BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Missed it Live? On Demand March VEF Now Available + Live Q&A Answered

Posted March 15, 2012    Sarah Lieber

Miss our live Vulnerability Expert Forum webinar earlier this week? Never fear, I’ve put the recording + slides + Q&A all together here for your convenience. Take your pick.

Additionally, find this month’s Security Bulletin here, a list of all the Audit IDs here, and the PDF of the presentation here.  If you have additional questions not listed here, please feel free to comment below and we’ll get our Research Team to answer.

LIVE Q&A

During the webinar there were some great questions brought up that we wanted to get answered immediately. Below are the live audience questions and our Research Team’s answers:

Q: Which one is more vulnerable to attacks – .com or .net sites and client computers attached to them?

DJ: Both are equally vulnerable. The domain extension, in this case, does not have a whole lot of significance.

JD: It’s not the name or location of the site that makes it vulnerable, it’s the content.

Q: Are the article sources available?

DJ: Yes they’re available and below.

CTx:

IT Admin:

Researcher:

Q: Is the kill switch only controllable by MS or are admins able to adminstrate that functionality?

DJ: Details are scarce, but from all appearances Microsoft has sole control over that, seeing as the applications come from their app store.

JD: My best guess is probably not, this isn’t something you normally pass around.  It will likely be kept as a last resort case for Microsoft.  Killswitches in the past are known for being very rarely, if ever, used.

Q: There seems to be a security update that’s in Microsoft’s update list but does not seem to have an associated bulletin number. Because of that, I’m having difficulty finding out more information about it. It’s KB2647518, Update Rollup for ActiveX Killbits for Windows 7 for x64-based Systems. There’s an Advisory for this at http://support.microsoft.com/kb/2647518, and that page (that has various downloads and installation instructions) references a page with what I’d expect to be the usual descriptive bulletin info at http://www.microsoft.com/technet/security/advisory/2647518.mspx, but this page doesn’t exist. Scanning this month’s list of bulletins, it’s not immediately apparent whether this is a patch without a bulletin number assigned to it, or if it may be included in one of the bulletins that were published this month. Do you have a handle on this? If so, what’s up?

JD: This is a security update, but did not warrant a Bulletin.  Try http://support.microsoft.com/kb/2647518 instead for the advisory.  It basically just disables some ActiveX controls in third party software.

Tags:
, , , , ,

Leave a Reply

Additional articles

Cavalancia-Headshot - Medium

Making Windows Endpoints the Least of your Worries

Posted September 2, 2015    Nick Cavalancia

We’re all concerned that someday an external hacker will try to gain access to your company’s critical data and systems. The problem? Your endpoints – both your workstations and servers – bypass (and often leave) the safety and security of your environment daily.

Tags:
, ,
powerbroker-difference-2

Why Customers Choose PowerBroker: Low Total Cost of Ownership

Posted September 2, 2015    Scott Lang

In a survey of more than 100 customers, those customers indicated that BeyondTrust’s low powerbroker-difference-2total cost of ownership was a competitive differentiator versus other options in the privileged account management market.

Tags:
, , ,
Larry-Brock-CISO

Passwords: A Hacker’s Best Friend

Posted September 1, 2015    Larry Brock

After all the years of talk about biometrics and multi-factor authentication, we still have passwords and will likely have them for a long time. Because many “high risk” systems require complex passwords (zk7&@1c6), most people that use them believe their passwords are secure. But they aren’t.

Tags:
, ,