Archive for the 'Security' Category


Phantastic site for Phishing research….

Wednesday, August 2nd, 2006

By way of Sunbelt blog… The Phishtank at Internet Defence has a realtime archive of phishing emails as well as real time information on the status of their host sites. On their phishing site monitor it says…    Send article as PDF   

Wireless Driver Vulnerabilities

Wednesday, August 2nd, 2006

There are a couple notes to pass along with regards to some pretty serious vulnerabilities in various wireless network adapter drivers. First, Sans has information on some Intel Centrino updates that resolve some vulnerabilities that would affect the Windows Centrino driver and the ProSet management software. F-secure chimes in on this noting that the download […]

Time for Apple Mac OS X updates again

Tuesday, August 1st, 2006

From the look of it Apple has released a bunch of updates for OS X. A number of security issues are detailed. As always, SANS has some good details and links to more info on each of the ~13 issues. Many of them are legacy bugs if you will from older *nix-based systems. This is […]

More reason to be cautious with Firefox plugins

Tuesday, August 1st, 2006

Again…. this article referring to an exploit related to the cross platform plugin capability in firefox, is a GOOD reminder to be cautious when looking at potential plugins to install for mozilla firefox. In fact, the advice is usually do NOT install software (including plugins) from untrusted sources. By all means, please investigate any piece […]

Banks and Web security

Tuesday, August 1st, 2006

George Ou has a good post on Banks cheating their way to meet web security guidelines. Many of the observations that he notes come from the Between the Lines column here and are SPOT ON. The biggest I see is related to “multifactor authentication”….    Send article as PDF   

Security Tip a day for August

Tuesday, August 1st, 2006

SANS has an answer to last months browser vulnerability a day blog… for August they’ll present a security tip a day. So, if you haven’t visited the handlers diary, this may be a good time to “tune in”. The first one has to do with strong passwords (I think they decided they may as well […]

Fun way to mess with wireless freeloaders….

Monday, July 31st, 2006

Some people spend a lot of time finding ways to block the freeloaders from their wireless internet. Others find fun ways to mess with them…. They start off by settup up dhcpd.conf to carve out two subnets a “good” one with known mac addresses and an untrusted…. then the fun begins with some proxy side […]

Firefox 1.5.0.5 out and be cautious with extensions…

Monday, July 31st, 2006

Well, let’s start with the extensions first. Like ANY software, you should be cautious installing something from an untrusted source. If you think an extension looks neat and cool – look for reviews and third party information before installing it. That much said…. never install an extension that comes attached as an unexpected email…. Apparently, […]

Internet Explorer 7 as High Priority update and the ability to prevent it’s auto-download

Monday, July 31st, 2006

The news has come that Internet Explorer 7 will come out as a high priority security update when it’s released later this year. This should mean good things for the folks that are still using IE6 as it will bring quite a few security enhancements. (On a side note, my test of Vista with IE7 […]

Microsoft Issues advisory on Powerpoint flaw

Tuesday, July 18th, 2006

Here’s the link to Microsoft’s advisory. The main workaround seems to be…. Don’t open or save powerpoint attachments that you receive from untrusted sources, OR that you receive unexpectedly from trusted sources…. So, the only real workaround is what SHOULD be common practice. Whether or not there is a vulnerability in the news you should […]

Google
 
Web www.averyjparker.com