Browse by Tags

All Tags » Security (RSS)

Sites pulling sneaky Flash cookie-snoop

“What's far less well known is that Adobe Flash software also features cookies that can be used in much the same way as HTTP cookies. Flash cookies can be used for storing the volume level of a Flash video but the technology can also be used as "secondary...
Posted by Tony | with no comments
Filed under: ,

Key fobs for logging onto domains

A while back I read that Paypal were offering key fobs for logging onto their system. Also a while back fellow MVP Susan Bradley mentioned the AuthAnvil Tokens in her SBS Diva blog entry The "Later" Decision. This is looking like a very interesting...
Posted by Tony | with no comments
Filed under:

Who is reading your email?

E-Mail Surveillance Renews Concerns in Congress What about your ISP or mail server hosting service? Or even Google, Yahoo or Hotmail. For the record I've had discussions about privacy issues with employees of Microsoft. Not only do I doubt corporations...
Posted by Tony | 1 comment(s)
Filed under:

An older version of MSCOMM32.OCX has had the "kill bit" flag set.

The latest Windows Update has set the kill bit flag for an out of date but commonly used version of mscom32.ocx. Microsoft Security Advisory (969898) Options - roll back the update. Not recommended however instructions are in the above web page. - locate...
Posted by Tony | 10 comment(s)

DbUtilities - Transfer object permissions from a secured database to a new database container

The first item "is a fantastic re-write of DbUtilities which, as an Add-in, makes it easier to transfer the object permissions from a secured database to a new database container. " Author: Jeff Conrad (aka "Access Junkie"), former...
Posted by Tony | with no comments
Filed under: ,

Encryption and developers

A newsgroup poster recently stated: I found a freeware dll, md5lib.dll, on the web and am trying to use it in Access 2003. My reply (which has been added to for the purposes of this posting) I would strongly urge using the CryptoAPI as specified by Microsoft...
Posted by Tony | 1 comment(s)
Filed under: ,

Security expert talks Russian gangs, botnets

Security expert talks Russian gangs, botnets A very interesting story about a very low profile Botnet which has been around since 2002. "50 gigabytes of compressed data, searchable in a MySQL database. "
Posted by Tony | with no comments
Filed under:

New type of phishing spam targeting domain owners

I get 300 to 500 spams per day and Mail Washer Pro does a darned good job of removing the crap. This last day or so I've been noticing a new type of spam targeting the owner of my domains. Text is below. The right most two domain chunks, in this case...
Posted by Tony | with no comments
Filed under:

How to secure your personal data on a removed hard disk drive.

How to secure your personal data on a removed hard disk drive. That works. A bit extreme mind you. I'd also ensure I was upwind.
Posted by Tony | with no comments
Filed under:

Investigation confirms proper safeguards were in place for stolen laptop computer

So is employee information in your business encrypted? If not why not? (Note that just employee names isn't that big of a deal as they would mostly be in the phone book anyhow.) Investigation confirms proper safeguards were in place for stolen laptop...
Posted by Tony | with no comments
Filed under:

Interesting WPA/WPA2 and docx, zip, etc. files cracking breakthrough

Slash dot reported Elcomsoft Claims WPA/WPA2 Cracking Breakthrough . There are some details there though so if this issue affects your corporate network, ensure you read the details. Note the large number of file formats which it will brute force crack...
Posted by Tony | 1 comment(s)
Filed under:

Stunningly weak Yahoo password security

I was wondering just how the hacker got into Palin's account so easily. "Rubico claimed the actual intrusion into Palin's account was a relatively easy matter. It began after Rubico read news accounts claiming Palin used gov.palin@yahoo.com...
Posted by Tony | 3 comment(s)

With Software, Till Tampering Is Hard to Find

A very interesting story on till tampering and cash in restaurants. With Software, Till Tampering Is Hard to Find Indeed any cash business. Thanks to Slashdot for the link However that story concentrated on business owners and missed one area of attack...
Posted by Tony | with no comments
Filed under:

Malicious Thumb Drives

"Please be advised that two USB thumb drives were discovered on the 9th Floor of the Bicentennial Building. One was discovered in the Men's restroom yesterday afternoon. Another was found this morning on a facsimile machine. The drives contain...
Posted by Tony | with no comments
Filed under:

MS08-041 : The Microsoft Access Snapshot Viewer ActiveX control

MS08-041 fixes a vulnerability in the Microsoft Access Snapshot Viewer ActiveX control. It’s an interesting vulnerability so we wanted to go into more detail about platforms at reduced risk and also more about the servicing strategy for this vulnerability...
Posted by Tony | with no comments
Filed under: ,

Vulnerability in the Snapshot Viewer for Microsoft Access

Microsoft Security Advisory (955179) - Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (I've always wondered how they can come up with a FAQ section on a brand new vulnerability....
Posted by Tony | with no comments
Filed under:

Stopping SQL Injection in its Tracks

Stopping SQL Injection in its Tracks Highly recommended if you are running ASP or IIS.
Posted by Tony | with no comments
Filed under:

News Flash: Spaces are legal characters in both filenames and passwords!

News Flash: Spaces are legal characters in both filenames and passwords! My comments to that posting: I didn't know spaces were valid in a Windows password until I happened to be watching a Microsoft video a year or three ago. Oh I knew all about...
Posted by Tony | with no comments
Filed under:

Don't Forget To Lock Your Computer

Don't Forget To Lock Your Computer
Posted by Tony | with no comments
Filed under: ,

Access 2000 security patches

Warning: Microsoft Update, which includes Windows and Office Updates, will not locate Office 2000 patches. I was a bit startled recently when I managed to somehow get to an Office Update screen that informed me I was missing a number of Office 2000, and...
Posted by Tony | with no comments
Filed under: , ,
More Posts Next page »