Oracle’s April patches late….

Wednesday, May 10th, 2006

Oracle released 36 patches in mid-April as part of their quarterly patch cycle…. unfortunately, not all of the patches were released. Apparently they hadn’t finished testing and users were advised to look for the updates around the first of May. Well, guess what – they’re not out yet and the word is that they won’t […]

IE exploit unofficial patches

Tuesday, March 28th, 2006

While we wait for Microsoft to release a patch for the MOST recent Internet Explorer vulnerability….. it looks as though MS is “planning” to release a patch on their routine patch day of April 11th. (However they could always change their mind…) As before though there are some 3rd party patches. I’ve got to say […]

March Microsoft Updates – etc.

Friday, March 10th, 2006

I can’t believe it’s been so long without a post – last post was the last MS update cycle. I’ve been trying to avoid spending almost every waking hour at a computer for a while. Anyway, advance notice for the March Microsoft updates came out and it appears as though the only critical update is […]

MS responds to “intentional backdoor”, WMF claim

Friday, January 13th, 2006

Microsoft is disputing claims by Steve Gibson, that the WMF vulnerability was an intentionally placed backdoor. There is a response to the claims in the Microsoft Security Incident Response blog. Apparently since the SetAbortProc procedure relates to printing, previous versions of Windows ignored the call unless printing was involved. (Why did windows start paying attention […]

Microsoft releases patch early for WMF exploit

Thursday, January 5th, 2006

Microsoft has released the patch for the WMF vulnerability that’s been all over the news early. It was released to http://windowsupdate.microsoft.com ahead of the previously announced January 10th “patch Tuesday”. Congrats to Microsoft for getting this out the door early. That should go a long ways to blunting the attacks that are making use of […]

MS seeing WMF with rose colored glasses?

Tuesday, January 3rd, 2006

Ok – so at least I wasn’t the only one to see Microsoft’s update to the security bulletin as downplaying the threat…. Of course, I don’t expect them to say…. “OH NO>>>> THE INTERNET WILL BE CRASHING AND BURNING…” But acknowledging that it is a very serious threat and there are few ways (outside of […]

WMF patch from Microsoft expected January 10th

Tuesday, January 3rd, 2006

The Microsoft security bulletin on the WMF vulnerability has been updated to indicate that Microsoft expects to release an update for the issue in their regular patch release on January 10th. The first couple paragraphs strike me as a bit defensive. Explaining about their immediate mobilization of Incident Response and immediate work on a patch, […]

WMF Exploit — it’s worse…

Sunday, January 1st, 2006

This is going to be a rough start to the new year for IT staff and computer users…. There’s coverage at Incidents.org, the sunbeltblog and f-secure of the latest twist in what will likely be a BIG mess to clean up. It looks like there’s a someone spamming emails to tons of addresses with a […]

Third Party WMF patch

Saturday, December 31st, 2005

The F-secure blog is reporting on a third party patch for the WMF exploit. I have not tested it, it seems to come from a knowledgable source though. As I’m writing this though, the thought strikes me that a really nasty trick would be a claimed fix that actually exploited the vulnerability. It pays to […]

Update on the WMF exploit – more sites to block

Thursday, December 29th, 2005

I haven’t checked to see if these are already on other block lists for the WMF exploit, but the following addresses are advised to be blocked (from f-secure)…. toolbarbiz[dot]biz toolbarsite[dot]biz toolbartraff[dot]biz toolbarurl[dot]biz buytoolbar[dot]biz buytraff[dot]biz iframebiz[dot]biz iframecash[dot]biz iframesite[dot]biz iframetraff[dot]biz iframeurl[dot]biz    Send article as PDF   

Google
 
Web www.averyjparker.com