<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Dear USA Today...now the story is even better</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx</link><description>Follow up to our lovely USA today article about the &amp;#8220;finagle vulnerability&amp;#8221;...you remember they did a honeypot and " To hijack the Windows Small Business Server, the attacker finagled his way into a function of the Windows operating system</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>An open letter to the Security Community:</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#23543</link><pubDate>Sun, 12 Dec 2004 08:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:23543</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=23543" width="1" height="1"&gt;</description></item><item><title>An open letter to the Security Community:</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#23541</link><pubDate>Sun, 12 Dec 2004 08:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:23541</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=23541" width="1" height="1"&gt;</description></item><item><title>re: Dear USA Today...now the story is even better</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#22769</link><pubDate>Tue, 07 Dec 2004 15:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:22769</guid><dc:creator>bradley</dc:creator><description>I'm waiting for a story on XYZ Company's Auto Alarm - and how a thief was able to finagle their way around it.  Of course, the story would fail to mention that even though the alarm was armed, the car was parked in the wrong part of town, all of the windows were left down, and the keys were left in the driver's seat . . .    &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=22769" width="1" height="1"&gt;</description></item><item><title>re: Dear USA Today...now the story is even better</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#22744</link><pubDate>Tue, 07 Dec 2004 10:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:22744</guid><dc:creator>bradley</dc:creator><description>This feels like a newsgroup reaching for some mud to sling just so they can run a story to fill some blank space.&lt;br&gt;&lt;br&gt;James&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=22744" width="1" height="1"&gt;</description></item><item><title>re: Dear USA Today...now the story is even better</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#22608</link><pubDate>Mon, 06 Dec 2004 17:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:22608</guid><dc:creator>bradley</dc:creator><description>Agreed--absolutely bogus.  Even a novice setting up SBS-2003 for the first time would be have difficulty doing that.  In fact, the novice would probably be behind a SOHO router, which also would have prevented the attack.&lt;br&gt;&lt;br&gt;This is poor reporting.  Yes, you CAN set the box up that way.  You can turn off the firewall in XP SP2, too.  A reasonable reporting procedure would be to set the box up as recommended by the vendor.  Most people setting up servers actually read (or have read) a good bit of the documentation.&lt;br&gt;&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=22608" width="1" height="1"&gt;</description></item><item><title>re: Dear USA Today...now the story is even better</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/06/22529.aspx#22536</link><pubDate>Mon, 06 Dec 2004 07:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:22536</guid><dc:creator>bradley</dc:creator><description>This is only confirms what I have always believed: that newspapers write stories in order to sell more newspapers! I mean that if you set up the server the way it is supposed to be set up and its safe, there is NO story.&lt;br&gt;Let's face it, anything not set up the way it is recommended can cause problems. If your car manufacturer recommends 30psi tyre pressure and you put in 50psi, you can't be surprised when the first pot hole bounces you all over the place, or if you slide off at the first bend!&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=22536" width="1" height="1"&gt;</description></item></channel></rss>