<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Tips -Tech Info &#187; Security-updates</title>
	<atom:link href="http://www.averyjparker.com/category/security-updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.averyjparker.com</link>
	<description>and Internet Security, Windows, Linux, Mac and other Tech Info from Avery J. Parker</description>
	<lastBuildDate>Mon, 21 Nov 2011 06:25:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Extended support for XP Home and Media center</title>
		<link>http://www.averyjparker.com/2007/01/29/extended-support-for-xp-home-and-media-center/</link>
		<comments>http://www.averyjparker.com/2007/01/29/extended-support-for-xp-home-and-media-center/#comments</comments>
		<pubDate>Tue, 30 Jan 2007 01:13:07 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Tech Support]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[support]]></category>
		<category><![CDATA[time]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2007/01/29/extended-support-for-xp-home-and-media-center/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
I want to make a note of this here&#8230; Microsoft has announced that XP Home and Media center editions will get extended support on par with that of XP Pro. Essentially this means security updates for these versions of the OS should be available until 2014. Previously support for XP Home was to have ended [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>I want to make a note of this here&#8230; <a href="http://news.com.com/Microsoft+extends+support+for+XP+Home%2C+XP+Media+Center/2100-1016_3-6152952.html?tag=cd.hed"></a> Microsoft has announced that XP Home and Media center editions will get extended support on par with that of XP Pro.  Essentially this means security updates for these versions of the OS should be available until 2014.  Previously support for XP Home was to have ended as soon as December 2006, but was then extended modestly until after the release of Vista.  The &#8220;Home&#8221; oriented products weren&#8217;t given the same length of support as the &#8220;Professional&#8221; or Business class products at that time.  This announcement puts the two versions of XP on par with Pro.</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1518&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2007/01/29/extended-support-for-xp-home-and-media-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive Oracle quarterly patches</title>
		<link>http://www.averyjparker.com/2006/10/18/massive-oracle-quarterly-patches/</link>
		<comments>http://www.averyjparker.com/2006/10/18/massive-oracle-quarterly-patches/#comments</comments>
		<pubDate>Wed, 18 Oct 2006 23:46:49 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Massive Oracle]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/10/18/massive-oracle-quarterly-patches/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
If Microsoft patched 101 flaws in one release it would make big headlines &#8211; so this deserves some headlines too&#8230;. more coverage at incidents.org]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>If Microsoft patched <a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1225022,00.html">101 flaws in one release</a> it would make big headlines &#8211; so this deserves some headlines too&#8230;. <a href="http://isc.sans.org/diary.php?storyid=1795">more coverage at incidents.org</a></p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1459&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/10/18/massive-oracle-quarterly-patches/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft October 2006 patch Tuesday</title>
		<link>http://www.averyjparker.com/2006/10/10/microsoft-october-2006-patch-tuesday/</link>
		<comments>http://www.averyjparker.com/2006/10/10/microsoft-october-2006-patch-tuesday/#comments</comments>
		<pubDate>Tue, 10 Oct 2006 22:32:26 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tech Support]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[Automatic Updates]]></category>
		<category><![CDATA[microsoft update]]></category>
		<category><![CDATA[public]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows update]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/10/10/microsoft-october-2006-patch-tuesday/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
The first thing I should mention is that this months update from Microsoft is the last for XP SP1 users should plan a migration path to SP2 to keep getting updates to XP. Multiple vulnerabilities this month have been patched in Office There are 4 advisories, but a total of 15 issues covered by those [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>The first thing I should mention is that this months update from Microsoft <a href="http://blog.washingtonpost.com/securityfix/2006/10/still_running_service_pack_1_o.html">is the last for XP SP1</a> users should plan a migration path to SP2 to keep getting updates to XP.  Multiple vulnerabilities this month have been patched in Office <a href="http://isc.sans.org/diary.php?storyid=1772">There are 4 advisories</a>, but a total of 15 issues covered by those four.  Powerpoint, Excel, Word and Office/Publisher there are a variety of exploits, some public (like the powerpoint) others that were privately reported.  Also, Incidents.org gives a <a href="http://isc.sans.org/diary.php?storyid=1770">nice summary of the advisories and the severity</a> of each (urgency of updating.)  The setslice vulnerability is patched in this batch by the way.</p>
<p><span id="more-1437"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>Unfortunately, this patch day has already had it&#8217;s share of problems <a href="http://news.zdnet.com/2100-1009_22-6124447.html" class="broken_link" rel="nofollow">Zdnet reports</a> the following&#8230;.</p>
<blockquote><p>&#8220;Due to technical difficulties experienced on the Microsoft Update platform, security updates released today are not currently available via Microsoft Update, Automatic Updates, Windows Server Update Services or Windows Update v6,&#8221;</p></blockquote>
<p>Which explains why the workstation that I led to windows update this afternoon saw that there were 0 new updates available&#8230;.</p>
<p><a href="http://blog.washingtonpost.com/securityfix/2006/10/microsoft_updates_fix_26_secur.html">Brian Krebs at the Security fix has a few good points as well&#8230;</a>  Two of these updates affect Vista.  Also, among the Office updates, they are most critical on Office 2000, which is not serviced by automatic updates and so Office 2000 users SHOULD VISIT OFFICE UPDATE&#8230;. <a href="http://office.microsoft.com/en-us/officeupdate/default.aspx">office.microsoft.com/en-us/officeupdate/</a></p>
<p>These days the focus of crackers seems to be client applications and the distribution of updates seems to reflect that.  (Which makes it all the more important that even Office 2000 users get their updates.)</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1437&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/10/10/microsoft-october-2006-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October Microsoft update advance notice&#8230;.</title>
		<link>http://www.averyjparker.com/2006/10/05/october-microsoft-update-advance-notice/</link>
		<comments>http://www.averyjparker.com/2006/10/05/october-microsoft-update-advance-notice/#comments</comments>
		<pubDate>Thu, 05 Oct 2006 20:14:16 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[NET]]></category>
		<category><![CDATA[October Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/10/05/october-microsoft-update-advance-notice/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
11 patches will be released by Microsoft on the 10th of October. Bulletin is here, 6 for windows, 4 for Office (at least one in each of those two batches is critical) and 1 .NET (moderate) &#8211; yes the Windows updates will likely require a restart. Betanews has a bit more coverage hoping the WebViewFolderIcon [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p><a href="http://isc.sans.org/diary.php?storyid=1761">11 patches will be released by Microsoft on the 10th</a> of October.  <a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx">Bulletin is here</a>, 6 for windows, 4 for Office (at least one in each of those two batches is critical) and 1 .NET (moderate) &#8211; yes the Windows updates will likely require a restart.  <a href="http://www.betanews.com/article/Microsoft_to_Issue_11_Security_Patches/1160073925">Betanews has a bit more coverage</a> hoping the WebViewFolderIcon ActiveX control vulnerability will get fixed in this batch.</p>
<p><span id="more-1431"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><a href="http://blog.washingtonpost.com/securityfix/2006/10/microsoft_to_issue_eleven_patc.html">The Security Fix also has coverage on the advance notice.</a>  Here&#8217;s hoping that the three vulnerabilities Brian mentions are among those fixed.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1431&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/10/05/october-microsoft-update-advance-notice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploits in wild for recent Apple vulnerabilities</title>
		<link>http://www.averyjparker.com/2006/10/03/exploits-in-wild-for-recent-apple-vulnerabilities/</link>
		<comments>http://www.averyjparker.com/2006/10/03/exploits-in-wild-for-recent-apple-vulnerabilities/#comments</comments>
		<pubDate>Tue, 03 Oct 2006 21:40:01 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Mac Software]]></category>
		<category><![CDATA[Mac Tech Support]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Security-Vulnerabilities]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/10/03/exploits-in-wild-for-recent-apple-vulnerabilities/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
If you&#8217;ve been delaying on updating with the recent Apple Mac OS X updates&#8230;. don&#8217;t, there are exploits in the wild now for at least one. It&#8217;s speculated that this code may have been in the wild before Apple released the security updates.]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>If you&#8217;ve been delaying on updating with the recent Apple Mac OS X updates&#8230;. <a href="http://www.betanews.com/article/Mac_OS_X_Exploit_Emerges_After_Patch/1159893722">don&#8217;t, there are exploits in the wild now for at least one.</a>  It&#8217;s speculated that this code may have been in the wild before Apple released the security updates.</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1424&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/10/03/exploits-in-wild-for-recent-apple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Apple updates as Mac goes to version 10.4.8</title>
		<link>http://www.averyjparker.com/2006/10/01/multiple-apple-updates-as-mac-goes-to-version-1048/</link>
		<comments>http://www.averyjparker.com/2006/10/01/multiple-apple-updates-as-mac-goes-to-version-1048/#comments</comments>
		<pubDate>Mon, 02 Oct 2006 01:45:43 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Mac Software]]></category>
		<category><![CDATA[Mac Tech Support]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Security-Vulnerabilities]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Microsoft Word]]></category>
		<category><![CDATA[Multiple Apple]]></category>
		<category><![CDATA[RAW]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[USB]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/10/01/multiple-apple-updates-as-mac-goes-to-version-1048/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
Apple is fixing 15 security flaws with the 10.4.8 version upgrade of Mac OS X. (There is a second update as well&#8230;. Security Update 2006-006). In typical fashion there are a bundle of issues in these updates. Several address remotely exploitable vulnerabilities. According to Incidents.org 10.4.8 addresses the following&#8230;. - connecting to wireless networks using [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p><a href="http://blog.washingtonpost.com/securityfix/2006/10/apple_patches_15_security_flaw.html">Apple is fixing 15 security flaws</a> with the <a href="http://isc.sans.org/diary.php?storyid=1746">10.4.8 version upgrade of Mac OS X</a>.  (There is a second update as well&#8230;. Security Update 2006-006).  In typical fashion there are a bundle of issues in these updates.  Several address remotely exploitable vulnerabilities.</p>
<p><span id="more-1419"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
According to Incidents.org 10.4.8 addresses the following&#8230;.</p>
<blockquote><p>
- connecting to wireless networks using the EAP-FAST protocol<br />
- Apple USB modem reliability<br />
- using OpenType fonts in Microsoft Word<br />
- compatibility with 3rd party USB hubs<br />
- scanner performance<br />
- RAW camera support<br />
- printing documents with Asian language names<br />
- performance of the Translation widget<br />
- broadband network performance
</p></blockquote>
<p>That didn&#8217;t sound too bad, but some of the bad issues are lumped in to the 2006-006 security update.</p>
<p>Some of the remotely exploitable vulnerabilities COULD be exploited merely by a user visiting a malicious website that was specially crafted to take advantage of the flaw.  Patch away.</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1419&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/10/01/multiple-apple-updates-as-mac-goes-to-version-1048/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft releases official VML patch!!</title>
		<link>http://www.averyjparker.com/2006/09/26/microsoft-releases-official-vml-patch/</link>
		<comments>http://www.averyjparker.com/2006/09/26/microsoft-releases-official-vml-patch/#comments</comments>
		<pubDate>Tue, 26 Sep 2006 21:03:28 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Security-Vulnerabilities]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[DRM]]></category>
		<category><![CDATA[Microsoft Windows Media]]></category>
		<category><![CDATA[RC]]></category>
		<category><![CDATA[Security Fix]]></category>
		<category><![CDATA[VML]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/09/26/microsoft-releases-official-vml-patch/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
The big news this afternoon is that Microsoft HAS gone out of the routine patch cycle to release a security fix for the VML vulnerability that&#8217;s been actively exploited in recent days for everything from sneak keylogger installs to massive spyware installs. Sans has a few links, if you de-registered the affected DLL you should [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>The big news this afternoon is that Microsoft HAS gone out of the routine patch cycle to release a security fix for the VML vulnerability that&#8217;s been actively exploited in recent days for everything from sneak keylogger installs to massive spyware installs.  <a href="http://isc.sans.org/diary.php?storyid=1738">Sans has a few links</a>, if you de-registered the affected DLL you should consider re-registering the same so that you&#8217;ll be able to view/access vml content in the future.  <a href="http://www.microsoft.com/technet/security/Bulletin/MS06-055.mspx">Here&#8217;s Microsoft&#8217;s technet Security Bulletin on the matter.</a>  (Visit <a href="http://update.microsoft.com">update.microsoft.com</a> if it&#8217;s not automatically downloaded for you.)  It should be noted that the RC of IE 7 was not affected by this vulnerability.</p>
<p><span id="more-1412"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>A few days ago, I speculated that the way to get this patched by 9/25/06 was if it were discovered that the vulnerability were being used to strip DRM from Microsoft&#8217;s Windows Media audio/video files&#8230;. I&#8217;m glad to see that they did it early without their DRM future at stake&#8230;.</p>
<p>Also, I should mention if you&#8217;ve installed the unofficial patch, uninstall that at this time as well.  <a href="http://blog.washingtonpost.com/securityfix/2006/09/microsoft_issues_emergency_pat.html">Brian Krebs at the Security Fix</a> also has coverage on this.</p>
<p>Good job Microsoft, thanks for going &#8220;out of cycle&#8221; to get this update out there.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1412&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/09/26/microsoft-releases-official-vml-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Macbook pro and other wireless fixes</title>
		<link>http://www.averyjparker.com/2006/09/21/apple-macbook-pro-and-other-wireless-fixes/</link>
		<comments>http://www.averyjparker.com/2006/09/21/apple-macbook-pro-and-other-wireless-fixes/#comments</comments>
		<pubDate>Fri, 22 Sep 2006 01:14:07 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Mac Software]]></category>
		<category><![CDATA[Mac Tech Support]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[Apple Macbook]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[Security Fix]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/09/21/apple-macbook-pro-and-other-wireless-fixes/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
Do you remember the big bruhaha a month or so back about the &#8220;apple wireless vulnerability&#8221; that everybody picked apart because in the video taped demonstration they used a third party card&#8230;. EVEN though the demonstrators stated that the same vulnerability existed in Apple&#8217;s own driver some on the internet tore one reporter up over [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>Do you remember the big bruhaha a month or so back about the &#8220;apple wireless vulnerability&#8221; that everybody picked apart because in the video taped demonstration they used a third party card&#8230;. EVEN though the demonstrators stated that the same vulnerability existed in Apple&#8217;s own driver some on the internet tore one reporter up over stating that because Apple denied being shown exploit code (slight semantic issue there&#8230;)  Well&#8230; those driver vulnerabilities that must have not existed, were fixed today by Apple.  <a href="http://blog.washingtonpost.com/securityfix/2006/09/apple_issues_patches_for_macbo.html">Brian Krebs has the story</a>, as well as <a href="http://isc.sans.org/diary.php?storyid=1724">incidents.org</a></p>
<p><span id="more-1409"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>What&#8217;s really interesting is that several remote code execution vulnerabilites are fixed in this update, but no credit is given to the company that presented the vulnerability, so it&#8217;s either &#8220;bad blood&#8221; over the issue or a matter of pride for Apple since they&#8217;ve not admitted the demonstrated vulnerability was actually in their driver.  In fact&#8230;. according to the Security Fix post they (Apple) say&#8230;</p>
<blockquote><p>&#8220;Basically, what happened is SecureWorks approached Apple with a potential flaw that they felt would affect the wireless drivers on Macs, but they didn&#8217;t supply us with any information to allow us to identify a specific problem. So we initiated our own internal product audit, and in the course of doing so found these flaws.&#8221;</p></blockquote>
<p>&#8211;Update 10/1/06&#8211;</p>
<p>This is <a href="http://blog.washingtonpost.com/securityfix/2006/09/jon_ellch_on_the_cancelled_too.html">still an ongoing controversy</a>.  There definitely appears to be bad blood, it&#8217;ll continue to be interesting to follow this one.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1409&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/09/21/apple-macbook-pro-and-other-wireless-fixes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ANOTHER Microsoft patch problem</title>
		<link>http://www.averyjparker.com/2006/09/11/another-microsoft-patch-problem/</link>
		<comments>http://www.averyjparker.com/2006/09/11/another-microsoft-patch-problem/#comments</comments>
		<pubDate>Tue, 12 Sep 2006 00:07:51 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[DRM]]></category>
		<category><![CDATA[MS]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/09/11/another-microsoft-patch-problem/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
This is getting to be like clockwork, but it sounds like this may be one of the nastiest problems so far. It appears that there is a problem with one of the recent patches from Microsoft MS06-49. It looks as though the problem is data corruption for small files (under 4096 bytes.) There&#8217;s a google [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>This is getting to be like clockwork, but it sounds like this may be one of the nastiest problems so far.  It <a href="http://it.slashdot.org/article.pl?sid=06/09/11/1342224">appears that there is a problem with one of the recent patches from Microsoft MS06-49</a>.  It looks as though the problem is data corruption for small files (under 4096 bytes.)  <a href="http://groups.google.co.uk/group/microsoft.public.win2000.file_system/browse_frm/thread/e4b7037b0a73dcd5/a56ac72f779e1f25?lnk=st&#038;q=kb920958&#038;rnum=2&#038;hl=en#a56ac72f779e1f25">There&#8217;s a google groups thread here.</a>  The key factor seems to be that IF the folder is compressed, the data within is subject to this possible corruption.</p>
<p><span id="more-1396"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>This <a href="http://www.microsoft.com/technet/community/newsgroups/dgbrowser/en-us/default.mspx?dg=microsoft.public.windowsupdate&#038;tid=a86c111b-48a7-4534-9bb9-29d8e5b0a856&#038;cat=en-us-technet-filesvcs&#038;lang=en&#038;cr=US&#038;sloc=en-us&#038;m=1&#038;p=1">appears to just affect Windows 2000 pro and server.  It&#8217;s been reported to Microsoft, but no official word yet from them.  (Maybe they should have claimed that the bug disabled DRM on subscription based media files&#8230;.)</p>
<p>I haven&#8217;t tried to do an official count, but it seems like one &#8220;problem child&#8221; update a month this year for MS.</p>
<p>Oh, and tomorrow (Tuesday the 12th) is patch day&#8230;. happy rebooting.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
</a></p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1396&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/09/11/another-microsoft-patch-problem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s priorities&#8230;</title>
		<link>http://www.averyjparker.com/2006/09/08/microsofts-priorities/</link>
		<comments>http://www.averyjparker.com/2006/09/08/microsofts-priorities/#comments</comments>
		<pubDate>Fri, 08 Sep 2006 15:44:50 +0000</pubDate>
		<dc:creator>Avery</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security-updates]]></category>
		<category><![CDATA[Windows Software]]></category>
		<category><![CDATA[Windows Tech Support]]></category>
		<category><![CDATA[DRM]]></category>
		<category><![CDATA[time]]></category>
		<category><![CDATA[Tuesday September]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows Media Files]]></category>

		<guid isPermaLink="false">http://www.averyjparker.com/2006/09/08/microsofts-priorities/</guid>
		<description><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>
I didn&#8217;t really think of this in context, but George Ou points out that Microsoft issued an &#8220;out of cycle&#8221; patch for their DRM software in response to the FairUse4WM software that stripped DRM protections from Windows Media Files. It took a mere 3 days from being made aware of the issue to releasing a [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
#leftcontainerBox {
	float:left;
	position: fixed;
	top: 60%;
	left: 70px;
}
#leftcontainerBox .buttons {
	float:left;
	clear:both;
	margin:4px 4px 4px 4px;
	padding-bottom:2px;
}
#bottomcontainerBox {
	width: 50%;
	padding-top: 1px;
}
#bottomcontainerBox .buttons {
	float: left;
	margin: 4px 4px 4px 4px;
}
</style>

<!-- google_ad_section_start -->
<!--INFOLINKS_ON-->
<p><p>I didn&#8217;t really think of this in context, but <a href="http://blogs.zdnet.com/Ou/?p=312">George Ou points out that</a> Microsoft issued an &#8220;out of cycle&#8221; patch for their DRM software in response to the FairUse4WM software that stripped DRM protections from Windows Media Files.  It took <em>a mere 3 days</em> from being made aware of the issue to releasing a patch.  In context, we have seen numerous instances in the last year of &#8220;zero-day&#8221; vulnerabilities becoming known just after a monthly patch day, and Microsoft waiting until the next patch day to release a fix.  So why the different response?</p>
<p><span id="more-1387"></span><br />
<script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6855210186";
google_ad_width = 468;
google_ad_height = 15;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>Some might give Microsoft the benefit of the doubt.  Patching a full application is different than just patching DRM schemes, it requires a lot more testing to make sure things work right and don&#8217;t break.  (I presume with this argument there&#8217;s no concern for media files &#8220;breaking&#8221; in any way with a change to the DRM scheme &#8211; of course &#8211; we could get into a tangent on &#8220;broken&#8221; in relation to media files, but we&#8217;ll save that for another time&#8230;.)</p>
<p>I&#8217;m not giving them the benefit of the doubt.  In fact, I think it&#8217;s fairly obvious.  There are several very large companies that are paying pretty big for Microsoft&#8217;s DRM and are nervous at the thought of broken DRM.  I wouldn&#8217;t be surprised if, on news of this DRM &#8220;workaround&#8221; or breakage, they didn&#8217;t hear from some VERY upset people with some of the big content distributors &#8220;urging&#8221; them to fix things as soon as possible.  (OR ELSE.)</p>
<p>When it comes to security vulnerabilities in a Microsoft product there isn&#8217;t a single entity that can tell them&#8230;. &#8220;Look &#8211; you need to get this fixed now, or we&#8217;ll suspend our contract and go elsewhere.&#8221;  This is ONE of the many reasons that I think we need to really invest time and attention in potential alternatives to Windows (as well as other Microsoft products.)  Because the day that there&#8217;s a zero day in Microsoft office that prompts Fortune 500 companies to say, &#8220;you need to get this fixed or I&#8217;m migrating to xxxxoffice suite and not coming back.&#8221;  we won&#8217;t see quite the responsiveness on security issues.  One thing on this, moving away from the one time software purchase model may actually be a good thing for this to change because if you&#8217;re &#8220;subscribing&#8221; to the software (or maintenance) you have more leverage to be able to say &#8220;fix it or I&#8217;m out the door&#8221;.</p>
<p>It would be interesting to hear Microsoft&#8217;s explanation of how this patch was streamlined so quickly, while most security updates sit on the shelf longer.  Oh, and by the way, DRM was slightly broken again within a couple days after the patch.  (But not for songs with an expiration date. (subscription services))</p>
<p>Oh, by the way, it is that time again &#8211; updates coming Tuesday (September 12).  <a href="http://isc.sans.org/diary.php?storyid=1679">Sans has details</a> &#8211; 2 &#8220;important&#8221; updates for Windows (no critical this time&#8230;)  and 1 critical for Microsoft Office (hopes are that this fixes the most recent zero-day vulnerability that&#8217;s been circulated.)  There are other non-security related updates for a total of 9, but it seems relatively low-key.  The bulletin from Microsoft can be <a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx">found here.</a>  (Yes reboot will be required for at least one of the updates.)</p>
<p><a href="http://blog.washingtonpost.com/securityfix/2006/09/three_patches_from_microsoft_n.html">Brian Krebs of the SecurityFix</a> has the story as well, and notes that this is far fewer than what we&#8217;ve seen in recent months on patch Tuesday.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-5003751123450346";
google_ad_slot = "6558276326";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

<!--INFOLINKS_OFF-->
<!-- google_ad_section_end -->
<img src="http://www.averyjparker.com/?ak_action=api_record_view&id=1387&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.averyjparker.com/2006/09/08/microsofts-priorities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

