Archive for the 'Security' Category


Sony DRM Rootkit — it’s worse

Tuesday, November 15th, 2005

I did this as updates to an earlier post, but it probably deserves it’s own post now. The morning brought us the news of SERIOUS flaws in the Uninstaller ActiveX control for Sony’s DRM, then came news of ANOTHER flaw, this one a privilige escalation “attacker can take control of PC” vulnerability in the DRM […]

Lynx web browser vulnerability

Tuesday, November 15th, 2005

Incidents.org is reporting on an advisory for users of lynx. For those of you that don’t know lynx, it is a text based web browser used in text only terminal environments. I’ve used lynx from time to time to see what websites look like to a text only reader to help design towards better accessibility. […]

Sony discs to be recalled

Tuesday, November 15th, 2005

It looks as though the uninstaller as claimed last night, does have more serious implications than the original rootkit, in Sony’s continuing DRM nightmare. Basically, the uninstaller will allow any web page to run arbitrary code and or remotely control your pc. Which is sort of the holy grail of remote exploits. The ActiveX control […]

FTC’s message to Enternet Media has not quite sunk in…

Tuesday, November 15th, 2005

In spite of the FTC’s raid of Enternet Media and charges against them for various details such as deceptive install practices, unfair installation of code, failure to disclose nature of bundled software and furnishing code to others that interferes with the use of the computer… well, Enternet Media seems to be proliferating their wares just […]

SONY DRM rootkit – the gift that keeps on giving

Tuesday, November 15th, 2005

Well… I said, more legs than a centipede for this one…. It looks as though the uninstaller from Sony is an activex control that may have some SEVERE security implications. The ActiveX invokes a command to reboot the computer (RebootMachine). (Which is likely remotely exploitable). Also it appears to use an (InstallUpdate) download which could […]

New Sober virus variant coming

Tuesday, November 15th, 2005

This is unusual, but there is advance notice from the Bavarian Police warning about a new variant on the Sober worm which will be released tomorrow. More information can be found at f-secure, as well as sunbeltblog.    Send article as PDF   

CJB sites spawning spyware downloads?

Monday, November 14th, 2005

You might be cautious visiting the free sites at cjb.net according to the sunbelt blog many of them are unwittingly providing spyware downloads to users. The download is for a 180solutions pest. If you have a free cjb site, you would be well served to test your page to see for yourself what your visitors […]

Some companies unable to secure your data

Monday, November 14th, 2005

It’s sad, but true. Some companies are just plain irresponsible with your data. Whether it be credit card information, or address and phone number there are those that aren’t good about keeping their databases private. The securityfix is reporting that a recent survey found 12% of people had been notified by companies that they did […]

The wolf in sheeps clothing, software that claims to be anti-spyware, but installs more spyware on your pc

Sunday, November 13th, 2005

The bad news is that the spyware situation for home pc users can be murkier every day. I remember a particular user who once installed an antivirus program because a popup appeared claiming to have found viruses on his drive, next thing he knew he was having all sorts of spyware problems, viruses found all […]

Getting rid of an old PC – wipe the hard drive!!

Sunday, November 13th, 2005

I’ve said it before and mentioned DBAN (Darik’s Boot and Nuke) as my favorite tool for this, but Sunbeltblog is mentioning this and it’s worth reminding you. When you replace a PC, you might keep the hard drive around for a short period to make sure you have all your data, but PLEASE plan on […]

Google
 
Web www.averyjparker.com