Showing posts with label Microsoft mcitp certification. Show all posts
Showing posts with label Microsoft mcitp certification. Show all posts

Thursday, November 10, 2011

Microsoft patches critical Windows 7 bug, downplays exploit threat

Microsoft today delivered four security updates that patched four vulnerabilities in Windows, most of them affecting the newer editions of Vista and Windows 7.

MCTS Certification, MCITP Certification
Cisco CCNA Training, Cisco CCNA Certification 2000+ Exams at Examkingdom.com



Only one of the updates was marked "critical," Microsoft's most-serious threat ranking. Two of the remaining were labeled "important" and the fourth was tagged as "moderate."

As expected, Microsoft did not patch the Windows kernel vulnerability exploited by the Duqu campaign.

Top on Microsoft's chart today -- and on outside researchers' to-do lists as well -- was the MS10-083 update that patches a bug in Windows Vista's, Windows 7's and Server 2008's TCP/IP stack, which regulates Internet connections.

The vulnerability could be used by attackers in certain circumstances to hijack an unpatched PC, said Microsoft, which nevertheless downplayed the likelihood of successful attacks.

"This critical bug allows an attack via the network, and looks troublesome at first glance," said Andrew Storms, director of security operations at nCircle Security. "But it doesn't look very easy to pull off, so in this case, it's not as big a concern as one would think."

Storms pointed to a post by Microsoft engineers on the Security Research & Defense blog that spelled out the necessary conditions for an effective attack.

"We believe it is difficult to achieve [remote code execution] using this vulnerability considering that the type of network packets required are normally filtered at the perimeter and the small timing window ... and [that] a large number of packets are required to pull off the attack," wrote Ali Rahbar and Mark Wodrich of the Microsoft Security Response Center (MSRC).

Microsoft gave the vulnerability an exploitability index rating of "2," meaning that it expects only unreliable exploit code to appear in the next 30 days.

Even so, some researchers warned that if criminals focused their attention on the bug, they may be able to craft a consistent exploit that could be used to launch worm-based attacks.

Microsoft also updated Windows Mail and Windows Meeting Space on Vista, Windows 7 and Server 2008 to fix yet another "DLL load hijacking" vulnerability.

DLL load hijacking, sometimes called "binary pre-loading," describes a class of bugs first revealed in August 2010. Microsoft has been patching its software to fix the problem -- which can be exploited by tricking an application into loading a malicious file with the same name as a required dynamic link library, or DLL -- since last November.

Today's MS11-085 update was the eighteenth Microsoft has issued to fix DLL load-hijacking vulnerabilities in its software.

"They're a dime-a-dozen these days," said Storms of the latest in the long-running series.

Researchers also noted that while Microsoft did not patch the Duqu-exploited bug, it did fix a different flaw in the TrueType font parsing engine, the component targeted by the Trojan's attacks.

MS11-084 fixes a single vulnerability in the Windows kernel-mode driver "Win32k.sys" that can be exploited through a malformed TrueType font file.

"We're see a pattern of kernel-level bugs and parsing of font files," said Storms. "And they're going to have to come back and patch this again for Duqu."

Microsoft patched the TrueType engine within Win32k.sys just last month, fixing a flaw that let hackers conduct denial-of-service attacks to cripple Windows PCs. Today's bug was also categorized as a denial-of-service flaw.

In lieu of a fix, Microsoft last week told customers that they could defend their systems by blocking access to "t2embed.dll," the dynamic link library that handles embedded TrueType fonts.

An advisory offered command-prompt strings IT administrators can use to deny access to t2embed.dll, and links to one of Microsoft's "Fix-it" tools that automate the process of blocking or unblocking access to the library.

Blocking t2embed.dll, however, has side effects: Applications, including Web browsers, applications in Microsoft's Office suite and Adobe's Reader, may not render text properly.

Microsoft also updated that advisory today with a link to a list of its antivirus partners that have issued signatures to detect the kernel-based Duqu attacks.

November's security patches can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

Tuesday, November 1, 2011

Study: User tools to limit ad tracking are clunky

People who want to limit the behavioral advertising and tracking they are subjected to on the Web aren't well served by some popular privacy tools, according to a Carnegie Mellon University study.

MCTS Certification, MCITP Certification
Cisco CCNA Training, Cisco CCNA Certification 2000+ Exams at Examkingdom.com



Researchers concluded that the tools evaluated in the study, which included IE and Firefox components, were generally too complicated and confusing, leading people to misuse them.

"We found serious usability flaws in all nine tools we examined," reads the 38-page report, released on Monday.

The nine tools fall into three main categories: tools that block access to advertising websites; tools that create cookies that indicate users want to opt out of behavioral advertising; and privacy tools built into web browsers.

The researchers enlisted 45 people to try out the tools. The participants weren't technical experts, nor were they knowledgeable about privacy tools, but did have an interest in this type of tools.

Each tool was tried out by five participants. Researchers observed how participants installed and configured the tools, and recorded the users' perceptions and opinions.

"None of the nine tools we tested empowered study participants to effectively control tracking and behavioral advertising according to their personal preferences," the researchers wrote.

Tools for creating opt-out cookies give users a laundry list of ad networks with little or no additional information for users to decide which ones to block.

As a result, users generally opted to block all ad network trackers instead of making informed decisions on a per-company basis, the researchers found.

Another problem: the default settings for most tools were "inappropriate" because they come out-of-the-box with most protections turned off, putting the onus on users to activate and configure them.

A related issue is that the tools do a poor job of explaining to users how they work and how they should be configured, presenting information in terms that were either too simplistic or too technical.

And once configured, the tools didn't clearly communicate to users what they were doing, particularly when they blocked specific content and functionality in websites users were visiting.

The design of the user interfaces also contributed to the users' confusion and inability to properly use the tools, according to the study.

"Our results suggest that the current approach for advertising industry self-regulation through opt-out mechanisms is fundamentally flawed," the researchers wrote.

The tools evaluated by the study are DAA Consumer Choice from the Digital Advertising Alliance; Global Opt-Out and Ghostery 2.5.3, both from Evidon; Privacy Choice's PrivacyMark; TACO 4.0 from Abine; Adblock Plus 1.3.9; Mozilla Firefox 5's privacy panel; and Microsoft IE9's privacy controls and Tracking Protection mechanism.

Rob Shavell, co-founder of Abine, agrees with the researchers' general conclusion.

"People need easier-to-use tools," said Shavell, adding that Abine is working hard to make TACO (Targeted Advertising Cookie Opt-out) simpler.

"We'll get there. We'll create an awesome product," he said in a phone interview. "We're making it easier every day."

There is an ongoing discussion among privacy software vendors, online advertising providers and government regulators about simplifying tools and processes for consumers so that they can more easily control online behavioral ad tracking, such as through the proposed Do Not Track standard, Shavell said.

Complicating matters is that interest among consumers in tools that offer control over online tracking is fairly new, so users aren't generally familiar with this type of software, he said.

A spokeswoman for Microsoft said the Tracking Protection feature in IE9 lets users add "an industry curated" tracking protection list with one click.

"Tracking Protection Lists offers consumers an opt-in mechanism to identify and block many forms of undesired tracking," she said via e-mail.

These lists, compiled by third-party organizations with expertise in this field, let users control which third-party site content can track them when they're online, and they can be designed to either "block" or "allow" certain third party content, she said.

"IE9 also includes the broadly discussed Do Not Track User Preference -- via both a DOM property and an HTTP header, as described in the W3C submission -- as a secondary method," she added.

Scott Meyer, founder and CEO of Evidon, said his company's products aim to create "transparency," not just opt-out mechanisms.

"Transparency enables consumers to make more informed decisions, and the fact is that the vast majority choose not to opt-out when presented with more information," he said in an e-mailed statement. "Our research ... shows that 67 percent of consumers feel more positive about brands which give them this level of transparency and control."

Jim Brock, Privacy Choice's CEO and founder, said independent tests such as the one from Carnegie Mellon are very valuable, even if they are subjective, and Privacy Choice will take the findings into account.

However, Privacy Choice's principal blocking service for consumers is TrackerBlock, which the Carnegie Mellon researchers didn't include in the study, and not PrivacyMark, he said via e-mail.

In addition, internal surveys at Privacy Choice reveal that more than 75 percent of PrivacyMark users understand what the service does and would recommend it to a friend, he said.

Friday, October 21, 2011

Microsoft staffing secretive Windows Phone project

Microsoft is working on a secretive new project in its Windows Phone division, according to a job description it posted over the weekend.

MCTS Certification, MCITP Certification
Best Comptia A+ Training | Comptia A+ Certification 2000+ Exams at Examkingdom.com



The description, for a software development engineer in test, gives few hints about the project.

"We are a team working on a top secret project inside the Windows Phone division. Our mission...GO BIG! DISRUPT THE MARKET!" the job description reads.

The advertisement says the project involves the first version of a new feature set and the group will complete planning for the features in a month.

"We can't give you many details on this [job description], but I can assure you we have a passionate group of engineers charged and ready to take on the challenge," the ad reads.

The Windows Phone News blog first spotted the ad, which is running on Microsoft's website and on LinkedIn.

One analyst suspected there's not much of a secret behind the job description. "I am going to go out on a limb and guess that the manager who put up this hurried [job description] used a template from early last year before they went public with the Windows Phone 7 UI (in March 2010)," said Al Hilwa, an analyst with IDC.

However, Microsoft could be developing new capabilities that it hopes will set Windows Phone apart from the competition. Microsoft lags behind market leaders Google, Apple and Research In Motion, and some unique new features could help Microsoft expand its market share.

According to comScore, Microsoft's market share in smartphones dipped to 5.8 percent in May, down from 7.7 percent in February.

Monday, September 26, 2011

3 ways SMBs can avoid being ambushed as cloud pioneers

When it comes to cloud adoption, midsize companies are ahead of big businesses. That means they will take some chances as they migrate to this technology delivery model.

MCTS Certification, MCITP Certification
Best Comptia A+ Training | Comptia A+ Certification 2000+ Exams at Examkingdom.com



Research firm Gartner published some new data this week suggesting that at least 10 percent of email and cloud applications within what it calls enterprise accounts will be using a cloud-based version of said technology by 2014. That actually is much slower than anticipated by about two years, because of things like corporate inertia, a focus on the strategic, and (realistically) concerns over the feature sets of some of their options.

Ho-hum.

Among small and midsize businesses, however, adoption rates continue to be much higher. Exhibit A is a study released earlier this year by Microsoft, which is attempting to recast itself as a bonafide cloud service provider after years in the on-premise world. The study, SMB Cloud Adoption Study 2011, found that almost 40 percent of SMBs expect to be paying for one or more cloud service within the next three years, compared with the approximately 29 percent who do so today.

The survey found that 82 percent of SMBs buying cloud services feel that a local presence offered by their cloud service provider is important. Read: they don’t want everything to be remote because they like having someone able to work through issues on site. When it comes to size, companies with 51 to 250 employees appear to benefit most from cloud technology options; 56 percent of this respondent base said they expect to pay for an average of 3.7 services within three years.

The MIcrosoft research was fielded among 3,258 SMBs worldwide in conjunction with Edge Strategies. The actual survey was fielded in December 2010.

Exhibit B in terms of SMB cloud adoption data comes from CompTIA, the technology advocacy organization. CompTIA’s third annual study of SMB adoption trends released over the summer of 2011 suggests that this community can be classified as an early adopter when it comes to cloud-based infrastructure and applications. SMBs’ top three reasons for giving love to this model:

Expand capabilities
Lower total cost of ownership
Gain access to more/better features

In short, small businesses can look much larger and more innovative through cloud infrastructure while saving money. What’s not to like?

Little wonder, then, that the CompTIA survey found one-third of the roughly 600 companies surveyed were using some sort of cloud applications — from infrastructure as a service (IaaS) to software as a service (SaaS). Here are the top five applications that smaller companies were moving to the cloud (along with the percentage of cloud-friendly companies using this sort of application):

Storage/backup = 71 percent
Email = 62 percent
Document management = 59 percent
Collaboration = 56 percent
CRM = 53 percent

One big red flag, though.

The CompTIA survey reported that among those SMBs that have moved part of their infrastructure to the cloud, approximately one-third have found the transition to be more costly or difficult than expected. What’s more, here are their top five concerns when considering the transition:

Security
Reliability of cloud provider
Reliability of internal internet connection
Integration with current systems
Long-term pay-as-you-go model

The reality is that very few companies will ever be “pure cloud,” which means that SMBs — especially because they ARE pioneers — could experience some hurdles as they migrate some applications to the cloud. That’s especially true because there really aren’t that many “best practices” that have been established, so far. WIth that in mind, here are three ways small businesses can protect themselves if they choose to try cloud services sooner rather than later:

Pay particular attention to integration implications. That might mean hiring an independent expert who can assess where cloud services might fit within your business infrastructure; and that can offer expertise in ensuring that cloud applications tie into on-premise applications seamlessly.
Battle-test network infrastructure. SMBs are right to worry about security and bandwidth, so they should ensure that connections are in order before committing to a cloud application that could affect productivity. They should also explore how the service being evaluated handles tasks offline. And, while I’m listing things to worry about, they should assess how to handle sign-in. Will employees need to first sign into a secure connection and then into the cloud application or will it be accessible from everywhere?
Understand service level agreements and contract terms. Small businesses should really spend time to consider what is included and what is not with a cloud service contract. Does the length of the contract make sense or will you be locked into something too long? How quickly does the cloud provider promise that interruptions will be fixed and does it have the wherewithal to deliver that? Speaking of which, will your organization get true 24×7 support or will it be confined to asking questions during “traditional” business hours. Whatever they are.

Any additional tips that some of you early cloud adopters would like to share? Have at it.

Wednesday, September 14, 2011

CompTIA: IT business confidence up

Members of the U.S. IT sector are more confident now in their business prospects than they have been in the last year and a half, according to a new survey released by the Computing Technology Industry Association.

The CompTIA IT Industry Business Confidence Index -- measuring IT managers' and workers' confidence in their own industry, their own companies and the U.S. economy -- stood at 60 in December, the trade group said. The index, based on a survey of more than 1,100 IT workers and managers, asks respondents to rate their confidence in those three areas on a 100-point scale.

MCTS Certification, MCITP Certification
Best Comptia A+ Training | Comptia A+ Certification 2000+ Exams at Examkingdom.com




CompTIA launched the index in June 2009, and December's confidence numbers in the U.S. were the highest in the history of the index.

Global IT spending should grow by 4% in 2011, CompTIA predicted.

The U.S. index was up seven points between September and December, while the global index was up eight points, to 64. The confidence index was highest in Brazil and India, at 75, while it was lowest in the U.S. and South Africa among eight countries indexed.

CompTIA predicted that the confidence index will rise again in the next quarter.

"After several quarters of lackluster performance, an improving CompTIA confidence index should be welcome news to companies eager for economic stability," Tim Herbert, vice president of research for CompTIA, said in a statement.

U.S. IT workers and managers -- 41% of respondents were senior to executive management -- expressed most confidence in the IT industry and in their own companies. Confidence in the U.S. economy remained below 50 on the 100-point scale.

Forty-five percent of U.S. IT firms are planning to increase spending on new products and business lines over the next half year, and 43% plan technology-related investments, an increase of 10 percentage points from September, CompTIA said. Thirty-two percent of U.S. IT companies said they planned to increase hiring over the next six months, compared to 37% in September, the survey said.

Employment trends are "still cause for concern," Herbert said.

Worldwide, 52% of IT firms plan to increase spending on new product lines, and 51% plan to increase spending on technology. "With renewed market stability and optimism, businesses will likely start spending a bit more freely," the study said.

A number of factors could "potentially derail or minimize growth," the study said. IT executives remain concerned about weak consumer spending, government regulation and unexpected economic shocks such as increased oil prices, the study said.

Pent-up demand for IT products and services, along with strong sales in emerging markets and industries such as health care, will help the IT industry grow this year, CompTIA predicted. However, consumers could seek low-cost options for their IT products, resulting in high growth in unit sales, but modest revenue growth, the trade group said.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross.

Friday, September 9, 2011

Can simulations fill the gap in 21st century ed?

While plenty of schools offer solid computer science training and certification programs, this can be resource intensive and costly in terms of both the necessary hardware instructional expertise required…can simulation software fill the gap?

MCTS Certification, MCITP Certification
Cisco CCNA Training, Cisco CCNA Certification 2000+ Exams at Examkingdom.com




Whether students live in rural areas, are home-schooled, are exceeding what their schools can offer for coursework, or their schools simply lack technical education resources, a majority of young people struggle to find relevant courses in technology education. While plenty of schools offer solid computer science training and certification programs, this can be resource intensive and costly in terms of both the necessary hardware instructional expertise required.

One rural high school in Walla Walla, Washington (yes, it’s really called Walla Walla, Washington; I’ve been there and it may have a funny name, but there’s nothing like a Walla Walla sweet onion), turned to simulation software to fill the gap in the courses they were able to offer and the skills they were able to impart. Using LabSim software (available both online and locally installed), the school was immediately able to begin running certification programs in A+, Network+, Security+, CCNA and MCSA.

In a town where graduation rates are low, college placement is lower, and unemployment is relatively high, relevant, rigorous vocational programs are a must. Distance learning and “virtual high school” programs, dual enrollment with local community colleges, apprenticeships, and internships can all supplement limited resources. However, LabSim does provide an interesting alternative that can address needs both at the high school, trade school, and community college/post-secondary level.

According to their website,

Learning is doing, and the only way to master a skill is through practical application. The online labs in LabSim give your students the tools they need to truly master essential skills. And learning correctly means allowing them to make mistakes; which is why we developed online labs that allow students to experience a virtual environment where they can explore all the functionality of the application they’re learning.

Course materials include instructional videos, tests and evaluations, as well as simulations ranging from virtual computer repair to sandboxed Linux OS simulations for teaching systems administration skills. As the instructors in Walla Walla found, a hybrid approach of in-class teaching and LabSim work allowed them to reduce their hardware and system needs substantially since much more of the work was simulated.

While the technology and simulations are fairly impressive (and would be a great choice for schools and students who might not otherwise have ready access to full labs or experienced instructors with IT certification backgrounds), they don’t come cheap. You can download a free trial of the Windows-only software here (most courses are now available online, as well). However, courses run on the order of $500 for a single-user license. A single user is literally a single user: once a student has completed the course, the software can’t be used for another student.

The company does offer multi-user licensing for schools including 3-year licensing deals that allow re-use of the software. They will assemble custom quotes, but even with expected savings of up to 50% with multi-user options, costs can still add up quickly.

Update as of 6:45, October 16th: The PR folks who originally contacted me about LabSim clarified pricing structures. Higher education students are eligible for up to 80% discounts over the list price on single user courseware. Thus, students in post-secondary education can access these courses for around $50 a piece, increasing the value proposition significantly. In high schools, LabSim offers site licensing that allows full classes to use the courseware. For the cost of that option, schools will need to contact the company directly. The 50% savings noted above, by the way, is the savings that organizations can realize by offering training for multiple staff members; these costs are outside of their educational pricing.

Schools will need to evaluate whether simulations can meet their needs at lower costs than certified staff and full lab implementations. I’m inclined to believe that’s the case. I’m also inclined to believe that simulations like these are useful as one-offs for students who want to explore coursework that their schools can’t support due to limited funding or interest. In the case of vocational technical schools, though, where well-qualified staff are easier to find and funding for true hands-on, experiential learning is a priority, LabSims will be a harder sell.

Based on the updated pricing above, have my thoughts on LabSims changed? A little bit. As I noted (even at the higher prices), the cost of these programs drastically undercuts staff with significant technical expertise. I also still believe that LabSims can bridge important gaps in public education and even some post-secondary settings where human and physical resources are lacking. However, in vocational-technical settings, these should probably be limited to supplemental materials used in conjunction with hands-on, lab-based learning. When they are supplements, then school IT decision-makers still need to carefully weigh their value, regardless of cost, just as they would any classroom materials they supply to students and teachers.