BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Missed it Live? On Demand March VEF Now Available + Live Q&A Answered

Posted March 15, 2012    Sarah Lieber

Miss our live Vulnerability Expert Forum webinar earlier this week? Never fear, I’ve put the recording + slides + Q&A all together here for your convenience. Take your pick.

Additionally, find this month’s Security Bulletin here, a list of all the Audit IDs here, and the PDF of the presentation here.  If you have additional questions not listed here, please feel free to comment below and we’ll get our Research Team to answer.

LIVE Q&A

During the webinar there were some great questions brought up that we wanted to get answered immediately. Below are the live audience questions and our Research Team’s answers:

Q: Which one is more vulnerable to attacks – .com or .net sites and client computers attached to them?

DJ: Both are equally vulnerable. The domain extension, in this case, does not have a whole lot of significance.

JD: It’s not the name or location of the site that makes it vulnerable, it’s the content.

Q: Are the article sources available?

DJ: Yes they’re available and below.

CTx:

IT Admin:

Researcher:

Q: Is the kill switch only controllable by MS or are admins able to adminstrate that functionality?

DJ: Details are scarce, but from all appearances Microsoft has sole control over that, seeing as the applications come from their app store.

JD: My best guess is probably not, this isn’t something you normally pass around.  It will likely be kept as a last resort case for Microsoft.  Killswitches in the past are known for being very rarely, if ever, used.

Q: There seems to be a security update that’s in Microsoft’s update list but does not seem to have an associated bulletin number. Because of that, I’m having difficulty finding out more information about it. It’s KB2647518, Update Rollup for ActiveX Killbits for Windows 7 for x64-based Systems. There’s an Advisory for this at http://support.microsoft.com/kb/2647518, and that page (that has various downloads and installation instructions) references a page with what I’d expect to be the usual descriptive bulletin info at http://www.microsoft.com/technet/security/advisory/2647518.mspx, but this page doesn’t exist. Scanning this month’s list of bulletins, it’s not immediately apparent whether this is a patch without a bulletin number assigned to it, or if it may be included in one of the bulletins that were published this month. Do you have a handle on this? If so, what’s up?

JD: This is a security update, but did not warrant a Bulletin.  Try http://support.microsoft.com/kb/2647518 instead for the advisory.  It basically just disables some ActiveX controls in third party software.

Tags:
, , , , ,

Leave a Reply

Additional articles

gartner market guide image - aug 2014

Introducing the Gartner Market Guide for Privileged Account Management

Posted July 29, 2014    Chris Burd

Gartner recently released a new Market Guide for Privileged Account Management (PAM), and we’d like to share a complimentary copy with you. The report includes PAM market analysis and direction, vendor overviews, and recommendations for selecting PAM solutions for your environment. BeyondTrust is one of two representative vendors (out of 20) to address all solution…

Tags:
, , , , , , , ,
Integrating Least Privilege and Password Management to Solve Account Security Challenges

Integrating Least Privilege and Password Management to Solve Account Security Challenges

Posted July 24, 2014    Morey Haber

There is a reason all BeyondTrust Privileged Account Management (PAM) solutions share the PowerBroker name: They all inherently enable you to reduce user-based risk and can be integrated under a centralized IT risk management platform. Here’s one common use case that demonstrates how this integration changes the playing field. Consider the challenge of privileged access:…

Tags:
, , , , ,
PowerBroker Password Safe Password Age Report

Reshaping Privileged Password Management with Password Safe 5.2

Posted July 21, 2014    Martin Cannard

Today, we’re pleased to unveil the latest edition of our privileged password management solution, PowerBroker Password Safe. I’ll start with a brief intro of what’s new and then tell you a little about the driving factors behind Password Safe development. New features for mitigating password risk and ensuring accountability enterprise-wide Here’s the 10,000-foot overview of…

Tags:
, , ,