SwiftecIT: Corporate Quality IT for growing businesses SwiftecIT: Corporate Quality IT for growing businesses SwiftecIT: Corporate Quality IT for growing businesses

Archive for the ‘IT in the Workplace’ Category

‘Fully Patched’ Microsoft Windows XP, 2000 Still Vulnerable To Attack

Wednesday, July 7th, 2010

Source

By Stefanie Hoffman, CRN 8:04 PM EDT Tue. Jul. 06, 2010

There’s yet another critical Microsoft (NSDQ:MSFT) Windows vulnerability out there, this time in fully patched Windows 2000 and Windows XP versions, which can be exploited by hackers to launch malicious attacks, security firm Secunia reported.The Windows vulnerability, which Secunia rates as “moderately critical” is the result of a boundary error in the “UpdateFrameTitleForDocument()” function of the CFrameWnd class in mfc42.dll. The vulnerability can be exploited to cause a stack-based buffer overflow error, which occurs by passing an overly long title string argument to the vulnerable function.

If exploited, the vulnerability can open the door for hackers to launch remote code execution attacks, aimed at taking control of a user’s computer and stealing sensitive data, typically through social engineering schemes. Specifically, the vulnerability is confirmed in fully patched versions of Windows 2000 Professional SP4 and Windows XP SP2/SP3, although other versions may also be affected. In addition, the PowerZip version 7.2 Build 4010 was also found to be an attack vector exploiting the flaw, the Secunia advisory states.

Thus far, Microsoft has yet to release a patch fixing the error, and has not yet issued an advisory warning users about the flaw. Until then, Secunia recommends that users restrict access to applications that allow user-controlled input to be passed to the vulnerability.

Security: Copier machines – huge security risk

Monday, May 10th, 2010

This is not for the faint of heart.  Copiers digitally store all your confidential and personal information – and when you trade in your copier you are handing all of this information to someone you don’t know!  Never mind the security implications for MA Regulation 201 CMR 17.00 – but what about confidentiality.  Oy vey!

http://www.cbsnews.com/video/watch/?id=6412572n

What to do?  Get a letter from the company taking the copier that they have wiped the hard drive in the copier, or find a company that will do this before you trade the unit in.

John St. Laurent to Manager of Technical Services

Friday, May 7th, 2010

John St Laurent

Swiftec IT of Shrewsbury has promoted John St. Laurent to manager of technical services.

In his new position, St. Laurent will work with clients and oversee the firm’s technicians.

St. Laurent started at Swiftec in January as a senior technician. He has more than 13 years of experience servicing computers. Before joining Swiftec, he was the network administrator for the Auburn Police Department and worked for IMC (software for Police Departments) in Connecticut.

He is married and lives in Worcester.

iPad – security issues

Thursday, April 8th, 2010

The new iPad looks and sounds like a cool gadget (some might say toy).  Here are some points for you to consider prior to purchasing one. (thank you to ChannelWeb)

  1. Operating system quite hackable. “This was not particularly surprising, considering that the iPad’s nearest cousin, the iPhone, has been subject to a slew of jailbreak attacks since its inception. But the attack likely foreshadows a barrage of jailbreaking assaults yet to come as some adventurous iPad hobbyists and hackers attempt to open up their device to a new world of applications and software not found or approved by the Apple App Store.”
  2. Popularity drives attempts to hack.  For exmaple: Symantec is the most popular anti-virus software – so it is subjected to the most attempts to fool it ( and quite a few succedd :( ).
  3. Maleware / exploit browsing – will work even better on the iPad because you cant put software to protect yourself on it.
  4. AntiVirus not an option – Apple considers themselves safe from viruses and does not allow third party development of antivirus software.  (so an open door to those who enjoy a challenge)
  5. E-mail attacks – see #4.  There is already code which will create a buffer overflow and crash the system
  6. Encryption – nothing really there. Hoffman, of SMobile Systems, said that from a forensics standpoint, iPad’s embedded encryption was “worthless.”
  7. Firewall – doesn’t have one (see #4)
  8. Image exploits – Apple recently released 88 security patches for their software, but there are still a host of vulnerabilities in software such as Quicktime (which is embedded into the iPad)

So, the iPad does not seem ready for business yet.  Give it some time and these issues will either be addressed or you will go back to the itouch for music, apps, and browsing.


FixWin a free utility for Windows 7

Tuesday, March 30th, 2010

ust came across FixWin a free utility for Windows 7 and Windows Vista. FixWin is interesting because all it does is a fix 50 known issues in Windows 7 and Windows Vista with 10 fixes under 5 different categories. FixWin doesn’t identify or diagnose a problem for you but if you know you do have a problem that FixWin can resolve then the resolution is just click away.

FixWin is a portable application meaning it doesn’t need installation on your system. Simply unzip the download and run the FixWin application. It’s that simple.

Interestingly, FixWin can help you run System File Checker a well known Windows utility which basically checks for corrupt system files and replaces them and can help you create a Restore point before fixing the issues.

The categories of issues that can be resolved include

Windows Explorer

Internet & Network connectivity

Windows Media

System Tools

and Additional common fixes for Windows

The picture gallery below shows all the problems that FixWin can indeed fix.

Upgrading to Microsoft® Office 2010

Friday, March 26th, 2010
Upgrading to Microsoft® Office 2010 is easy



  1. Buy a qualifying Office 2007 product (with or without a new PC) between March 5 and September 30, 2010.
  2. Install and activate your copy of Office 2007 by September 30, 2010.
  3. Once Office 2010 is available, simply go to www.office.com/techg by October 31, 2010 to download it at no additional cost, or purchase a DVD for a fee. Follow the online steps to verify eligibility. You will need an activated Office 2007 Product Key.

View the qualify software, upgrade, and new features of Office 2010 on Microsoft Office page located at www.senecadata.com.

Spector 360® 2010 Product Upgrade Release Notice

Tuesday, January 26th, 2010

FYI – for clients running SpectorSoft for web filtering.  If this affects you and you would like the upgrade installed, please let us know.

Microsoft Critical Product Vulnerability, January 21 (Out-of-Band)

Sunday, January 24th, 2010

Cumulative Security Update for Internet Explorer (978207) MS10-002

Affected Software
All supported versions of Internet Explorer on Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008*, Windows 7, and Windows Server 2008 R2*.

Symantec claiming to be out of date!

Wednesday, January 6th, 2010

Current certified definitions are December 31, 2009 rev 117 and contain updates through January 5, 2010.

—————————————————————————————————————————————————–

An issue has been identified in the Symantec Endpoint Protection Manager (SEPM) server whereby all types of SEP definition content [AV/AS, IPS] with a date greater than December 31, 2009 11:59pm are considered to be “out of date”.

Customers running SEP are still protected, and we are continuing to release updated definitions as normal.  However, for the time being, SEP definitions will display a date of December 31, 2009, with increasing revision numbers.

Swiftec merges with TrekMicro!

Friday, January 1st, 2010

We want to share with you some exciting news at Swiftec IT, Inc (Swiftec). Effective January 1, 2010 Swiftec and TrekMicro have merged to jointly provide IT services to their combined client base under the Swiftec IT, Inc name. The technical support you have been receiving from Swiftec and TrekMicro will continue as before, but will be enhanced by additional staff.

Read full press release here