Archive for the 'Security' Category


F-secure list of sober virus urls

Saturday, December 10th, 2005

When the news was first out that an antivirus firm (f-secure) had cracked the psuedo-random algorithm that the sober worm uses to determine where to download “updates” from, they said that they had previously notified German authorities where the free hosting sites were located so that they could deal with the sites. I did find […]

How much is a 0-day vulnerability worth?

Friday, December 9th, 2005

ZDnet has this article today of an ebay auction for information on a Microsoft Excel vulnerability that the auction-seller had notified Microsoft of. An online auction of a “brand new vulnerability” in Microsoft Excel had reached about $60 when eBay pulled the item late Thursday. A seller using the name “fearwall” started the auction Wednesday […]

10 things to do before hooking a Linux PC up to the net

Friday, December 9th, 2005

An editor at tech republic gave a challange not too long ago to Linux users to step up and offer articles along the lines of the top 10 things to do before hooking a linux pc up to the internet. Click to read the first of these submissions (I don’t know if there will be […]

DRM => spyware

Friday, December 9th, 2005

Freedom-to-tinker once again has continued analysis of the whole Sony DRM mess. They basically have taken a look at the ways of protecting an audio cd. Active protection (using software to prevent the duplication of music) is currently the main practical solution if you’re pursuing DRM. But what’s interesting is how much in common they […]

More details on Sober worm

Friday, December 9th, 2005

There’s a bit more detail in this betanews article on the sober worm. They basically say that the next expected “release” is January 8th, that f-secure has cracked the “code” of the worm. You see it appears that the URL’s that new versions of the worm are downloaded from are not hardcoded, but “psuedorandom” and […]

More on Firefox 1.5 “vulnerability”

Friday, December 9th, 2005

I put vulnerability in quotes because it’s looking less like a problem. (Correct me if I’m wrong.) Here’s the situation. Both Sans and Mozilla have failed to duplicate the crash although have duplicated extremely slow browser performance. Here’s the official response from mozilla.org… We have investigated this issue and can find no basis for claims […]

Two critical fixes from Microsoft on December patch Tuesday

Thursday, December 8th, 2005

December’s rendition of Microsoft’s monthly Patch Tuesday will feature two critical security fixes. The malicious software removal tool will also be updated… Additionally, Microsoft will issue two non-security high-priority updates through Windows Update and Software Update Services, and three non-security high-priority updates through Microsoft Update and Windows Server Update Services. It is standard Microsoft procedure […]

Most home pc users lacking on PC security…

Thursday, December 8th, 2005

Surprise!!… ummm wait, no… This article has come out while I’ve been in the midst of cleaning up a Windows ME pc that has been “0\/\/ned” (owned/controlled…) by someone other than the owner for a bit over 15 months. The system had NO antivirus, no firewall (no antispyware) and used dialup for internet. (That much […]

Registrars not verifying contact information on domains?

Thursday, December 8th, 2005

According to a GAO report one of the reasons that phishing and scam websites are because of a lack of enforcement and policing by registrars of accurate contact information. According to their study over 5% of sites had been registered with false data. ~2.5% had been registered with incomplete information. These findings come from a […]

Firefox 1.5 vulnerability

Wednesday, December 7th, 2005

Incidents.org has reported on the first announced vulnerability with Mozilla Firefox 1.5 since it’s release. The vulnerability is along these lines. History of visited sites is kept in a file called history.dat IF a URL for a visited site is long enough it will cause a buffer overflow and denial of service. (After visiting such […]

Google
 
Web www.averyjparker.com