<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>commonIT blog &#187; Mathieu Lafon</title>
	<atom:link href="http://commonit.com/blogs/en/author/mlafon/feed/" rel="self" type="application/rss+xml" />
	<link>http://commonit.com/blogs/en</link>
	<description>stress-free internet</description>
	<pubDate>Tue, 24 Jan 2012 13:32:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
	<language>en</language>
			<item>
		<title>Keeping plug-ins under control</title>
		<link>http://commonit.com/blogs/en/2010/11/16/keeping-plug-ins-under-control/</link>
		<comments>http://commonit.com/blogs/en/2010/11/16/keeping-plug-ins-under-control/#comments</comments>
		<pubDate>Tue, 16 Nov 2010 10:48:42 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[R&amp;D]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[browser security]]></category>

		<category><![CDATA[Java]]></category>

		<category><![CDATA[plug-ins]]></category>

		<category><![CDATA[security patches]]></category>

		<category><![CDATA[software updates]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=521</guid>
		<description><![CDATA[It’s now widely recognized that the browser is one of the leading weaknesses in the enterprise information security environment, increasingly under attack as criminals race to develop exploits for each new vulnerability faster than the browser vendors can patch the problem.
But the problem isn’t limited to the browser itself. The browser hosts mutliple add-ons and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://commonit.com/blogs/fr/files/2010/10/flash_attack.jpg" alt="" width="200" height="200" />It’s now widely recognized that the browser is one of the leading weaknesses in the enterprise information security environment, increasingly under attack as criminals race to develop exploits for each new vulnerability faster than the browser vendors can patch the problem.</p>
<p>But the problem isn’t limited to the browser itself. The browser hosts mutliple add-ons and helper applications in an extremely complex runtime environment to offer the user seamless access to rich media content (PDF, webex, video streaming and so on). These add-on programs have (naturally) their own vulnerabilities. Adobe and Oracle issue frequent updates for their leading browser add-ons, Adobe Acrobat Reader, Adobe Flash Player, and Java. Recently, Microsoft announced that <a title="MMPC and Java attacks" href="http://news.techworld.com/security/3244727/microsoft-points-out-large-increase-in-java-hacker-attacks/" target="_blank">MMPC (Microsoft Malware Protection Center) had blocked over 6 million Java attacks</a> in a single quarter. The problem for the enterprise is that any one of these updates may render the browser environment incompatible with business-critical applications – and it may be practically impossible to back out of the update. To avoid this situation many enterprises now freeze end-user deployments with a specific, tested Java release or service pack level of Microsoft’s Internet Explorer despite the security risks of not running the latest updates.</p>
<p>The winners, in this situation, are the security software vendors, continuously developing new solutions to install on the end-point platform (antivirus, antispyware, anti-malware…), each one slowing the PC down a little more, and mostly incapable of preventing an attack launched against the latest 0-day vulnerability. One way of resolving the problem would be to deploy a separate machine for each application, on every user&#8217;s desktop; isolated and correctly configured, security and performance could be optimized &#8212; for a certain cost. Fortunately for the bottom line, there&#8217;s the <a title="Virtual Browser" href="http://commonit.com/en/technology/overview">Virtual Browser</a> solution.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/11/16/keeping-plug-ins-under-control/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Release 2.1: Improved performance and ease of use</title>
		<link>http://commonit.com/blogs/en/2010/11/05/release-21-improved-performance-and-ease-of-use/</link>
		<comments>http://commonit.com/blogs/en/2010/11/05/release-21-improved-performance-and-ease-of-use/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 10:07:54 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Software release]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[iPad]]></category>

		<category><![CDATA[performance]]></category>

		<category><![CDATA[video]]></category>

		<category><![CDATA[virtual browser]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=515</guid>
		<description><![CDATA[Version 2.1 of the Virtual Browser solution is now available. Among the many enhancements, we&#8217;re particularly proud of the work we&#8217;ve done to improve the way video streaming is handled (already discussed here), with automatic detection of embedded video and data compression optimized in real time. The problem with video is that when page rendering is taking place [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://commonit.com/blogs/fr/files/2010/10/deux-point-un.jpg" alt="" width="189" height="187" />Version 2.1 of the Virtual Browser solution is now available. Among the many enhancements, we&#8217;re particularly proud of the work we&#8217;ve done to improve the way video streaming is handled (<a title="Video streaming" href="http://commonit.com/blogs/en/2010/09/22/improved-support-for-video-streaming-in-virtual-browser/">already discussed here</a>), with automatic detection of embedded video and data compression optimized in real time. The problem with video is that when page rendering is taking place remotely rather than on the user&#8217;s system, the fluidity and continuity of real-time elements such as video can suffer. It&#8217;s important to us that the end-user experience of increasingly dynamic web sites and applications is identical whether they are using Virtual Browser or a classic locally-installed and executing web browser, so we chose to invest significant R&amp;D efforts in the development of new techniques to deliver a superior video delivery mechanism for the Virtual Browser client. Not only have we achieved our objective with release 2.1, we&#8217;ve also dramatically reduced bandwidth requirements, by up to a factor of 10 for certain types of streaming. This is a key breakthrough in its own right as with the rapid uptake of the Apple iPad - a <a title="Virtual Browser iAgent" href="http://itunes.apple.com/app/vb-iagent/id371457965">Virtual Browser iPad client</a> has also been released - the number of users on 3G networks is set to accelerate. With Virtual Browser, any web application, including Flash-based applications and those supported only in IE, is accessible from any end-point device - including Apple&#8217;s.</p>
<p>Other new features in version 2.1 include support for VNC, complementing the already supported Citrix and TSE remote desktop environments. With this technology Virtual Browser can be deployed as a universal telecommute/mobile office environment, delivering remote access to the corporate intranet, web services, virtual desktop environments and even physical desktop systems.</p>
<p>Version 2.1 also offers new levels of flexibility in user interface management. A key feature of the Virtual Browser architecture is that the rendering engine and user interface are separate entities. This means the system administrator can decide what look-and-feel is presented to the user independently of the underlying browser technology and plugins.  For example, with version 2.1 the user can be presented with an Internet Explorer-like user interface while the Virtual Browser appliance is in fact executing Firefox. In the enterprise environment where the slightest change to an application UI can impact productivity as ingrained users habits are challenged, this feature can greatly facilitate application updates and migration while limiting the impact on the end-user population.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/11/05/release-21-improved-performance-and-ease-of-use/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Improved support for video streaming in Virtual Browser</title>
		<link>http://commonit.com/blogs/en/2010/09/22/improved-support-for-video-streaming-in-virtual-browser/</link>
		<comments>http://commonit.com/blogs/en/2010/09/22/improved-support-for-video-streaming-in-virtual-browser/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 07:03:07 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[R&amp;D]]></category>

		<category><![CDATA[compression algorithms]]></category>

		<category><![CDATA[streaming]]></category>

		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=502</guid>
		<description><![CDATA[During the summer a section of the R&#38;D team was tasked with taking a closer look at video support in Virtual Browser.
Up to now Virtual Browser (like most remote display/desktop technologies) managed video display by sequentially transfering a series of static images from the server to the client, a process which consumes an excessive amount [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://commonit.com/blogs/fr/files/2010/09/video.jpg" alt="" width="211" height="141" />During the summer a section of the R&amp;D team was tasked with taking a closer look at video support in <a href="http://commonit.com/en/technology/overview" target="_blank">Virtual Browser</a>.</p>
<p>Up to now Virtual Browser (like most remote display/desktop technologies) managed video display by sequentially transfering a series of static images from the server to the client, a process which consumes an excessive amount of bandwidth, puts an excessive load on the server, and delivers a frequently unsatisfactory result for the end user (jerky films, interruptions, and the like).</p>
<p>This wasn&#8217;t very satisfactory for us either. We attach a lot of importance to the user experience, so we decided to take a closer look at the problem of streaming and remote display technology. Thibault, one of our R&amp;D engineers, analyzed the situation in depth, leading to us developing and implementing two modifications to our solution which will have a significant positive impact on user of experience of video streaming:</p>
<ul>
<li>Dynamic selection of lossy or lossless <a href="http://en.wikipedia.org/wiki/Data_compression" target="_blank">image compression</a> algorithms according to the image type detected (photo/graphic, static/dynamic).</li>
<li>On-the-fly identification of dynamic zones (especially videos) and the generation of an MPEG <a href="http://en.wikipedia.org/wiki/Streaming_media" target="_blank">streaming</a> channel to optimise transfer, instead of transfering sequential static images.</li>
</ul>
<p>These changes are currently under test, and we expect to roll them out with release 2.1 at the end of the month.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/09/22/improved-support-for-video-streaming-in-virtual-browser/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware of social networking in 2010</title>
		<link>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/</link>
		<comments>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 15:35:32 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Cloud computing]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=445</guid>
		<description><![CDATA[Malware researchers at McAfee Labs, the research division of McAfee, have just published their annual report “2010 Threat Predictions”. The browser, unsurprisingly, continues to be the principal vector for attacks, according to the report; the news is that social networking sites are fast becoming the main source of threats.  One simple example: the popularity [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-448" src="http://commonit.com/blogs/en/files/2010/01/109184facebook-virus-175x175.jpg" alt="" width="175" height="175" />Malware researchers at McAfee Labs, the research division of <a href="http://www.mcafee.com/" target="_blank">McAfee</a>, have just published their annual report <a href="http://mcafee.com/us/local_content/white_papers/7985rpt_labs_threat_predict_1209_v2.pdf" target="_blank">“2010 Threat Predictions”</a>. The browser, unsurprisingly, continues to be the principal vector for attacks, according to the report; the news is that <a href="http://en.wikipedia.org/wiki/List_of_social_networking_websites" target="_blank">social networking sites</a> are fast becoming the main source of threats.  One simple example: the popularity of URI shorthands (bit.ly, tinurl.com) to save characters in <a href="http://twitter.com/">Twitter</a> makes it easy to get even the most aware user to click on a “poisoned” link which may download malware or launch a cross-site attack.</p>
<p>The McAfee report also discusses the recent growth in exploits taking advantage of vulnerabilities in helper applications and browser plug-ins such as <a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_blank">Adobe Acrobat</a> and Flash. And they highlight the risk of <a href="http://dev.w3.org/html5/spec/Overview.html" target="_blank">HTML 5.0</a> “blurring and removing the lines between a web application and a desktop application”. The need for the enterprise to <a href="http://www.commonit.com/en/virtualbrowser/" target="_blank">isolate different web usages</a> based on security policies will become increasingly urgent in 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/feed/</wfw:commentRss>
		</item>
		<item>
		<title>And now for version 1.3&#8230;</title>
		<link>http://commonit.com/blogs/en/2009/12/08/and-now-for-version-13/</link>
		<comments>http://commonit.com/blogs/en/2009/12/08/and-now-for-version-13/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 11:01:14 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Cloud computing]]></category>

		<category><![CDATA[Software release]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[new release]]></category>

		<category><![CDATA[virtual browser]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=420</guid>
		<description><![CDATA[Hot on the heels of Virtual Browser version 1.2, version 1.3 is now ready for release. Why are we introducing two versions at so close together? Well, it&#8217;s part of an ambitious product roadmap which leads up to a full rollover to version 2.0 during Q1 2010. Regular intermediate releases help keep us focused, while [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-424" src="http://commonit.com/blogs/en/files/2009/12/logo-vb-fluo1_3-300x165.jpg" alt="" width="300" height="165" />Hot on the heels of Virtual Browser version 1.2, version 1.3 is now ready for release. Why are we introducing two versions at so close together? Well, it&#8217;s part of an ambitious product roadmap which leads up to a full rollover to version 2.0 during Q1 2010. Regular intermediate releases help keep us focused, while fulfilling customer and partner expectations in terms of fast time-to-market for new features and functionality.</p>
<p>Virtual Browser release 1.3 delivers support for transparent authentication modes so that, for example, user authentication for Virtual Browser sessions can be based on Windows logon credentials. On the server side, Virtual Browser can now integrate ICA and RDP clients, opening up a whole new range of possibilities for enterprise deployments.</p>
<p>Looking ahead, the objective is to position Virtual Browser as the universal client for the Cloud Computing era. For the enterprise moving to Cloud-based solutions, Virtual Browser offers a single, centralized point of control for multi-platform access to any web-enabled or virtualized application, wherever it&#8217;s hosted. By integrating support for ICA and RDP clients on the Virtual Browser server, end users can access web applications and Citrix or TSE applications through a single, secure, multiplatform browser interface.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/12/08/and-now-for-version-13/feed/</wfw:commentRss>
		</item>
		<item>
		<title>0-day vulnerablity hits IE6 and IE7</title>
		<link>http://commonit.com/blogs/en/2009/11/30/0-day-vulnerablity-hits-ie6-and-ie7/</link>
		<comments>http://commonit.com/blogs/en/2009/11/30/0-day-vulnerablity-hits-ie6-and-ie7/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 18:26:28 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[0day]]></category>

		<category><![CDATA[IE]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=405</guid>
		<description><![CDATA[Details of a new vulnerability in IE6 and IE7 were published on the internet at the beginning of last week, before Microsoft was aware of the problem. Microsoft has issued a security advisory but has yet to announce an update to correct the problem. Like previous vulnerabilities (see here and here), recommended workarounds and protection [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-407" src="http://commonit.com/blogs/en/files/2009/11/ie_browser_bandaid.jpg" alt="" width="200" height="180" />Details of a <a href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">new vulnerability in IE6 and IE7</a> were published on the internet at the beginning of last week, before Microsoft was aware of the problem. Microsoft has issued a <a href="http://www.microsoft.com/technet/security/advisory/977981.mspx" target="_blank">security advisory</a> but has yet to announce an update to correct the problem. Like previous vulnerabilities (see <a href="http://commonit.com/blogs/en/2009/07/08/ie-activex-zeroday-vulnerability/">here</a> and <a href="http://commonit.com/blogs/en/2009/07/20/browser-updates/">here</a>), recommended workarounds and protection measures place heavy (unrealistic?) demands on users, and the risks remain high &#8212; an attacker can inherit the user&#8217;s access rights on the attacked machine. IE6 and IE7 are still the most widely used browsers on enterprise networks.</p>
<p>It&#8217;s worth remembering that even the most well-informed users can fall victim to a web-based attack. It happened to well-known security expert Gadri Evron, who unwittingly <a href="http://www.darkreading.com/blog/archives/2009/11/new_facebook_wo.html?cid=ref-true">helped propagate a worm</a> on Facebook. While Facebook reacted quickly to the attack, it&#8217;s interesting to note the propagation method was based on <a href="http://en.wikipedia.org/wiki/Clickjacking" target="_blank">clickjacking</a> rather than on XSRF as some early blog posts said.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/11/30/0-day-vulnerablity-hits-ie6-and-ie7/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Announcing Virtual Browser release 1.2</title>
		<link>http://commonit.com/blogs/en/2009/11/25/announcing-virtual-browser-release-12/</link>
		<comments>http://commonit.com/blogs/en/2009/11/25/announcing-virtual-browser-release-12/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 17:07:16 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Software release]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[new release]]></category>

		<category><![CDATA[virtual browser]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=395</guid>
		<description><![CDATA[Just a month after the release of version 1.1, version 1.2 of the Virtual Browser server component is ready for deployment.
The latest release offers improved performance, but more importantly for enterprise deployments multi-server support means that high availability and load balancing features are now available. It&#8217;s also possible to configure individual web sessions so that [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-398" src="http://commonit.com/blogs/en/files/2009/11/logo-vb-fluo1_2-300x185.jpg" alt="" width="300" height="185" />Just a month after <a href="http://commonit.com/blogs/en/2009/09/30/virtual-browser-version-11-is-now-released/">the release of version 1.1</a>, version 1.2 of the Virtual Browser server component is ready for deployment.</p>
<p>The latest release offers improved performance, but more importantly for enterprise deployments multi-server support means that high availability and load balancing features are now available. It&#8217;s also possible to configure individual web sessions so that they are isolated on separate physical servers, optimizing network topologies and performance and further reinforcing application security.</p>
<p>Eagerly awaited by our most demanding users, these new features guarantee continuity of service for Virtual Browser end-users independently of the failsafe mechanisms offered by the underlying platform (the Virtual Browser server is designed for installation in <a title="VMware web site" href="http://www.vmware.com" target="_blank">VMware</a> environment), while also improving scalability, optimizing performance when very large numbers of sessions are open simultaneously.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/11/25/announcing-virtual-browser-release-12/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Virtual Browser version 1.1 is now released</title>
		<link>http://commonit.com/blogs/en/2009/09/30/virtual-browser-version-11-is-now-released/</link>
		<comments>http://commonit.com/blogs/en/2009/09/30/virtual-browser-version-11-is-now-released/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 16:37:22 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Software release]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[OSX]]></category>

		<category><![CDATA[strong authentication]]></category>

		<category><![CDATA[virtual browser]]></category>

		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=357</guid>
		<description><![CDATA[Version 1.1 of the Virtual Browser solution  enhances the product with new features facilitating seamless integration with the enterprise infrastructure:

Strong authentication based on X.509 certificates increases protection for the enterprise and reduces the risk of security being breached by simple password theft from a compromised terminal.
Role-based administrator access ensure that each admin only has [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-358" src="http://commonit.com/blogs/en/files/2009/09/image-1-300x201.png" alt="" width="300" height="201" />Version 1.1 of the Virtual Browser solution  enhances the product with new features facilitating seamless integration with the enterprise infrastructure:</p>
<ul>
<li>Strong authentication based on X.509 certificates increases protection for the enterprise and reduces the risk of security being breached by simple password theft from a compromised terminal.</li>
<li>Role-based administrator access ensure that each admin only has the authority to execute authorised tasks (eg configuration, monitoring, etc).</li>
<li>An IE6 rendering engine provides support for older web-based applications, incompatible with more recent browsers.</li>
<li>Virtual Browser client installations are now available for Apple Macintosh OSX and Linux platforms, in addition to the Microsoft Windows client.</li>
</ul>
<p>Additional minor modifications have been made to improve performance and ease of use, so that Virtual Browser remains the best solution for secure web access in the enterprise.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/09/30/virtual-browser-version-11-is-now-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>0-day vulnerability in Adobe Flash Player</title>
		<link>http://commonit.com/blogs/en/2009/07/24/0-day-vulnerability-in-adobe-flash-player/</link>
		<comments>http://commonit.com/blogs/en/2009/07/24/0-day-vulnerability-in-adobe-flash-player/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 08:32:51 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[0day]]></category>

		<category><![CDATA[adobe]]></category>

		<category><![CDATA[flash]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=317</guid>
		<description><![CDATA[The fourth 0-day vulnerability (after this one and these) in only two weeks has just appeared and it is targeting one of the most used plugins: the Flash Player from Adobe which is used to make web sites visually appealing, to watch videos on YouTube, to play online games, &#8230;
What do we face:

A critical vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>The fourth 0-day vulnerability (after <a title="0-day vulnerability actively exploited in IE" href="http://commonit.com/blogs/en/2009/07/08/ie-activex-zeroday-vulnerability/">this one</a> and <a title="Browser updates" href="http://commonit.com/blogs/en/2009/07/20/browser-updates/">these</a>) in only two weeks <a title="YA0D (Yet Another 0-Day) in Adobe Flash player" href="http://isc.sans.org/diary.html?storyid=6847">has just appeared</a> and it is targeting one of the most used plugins: the <a title="Adobe Flash Platform" href="http://www.adobe.com/flashplatform/">Flash Player</a> from Adobe which is used to make web sites visually appealing, to watch videos on YouTube, to play online games, &#8230;</p>
<p>What do we face:</p>
<ul>
<li><a title="Security advisory for Adobe Reader, Acrobat and Flash Player" href="http://www.adobe.com/support/security/advisories/apsa09-03.html">A critical vulnerability in the Flash player</a> (at least in version 9 and 10) which can be exploited from all browsers and OS when accessing a compromised website (<a title="Drive-by download" href="http://en.wikipedia.org/wiki/Drive-by_download">drive-by attack</a>) or when viewing a malicious PDF using Adobe Acrobat Reader ;</li>
<li>Both exploitation methods have already been seen in the wild ;</li>
<li>No mitigation methods except removing the Flash player or some of its components ;</li>
<li>Javascript desactivation <a title="Heap Spraying with Actionscript" href="http://blog.fireeye.com/research/2009/07/actionscript_heap_spray.html">will not protect against all kind of exploitation</a> ;</li>
<li>Adobe will not release security updates until July 30.</li>
</ul>
<p>What do you do ?</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/07/24/0-day-vulnerability-in-adobe-flash-player/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Browser updates</title>
		<link>http://commonit.com/blogs/en/2009/07/20/browser-updates/</link>
		<comments>http://commonit.com/blogs/en/2009/07/20/browser-updates/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 13:04:13 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[firefox]]></category>

		<category><![CDATA[Google Chrome]]></category>

		<category><![CDATA[IE]]></category>

		<category><![CDATA[safari]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=313</guid>
		<description><![CDATA[Most of the browsers are impacted by security issues in early July.

After the vulnerability in the Video Control component which is still not patched by Microsoft, it is now the Office Web Components Control which is actively exploited on Internet to take ownership of Internet Explorer by executing remode code&#8230; [Microsoft Security Advisory 973472]
Mozilla has [...]]]></description>
			<content:encoded><![CDATA[<p>Most of the browsers are impacted by security issues in early July.</p>
<ul>
<li>After the <a title="0-day vulnerability actively exploited in IE" href="http://commonit.com/blogs/en/2009/07/08/ie-activex-zeroday-vulnerability/">vulnerability in the <em>Video Control component</em></a> which is still not patched by Microsoft, it is now the <em>Office Web Components Control</em> <a title="Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution" href="http://isc.sans.org/diary.html?storyid=6778">which is actively exploited</a> on Internet to take ownership of Internet Explorer by executing remode code&#8230; [<a title="Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/advisory/973472.mspx">Microsoft Security Advisory 973472</a>]</li>
<li>Mozilla has quickly published <a title="Firefox 3.5 Release Notes" href="http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/">Firefox 3.5.1</a> to fix a <a title="Corrupt JIT state after deep return from native function" href="http://www.mozilla.org/security/announce/2009/mfsa2009-41.html">critical vulnerability in the Javascript engine</a> which can be used to execute remote code. Since then, <a title="Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2479">a new vulnerability</a> has been discovered but <a title="milw0rm 9158 “stack overflow” crash not exploitable (CVE-2009-2479)" href="http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/">Mozilla argue that it is not exploitable</a>, it is just a DoS vulnerability&#8230;</li>
<li>Google has published in advance <a title="Google Chrome 2.0.172.37" href="http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.html">a new version (2.0.172.37) of Google Chrome</a> which fix two critical vulnerabilities discovered by the Google security team (not yet public). On these two vulnerabilities, the sandbox technology used by Google is only able to mitigate one&#8230;</li>
<li>Apple has fixed <a title="About the security content of Safari 4.0.2" href="http://support.apple.com/kb/HT3666">two critical vulnerabilities in Safari 4.0.2</a> : cross-site scripting, denial of service and remote code execution&#8230;</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/07/20/browser-updates/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

