Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Monday, December 7, 2020

Microsoft Defender for Linux adds new security feature

Microsoft's server-based Linux protection program is now offering a public preview of improved endpoint detection and response features.

I know it's still hard for some of you to wrap your minds around it, but Microsoft really does support Linux these days. A case in point: Back in June, Microsoft released Microsoft Defender Advanced Threat Protection (ATP) for Linux for general use. Now, Microsoft has improved the Linux version of Defender, by adding a public preview of endpoint detection and response (EDR) capabilities.

This is still not a version of Microsoft Defender you can run on a standalone Linux desktop. Its primary job remains to protect Linux servers from server and network threats. If you want protection for your standalone desktop, use such programs as ClamAV or Sophos Antivirus for Linux.

For businesses, though, with workers from home now using their Macs and Windows PCs here, there, and everywhere, it's a different story. While based on Linux servers, you'll be able to use it to protect PCs running macOS, Windows 8.1, and Windows 10. 

With these new EDR capabilities, Linux Defender users can detect advanced attacks that involve Linux servers, utilize rich experiences, and quickly remediate threats. This builds on the existing preventative antivirus capabilities and centralized reporting available via the Microsoft Defender Security Center. Specifically, it includes:

  • Rich investigation experience, which includes machine timeline, process creation, file creation, network connections, login events, and advanced hunting.
  • Optimized performance-enhanced CPU utilization in compilation procedures and large software deployments.
  • In-context AV detection. Just like with the Windows edition, you'll get insight into where a threat came from and how the malicious process or activity was created.

To run the updated program, you'll need one of the following Linux servers: RHEL 7.2+; CentOS Linux 7.2+; Ubuntu 16.04 or higher LTS; SLES 12+; Debian or higher; or Oracle Linux 7.2.

Next, to try these public preview capabilities, you'll need to turn on the preview features in Microsoft Defender Security Center. Before you do this, make sure you're running version 101.12.99 or higher. You can find out which version you're running with the command: 

mdatp health

You shouldn't switch all your servers running Microsoft Defender for Endpoint on Linux to the preview in any case. Instead, Microsoft recommends you configure only some of your Linux servers to Preview mode, with the following command:

$ sudo mdatp edr early-preview enable 

Once that's done, if you're feeling brave and want to see for yourself if it works, Microsoft is offering a way to run a simulated attack. To do this, follow the steps below to simulate a detection on your Linux server and investigate the case. 

1 - Verify that the onboarded Linux server appears in Microsoft Defender Security Center. If this is the first onboarding of the machine, it can take up to 20 minutes until it appears. 

2 - Download and extract the script file from here aka.ms/LinuxDIY to an onboarded Linux server and run the following command:

./mde_linux_edr_diy.sh

After a few minutes, it should be raised in Microsoft Defender Security Center.

Look at the alert details, machine timeline, and perform your typical investigation steps.


Good luck!  


By Steven J. Vaughan-Nichols for Linux and Open Source | November 17, 2020 -- 21:16 GMT (13:16 PST) | Topic: Security

Source: https://www.zdnet.com/article/microsoft-defender-for-linux-adds-new-security-feature/

NSA says Russian state hackers are using a VMware flaw to ransack networks

If you use VMWare, you might be concerned about your environment's security ...

Multiple VMware products are exploited in attacks that access Windows active directory.

DAN GOODIN - 12/7/2020, 4:19 PM

The National Security Agency says that Russian state hackers are compromising multiple VMware systems in attacks that allow the hackers to install malware, gain unauthorized access to sensitive data, and maintain a persistent hold on widely used remote work platforms.

The in-progress attacks are exploiting a security bug that remained unpatched until last Thursday, the agency reported on Monday. CVE-2020-4006, as the flaw is tracked, is a command-injection flaw, meaning it allows attackers to execute commands of their choice on the operating system running the vulnerable software. These vulnerabilities are the result of code that fails to filter unsafe user input such as HTTP headers or cookies. VMware patched CVE-2020-4006 after being tipped off by the NSA.

A hacker’s Holy Grail

Attackers from a group sponsored by the Russian government are exploiting the vulnerability to gain initial access to vulnerable systems. They then upload a Web shell that gives a persistent interface for running server commands. Using the command interface, the hackers are eventually able to access the active directory, the part of Microsoft Windows server operating systems that hackers consider the Holy Grail because it allows them to create accounts, change passwords, and carry out other highly privileged tasks.

“The exploitation via command injection led to installation of a web shell and follow-on malicious activity where credentials in the form of SAML authentication assertions were generated and sent to Microsoft Active Directory Federation Services, which in turn granted the actors access to protected data,” NSA officials wrote in Monday’s cybersecurity advisory.

For attackers to exploit the VMware flaw, they first must gain authenticated password-based access to the management interface of the device. The interface by default runs over Internet port 8443. Passwords must be manually set upon installation of software, a requirement that suggests administrators are either choosing weak passwords or that the passwords are being compromised through other means.

“A malicious actor with network access to the administrative configurator on port 8443 and a valid password for the configurator admin account can execute commands with unrestricted privileges on the underlying operating system,” VMware said in an advisory published on Thursday. “This account is internal to the impacted products and a password is set at the time of deployment. A malicious actor must possess this password to attempt to exploit CVE-2020-4006.”

The active attacks come as large numbers of organizations have initiated work-from-home procedures in response to the COVID-19 pandemic. With many employees remotely accessing sensitive information stored on corporate and government networks, software from VMware plays a key role in safeguards designed to keep connections secure.

The command-injection flaw affects the following five VMware platforms:

  • VMware Access 3 20.01 and 20.10 on Linux
  • VMware vIDM 5 3.3.1, 3.3.2, and 3.3.3 on Linux
  • VMware vIDM Connector 3.3.1, 3.3.2, 3.3.3, 19.03
  • VMware Cloud Foundation 6 4.x
  • VMware vRealize Suite Lifecycle Manager 7 8.x

People running one of these products should install the VMware patch as soon as possible. They should also review the password used to secure the VMware product to ensure it’s strong. Both the NSA and VMware have additional advice for securing systems at the links above.

Monday’s NSA advisory didn’t identify the hacking group behind the attacks other than to say it was composed of “Russian state-sponsored malicious cyber actors.” In October, the FBI and the Cybersecurity and Infrastructure Security Agency warned that Russian state hackers were targeting the critical Windows vulnerability dubbed Zerologon. That Russian hacking group goes under many names, including Berserk Bear, Energetic Bear, TeamSpy, Dragonfly, Havex, Crouching Yeti, and Koala.

From: https://arstechnica.com/information-technology/2020/12/nsa-says-russian-state-hackers-are-using-a-vmware-flaw-to-ransack-networks/

Wednesday, November 21, 2012

TMG URL Category errors

Not really an error, but some URLs are wrongly categorized by TMG, such as www.bancohonda.com.br, a financial tool from Honda. TMG consider this as a weapon site:


Not only this, but several other URLs are not correctly filed. That is easy to resolve, but WHY a financial site is considered a Weapons site?

Monday, November 23, 2009

MSN forced update

Until some days ago, My MSN Live was always reminding me to update. But, as lots of guys, I didn't. Right now, it refused to work until I accepted to update. I don't know what for, I did not received any comment about it, I did not authorized any download. But anyway, they did it again.

I am not one of the Linux evangelists anymore, I do agree with interoperability, I do think it is necessary. But I paid any single cent for my computer, so I am the one to decided what will be in it or not.

The reason I left MS Vista HP in my Toshiba was: it is legal. After some years only working with Linux in home and XP in the office left me behind in several topics. I tried to give MS a chance.

But they keep wandering around in my laptop, in and out, without telling why or when. It is just like this is not my laptop. I am aware that they allowed me to use Vista, and that I do not own it. Okay!!! But the laptop is still mine, I own it, I must decide what I want or not! and also when!!
Up here they allow me to choose yes (Sim) or no (Não) as an answer to "May I (MS) install the software I (MS) downloaded in your laptop (the sucker's laptop)? ".

They "offered" some stuff to install, and I answered them "no,thanks". Since I have no choice (not democratic!), just give me Live MSN, thanks. But they warned it would cost 160MB. Awful!

Not only this, but there is an interesting translating problem: Silverlight's is in English !!! Here in Brazil they always complained about our poor translation. But that, years ago. Now, in 2009, they did the same ? Shame on you ...

After, I spent some minutes to overview the contract, and there they told me:
- I cannot use the service in a "harmful way" (my translation) to MS or to the announcers. So, I can't use MSN to complain about my insatisfaction with MS? Is that correct ?
- I agree that they may use whatever I type in MSN, almost in the way they understand they should.
- In case of being prejudiced, the MS can refund me as compensation no more than the value I pay monthly. Not even a penny more. Also, it doesn't matter whether MS knew or should know about anything that could prejudice me!!!
- This contract is eletronic, but I can not copy/paste it or at least perform a search in it. And if I need to find any word in it? no way!
- MS does not guarantee anything. Software SHOULD work, OS SHOULD work. And where is the problem in using free software ? It is also not guaranteed.
- In my case, as it is for everyone who lives in any country of South America, most problems related to the service should be resolved in Washington. If I am complaining, and if in Brazil we have MS offices also, why in the world should I go to Washington ?

For now, I had to accept this all. I will still try to evaluate if it is really worthy to use a licensed Windows copy. I am not speaking about piracy. I am speaking about free software, mainly Ubuntu.

Thursday, November 12, 2009

ODT being read in MS Word

Maybe I am late with this, but ...

Until 2 weeks ago, I could not have my ODT document edited in MS Word 2007. All of a sudden, I open my work with Vista Home Premium (Legal Copy), and I saw my work with MS Word Icon. WOW!!! These last couple of days, Vista has warned several times it needed to restart, because of updates, and things like that. I understand updates, but I don't agree with all that everlastings restartings.

Anyway, I tried to watch the way MS Word understood my book. In past days, OpenOffice tried to understand DOC documents, but several troubles of formatting always were there, for
sarcasm of all: "it is awful, it will never do it, you will loose your work", and on.








MS did a really good job, except for some details:




1) Headings got off the margin:












2) Bullets were not correctly interpreted








3) Background images were not imported. In this image, there is a wall image behind the text "notas importantes", but it was not imported. Notice that, when I wrote this box, I inserted the image in the original ODT file. Also the watermark I defined (a Creative Commons license, converted to JPG) was not imported.




Other features I used in OOWrite worked perfectly. After all, opening ODT files in this updated version of Word was not as complicated as opening old DOCs format in OOWriter, but it was not perfect. Anyway, it is a good step for MS, having in mind interoperactivity.

If you know about more details, let me know. Also, do not forget to comment and to tell if this was useful or not.

Update:
MSWord also does not natively export to PDF documents.

Tuesday, September 22, 2009

My old Acer has finally gone ...

After almost 5 years wth me, my Acer laptop (Celeron) has been sold. Since it's arrival, it has mostly worked with Ubuntu in a partition, and Windows XP in another.

After some months, only Ubuntu, and until last month, Ubuntu 9.04. I bought a brand new one (thanks, Lon !!!) from Toshiba. And a friend of us asked me that laptop for his son. I told him to keep Ubuntu, for it is better, safer, and all the stuff we know about it.

- No, because he will have to learn lots of new concepts, and on.

And that is for studying only. After some words, I finally gave up, and had to start reinstalling Windows XP on it. Vista would not work well. My first problem was with drivers, since I didn't have them. Not that difficult, Acer's site is really a breeze. I downloaded almost 10 drivers and started a painful path of OS rebuilding. More than 8 reboots after, I had a fully functional Windows: sound, video and anything useful else. Typical. No Compiz, jelly windows, cube desktop, or many other useful stuffs. Hummm ... I mentioned it was only a Celeron with 1G ?

Office, Avira, hotfixes, all this stuff to be installed AFTER ending OS on Partition. More than 1:30 hours, My future ex-Acer is ready to serve someone else: a teenager ... (brrr).

One week after, all the system was compromised with "some" viruses. Now, after all that problems, he'll give Linux a chance. I'll let you know about it after.

Sunday, April 19, 2009

MSN Messenger access Microsoft secretly

At least, most of MSN Messenger does not know that ...

Recently I was called by a friend, to help him in his computer problems. A reasonable desktop box, with Windows XP and ESET anti-virus.

MSN 2009 had been installed, but just was not working. I started ESET firewall, and set him to block data traffic, incoming or outgoing. This way I could watch any MSN access. Unfortunatelly, it did not worked at all, so I started working in some others tries, but left Firewall working in the same way. Searching on Internet, I found this page, with older versions of MSN.

After downloading 8.5, I started removing the 2009 version. Surprisingly, ESET Firewall blocked an access try to the Software Vendor. And more than 3 times !!! I cannot understand this. If I was uninstalling the software, why to contact Microsoft ?

I immediately thought of VLC, as shown in this popup. This just did not happened with MSN. The software did not warned me of this, just did it. this is disgusting. They could at least prompt the user about what was about to be done.

After this bad experience, after breathing deeply, I decided to continue, of course. Having installed 8.5 version, I started it, and I was prompted by a warning of a new version to be installed. Of course, I denied, and ... nothing happened. Twice, 3 times, and nothing happened. That means, get the new verson, it is an order. Or else just does not use it.

Wow! Those guy are really bold!! The computer is owned by the one who bought it, if he wants to use it with an older version, it is his business, not Microsoft business.

Mais uma vez fiquei tremendamente irritado. O computador pertence ao seu dono, ou seja, a quem desembolsou dinheiro para o comprar, e o fornecedor do software se acha no direito de impôr suas decisões sobre qual versão do software o usuário tem que usar. It was his own money!!!

Went for a little (a lotta) water, to cool my hatred. I found some tricks to apply on Register (nothing that easy, as many says) and MSN 2009 (after being re-downloaded) was ready to be used. That's okay, it is a Beta version. It will be fixed.

But, I ask any of you: Why does it must be this way ? please, technical answers, and not those built upon a "I think" basis.

Sunday, November 30, 2008

Windows 7 and it's news

For some time, I have been working with computers. In my blog in portuguese, I have detailed some funny moments of this road, although many of them were not so funny.Here in Brazil Windows is the OS market leader, and there is nothing anyone can say to change this. It's just that. But we must face a fact, things are really changing.

Apple in Brazil
Unfortunatelly, Apple does not do a good marketing work here. And that is really a pity, if you know what an Apple can do for you, you do know what I am talking about. Prices are always hiting the ceiling, almost no official reseller, and the few are concentrated in RJ or SP. The brazilian site itself does not shows the same stuff you find in american version. For sure, there are reasons, and I just don't know anything about them. So, Windows has been the choice.

A better Windows
Guys from networking knows that just since last years, Windows has become a secure option. Windows 2003 is a shift, if you see the bad steps of MS, in security, resource comsunption and so on. It is astonishing to see how a so unperfect OS has been working for so long. And not only to end users, but for the network basements. After 2003 (IMHO) things started to change. Lighter, faster, less unsecure. Okay, nobody is perfect. You still MUST be afraid of tons of new aggressive codes that works through loads of MS Windows weakness. not only about virus, but worms & Co. Just to remember, Unix OS also may be affected by them. Hummm ... in second thought: mostly server softwares may be, and much more than the OS.

NNF Technology
Anyway, there is another thing we cannot deny: Vista was such a wrong shot. Oh, there is the Mojave Experiment. That made think about the NNF technology wich is the knowledge basis of most computers technicians I know. Most of "computer guys" are not really prepared. But they know that reading the screens wil help them to make the work. They acquire that "knowledge", but are really not prepared to different situations. Let's then suppose that a Martian Ideas Transmission device is to be installed. That's the best moment for applying the , such as: it is not working, it is not compatible, your computer is not ready for that, it may be spoiled.

In another hand, the "Mojave OS" was already there, and correctly installed. And that is okay! End user are not to install an OS. Or it is ready-to-use or you should have someone to install it. Ops!!! As far as I can remember, MS warriors complained about Linux complexicity. Touché!

"News" on Windows 7
Why this all? There are tons of noise about Windows 7 and its innovative-brand new-shiny desktop. In Brazilian version of PCWorld, some shots of it is shown, and I got some disappointed to see that it is not that all. As an user of Ubuntu Desktop, I see some characteristics I have been making full usage since 04/2007. They were fully disponible in Ubuntu 7.04 version. If the goal is to prepare an eye-candy desktop, there are a lot to go through. I know it is just a preview, a Beta version, and so on. But all these has been ready to be used, as I told before. Not to commom users to install, but it was (and is) there.
  • The Windows Gadgets are available through gdesklets.
  • The Jumplists were first shown in KDE through SuSE. Note that this page is from April 2007. Windows Media Player also makes use of Jumplists.
  • The Device stage is somehow innovative, and not. It depends on the manufacturers to make available hardware specifications, and he correct drivers will be done. Here a petition for compatibility from VIA to Linux states the following:
While VIA has been on the market for a lot of time and claims to support Linux, this is not actually true. VIA does not support Linux (any distribution), at least regarding Video Chipsets support, since it's Linux drivers do not allow users to use their hardware up to the chipset specifications. However, using the same hardware on Windows, the manufacturer specifications are met. This shows that current driver developing efforts by VIA consider only Windows users (again, Linux is *not* supported).
  • The Media Collections (is that supposed to be correct in English ?) seems to be an development of Images, Video and Music folders in My Documents. I really do not know if there is something referred native to system. Of course, we have softwares that can work like this, but not native to the desktop environment. Since I am an Gnome fan, I haven't watched KDE yet. But the KDE guys really work hard on media stuff.
  • The User Account Control is something that has no corresponding item since securitty issues are dealt in different manners.
  • The Windows Solution Center seems to group several warnings in one place allowing the user to see them all. Guess some advanced users asked for this, but it can be a problem to common users, who are just used to make use of the sytem, and almost never care about security levels, warnings, and on. Most of time, they just want to know where is the OK button. Again, I don't know wether there is or not such a feature in an Linux Desktop Environment.
  • The Federated Search is an useful network search tool. Probably it will search for data in different versions of MS OS, like XP, 2003, and so on. Probably, it will not search in Apple or Linux hosts.
  • Themes should be easier to work with. It was not difficult, but the screen shows a broader range of options. In Ubuntu, it is really easy to make detailed changes in theme configuration. Here, one of the many videos showing how to do so.
  • Zoom effect is a quite useful feature, specially in a presentation. In this screen a square shows an magnified square area. Zoom in linux, as shown in this video, works in the full screen area.
  • When the desktop is crowded with many windows, sometimes is necessary to see the desktop, or the gadgets. Hiding the winows is a solution.
  • I don't understand how useful could be the resource of streaming. If videos and musics must be licensed, what will be done in my system to control this ? Only my medias can be deployed, but many will spread forbidden media, and that may arouse legal issues. Is this feature an effort against P2P networks ?
  • A lighter Windows Media Player. Hopefully, it will be. Linux has Totem, but it is way too slow and somehow buggy. Installing VLC and making it the default media player is preferred. It can be installed directly by Synaptic.
  • The MSPaint now uses the "brand-new" and complicated substitute for old-fashioned Menu bar. I did not understand what is new about this. I hope Paint records in JPG format by default.
  • Some visual enhancing to the calculator.
  • The Battery Monitor now shows minutes remaining, as Gnome always did.
Don't forget that I am only comparing what an review states abou the new Windows version with a few things I know in Linux. I'd love to receive opinions about Windows 2007.