Flash and PHP Both Have Security Holes That YOU Should Patch Now!

Security issues with Flash and PHP! Dewd! Patch as soon as possible!

Emergency Patches Pushed for Flash, PHP

“Adobe pushed an emergency patch Friday for its Flash Player to fix a flaw that’s being actively exploited to attack computers running Windows.

Meanwhile, software writers are still scrambling to fix a vulnerability, made public earlier this week, in PHP, a scripting language which is used widely to run servers on the Web, including those of Facebook.

The Adobe fix aims to cure an ‘object confusion vulnerability’ discovered in all versions of the player — Windows, Macintosh, Linux, and Android — but thus far has only been used to attack Windows systems using Microsoft’s browser software, Internet Explorer, according to a company bulletin on the subject.

When exploited, the defect could crash Flash Player and allow an attacker to take control of your computer.

Malware exploiting the vulnerability is being delivered in email messages containing an attachment. The email, though, is highly targeted, which means it’s directed at a limited number of individuals.

Adobe’s PDF file format has become a popular vehicle in recent times for delivering a malicious payload to a computer, according to John Harrison, a group product manager at Symantec. ‘The malicious attachments that are coming these days don’t include executables; they’re a PDF or [Microsoft] Office document,’ he told PCWorld.

‘Today,’ he adds, ‘PDFs are inherently more dangerous, in my opinion, than executables because you’re lulled into thinking you’re just looking at a document that has some text. You may be reading some text, but behind the scenes it’s really doing whatever an attacker wants.’

Adobe recommends that Windows, Macintosh and Linux users of Flash Player 11.2.202.233 or earlier, upgrade to the latest version of the program immediately.

The same should be done by users of Android 4.x using Flash Player 11.1.115.7 and Android 2.x and 3.x using version 11.1.111.8 of the software.”

Geek Software of the Week: Xmarks!

Xmarks Software

Xmarks is software by a favorite software company of mine… Lastpass! I love Lastpass for managing all my passwords across the entire Interweb! Now, Lastpass has a product that manages all your web bookmarks across all major browsers! Very cool!

Xmarks by Lastpass

Sync and Backup
Install Xmarks on each computer you use, and it seamlessly integrates with your web browser and keeps your bookmarks safely backed up and in sync.

Xmarks will sync across browsers too. Today we support Firefox, Chrome, Internet Explorer, and Safari (Mac OS).

Smarter Search
Xmarks will highlight the top sites in your search results based on how other users have bookmarked and rated them. Simply click to learn more. (Available in Firefox only)

Site Info built into your browser
Click on the Xmarks info icon in your location bar to see detailed information about the site you are on, and discover other great sites just like it. (Available in Firefox only)”