<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Microsoft on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/microsoft/</link>
    <description>Recent content in Microsoft on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 12 Feb 2015 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/microsoft/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to go ahead with future end of life Windows (2003) Servers</title>
      <link>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</link>
      <pubDate>Thu, 12 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</guid>
      <description>&lt;p&gt;Server operating systems with an OS, for which vendor support has ended, come with many risks that have to be considered and addressed. The primary goal should be always to decommission or migrate the majority of end-of-life (EoL) servers to OS versions, supported by the vendor. Here it should be noted that a migration to an up-to-date OS should be preferably done before your organization enters the end of life of that software 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Windows Update over IPv6 (or not?)</title>
      <link>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</link>
      <pubDate>Wed, 21 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I recently stumbled over a &lt;a href=&#34;http://technet.microsoft.com/en-us/network/hh994905.aspx&#34;&gt;document&lt;/a&gt; from Microsoft which lists all services/applications that support IPv6. Most of the content wasn’t new for me, but one item caught my attention. &lt;em&gt;Windows Update&lt;/em&gt;. I haven’t heard before that Windows Update can be done over IPv6 (but this could just be me not looking hard enough ;)), so I was eager to test it out seeing if this is really the case. I was also curious why Microsoft referenced this &lt;a href=&#34;http://blogs.msdn.com/b/b8/archive/2012/06/05/connecting-with-ipv6-in-windows-8.aspx&#34;&gt;document&lt;/a&gt; in the respective column.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EMET v4.0 with New Certificate Trust Feature Released</title>
      <link>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</link>
      <pubDate>Mon, 01 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</guid>
      <description>&lt;p&gt;Microsoft released &lt;a href=&#34;http://www.microsoft.com/en-us/download/details.aspx?id=39273&#34;&gt;EMET v4.0&lt;/a&gt;  with a new (security) feature that enables protection against fraudulent websites or compromised root certification authorities (do you remember Comodo, DigiNotar, DigiCert, Turktrust et al. ;-)?)&lt;/p&gt;&#xA;&lt;p&gt;EMET defines via “certificate trust“ a trust chain between the domain name of a website (and its associated website certificate) and a root CA certificate. This is done through so called “pinning rules”. Here is one of the default pinning rules of EMET 4.0 for the domain name &lt;em&gt;login.live.com&lt;/em&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Doc “Best Practices for Securing Active Directory”</title>
      <link>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</link>
      <pubDate>Wed, 05 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;MS just &lt;a href=&#34;http://blogs.technet.com/b/security/archive/2013/06/03/microsoft-releases-new-mitigation-guidance-for-active-directory.aspx&#34;&gt;released&lt;/a&gt; a new guide on securing Active Directory. At the first glance seems a fairly comprehensive document to me.&lt;/p&gt;&#xA;&lt;p&gt;At this occasion I may furthermore draw your attention to our (German language) &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/ERNW_Newsletter_40_AD_SRV2008R2_BSI_compliant_de_signed.pdf&#34;&gt;newsletter no. 40&lt;/a&gt; covering hardening MS Windows Server 2008 + AD.&lt;/p&gt;&#xA;&lt;p&gt;have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Update: Microsoft Advisory 2757760 Windows Internet Explorer Vulnerability</title>
      <link>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</link>
      <pubDate>Thu, 20 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</guid>
      <description>&lt;p&gt;Microsoft takes this vulnerability quite serious and was acting fast. The Microsoft Security Response Center announced the availability of a fix last night in the &lt;a href=&#34;http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx&#34;&gt;MSRC Blog&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The fix will be available via Windows Update on friday, the 21st of september. So it’s time to get ready for this update ;-).&lt;/p&gt;&#xA;&lt;p&gt;Have a nice day&lt;br&gt;&#xA;Michael&lt;/p&gt;</description>
    </item>
    <item>
      <title>MS10-063, Prevention</title>
      <link>https://insinuator.net/2010/09/ms10-063-prevention/</link>
      <pubDate>Wed, 15 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/ms10-063-prevention/</guid>
      <description>&lt;p&gt;One of the four vulnerabilities rated “critical” from yesterday’s MS patchday, that is &lt;a href=&#34;http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx&#34;&gt;MS10-063&lt;/a&gt;, has an interesting “Workarounds” section as for MS Internet Explorer. There it’s stated:&lt;/p&gt;&#xA;&lt;p&gt;“Disabling the support for the parsing of embedded fonts in Internet Explorer prevents this application from being used as an attack vector.”&lt;/p&gt;&#xA;&lt;p&gt;which, according to the advisory, should/can be done by setting the “Font Downloading” parameter to “Disable”.&lt;/p&gt;&#xA;&lt;p&gt;Which is exactly what &lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1497/download1499/ERNW_Newsletter_31_Secure_IE8_Configuration_en_ger.pdf&#34;&gt;this document&lt;/a&gt; suggests. So taking a preventive approach, once more, might have saved some concerns (“Will we be targeted by this one”) and patch/testing time…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Just a Quick Note on the Library Loading / Binary Planting Stuff</title>
      <link>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</link>
      <pubDate>Tue, 24 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</guid>
      <description>&lt;p&gt;For those of you who missed it: Microsoft released the &lt;a href=&#34;http://www.microsoft.com/technet/security/advisory/2269637.mspx&#34;&gt;associated advisory&lt;/a&gt; yesterday, together with a &lt;a href=&#34;http://support.microsoft.com/?kbid=2264107&#34;&gt;hotfix&lt;/a&gt; introducing a new registry key that allows users to control the DLL search path algorithm. For a detailed explanation of the problem we refer to &lt;a href=&#34;http://arstechnica.com/microsoft/news/2010/08/new-windows-dll-security-flaw-everything-old-is-new-again.ars&#34;&gt;the excellent article on Ars Technica&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For the record: no, AV (anti-virus software) will – in most cases – not protect you from security problems related to this one. And, no, there is no easy patch for this one either.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
