Archive for the 'Security' Category


Sony’s OTHER DRM software uninstaller will be pulled

Saturday, November 19th, 2005

According to zdnet.com, Sony and SunnComm are pulling the OTHER DRM uninstaller from the web and it will be replaced with a safer version of the uninstaller. Researchers blogging at freedom-to-tinker.com had detailed serious vulnerabilities in the uninstaller for the DRM software made by SunnComm (called MediaMax). The companies say an effort will be made […]

Apple iTunes vulnerability on Windows

Friday, November 18th, 2005

eEye has discovered a remotely expoitable security vulnerability in Apple’s iTunes software. It affects iTunes 6 and prior and the current security updates (released yesterday) do not address the issue. News.com has coverage as well. Earlier they reported that it affected “all operating systems”, however now they are saying that it’s only been found on […]

GMail security problem fixed

Friday, November 18th, 2005

Google’s not had a great week it would appear (Sony’s had worse… but that’s another story). The Analytics launch was somewhat rocky from most accounts and there is a GMail security bug that’s been announced and fixed. Details on the bug are here, and a writeup is also here. Apparently a flaw in the authentication […]

Keyloggers a growing problem

Friday, November 18th, 2005

It’s interesting some years ago when viruses on Windows machines were SOOOO plentiful it seemed like that’s all I spent my time cleaning up, I thought… “you know, most viruses are prankster-ish programs. They rearrange icons, maybe cause Windows to crash, or send random files out to others, but they could be MUCH worse.” Since […]

OTHER Sony DRM software has security flaws too.

Thursday, November 17th, 2005

You almost want to bury your head in the sand at this point if you’re Sony…. Freedom-to-tinker has some details. The last couple weeks the XCP copy protection that Sony uses has been the center of a Firestorm for rootkit capabilities and massive security problems. Well, it seems the OTHER Digital Rights Management (DRM) software […]

TRUSTe will offer certification for adware

Thursday, November 17th, 2005

TRUSTe has announced a program to certify software downloads. Among them are certifications for adware and “trackware” (spyware?). The bullet summary for the article claims this will bring an end to “unwanted popups”. A clip from the article reads as follows… To be placed on the whitelist, adware and trackware must prominently disclose the types […]

Windows Denial of Service via RPC vulnerability

Thursday, November 17th, 2005

The Sans Institute is reporting on a vulnerability in Windows 2000 and XP SP1 (sp2 and 2003 not affected), that “could allow an attacker to levy a denial of service attack of limited duration”. It appears that valid login credentials are necessary for this. There is no patch yet, the best solution at this point […]

The best way to get rid of the Sony DRM rootkit

Thursday, November 17th, 2005

The SecurityFix has a great how to article for the general public on the best way to remove the Sony DRM rootkit that’s been big news the last two weeks in tech circles. First, DON’T use Sony’s removal software as that introduces more security problems. Hopefully Sony will get together a removal for THAT eventually. […]

Spammers/ phishers looking to get past “turin test” images

Thursday, November 17th, 2005

A lot of web sites these days use “turin tests” to keep from having automated bots sign up for mail or other services. (Or post entries to a forum or something.) For those that don’t know, a turin test is a test designed to filter machines from people. I doubt I’m the only one that […]

Beware web links from untrusted sources

Thursday, November 17th, 2005

There are flaws in Opera and Internet Explorer which could allow URL’s in the address bar to be obfuscated. One of the safest approaches is to be wary of web links from unknown or untrusted sources. To quote…. Claudio “Sverx” has discovered a weakness in Opera and Internet Explorer, which can be exploited by malicious […]

Google
 
Web www.averyjparker.com