Showing posts with label Secunia. Show all posts
Showing posts with label Secunia. Show all posts

Wednesday, January 21, 2009

Apple Security Updates

Hey, all you QuickTime users. Apple has a little present for you. For QuickTime 7.6, Apple brings you APPLE-SA-2009-01-21 QuickTime 7.6 that closes many, many vulnerabilities that reference "arbitrary code execution". Yikes.

Make sure you upgrade to the latest version of QT, because patching the older versions just doesn't seem to buy you much benefit anymore.

Don't waste much time rolling out this new update. Since users typically have feet of clay when upgrading or patching some software peripherals like QuickTime, Flash, Adobe Reader, and so on, evildoers have taken to using them as fertile attack vectors. Just viewing a specially-crafted streaming video or movie file. And we all know how tempted you are to see that free video of Paris Hilton or Megan Fox that gets delivered to your inbox.


If I haven't convinced you yet, let me try again: Secunia PSI is a good, free offering that keeps track of all your software that needs updating or is end of life, meaning no support is available. If you're running a Windows laptop or desktop, PSI is a good investment, if for no other reason than it streamlines notification of problems you need to fix.



Monday, December 8, 2008

How insecure is your PC?

Frequent readers of Red Gecko have seen my posts about keeping your home PCs secure so they don't become zombies as part of some huge botnet. With the threat landscape constantly evolving, it's tough to keep up with all the insecure software that might reside on your home box.

You've also read my recommendations for a free tool called Secunia PSI that runs in the background and reminds you of things like missing patches, insecure programs, and end-of-life products that probably no longer have security support at all, so running them is a bad idea.

Secunia has posted a nice little survey based on results they've noted from loaded machines reporting back their scanning results. Not sure I like that, but it's a trade off to consider...having a program keep you current while recording users issues for analysis and publication.

Anyway, here's a snippet from their results:

Number of insecure programs per PC/user:
0 Insecure Programs: 1.91% of PCs
1-5 Insecure Programs: 30.27% of PCs
6-10 Insecure Programs: 25.07% of PCs
11+ Insecure Programs: 45.76% of PCs

98% of PCs surveyed had at least one outdated program. If you keep in mind that each insecure or end of life piece of software increases your risk, you can see that having 11+ instances of this is a lot like leaving your doors and windows open and trusting the bad guys to either not notice or pass you by for the house down the street. Eventually, your number will come up.

Just some info for you to chew on.