Month: April 2006

  • Make an autorun cd show a web document on autoplay…

    There’s a utility called Thumbs that looks like a good quick way to make a cd launch a web documented on autoplay in Windows 95/98/ME/NT/2000/XP/ …Of course, autoplay under windows is fairly easy to setup. If you have a program on the disk you can just have autorun.inf in the root directory of the cd and in that you can specify WHAT program to autorun. The problem with html documents on a disk is telling the computer how to run it. (Yes you can adjust the icon as well.)

    (more…)

  • The do-not-do business with list….

    I found an interesting link through The Sunbeltblog on the “do not do business with” list… I don’t think this is a NEW thing really, for years there have been government policies against doing business with certain individuals, etc… but…. anyway Bruce Schneier has done an article on it which gives some interesting points that you probably aren’t aware of.

    (more…)

  • 3 Critical Microsoft Updates, 1 Important, 1 Moderate and 1 re-released

    Looks like an interesting patch day. Looks like there are several bugs covered by the cumulative IE patch… Sans has a good writeup (7 CVE issues addressed by this 1 patch….) Also the Eolas ActiveX settlement (“Eolas Patent Patch”) solution seems to be included in this bundle. Also a MDAC and a Windows Explorer (not to be confused with the Internet Explorer) patch. (The Windows Explorer AND MDAC bugs are Remote code execution vulnerabilities…)

    (more…)

  • Clamav 0.88.1 for Mandrake 10.0

    Since, I’ve still got a few older Mandrake 10 installs that I’m maintaining as mailservers, there aren’t supported security fixes for various things anymore… Friday there was news of a new clamantivirus to fix some security flaws with 0.88, new version is 0.88.1 I’ve taken the cooker srpm and recompiled for 10.0, so… for my convenience (and that of anyone with an older Mandrake box…) the links will be below.

    (more…)

  • IE phishing exploit..

    There is ANOTHER IE vulnerability that’s come across the news in the last week. It seems that this is currently only a Proof of Concept, I’ll have to check and see if anyone’s reported seeing this in the wild…, but essentially a race condition between a Macromedia flash file and web content can allow a forged address bar location… in other words it might say www.google.com in the address bar, but you’re actually looking at www.evilhackerplayground.org….

    (more…)

  • WordPress plugin stattraq speedup

    I’ve made mention I think that I use the stattraq plugin for wordpress as one of the ways to see where traffic is coming from on the site, etc. etc. etc. I think I mentioned it as one of my stat tracking tools about the time Google Analytics limped out of the gate… Anyway.. one of the things that had bugged me about it for some time was that it was SOOOOO slow to pull up any information (maybe a minute to pull in the page?) I had noticed a performance tip from the author…

    (more…)

  • Multi-OS virus?

    The multi-OS virus may be a proof of concept, but it could be a sign of bad things to come. Let’s face it, there have been viruses that have taken advantage of multiple ways of spreading (email/open network shares/instant messengers…) It would almost make sense that even though it’s POC…. it may be quickly incorporated into future virus strategies….

    (more…)

  • WordPress trackback problem FINALLY SOLVED….

    For around 3-4 months now I’ve had a REALLY annoying problem with the wordpress install on this site. Trackbacks suddenly stopped working. Somewhere around my 800th post or so while the WMF vulnerability was circulating (between Christmas and New Years) and I was typing furiously – poof…. suddenly trackbacks stopped going out. (Incoming trackbacks seemed to work just fine…) What’s had me stumped for so long is that I host 2 (now three) other sites off the same domain and I haven’t had a problem with ANY of those sending pingbacks or trackbacks.

    (more…)

  • OK – just fresh off the 5 wordpress install updates and now clamav…

    So, I spent the better part of the evening doing WordPress updates to get 5 blogs up to v. 2.0.2 and now….. clamav has multiple vulnerabilities …………… oi…. now it’s time to rebuild clamav to install on 2 machines……

    (more…)