Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
More Than Half of SMB Devices Run Outdated Operating Systems
Newest First  |  Oldest First  |  Threaded View
tdsan
50%
50%
tdsan,
User Rank: Ninja
7/6/2019 | 11:02:54 PM
Re: Windows 7 has to go
I agree with you there.

Rid bloatware - get-appxprovisionedpackage -online | out-gridview -passthru | remove-appxprovisionedpackage -online (PowerShell - remove bloatware)

I also updated the security aspects on the system and disabled firewall rules (sample below using PS):

Write-Host " "
Write-Host "Disable Toredo (UDP-In|Out)"
Write-Host "---------------------------"


$NameTor = "*Teredo*UDP*"
$TorFW = (Get-NetFirewallRule -DisplayName $NameTor) | foreach{$_.Name}
$TorPort = (Get-NetFirewallrule -DisplayName $NameTor).Enabled
foreach ($i in $TorFW) {
    $val = (Get-NetFirewallrule -DisplayName $i).Enabled
    if ( $val -eq "False") {
        Write-Host $i "is already disabled - ok"
    } else {
        (Get-NetFirewallRule -Name $i) | Set-NetFirewallRule -Enabled False
        Write-Host (Get-NetFirewallRule -Name $i).Name "is disabled - ok"
    }
}

I do agree with you, one thing to mention, DHS has been pinged for not removing Windows XP from certain enclaves, it is going to be interesting what they finally decide to do:
  • However, we identified deficiencies in DHS' overall patch management process and the Cybersecurity and Infrastructure Security Agency's weakness remediation and security awareness training activities.

T
 

 
BillB031
50%
50%
BillB031,
User Rank: Strategist
7/5/2019 | 9:11:33 AM
Re: Windows 7 has to go
Been using Win10 for two years now.  After getting rid of the bloatware, and disabling Msoft's cortina garbage, it's been solid as a rock.
PaulH129
50%
50%
PaulH129,
User Rank: Apprentice
7/4/2019 | 8:40:52 AM
I actually find numbers low
I think we need to revisit this next year after Jan 22. That number will probably be bigger.
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
7/3/2019 | 3:09:53 PM
Windows 7 has to go
After years of mis-guided operating systems in variety of forms, Windows 7 must be given a farewell - it served us all a world of good and Server 2008 was solid as acan be --- so welcome to Windows 10 and a whole new world of headaches for users.  


The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13096
PUBLISHED: 2019-07-22
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.
CVE-2019-13097
PUBLISHED: 2019-07-22
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
CVE-2019-10102
PUBLISHED: 2019-07-22
OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress() (file dcrledec.h, line 122). The attack vector is: Many scenarios of DICOM file processing (e.g. DICOM to image conver...
CVE-2019-12326
PUBLISHED: 2019-07-22
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.
CVE-2019-13100
PUBLISHED: 2019-07-22
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml.