<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>commonIT blog &#187; security</title>
	<atom:link href="http://commonit.com/blogs/en/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://commonit.com/blogs/en</link>
	<description>stress-free internet</description>
	<pubDate>Tue, 24 Jan 2012 13:32:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
	<language>en</language>
			<item>
		<title>Developing OEM partnerships</title>
		<link>http://commonit.com/blogs/en/2010/10/15/developing-oem-partnerships/</link>
		<comments>http://commonit.com/blogs/en/2010/10/15/developing-oem-partnerships/#comments</comments>
		<pubDate>Fri, 15 Oct 2010 10:55:23 +0000</pubDate>
		<dc:creator>Albino Pili</dc:creator>
		
		<category><![CDATA[channel]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[Hermitage Solutions]]></category>

		<category><![CDATA[mobility]]></category>

		<category><![CDATA[OEM]]></category>

		<category><![CDATA[partnerships]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=507</guid>
		<description><![CDATA[The Virtual Browser solution offers an excellent alternative to traditional VPN-based technologies for remote access to web-based applications or remote desktop (Citrix/TSE) environments, or even for connection to the office PC. Virtual Browser delivers higher performance and security, and it&#8217;s simpler and less costly.
To accelerate the uptake of Virtual Browser as a solution for mobile [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://commonit.com/blogs/fr/files/2010/09/mobilite_site-300x178.jpg" alt="" width="300" height="178" />The Virtual Browser solution offers an excellent alternative to traditional VPN-based technologies for remote access to web-based applications or remote desktop (Citrix/TSE) environments, or even for connection to the office PC. Virtual Browser delivers higher performance and security, and it&#8217;s simpler and less costly.</p>
<p>To accelerate the uptake of Virtual Browser as a solution for mobile and remote access, we&#8217;ve developed an OEM partnership program for security and mobility solutions vendors. OEM partners will be able to offer Virtual Browser technology under their own brand, with pricing adapted to their business model.</p>
<p>The solution is delivered using the SaaS model, hosted on our own servers or on the OEM partner&#8217;s infrastructure, with technical support from commonIT. Our objective is to make Virtual Browser available to the largest possible user population through partnering with software and hardware developers for whom the solution represents an opportunity to add value and generate new revenue streams in a market where demand is strong.</p>
<p class="MsoNormal">In addition to the <a title="Cyberdefense offering" href="http://commonit.com/blogs/en/2010/09/16/hermitage-solutions-integrates-commonit-technology-in-its-cyberdefense-offering/">recently announced partnership</a> with Hermitage Solutions, we are currently in discussion with three other potential partners in Europe; we hope to see the results early in the new year. For more about the OEM program contact us at <a href="mailto:oem@commonit.com">oem@commonit.com</a>.</p>
<p class="MsoNormal">
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/10/15/developing-oem-partnerships/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware of social networking in 2010</title>
		<link>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/</link>
		<comments>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 15:35:32 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[Cloud computing]]></category>

		<category><![CDATA[commonIT]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=445</guid>
		<description><![CDATA[Malware researchers at McAfee Labs, the research division of McAfee, have just published their annual report “2010 Threat Predictions”. The browser, unsurprisingly, continues to be the principal vector for attacks, according to the report; the news is that social networking sites are fast becoming the main source of threats.  One simple example: the popularity [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-448" src="http://commonit.com/blogs/en/files/2010/01/109184facebook-virus-175x175.jpg" alt="" width="175" height="175" />Malware researchers at McAfee Labs, the research division of <a href="http://www.mcafee.com/" target="_blank">McAfee</a>, have just published their annual report <a href="http://mcafee.com/us/local_content/white_papers/7985rpt_labs_threat_predict_1209_v2.pdf" target="_blank">“2010 Threat Predictions”</a>. The browser, unsurprisingly, continues to be the principal vector for attacks, according to the report; the news is that <a href="http://en.wikipedia.org/wiki/List_of_social_networking_websites" target="_blank">social networking sites</a> are fast becoming the main source of threats.  One simple example: the popularity of URI shorthands (bit.ly, tinurl.com) to save characters in <a href="http://twitter.com/">Twitter</a> makes it easy to get even the most aware user to click on a “poisoned” link which may download malware or launch a cross-site attack.</p>
<p>The McAfee report also discusses the recent growth in exploits taking advantage of vulnerabilities in helper applications and browser plug-ins such as <a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_blank">Adobe Acrobat</a> and Flash. And they highlight the risk of <a href="http://dev.w3.org/html5/spec/Overview.html" target="_blank">HTML 5.0</a> “blurring and removing the lines between a web application and a desktop application”. The need for the enterprise to <a href="http://www.commonit.com/en/virtualbrowser/" target="_blank">isolate different web usages</a> based on security policies will become increasingly urgent in 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2010/01/12/beware-of-social-networking-in-2010/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Browser updates</title>
		<link>http://commonit.com/blogs/en/2009/07/20/browser-updates/</link>
		<comments>http://commonit.com/blogs/en/2009/07/20/browser-updates/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 13:04:13 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[firefox]]></category>

		<category><![CDATA[Google Chrome]]></category>

		<category><![CDATA[IE]]></category>

		<category><![CDATA[safari]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=313</guid>
		<description><![CDATA[Most of the browsers are impacted by security issues in early July.

After the vulnerability in the Video Control component which is still not patched by Microsoft, it is now the Office Web Components Control which is actively exploited on Internet to take ownership of Internet Explorer by executing remode code&#8230; [Microsoft Security Advisory 973472]
Mozilla has [...]]]></description>
			<content:encoded><![CDATA[<p>Most of the browsers are impacted by security issues in early July.</p>
<ul>
<li>After the <a title="0-day vulnerability actively exploited in IE" href="http://commonit.com/blogs/en/2009/07/08/ie-activex-zeroday-vulnerability/">vulnerability in the <em>Video Control component</em></a> which is still not patched by Microsoft, it is now the <em>Office Web Components Control</em> <a title="Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution" href="http://isc.sans.org/diary.html?storyid=6778">which is actively exploited</a> on Internet to take ownership of Internet Explorer by executing remode code&#8230; [<a title="Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/advisory/973472.mspx">Microsoft Security Advisory 973472</a>]</li>
<li>Mozilla has quickly published <a title="Firefox 3.5 Release Notes" href="http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/">Firefox 3.5.1</a> to fix a <a title="Corrupt JIT state after deep return from native function" href="http://www.mozilla.org/security/announce/2009/mfsa2009-41.html">critical vulnerability in the Javascript engine</a> which can be used to execute remote code. Since then, <a title="Mozilla Firefox Unicode Data Remote Denial of Service Vulnerability" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2479">a new vulnerability</a> has been discovered but <a title="milw0rm 9158 “stack overflow” crash not exploitable (CVE-2009-2479)" href="http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/">Mozilla argue that it is not exploitable</a>, it is just a DoS vulnerability&#8230;</li>
<li>Google has published in advance <a title="Google Chrome 2.0.172.37" href="http://googlechromereleases.blogspot.com/2009/07/stable-beta-update-bug-fixes.html">a new version (2.0.172.37) of Google Chrome</a> which fix two critical vulnerabilities discovered by the Google security team (not yet public). On these two vulnerabilities, the sandbox technology used by Google is only able to mitigate one&#8230;</li>
<li>Apple has fixed <a title="About the security content of Safari 4.0.2" href="http://support.apple.com/kb/HT3666">two critical vulnerabilities in Safari 4.0.2</a> : cross-site scripting, denial of service and remote code execution&#8230;</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2009/07/20/browser-updates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The perfectly secure browser doesn&#8217;t exist</title>
		<link>http://commonit.com/blogs/en/2008/12/17/the-perfectly-secur-browser-doesnt-exist/</link>
		<comments>http://commonit.com/blogs/en/2008/12/17/the-perfectly-secur-browser-doesnt-exist/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 12:50:49 +0000</pubDate>
		<dc:creator>Mathieu Lafon</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[IE]]></category>

		<guid isPermaLink="false">http://commonit.com/blogs/en/?p=166</guid>
		<description><![CDATA[A few months ago, Window Snyder (Chief Security Officer at Mozilla Corporation), in an interview for Computerworld, explained that it is impossible to build a perfectly secure browser. Reading the Browser Security Handbook published a few days ago by Google helps us understand why this is the case.  And when the browser is required [...]]]></description>
			<content:encoded><![CDATA[<p>A few months ago, <a title="Window Snyder" href="http://en.wikipedia.org/wiki/Window_Snyder">Window Snyder</a> (Chief Security Officer at Mozilla Corporation), in an <a title="Mozilla security chief outlines plan to protect Firefox users" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9060862">interview for Computerworld</a>, explained that it is impossible to build a perfectly secure browser. Reading the <a title="Browser Security Handbook" href="http://code.google.com/p/browsersec/wiki/Main"><em>Browser Security Handbook</em></a> published a few days ago by Google helps us understand why this is the case. <img class="alignright size-thumbnail wp-image-168" src="http://commonit.com/blogs/en/files/2008/12/malware-150x150.jpg" alt="" width="150" height="150" /> And when the browser is required to support more and more file formats, the number of potential vulnerability sources is more and more important.</p>
<blockquote><p>&#8220;It&#8217;s impossible to build a perfectly secure browser&#8221; &#8212; Window Snyder</p></blockquote>
<p>And then last week we learnt that Microsoft is being hit by <a title="Microsoft Security Advisory (961051)" href="http://www.microsoft.com/technet/security/advisory/961051.mspx">a critical vulnerability in IE</a> (<a title="  IE7 Zero Day Technical Analysis" href="http://securitylabs.websense.com/content/Blogs/3263.aspx">perfectly analyzed</a> by websense) which is heavily exploited to infect Windows hosts. Discovered at the same time as the <a title="Microsoft Security Bulletin Summary for December 2008" href="http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx">December</a> <a title="Patch Tuesday" href="http://en.wikipedia.org/wiki/Patch_Tuesday">Patch Tuesday</a>, the vulnerability is likely to do a lot of damages before Microsoft is able to publish a hotfix, especially as the <a title="Clarification on the various workarounds from the recent IE advisory" href="http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx">available workarounds</a> are not easy to apply. To contain the risk, Microsoft should release an out-of-band patch for IE immediately.</p>
<p>Which leads us to the inevitable conclusion that the browser is an incredibly risky environment, constantly under attack; and sooner or later, a zero-day attack, a previously unkown vulnerability, or simply a badly designed plug-in will leave your information systems exposed. The solution is to put <a title="“Browser in a sandbox” ≠ “Virtual Browser”" href="http://commonit.com/blogs/en/2008/11/18/browser-in-a-sandbox-≠-virtual-browser/">the browser in a virtualized environment</a>, preventing web-based malware infecting the user&#8217;s PC before spreading across the corporate network.</p>
]]></content:encoded>
			<wfw:commentRss>http://commonit.com/blogs/en/2008/12/17/the-perfectly-secur-browser-doesnt-exist/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

