Recommended Product
Network Security Audit Software
Network Security Audit Software and Computer Security Tools
  Learn More
 
 
  Network Security Software
Network Bandwidth Monitor

Network Bandwidth Monitor
NBMonitor displays real-time details about your network connections & bandwidth usage.

   
Network Access Monitoring

Network Access Monitoring
ShareAlarmPro monitors network access to shared folders and resources.

   
Product Key Finder
Product Key Finder

Product Key Explorer retrieves over 800 software product keys from network computers.
   
Network Shares Monitoring

Network Share Watcher
Monitors network folders permissions and identify shares which are violating company data access policy.

 
 

Network Security News

Microsoft To Address DLL Load Hijacking Flaw

September 1, 2010

In an update on an ongoing Microsoft investigation into a dynamic-link library (DLL) preloading vulnerability, Microsoft said it would issue security updates to address the vulnerability in its applications. The software giant rated the flaw important because a user would need to click through a series of warnings and dialogs to open a malicious file attempting to exploit the vulnerability.

"DLL preloading is a well-known class of vulnerabilities and we have had guidance for developers in place for quite some time. We have recently updated that guidance to provide more clarity," wrote Jerry Bryant, Microsoft's group manager of response communications in the Microsoft Security Response Center blog. "Even with improved guidance, we recognize that it may take quite a bit of time for all affected applications to be updated and for some an update may not be possible."

The DLL preloading issue surfaced late last month when security researcher and Metasploit architect H.D. Moore, CSO at Rapid7, published details about the DLL load hijacking issue, along with a generic exploit module for the Metasploit framework and an audit kit to identify affected applications on a system. Moore said he published the details after a Slovenian security firm published an advisory about a "binary planting" flaw in iTunes.

Microsoft issued a security advisory Aug. 23, with updated guidance for developers and a new tool that could prevent unsafe DLL loading. In addition a temporary automated patch has been developed to address network-based attack vectors, Microsoft said.

View more news

 
  Most Popular
. Computer Security

. Ethical Hacking

. Windows 7: the untold story of how the enterprise gets snubbed

. Open source identity: Linux founder Linus Torvalds

. FAQ: How to protect your PC against the Downadup worm

. Brocade's new CTO takes aim at Cisco

. Heartland tries to rally industry in wake of data breach

. IBM confirms layoffs

. Apple puts iPhone Nano and Netbook rumors to rest

. Microsoft 'can't imagine' PS3 catching up to Xbox 360
 
 
  Popular Searches
 
 
 

 

Sponsored Links
Network Security Auditor
Nsauditor is a complete networking utilities package that includes more than 45 network tools and utilities for network auditing, scanning,network connections monitoring and more. For more information, please visit:
www.nsauditor.com


Password Recovery Software
SpotAuditor is All-in-one password recovery program that offers administrators and users a comprehensive solution for recovering passwords and other critical business information saved in users' computers. For more information, please visit:
www.password-recovery-software.com

BlueAuditor - Monitor YourBluetooth Network
BlueAuditor detects and monitors Bluetooth devices in a wireless network and allows network administrators to audit wireless networks against security vulnerabilities associated with the use of Bluetooth devices. For more information, please visit:
nsauditor.com/bluetooth_network_scanner.html