Showing posts with label Microsoft Windows. Show all posts
Showing posts with label Microsoft Windows. Show all posts

Microsoft Security Update Turn Pirate's Screen Black

Justify Full

An anti-piracy tactic by Microsoft that turns some computer users' screens black is setting off a wave of unexpected indignation among Chinese consumers, posing renewed problems for the software maker in the huge China market.

In the days since Microsoft deployed an updated anti-piracy tool here, some Chinese have fumed about what they see as an invasion of privacy. Users of legitimate software have been turning their own screens black in protest. One authorized user complained to the police.

"It's a crime," said Beijing lawyer Dong Zhengwei, who filed a complaint against Microsoft with the Public Security Ministry. The ministry hasn't responded.

"The black-screen plan implies that Microsoft can hack all its users, not just the pirates," Dong said. "That's not fair."

Microsoft defended its actions, saying the company complies with Chinese law. It issued a statement late last week promising its anti-piracy campaign would not be used to collect personal information. It is also offering steep discounts on some software to give consumers an affordable legal alternative.

At issue is a software feature that searches for pirated copies of Windows and is part of the XP operating system and Vista. In conducting the search, the tool logs certain information about the personal computer and then notifies the user if it detects illegal copies or counterfeits.

While the tool has been in use for several years, the update released last week by the Internet is more intrusive when it detects a fake copy of XP: it turns the PC's desktop black, replacing the user's background image. A piracy warning appears in the corner of the screen. Though the user can override the blackout, it reappears every 60 minutes.

In all other ways, the blacked-out computer still works. Users not yet affected can avoid getting hit by disabling Windows' automatic update feature, though they will then might miss security updates. For those already hit, software patches to avoid the black screen are already circulating online.

But Chinese computer users' outrage points to continuing problems for the world's largest software maker in what is projected to become the world's biggest computer market.

While Chinese know their Internet is monitored and censored, that rarely creates such a stir. Rather the reaction against Microsoft's Big Brother-esque tactics show Chinese consumers' persisting belief that there's little wrong with buying cut-rate pirated goods.

Knockoff software and electronics are rampant in China. Brand-name computers are sold by retailers with pirated software bundled in, helping to keep prices low. More than 80 percent of personal computer software in China last year was pirated, according to the U.S.-based Business Software Alliance. One in five Chinese consumers do not know they're using pirated software, Microsoft said in a statement.

In an upstairs corner of a Cybermart electronics emporium in downtown Shanghai, saleswoman Jin Li stood in a pink smock under a large Microsoft sign, the shop's counters cluttered with computer parts, mobile phone trinkets and imitation iPods. The shop isn't a licensed Microsoft seller.

"We just wanted to put a brand name up there," Jin said, nodding at the sign.

Customers, she said, have a main complaint about Windows XP. "The real thing is definitely too expensive. They can download it or buy it pirated for 10 yuan," or less than $2, she said. "The real thing is hundreds of yuan. What do you think?"

That easy availability threatens Microsoft's potential profits.

Microsoft Chief Executive Steve Ballmer told a business forum last month that China will surpass the United States as the largest consumer market for personal computers within two years. But software piracy in China has undercut sales of the real thing, keeping Microsoft from meeting revenue growth targets, according to Chief Financial Officer Chris Liddell.

The focus on the Chinese consumer has grown with the China market. For years, Microsoft aimed its anti-piracy campaigns at businesses, the government and other large customers. Two years ago, the Redmond, Washington-based company began signing deals with computer makers both inside and outside China to install genuine versions of its software before PCs reach the stores.

Duncan Clark, chairman of BDA China Ltd., a Beijing tech consulting firm, said the updated Genuine Advantage push is likely an attempt to use shame to target business customers and professionals who do not want to be seen using a fake product.

"There's a little bit of a Big Brother effect," said Clark. "As for the youth, Microsoft probably couldn't win them over in any case."

The move has only increased bitter feelings toward a company perceived by many to charge too much.

"There's absolutely no need for such a monster cash cow like Microsoft to take this obviously dramatic step and make itself the No. 1 enemy of most Chinese PC users," said Steven Lin, a spokesman for the video sharing Web site Youku.com, in an e-mail. "Business/government users are their primary income source in China, how much more can they squeeze from ordinary users who can make on average $500 (3,400 yuan) per month? They're crazy!"

So far, the Chinese government has made no comment, though the Web site of People's Daily, the Communist Party's flagship newspaper, allowed plenty of room for Chinese to vent.

As of Thursday, almost 80 percent of more than 10,000 people responding to a poll on the site said Microsoft should solve the piracy issue by further lowering its prices.

Still, with piracy rampant across the country, lower prices might not be enough.

As the day of the black-screen update loomed in China, a poll taken by the popular Tencent QQ instant messaging system showed 84 percent of the more than 90,000 respondents said they were using pirated software -- and 60 percent said they'd keep doing so.

"Actually, I'll still use pirated software," said 24-year-old Shanghai advertising salesman Tai Chenggong, whose screen turned black this week after downloading a fake copy of Windows for free. "It still works, no problem."

Sphere: Related Content

Microsoft Windows XP & 2003 Server Gets New Updates

Robert McMillan
Microsoft has released its November security updates, fixing a critical Windows bug that has been exploited by online criminals.

Microsoft released just two security updates this month, but security experts say that IT staff will want to install both of them as quickly as possible. The MS07-061 update is particularly critical because the flaw it repairs has been seen in Web-based attack code, said Amol Sarwate, manager of Qualys's vulnerability research lab. "This was a zero day [flaw] that was being used in the wild by hackers," he said.

The flaw has to do with the way Windows passes data between applications, using a technology called the URI (Uniform Resource Identifier) protocol handler. This is the part of Windows that allows users to launch applications -- an e-mail or instant messaging client, for example -- by clicking on a Web link. Because Windows does not perform all of the security checks necessary, hackers found ways to sneak unauthorized commands into these Web links and the flaw could be exploited to install unauthorized software on a victim's PC.

This type of flaw lies in both Windows and the programs being launched by the Web link and Microsoft had initially said that it was up to third-party software developers to fix the issue. It later reversed this position and decided to fix the flaw in Windows as well. These URI protocol handler problems have turned up in Adobe, Firefox and Outlook Express.

Microsoft was forced to revise its position on the URI bugs after researchers discovered that they were far more problematic than first thought, said Nathan McFeters, a security researcher with Ernst & Young, who has been studying this problem. "I think that early on it wasn't clear that this was an issue," he said via e-mail. "There's really a handful of issues with this URI use and abuse stuff."

Microsoft's patch for this problem is rated critical for Windows XP and Windows Server 2003 users, but the bug does not affect Windows 2000 or Vista, Microsoft said.

The second vulnerability, rated "important" by Microsoft, has to do with Windows DNS (Domain Name System) servers, which are used to exchange information about the location of computers on the Internet. Attackers could exploit this flaw to redirect victims to malicious Web sites without their knowledge, something known as a "man in the middle" attack. "All system administrators should look very closely at this vulnerability," Sarwate said. "I would have personally rated it as critical," he said.

Security experts were surprised that Microsoft did not include a patch for a known vulnerability in some Macrovision antipiracy software that has been shipping with Windows for the last few years. Microsoft has said that it plans to patch the problem and that it is aware of "limited attacks" that exploit this vulnerability to get elevated privileges on a victim's machine.

The bug lies in the secdrv.sys driver built by Macrovision that ships with Windows XP, Server 2003 and Vista, but Vista is not vulnerable to the problem, according to Microsoft.

Macrovision has also published a patch for this problem.

Its a "bit worrisome" that Microsoft hasn't pushed out a patch for the bug, given that Macrovision has already made its fix available, said Andrew Storms, director of security operations with nCircle Network Security. "However, [it's] understandable that Microsoft would want to run the patch through its QA [quality assurance] and software release cycles," he added. "Given the choice between the URI bug and the Macrovision fix, enterprise security operations teams would much rather have the URI fix."

Users of Microsoft's WSUS (Windows Server Update Services) update system had been wondering if they were going to get Tuesday's patches, after a Microsoft programming error knocked WSUS administration consoles offline on Sunday and Monday. Microsoft had misnamed an entry in WSUS's database causing the consoles to crash.

The problem was fixed on Monday, said Bobbie Harder, a Microsoft senior program manager, in a blog posting. But WSUS servers that synchronized with Microsoft between 5 pm.Sunday and 11 am Monday Pacific Time will need to resynchronize to avoid the problem.

Though she had heard of one user who had to manually updated his WSUS server, Tuesday's updates went off without a hitch, said Susan Bradley, a WSUS user who is chief technology officer with Tamiyasu, Smith, Horn and Braun, Accountancy.

Sphere: Related Content

Microsoft Releases Three Updates For Vista

John Fontana
Microsoft releases three non-security updates to Windows Vista that relate to battery life, sleep/hibernation issues, and glitches in the Media Center version.

The updates are part of an ongoing release of fixes for Vista that will eventually be incorporated into Service Pack 1, which is set to ship in the first quarter next year.

A public beta of the service pack is due by the end of the year.

Microsoft has been using occasional updates to tune Vista since it shipped a year ago. The company has been promoting the on-going updates to Vista as an alternative to one large service pack.

In October, the company released speed and reliability updates for Vista. In August it issued a pair of updates to address reliability and performance in the operating system.

The first update for this latest release addresses system compatibility, reliability and stability, including the extension of battery life for mobile devices and the stability of Windows PowerShell and wireless network services.

The update also improves the stability of portable and desktop computers that use an uninterruptible power supply (UPS), and the reliability of Vista when you open the menu of a startup application. The upgrade also shortens the startup time of Windows Vista by using a better timing structure, the recovery time after Windows Vista experiences a period of inactivity, and the recovery time when users try to exit the Photos screen saver.

The second update addresses a number of USB core components, including problems trying to recover or enter sleep or hibernation mode. The upgrade is a collection of 21 previously released fixes for USB issues. The second upgrade also addresses problems with USB devices that may no longer work correctly after Vista resumes from sleep or hibernation, problems that may occur with USB-connected microphones, the enabling and re-enabling USB composite devices, and problems with the hardware removal and "eject" command when used with an Apple iPod.

The third update focuses on Windows Media Center and issues with its extensibility platform. It also fixes issues associated with interaction between Media Center and Xbox360, when the gaming console is used as a Media Center Extender.

Microsoft plans to make the updates available via Windows Update beginning November 13, which is the same date for the release of the company's monthly security patch updates.

The three updates will also be included with Vista Service Pack 1, which also will include an update to the Windows kernel to align it with the kernel in Windows Server 2008.

The service pack is expected to ship at the same time as the server, which is slated for the first quarter of 2008. Microsoft officials hope to ship the server on or before the February 27, 2008, launch event in Los Angeles.

Sphere: Related Content

Two New Updates From Microsoft Expected Tuesday

Gregg Keizer

Microsoft has scheduled just two security updates for Tuesday to fix flaws in Windows 2000, XP and Server 2003. One of the two is a leftover from October that was bumped at the last minute.

Only one of the bulletins will be rated "critical," Microsoft's highest ranking, while the other will be labeled "important," the next-lower rating. As usual, Microsoft disclosed a limited amount of information about the upcoming updates in a prepatch notification posted to the company's Web site today.

The critical update affects Windows XP and Windows Server 2003, said Microsoft, which classified the vulnerability as a remote code execution bug. What the bulletin will fix, however, is up for speculation.

"It could be the Macrovision vulnerability," said Andrew Storms, director of security operations at nCircle, referring to the digital rights management software bundled with Windows that has already been targeted by in-the-wild attacks. "Macrovision has already got a fix, so Microsoft wouldn't have had to do any coding."

Storms noted, however, that Microsoft would have to stretch its usual definition of "remote code execution" to make the Macrovision vulnerability fit the update, since both companies have been calling it a privilege elevation flaw, and thus less serious. "Microsoft sometimes seems to go back and forth about privilege elevation," Storms said. "They might just say, 'sure it's an elevation, but it could also lead to remote code execution.' Or we may just see a reversal here of the bug's severity."

On the other hand, the critical bulletin may be aiming at something completely different. "It could be the URI protocol handler bug," Storms said.

Less than two weeks ago, Microsoft accepted responsibility for fixing a widespread flaw in how Windows deals with the Uniform Resource Identifier (URI) protocol handlers, which let browsers run other programs via commands in a URL. At the time, Bill Sisk, a member of Microsoft's security response team, said that the group was "working around the clock" on a patch. The company would not commit to a release date, however, or say whether it would make the next update rollout, now just a day away.

The debate over who was responsible for patching the problem with the URI protocol handler raged over the summer, when Microsoft denied that its software was at fault, and third-party application vendors, including Mozilla and Adobe Systems, pointed fingers at the company even as they patched their own products.

Tuesday's second update, which targets Windows 2000 and Windows Server 2003 but not XP, appears to be the one that was yanked before October's bulletins hit the Internet. The only hint Microsoft gave of its composition was the "Spoofing" label, which in the past has usually been used to describe vulnerabilities in Internet Explorer that phishers and identity thieves exploit to deceive users.

"I have no idea what this one is about," Storms said.

He was, however, sure of one thing: the light patching load users and administrators faced this month. "It's a 'where's the beef?' kind of month," he said. "Maybe we can all catch up a bit."

Sphere: Related Content

Microsoft Finally Agrees To Share Its Secrets

Microsoft has finally agreed to start sharing information with other software developers in compliance with a European Commission 2004 anti-monopoly ruling against it. It will now give third party program developers access to information that will allow them to make systems interoperable with Windows.

The commission said Microsoft would now "comply with its obligations".

The software giant was ruled to have shut out rivals from its Windows operating system to gain a larger share of the market for web servers.

It will also substantially cut the fees it charges for such data.

EU Competition Commissioner Neelie Kroes said she had secured the agreement following a phone call to Microsoft chief executive Steve Ballmer.

Microsoft's move comes a month after it lost its appeal against the Commission's 2004 ruling.

The software giant had taken its appeal all the way to the European Court of First Instance, but it upheld the Commission's judgement that Microsoft had abused its dominant market position.

The court also upheld the Commission's record 497m euros (£343m; $690m) fine against the US company.

"I welcome that Microsoft has finally undertaken concrete steps to ensure full compliance with the 2004 decision," said Ms Kroes.

"It is regrettable that Microsoft has only complied after a considerable delay, two court decisions, and the imposition of daily penalty payments."

The European Commission said Microsoft will now charge a one-time fee of 10,000 euros to firms that want "complete and accurate" technical information on Windows software.

In addition, it will also allow the data to go to open source software developers.

Open source software allows users to read, alter and improve its code - in contrast to proprietary software where a company controls the source code.

Further, Microsoft will cut the price it charges for worldwide licenses and patents to less than 7% of previous levels.

"It is a victory day for the consumer... not the Commission," added Ms Kroes.

"The measures that the Commission has insisted upon will benefit computer users by bringing competition and innovation back to the server market."

Sphere: Related Content

Windows Vista Features In The New Windows XP SP3

A Web site that leaked details of Windows XP Service Pack 3 over the weekend claimed that the update includes several new features, including some borrowed from Windows Vista.

According to NeoSmart Technologies, Windows XP SP3 build 3205, which was released to beta testers on the weekend, includes four new features among the 1,000-plus individual hot fixes and patches that have been issued since XP2's debut three years ago.

Features backported from Vista, said NeoSmart, include Network Access Protection (NAP), an enterprise policy enforcement technology that inspects client PCs before they access a corporate network, then updates the machines if necessary or blocks them if they don't meet specified security criteria.

Other additions range from a kernel module containing several encryption algorithms that can be accessed by third-party developers, to a new Windows activation model that doesn't require users to enter a product key.

Microsoft had previously announced SP3 support for NAP, which is part of Windows Vista and will be included in the not-yet-finalized Windows Server 2008.

Windows XP SP3, which Microsoft has said will be released early in 2008, will be one more move by the developer to extend the lifespan of the six-year-old operating system. Last month, for example, Microsoft gave Windows XP a five-month reprieve by pushing back the end of retail sales and sales of XP-powered PCs by large resellers to June 30, 2008.

And last week, Microsoft debuted a new "get-legal" program that lets companies purchase large quantities of Windows XP Professional licenses through their usual resellers.

Microsoft was not immediately available for comment on the leak, or the new features touted by NeoSmart.

Sphere: Related Content

Microsoft Extends Sales Of Microsoft Windows XP


Microsoft plans to keep selling its Windows XP operating system until the end of June 2008, delaying a scheduled transition to its newer Windows Vista software by five months.

The world's largest software maker introduced Windows Vista in January with the plan to phase out sales of its predecessor, Windows XP, by January 30, 2008.

Microsoft said it decided to extend XP sales in response to feedback from computer manufacturers who said there were customers who still wanted to buy the older operating system.

Some customers have voiced displeasure with Vista due to a lack of compatibility with existing software programs and devices. The hardware requirements needed to run Vista also are a significant upgrade from many older computers.

The company downplayed any dissatisfaction with Vista, saying it is the fastest-selling operating system in the history of Microsoft. As of the end of June, Microsoft had sold more than 60 million Windows Vista licenses.

Microsoft said the top 50 consumer software applications now have a Vista-compatible version and it provides support for more than 2.2 million devices. The Windows operating system sits on about 95 per cent of the world's computers.

The Redmond, Washington-based company also said Microsoft historically makes its older operating system available to customers for two years after the new one is introduced, but it decided to shorten that period to one year with Vista.

"We were a little ambitious to think that we would need to make Windows XP available for only a year after the release of Windows Vista," said Mike Nash, a Microsoft corporate vice president.

Microsoft has forecast that XP will account for about 22 per cent of Windows sales in the current year to June with Vista comprising the remainder. The company said it plans to update this forecast when it announces quarterly results in October.

The company also said it plans to extend sales of the most basic Windows XP Starter Edition for very low cost computers in emerging markets until June 30, 2010. It had also planned to stop sales of that system in January

Sphere: Related Content

Microsoft Releases Six Security Updates

The security bulletins for July 2007 are as follows, in order of severity:

Bulletin Identifier

Microsoft Security Bulletin MS07-036

Bulletin Title

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542)

Executive Summary

This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. This update does not require a restart.

Affected Software

Office, Excel. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-039

Bulletin Title

Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122)

Executive Summary

This critical security update resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-040

Bulletin Title

Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)

Executive Summary

This update resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

.NET Framework. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-037

Bulletin Title

Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (936548)

Executive Summary

This important security update resolves one publicly disclosed vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Microsoft Office Publisher file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update does not require a restart.

Affected Software

Office, Publisher. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-041

Bulletin Title

Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution (939373)

Executive Summary

This important security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows XP Professional. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-038

Bulletin Title

Vulnerability in Windows Vista Firewall Could Allow Information Disclosure (935807)

Executive Summary

This moderate security update resolves a privately reported vulnerability. This vulnerability could allow incoming unsolicited network traffic to access a network interface. An attacker could potentially gather information about the affected host.

Maximum Severity Rating

Moderate

Impact of Vulnerability

Information Disclosure

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows Vista. For more information, see the Affected Software and Download Locations section.

More updates In August 2007

Sphere: Related Content