Independent

ComputerWorldIndependent

InSpectre: See whether your PC's protected from Meltdown and Spectre

Credit to Author: Woody Leonhard| Date: Tue, 16 Jan 2018 11:16:00 -0800

If you’re wondering whether your computer is susceptible to the latest bête noir, Meltdown and Spectre, you can take the official Microsoft patch and, after a suitable amount of technical drudgery, come away with a result that doesn’t answer much. Or you can try Steve Gibson’s new InSpectre and – with suitable caveats – see some meaningful results and a few hints about catching up.

Microsoft has a complex PowerShell script that details your machine’s exposure to the Meltdown and Spectre security flaws. Running that script on all but the simplest and most up-to-date systems turns into a hair-pulling exercise, and the results are coated in 10 layers of technical gobbledygook.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Microsoft's mystifying Meltdown/Spectre patches for AMD processors

Credit to Author: Woody Leonhard| Date: Tue, 16 Jan 2018 07:33:00 -0800

I’ve seen a lot of bizarre Microsoft patches-of-patches, but the new patches for AMD processors are in a world of their own. The security-only, manually downloadable patches appear to be Meltdown/Spectre patches for machines that were bricked by other bad patches, earlier this month, but they’ve arrived with no instructions — and a strange circular logic.

Last week, Microsoft released two patches, with these official titles:

  • KB 4073578: Unbootable state for AMD devices in Windows 7 SP1 and Windows Server 2008 R2 SP1
  • KB 4073576: Unbootable state for AMD devices in Windows 8.1 and Windows Server 2012 R2

The Win7 KB article says:

To read this article in full, please click here

Read More
ComputerWorldIndependent

How to make sure Windows gets the right patches coming to it

Credit to Author: Gregg Keizer| Date: Tue, 16 Jan 2018 03:12:00 -0800

The Windows emergency security updates issued by Microsoft earlier this month came with an unprecedented prerequisite – a new key stored in the operating system’s registry – that antivirus vendors were told to generate after they’d guaranteed their code wouldn’t trigger dreaded Blue Screens of Death (BSoD) when users apply the patches.

The demands confused customers, and fueled a flood of support documents and an avalanche of web content. Those who heard about the Meltdown and Spectre vulnerabilities struggled to figure out whether their PCs were protected, and if not, why not. Millions more, not having gotten wind of the potential threat, carried on without realizing that their PCs might be barred from receiving several months’ worth of security updates.

To read this article in full, please click here

Read More
IndependentSecuriteam

SSD Advisory – GitStack Unauthenticated Remote Code Execution

Credit to Author: SSD / Maor Schwartz| Date: Mon, 15 Jan 2018 12:22:25 +0000

Vulnerability Summary The following advisory describes an unauthenticated action that allows a remote attacker to add a user to GitStack and then used to trigger an unauthenticated remote code execution. GitStack is “a software that lets you setup your own private Git server for Windows. This means that you create a leading edge versioning system … Continue reading SSD Advisory – GitStack Unauthenticated Remote Code Execution

Read More
ComputerWorldIndependent

Intel says new firmware patches trigger reboots in Haswell and Broadwell systems

Credit to Author: Woody Leonhard| Date: Fri, 12 Jan 2018 05:18:00 -0800

The headlong race to cover the Meltdown/Spectre debacle has claimed another victim. In a surprising move, Intel has raised a red flag about some of its firmware patches. What should you do? Wait.

Yesterday, Intel executive VP Navin Shenoy posted on the company blog:

We have received reports from a few customers of higher system reboots after applying firmware updates. Specifically, these systems are running Intel Broadwell and Haswell CPUs for both client and data center. We are working quickly with these customers to understand, diagnose and address this reboot issue. If this requires a revised firmware update from Intel, we will distribute that update through the normal channels.

To read this article in full, please click here

Read More