 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Business Intelligence Technology &#187; DLL preloading</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/business-alignment/tag/dll-preloading/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/business-alignment</link>
	<description>Technology that business can use</description>
	<lastBuildDate>Sat, 13 Nov 2010 15:45:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Microsoft Binary Planting Bug Disclosed</title>
		<link>http://itknowledgeexchange.techtarget.com/business-alignment/microsoft-binary-planting-bug-disclosed/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-alignment/microsoft-binary-planting-bug-disclosed/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 03:43:18 +0000</pubDate>
		<dc:creator>Jay Dugan</dc:creator>
				<category><![CDATA[binary planting bug]]></category>
		<category><![CDATA[DLL preloading]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[SMB]]></category>
		<category><![CDATA[WebDAV]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-alignment/?p=122</guid>
		<description><![CDATA[On Monday August 23, 2010 Microsoft released a security advisory regarding insecure library loading also known as “DLL preloading or “binary planting,” MS security advisory 2269637. DLLs or dynamic link libraries are modules of computer code that act as building block for many computer programs. According to Microsoft, poorly written programs allow hackers to disguise [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-family: &quot;Helvetica&quot;,&quot;sans-serif&quot;font-size">On Monday August 23, 2010 Microsoft released a security advisory regarding insecure library loading also known as “DLL preloading or “binary planting,” <a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx?pubDate=2010-08-23">MS security advisory 2269637</a>. DLLs or dynamic link libraries are modules of computer code that act as building block for many computer programs. According to Microsoft, poorly written programs allow hackers to disguise malware as a legitimate DLL that is loaded and executed when an unsuspecting user opens a file from an untrustworthy site.</span></p>
<p><span style="font-family: &quot;Helvetica&quot;,&quot;sans-serif&quot;font-size">Microsoft cautions that this problem only affects programs that do not load DLLs securely. In addition, users must visit an untrusted site and execute a file to initiate the attack.</span></p>
<p><span style="font-family: &quot;Helvetica&quot;,&quot;sans-serif&quot;font-size">Remote servers using Server Message Block (SMB) or web distributed authoring and versioning, WebDAV are vulnerable. Microsoft has a tool for IT pros that disables library loading from WebDAV shares, see <a href="http://support.microsoft.com/kb/2264107">KB2264107</a>. Network Security Administrators should check that SMB is blocked at the firewall by default. TCP ports 139 and 445 can also be blocked, however; this should be tested first as some network functionality may be lost.<span>     </span></span></p>
<p><span style="font-family: &quot;Helvetica&quot;,&quot;sans-serif&quot;font-size">This alert is important because it points out a new vector for the type of malware that steals personal information such as credit card account numbers and passwords and contributes to identify theft. The extent of the problem is still not known and may affect not only third party programs</span><span style="font-family: Times New Roman;font-size: small"> </span><span style="font-family: &quot;Helvetica&quot;,&quot;sans-serif&quot;font-size">but Microsoft applications as well. However, Microsoft has not been forthcoming with information in this regard.</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-alignment/microsoft-binary-planting-bug-disclosed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
