Archive for the 'Security' Category


But it’s brand new, how could it have so many updates?

Wednesday, August 23rd, 2006

This morning I was doing a fresh install of Windows XP SP2 into a Virtual Machine. So far, things are fine I went through windowsupdate and found 3 updates the first time, then rebooted and hit windowsupdate again to see 55 updates available. A lot of times when I set up a new pc for […]

Powerpoint vulnerability (August 2006)

Tuesday, August 22nd, 2006

I’m having to make sure I put the date in the title of these posts now…. over the weekend there were rumors of a new powerpoint vulnerability. Sans had an early notice of some trojan droppers using powerpoint files. And by the 20th (Sunday) it was being called a 0-day. There is a good FAQ […]

Mac Wireless driver Security vulnerability revisited

Friday, August 18th, 2006

A couple weeks ago the hot story was about the demonstration of a vulnerability in a 3rd party wireless card driver on a Mac. The individuals that demonstrated the vulnerability (in a video taped presentation) also claimed that many wireless drivers were vulnerable to this same flaw and it included the MacBook native drivers (among […]

Encrypting wireless traffic

Thursday, August 17th, 2006

Incidents.org has been running their security tip a day this month and I really liked this one. It’s essentially a way to encrypt your wireless traffic using ssh. That’s something I’ve covered here before, but it’s worth reminding that it’s possible and a good idea.    Send article as PDF   

Other MS patch news as well as a Yahoo vulnerability?

Monday, August 14th, 2006

Or lack of currently available patch as the case may be. From the previous link it appears that there was at least one previously announced vulnerability that was not addressed in the recent patch day from Microsoft. From MS… “this is a DoS only issue that was not addressed in MS06-040, but will be addressed […]

MS06-040 update

Monday, August 14th, 2006

MS06-040 is one of last weeks Windows updates and is the one that was probably the biggest target for “wormable” activity. There’s a good deal of news from over the weekend with regards to this. First: Snort signatures, the MS06-040 exploit was spotted actively “in the wild”, and of course, our perennial friends in the […]

Being cautious on the web…

Monday, August 14th, 2006

Incidents.org is reporting on the defacement of a security related web site (winsnort.com). They say they usually decline to comment on those because the attention is what the defacers thrive on. However, it does pay to keep your browser updated and antivirus current. What’s more…. Several days ago there was the news that the President […]

Ruby on Rails urgent update

Thursday, August 10th, 2006

A new version of Ruby on Rails has been released in response to a critical security vulnerability. The link will take you to information at incidents.org. 1.1.5 is the new version and should be compatible with 1.1.4 all previous versions appear to be vulnerable.    Send article as PDF   

Exploit out for MS06-040

Thursday, August 10th, 2006

The big computer security news of the day is the release of exploit code publicly for MS06-040. The patch of course was released Tuesday and it is fairly critical to get the update installed. This is “wormable” It CURRENTLY affects all Windows 2000 systems and XP (with no service pack) as well as SP1. It […]

Blackberry vulnerability to be released soon

Tuesday, August 8th, 2006

Between the Lines is warning that Blackberry Enterprise servers ought to be placed in the DMZ (if not already.) There is word that a critical vulnerability will be announced on August 14th. (And if we already know that’s coming then SOMEONE knows what that vulnerability is.) It basically uses software on the Blackberry (which could […]

Google
 
Web www.averyjparker.com