Friday, July 10, 2009

Phishing Attempts Aimed at Penn State Faculty and Staff

Faculty and staff are reminded that the college and university will *NEVER* request account/password information via E-mail.

You should never reply to a message asking for account information, nor should you ever click a link from a message that asks for account information. Penn State and the College of Ag Sciences will never ask for your account/password in this method.

If you receive messages of this type, simply delete the message.
Normally, Ag IT will not send alerts warning employees of individual phishing scams. These scams are too numerous to regularly keep on top of, so please remember legitimate entities do not request information in this manner.

However, in the past week we have seen new examples of phishing aimed at our employees. We are taking this opportunity to refresh in everyone's mind that these messages should be deleted if they make it past the college and university's spam filters.

Sample 1 below is a general attempt to have you click on the link. In this case, the link doesn't appear to show you a form. Instead the page attempts to download and install malware on your computer. If you receive messages of this type, simply delete the message.

Sample 1

Subject: Your Webmail Quota Has Exceeded The Set Quota/Limit

Your Webmail Quota Has Exceeded The Set Quota/Limit Which Is 20GB.
You Are Currently Running On 23GB Due To Hidden Files And Folder On Your Mailbox.

Please Click the Link Below To Validate Your Mailbox And Increase Your Quota.

w w w.jotform.com/form/9999999999
[number changed and link removed]
Failure To Click This Link And Validate Your Quota May Result In Loss Of Important Information In Your Mailbox/Or Cause Limited Access To It.

Sample 2 below is an example of a "spear-phishing" message. These messages are attacks aimed directly at a company, government agency, organization, or group. Spear phishers send E-mail that appear genuine to all the employees or members of these groups

You can read the sample E-mail below. It is a well crafted note! We've removed the actual link below. But if you were to receive an E-mail like this, you can hover (hold the mouse over the link without clicking) to see the destination address.

In the actual E-mail the address started with "http://psu.edu" but then added "ec-uk.org" as the actual destination. This will usually confirm what you knew anyway. So, simply delete the message.

Sample 2

From: PSU Help Desk [mailto:it_dept@psu.edu]
Subject: Mandatory Security Update: July 2009

The Pennsylvania State UniversityInformation Technology ServicesThe ITS Help Desk

URGENT SECURITY UPDATE - JULY 2009

Due to the recent increase in spam emails, we have upgraded to an advanced server for your premium security to prevent spam from getting to your inbox. As a result of this, it is important that you login to your email using the link below, to make sure that your account information is up-to-date.

Click Here to Protect Your Account [link removed]

This email has been sent to all PSU Webmail users and it is mandatory to follow.

Thank you for your cooperation.

IT DepartmentCopyright © 2009 The Pennsylvania State University


Sample 2 Image

If you had clicked the link, you would be taken to a page that mimicked the real Penn State WebAccess login window. But again, the actual address is fake.



The ITS Alerts site has a listing of E-mail (spam, phishing) alerts which gives you an idea of how prevalent these activities are.

Thursday, June 11, 2009

Sun Releases Java(TM) 6 Update 14

As of May 29, 2009, the current version of Sun's Java client is Java(TM) 6 Update 14.

Action Required:
If you see the Java Update icon or "Java Update Available" balloon in the lower right corner of the screen, the latest version of Java should be ready to install. You can click the icon and follow its prompts to apply the update. Note: We recommend that you do not install any offered "extras" like the MSN Toolbar, OpenOffice.org Installer or Microsoft's Live Search. Please un-check these options if they appear.

Or, our How To Update Sun's Java Software, http://it.cas.psu.edu/260.htm, has complete steps on how to install Java from either the "Java Update Available" message or how to download and install Java manually .

Fixed:
This release contains feature enhancements that includes support for Internet Explorer 8. The full list of changes may be found here: http://java.sun.com/javase/6/webnotes/6u14.html

Note:
Previously, older versions of Sun Java were not removed from your computer when you updated. You had to manually remove older versions of Sun Java from your computer. This has now changed. You no longer need to remember to remove the previous Java version.

Updates for Adobe Reader 9 and Adobe Acrobat Professional 7, 8, & 9 Are Available

Adobe shipped a critical security update to its Adobe products on June 9, 2009 that patches 13 critical bugs in Reader 9.1.1 and Acrobat 9.1.1 or earlier versions. This update resolves a stack overflow and integer overflow bugs that lead to code execution potential and Denial of Service attack/code execution. Additional memory corruption and heap overflow vulnerabilities were also fixed.

Note: To determine the version of any of the above applications, open the Adobe program. Then from the Help menu choose About Adobe, (name of program). You should see the version listed in a new box. Then, you can click anywhere on this box to close it.

The current version of Adobe Acrobat and Adobe Reader is version 9.1.2. If you have earlier versions of Adobe Acrobat Professional, version 7 or 8, Adobe has released 7.1.3 and 8.1.6 updates as well.

Note: If you have Adobe Reader version 8.x on your computer, you should remove this version and updater to Adobe Reader 9.1.1. See our How To Install and Configure Adobe Reader v9 for Windows.

Action Required: Ag IT recommends that College of Ag Science faculty and staff update any Adobe products to their current version.

To apply these updates:

  1. Close all other programs and then open your version of Adobe Reader or Acrobat Professional.
  2. From the Help menu choose Check for Updates.
  3. If updates were found, they should begin to download. If not, click the Download and Install Updates button.
  4. When the update is ready, click Install Now.
  5. The updater will prompt you to close the program before the update can be installed. Click Continue.

    Note: The Installation Progress window may be minimized to the lower right of the screen (in the notification tray). To see the Installation Progress window, right click on its white icon and choose Show Progress.

  6. When the process completes, click Quit.
  7. The Adobe Reader or or Acrobat Professional program will re-open.
  8. From the Help menu choose Check for Updates. If no updates are available, click Quit.
  9. Close Adobe Reader or or Acrobat Professional.
Note: Earlier versions of Adobe Acrobat Professional (version 6 or lower) will not be patched.

The Adobe Security bulletin, Security Updates available for Adobe Reader and Acrobat, has additional information and links.

Wednesday, June 03, 2009

QuickTime 7.6.2 Update Released

On June 1, 2009, an updated version of QuickTime was released (7.6.2). This update fixes an issue where opening a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. In simple terms, malware could be installed on your computer. See more details here (Scroll down to the Security Updates section and click the link for QuickTime 7.6.2).

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required: Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Wednesday, May 13, 2009

Updates for Adobe Reader 9 and Adobe Acrobat Professional 7, 8, & 9 Are Available

Adobe shipped a critical security update to its Adobe products on May 12, 2009 that addresses a vulnerability that can cause the application to crash and allow an attacker to take control of the affected system.

Note: To determine the version of any of the above applications, open the Adobe program. Then from the Help menu choose About Adobe, (name of program). You should see the version listed in a new box. Then, you can click anywhere on this box to close it.

The current version of the Adobe Acrobat and Adobe Reader is version 9.1.1. If you have earlier versions of Adobe Acrobat Professional, version 7 or 8, Adobe has released 7.1.2 and 8.1.5 updates as well.

Note: If you have Adobe Reader version 8.x on your computer, you should remove this version and updater to Adobe Reader 9.1.1. See our How To Install and Configure Adobe Reader v9 for Windows.

Action Required: Ag IT recommends that College of Ag Science faculty and staff update any Adobe products to their current version.

To apply these updates:

  1. Close all other programs and then open your version of Adobe Reader or Acrobat Professional.
  2. From the Help menu choose Check for Updates.
  3. If updates were found, they should begin to download. If not, click the Download and Install Updates button.
  4. When the update is ready, click Install Now.
  5. The updater will prompt you to close the program before the update can be installed. Click Continue.

    Note: The Installation Progress window may be minimized to the lower right of the screen (in the notification tray). To see the Installation Progress window, right click on its white icon and choose Show Progress.

  6. When the process completes, click Quit.
  7. The Adobe Reader or or Acrobat Professional program will re-open.
  8. From the Help menu choose Check for Updates. If no updates are available, click Quit.
  9. Close Adobe Reader or or Acrobat Professional.
Note: Earlier versions of Adobe Acrobat Professional (version 6 or lower) will not be patched.

The Adobe Security bulletin, Security Updates available for Adobe Reader and Acrobat, has additional information and links.

Friday, March 27, 2009

Sun Releases Java(TM) 6 Update 13

As of March 26, 2009, the current version of Sun's Java client is Java(TM) 6 Update 13.

Action Required:
If you see the Java Update icon or "Java Update Available" balloon in the lower right corner of the screen, the latest version of Java should be ready to install. You can click the icon and follow its prompts to apply the update. Note: We recommend that you do not install any offered "extras" like the MSN Toolbar, OpenOffice.org Installer or Microsoft's Live Search. Please un-check these options if they appear.

Or, our How To Update Sun's Java Software, http://it.cas.psu.edu/260.htm, has complete steps on how to install Java from either the "Java Update Available" message or how to download and install Java manually .

Fixed:
This release contains feature enhancements and bug fixes. This full list of changes may be found here: http://java.sun.com/javase/6/webnotes/6u13.html

Note:
Previously, older versions of Sun Java were not removed from your computer when you updated. You had to manually remove older versions of Sun Java from your computer. This has now changed. You no longer need to remember to remove the previous Java version.

Thursday, March 19, 2009

Adobe Acrobat Professional Updates for version 7 and 8 Released

On March 11, 2009 Ag IT posted a Tech Alert about the "version 9.1.0 Update for Adobe Reader 9 and Adobe Acrobat 9 Professional is Available". In this Tech Alert it was recommended that College of Ag Science faculty and staff see our How To Install and Configure Adobe Reader v9 for Windows for steps on updating Adobe Reader to the current version.

However, there are a number of staff who use version 7 and 8 Adobe Acrobat Professional.

On March 18, 2009 Adobe has released updates for these versions as well.

The current version of Adobe Acrobat Professional 7 is now 7.1.1.The current version of Adobe Acrobat Professional 8 is now 8.1.4.

Action Required: Ag IT recommends that College of Ag Science faculty and staff who use either version 7 and 8 Adobe Acrobat Professional update their Adobe Acrobat Professional to these versions.

To apply these updates:

  1. Close all other programs and then open your version of Adobe Professional.
  2. From the Help menu choose Check for Updates.
  3. If updates were found, they should begin to download. If not, click the Download and Install Updates button.
  4. At this point, you can click the Adobe Professional window to make it active, then Exit Acrobat Professional. If you don't exit Adobe Professional, the updater will prompt you to close the program before the update can be installed.
  5. When the update is ready, click Install Now.

    Note: The Installation Progress window may be minimized to the lower right of the screen (in the notification tray). To see the Installation Progress window, right click on its white icon and choose Show Progress.

  6. When the process completes, you may be asked to restart.
Note: If you can't use the Adobe Updater to apply the updates, here are links to the individual updates. Click the needed link for your version. Then click Proceed to Download. Click Download Now. Click Open (rather than Save). Click Run. Click Update. When done, click Finish.
Note: In order to install these updates, you may need to install other updates first. For example, the 8.1.4 update can only be applied to Adobe Acrobat version 8.1.3. To find other updates, go to Acrobat for Windows - Downloads for their complete list of available updates.

Note: Earlier versions of Adobe Acrobat Professional (version 6 or lower) will not be patched.

Wednesday, March 11, 2009

version 9.1.0 Update for Adobe Reader 9 and Adobe Acrobat 9 Professional is Available

Adobe shipped a critical security update to its Adobe version 9 products on March 10, 2009 that addresses a vulnerability that can cause the application to crash and allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

The current version of the Adobe Acrobat and Adobe Reader is version 9.1.0.

Action Required: Ag IT recommends that College of Ag Science faculty and staff see our How To Install and Configure Adobe Reader v9 for Windows for steps on updating Adobe Reader to the current version.

Note: To determine the version of either of the above applications, open the Adobe program. Then from the Help menu choose About Adobe, (name of program). You should see the version listed in a new box. Then, you can click anywhere on this box to close it.

If you have the "full" version of Adobe Acrobat, you can update this program via its updater feature. Open Adobe Acrobat 9 Professional. From the Help menu, choose Check for Updates. If updates are found, close Adobe Acrobat 9 Professional. Then, click Download and Install Updates. When they complete, restart the computer.

If you have Adobe Reader version 8.x on your computer, you should remove this version and updater to Adobe Reader 9.1.0. See our How To Install and Configure Adobe Reader v9 for Windows f

If you have earlier versions of Adobe Acrobat Professional, version 7 or 8, Adobe is planning to make updates available by March 18, 2009.

Sun Releases Java(TM) 6 Update 12

As of March 11, 2009, the current version of Sun's Java client is Java(TM) 6 Update 11.

Action Required:
If you see the Java Update icon or "Java Update Available" balloon in the lower right corner of the screen, the latest version of Java should be ready to install. You can click the icon and follow its prompts to apply the update. Note: We recommend that you do not install any offered "extras" like the MSN Toobar, OpenOffice.org Installer or Microsoft's Live Search. Please un-check these options if they appear.

Or, our How To Update Sun's Java Software, http://it.cas.psu.edu/260.htm, has complete steps on how to install Java from either the "Java Update Available" message or how to download and install Java manually .

Fixed:
This release contains feature enhancements and bug fixes. This full list of changes may be found here: http://java.sun.com/javase/6/webnotes/6u12.html

Note:
Previously, older versions of Sun Java were not removed from your computer when you updated. You had to manually remove older versions of Sun Java from your computer. This has now changed. You no longer need to remember to remove the previous Java version.

Thursday, February 26, 2009

Adobe Releases Flash Player 10 Update to Address Security Vulnerabilities

On February 24, 2009 Adobe released a Security advisory called Flash Player update available to address security vulnerabilities that announced the availability of updated Flash Player 10 software. The advisory states in part:

Summary
A potential vulnerability has been identified in Adobe Flash Player 10.0.12.36 and earlier that could allow an attacker who successfully exploits this potential vulnerability to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit this potential vulnerability. Additional vulnerabilities have been addressed in this update. Adobe recommends users update to the most current version of Flash Player available for their platform.

Affected software versions
Adobe Flash Player 10.0.12.36 and earlier.

Severity rating
Adobe categorizes this as a critical update and recommends affected users upgrade to version 10.0.22.87.

Action Required: Ag IT recommends that you update the Adobe Flash Player on your Enterprise machine to mitigate the effects of malicious SWF (Shockwave Flash) files that you might view in your web browser.

  1. To verify the Adobe Flash Player version number, you can visit the About Flash Player page. If this version is Flash Player 10.0.12.36 or earlier, please complete the remaining steps.
  2. To update to current Adobe Flash Player version, go to the Player Download Center.
  3. UN-CHECK any extra toolbars that are offered. Example: Google Toolbar.
  4. Click Agree and install now.
  5. Follow on-screen steps to install.
  6. When the installation completes, you should see the current version of Flash Player (10.0.22.87) displayed on the screen.

    NOTE: If you still see the older version (Example: 10.0.12.36), go to How to uninstall the Adobe Flash Player plug-in and ActiveX control and download the Adobe Flash Player uninstaller. Follow the steps to remove Adobe Flash. Then go back to the Player Download Center and install the new Adobe Flash Player again.

Note: If you use multiple browsers, perform the check for each browser you have installed on your computer.

Tuesday, February 10, 2009

Trouble Adding Participants to an Adobe Connect Meeting Space?

Have you created an Adobe Connect Meeting space that should be restricted to only certain participants, gone to add someone as a participant, and then not been able to find the participant in the Adobe Connect user list?

If so, it is likely because the user has never previously logged into an Adobe Connect meeting. Until a user logs into an “open” Adobe Connect meeting (one that is not restricted to certain participants) the Adobe Connect server does not realize they exist. It is not until after a user has logged into a meeting space that they are added to the Adobe Connect user list.

To resolve the issue, ask the user to log into http://breeze.psu.edu/opensite, which is a meeting space we have made accessible to anyone who has a Penn State or Friends of Penn State user account. Once the user gets log into the open meeting they can immediately exit out and then you should be able to find them in the Adobe Connect user list and add them to your meeting space.

Wednesday, January 21, 2009

QuickTime 7.6.0 Update Released

On Jan 21, 2009, an updated version of QuickTime was released (7.6.0). This update fixes an issue where a maliciously crafted URL may lead to an unexpected application termination or arbitrary code execution. In simple terms, malware could be installed on your computer. See more details here (Scroll down to the Security Updates section and click the link for QuickTime 7.6).

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required: Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Thursday, January 15, 2009

Error Message: Secure VPN Connection terminated locally by client. Reason 429

Within Penn State's VPN client, there are connection entries for "ITS Wireless at campusname." Entries include ITS Wireless at UP, ITS Wireless at Altoona, ITS Wireless at Beaver, etc. In the Host entry for these entries you see "mobility.campusname.psu.edu" (where campusname represents the abbreviation for a campus location. Entries include mobility.up.psu.edu, mobility.as.psu.edu, mobility.br.psu.edu, etc.

According to http://its.psu.edu/wireless/faq.html#21, "If you are in a location that has Penn State Wireless you need to launch the VPN client on your laptop and select the Penn State campus where you are located. Once you login using your Access Account, you can begin to use the wireless network for your tasks."

Situation:
According to http://alerts.its.psu.edu/alert-867, on Thursday, October, 23, 2008, all campuses using the ITS Wireless VPN service began using Cisco's Adaptive Security Appliance (ASA) platform. As a result, all campus wireless traffic is re-routed to ASA's located at University Park. In other words there is no longer a need for separate "mobility.campusname.psu.edu" names in the VPN client. In effect, all the VPN traffic needs to find mobility.up.psu.edu in order to connect.

If you attempt to use the VPN client to access an ITS Wireless location and receive this error, Reason 429: Unable to resolve server address, your laptop is unable to resolve mobility.up.psu.edu to its IP address.

Workaround:
You can create an ITS Wireless connection that uses the direct IP address for mobility.up.psu.edu.

  1. Open the VPN client. Click the New button.
  2. In Connection Entry, enter ITS Wireless.
  3. You may leave Description blank.
  4. In Host, enter 172.28.41.68.
  5. Under Group Authentication, the Name should be pennstate
  6. The Password and Confirm Password should also be pennstate

    Note: The passwords are case-sensitive (for example, Pennstate is not the same as pennstate)
  7. Click Save.
  8. You can use this connection to access ITS Wireless from any campus including University Park.

Wednesday, December 03, 2008

Sun Releases Java(TM) 6 Update 11

As of December 2, 2008, the current version of Sun's Java client is Java(TM) 6 Update 11.

Action Required:
If you see an alert icon in your notification area, lower right corner of screen, to update Java, you can click the icon and follow its prompts to apply the update. If you receive an "Error 1606" while installing, click Cancel. Click OK. Uncheck the Open Java Help box. Click Finish. You should restart the computer and try the install again.

Or, you can follow our How To Update Sun's Java Software, http://it.cas.psu.edu/260.htm instead.

Fixed:
This release contains feature enhancements and bug fixes. This full list of changes may be found here: http://java.sun.com/javase/6/webnotes/6u11.html

Note:
Previously, older versions of Sun Java were not removed from your computer when you updated. You had to manually remove older versions of Sun Java from your computer.

This has now changed. The previous version, Java 1.6.0_10, included code to allow patch-in-place to occur. So, from now on, you will not need to remember to remove the previous Java version.

Tuesday, November 11, 2008

version 8.1.3 Update for Adobe Acrobat 8 Professional and Adobe Reader is Available

Adobe shipped a critical update to its Adobe version 8 products on November 4, 2008 that addresses a number of customer workflow issues and security vulnerabilities.

Action Required: Ag IT recommends that College of Ag Science faculty and staff apply the 8.1.3 update to their EN machines.

Note: To determine the version of either of the above applications, open the Adobe program. Then from the Help menu choose About Adobe, (name of program). You should see the version listed in a new box. Then, you can click anywhere on this box to close it.

If you have the "full" version of Adobe Acrobat, Adobe Acrobat 8 Professional, you can update this program via its updater feature. Open Adobe Acrobat 8 Professional. From the Help menu, choose Check for Updates. If updates are found, close Adobe Acrobat 8 Professional. Then, click Download and Install Updates. When they complete, restart the computer.

If you have Adobe Reader version 8.1.2, on your computer, you can use the steps from How To Install and Configure Adobe Reader v8 for Windows, http://it.cas.psu.edu/222.htm, to apply the version 8.1.3 update.

Note: you can also try to use the updater feature for Adobe Reader as well. We have seen a number of 8.1.2 installations that lack the Check for Updates choice from the Help menu however. This is why we recommend the above How To.

Monday, October 27, 2008

Sun Releases Java(TM) 6 Update 10

As of Oct 27, 2008, the current version of Sun's Java client is Java(TM) 6 Update 10.

Action Required: Please follow our "How To Update Sun's Java Software" to update your Java software.

Fixed: This release contains feature enhancements and bug fixes. This full list of changes may be found here.

Note: Older versions of Sun Java are not removed from your system when downloading and installing new versions from Sun. Therefore, if you have the latest Sun Java version installed, then you should consider removing all older versions of Sun Java from your system. This can be done via "Add/Remove Programs" in the Microsoft Windows "Control Panel".

Friday, October 24, 2008

Audio Problem Troubleshooting Suggestions from Adobe Connect (Breeze)

Issue: Since PSU ITS updated to Adobe Connect v7 earlier this year, there have been intermittent audio issues during Adobe Connect meetings and trainings.

This Tech Alert is in response to an ALERT from Adobe:
In Connect 7, Adobe included an “enhanced” audio solution for PC users when running the audio setup wizard. It’s in the advanced settings area. This is different than Connect v6 and the cause of some of the problems out there. Until the service pack fix is initiated, I believe this enhanced audio feature is defaulting to “on”. We would like everyone to turn that off as a troubleshooting option (and it will default to off with the service pack).

This means everyone in the meeting should have the enhanced audio box checked to “off”. Otherwise, the enhanced audio may create problems with gain and other audio pickup and cause “breaks” in the delivery for everyone (on a congested network).

The service pack referred to is expected sometime in November. We will pass along information as it becomes available. Additional troubleshooting tips received today are posted at http://meeting.psu.edu/node/519.

Action Required (if you use Adobe Connect): EACH TIME you log into an Adobe Connect Meeting, you need to run through the Audio Set-up Wizard to configure your audio. As you go through the Audio Set-up wizard, the last window called “Finished,” click on the Advanced Settings button, then look for the checkbox in the upper right-left portion of your screen. Uncheck the “use Enhanced Audio.”

If you have questions, don’t hesitate to contact Ag IT Support.

Thursday, October 16, 2008

Adobe Releases Flash Player 10 to Address Security Vulnerabilities (Clickjacking)

Adobe Systems has released a new version of its Flash Player software. This version includes a fix for the critical security bug that allowed hackers to hijack your browser in what's come to be known as a clickjacking attack.

On Oct 15, 2008 Adobe released a Security advisory called Flash Player update available to address security vulnerabilities that announced the availability of new Flash Player 10 software. The advisory states in part:

Summary
Potential vulnerabilities have been identified in Adobe Flash Player 9.0.124.0 and earlier that could allow an attacker who successfully exploits these potential vulnerabilities to bypass Flash Player security controls. Adobe recommends users update to the most current version of Flash Player available for their platform.


Affected software versions
Adobe Flash Player 9.0.124.0 and earlier.


Severity rating
Adobe categorizes this as a
critical update and recommends affected users upgrade to version 10.0.12.36.

Action Required: Ag IT recommends that you update the Adobe Flash Player on your Enterprise machine to mitigate the effects of clickjacking.
  1. To verify the Adobe Flash Player version number, you can visit the About Flash Player page. If this version is Flash Player 9.0.124.0 and earlier, please complete the remaining steps.
  2. To update to current Adobe Flash Player version, go to the Player Download Center.
  3. Click Agree and install now.
  4. Follow on-screen steps to install.
  5. When the installation completes, you should see the current version of Flash Player displayed on the screen.

Note: If you use multiple browsers, perform the check for each browser you have installed on your computer.

Wednesday, October 08, 2008

Security Risk - Clickjacking

Clickjacking is a nasty security risk — it’s transparent to you the user, easy to put into operation and difficult to stop.

What is Clickjacking? This threat was brought to the public's attention in late September 2008. According to researchers Robert Hansen and Jeremiah Grossman, clickjacking happens when your browser is directed to a malicious Web site when you click on what appears to be a valid link.

How does this happen? First, a hacker has to break in and compromise a good site. The hacker can then set their external, malicious content to be invisible and overlay the normal page with a "transparent" cover. When you click on the normal page, you are in fact clicking on the externally loaded page. The content or page which then loads is whatever the hacker wants. For example, it could install a malware program like a rogue Anti-Spyware program.

In another clickjacking scenario, the page may not need to have the transparent overlay. Instead, the good page may have been hacked to contain JavaScript code that makes the invisible target constantly follow the mouse pointer, intercepting your first click wherever it may be.

On Oct 7, 2008 Adobe released a Security advisory called Flash Player workaround available for "Clickjacking" issue. The advisory states:

SUMMARY
Adobe is aware of recently published reports of a 'Clickjacking' issue in multiple web browsers that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. It has been determined that this potential "Clickjacking" issue affects Adobe Flash Player. Adobe is working to address this issue in an upcoming update to Flash Player.

SOLUTION
Customers:
To prevent this potential issue, customers can change their Flash Player settings as follows

  1. Access the Global Privacy Settings panel of the Adobe Flash Player Settings Manager at the following URL: http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html
  2. Select the "Always deny" button.
  3. Select 'Confirm' in the resulting dialog.
  4. Note that you will no longer be asked to allow or deny camera and / or microphone access after changing this setting.

    Customers who wish to allow certain sites access to their camera and / or microphone can selectively allow access to certain sites via the Website Privacy Settings panel of the Settings Manager at the following URL:
    http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager06.html.

Action Required: Ag IT recommends that you follow the Adobe steps to mitigate the effects of clickjacking.

Note: If you use Adobe Connect (Breeze) for meetings or trainings, you will need to allow these sites access to Flash Player as mentioned in Step 4.

For detailed steps on how to do this, you can use our How To Allow "Camera and Microphone Access" in Adobe Connect (Breeze) steps.

Wednesday, October 01, 2008

Another Phishing message circulating

Faculty and staff are reminded that the College and University will *NEVER* request account/password information via email.

You should never reply to a message asking for account information, nor should you ever click a link from a message that asks for account information. Penn State and the College of Ag Sciences will never ask for your account/password in this method. If you receive messages of this type in the future, simply delete the message.

Here is an example of the latest phishing that we have seen in the College.


Date: Wed, 1 Oct 2008 14:28:01 +0200 (CEST)
Subject: Account Expire in 4 Day(s)
From: "IT SERVICE"


Dear Webmail User,

This message was sent automatically by a program on Webmail which
periodically checks the size of inboxes, where new messages are received.
The program is run weekly to ensure no one's inbox grows too large. If
your inbox becomes too large, you will be unable to receive new email.
Just before this message was sent, you had 18 Megabytes (MB) or more
of messages stored in your inbox on your Webmail. To help us re-set
your SPACE on our database prior to maintain your INBOX, you must
reply to this e-mail and enter your

Current User name ( )
and Password( ).

You will continue to receive this warning message periodically if your
inbox size continues to be between 18 and 20 MB. If your inbox size
grows to 20 MB, then a program on Bates Webmai will move your oldest
email to a folder in your home directory to ensure that you will
continue to be able to receive incoming email. You will be notified by
email that this has taken place. If your inbox grows to 25 MB, you
will be unable to receive new email as it will be returned to the
sender.
After you read a message, it is best to REPLY and SAVE it to another
folder.

Thank you for your cooperation.
WEBMAIL Help Desk

Tuesday, September 23, 2008

Computer Account Requests - New Processes as of Sept 2, 2008

In the past, we have had different account processes and services for many different types of employees and volunteers. We now have streamlined the account process down to two divisions. We will follow one process if the employee is paid by Penn State, and follow a second process if the person is not paid by Penn State.

One of the most significant changes in the process is that the College of Ag IT Unit will no longer play a role in applying for or receiving a Penn State Access Account. Computer security policies no longer allow us to receive an employee’s confidential account information. New employees will file the access account application form directly with the Accounts office at University Park, and will need to visit any campus of the university to receive their password. We used to provide an intermediary service for these account procedures, it is now against policy to do so.

If the person is paid by Penn State, he/she will need to apply for a Penn State Access Account. This username and password combination will grant the employee access to manage their Penn State benefits online, to access Penn State Library information, to connect to authorized Penn State wireless services, to use Penn State campus training computer labs, and to login to CASPAR. Additionally, the employee will need to apply for a College of Ag domain account to gain access to other needed services – to use Enterprise computers, to send and receive e-mail using the College’s Outlook/Exchange system, and to connect to SharePoint services.

Account request process for Penn State paid employees can be found at - http://it.cas.psu.edu/1207.htm

Everyone else NOT paid by Penn State - county paid staff, student interns, and dedicated volunteers who need access to college computers (office computers or SharePoint Sites) to perform their duties - do not receive a Penn State Access Account. They must apply for a “Friends of Penn State” account and the College of Ag Domain Account. Depending on the services requested when the account is created, the domain account will enable this person to use Enterprise computers, send and receive e-mail through the College’s Outlook/Exchange mail system and connect to SharePoint services.

Account request process for County paid employees can be found at - http://it.cas.psu.edu/386.htm

Thank you for your cooperation and patience as we help to make these new processes more routine.

Wednesday, September 10, 2008

QuickTime 7.5.5 Update Released

On Sept 9, 2008, an updated version of QuickTime was released (7.5.5). This update fixes an issue where a maliciously crafted movie file may lead to arbitrary code execution on your computer. In simple terms, malware could be installed on your computer. See more details here (Scroll down to the Security Updates section and click the link for QuickTime 7.5.5).

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required: Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Tuesday, August 05, 2008

Adobe urges users to validate Software Update Installers

The Adobe Product Security Incident Response Team (PSIRT) posted a Verifying Installers entry on August 4, 2008 (in italics below). They added this notice following the news that malware links are being included in the comments sections of such Web 2.0 sites as MySpace and Facebook. Hackers are attempting to trick Windows users into installing a Flash Player update that turns out to be a malicious program. To read more about these worms, see Web worms squirm through Facebook, MySpace.

Adobe makes a number of good points below, that we've bolded. Even if you don't use sites like MySpace, Facebook or Twitter, you should be very cautious of links or pop-ups that want you to download and install software. If in doubt, just say NO. You should also be aware that you can verify valid software by checking its digital certificate.

"We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.

We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player
here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.

Second, all Adobe software for Windows is signed with a digital certificate that is validated by Windows when you install our software. The Publisher will always be ‘Adobe Systems, Incorporated’, and you can verify this when you double-click the installer, or by right-clicking on the installer, selecting ‘Properties’, and going to the ‘Digital Signatures’ tab.

For Flash Player in particular, you can always go to
this page to verify what version of Flash Player you have installed, and what the current version of Flash Player is for your Operating System. The current Flash Player version is 9.0.124.0."

Thursday, July 10, 2008

Adobe Reader v9.0 is Available

As of June 25, 2008, the current version of the Adobe Acrobat and Adobe Reader is version 9.0.0.

NOTE: If you have version 8.1.2 with Security Update 1 of either Adobe Acrobat or Adobe Reader, you do not need to update to version 9.0.0. You can continue to use the 8.1.2 version.

If you would like to install the new Adobe Reader, please see our How To Install and Configure Adobe Reader v9 for Windows for steps on updating Adobe Reader to the current version.

If you would like to purchase a license for the "full" version of Adobe Acrobat 9, this is available to faculty, staff and students at the Penn State Computer Store at http://www.computerstore.psu.edu/. Adobe Acrobat is Departmental Site Licensed software.

From the Computer Store's home page, click Departmental Licenses then click Adobe License. You will see a Acrobat 9 Pro Win License ($56.00 SLWNSR046) and Acrobat 9 Pro Win DVD Media ($7.50 SMWNSR054). These are sold separately. Why? Often a Department will buy 1 copy of the media. Then Faculty or Staff purchase their individual license for $40. You can then sign out the departmental DVD for the install. But, if you want a DVD of your own, you would need to purchase both a copy of the media along with a paper license.

Wednesday, July 09, 2008

Sun Releases Java(TM) 6 Update 7

As of July 9, 2008, the current version of Sun's Java client is Java(TM) 6 Update 7. Please follow our "How To Update Sun's Java Software" to update your Java software.

Fixed: This release contains fixes for one or more security vulnerabilities.

Note: Older versions of Sun Java are not removed from your system when downloading and installing new versions from Sun. Therefore, if you have the latest Sun Java version installed, then you should consider removing all older versions of Sun Java from your system. This can be done via "Add/Remove Programs" in the Microsoft Windows "Control Panel".

Tuesday, June 24, 2008

Adobe Releases Security Update 1 for Adobe 8.1.2

A critical vulnerability has been identified in Adobe Reader and Acrobat 8.1.2. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system.

Adobe recommends users of Acrobat 8 and Adobe Reader install the 8.1.2 Security Update 1 patch. Adobe Reader is installed on all Enterprise computers.

To see what version of Adobe Reader you have installed, follow these steps:

  1. Open Adobe Reader.

  2. From the Help menu choose About Adobe Reader ....

    Note: You will see the version number listed in this window.

  3. Click the version window to close it.

  4. If you saw Version 8.1.2, go to the Apply Security Update 1 section of our How To Install and Configure Adobe Reader for Windows for steps on applying the Security Update.

    If you have an earlier version than 8.1.2, please see our How To Install and Configure Adobe Reader v9 for Windows for steps on downloading the new version, remove any old versions, install the new version and apply the Security Update 1 patch.
If you are still using a previous version of the "full" Adobe Acrobat (version 7), Adobe recommends Acrobat 7 users on Windows update to Acrobat 7.1.0, available here: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows

Full details can be found on the Adobe Security Update available for Adobe Reader and Acrobat 8.1.2 page.

Thursday, June 12, 2008

Install Compatibility Pack to Read Office 2007 Files - Service Pack 1 (SP1)

The Compatibility Pack for the 2007 Office system allows computers with Microsoft Office 2003 to open Office 2007 documents.

Microsoft has released Office Compatibility Pack Service Pack 1 (SP1) which contains security, stability, and performance improvements. If you have Compatibility Pack for the 2007 Office system installed on your Enterprise (EN) machine, you should apply this update.

Action Required for Office 2003 Users Only:
Please see our How To Install Compatibility Pack SP1 to Read Office 2007 Files for steps on applying the SP1 update.

Note: If your EN machine has Microsoft Office 2007, you should not follow these steps!

Tuesday, June 10, 2008

QuickTime 7.5 Update Released

On June 9, 2008, an updated version of QuickTime was released (7.5). This update includes fixes that improves application compatibility and addresses security issues. See more details here (Scroll down to the Security Updates section and click the link for QuickTime 7.5).

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required: Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Wednesday, May 14, 2008

Windows XP Service Pack 3 News

Microsoft has made Windows XP Service Pack 3 (SP3) available for download on the Microsoft Update site.

Windows XP SP3 is the final Windows XP service pack. It's a collection of all previously-released fixes and security updates for Windows XP (this was well over 100 separate fixes).

IT Support staff have installed Windows XP SP3 on several our EN machines. College Faculty and Staff with EN machines are encouraged to NOT install this update on your EN machine at this time. We will notify staff when we have completed testing and are ready to implement Windows XP SP3.

Enterprise (EN) computers has been configured to automatically download High Priority updates. At this time, Windows XP SP3 will not be installed via this automatic process. If you see the High Priority update upright shield in your Notification Area, you can choose to install these updates.

Our How To Install High Priority (Critical) Updates page has been updated with steps and images of the manual install High Priority updates process. This process will show you XP SP3 update. The steps walk you through how to avoid applying the update in this process.

Tuesday, April 22, 2008

Sun Releases Java(TM) 6 Update 6

As of April 21, 2008, the current version of Sun's Java client is Java(TM) 6 Update 6.
Plase follow our "How To Update Sun's Java Software" to update your Java software.


Fixed: This release contains fixes for one or more security vulnerabilities.


Note: Older versions of Sun Java are not removed from your system when downloading and installing new versions from Sun. Therefore, if you have the latest Sun Java version installed, then you should consider removing all older versions of Sun Java from your system. This can be done via "Add/Remove Programs" in the Microsoft Windows "Control Panel".

Thursday, April 03, 2008

QuickTime 7.4.5 Update Released

On April 2, 2008, an updated version of QuickTime was released (7.4.5). This update includes fixes that enhance reliability, improve compatibility with third-party applications, and addresses security issues. See more details here.

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required: Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Wednesday, March 19, 2008

Apple Software Update offers Safari 3.1 Web browser

Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College). We've recommended and installed QuickTime for a number of years. In the past year, Apple has included software called 'Apple Software Update' as part of the QuickTime install. In our How To Install QuickTime for Windows using the Standalone Installer, we recommend that this software is installed. The Apple Software Update software looked for new releases of QuickTime and prompted you to install new versions.

On March 18, 2008 Apple began offering their current web browser, Safari v3.1, via Apple Software Update as well.

We recommend that you do not install Safari on your Enterprise computer.

You should un-check this option if it appears. We also strongly recommend that you use Microsoft Internet Explorer (IE) as your browser. As an example, Internet Explorer is compatible with the College's SharePoint sites. If you use multiple browsers, we recommend that you use IE as your default browser. To minimize software conflicts do not run different browsers at the same time. If conflicts appear, you may need to reboot your computer and run only the browser of your choice.

Wednesday, March 05, 2008

Sun ODF Plugin 1.1 for Microsoft Office

The Sun ODF Plugin for Microsoft Office allows users of Microsoft Office to read, edit and save to the Open Document Format (ODF). The new version (1.1) adds more languages and improves the import and export of ODF files into Microsoft Office, increasing the interoperability of the Plugin.

The Sun ODF Plugin for Microsoft Office gives users of Microsoft Office Word, Excel and PowerPoint the ability to read, edit and save to the ISO-standard Open Document Format (ODF). The plugin works with Microsoft Office 2007 (Service Pack 1 or higher).

Note: You would only need to download and isntall this software if you commonly receive StarOffice or OpenOffice attachments from others.

FAQs for Sun ODF Plugin 1.1 for Microsoft Office
http://www.sun.com/software/star/odf_plugin/faqs.jsp

Link to Download the software is on the above page.

Sun Releases Java(TM) 6 Update 5


As of March 5, 2008, the current version of Sun's Java client is Java(TM) 6 Update 5.

Plase follow our "How To Update Sun's Java Software" to update your Java software.

Fixed:
This release contains fixes for one or more security vulnerabilities.

Note:
Older versions of Sun Java are not removed from your system when downloading and installing new versions from Sun. Therefore, if you have the latest Sun Java version installed, then you should consider removing all older versions of Sun Java from your system. This can be done via "Add/Remove Programs" in the Microsoft Windows "Control Panel".

Tuesday, February 26, 2008

Adobe Vulnerability Requires Update to Adobe Acrobat and Adobe Reader

Adobe Acrobat and Adobe Reader users should install Adobe's new 8.1.2 update immediately to protect themselves from potential software vulnerabilities, according to ITS Security Operations and Services (SOS).

Adobe has recently released Acrobat/Reader version 8.1.2 to combat the Zonebac trojan vulnerabilities in all previous Acrobat and Reader versions (8, 7.0.9, 7 and earlier). Adobe Reader is installed on all Enterprise computers.

If you are currently in the Enterprise Network (AG domain), IT will automatically update Adobe Reader on your computer starting Wednesday February 27th. Your computer will receive the update the first time it is available on the network. You do not need to leave your computer in the office that evening.

If you are not a part of the Enterprise Network, please see our How To Install and Configure Adobe Reader for Windows for steps on updating Adobe Reader to the current version.

Keep in mind, only version 8 of the "full" Adobe Acrobat can be updated for free. If you are still using a previous version of the "full" Adobe Acrobat (versions 7 and earlier), you should purchase a license for Adobe Acrobat 8. This is available to faculty, staff and students at the Penn State Computer Store at http://www.computerstore.psu.edu/. Once the software has been purchased, you can remove the vulnerable older version, install the new version, and then visit the Adobe Web site at http://www.adobe.com/ to apply the necessary product updates.

Adobe Acrobat is Departmental Site Licensed software. If you search for Adobe Acrobat 8.0 in the Computer Store's Product Quick Search box, you will see a Acrobat Pro 8.0 Win License ($40.00 SLWNSR040 ) and Acrobat Pro 8.0 Win Media ($5.00 SMWNSR036). These are sold separately. Why? Often a Department will buy 1 copy of the media. Then Faculty or Staff purchase their individual license for $40. You can then sign out the departmental CD for the install. But, if you want a CD of your own, you would need to purchase both a copy of the media along with a paper license.

Thursday, February 21, 2008

Sun Releases Java(TM) 6 Update 4

As of Feb 21, 2008, the current version of Sun's Java client is Java(TM) 6 Update 4.

Plase follow our "How To Update Sun's Java Software" to update your Java software.

Fixed:
This update fixes a security issue allowed malicious people to bypass security restrictions and run malicious XML data within a trusted applet or Java Web Start application.

Note:
Older versions of Sun Java are not removed from your system when downloading and installing new versions from Sun. Therefore, if you have the latest Sun Java version installed, then you should consider removing all older versions of Sun Java from your system. This can be done via "Add/Remove Programs" in the Microsoft Windows "Control Panel".

Monday, February 11, 2008

Cisco VPN Client 5.0.02 Released

An updated version of the Cisco VPN Client is now available from downloads.psu.edu.

Virtual Private Network (VPN) software is used by Penn State faculty, staff and students when connecting to a Penn State network from any other ISP (internet service provider). For example, if you take a EN notebook on the road, you should connect with the the VPN Client software as soon as you establish a network connection. Then you can open OWA or browse the Internet.

The Cisco System VPN Client is installed on all Enterprise computers.

Action Required:
Please see our How To Install the VPN Client v5.x for Windows XP for steps on updating the Cisco VPN client to the latest version.

To determine what version of the VPN client installed on your computer, from the Start menu choose All Programs then click Cisco Systems VPN Client. From the Help menu choose About VPN Client. If the version is lower than 5.0.02, you should update the VPN software.

[UPDATE Feb 14, 2008] We have had reports of the VPN install process locking up in County Extension Offices. The steps now include unplugging the network cable from the machine at the appropriate time. If the computer is connected to the network during the install, the process will not complete! This may be difficult for desktops but it is required.
-jsw

Thursday, February 07, 2008

QuickTime 7.4.1 Update Released

On Feb 7, 2008, an updated version of QuickTime was released (7.4.1). This update fixed an issue where visiting a malicious website could lead to an unexpected application termination or arbitrary code execution. See more details here.

QuickTime is installed on all Enterprise computers. Apple's QuickTime software allows your Enterprise computer to view graphics, videos, on-line video streams (ex: Candidate Interviews in the College), and more.

Action Required:
Please see our How To Install QuickTime for Windows using the Standalone Installer for steps on updating QuickTime to the latest version.

Wednesday, February 06, 2008

Update to Adobe Reader v8 released (8.1.2)

On February 6, 2008, an update to version 8 of Adobe Reader was released (8.1.2). This update addresses a number of customer workflow issues and security vulnerabilities while providing more stability. More here.

UPDATE 2-25-08: Adobe Acrobat and Adobe Reader users should install Adobe's new 8.1.2 update immediately to protect themselves from potential software vulnerabilities, according to ITS Security Operations and Services (SOS). If you are currently in the Enterprise Network (AG domain), IT will automatically update Adobe Reader on your computer starting Wednesday February 27th. Your computer will receive the update the first time it is available on the network. You do not need to leave your computer in the office that evening.

UPDATE 2-20-08: According to the following PSU ITS Alert, "The University has experienced a large number of incidents related to a type of PDF-based hostile code that has been circulating through the use of vulnerable (pre 8.1.2.) versions of Acrobat and Reader software. When users open the infected PDF file it downloads a variant of the "Zonebac" trojan horse, resulting in control of the individual's computer system. The code also attempts to render all antivirus applications inoperable."

Adobe Reader is installed on all Enterprise computers. All College faculty and staff are encouraged to update their Adobe Reader software to this version.

Please see our How To Install and Configure Adobe Reader for Windows for steps on updating Adobe Reader to the current version.

Quick tip: If you already have version 8 of Adobe Reader installed (from the Help menu choose About Adobe Reader to see the version), follow these steps to apply the update.


  1. From the Help menu choose Check for Updates.
  2. If updates were found, they should begin to download.
    If not, click the Download and Install Updates button.
  3. At this point, you can click the Adobe Reader window to make it active, then Exit Acrobat Reader. If you don't exit Adobe Reader, the updater will prompt you to shut down Adobe Reader by clicking Continue.
  4. When the update finishes downloading, click Install Now.

    Note: The Installation Progress window may be minimized to the lower right of the screen (in the notification tray). To see the Installation Progress window, right click on its white icon and choose Show Progress.
  5. Wait for the update to be applied. When the process completes, click Quit.


Tuesday, November 20, 2007

SAV alert possible with Logitech webcam

If you have a Logitech webcam installed you AND you update SAV to 10.1.7.x, you MAY receive an SAV alert box about a Tampering Protection scan.
This happened to me and this is what I did to get it resolved:

Go there - http://www.logitech.com/index.cfm/support_downloads/downloads/&cl=us,en
Select Product type - webcams
Select Product name - ie - Logitech pro 5000
Click greenish/blue arrow

Should see a picture of your webcam and QuickCam Pro 5000
Click Get Software

Select OS - Windows XP
Select File - Multilingual 32-bit
Click Download Software

Click Save
Save to your desktop
Once downloaded, double-click on the exe file (ie. qc1150.exe)
Allow to install and follow the steps on screen.
NOTE: You will need to unplug and re-plug your camera during the installation so follow the instructions on screen.

Once the new Logitech software was installed, it opened and wanted me to test the audio and wizard.

And...no more SAV alerts!

Monday, November 19, 2007

Symantec AntiVirus (SAV) version 10.1.7 is available

Action Item: An updated version of Symantec AntiVirus is available from the Penn State ITS Downloads page.

Please see our How To Install and Configure SAV Corporate Edition 10.1 for Windows for complete steps on installing or updating to the newest version of Symantec AntiVirus.

Please take the time to follow the above How To on your College Enterprise machine to update the computer to the most up-to-date AntiVirus protection.

Friday, October 26, 2007

Office 07 - Post installation tips

1. Shortcuts that point to the Office 2003 will no longer work. You will need to delete any shortcuts that still point to the "old" Office applications! You can then recreate shortcuts for the new Office 2007 applications. You can find the new applications by clicking Start ... All Programs ... Microsoft Office.

2. When looking for the new Outlook ... it's now called Microsoft Office Outlook 2007, don't open Outlook Express by mistake. We don't use Outlook Express.

Office 2007 - it's here!

Here's our Office 2007 Project page - http://ict.ag.psu.edu/Office2007.html

We've begun to add How To's to the IT website that focus on Office 2007. Look here for the list. More will be added in upcoming weeks as we receive questions from you.
http://go.cas.psu.edu/howto/HowToList.cfm?Cat=Microsoft-Office-2007

New Office 2007 users should look for the small blue and white Help button in the upper right of Office 2007 applications. It looks like a question mark. The Ed Tech's have a page with links to assist you in learning more about Office 2007 as well.
http://ict.ag.psu.edu/Training/Office2007LearningOpps.html

We also have a How To for staff still using Office 2003. With Office 2007 being installed in the College, staff that are still using Office 2003 may see a message that they need to download a ‘compatibility pack’ to work with a file saved in the newer format. For example, when someone opens a Word 2007 document with Word 2003, a message will appear that says: "This file was created by a newer version of Microsoft Word. Do you want to download a compatibility pack so that you can work with this file?"
If you see a message like that, you should click Cancel.

Follow the steps in the below How To and check for updates and install the compatibility pack. By installing the compatibility pack for earlier version of Microsoft Office you will be able to open, edit, and save files using the 2007 file formats new to Word, Excel, and PowerPoint.

How to Install Compatibility Pack to Read Office 2007 Fileshttp://ict.ag.psu.edu/training/howto/office07/CompatibilityPack.htm

Thursday, October 04, 2007

Sun Releases Java(TM) 6 Update 3

As of Oct 2, 2007, the current version of Sun's Java client is 1.6.0_3. If you have previous versions of this Plugin installed, you should remove them. If you have installed Sun's Java client, please follow our "How To Update Sun's Java Software" to update your Java software.

http://ict.cas.psu.edu/Training/howto/util/sun_java_update.htm

Thursday, September 06, 2007

Update to Annual Password Change

The following email was sent out by ITS on Sept 6, 2007. It describes a change in policy for the annual password change from Penn State. This change will occur on September 11, 2007.

See the email below.


-Start-

"The annual password change initiative that went into effect last year requires users to change their passwords periodically. The way things currently stand WebAccess forces users to change their passwords with no prior warning. This has created problems for some users. To alleviate this problem, ITS will implement the following on Tuesday, 9/11/07:

1.) Eight (8) weeks before the password expires, ITS will send an email notification of the expiration date. This email notification will be sent weekly until the password is changed or expires.

2.) Four (4) weeks before the password expires, WebAccess will require users to change their password.

3.) If the password expires, the user will have to go to a signature station to reinstate the account.


The email notification that the users will receive is shown below:

Dear Penn State Access Account Holder,

Penn State's password initiative requires that you change your Penn State Access Account password periodically. Please change your password before 12/03/07. If you do not change your password by 12/03/07, you will be required to change it when you log in to any application that uses WebAccess (WebMail, ANGEL, ESSIC, etc.)

Your current password will expire on 12/31/07. If you do not change your password by this date, your password will expire.

If your password expires, you will lose access to University e-mail and Internet services, and you will need to go to a signature station at one of the University's campuses or you will need to contact the ITS Account Services Office in the Computer Building to reinstate your connection to the Penn State network.

The password change requirement increases the personal security of all Penn State community members and helps protect business, research and academic resources throughout the University. Thank you for your
cooperation.

For more information or to change your password, visit its.psu.edu/password on the Web. If you have questions, call the help desk at 814-863-1035 or 814-863-2494 or send e-mail to
helpdesk@psu.edu
."

-Stop-



Tuesday, September 04, 2007

New Ninja How To's posted

We have posted several new How To's that will help you turn off Outlook's spam filtering and one to help you understand how the 3 spam folders for Ninja work. These How To's are available at http://go.cas.psu.edu/howto/HowToList.cfm?Cat=Ninja

Monday, August 20, 2007

Ninja - Turn off Outlook's junk e-mail filtering

From: AgCompSupport [mailto:AgCompSupport@psu.edu]
Sent: Monday, August 20, 2007 4:26 PM

Subject: Turning off Junk E-mail and Rules in Outlook

With the configuration of Ninja moving along, we are now ready to turn off junk e-mail and rules in Outlook.
Turn off Junk E-mail filtering in Outlook 2003
1. Open Outlook.
2. Under Actions on the menu bar, pull down to Junk E-mail, then pull down to Junk E-mail Options.
3. A new window will open up. Choose No Automatic Filtering.
4. Click OK.
5. Quit and re-open Outlook.

Turn off Specific Rules and Alerts in Outlook 2003 and 2007
1. Open Outlook
2. Under Tools menu, choose Rules and Alerts. A new window will open
3. If present, Uncheck rule: X-Spam-Flag: YES
4. click OK.
5. Quit and re-open Outlook.

Thanks,
Mike Leiter, Support Coordinator

Ninja installed on August 8

Ninja, an antispam/antivirus software, was installed on the College’s Exchange servers on Wed, August 8. [Update: Ninja was not installed on Aug 8th. The planned install was postponed and Ninja was installed on Aug 15th - vcv]. It will help block and actually delete known Spam messages before they even hit our mailboxes. You should now see a Spam folder in your Outlook folder list. In that folder, there are 3 folders: Allowed Senders, Blocked Senders, and Quarantine.

As we work to get the filter levels correct, we still need to know from you if you are getting good mail in the Quarantine folder. Please send an AgCompSupport@psu.edu a note if you receive a good message in this Quarantine folder. You can move this good message to your inbox simply but clicking and dragging to Inbox. There are many filter settings so we can adjust them as needed. We hope to eventually get all the spam/junk messages going to the Quarantine folder or perhaps not even making it to our mailboxes at all!

You may actually notice that you are getting MUCH less spam arriving in your Junk E-mail or Spam folders. This is because Ninja is deleting messages that are 100% obvious spam and it never arrives to our mailboxes. As we adjust the settings we hope to delete more and quarantine less of these spam messages.

Once we get more of the filter settings adjusted, we will be providing directions on how to turn off the Junk E-mail folder provided by Outlook. It won’t be needed with Ninja fully functioning.

So you may be asking what do I do with the other folders under Spam – the Allowed Senders and Blocked Senders. These folders allow you to “personalize” what messages you receive or don’t receive if they end up in your Inbox or your Quarantine folder.

  • The Allowed Folder Use the Allowed folder to create a list of email addresses from which you always want to receive messages. Any message you drop in the Allowed folder will not be quarantined. If you want an email to get through, to but do not want to add it to your contact list (i.e. a list to which you subscribe), simply drop one message from this sender into the Allowed folder. Future messages from this address should then appear in your In mailbox.
  • The Blocked Folder You can use the Blocked folder to create a list of users from whom you do not want to receive messages. There is no need to maintain a large list in the Blocked folder since most unsolicited spam emails are caught by Ninja before they reach your inbox. However, if you receive messages that still slip, simply drop one of these messages into your Blocked folder and you will not receive another message from that sender.

How does the Quarantine Folder work?Any messages that meet the preset spam criteria are automatically placed into this folder. Our System Administrators have determined the selection criteria in your spam detection settings. We recommend that you delete individual messages or the entire contents of the folder on a regular basis to keep the size of the folder low and make sure your mailbox is free of spam.

You can also drag messages from this folder to any other folder. If you want to continue receiving messages from a sender, drag the current messages into the Allowed folder. If you want to block future messages from a sender, drag them into the Blocked folder.
In addition, you can delete the Quarantine folder anytime, erasing the entire contents of spam messages in one easy step. The next time you receive a message containing spam, the system automatically rebuilds the folder and places the new spam message into it.

And finally, one final tip from Ninja on making their Spam Filtering work better for you – Keep your Contacts list Current. Any email address or user in your contact list will not be quarantined. Keep your Contacts list is up-to-date by adding or deleting contacts as needed.

Stay tuned for more information about Ninja.

Thursday, July 19, 2007

Flash Player update available to address security vulnerabilities

Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. Users are recommended to update to the most current version of Flash Player available for their platform.

To see what version of Macromedia Flash Player you have, go to this Adobe Flash Player page. Wait for the page to load. The version will be displayed in a box called "Version Information." If it says "You have version 9,0,47,0 installed" then you have the newest version.

Adobe recommends all Flash Player 9.0.45.0 and earlier upgrade to the new version, which can be downloaded from the Player Download Center.

Note: If you visit this page, you should uncheck the installation for the Google Toolbar!

Wednesday, July 18, 2007

Sun Releases Java(TM) 6 Update 2

As of July 18, 2007, the current version of Sun's Java client is 1.6.0_2.

If you have previous versions of this Plugin installed, you should remove them. If you have installed Sun's Java client, please follow our "How To Update Sun's Java 2 Runtime Environment Plug-in" to update your Java software.

http://ict.cas.psu.edu/Training/howto/util/sun_java_update.htm

Thursday, July 05, 2007

Startup Message: Computer must be restarted before updating can continue

Each time you start your computer you see the following message:
The Computer must be restarted before updating can continue. Would you like to restart now?
Your choices are Yes or No. If you click Yes, the computer is forced into a reboot, but the message returns. If you click No, you can work normally.

ISSUE: You may have a failed Adobe Reader 8 update. This updater places an entry in a Registry RUN key for the "AdobeUpdater.exe" application. The "AdobeUpdater.exe" application is located here: C:\Program Files\Common Files\Adobe\Updater5

If you open these folders and double-click on the "AdobeUpdater.exe" application, you should see the same message as above.

To test if you need to do the Workaround, do this first. Open Adobe Reader 8. From the Help menu choose Check for Updates. If the program checks for updates and finds them, apply. This may solve the issue. But if you see the same error message after a restart, you should do the Workaround steps are provided in our eNews article.

Switching displays on a Laptop takes time

From the Microsoft Knowledge Base Article KB 937930, You may be unable to switch between displays on a portable computer that is running Windows XP.

The article is listed as applying to Microsoft Windows XP Professional, not to Microsoft Windows XP Professional with Service Pack 2. So, this may be a moot point for our College Enterprise machines. But I found it interesting that the article lists the "wait for a full minute before you try to switch displays" as a workaround.

If you have this issue on your machine, you can at least try that.

Fake Greeting Card E-mails and Sites

In last year's eNews, we ran an article called eCard Sites To Stay Away From. If you go to some of these sites to send a virtual greeting card, you ran the risk of becoming infected with malware.

Normally, when you use sites like AmericanGreetings.com or Hallmark.com to send a virtual birthday, anniversary, etc. to friends or family, the process works like this. You pick a card, create a message, and enter the person's email address. You add your own email address and you can send the E-card. Your friend or family member is notified to pick up the card on the web site via email. They will need to click on a link in the message to see the greeting. Pretty standard stuff.

Recently, phishers have begun to exploit this common service in a new way. You might RECEIVE a fake card with URLs that, when clicked on, take you to a malicious site. The computer can then be infected with malware that attempts to steal information to be used for identity theft.

Most of the real greeting card services give you, in the email notice, the name or email address of the sender. If the message simply says "a friend sent you a card," with no identifying info, as in the above example, DELETE the message without clicking on the link.

Friday, June 22, 2007

Adding Signatures in Outlook 2003 with Word as the E-mail Editor

If you have enabled Word to be the editor of Outlook 2003 E-mail messages, you may have "lost" a common Outlook function. You appear to lose the toolbar icon to add/delete/change signatures in an e-mail message. Here's the alternate process to add a signature to a message.
In Outlook 2003, create a new signature, but put nothing in it - no text at all. Name it something obvious - "empty" or "blank" etc.

Now, when creating a new message, you will have the opportunity to right-click on the default signature appearing in the new message. Right-clicking presents a list of all signatures for selection -including the blank signature.

If you would like the message sent without a signature, select "blank" and the mail will be sent without appearing to have a signature line.

Java problems in QuickTime

Apple is recommending that QuickTime users download its update for Version 7.1.6 to fix a pair of security glitches.
One of the first two problems, in QuickTime for Java, can lead users to having their systems hijacked if they visit a malicious site. If a user visits a site containing a maliciously crafted Java applet, an attacker can trigger the vulnerability and take over the target system. The second glitch, like the first, a user has to visit a site with a maliciously crafted Java applet. The attacker can take advantage of the vulnerability and may be able to read sensitive information off your system.
See our How To for steps in installing QuickTime 7.1.6.http://ict.cas.psu.edu/training/howto/util/QuickTimeInstall.htm

Penn State to add DNS Security on July 9, 2007

In an effort to enhance Domain Name Server (DNS) security and improve resource usage on the Penn State Network, ITS (http://its.psu.edu/) will restrict a function called "Recursive DNS lookups" in the University's domain name service on July 9, 2007.

Don't panic. College Enterprise computers should be set to use College DNS numbers or be set to Obtain DNS server address automatically. In these cases, the PSU DNS numbers will not be used and you can continue to access Internet sites as expected.

To verify whether or not a particular computer is currently configured to use the Penn State DNS servers, see our How To. You may need to remove one Penn State DNS number: 128.118.25.3. This How To has complete steps to verify your network settings and includes pictures.

For More information, see our eNews article: http://ict.cas.psu.edu/NewsLetters/enews72.html#Article1

Monday, June 11, 2007

Yahoo! Messenger software needs Upgrade

Two critical vulnerabilities reside in Yahoo! Messenger versions 8.1.0.249 and earlier. Computers running earlier versions of the Yahoo IM software could be hijacked by visiting a malicious Web page.

The company has pushed out a fix to plug two newly discovered security holes. Yahoo! Messenger users should download and install the latest version immediately.

http://messenger.yahoo.com/download.php

Thursday, March 15, 2007

Office 07 & Vista Deployment Plans

It's been in the news and we've received emails - Microsoft Office 2007 and Microsoft Vista operating system are available!! What's happening with these two different software packages in the College of Ag Sciences? Read on about each one…

The deployment of Office 07 will begin September 2007 - November 2007. (Enterprise computers shipped after October 2007 will be shipped with Office 2007).

There are several reasons why we feel this is the best time to deploy Office 2007:
  • Timing of the upgrade is important - if all staff do not upgrade to Office 2007 at the same time, those still using Office 2003 wouldn't be able to open any Office 2007 documents without downloading a file converter.
  • Breeze (Adobe Connect Pro) Web Conferencing is not able to convert PowerPoint 2007 presentations yet. We expect this to be corrected by September.
    Penn State technology classrooms and computer labs will have Office 2007 installed during the summer of 2007.
  • Training issues - training materials for Office 2007 are not yet completely developed. Office 2007 has a very different interface. Our goal is to minimize the impact on productivity by providing thorough training opportunities.
  • There will never be a "good" time to upgrade, but by doing this over a couple months you should be able to work around busy schedules. Also, by working in the fall we can avoid county fair season, the beginning of the semester, and before winter meetings and conferences.

Now, comes the fun part. If you would like to be part of the CoAS Office 2007 Pilot, please email us as the Project contacts. After reviewing the emails, we will select a sampling of different office environments, up to 25. If you are selected, we will send you an email with all the details. Vista operating system WILL NOT be part of this pilot.

The Vista operating system deployment will begin in September 2008 (not a typo this IS NEXT YEAR). By that date, we expect that some of the initial adjustments (new features, drivers, and compatibility issues) will have been worked out and the first service release packs will have been made available. This is consistent with the university's deployment approach for the computer labs and technology classrooms. Right now there is no "must have" reason to switch to the next generation Vista operating system. Enterprise computers will NOT be shipped with Vista operating system until September 2008. ICT will not be supporting Vista operating system machines on the Enterprise network until after Sept 2008. We will keep you up to date with our plans with both of these products via eNews, ICT Tech Alerts, and our ICT Web site.

If you have questions or would like to sign up for the CoAS Office 2007 Pilot, please email Jacki (jweikert@psu.edu) or Peg (pshuffy@psu.edu).

Tuesday, January 30, 2007

Clock continues to TICK on Password Change Deadline

Penn State's initiative to foster a safer computing environment requires that all Access Account holders change their passwords on an annual cycle. Note: any university password changed after August 1, 2006 will expire exactly 365 days from the date and time of change. The College of Ag Sciences is following the same initiative in regards to AG account passwords.

College of Ag Science faculty and staff will normally have TWO accounts. They will have a PSU Access Account and a College of Ag Sciences' AG account. Note, some have more and other faculty/staff have less. Also note that county email accounts are AG accounts and also need their passwords changed by April 2.

This means that you need to change your password, in most cases, 2 places. Our How To provides directions on How To Change your PSU Access Account password and your AG password. This How To also gives you a list of which services use your AG password and which one use your PSU password. For example, if you use Dreamweaver for web development on the college's web server, you will need to update the AG password in Dreamweaver's settings.

For more infromation, including deadlines in the University's campaign to have all Penn State community members change their Access Account passwords, see the following eNews article from Jan 18, 2007.

Change your Password - no April Fool's (or Groundhog Day Eve) joke!

Monday, January 22, 2007

Install IE7 Phishing Filter Update

The new IE7 Phishing Filter evaluates an entire Web page when the page is opened. If a page contains a number of frames, the Phishing Filter may prevent it from loading. One example we have seen was a web based video conference using streaming QuickTime. The page never loaded with the Phishing Filter enabled. On Dec 12, 2006, Microsoft released an update to Internet Explorer 7. The update is designed to resolve slowdowns for Web pages containing a number of frames.

See these Install Phishing Filter Update steps from the How To Install Internet Explorer 7 for Windows XP. They are written for College Enterprise computers that are using Windows XP Service Pack 2.

Friday, December 08, 2006

Adobe Download Manager 2.1 and earlier should be removed

A critical vulnerability has been identified in Adobe Download Manager 2.1 and earlier. Adobe is recommending that users uninstall these versions of Adobe Download Manager.

Note: Adobe Download Manager is a stand-alone application that improves the process of downloading files from Adobe. Customers who have downloaded software from Adobe, including Adobe Reader, may have Adobe Download Manager installed.

To verify if a vulnerable version of Adobe Download Manager is installed, and to uninstall Adobe Download Manager if necessary, please follow these steps.

Note: These steps are written for College of Ag Sciences Enterprise computers with Windows XP Service Pack 2.

1. Open My Computer. Open Local Disk (C:). Open the Program Files folder.
2. Open the Common Files folder. Open the Adobe folder.

Note: If you don't see an ESD folder, you don't have Adobe Download Manager installed. Stop here.

3. If you see an ESD folder, open the ESD folder.
4. Right-click on the AdobeDownloadManager.exe file and select Properties.
5. Click on the Version tab.
6. If the version is 2.1.x or higher, your version is not affected. Click OK. Close all windows. If the version 2.1.x or lower, you need to uninstall Adobe Download Manager. Click OK. Close all windows.
7. Download the Adobe uninstaller and save it to your Desktop.
8. Double click on the DLMUninst_001.exe file to remove the Adobe Download Manager.
9. Click OK.
10. You can now delete the DLMUninst_001.exe file.

Update available for potential vulnerabilities in Adobe Reader and Adobe Acrobat 7

Critical vulnerabilities have been identified in Adobe Reader 7.0 through 7.0.8 that could allow an attacker to take control of your machine. Adobe is recommending that users update to Adobe Reader 8. For complete steps please see our How To Install and Configure Adobe Reader for Windows.

If you have installed the FULL version of Adobe Acrobat 7 (software that allows you to create PDF documents), Adobe has workaround steps to update the AcroPDF.dll on your machine. This will allow you to keep Adobe Acrobat 7 Professional on your machine and be safe as well. Follow Steps 1 - 5 from the Solution section of this Adobe Security bulletin.

Again, folks who just have Adobe READER installed, should upgrade to Adobe Reader 8.

Monday, November 20, 2006

ITS download site changes

ITS has changed their policies and permissions on their downloads site (http://downloads.its.psu.edu/) depending on if you are a full-time PSU employee vs an access account holder.

Only full-time PSU employees can get the "complete" list of installers (including SAV, Office)

In most cases this means that only full-time PSU employees and extension educators can use this site to access these installers. Extension support staff will need to ask educators to download these installers for them.

-jsw

Friday, November 03, 2006

Unable to load Penn State Newswire's live.psu.edu webpage in IE6

For the latest Penn State news and information, you can visit http://live.psu.edu/

When you attempt to visit the page, you are asked to run an ActiveX control. The screen goes blank and your only option is to click OK in the dialog box. When you do, Internet Explorer locks up and crashes.

Issue
The live.psu.edu page has a strip of video's on the left side that use ActiveX to be displayed. If you have an older version of QuickTime installed on your computer, these controls can't be shown in the window.

Fix
Update to the most recent version of QuickTime. Use these How To steps.

Install QuickTime for Windows using the Standalone Installer