Archive for the 'Security' Category


OK – just fresh off the 5 wordpress install updates and now clamav…

Friday, April 7th, 2006

So, I spent the better part of the evening doing WordPress updates to get 5 blogs up to v. 2.0.2 and now….. clamav has multiple vulnerabilities …………… oi…. now it’s time to rebuild clamav to install on 2 machines……    Send article as PDF   

Microsoft April Updates coming Tuesday

Friday, April 7th, 2006

To change the Google theme of the afternoon…. Microsoft is due to release their April updates this coming Tuesday (April 11th.) Advance bulletin is here. Four updates affecting Windows, one affecting Office AND Windows. Highest severity is Critical (Explorer flaw probably) Reboot will be required… The Office/Windows update MAY require a reboot and is listed […]

IE exploit unofficial patches

Tuesday, March 28th, 2006

While we wait for Microsoft to release a patch for the MOST recent Internet Explorer vulnerability….. it looks as though MS is “planning” to release a patch on their routine patch day of April 11th. (However they could always change their mind…) As before though there are some 3rd party patches. I’ve got to say […]

Internet based filesystem with no transfer fees

Monday, March 27th, 2006

I thought this was a great idea…. rsync.net Okay for 2$ per GB of storage per month (or $24 per year for 1GB of storage) you can have your very own secure online storage drive. For you windows users think of a G: drive or a Z: drive that you could SECURELY connect to from […]

Update on Internet Explorer Exploit in the wild

Monday, March 27th, 2006

If you use Internet Explorer to browse the web, I’d suggest finding the instructions to disable active scripting, or drop it and use something else in light of the recent exploit floating around. It seems that in spite of Microsoft’s infinite wisdom that “Microsoft has determined that an attacker who exploits this vulnerability would have […]

Another critical IE flaw

Thursday, March 23rd, 2006

I should mention a fairly big Windows vulnerability (which involves active scripting). Apparently there are proof-of-concept exploits circulating that do innocent things like open up the calculator. Unfortunately, once exploits are out that can do this, it’s trivial for them to do worse. The bottom line is, be careful what sites you visit, beware of […]

March Microsoft Updates – etc.

Friday, March 10th, 2006

I can’t believe it’s been so long without a post – last post was the last MS update cycle. I’ve been trying to avoid spending almost every waking hour at a computer for a while. Anyway, advance notice for the March Microsoft updates came out and it appears as though the only critical update is […]

Microsoft February Patch day advance notice

Thursday, February 9th, 2006

Microsoft has given advance notice that next Tuesday they will be releasing 7 updates for Windows, as many as 5 of these will be tagged as critical. The Security Fix has a bit on the advance notice as does Sans. Looks like one of the critical updates will be for Media Player, 4 for Windows […]

Winamp and Shoutcast vulnerabilities

Tuesday, January 31st, 2006

In the last several days there have been a couple vulnerabilities disclosed that I should cover. The first up is related to Winamp. Version 5.12 is vulnerable to a problem with the way it handles .pls (playlist) files. This could allow very bad things with a specially crafted pls file. There were some workarounds mentioned, […]

Network Security – Arp spoofing series

Monday, January 30th, 2006

I think I’ve wrapped up the series on arp spoofing and it’s implications for network security. I know there’s nothing earth shattering here, most network security types are well aware of the problems (and perhaps aware of more sophisticated solutions?). For some though, this series is likely an eye opener as there are myths that […]

Google
 
Web www.averyjparker.com