Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Wednesday, 17 July 2013

20 years after Windows 3.11, Linus unveils “Linux for Workgroups”

A couple of years ago, Linus Torvalds was discussing Linux version numbers and said, "I think I will call it 3.11 Linux for Workgroups."

It turns out he wasn't joking. With a release candidate of Linux 3.11 now available, Torvalds has actually named the new version of the kernel "Linux for Workgroups." He even gave it a Windows-themed boot icon featuring Linux's mascot penguin, Tux, holding a flag emblazoned with an old Windows logo. The name "Linux for Workgroups" follows such whimsical past Linux version names as "Pink Farting Weasel," "Killer Bat of Doom," "Erotic Pickled Herring," and "Jeff Thinks I Should Change This, But To What?"

The actual code of Linux 3.11, by the way, comes with improved support for Radeon power management features and support for Intel Rapid Start Technology.

Windows for Workgroups 3.11 was released in August, 1993, about two years after Torvalds created the Linux kernel. An update in 1994 allowed Windows for Workgroups to support TCP/IP networking without a third-party add-on.

"I was part of a Windows system install in 1993 for a mid-sized corporation. At that time, Windows 3.11 was wonderful," one commenter on Hacker News wrote today. "People were amazed by it. There were no writable CDs back then (floppies ruled), but it was being researched and people were excited about the huge storage potential. Things have changed a lot since that time, but some things have stayed the same (red black trees are still red black trees). Microsoft is still a heck of a systems programming shop, but back then, they were God. The Linux name change is a fitting tribute to Windows system programmers everywhere."

Windows 3.11 lived a long life, surviving well after the massively popular Windows 95 and even Windows XP. In November 2008, Ars wrote that "Windows for Workgroups 3.11 is finally, officially, totally dead at the age of 15. ... Long after it was supplanted on the desktop by the likes of NT 4.0 and/or Windows 95, Windows for Workgroups 3.11 lived on in the embedded market, powering various point-of-sale terminals, cash registers, and long-haul entertainment systems in certain Virgin and Quantas jets. All of this has come to an end, and Microsoft will no longer sell embedded licenses for the operating system."


View the original article here

Wednesday, 10 July 2013

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Microsoft kicks back $5-$10 to resellers who peddle select Windows 8 hardware

Starting this week, Microsoft will give resellers up to $10 for each device they sell from a list of 21 Windows 8 touch-enabled PCs and tablets, company executives said.

The new program is the latest move by Microsoft to kick up sales, which on the PC side have been downright depressing. Research firm IDC, for instance, has forecast a decline of nearly 8 percent for 2013, and has already hinted that the drop may be even steeper. In tablets, Microsoft has had little luck in making much of an inroad into a market dominated by operating systems built by rivals Apple and Google.

But the selective nature of the incentive program—fewer than two dozen different devices qualify—shows it’s also a continuation of a strategy Microsoft has used since last summer’s launch of the Surface line, when the company said it entered the hardware business to have a platform that really flaunted Windows 8.

Both Tami Reller, the CFO of the Windows division, and Jon Roskill, who heads the firm’s global partner group, talked up the new program, dubbed “TouchWins,” at Microsoft’s Worldwide Partner Conference (WPC) Monday.

“The whole idea is to provide incentives for the commercial channel for featured devices and tablets, PCs and tablets, and through this program we will provide incentives directly to authorized distributors, as well as reseller partners, who sell featured PCs and tablets that have Windows [8] Pro and are touch-enabled,” said Reller during the day’s keynote.

Among Microsoft’s U.S.-based authorized OEM distributors are big-name sellers like Ingram Micro and ASI. Resellers run the size gamut from tiny consultancies to huge outfitters such as CDW.

Later in the presentation, Roskill characterized TouchWins as “pouring gasoline on that touch fire” as he stood in front of a screen that pegged the program’s per-device incentives between $5 and $10.

Twenty-one devices from nine OEMs—Acer, Asus, Dell, Fujitsu, HP, Lenovo, Samsung, Sony and Toshiba—have been tagged as eligible for the cash-back incentives. Acer, for example, sported three qualifying devices: the Aspire S7 touch-based “ultrabook,” which lists for $1,300; and the Iconia W5 and Iconia W7 tablets that sport screens of 10.1-in. and 11.6-in., respectively.

(Each vendor’s eligible devices can be found by clicking on the company logos here.)

The low number of qualifying devices puts TouchWins in the same general category as the Surface and Microsoft’s Signature class of “crapware”-free PCs. Like those lines, TouchWins pushes systems Microsoft believes parade Windows 8’s capabilities. It’s just one more attempt to put the OS’s best possible foot forward, said analyst Carolina Milanesi of Gartner.

TouchWins could also be seen as a stop-gap move, one that takes the best Windows 8 devices available now if, as Milanesi and other analysts expect, by this fall OEMs will have moved to newer processors that deliver much longer battery life—one of the biggest criticisms of current hardware running Windows 8 Pro.

Already-enrolled partners can jump onto the TouchWins program immediately, said Roskill, while others will be able to sign up later this summer.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news.
More by Gregg Keizer, Computerworld


View the original article here

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here