11.07.2015 Views

Platinum Technical Support Newsletter - The Place at McAfee

Platinum Technical Support Newsletter - The Place at McAfee

Platinum Technical Support Newsletter - The Place at McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong>February 13, 2009<strong>McAfee</strong> Avert Labs Thre<strong>at</strong> CenterCurrent MalwareOSX/IWService 22 Jan 2009W32/Waledac.gen.b 14 Jan 2009Downloader‐UA.h 02 May 2008BackDoor‐DNM 21 Feb 2008Downloader.gen.a 30 Jul 2007Current VulnerabilitiesMS09‐001 SMB RC 9586.. 13 Jan 2009MS09‐001 SMB BO 9586.. 13 Jan 2009MS08‐072 word 957173 09 Dec 2008MS wordpad RCE 09 Dec 2008MS IE d<strong>at</strong>abind RCE 09 Dec 2008MS09‐001 SMB DoS 958.. 14 Sep 2008Breaking AdvisoriesFebruary 5, 2009: Microsoft has posted their Advance notific<strong>at</strong>ion for the February 2009 bulletin release (releasingFebruary 10). This release will include two 'Critical' upd<strong>at</strong>es (Internet Explorer and Microsoft Exchange). Upd<strong>at</strong>es forMicrosoft SQL Server and Visio will be includef as well. All four bulletins carry a potential impact of remote codeexecution.Learn MoreAudio ParasiticsEpisode 55 ‐ Part 2 of 2 ‐ Jim and Dave discuss the 2009 Thre<strong>at</strong> Predictions, Trojans on Mac OS X, and theDATs hitting 500,000!Episode 54‐ Part 1 of 2 ‐ Jim and Dave discuss the 2009 Thre<strong>at</strong> Predictions, Trojans on Mac OS X, and theDATs hitting 500,000!Episode 53‐ It's time to p<strong>at</strong>ch....Dave and Jim discuss W32/Conficker.worm and MS08‐067.…Previous Episodes…Listen via iTunes, Podzinger or direct from the Thre<strong>at</strong> Center<strong>McAfee</strong> Monthly Spam Report for February is Available OnlineThis month's edition of the <strong>McAfee</strong> Monthly Spam Report is now online and available for download. Again, agre<strong>at</strong> example of our collective, global thre<strong>at</strong> intelligence model in action!Download HereConcerned About PCI Compliance?<strong>McAfee</strong> is uniquely poised help organiz<strong>at</strong>ions optimize their security posture while meeting PCI compliancethrough its breadth of solutions and services. Our comprehensive suite of solutions and services helps youexceed PCI requirements, via a layered security model.New <strong>McAfee</strong> PCI DSS Requirement Mapping Tool now available<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 1 of 6


Keeping Inform<strong>at</strong>ion Assets Secure as Organiz<strong>at</strong>ional Boundaries GoGlobalTechnology and the Internet have transformed the traditional boundaries of organiz<strong>at</strong>ions, resulting in adistributed network of unsecured economies, leaving inform<strong>at</strong>ional assets such as intellectual property andsensitive inform<strong>at</strong>ion even more <strong>at</strong> risk of theft and misuse.This report investig<strong>at</strong>es the Cybercrime risks in various global economies, and the need for organiz<strong>at</strong>ions totake a more holistic approach to vulnerability management and risk mitig<strong>at</strong>ion in this ever‐evolving globalbusiness clim<strong>at</strong>e.Download the Unsecured Economies Report.Hear wh<strong>at</strong> more than 1,000 senior global IT decision makers have to say regarding the potential implic<strong>at</strong>ionsof doing business in specific countries as it pertains to securing inform<strong>at</strong>ional assets.Learn how culture may have an impact on <strong>at</strong>titudes towards intellectual property and wh<strong>at</strong> types ofinform<strong>at</strong>ion are considered sensitive and not.Learn how organized crime, employee turnover, reverse engineering, phishing <strong>at</strong>tacks and money mules areputting your company d<strong>at</strong>a assets <strong>at</strong> risk.Discover which countries are investing in inform<strong>at</strong>ion security and upd<strong>at</strong>ing regul<strong>at</strong>ions to address thegrowing concern of protecting d<strong>at</strong>a assets, and those countries less concerned with the issue.Gain valuable insight from industry experts in d<strong>at</strong>a protection and intellectual property, including bestpractices for protecting the vital inform<strong>at</strong>ion of your organiz<strong>at</strong>ion.Download this report today to learn more about the issues of Cybercrime and unsecured economies puttingthe world's inform<strong>at</strong>ion assets <strong>at</strong> risk; how the trends could impact your organiz<strong>at</strong>ion and steps you can taketo build a stronger defense against thre<strong>at</strong>s.<strong>McAfee</strong> Rolls Out Artemis Technology to All <strong>Pl<strong>at</strong>inum</strong> Customers<strong>McAfee</strong> is extending the availability of Artemis thre<strong>at</strong> protection technology to all <strong>Pl<strong>at</strong>inum</strong> <strong>Support</strong> customersrunning <strong>McAfee</strong> VirusScan Enterprise (VSE) 8.7i or 8.5i beginning January 28, 2009, <strong>at</strong> no additional cost.Artemis is successfully deployed on more than 10 million consumer, small and medium business, andenterprise customer nodes. Given the success of this new technology in providing gre<strong>at</strong>er real‐time protectionagainst malware combined with extremely low incidence of escal<strong>at</strong>ions, we are extending Artemis availabilityin Q1 to include all <strong>Pl<strong>at</strong>inum</strong> customers with VSE 8.7i or 8.5i.<strong>Pl<strong>at</strong>inum</strong> customers interested in assessing Artemis in a pilot environment or deploying it across theirenterprise network must contact their <strong>McAfee</strong> <strong>Support</strong> Account Managers (SAMs) to request the SDATpackages. SAMs will be contacting <strong>Pl<strong>at</strong>inum</strong> VSE customers proactively regarding this opportunity.Further details regarding how to enable Artemis in the near term and wh<strong>at</strong> is being planned are explained inKnowledgeBase article KB 53732. For more inform<strong>at</strong>ion, click here or contact your SAM.<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 2 of 6


ePO 4.5 Beta Now AvailableA beta version of <strong>McAfee</strong>’s flagship product – ePolicy Orchestr<strong>at</strong>or (ePO) – is now available for customers totest, evalu<strong>at</strong>e and give feedback. This is a gre<strong>at</strong> way to engaged with some of the new functionality in thisnext version.New fe<strong>at</strong>ures include:Multi‐tier architecture to gre<strong>at</strong>ly improve scalability• Reduced server hardware requirements• Failover managementImproved visibility and control across multiple ePO servers• Policy sharing & assignment reporting• Multiple server reporting• Moving agents between serversStreamline notific<strong>at</strong>ion through autom<strong>at</strong>ed rule based remedi<strong>at</strong>ion response/workflow to events/incidents• Trouble Ticket gener<strong>at</strong>ion ‐ Remedy & HP Service Desk• SNMP/email notific<strong>at</strong>ionsImproved user‐based management to more efficiently deploy security policy• Use Active Directory user rights for ePO permissions• Develop policies based on either users or groupsUser interface improvements to spend less time managing security• Drag & drop capabilities• Customizable shortcut toolbar• Query & extension groupingParticip<strong>at</strong>e in this beta to get a first hand look <strong>at</strong> wh<strong>at</strong> this new version of ePO has to offer. <strong>The</strong> public betasare available to anyone who is interested in testing our enterprise software and providing feedback to ourengineering teams.Sign up and download the ePO 4.5 beta Here.<strong>McAfee</strong> Avert Labs Security Advisories<strong>McAfee</strong> Avert Labs Security Advisories are a free notific<strong>at</strong>ion service backed by our global research team.<strong>McAfee</strong> Avert Labs Security Advisories map high profile thre<strong>at</strong>s to the <strong>McAfee</strong> technologies th<strong>at</strong> protect yourenvironment.Sign up here<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 3 of 6


End‐of‐Life Notice:GroupShield for Domino 5.3, SpamKiller for Domino 2.1As a result of the obsolescence of Microsoft Windows 2000 SP1, <strong>McAfee</strong> plans to stop supporting GroupShieldfor Domino v5.3 and SpamKiller for Lotus Domino v2.1 running on Microsoft Windows 2000 SP1 on September1, 2009. To receive continued support, customers should upgrade their oper<strong>at</strong>ing system to Windows 2003.As a result of <strong>McAfee</strong>'s product lifecycle, <strong>McAfee</strong> plans to stop supporting GroupShield for Domino v5.3 onWindows and SpamKiller for Lotus Domino v2.1 on December 31st 2009. To receive continued support,customers should upgrade to the l<strong>at</strong>est version of these <strong>McAfee</strong> products.Product documents and Knowledgebase articlesCheck out these useful Product Document and Knowledgebase articles from the Email & Web Security teamon the <strong>McAfee</strong> Knowledgebase <strong>at</strong> our ServicePortal<strong>McAfee</strong> Email Security Appliance 5.0 Best Practices GuidePD20780<strong>McAfee</strong> Web Security Appliance 5.0 Best Practice GuidePD20781Upgrading the Appliance to Email and Web Security 5.0 Service Pack 1KB60300ERROR: Size of a request header field exceeds server limit (when using Kerberos Authentic<strong>at</strong>ion) KB60332ERROR: Device Pl<strong>at</strong>form not supported, displayed when installing Appliance software KB60429Message from <strong>McAfee</strong> Avert Labs<strong>McAfee</strong> Avert Labs would like to communic<strong>at</strong>e out on <strong>McAfee</strong>’s str<strong>at</strong>egy for addressing some of the criticalissues customers are having with regards to DAT size and growth r<strong>at</strong>e containment. <strong>The</strong>re are a few items th<strong>at</strong>are planned for the near future:ePO 4.0 P<strong>at</strong>ch 4With ePO P<strong>at</strong>ch 4, customer will have the option to configure the ePO server via registry key to allow for V2only DAT downloads as well as a global replic<strong>at</strong>ion setting of Incremental files only. Each of these fe<strong>at</strong>ures wasdesigned to address the speed of replic<strong>at</strong>ion along with the size of the content being delivered.To address the size of the content being replic<strong>at</strong>ed to distributed repositories, you can now configure ePO toonly replic<strong>at</strong>e the V2 DAT content. This will elimin<strong>at</strong>e over 50% of the DAT content being replic<strong>at</strong>ed. <strong>The</strong> ePOserver pull tasks will still download both content versions to the master repository. If you are using theproducts below you will still need to replic<strong>at</strong>e both V1 and V2 DATs to your repositories. As this is a globalsetting, all repositories will either have V1 and V2, or V2 only content.Global incremental DAT replic<strong>at</strong>ion can also be configured, but it is critical th<strong>at</strong> it is understood th<strong>at</strong> ePO willonly replic<strong>at</strong>e the incremental files themselves and not the full DAT file. If systems need to have access to thefull DAT, when they are either 14 versions out of d<strong>at</strong>e or during a new VSE install<strong>at</strong>ion, then you will have tocopy the full DAT to the repositories. This can be accomplished with external file copy utility, such as“Robocopy”. As most customers will need to have the full DAT files available, this option is best suited for veryspecific use cases and should only be utilized after careful review of the environment.<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 4 of 6


ePO 4.0 P<strong>at</strong>ch 4…ContinuedAnother key item to remember is th<strong>at</strong> if a product needs content th<strong>at</strong> is not available the agent it will checkeach of its configured repositories and eventually the fallback repository, if so configured. By default this is the<strong>McAfee</strong> HTTP download site. A situ<strong>at</strong>ion could arise where a large number of systems would either need theV1 DAT content or the full DAT file and end up downloading the files from our internet loc<strong>at</strong>ion which couldhave neg<strong>at</strong>ive network impact. It will be crucial for customers to review their deployed products portfolio toensure th<strong>at</strong> content is not needed prior to configuring V2 content only and/or incremental file onlyreplic<strong>at</strong>ion.Incremental DATsIn March, we will be increasing the number of incremental DAT upd<strong>at</strong>es from 15 to 35. This means th<strong>at</strong>customers can be outd<strong>at</strong>ed from upd<strong>at</strong>ing their DATs for up to 35 days before they will be forced to take thefull DAT file. This change will only impact Enterprise customers. We are planning to change this for SMB andour Consumer markets in a Phase 2 of the project. <strong>The</strong>re will be no changed needed by the customer to makeuse of this modific<strong>at</strong>ion.V2 Only Download SiteAlso in March, we will be launching a new ePO download site for V2 only DAT content. <strong>The</strong> existing site for V1and V2 will remain, but customers exclusively running 8.5 and higher will be able to point ePO to this new site.This will have immedi<strong>at</strong>e and clear benefits, as the V2 content is less than half of the package th<strong>at</strong> customerscurrently must pull. <strong>The</strong>re will be no forced change, meaning, unless a customer chooses to make use of thisnew site no change will autom<strong>at</strong>ically happen. <strong>The</strong> customer will always be able to revert back to the old site ifneeded.DAT Optimiz<strong>at</strong>ionsAvert Labs, in an effort to provide the best detection quality along with the lowest impact to the user, willbegin DAT optimiz<strong>at</strong>ion effort February 16th. This effort is targeted <strong>at</strong> streamlining the content in our DATswith the end goal of reducing overall DAT size. A bi‐product of this will be a potential increase to the size ofthe incremental DAT files over the course of the 6 weeks from start to completion of the project. We do notexpect th<strong>at</strong> the incremental upd<strong>at</strong>es will go beyond 500KB during this time. It is not guaranteed th<strong>at</strong> theincremental DATs will consistently be this size; however, we would like our customers to be aware of thecause for this.Feel free to contact Anna Stepanov for any questions regarding the DAT upd<strong>at</strong>ing roadmap.AStepanov@avertlabs.comFeel free to contact Ulli Tanurhan for any questions regarding the ePO P<strong>at</strong>ch 4UTanurhan@mcafee.com<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 5 of 6


Useful Links<strong>McAfee</strong> Corpor<strong>at</strong>e Website<strong>McAfee</strong> MER Tool<strong>McAfee</strong> Knowledge Search<strong>McAfee</strong> WebMER (See NAI33333)<strong>McAfee</strong> Downloads<strong>McAfee</strong> Virtual Technician (MVT)<strong>McAfee</strong> Thre<strong>at</strong> Center<strong>McAfee</strong> Global Solutions Lab<strong>McAfee</strong> Security Upd<strong>at</strong>esAVERT Tools and Utilities<strong>McAfee</strong> Product & <strong>Support</strong> End of LifeBeta Program<strong>McAfee</strong> Service PortalAvert BlogService Portal Help & FAQsFree <strong>McAfee</strong> ToolsFe<strong>at</strong>ure Modific<strong>at</strong>ion RequestFree <strong>McAfee</strong> Foundstone Tools<strong>McAfee</strong> Product Content Releases<strong>McAfee</strong> Inc © 2008 <strong>Pl<strong>at</strong>inum</strong> <strong>Technical</strong> <strong>Support</strong> <strong>Newsletter</strong> 2/13/2009 Page 6 of 6

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!