Tuesday, November 24, 2009
Tuesday, November 3, 2009
Very Important QuickBooks Update!
Quickbooks ActiveX Controls
To our Customers:
Intuit has identified, and created a solution for, a potential security vulnerability in some of our Quickbooks desktop software (2009 and older supported versions). We know of no cases where someone has taken advantage of this vulnerability. However, if exploited, it could allow a cyber criminal to access the data on your computer. Downloading the update and applying these product updates will eliminate this vulnerability, so it’s important for every customer to install this update.
Two ActiveX controls were affected. These are HtmlHelper.dll and QBInstanceFinder.dll.
Identified versions: These vulnerabilities affect several versions of Intuit Quickbooks products that should receive updates. The identified versions of these Quickbooks products are:
U.S. Products
- QuickBooks Product Line
QuickBooks Simple Start, Pro, Premier and Enterprise – versions 2007 - 2009
Canadian Products
- QuickBooks 2009 (both English and French editions)
- QuickBooks 2008
- QuickBooks Multicurrency Edition
- QuickBooks 2007 (French edition only)
U.K. Products—these products have already been patched
- UK & South Africa (note that there was no QB 2009 for the UK)
- QuickBooks 2008 R12
- Quickbooks 2006, R12
Australian Products
- QuickBooks 2009/10 AU (v18)
QuickBooks 2010 in the U.S. and Canada, released in September 2009, is not affected by this vulnerability. Other Intuit products, at this time and to the best of our knowledge, do not have this vulnerability. If we learn otherwise, we will provide further guidance at that time.
Intuit has already released an automatic patch which may have been applied. If the security patch has been applied, the QuickBooks release level will be updated to the latest version. To get this information, open QuickBooks, and press the F2 key. In the display, you should see the product version information in the first line. Versions of QuickBooks with the patches applied are the following:
- QuickBooks 2009 R8 US
- QuickBooks 2008 R10 US
- QuickBooks 2007 R13 US
- QuickBooks 2006 R12 UK
- QuickBooks 2008 R12 UK
- QuickBooks 2009 R6 CAN
- QuickBooks 2008 R8 CAN
- QuickBooks MC R24 CAN
- QuickBooks 2009 French R6 CAN
- QuickBooks 2007 French R7 CAN
- QuickBooks 2009/10 AU (v18)
If the patch was not automatically applied, it is very important for you to apply the patch now.
What You Need To Do
If you have ever installed any of the identified products on your computer you should download and install Intuit’s patch, which will immediately eliminate the vulnerability.
US customers can download the patch from: http://support.quickbooks.intuit.com/Support/ProductUpdates.aspx
Canadian customers can download the patch from: QuickBooks: http://support.intuit.ca/quickbooks/en-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html
SuccesPME customers can download the patch from: http://support.intuit.ca/succespme/fr-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html
For UK customers, this fix was released in R12 which you should already have installed. If not, install the patch from: http://support.intuit.co.uk/quickbooks/en-gb/kb/update/update-quickbooks-to-new-product-update/Update_main.html
As a further precaution, we will coordinate release of this information with US-CERT and with Microsoft, for a future release within their regular security updates for ActiveX control configuration. Downloading Intuit’s patch is the most immediate way to eliminate the vulnerability.
We apologize for any inconvenience this may cause.
Technical Support Contact Information
If you encounter any problems installing the patch:
- U.S. customers please visit us at:
http://support.quickbooks.intuit.com/support/defaultb.aspx - Canadian customers please visit us at:
http://support.intuit.ca/quickbooks/index.jsp - French Canadian customers please visit us at:
http://support.intuit.ca/succespme/index.jsp - U.K. customers please visit us at:
http://support.intuit.co.uk/quickbooks/index.jsp
Questions and Answers About the ActiveX Control Vulnerability
Q1. What if I’ve uninstalled one of these products and no longer use it? Do I still need the patch?
A1. If you have uninstalled QuickBooks, you should not be vulnerable to these vulnerabilities. If you have installed multiple versions of QuickBooks, you will be vulnerable if any identified version is still installed. Uninstalling all identified versions of the software will remove the vulnerability from your system. When uninstalling multiple versions, ensure that you uninstall the most recent version of the software last.
Q2. How do I download and install the patch?
A2. All users of an identified version of Quickbooks should download the security patch at: http://support.quickbooks.intuit.com/Support/ProductUpdates.aspx. Canadian users can also download updates from: http://support.intuit.ca/quickbooks/en-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html
When the page appears:
- Choose your product by clicking the product selector link.
- Click the “Update” button to start the download and click “Go.”
- Select “Open” or “Run This Program From its Current Location” to begin installing the patch immediately. Restarting your computer is not required.
- If you don’t have time to install the patch, you can select “Save” or “Save This Program to Disk” and the patch file, called qbwebpatch.exe, will download to your hard drive. You’ll need to open that file to run the patch.
Q3. How do I check that the security patch has been applied?
A3. To make sure the patch has been applied and is installed on your system, do the following:
If the security patch has been applied, the QuickBooks release level will be updated to the latest version. To get this information, open QuickBooks, and press the F2 key. In the display, you should see the product version information in the first line. Versions of QuickBooks with the patches applied are the following:
QuickBooks 2009 R8 US
QuickBooks 2008 R10 US
QuickBooks 2007 R13 US
QuickBooks 2006 R12 UK
QuickBooks 2008 R12 UK
QuickBooks 2009 R6 CAN
QuickBooks 2008 R8 CAN
QuickBooks MC R24 CAN
QuickBooks 2009 French R6 CAN
QuickBooks 2007 French R7 CAN
QuickBooks 2009/10 AU (v18)
Q4. What operating systems are supported?
A4. The security patch is available for all operating systems used by any identified versions of the Quickbooks applications: Windows XP, Windows Vista, and Windows 2000. [If you are running Windows 98 or Windows ME, you need to have Internet Explorer 6.0 or later installed before you can install the update. Go to the Internet Explorer 6 Downloads Web page to install a more recent version of IE. ] Note: Intuit products for Apple MacOS X are not affected.
Q5. What if I have multiple Intuit products? Do I need to download and install the patch for each one?
A5. If you have installed more than one identified version of Quickbooks, you should apply patches for each version.
Q6. I still have a trial version of Quickbooks installed on my system. Do I still need to apply the security patch?
A6. Yes. If you have any trial versions of one of the identified versions of Quickbooks installed on your system, you should download and install the security patch.
Q7. I only use the Internet on a periodic basis. Do I still need to download the security patch?
A7. Yes. If you installed an identified version of Quickbooks on your computer, the vulnerability poses a security risk regardless of whether you are currently connected to the Internet. We recommend that all users of an identified version download and install the security patch.
Q8. How do I ensure that my computer has not already been compromised?
A8. If you have anti-virus software installed and have updates run automatically, the anti-virus software should detect the presence of any malware on your computer. If you want to determine if your computer has malware on it, run a complete scan of your computer using an anti-virus software product.
Q9. I’m the administrator of my office network. Some machines have had QuickBooks installed at some point but don’t any longer, and aren’t getting automatic updates. What should I do to secure my network?
A9. If you’d had QuickBooks installed on some computers at some point, and are no longer running QuickBooks on those machines and receiving automatic updates, you can secure these machines by following these steps:
- Copy the following text to a file with the “.REG” suffix.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX
Compatibility\{596801D8-2C9D-4627-9C67-195CB81B655A}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX
Compatibility\{03C3A013-02F2-4e56-87A8-B74A7C5DC75B}]
"Compatibility Flags"=dword:00000400 - Import this into the registry by double clicking on the .Reg file and it will automatically be imported. This will disable the affected ActiveX controls.
Q10. What if I use QuickBooks 2006 or a previous version?
A10. Intuit wants your data to be safe. We recommend you upgrade to a newer version of QuickBooks (2007 or later) as soon as possible and follow the instructions to update that version. QuickBooks 2006 and prior versions are no longer supported and Intuit does not release updates for these products.
For additional information please contact Intuit at security@intuit.com
Sunday, November 1, 2009
Let’s end the year with great cheer and start the year off right with an evening of mixing, networking and generating professional relationships to build business. Join us for an evening to unwind, enjoy cocktails and good conversations.
You should attend….
• if you want to build your business connections.
• if you want to expand you professional network.
• if you want to learn from a business expert.
• if you want to connect with the right people.
Don’t forget your business cards and invite your colleagues!
Mix, Mingle & Networking
Complimentary Appetizers
2 for 1 Drinks
Date:
Wednesday, December 16, 2009
Place:
SoMa 107 – VIP Lounge
107 Mamaroneck Avenue
White Plains, NY 10701
Time:
5:30pm – 8:00pm
Cost:
FREE
RSVP at rsvpevents@wnfp.org
Join Us at Gianna's in Yonkers, NY
After Hours Business Networking Event
“Reach for the Stars!”
Are you looking to build your business and generate professional contacts while having a good time? “Reach for the Stars” will allow you this opportunity, so join us November 11th at one of Westchester prominent venues where you will meet with some of the most influential professional men and women of Westchester County and surrounding areas.
Networking, Good Conversations, Complimentary Appetizers, Cash Bar
You should attend….
· if you want to build your business connections.
· if you want to expand you professional network.
· if you want to learn from a business expert.
· if you want to connect with the right people.
Date: November 11, 2009
Time: 5:30 pm - 8:00 pm
Place: Gianna's
1034 N Broadway
Yonkers, NY 10701
RSVP at rsvpevents@wnfp.org or REGISTER at www.wnfp.org
Need Help Setting Up QuickBooks?
Setting up your QuickBooks accounting software may seem like an easy task, but when it comes to your financial records as a business owner or manager it is imperative to have accurate financial information to run you business properly. If you are an individual who has knowledge of accounting and the process of keeping track of your finances, you should have no problems setting up QuickBooks for you business. For those who are not aware of the accounting process, you can save time, money and avoid the frustrations and worries by having it set up right the first time.
Hiring a professional to assist you with the process is a small investment compared to submitting unorganized financial statements to your accountant at tax time and having them charge you additional fees to correct your mistakes.
QuickBooks is inexpensive and offers many features which small businesses and entrepreneurs can utilize to keep track of their financial records, but if it is not set up properly the information entered would not generate accurate information for you to keep track of the financial status of your business. It is vital to have accurate and up to date records to identify the strengths and weaknesses of the business and how to improve the efficiency and profitability of the business or make changes to improve weaker areas.
In today’s economy it is crucial to have the resources to maintain and manage your financial records.
Bookkeeping & More Services can assist you with installation, set up, on-site training and trouble shooting. Visit us at www.bookkeepingnmoreservices.com for more information and business solutions we can provide.
Saturday, October 3, 2009
Masquerade VIP Networking Mixer
Cordially invites you to our…
Masquerade VIP Networking Mixer
Wednesday, October 28, 2009
Don't miss the chance to be someone else for the evening. Naughty or Nice!
Join us for an evening to unwind, socialize, and make connections with Westchester's Finest professional men and women at one of Westchester’s upscale venues, where the atmosphere is relaxing and the food is great.
All are welcome to join us for networking, good conversations, cocktails and entertainment.
Register Early! Receive Discount!
Mix, Meet & Network
Business Card Exchange
2 for 1 Drink Specials/Cash Bar
Tantalizing Appetizers
Light Music – Just right for networking
50/50 Raffle
Free Raffle Giveaways
Best Mask & Bead Exchange Contest
Venue:
SoMa 107 – VIP Lounge
107 Mamaroneck Avenue
White Plains, NY 10601
Time:
5:30pm – 8:00pm
Cost:
Advance Registrations: $25.00
Paying at the door: $30.00 w/Mask - $35.00 w/o Mask (Masks will be provided at the door)
Dress Code:
Business Casual & Mask (Required)
For Registration Information visit www.wnfp.org or call (914) 837-0219
WANT ADDITIONAL EXPOSURE: Sponsorship Opportunities and Raffle Participation Available – Call (914) 837-0219
Can’t Attend? Join our mailing list for updates to our future events and activities at www.wnfp.org