-
3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0
Revision Note: V1.0 (December 8, 2015): Advisory published. Summary: Microsoft is aware of an SSL/TLS digital certificate for *.xboxlive.com for which the private keys were inadvertently disclosed. The certificate could be used in attempts to perform man-in-the-middle attacks. It cannot be used...- News
- Thread
- advisory certificate cybersecurity digital certificates man-in-the-middle microsoft private keys security security advisory spoofing ssl supported releases technet tls update v1.0 vulnerability windows xbox live
- Replies: 0
- Forum: Security Alerts
-
3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0
Revision Note: V1.0 (December 8, 2015): Advisory published. Summary: Microsoft is aware of an SSL/TLS digital certificate for *.xboxlive.com for which the private keys were inadvertently disclosed. The certificate could be used in attempts to perform man-in-the-middle attacks. It cannot be used...- News
- Thread
- 2015 advisory certificate cybersecurity digital certificates man-in-the-middle microsoft private keys revision note security spoofing ssl support technet tls update v1.0 vulnerability windows xbox live
- Replies: 0
- Forum: Security Alerts
-
IT Showcase: Windows Terminal Services 2008 and TS Gateway
The MSIT pilot project of Windows Server 2008 Terminal Services was so successful that Microsoft IT went on to test the scalability and performance into the production environment. The environment acts as a SSL-based remote access solution and MSIT was able to create a scalable remote access...- News
- Thread
- access solution environmental global access https microsoft msit network performance pilot project production remote access scalability showcase ssl success terminal services testing ts gateway user experience windows server
- Replies: 0
- Forum: Live RSS Feeds
-
A
Windows Server Understanding Outlook 2010 Autoconfiguration for STARTTLS and SSL with Dovecot Servers
Hi, I'm a Linux guy and have been since 1998 - before then I was a maclot. I'm trying to understand (damnit - I can't put a link because I'm new - try searching for [Plan to automatically configure user accounts in Outlook 2010] article on the technet sub domain of MS website) The goal being...- Alice Wonder
- Thread
- assistance autoconfiguration client configuration domain domainrequired dovecot email email service encryption imap linux outlook pop3 settings ssl starttls technet thunderbird windows
- Replies: 1
- Forum: Programming and Scripting
-
June 2015 Website Updates and Changes
Good evening! June is upon us, and with no shortage of news or updates regarding WindowsForum.com As of the 1st of June: We have worked throughout most of the day to connect with Network Solutions, CloudFlare, ICANN, Google, and a number of other online institutions to resolve a problem that...- Mike
- Thread
- 2015 amazon app updates apple binaries cloudflare encryption google http2 icann microsoft mvp mobile apps network solutions ssl technical issues tls user contributions website updates windows forum
- Replies: 2
- Forum: Forum Announcements
-
TA15-120A: Securing End-to-End Communications
Original release date: April 30, 2015 Systems Affected Networked systems Overview Securing end-to-end communications plays an important role in protecting privacy and preventing some forms of man-in-the-middle (MITM) attacks. Recently, researchers described a MITM attack used to inject...- News
- Thread
- authentication browser security certificate certificate pinning communication cyberattack dane data security digital certificates encryption mitm attack network notary network security privacy ssl systems affected threat mitigation tls vulnerability web security
- Replies: 0
- Forum: Security Alerts
-
3046310 - Improperly Issued Digital Certificates Could Allow Spoofing - Version: 1.0
Revision Note: V1.0 (March 16, 2015): Advisory published. Summary: Microsoft is aware of an improperly issued SSL certificate for the domain “live.fi” that could be used in attempts to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported...- News
- Thread
- advisory cybersecurity digital certificates man-in-the-middle microsoft phishing revision note spoofing ssl update vulnerability windows security
- Replies: 0
- Forum: Security Alerts
-
Microsoft confirms FREAK vulnerability affects Windows as well
Ref: http://www.winbeta.org/news/microsoft-confirms-freak-vulnerability-affects-windows-well If you pop onto the site above it will check whether your browser is vulnerable to attack. Apparently the latest Chrome is fine as is IE (version 11.0.9800.0. the one that comes with win 10 build 9926)- kemical
- Thread
- attack browser build chrome cipher client systems encryption exploit freak internet explorer microsoft rsa schannel security ssl tls update version vulnerability windows
- Replies: 0
- Forum: Windows Security
-
Security Advisory 3046015 released
Today, we released Link Removed to provide guidance to customers in response to the SSL/TLS issue referred to by researchers as “FREAK” (Factoring attack on RSA-EXPORT Keys). Our investigation continues and we’ll take the necessary steps to protect our customers. MSRC Team Continue reading...- News
- Thread
- advisory freak msrc protection research rsa security ssl tls vulnerability
- Replies: 0
- Forum: Security Alerts
-
3046015 - Vulnerability in Schannel Could Allow Security Feature Bypass - Version: 1.1
Severity Rating: Important Revision Note: V1.1 (March 5, 2015): Advisory revised to clarify the reason why no workaround exists for systems running Windows Server 2003. See the Advisory FAQ for more information. Summary: Microsoft is aware of a security feature bypass vulnerability in Secure...- News
- Thread
- advisory attack best practices cipher downgrade freak important microsoft mitm schannel security server ssl tls vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
TA15-051A: Lenovo Superfish Adware Vulnerable to HTTPS Spoofing
Original release date: February 20, 2015 Systems Affected Lenovo consumer PCs that have Superfish VisualDiscovery installed and potentially others. Overview Superfish adware installed on some Lenovo PCs install a non-unique trusted root certification authority (CA) certificate, allowing an...- News
- Thread
- adware browser certificate decryption https impact komodia lenovo malware mitm network privacy root ca security spoofing ssl superfish threats uninstall vulnerability
- Replies: 0
- Forum: Security Alerts
-
February 2015 Updates
Today, as part of Update Tuesday, we released nine security bulletins – three rated Critical and six rated Important in severity, to address 56 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Microsoft Office, Internet Explorer, and Microsoft Server software. We...- News
- Thread
- 2015 advisory bulletin change critical cve exploitability important internet explorer microsoft microsoft office msrc re-release remote code execution response center security ssl update vulnerabilities windows server
- Replies: 0
- Forum: Security Alerts
-
TA14-318A: Microsoft Secure Channel (Schannel) Vulnerability (CVE-2014-6321)
Original release date: November 14, 2014 Systems Affected Microsoft Windows Vista, 7, 8, 8.1, RT, and RT 8.1 Microsoft Server 2003, Server 2008, Server 2008 R2, Server 2012, and Server 2012 R2 Microsoft Windows XP and 2000 may also be affected. Overview A critical vulnerability in...- News
- Thread
- arbitrary code bulletin critical cve-2014-6321 exploit impact microsoft mitigation network traffic patch management remote attack risk schannel security server ssl tls update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Security Advisory 3009008 released
Today, we released Link Removed to address a vulnerability in Secure Sockets Layer (SSL) 3.0 which could allow information disclosure. This is an industry-wide vulnerability that affects the protocol itself, and is not specific to Microsoft’s implementation of SSL or the Windows operating...- News
- Thread
- advisory browser connection encryption information information disclosure protocol security ssl vulnerability
- Replies: 0
- Forum: Security Alerts
-
"0x80092013, CRYPT_E_REVOCATION_OFFLINEA" error message when you try to verify a certificate...
Link Removed- News
- Thread
- certificate crypt_e_revocation error network issues revocation ssl troubleshooting verification windows security
- Replies: 0
- Forum: Knowledge Base (KB)
-
2982792 - Improperly Issued Digital Certificates Could Allow Spoofing - Version: 1.0
Revision Note: V1.0 (July 10, 2014): Advisory published. Summary: Microsoft is aware of improperly issued SSL certificates that could be used in attempts to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. The SSL certificates were improperly issued by the National...- News
- Thread
- certificate cybersecurity digital certificates man-in-the-middle microsoft phishing security advisory spoofing ssl vulnerability
- Replies: 0
- Forum: Security Alerts
-
Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 1.0
Severity Rating: Revision Note: V1.0 (November 12, 2013): Advisory published. Summary: Microsoft is announcing a policy change to the Microsoft Root Certificate Program. The new policy will no longer allow root certificate authorities to issue X.509 certificates using the SHA-1 hashing...- News
- Thread
- attack prevention code signing microsoft phishing policy change root certificate security sha1 ssl x.509
- Replies: 0
- Forum: Security Alerts
-
VIDEO Addressing Internet "Heartbleed" Emergency
This website is not affected by the exploit in any way. Further information: Last night news about a remote OpenSSL bug was disclosed on http://heartbleed.com/ which detailed out an exploit in the OpenSSL system library that handles HTTPS connections on your server. This bug impacts CentOS 6.x...- Mike
- Thread
- bug centos cpanel emergency exploit heartbleed https internet litespeed network openssl patch security server software ssl support update vulnerability whm
- Replies: 4
- Forum: Forum Announcements
-
D
Windows 7 Weird stuff happening with cookies/SSL
Hi all, Recently my wife noticed that when using sites such as Amazon and eBay problems occur. On Amazon, when you click view cart, it will not let you and gives an error telling you to enable cookies on your browser. They are enabled and everything is right. I get the same error on Internet...- Darbycrash
- Thread
- 64-bit adware amazon avg browser issues cache chrome ebay firefox internet explorer ip address malware network issues registry security ssl troubleshooting web browsing
- Replies: 1
- Forum: Windows Help and Support
-
Microsoft Security Advisory (2880823): Deprecation of SHA-1 Hashing Algorithm for Microsoft...
Revision Note: V1.0 (November 12, 2013): Advisory published. Summary: Microsoft is announcing a policy change to the Microsoft Root Certificate Program. The new policy will no longer allow root certificate authorities to issue X.509 certificates using the SHA-1 hashing algorithm for the purposes...- News
- Thread
- advisory algorithms attack certificate code signing digital security hashing man-in-the-middle microsoft phishing policy change revision note root certificate security sha1 spoofing ssl v1.0 x.509
- Replies: 0
- Forum: Security Alerts