Updates 2018-01-30

Hi, Folks!

It’s not Patch Tuesday, but there were a handful of updates released that you should be aware of. Security updates for most browsers, most Apple products, PS4 and others have been released.

The typical computer should see approximately 250mb of updates. Let’s get started.

Apple released updates for macOS High Sierra 10.13.3, macOS Security Update 2018-001 Sierra, macOS Security Update 2018-001 El Capitan, tvOS 11.2.5, Safari 11.0.3, iTunes 12.7.3 for Windows, and iCloud for Windows 7.3. These are security updates. Use the Apple App Store or Apple Software Update to install the most current versions.

iOS 11.2.5 is a security update. Use Settings, General, Software Update to install the most current version.

watchOS 4.2.2 is a security update. Use the Watch app from your iOS device to install the most current version.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 11.5.0.2698 adds email attachment action, error suppression for non-interactive accounts, additional output sizes and updated translations. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Intel Driver Update 3.1.2 is a security update.
https://www.intel.com/p/en_US/support/detect

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 64.0.3282.119 is a security update. Use Menu, Help, About to install the most current version.

Firefox 58.0.1 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 52.6.0 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 52.6.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

DiscordApp 1.25.2018 resolves several bugs, and updates libraries. This should be treated as a security update.
https://discordapp.com/download

IPNetInfo 1.78 adds display of Abuse Contact for supported registries. This is not a security update.
https://www.nirsoft.net/utils/ipnetinfo.html

WGet 1.19.4 improves compression, HTTP request compatibility, resolves several bugs, and updates libraries. This is a security update.
https://eternallybored.org/misc/wget/

Game Updates

These are unlikely to be of interest to most people.

PlayStation PS4 5.05 is a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

SteamOS 2.148 is a security update.
https://store.steampowered.com/steamos/download/?ver=custom

Security Software Updates

One or more of these is likely to be of interest to most people.

Wireless Network Watcher 2.16 adds per-device audio disconnect event support. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

RogueKiller 12.12.2 adds detecions and resolves a crash bug. This should be treated as a security update.
https://www.adlice.com/softwares/roguekiller/

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 10.0.7.9 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

CDex 1.99 improves Windows 10 compatibility and resolves several bugs. This is not a security update.
https://cdex.mu/?q=download

AVStoDVD 2.8.7 resolves several bugs, adds features, updates libraries. This should be treated as a security update.
https://sites.google.com/site/avstodvdmain/

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.5.0.5955 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

1Password for Windows 6.8.496 improves Edge compatibility, and resolves a form field bug. This is not a security update.
https://1password.com/downloads/

7-Zip 18.01 is the first release in a year and a half and adds support for several new formats, new default archive format (xz), improved sanity, and pipe support. This is not a security update.
http://www.7-zip.org/

GoodSync 10.7.5 resolves several bugs, improves service compatibility, adds several scripting variables, and improves reliability. This is not a security update.
https://12pd.com/click?goodsync

CPU-Z 1.83 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

DesktopOK 4.94 resolves a measurement bug. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Ketarin 1.8.9 adds several new features, improves compatibility with FileHippo, and resolves bugs. This is not a security update.
https://ketarin.org/

FileLocator Pro 8.2.2755 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

USBDeview 2.74 corrects a CLI parsing bug. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html

OSFMount 1.5.1018 resolves a couple bugs. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

BgInfo 4.25 resolves a parsing bug introduced in 4.20. This is not a security update.
https://live.sysinternals.com/

TraceRouteOK 1.21 improves language support and updates translations. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

WinScan2PDF 3.85 adds ability to append pages to an existing PDF file and composite PDFs from multiple sources. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

SQLite 3.22.0 improves trace and query planner, performance improvements, adds several new interfaces and extensions, and resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.5.0 resolves several bugs, improves security validation, and adds support for additional engines. This is a security update.
https://www.adminer.org/en/

TinyMCE 4.7.6 resolves over a dozen bugs. This is not a security update.
https://www.tinymce.com/download/

MailEnable 10.12 resolves several bugs and improves webmail message display. This is not a security update.
https://www.mailenable.com/

BuddyPress 2.9.3 is a security update.

Postie 1.9.15 resolves a minor bug. This is not a security update.

Redirection 3.1.1 improves compatibility, adds support for IPv6, and resolves several bugs. This is not a security update.

WooCommerce 3.3.0 resolves several bugs, improves appearance, adds several new features, and many development-level changes for integration. This is not a security update.

WP Mail SMTP 1.2.4 improves escaping, resolves a couple bugs. This should be treated as a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2017-12-12

Hi, Folks!

It’s Patch Tuesday and it’s a big one. Just in time for Christmas Microsoft, Apple, Adobe, and more have released tons of security updates to keep the IT guy you know and love busy all season long.

I’ve had a lot of calls recently from people whose computers seem unusually slow since late October. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 6gb through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients at The Farmory, or, if you prefer to have me mail it to you please contact me for information.

The typical computer should see roughly 2gb in updates today. Let’s get started.

Microsoft released updates to Windows, Edge, Internet Explorer, Flash, Defender, Server, .NET and MSRT (~1.5gb). This includes security updates. A reboot is required.

Apple released updates for macOS High Sierra 10.13.2, macOS Security Update 2017-002 Sierra, macOS Security Update 2017-005 El Capitan, tvOS 11.2, watchOS 4.2, iOS 11.2, Safari 11.0.2 and iTunes 12.7.2. This includes security updates. Use Apple Software Update to install the most current versions. A reboot is required.

iOS 11.2 is a security update. Use Settings, General, Software Update to install the most current version. A reboot is required.

watchOS 4.2 is a security update. Use the Watch app on your iPhone to install the most current version.

Google Chrome OS 62.0.3202.97 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Adobe Flash Player 28.0.0.126 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Adobe AIR 28.0.0.127 is a security update.
Win: https://12pd.com/click?air
Mac: https://12pd.com/click?airmac

Fedora 27-1.6 is a security update. This major version also adds several features, improvements to settings, network, and configuration, updated LibreOffice and more.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 17.0.8.0 improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver Update 3.1 improves scanning and reporting. This is not a security update.
https://www.intel.com/p/en_US/support/detect

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 63.0.3239.84 is a security update. Use Menu, Help, About to install the most current version.

Firefox 57.0.2 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 52.5.2 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 52.5.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

DiscordApp 12.11.2017 improves overlay, embeds, tray support, resolves several bugs, and more. This is not a security update.
https://discordapp.com/download

Line 7.17.0 adds in-app GIF creation and filters. This is not a security update.
https://line.me/update

uTorrent 3.5.0 Build 44294 resolves a couple bugs. This is not a security update.
https://www.utorrent.com/downloads

MaxMind GeoIP Data 201712 is a data refresh.
https://dev.maxmind.com/geoip/geolite

BrowsingHistoryView 2.12 adds Quick Filter feature. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

Npcap 0.97 improves hardware compatibility, WinPcap compatibility, and removes silent installation support. This is not a security update.
https://nmap.org/npcap/

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.7.2 is a security update. Use Apple Software Update to install the most current version.

Game Updates

These are unlikely to be of interest to most people.

PlayStation PS3 4.82 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps3/

EA Origin 10.5.8.11002 improves tray behavior, overlay adjustments, and other fixes. This is not a security update.
https://www.origin.com/en-us/download

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 6.0.7 improves stability and performance, PS plugin compatibility, and resolves several bugs. This is not a security update.
https://www.artweaver.de/

Notepad++ 7.5.3 resolves updater issues, improves stability. This is not a security update.
https://12pd.com/click?npp

SketchUp 18.0.16975 resolves dozens of bugs and adds several new features. This is not a security update.
https://www.sketchup.com/

Adobe Reader DC Patch 18.009.20050 is a security update. Use Help, Check for updates to install the most current version.

Adobe DNG Converter 10.1 adds support for new hardware. This is not a security update.
Win: https://supportdownloads.adobe.com/detail.jsp?ftpID=6285
Mac: https://supportdownloads.adobe.com/detail.jsp?ftpID=6283

FrameMaker 2017 Cumulative update 3 (2017.0.3) is a security update.
https://supportdownloads.adobe.com/detail.jsp?ftpID=6287

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 3.3 is a security update.
https://tails.boum.org/install/index.en.html

oclGaussCrack 1.4 improves reliability. This is not a security update.
https://hashcat.net/oclGaussCrack/

Wireshark 2.4.3 is a security update.
https://www.wireshark.org/

Gpg4win 3.0.2 resolves over a dozen bugs. This is not a security update.
https://www.gpg4win.org/download.html

RogueKiller 12.11.28 adds detections and resolves a device access bug.
https://www.adlice.com/softwares/roguekiller/

Intel-SA-00086 Detection Tool 1.0.0.146 improves accuracy of vulnerability detection.
https://downloadcenter.intel.com/download/27150

Capture Updates

These are unlikely to be of interest to most people.

VideoCacheView 2.98 improves YouTube compatibility. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

XSplit Broadcaster 3.2.1711.2907 resolves several bugs and improves performance. This is not a security update.
https://www.xsplit.com/get/

Converter Updates

These are unlikely to be of interest to most people.

CDex 1.96 improves compatibility. This is not a security update.
http://cdex.mu/?q=download

DVDFab 10.0.7.1 adds support for new encodings, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.5.0.5790 adds several new components and settings. This is not a security update.
https://www.ntlite.com/download/

8GadgetPack 25.0 resolves bugs. This is not a security update.
https://8gadgetpack.net/

GoodSync 10.6.8 improves self-maintenance activity to reduce clutter, improve log relevance, and improve performance. Resolves several bugs.This is not a security update.
https://12pd.com/click?goodsync

DesktopOK 4.89 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DMDE 3.4.2.722 improves Apple/macOS support, and resolves several bugs. This is not a security update.
https://dmde.com/

IsMyHdOK 1.31 integrates a new RNG. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

FileLocator Pro 8.2.2751 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

FolderChangesView 2.20 improves concurrency and adds Quick Filter feature. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

OSForensics 5.2.1003 removes several arbitrary number limits. This is not a security update.
https://www.osforensics.com/download.html

CCleaner 5.38.6357 resolves several bugs, and improves stability. This is a security update.
https://12pd.com/click?ccleaner

ProduKey 1.91 provides cosmetic improvements. This is not a security update.
https://www.nirsoft.net/utils/product_cd_key_viewer.html

Sysmon 6.20 adds the ability to randomize object names to foil malware that use them to detect its presence. This is a security update.
https://live.sysinternals.com/

AccessChk 6.20 resolves bugs. This is a security update.
https://live.sysinternals.com/

Sigcheck 2.60 resolves several bugs. This is a security update.
https://live.sysinternals.com/

Whois 1.20 adds support for registry server redirects. This is not a security update.
https://live.sysinternals.com/

TaskSchedulerView 1.36 adds tray icon support. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

TeamViewer 12.0.88438 resolves a reliability bug.
https://www.teamviewer.com/en/download/windows/

WinScan2PDF 3.77 adds output preview, fit/crop support, rotation, default storage location changes. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.17 adds support for copying selected object information to clipboard, and improves accuracy of percentages. This is not a security update.
https://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 3.0.1.0 resolves several bugs and provides performance improvements. This is not a security update.
https://developer.android.com/studio/index.html

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.5.4 doesn’t provide a detailed changelog, so should be treated as a security update.
http://ppsspp.org/downloads.html

VirtualBox 5.2.2-119230 resolves several bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Drupal 8.4.3 resolves dozens of bugs. This is not a security update.
https://drupal.org/download

Joomla 3.8.3 resolves dozens of bugs. This is not a security update.
https://www.joomla.org/

MailEnable Enterprise 10.10 resolves several bugs. This is not a security update.
https://www.mailenable.com/

phpMyAdmin 4.7.6 resolves several bugs. This is not a security update.
https://www.phpmyadmin.net/home_page/news.php

ScreenConnect 6.4.15361.6527 resolves a stability bug. This is not a security update.
https://www.screenconnect.com/Download

SMF 2.0.15 is a security update.
https://download.simplemachines.org/

WordPress 4.9.1 is a security update.
https://wordpress.org/

Contact Form 7 4.9.2 should be treated as a security update.

Email Log 2.2.4 provides license changes. This is not a security update.

NextScripts Social Networks Auto-Poster 4.1.1 resolves several bugs. This is not a security update.

Postie 1.9.14 improves logging. This is not a security update.

Redirection 2.10.1 adds support for multisite and resolves several bugs. This is not a security update.

W3 Total Cache 0.9.6 resolves over a dozen issues, including disabling the anonymous tracking feature by default. This should be treated as a security update.

Widgets on Pages 1.4.0 adds TinyMCE button for widgets. This is not a security update.

WooCommerce 3.2.5 resolves dozens of bugs. This is not a security update.

WP Edit 4.0.2 resolves a couple bugs. This is not a security update.

WP Mail SMTP 1.0.0 adds several email provider integrations and improves GUI. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2017-11-01

Hi, Folks!

It’s not Patch Tuesday, but Apple, Microsoft, Google and more have released updates this week.

The typical computer should see approximately 2gb of updates. Let’s get started.

Microsoft released an out-of-cycle security update for Flash Player 27.0.0.183. Use Windows Update to install the most current versions.

Apple released updates for macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, Security Update 2017-004 El Capitan, iOS 11.1, watchOS 4.1, tvOS 11.1, Safari 11.0.1, iCloud for Windows 7.1, iTunes 12.7.1 are security updates. Use the Apple App Store or Apple Software Update to install the most current versions.

iOS 11.1 is a security update. Use Settings, General, Software Update to install the most current version.

watchOS 4.1 is a security update. Use your updated iPhone to install the most current version through the Watch app.
https://support.apple.com/en-us/HT204641

tvOS 11.1 is a security update. Use Settings, General, Updates to install the most current version.

Google Chrome OS 62.0.3202.74 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Adobe Flash Player 27.0.0.183 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Seagull Scientific Driver collection 2017.1 improves compatibility, reliability and more. This is not a security update.
https://www.seagullscientific.com/drivers/windows-printer-drivers/

Display Driver Uninstaller 17.0.7.7 improves cleanup, compatibility, and resolves several bugs. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 62.0.3202.75 is a security update.

Firefox 56.0.2 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 52.4.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Line 7.14.0 improves camera integration. This is not a security update.
https://line.me/update

aria2 1.33.0 resolves several bugs and adds a couple new features. This is not a security update.
https://aria2.github.io/

MaxMind GeoIP Data 201711 is a data refresh.
https://dev.maxmind.com/geoip/geolite

IPInfoOffline 1.45 updates IP database and adds column autosizing. This is not a security update.
https://www.nirsoft.net/utils/ip_country_info_offline.html

Npcap 0.96 integrates several new Type selectors, improves memory handling, expands license. This is not a security update.
https://github.com/nmap/npcap/releases

WGet 1.19.2 is a security update.
https://eternallybored.org/misc/wget/

iCloud for Windows 7.1 is a security update. Use Apple Software Update to get the most current version.

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.7.1 is a security update. Use Apple Software Update to get the most current version.

Game Updates

These are unlikely to be of interest to most people.

EA Origin 10.5.5.5003 improves game management, storage options, and many cosmetic improvements. This is not a security update.
https://www.origin.com/en-us/download

PlayStation PS4 5.01 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

Office Updates

One or more of these are likely to be of interest to most people.

OpenOffice 4.1.4 is a security update. You are strongly advised to REMOVE OpenOffice and switch to LibreOffice!
https://www.openoffice.org/download/

Kindle for PC 1.21.0 Build 48017 doesn’t provide a changelog, so should be treated as a security update.
https://12pd.com/click?kindle4pc

Security Software Updates

One or more of these is likely to be of interest to most people.

Wireshark 2.4.2 is a security update.
https://www.wireshark.org/

RogueKiller 12.11.22 adds detections. This is not a security update.
https://www.adlice.com/softwares/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

XSplit Broadcaster 3.1.1709.1535 resolves several bugs. This is not a security update.
https://www.xsplit.com/get/

XSplit Gamecaster 3.1.1708.2941 resolves several bugs. This is not a security update.
https://www.xsplit.com/get/

Converter Updates

These are unlikely to be of interest to most people.

CDex 1.93 resolves compatibility issues. This is not a security update.
http://cdex.mu/?q=download

DVDFab 10.0.6.4 adds support for new encodings, resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.4.1.5675 resolves several bugs and upgrades components. This is not a security update.
https://www.ntlite.com/download/

1Password for Mac 6.8.3 resolves several bugs. This is not a security update.
https://1password.com/downloads/

GoodSync 10.6.5 resolves dozens of bugs, improves reliability and consistency, and improves compatibility. This is not a security update.
https://12pd.com/click?goodsync

RoboForm 8.4.3 improves stability and version compatibility. This is not a security update.
https://12pd.com/click?rf

CintaNotes 3.11 resolves several bugs and improves clicking. This is not a security update.
http://cintanotes.com/download

DesktopOK 4.85 resolves improves AutoHide behavior. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Easy2Boot 1.96 improves compatibility with some virtual images, and resolves several bugs. This is not a security update.
https://www.easy2boot.com/download/

HWMonitor 1.33 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

ImageUSB 1.3.1004 doesn’t provide a changelog, so should be treated as a security update.
https://www.osforensics.com/tools/write-usb-images.html

IsMyHdOK 1.29 improves detection. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

CurrPorts 2.36 adds auto-size columns support. This is not a security update.
https://www.nirsoft.net/utils/cports.html

WakeMeOnLan 1.82 removes an inactive menu item. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

OSForensics 5.2.1001 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

CCleaner 5.36.6278 improves cleanup and adds automatic updates. This is not a security update.
https://12pd.com/click?ccleaner

PointerStick 2.92 adds crosshair with arrows support. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

WinScan2PDF 3.71 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.15 adds MFT association, and resolves several bugs. This is not a security update.
http://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

WSUS Offline 11.0.3 resolves several bugs. This is not a security update.
http://download.wsusoffline.net/

.NET Framework 4.7.1 improves accessibility options, performance, reliability, and more. This is not a security update.
https://www.microsoft.com/net/

Java 8u151 is a security update. Consider removing Java instead of upgrading if you are not 100% sure you require it.
https://www.java.com/en/download/manual.jsp

Developer Updates

These are unlikely to be of interest to most people.

MySQL 5.7.20 is a security update.
https://www.mysql.com/downloads/installer/

SQLite 3.21.0 improves performance and resolves several bugs. This is a security update.
https://www.sqlite.org/download.html

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 5.2.0-118431 is a major update with several improvements to stability, reliability, and performance. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

phpMyAdmin 4.7.5 resolves several bugs. This is not a security update.
https://www.phpmyadmin.net/news/

ScreenConnect 6.4.15083.6507 resolves dozens of bugs, improves compatibility, and adds several new features. This is not a security update.
https://www.screenconnect.com/Download

WordPress 4.8.3 is a security update.
https://wordpress.org/

Contact Form 7 4.9.1 resolves several bugs. This is not a security update.

NextScripts Social Networks Auto-Poster 4.0.7 resolves a couple dozen bugs. This is not a security update.

Postie 1.9.10 resolves several bugs. This is not a security update.

Redirection 2.8.1 resolves several bugs. This is not a security update.

WooCommerce 3.2.2 resolves dozens of bugs and adds several features. This is not a security update.

WP Mail SMTP 0.11.1 improves compatibility with older versions of PHP. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

KRACK Attacks: Protocol Insecurity

The KRACK Attacks are a great example of why updates are important. Wireless networking has been around over 45 years with many encryption and security layers being adapted over that time. The variation most commonly in use today, Wi-Fi with WPA2, is about 13 years old. Thousands of people have reviewed the protocol documents. Vendors across the world have implemented the protocol as it was designed and it is in active daily use on billions of devices (yes, billions with a “b”). However, a relatively minor flaw in the design of the greeting/handshake allows an evil third party to essentially hijack any Wi-Fi network.

At least 6 months ago a series of vulnerabilities in all wireless protocols (including the most secure current wireless protocol, WPA2) were discovered that allowed for an evil third-party in range of your Wi-Fi network connection to emulate it and hijack your access to the connection to be able to siphon or change information between you and the Internet. These vulnerabilities also make it possible to intercept and alter “secure” traffic (such as HTTPS encrypted connections) by way of it’s MitM scope on some networks and devices.

Every vendor’s hardware that was tested was found to be vulnerable. The thing is, if they obeyed the protocol it would literally be impossible not to be vulnerable.

Several months ago the person that discovered the issue contacted different vendors to alert them of the problems and they are actively coordinating security updates this week to address them. FreeBSD patched it months ago. Microsoft patched it last Tuesday. Some Android devices have been patched over the last couple weeks, while others may never be. Security updates for ChromeOS should be released next Tuesday. Apple’s patch for iOS, macOS, tvOS and watchOS is planned for release “soon,” but every version of macOS and iOS are affected and not all are still supported (in other words – only some Apple devices will receive patches). Hardware vendors are gradually releasing updates for supported devices.

What should you do?

Patch or replace your hardware. All of your hardware: your routers, modems, phones, tablets, laptops, desktops that have Wi-Fi support, even your light bulbs and irrigation systems.

If a patch is not currently available for your hardware, hound the vendor until it is, or replace/avoid that hardware (and vendor).

If your hardware is no longer supported by the vendor you will not receive security updates to address this vulnerability. Most hardware still in use today is beyond it’s support period (aka “end of life/EOL”), so will never receive a security update to address this vulnerability or any other. Really. It’s probably time to replace that “perfectly good” wireless router you picked up “only 5 years ago” at a “helluva bargain” that “still works.” It’s annoying, but important to check the vendors site when purchasing hardware to ensure that it’s supported by them. Most vendors support their hardware only 5 to 10 years after a modem was initially released. Most people buy hardware at least half-way through this period, significantly reducing the applicable support period.

Always use TLS/SSL. If the sites you visit don’t support HTTPS, don’t use them or at least contact their webmasters to request HTTPS support.

Avoid wireless connections. Yes, really. Even if this had never occurred, understand that every wireless network is inherently insecure. Emulating your network the way the KRACK Attack operates is only one way to hijack it. There are many other risks in all forms of networking, from old, insecure, and unsupported network equipment that can be easily compromised to unmaintained and unsecureable hardware that joins the network. While a wired network generally contains all traffic within the cables that make up the network, a wireless network, by definition, broadcasts all network traffic for any evildoer within range to capture and record. While they may not be able to exploit that encrypted information today, it’s likely that similar vulnerabilities will be discovered that allow them to decrypt and abuse that information sometime in the future. Avoiding wireless connections reduces this risk.

I thought this only affected my router?

No. This vulnerability is a protocol-level issue, which means that every single wireless device in the world that was designed to obey the protocol is impacted. All of them. Patch or replace.

Many protocols have weaknesses that are eventually addressed with minor and sometimes major changes. SMTP – the protocol used to send email – didn’t require any form of authentication at any level for over 20 years! The geeks that think this stuff up are awesome, but we can’t anticipate everything.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2017-10-10

Hi, Folks!

It’s Patch Tuesday. Happy Anniversary to my beautiful bride — sorry it fell on Patch Tuesday. 🙁

*Updated to add updates for Flash, WinSCP and WifiInfoView.

The typical computer should see roughly 1.7gb in updates today. Let’s get started.

Microsoft released updates to Windows, Edge, Internet Explorer, Flash, .NET and MSRT (~1.5gb). This includes security updates. A reboot is required.

Apple released updates to macOS High Sierra, watchOS, and iOS. These are security updates. A reboot is required.

macOS High Sierra 10.13 “Supplemental Update” is a security update. Use Apple Software Update to install the most current version.

watchOS 4.0.1 is a security update. Use the Watch app on your iPhone to install the most current version.

iOS 11.0.1 and 11.0.2 are both security updates. Use Settings, General, Software Update to install the most current version. The battery drain and random recipient problems are known and will be addressed “soon.”

ChromeOS 61.0.3163.113 is a security update. Use Menu, Help, About to install the most current version.

Adobe Flash Player 27.0.0.159 does not provide a changelog (which is very weird for Adobe), so should be treated as a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

The quarterly Java security patch will be released next week. Since you’re doing updates today anyway, consider REMOVING Java so you don’t have to next week. Chances are good you don’t actually require it, so leaving it on your computer only increases your risk.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Browser Updates

One or more of these are likely to be of interest to everyone.

Firefox 56.0.1 is a security update. This version now pushes 32-bit upgrades to 64-bit on all devices that support it, except Lenovo IdeaPad laptops, which have a compatibility issue with Firefox 64-bit. Use Menu, Help, About to install the most current version.

Opera 48 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.10 adds an option (“/extractdeleteall”) to extract all attachments then delete them from the Outlook PST file (yay!). This is not a security update.
http://www.nirsoft.net/utils/outlook_attachment.html

Internet Updates

One or more of these are likely to be of interest to everyone.

Trillian 6.1.0.8 improves reliability and resolves several bugs. This is not a security update.
https://www.trillian.im/

uTorrent 3.5.0 Build 44090 resolves stability bugs and improves search behavior. This should be treated as a security update.
http://www.utorrent.com/downloads

FileZilla 3.28.0 resolves several bugs. This is not a security update.
http://filezilla-project.org/

FreeFileSync 9.4 resolves several bugs, improves reliability and GUI. This is not a security update.
https://www.freefilesync.org/download.php

MaxMind GeoIP Data 201710 is a data refresh. This is not a security update.
http://dev.maxmind.com/geoip/geolite

Game Updates

These are unlikely to be of interest to most people.

PlayStation PS4 5.00 is a major update which allows adding family members as users with parental control support, removes restrictions on following unverified accounts, adds custom lists, notifications in the quick menu, improved messaging, broadcasting in 1080p at 60 fps to Twitch and more. This is not a security update.
http://us.playstation.com/support/systemupdates/ps4/pc_update/index.htm

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 6.0.6 improves preview and resolves several bugs. This is not a security update.
http://www.artweaver.de/

Paint.net 4.0.19 improves performance, portability, per-user preferences, and resolves multiple crash bugs. This is not a security update.
http://www.getpaint.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 3.2 is a security update. This version adds PPPoE and dial-up support, disables Bluetooth by default, improves ASLR, and more.
https://tails.boum.org/install/index.en.html

Avast! Home Edition 17.7.2314 adds Webcam Shield, improved performance, and automated exclusions for Secure DNS. This is not a security update.
http://www.avast.com/free-antivirus-download

KeePass 1.34 improved print support, error handling and reporting, updates libraries and resolves several bugs. This should be treated as a security update.
http://keepass.sourceforge.net/

Wireless Network Watcher 2.15 adds automatic export capability. This is not a security update.
http://www.nirsoft.net/utils/wireless_network_watcher.html

RogueKiller 12.11.19 adds detections. This should be treated as a security update.
http://www.adlice.com/softwares/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

XSplit Broadcaster 3.1.1709.1531 resolves several bugs, adds Steam social login, and improves hardware compatibility. This is a security update.
http://www.xsplit.com/get/

XSplit Gamecaster 3.1.1708.2935 resolves several bugs, adds Steam social login, and improves hardware compatibility. This is a security update.
http://www.xsplit.com/get/

Converter Updates

These are unlikely to be of interest to most people.

CDex 1.92 improves ID3v2 support and resolves several bugs. This is not a security update.
http://cdex.mu/?q=download

DVDFab 10.0.6.2 adds several new output profiles and improves compatibility. This is not a security update.
http://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

WinSCP 5.11.2 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

NTLite 1.4.1.5632 improves compatibility, adds support for new components. This is not a security update.
https://www.ntlite.com/download/

8GadgetPack 24.0 improves compatibility and resolves several bugs. This is not a security update.
http://8gadgetpack.net/

GoodSync 10.6.2 improves compatibility and resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

DesktopOK 4.77 adds support for pixel color detection, resolves several bugs. This is not a security update.
http://www.softwareok.com/?seite=Freeware/DesktopOK

GSmartControl 1.1.1 resolves several bugs. This is not a security update.
https://gsmartcontrol.sourceforge.io/home/index.php/About

AS SSD Benchmark 2.0.6485 adds support for newer hardware and improves accuracy. This is not a security update.
http://www.alex-is.de/PHP/fusion/downloads.php?cat_id=4&download_id=9

FileLocator Pro 8.2.2744 resolves several bugs. This is not a security update.
http://www.mythicsoft.com/filelocatorpro/download

FolderChangesView 2.12 adds automatic export support. This is not a security update.
http://www.nirsoft.net/utils/folder_changes_view.html

NetworkTrafficView 2.11 adds automatic export support. This is not a security update.
http://www.nirsoft.net/utils/network_traffic_view.html

RegFileExport 1.09 resolves a reliability bug. This is not a security update.
http://www.nirsoft.net/utils/registry_file_offline_export.html

OSForensics 5.2.1000 adds over a dozen new features and resolves several bugs. This should be treated as a security update.
http://www.osforensics.com/download.html

PointerStick 2.91 improves compatibility. This is not a security update.
http://www.softwareok.com/?seite=Freeware/PointerStick

SystemRescueCD 5.1.1 is a security update.
http://www.sysresccd.org/

WifiInfoView 2.30 adds feature to view or export MAC Addresses. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WizTree 3.12 updates translations. This is not a security update.
http://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

WSUS Offline 11.0.2 improves detection and supersedence. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Redemption 5.15.0.4892 resolves over a dozen bugs, improves property access, and corrects the Japanese language bug. This is not a security update.
http://www.dimastr.com/redemption/

StrawberryPerl 5.26.1.1 updates libraries. This should be treated as a security update.
http://strawberryperl.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VMware Player 14.0.0 adds support for new guest operating systems, and updates libraries. This should be treated as a security update.
http://www.vmware.com/products/player/

Web Package Updates

These are likely to be of interest only to web developers.

Piwigo 2.9.2 is a security update.
http://piwigo.org/

Plupload 2.3.4 doesn’t provide a changelog, so should be treated as a security update.
http://www.plupload.com/

TinyMCE 4.7.1 resolves dozens of bugs. This is not a security update.
http://www.tinymce.com/download/

Drupal 8.4.0 resolves many bugs. This is not a security update.
https://www.drupal.org/download

Joomla 3.8.1 resolves several bugs. This is not a security update.
https://www.joomla.org/

Email Log 2.2.0 adds a new dashboard widget with log summary. This is not a security update.

Raw HTML 1.5.1 adds support for the Mediso editor. This is not a security update.

WPtouch 4.3.21 resolves a cosmetic bug. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/