No Image

An update on disabling VBScript in Internet Explorer 11

2017-07-08 KENNETH 0

An update on disabling VBScript in Internet Explorer 11 Beginning in the Windows 10 Fall Creators Update, we intend to disable VBScript execution in IE 11 for websites in the Internet Zone and the Restricted Sites Zone by default, to provide a more secure experience. This change was initially announced in a blog post in April. The new default behavior can be previewed beginning with today’s Windows Insider Preview release, build 16237. For customers on previous versions of Windows, we intend to include this change in future cumulative security updates for Internet Explorer 11.The settings to enable, disable, or prompt for VBScript execution in Internet Explorer 11 will remain configurable per site security zone, via Registry, or via Group Policy, on released versions of Windows. We will continue to post updates here in advance of these changes to default settings [ more… ]

Announcing Windows 10 Insider Preview Build 16237 for PC

2017-07-08 KENNETH 0

Announcing Windows 10 Insider Preview Build 16237 for PC Hello Windows Insiders! Today we are excited to release Windows 10 Insider Preview Build 16237 for PC to Windows Insiders in the Fast ring! Upcoming Bug Bash We’re really excited to do our 2nd (and final) Bug Bash for the Windows 10 Fall Creators Update! The Bug Bash will start at 12am (Pacific Time) on Friday July 14th and will run a full week ending at 11:59 pm (Pacific Time) on Sunday July 23rd. As usual, we will be publishing new quests and will be doing some Mixer webcasts. So be sure to open Feedback Hub and complete as many quests as you can! More details to come early next week! What’s New in Build 16237 For PC Microsoft Edge Improvements: Read aloud with word and line highlighting for all websites: [ more… ]

Announcing Microsoft Store back to school deals that begin today

2017-07-08 KENNETH 0

Announcing Microsoft Store back to school deals that begin today Starting July 7 through September 17, your local Microsoft Store is offering savings on best-in-class products for back to school. Before heading back to school or setting out on that first job search, there is a moment where the excitement, hope for the future and desire to learn is empowering, and Microsoft Store is the best place to discover and purchase the technology to help you achieve more. Starting July 7 through September 17, your local Microsoft Store is offering savings on best-in-class products, including the well-crafted Surface Pro 4 and Surface Book to help students and young professionals start new adventures and make ideas happen. Microsoft Store offers a 10 percent discount for students, faculty, and staff currently attending or working at a higher education institution in the U.S. [ more… ]

No Image

USN-3350-1: poppler vulnerabilities

2017-07-08 KENNETH 0

USN-3350-1: poppler vulnerabilities Ubuntu Security Notice USN-3350-1 7th July, 2017 poppler vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary poppler could be made to crash or run programs as your login if it opened a specially crafted file. Software description poppler – PDF rendering library Details Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000images. If a user or automated system were tricked into opening a craftedPDF file, an attacker could cause a denial of service or possibly executearbitrary code with privileges of the user invoking the program.(CVE-2017-2820) Jiaqi Peng discovered that the poppler pdfunite tool incorrectly parsedcertain malformed PDF documents. If a user or automated system were trickedinto opening a crafted PDF file, an attacker could cause poppler to crash,resulting in a denial of [ more… ]

[기술 백서] AWS WAF를 통해 OWASP 상위 10 웹 애플리케이션 취약점 방어하기

2017-07-07 KENNETH 0

[기술 백서] AWS WAF를 통해 OWASP 상위 10 웹 애플리케이션 취약점 방어하기 Open Web Application Security Project (OWASP)의 웹 애플리케이션 보안 향상 프로젝트를 알고 계시나요? 그 중에서도 OWASP Top 10이라는 가장 중요한 10 가지 애플리케이션 보안 결함 목록이 있습니다. 이 목록은 최근 웹 사이트 및 웹 애플리케이션에서 자주 발견되는 일반적인 취약점에 대한 내용을 포함합니다. AWS WAF는  이전 블로그 글에서 설명 드린 대로  SQL 인젝션 및 크로스 사이트 스크립팅과 같은 애플리케이션 계층 공격으로부터  사용자 지정 규칙을 만들어 허용 및 거부 트래픽 유형을 정의함으로서 보안을 강화할 수 있습니다. 신규 기술 백서 Use AWS WAF to Mitigate OWASP’s Top 10 Web Application Vulnerabilities 에서는 OWASP의 상위 열 가지 취약점을 완화하기 위한  AWS WAF 사용 방법을 설명합니다. 즉, OWASP Top 10 (공식적으로 A1에서 A10으로 알려짐)에서 가장 중요한 항목에 대한 세부적이고 구체적인 완화 전략 및 구현 세부 정보가 포함됩니다. A1 – Injection. A2 – Broken [ more… ]