In a past career, I was big in to computer security, and got paid well for doing the work. Since I’m now elsewhere professionally, I’m less in touch with the security industry than I used to be. However, I still keep up with a few important resources, and like to pass along really useful tips when I find them. Today in reading some security news and trying to catch up, I caught word of the F-Secure HealthCheck application patches scanning system. While this is unfortunately an Internet Explorer only tool currently, the site indicates work is in process for supporting other (and better, in my opinion, BTW) browsers. Hopefully that will happen soon.
Run HealthCheck to get a scan of applications on your system along with checks for patches and updates to those applications. This should help you track down security problems that have fixes available. If you keep up to date on these patches, it should help significantly with avoiding your machines getting taken over by a ‘bot-network. The tool appears to have been developed or at least re-announced (I’m not familiar enough with HealthCheck and it’s history nor age to know which is the correct term) as a result of an F-Secure poll regarding application patching.
It appears that many people are uncertain if their computers are fully patched when there are third party updates involved.
Q  What can you do about it?
A  F-Secure Health Check.
Health Check is a free online tool designed to help consumers identify security updates needed on their computers.
I will point out that HealthCheck requires installation of an ActiveX control in your Internet Explorer window. I personally trust the eggheads at F-Secure to not do malice as a result of this, but you need to understand that installing an ActiveX control is a security risk which gives the control vendor pretty much full access to your operating system. While *I* personally trust the F-Secure worker-bees to not corrupt, control, nor destroy my system, you’ll have to make that decision for yourself.
After running the test, here’s a snip of what I got as a result:
In my case, I’m on a work computer without anti-virus and anti-spyware protection. Sadly, I am not allowed to correct this flaw. I make up for it by using the PortableApps version of ClamWin, and regularly scan my system. I also run Firefox for my browser (actually, I use the PortableApps version of this application, too) and stick mostly to web sites I know and trust. I save my home computer for more risky online activity.
If you are unsatisfied with your HealthCheck scan results and the problem turns out to be a browser security issue, can I suggest you update to FireFox?
[tags]security, healthcheck, scanning, vulnerability, patch, Windows, Internet Explorer, FireFox[/tags]