Microsoft's bow, when they
announced their Linux-based OS. The Web-centric OS targets the always-connected,
and will integrate OS and Browser. Or so they tell us.
Google's focus has been on providing a speedy, simple, heavily web-oriented
and secure OS that likely will lean heavily on cloud computing.
Lots of speculation has been going around about this lightweight,
open-source OS aimed mainly at netbooks. Some of the facts:
- Expected to arrive in the second half of 2010,
- Will run on higher-end PCs as well
- Acer, Asus, Hewlett Packard, Lenovo and Intel are in on the act
- Will run on x86 and ARM processors, and all of Chrome's Web Apps
will work not only on the new OS but also on any standards-based browser.
Easy for developers: create one single app and it works Chrome OS, Mac,
Windows, or other Linux flavors. Google released it to open source for
developers, but said end users will not be able to use the Web OS
until late 2010. During a demo, Google's Sundar Pichai showed how Chrome
OS booted up on an Asus Eee PC netbook in 7 seconds, with 3 more seconds
to log onto an app.
Chrome OS has the look and feel of the Chrome Web browser, which has 40
million regular users. Google said its reference architecture, whose
components are still apparently being spec'd, won't support hard drives,
only solid-state memory, (which explains the fast boot times) and will
demand a somewhat larger form factor than today's notebooks to provide
for a full-sized keyboard and touchpad. Its connectivity will be Wi-Fi.
More at:
http://www.wservernews.com/091123-Chrome-OS
Microsoft Unveils Office 2010 Public Beta
Computerworld reported that Microsoft launched its first public beta of
Office 2010, posting the preview for download on its Web site. The download
is for Office Professional Plus 2010, a feature-laden edition that will be
available only to enterprises and organizations that purchase licenses in
volume when the final suite ships next year. Office Professional Plus
includes Word, Excel, Outlook, PowerPoint, OneNote, Access, Publisher,
InfoPath, SharePoint Workspace -- formerly called Groove -- and Communicator.
The 32-bit version of the English-language suite runs 685MB, while the
64-bit edition tips the scales at 750MB. Users who download Office 2010
Beta are provided with a 25-character product key to activate the preview.
As a defensive surprise, something called Outlook Social Connector has
been added to Office 2010 to display feeds from social networking sites
in Outlook starting with LinkedIn. Users won't have to abandon Outlook
to (social) network:
http://www.wservernews.com/091123-Office-2010-Beta
|
 |
Windows Server News |
|
The Best Free Virtualization Tools
While it's easy to find free virtualization products, it's difficult to find
solid, free virtualization software that isn't just "demoware." To help sort
the wheat from the chaff on free VMware virtualization tools, this guide
explores the best tools and their capabilities and provides additional
reviews of some of the top freeware: (Email Registration Required)
http://www.wservernews.com/091123-Virtualization-Tools
Microsoft Touts Groundbreaking 'clip-on' For Active Directory
This week, at the Professional Developers Conference, Microsoft will pass
out beta code week it hopes will define the next evolution of directories.
The code is so early-stage it does not have an official name, although
internally Microsoft calls it Next Generation Active Directory (NGAD).
They hope the beta code will define the next evolution of directories. It's
a modular add-on that is built on a database and designed to add querying
capabilities and performance never before possible in a directory.
NGAD is not a replacement for Active Directory but a "clip-on" that provides
developers a single programming API for building access controls into apps
that can run either internally, on devices, or on Microsoft's Azure cloud
operating system. Get the whole story at InfoWorld:
http://www.wservernews.com/091123-ActiveDirectory-Clip-on
Top Five Sharepoint Challenges And Solutions
Having some issues with SharePoint? It happens. This issue of the expert
SharePoint E-Zine describes some of SharePoint's most common problems and
provides the fixes to solve them. Plus, get some pointers on how to manage
external data access as part of your governance plan, and weigh the pros
and cons of SharePoint social computing: (Registration Required)
http://www.wservernews.com/091123-SharePoint-Challenges
|
 |
Third Party News |
|
A Reseller's Experience With VIPRE
Joe DePucci sent us this: "Just wanted to let you know that I've recently
become a VIPRE software reseller. I really don't sell anything I do not
believe in or have tested. So, I have a nice story that has made me
a believer.
I've recently repaired a laptop that was infected with oh, I'd say about
15 varieties of the trojan downloader. I was not able to boot up in safe
mode (BSOD) so had to boot up in normal mode. Well if you have any
experience in removing viruses/malware/spyware you would know that
system restore did not work, nor was I able to gain control of the
desktop, could not install any removal tools, etc.
I pulled the drive and connected it via a USB-2 adapter cable it to my
recently purchased windows 7 premium laptop with VIPRE. I ran a scan on
that drive and BAM- one trojan after another was quarantined. I simply
went to the manage screen and deleted the threats. When the scan was
complete I installed drive and was able to finish the job with some
other utilities and tools which are just a personal preference. Without
VIPRE I do not believe I would of been able to repair the laptop without
reloading it.
I am also a firm believer that Norton and McAfee Internet security suites
have a leak, as every system I've had to repair has had either/or installed
on them. Additionally I do like the low overhead and simplicity of the GUI
of VIPRE. -- Thanks, Joe DePucci
This Week's List Of Multi-Platform Network Vulnerabilities
SNSI uses the latest Mitre Common Vulnerabilities and Exposures (CVE)
list of computer incidents. It also contains the latest SANS/FBI top 20
vulnerability list. SNSI also uses the latest CERT, CIAC Microsoft and
FedCIRC (Department of Homeland Security) advisories.
New Checks:
S11 Virtual Desktop Infrastructure may make insecure LDAP connections - Solaris
S154 Kernel patch induced hang - Solaris 8 - 9
H80 Sun Java JRE Multiple Vulnerabilities - HP-UX 11
H84 OpenView Network Node Manager Vulnerability - HP-UX 11
L122 Libvorbis runtime libraries Ogg file format error - RHE
L123 Silc-toolkit multple format string & encode.c vulnerabilities - SuSE
L124 Open-iscsi discovery predictable name flaw - SuSE
L125 Openswan asn1_length function X.509 handling error - SuSE
L126 Mutt embedded NUL character handling X.509 error - SuSE
L127 OpenLDAP embedded NUL character handling X.509 error - SuSE
L128 Cyrus-imapd SIEVE script crafting weakness - SuSE
L129 Java-1.6.0-openjdk multiple vulnerabilities Aug 2009 - SuSE
L130 Postgresql multiple access violation errors - SuSE
L131 Java-1.4.2 malformed XML & CPU consumption errors - SuSE
L132 Wireshark OpCUA dissector memory consumption error - SuSE
L133 FreeRadius attribute validation vulnerability - SuSE
L134 Dovecot SIEVE script crafting weakness - SuSE
L135 PHP dba_replace/openssl_apply/& exif_read_data errors - SuSE
L136 Newt textbox.c dialog box request weakness - SuSE
L137 Rubygem-activepack escape code in form helpers error - SuSE
L138 Rubygem-actionsupport escape code in form helpers error - SuSE
L139 Samba share restriction bypass & oplock break errors - SuSE
L140 PhpMyAdmin PDF schema flaw & MySQL crafted name error - SuSE
L141 ViewVC view parameter & illegal printing of names/values flaws- SuSE
L142 Cyrus-imapd SIEVE script crafting weakness - SuSE
L143 Neon \0 character & recursion during entity expansion flaws - CentOS
L144 Apache2-mod_jk HTTP arbitrary request weakness - SuSE
L145 Expat update position function flaw - SuSE
L146 XPDF multiple integer overflow errors Nov 2009 - SuSE
L147 NSPR floating point conversion update Nov 2009 - SuSE
L148 IBM Java 6 Service Release 6 security update - SuSE
L149 Apache multiple vulnerabilities Sept 2009 - MDV
L150 Firefox multiple security update Nov 2009 - SuSE
L151 Wireshark dissector NULL pointer dereference error - MDV
L152 SquidGuard sgLog.c long URL with many slashes weakness- MDV
L153 Firefox/XulRunner/NSPR multiple security update Nov 2009 - MDV
L154 Apache SSL/TLS renegotiation handshake flaw- MDV
L155 GIMP ReadImage weakness via BMP width/height values - MDV
L156 FFmpeg lavf demuxer GIF file & signedness in fourxm flaw- MDV
L157 Xine qt_error parse & 4xm movie file demuxer errors - MDV
L158 Apache-conf HTTP TRACE per default flaw - MDV
L159 Wget NULL character handling in X.509 certificates - RHE
L160 Kernel swiotlb jumbo frames & other flaws - RHE
M11 Safari WebKit/ColorSync/XML Vulnerabilities
M25 MS Office 2004 Word/Excel Multiple Vulnerabilities - Mac OS X
M26 MS Office 2008 Word Excel Multiple Vulnerabilities - Mac OS X
M27 MS Office Open XML Format Converter Multiple Vulnerabilities - Mac OS X
S10 VirtualBox Guest Additions Vulnerability
S132 Pidgin/Gaim OSCAR/MSN Libpurple Vulnerabilities - Solsris 10
S179 CUPS Web Interface Vulnerabilities - OpenSolaris
S221 TCP Sockets Vulnerability - OpenSolaris
S238 Emulex Driver Regression - Solaris 10/OpenSolaris
W1979 Google Chrome Same Origin Bypass vulnerability
W2878 Citrix Online Plugin SSL/TLS Vulnerability
W3120 Apple Safari WebKit/XML/ColorSync Vulnerabilities - XP/W2K3/Vista/W2K8
W3131 GIMP BMP and PSD file load Plug-in vulnerability
Updated Checks
S92 SSHd may incorrectly represent AES192/AES256 - Solaris 10
S337 Kernel / SCSI tape drives may induce panic - Solaris 9
W1142 Anti-virus signature outdated - McAfee
W1986 Anti-virus signature outdated - Symantec
W1999 Anti-virus signature outdated - Trend Micro
W2067 Anti-virus signature outdated - F-Secure
W2070 Anti-virus signature outdated - CA eTrust
W3696 Windows TCP/IP stack errors - W2K/XP
M76 ClamXav / ClamAV signatures not the latest - Mac OS X
M80 Virex signature file out of date - Mac OS X
S33 ClamAV signatures not updated - Solaris
S54 Libpng image file handling vulnerability - Solaris 8 - 10
S351 Kernel IP/STREAMS memory management issues - Solaris 7 ^10
W2012 Anti-virus signature outdated - Avast! 4
W2013 Anti-virus signature outdated - AVG 8 - W2K/XP/W2K3
W2056 Anti-virus signature outdated - Norman
Sunbelt Network Security Inspector version 2.0.2670.0 Definition Set 205
was released November 20, 2009. Sunbelt Software recommends you download
the new SNSI Vulnerability Update Definitions 205, scan, and patch your
machines today. To get the latest SNSI version, visit:
http://www.wservernews.com/091123-SNSI
|
 |
WServerNews Fave Links |
|
This Week's Links We Like. Tips, Hints And Fun Stuff.
|
 |
WServerNews - Product of the Week |
|
Heads-Up: VIPRE Enterprise 10$/Seat Competitive Upgrade Ends 12/31!
The independent Tolly Group said in their September 2009 Anti-virus Performance
Test Report: "Consumes up to 38% and 45% less memory, and offers up to 2.6x and
3.6x scanning speed compared to Symantec and McAfee." It's clearly time to kiss
your antivirus bloatware goodbye. Sunbelt built VIPRE Enterprise; a completely
new technology combining corporate antivirus plus an enterprise antispyware
solution for total endpoint security designed by admins for admins. And that
means EASY DEPLOYMENT. Click on the 'Request Info' tab and ask for a quote now:
http://www.wservernews.com/091123-VIPRE
|
|
|
|
|