<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">CastleCops</title><subtitle type="html">Because Security IS Everything</subtitle><id>http://msmvps.com/blogs/castlecops/atom.aspx</id><link rel="alternate" type="text/html" href="http://msmvps.com/blogs/castlecops/default.aspx" /><link rel="self" type="application/atom+xml" href="http://msmvps.com/blogs/castlecops/atom.aspx" /><generator uri="http://communityserver.org" version="4.1.40407.4157">Community Server</generator><updated>2005-08-10T00:27:00Z</updated><entry><title>Rick Carlson Former Presdent/CEO Aluria Software Responds</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/03/05/85537.aspx" /><id>/blogs/castlecops/archive/2006/03/05/85537.aspx</id><published>2006-03-05T21:35:00Z</published><updated>2006-03-05T21:35:00Z</updated><content type="html">&lt;P&gt;&lt;STRONG&gt;By Robin Laudanski&lt;BR&gt;March 5, 2006&lt;BR&gt;&lt;BR&gt;&lt;/STRONG&gt;Finally someone from Aluria has decided to respond. In a &lt;A href="http://castlecops.com/article-6552-nested-0-0.html" target=_blank&gt;previous article&lt;/A&gt; I mentioned a thread at &lt;A href="http://discuss.pcmag.com/forums/2/1004308409/ShowPost.aspx#1004308409" target=_blank&gt;PCMag&lt;/A&gt; wherein some comments were made which basically suggested I was lieing about my attempts to contact Mr. Goldstone. Once again I've been called a liar, only this time it was by Rick Carlson former President/CEO of Aluria Software. The thing I find most remarkable about his entire reply is not that I'm being called a liar I expected that from Aluria and it isn't that Mr. Carlson actually admitted certifying WhenU as being spyware free was a mistake, although it is an enormous step even if the reason given for it being a mistake is misguided in my opinion. What I find most remarkable is that he seems to think I have something against Aluria, that I am attacking a name, when in fact all I'm doing is reporting the fact that information which showed there was once a relationship between Aluria and WhenU has conveniently disappeared. For someone who is leaving the company his response seems rather hostile.&lt;BR&gt;&lt;BR&gt;This is taken from the thread at PCMag:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://castlecops.com/a6556-Rick_Carlson_Former_Presdent_CEO_Aluria_Software_Responds.html"&gt;Continued in full...&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=85537" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Aluria's Attempt to Discredit CastleCops</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/03/04/85387.aspx" /><id>/blogs/castlecops/archive/2006/03/04/85387.aspx</id><published>2006-03-04T00:09:00Z</published><updated>2006-03-04T00:09:00Z</updated><content type="html">&lt;P&gt;&lt;STRONG&gt;By Robin Laudanski&lt;BR&gt;March 3, 2006&lt;BR&gt;&lt;BR&gt;&lt;/STRONG&gt;Earlier today I happen to come across something at another site, which I found quite funny since the comments seemed to be an attempt to discredit CastleCops and myself, by asserting that we didn't try to contact Mr. Goldstone of Aluria until after I published the &lt;A href="http://castlecops.com/article-6549-nested-0-0.html" target=_blank&gt;Aluria Trys To Whitewash The WhenU Fiasco&lt;/A&gt; article. When we publish something we do make every effort to ensure that the information provided is accurate and we also make every effort to ensure that everyone has a chance for their voice to be heard. &lt;BR&gt;&lt;BR&gt;You may remember when Aluria first said that WhenU was Spyware Free, we provided them with an opportunity to answer some questions in their own defense for their decision. To my knowledge no one else provided such an opportunity.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://castlecops.com/a6552-Alurias_Attempt_to_Discredit_CastleCops.html"&gt;Full Story&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=85387" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Aluria Trys To Whitewash The WhenU Fiasco</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/03/04/85386.aspx" /><id>/blogs/castlecops/archive/2006/03/04/85386.aspx</id><published>2006-03-04T00:08:00Z</published><updated>2006-03-04T00:08:00Z</updated><content type="html">&lt;P&gt;&lt;STRONG&gt;By Robin Laudanski&lt;BR&gt;March 2, 2006&lt;BR&gt;&lt;BR&gt;&lt;/STRONG&gt;Some of you might remember back in October of 2004 Aluria Software delisted WhenU and &lt;A href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=109&amp;amp;STORY=/www/story/10-27-2004/0002312862&amp;amp;EDATE" target=_blank&gt;Certified them as being Spyware Safe&lt;/A&gt;. Would it suprise you to find out it now appears Aluria is trying to cover their tracks? Isn't it wonderful the internet has such extensive resources that even when a company or individual tries to cover up something they did it is almost impossible to completely remove it. In previous articles written by CastleCops Staff on WhenU, Aluria and AOL there were many links going back to Aluria both to their support forums and press releases, imagine my suprise when the pages those links pointed to suddenly don't exist. In some cases the link isn't dead, rather it points to a new location eg. &lt;A href="http://updates.aluriasoftware.com/index.php?menu=press&amp;amp;submenu=news&amp;amp;link=Aluria_Certifies_WhenU" target=_blank&gt;Aluria_Certifies_WhenU&lt;/A&gt; That link should point to the original press release from Aluria, but it doesn't. All press related material are redirected to the same location in the same manner. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://castlecops.com/a6549-Aluria_Trys_To_Whitewash_The_WhenU_Fiasco.html"&gt;Full Story&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=85386" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>SpyFalcon, a nightmare rebranded</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/02/09/82953.aspx" /><id>/blogs/castlecops/archive/2006/02/09/82953.aspx</id><published>2006-02-09T03:24:00Z</published><updated>2006-02-09T03:24:00Z</updated><content type="html">&lt;P&gt;&lt;A href="http://castlecops.com/a6514-SpyFalcon_a_nightmare_rebranded.html"&gt;Full Source&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Last time we wrote about a rebrand of SpyAxe called &lt;A href="http://castlecops.com/article-6454-nested-0-0.html"&gt;SpywareStrike&lt;/A&gt;, this time we alert you to SpyFalcon courtesy of Sunbelt-Software. First, if you think you're infected, &lt;A href="http://wiki.castlecops.com/Malware_Removal:_SpyAxe_Removal"&gt;read our removal tutorial&lt;/A&gt; on the whole SpyAxe issue. And there is an interesting twist... the webhost provider is dishing out the WMF Exploit!&lt;BR&gt;&lt;BR&gt;This domain was &lt;A href="http://www.dnsstuff.com/tools/whois.ch?ip=spyfalcon.com&amp;amp;cache=off&amp;amp;email=on"&gt;registered&lt;/A&gt; on 16-Jan-2006 by David Taylor under the guise of SunShine Ltd. It uses the "ANTISPYDNS.BIZ" domain for its DNS traffic. The domain is hosted by &lt;A href="http://uptime.netcraft.com/up/graph?site=spyfalcon.com"&gt;NetcatHosting&lt;/A&gt; who owns its IP: 195.225.176.79. What is interesting even more about the netblock &lt;A href="http://uptime.netcraft.com/up/hosted?netname=NETCATHOST,195.225.176.0,195.225.179.255"&gt;is this&lt;/A&gt;... &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=82953" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Kama Sutra/Blackworm Timebomb</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/25/81792.aspx" /><id>/blogs/castlecops/archive/2006/01/25/81792.aspx</id><published>2006-01-25T05:20:00Z</published><updated>2006-01-25T05:20:00Z</updated><content type="html">&lt;DIV id=leftbar&gt;&lt;/DIV&gt;
&lt;DIV id=timage&gt;&lt;A href="http://castlecops.com/article-topic-16.html"&gt;&lt;IMG alt=Worms src="http://castlecops.com/images/topics/eworm.gif" border=0&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;FONT class=storycontent&gt;There is a new mass mailing worm that has been infecting many users. Going by some different names, its best known as the Blackworm or Kama Sutra. On February 3rd, this worm is scheduled to overwrite the following file types with bogus data:&lt;BR&gt;&lt;BR&gt;
&lt;LI&gt;*.DOC 
&lt;LI&gt;*.XLS 
&lt;LI&gt;*.MDE 
&lt;LI&gt;*.MDB 
&lt;LI&gt;*.PPT 
&lt;LI&gt;*.PPS 
&lt;LI&gt;*.RAR 
&lt;LI&gt;*.PDF 
&lt;LI&gt;*.PSD 
&lt;LI&gt;*.DMP 
&lt;LI&gt;*.ZIP&lt;BR&gt;&lt;BR&gt;Feb 3rd is just the beginning, because its scheduled to activate on the 3rd of every month. Once someone is infected, the worm visits a webpage at rcn.net to increment a counter. This counter theoretically displays the number of infections. As of the article, that counter states:&lt;BR&gt;&lt;BR&gt;&lt;IMG src="http://castlecops.com/zx/Paul/Count1.gif"&gt; 
&lt;P&gt;&lt;A href="http://castlecops.com/a6486-Kama_Sutra_Blackworm_Worm_Timebomb.html"&gt;Read here for full details.&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=81792" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Microsoft Security Bulletin MS06-001: Official WMF Patch</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/05/80388.aspx" /><id>/blogs/castlecops/archive/2006/01/05/80388.aspx</id><published>2006-01-05T20:43:00Z</published><updated>2006-01-05T20:43:00Z</updated><content type="html">&lt;A href="http://castlecops.com/a6450-Microsoft_Security_Bulletin_MS06_001_Official_WMF_Patch.html"&gt;Microsoft has just released&lt;/A&gt; its official patch for the &lt;A href="http://castlecops.com/a6445-WMF_Exploit_FAQ.html"&gt;WMF 0-Day&lt;/A&gt;. In the &lt;A href="http://www.microsoft.com/technet/security/Bulletin/ms06-001.mspx"&gt;Microsoft Security Bulletin MS06-001&lt;/A&gt;, Microsoft states in its executive summary: 
&lt;BLOCKQUOTE&gt;
&lt;HR&gt;
This update resolves a newly-discovered, public vulnerability. The vulnerability is documented in the "Vulnerability Details" section of this bulletin. &lt;BR&gt;&lt;BR&gt;&lt;B&gt;Note&lt;/B&gt; This vulnerability is currently being exploited and was previously discussed by Microsoft in Microsoft Security Advisory 912840. &lt;BR&gt;&lt;BR&gt;If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. &lt;BR&gt;&lt;BR&gt;We recommend that customers apply the update immediately. 
&lt;HR&gt;
&lt;/BLOCKQUOTE&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80388" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Congratulations to the newest MVPs</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/05/80340.aspx" /><id>/blogs/castlecops/archive/2006/01/05/80340.aspx</id><published>2006-01-05T03:35:00Z</published><updated>2006-01-05T03:35:00Z</updated><content type="html">&lt;P&gt;&lt;SPAN class=postbody&gt;Congratulations to all the newest Microsoft MVP for Windows-Security &lt;BR&gt;&lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-corrine.html"&gt;corrine&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-coyote.html"&gt;coyote&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-daveai.html"&gt;daveai&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-dvk01.html"&gt;dvk01&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-ikeb.html"&gt;ikeb&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-jacee.html"&gt;jacee&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-marianna.html"&gt;marianna&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-negster22.html"&gt;negster22&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-oldfrog.html"&gt;oldfrog&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-swandog46.html"&gt;swandog46&lt;/A&gt; &lt;BR&gt;&lt;IMG src="http://castlecops.com/modules/Forums/templates/Cops_1024/images/icon_mini_profile.gif" align=absMiddle&gt;&lt;A href="http://castlecops.com/userinfo-taz71498.html"&gt;taz71498&lt;/A&gt; &lt;BR&gt;&lt;BR&gt;Soon to be added to: &lt;A href="http://wiki.castlecops.com/Microsoft_MVP" target=_blank&gt;http://wiki.castlecops.com/Microsoft_MVP&lt;/A&gt; &lt;BR&gt;&lt;BR&gt;You all deserve it! &lt;IMG alt="Gold Cup" src="http://castlecops.com/modules/Forums/images/smiles/eclipsee_gold_cup.gif" border=0&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=postbody&gt;&lt;A href="http://castlecops.com/t143405-Congratulations_to_the_newest_MVPs.html"&gt;Source&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80340" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>WMF Exploit FAQ</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/05/80327.aspx" /><id>/blogs/castlecops/archive/2006/01/05/80327.aspx</id><published>2006-01-05T01:52:00Z</published><updated>2006-01-05T01:52:00Z</updated><content type="html">There is a lot of public information available right now on the WMF Exploit and workaround patches. This article will attempt to answer some basic questions surrounding the WMF Exploit and those patches, including why Microsoft is waiting to release their official patch on January 10th, and rumors of an early MS patch Internet leak.&lt;BR&gt;&lt;BR&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;B&gt;What is WMF?&lt;/B&gt;&lt;BR&gt;Microsoft defines WMF as the Windows Metafile, a 16 bit metafile image format contained both vector and bitmap data. &lt;BR&gt;&lt;BR&gt;
&lt;LI&gt;&lt;B&gt;What is the issue with WMF?&lt;/B&gt;&lt;BR&gt;The WMF image is a little different from other images, it can call external procedures -- one of which can execute code.&lt;BR&gt;&lt;BR&gt;
&lt;LI&gt;&lt;B&gt;How can I get the WMF Exploit?&lt;/B&gt;&lt;BR&gt;The answer to this varies right now, however, one thing is certain, you can get the exploit by visiting an infected web page. Others suggest it can arrive thru email attachments, instant messaging, Lotus Notes, the list goes on.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;A href="http://castlecops.com/a6445-WMF_Exploit_FAQ.html"&gt;Continued in full here.&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80327" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Hot off the press: WMF Vulnerability Checker</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/02/80152.aspx" /><id>/blogs/castlecops/archive/2006/01/02/80152.aspx</id><published>2006-01-02T06:22:00Z</published><updated>2006-01-02T06:22:00Z</updated><content type="html">&lt;DIV id=leftbar&gt;&lt;/DIV&gt;
&lt;DIV id=timage&gt;&lt;A href="http://castlecops.com/article-topic-33.html"&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;FONT class=storycontent&gt;As you've read in the &lt;A href="http://castlecops.com/a6437-HAZARDOUS_SECURITY_ALERT.html"&gt;security alert&lt;/A&gt; concerning the WMF exploit there are very limited tools to patch or catch an exploitable computer system. Ilfak Guilfanov, the author of the Windows WMF Hotfix, has written a WMF Vulnerability Checker. Please read &lt;A href="http://www.hexblog.com/2006/01/wmf_vulnerability_checker.html"&gt;Ilfak's instructions&lt;/A&gt; on using the WMF vulnerability checker. Although a word of caution is offered:&lt;BR&gt;&lt;BR&gt;&lt;B&gt;Do not use this check as a definite answer to the WMF vulnerability question. But if your system was vulnerable, it should be invulnerable after installing the hotfix and display the second dialog box. In other words you can use this checker as a means to verify that the hotfix is doing its job. One more word of caution: do not forget to reboot your computer after the installation. If you do not reboot it, the checker will tell you that the system is invulnerable while some systme processes will still be.&lt;/B&gt;&lt;BR&gt;&lt;BR&gt;&lt;A href="http://castlecops.com/modules.php?name=Downloads&amp;amp;d_op=getit&amp;amp;lid=495"&gt;Download&lt;/A&gt; - &lt;A href="http://castlecops.com/downloads-file-495-details-WMF_Vulnerability_Checker.html"&gt;View Details&lt;/A&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80152" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>HAZARDOUS SECURITY ALERT</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2006/01/02/80150.aspx" /><id>/blogs/castlecops/archive/2006/01/02/80150.aspx</id><published>2006-01-02T03:00:00Z</published><updated>2006-01-02T03:00:00Z</updated><content type="html">&lt;P&gt;&lt;SPAN class=gen&gt;There is a new danger floating around the Internet right now, a zero-day exploit taking advantage of the Windows Media Format (WMF). Its not limited to WMF files, it is taking the shape of images as well. This exploit is currently billed as the worst infection in history. It can hide rootkits, it can even hide itself.&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;This is not a joke&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;Many antivirus companies can not discover this malware at present. Microsoft is not responding fast enough. There is currently no known way to detect if your system has been infected. However, don't let this stop you from applying two specific workaround patches.&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;Read the following two articles and install the "Windows WMF Hotfix" followed by de-registering the file "shimgvw.dll". Then reboot. Now, wait with the rest of us for Microsoft and antivirus companies to officially patch this vulnerability and detect/clean it.&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;- &lt;A class=postlink href="http://castlecops.com/a6436-Newest_WMF_Exploit_Patch_Saves_the_Day.html" target=_blank&gt;Install the WMF Hotfix&lt;/A&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;/SPAN&gt;- &lt;A class=postlink href="http://castlecops.com/a6428-Vulnerability_in_Graphics_Rendering_Engine_Could_Allow_Remote_Code_Execution.html" target=_blank&gt;De-register the "shimgvw.dll" file&lt;/A&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80150" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Make lots of money within 45 days</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/12/29/79970.aspx" /><id>/blogs/castlecops/archive/2005/12/29/79970.aspx</id><published>2005-12-29T21:02:00Z</published><updated>2005-12-29T21:02:00Z</updated><content type="html">&lt;P&gt;Source: &lt;A href="http://castlecops.com/a6420-Make_lots_of_money_within_45_days.html"&gt;click here&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Merry Christmas, I get an email last night promising me I'd be making within 45 days $3500 to $5500 monthly. All I need to do is exactly as the email says. And I'll know &lt;B&gt;exactly&lt;/B&gt; what I'm getting into with no pre-enrollment stage fee. Signed, some guy named Robert Chin. Hey, I might be one of the lucky 200 people able to participate in this program after they ask me some private confidential information like how much the family household income is, how many children we have, what are social security numbers are, right on down to how much hair I have on my pinky toe. &lt;BR&gt;&lt;BR&gt;So lets take a look at this first snapshot which starts off the email under Outlook Express: &lt;BR&gt;&lt;BR&gt;&lt;/P&gt;&lt;A href="http://castlecops.com/modules.php?full=1&amp;amp;set_albumName=album02&amp;amp;id=robertchin1&amp;amp;op=modload&amp;amp;name=Gallery&amp;amp;file=index&amp;amp;include=view_photo.php" target=_blank&gt;&lt;IMG src="http://castlecops.com/albums/album02/robertchin1.sized.jpg" border=0&gt;&lt;/A&gt;&lt;BR&gt;&lt;I&gt;[click to enlarge]&lt;/I&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79970" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>So how did I get infected in the first place?</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/12/29/79968.aspx" /><id>/blogs/castlecops/archive/2005/12/29/79968.aspx</id><published>2005-12-29T20:58:00Z</published><updated>2005-12-29T20:58:00Z</updated><content type="html">Coming to the end of 2005 we've observed many folks get infected. Tony Klein &lt;A href="http://castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html"&gt;has written&lt;/A&gt; the de facto answer to the question:&lt;BR&gt;&lt;BR&gt;So how did I get infected in the first place? &lt;IMG src="http://castlecops.com/zx/Paul/hijackthis.gif" align=absMiddle&gt; &lt;BR&gt;&lt;BR&gt;Bullet number 1: &lt;B&gt;Watch what you download! &lt;/B&gt;&lt;BR&gt;"Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use."&lt;BR&gt;&lt;BR&gt;Bullet number 2: "2.) Go to IE &amp;gt; Tools &amp;gt; Windows Update &amp;gt; Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections. &lt;BR&gt;&lt;BR&gt;It's important to always keep current with the latest security fixes from Microsoft. Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers. " &lt;BR&gt;&lt;BR&gt;This is just a teaser. For the full text, visit &lt;A href="http://castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html"&gt;So how did I get infected in the first place?&lt;/A&gt;. Also be sure to check out our own &lt;A href="http://wiki.castlecops.com/MRP"&gt;Malware Removal and Prevention&lt;/A&gt; procedure. Learn how to distance yourself from malware.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79968" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>180Solutions/Zango brings you the 'best amizing racist videos on the web'</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/12/05/78148.aspx" /><id>/blogs/castlecops/archive/2005/12/05/78148.aspx</id><published>2005-12-06T01:04:00Z</published><updated>2005-12-06T01:04:00Z</updated><content type="html">We've all &lt;A href="http://news.zdnet.com/2100-9588_22-5979179.html"&gt;read about&lt;/A&gt; the lawsuit 180Solutions/Zango has filed against Zone Labs by calling its software out on the mat as malware. But did you know that 180Solutions, that same company who makes Zango, has created a distribution system where they deliver the &lt;B&gt;'best amizing racist videos on the web'&lt;/B&gt;? The advertisement says simply to "Download Zango and enjoy FREE unlimited access to amizing racist videos".&lt;BR&gt;&lt;BR&gt;For details and snapshots, &lt;A href="http://castlecops.com/p672607-180Problems_Suing_ZoneLabs.html#672607"&gt;visit here&lt;/A&gt;. It includes more information about one of Zango's distribution partners which even publicly displays who has visited the site by showing unique visitor statistics. 180 Solutions... put a foot in it. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=78148" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author><category term="Spyware" scheme="http://msmvps.com/blogs/castlecops/archive/tags/Spyware/default.aspx" /></entry><entry><title>Happy thanksgiving</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/11/23/76554.aspx" /><id>/blogs/castlecops/archive/2005/11/23/76554.aspx</id><published>2005-11-24T02:08:00Z</published><updated>2005-11-24T02:08:00Z</updated><content type="html">Happy thanksgiving to everyone, enjoy, and be safe.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=76554" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>CastleCops ramps up fight against CoolWebSearch/HomeSearch</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/09/14/66422.aspx" /><id>/blogs/castlecops/archive/2005/09/14/66422.aspx</id><published>2005-09-14T21:48:00Z</published><updated>2005-09-14T21:48:00Z</updated><content type="html">&lt;A href="http://castlecops.com/a6249-CastleCops_ramps_up_fight_against_CoolWebSearch_HomeSearch.html"&gt;CastleCops&lt;/A&gt; keeps and maintains various databases on malware and legitimate items for browser helpers objects, toolbars, startups, services, and activex objects. &lt;BR&gt;&lt;BR&gt;Thanks to the collaboration of many Team CastleCops Expert members, CC is frequently among the first to indentify and analyze a new emerging pest, and hence to add information on its components to the various Lists. We were for example the first to spot and categorize a new BHO co-responsible for an all new version of SpySheriff/PsGuard/SmitFraud, one of the most insidious and prevalent pests around: &lt;BR&gt;&lt;BR&gt;&lt;A href="http://castlecops.com/tk6387-hp_tmp_random_char_or_digit.html"&gt;/tk6387-hp_tmp_random_char_or_digit.html&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;CastleCops is also in progress of entering all BHOs pertaining to the notorious CoolWebSearch/HomeSearch parasite variant to its CLSID database list. That information is used to power publicly accessible applications such as (in addition to researcher based utilities): &lt;BR&gt;&lt;BR&gt;&lt;A href="http://www.definitivesolutions.com/bhodemon.htm"&gt;BHODemon&lt;/A&gt;&lt;BR&gt;&lt;A href="http://merijn.org/downloads.html"&gt;BHOList&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;The BHO database in its entirety is made available to the public here: &lt;BR&gt;&lt;BR&gt;&lt;A href="http://castlecops.com/CLSID.html"&gt;/CLSID.html&lt;/A&gt;&lt;!--
&lt;rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/"&gt;
&lt;rdf:Description
  rdf:about="http://castlecops.com/articlei.html"
  dc:identifier="http://castlecops.com/articlei.html"
  dc:title="CastleCops ramps up fight against CoolWebSearch/HomeSearch"
  trackback:ping="http://castlecops.com/tb/News/i" /&gt;
&lt;/rdf:RDF&gt;
--&gt; &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=66422" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author><category term="Spyware" scheme="http://msmvps.com/blogs/castlecops/archive/tags/Spyware/default.aspx" /></entry><entry><title>[NewAngels Advisory #7]PHP Nuke &lt;= 7.8 Multiple SQL Injections</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/09/14/66352.aspx" /><id>/blogs/castlecops/archive/2005/09/14/66352.aspx</id><published>2005-09-14T05:51:00Z</published><updated>2005-09-14T05:51:00Z</updated><content type="html">&lt;P&gt;&lt;FONT face=Arial color=#000000&gt;So there is this advisory which is &lt;/FONT&gt;&lt;A href="http://securityfocus.com/archive/1/410314/30/0/threaded"&gt;&lt;FONT face=Arial color=#0000ff&gt;released&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial color=#000000&gt;:&lt;/FONT&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;[NewAngels Advisory #7]PHP Nuke &amp;lt;= 7.8 Multiple SQL Injections&lt;BR&gt;========================================================================&lt;BR&gt;=====&lt;BR&gt;&lt;BR&gt;Software: PHP Nuke 7.8&lt;BR&gt;Type: SQL Injections&lt;BR&gt;Risk: High&lt;BR&gt;&lt;BR&gt;Date: Sep. 10 2005&lt;BR&gt;Vendor: PHP-Nuke (phpnuke.org)&lt;BR&gt;&lt;BR&gt;Credit:&lt;BR&gt;=======&lt;BR&gt;Robin 'onkel_fisch' Verton from it-security23.net&lt;BR&gt;&lt;BR&gt;Description:&lt;BR&gt;============&lt;BR&gt;PHP-Nuke is a news automated system specially designed to be used in Intranets and Internet.&lt;BR&gt;The Administrator has total control of his web site, registered users, and he will have in the hand&lt;BR&gt;a powerful assembly of tools to maintain an active and 100% interactive web site using databases.&lt;BR&gt;[http://www.phpnuke.org/]&lt;BR&gt;&lt;BR&gt;Vulnerability:&lt;BR&gt;==============&lt;BR&gt;&lt;BR&gt;PHP Nuke 7.8 is prone to multiple SQL injection vulnerabilities.&lt;BR&gt;These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.&lt;BR&gt;&lt;BR&gt;In the modules.php&lt;BR&gt;&lt;BR&gt;$result = $db-&amp;gt;sql_query("SELECT active, view FROM ".$prefix."_modules WHERE title='$name'");&lt;BR&gt;&lt;BR&gt;The $name variable is not checked so you could inject malicious SQL Code. In an file which is included whe have the following code:&lt;BR&gt;&lt;BR&gt;$queryString = strtolower($_SERVER['QUERY_STRING']);&lt;BR&gt;if (stripos_clone($queryString,'%20union%20') OR stripos_clone($queryString,'/*') OR stripos_clone($queryString,'*/union/*') OR stripos_clone($queryString,'c2nyaxb0')) {&lt;BR&gt;header("Location: index.php");&lt;BR&gt;die();&lt;BR&gt;}&lt;BR&gt;&lt;BR&gt;[...]&lt;BR&gt;&lt;BR&gt;if (!ini_get("register_globals")) {&lt;BR&gt;import_request_variables('GPC');&lt;BR&gt;}&lt;BR&gt;&lt;BR&gt;So you can use UNION in a GET var. But because they use register_globals or impor_request_variables you can send&lt;BR&gt;the malicous SQL-Code via POST so it is not checked if you insert an "union".&lt;BR&gt;&lt;BR&gt;http://www.example.com/modules.php POST: name=' OR 1=1/*&lt;BR&gt;will produce an error, neither&lt;BR&gt;http://www.example.com/modules.php POST: name=' OR 1=2/*&lt;BR&gt;will only tell you taht the requestet 'modul' is not active, so you can read out the admin password hahs via blind injections.&lt;BR&gt;&lt;BR&gt;Additionaly there are a few SQL-Injections in the modules.&lt;BR&gt;Here a few examples:&lt;BR&gt;&lt;BR&gt;http://www.example.com/modules.php?name=News&amp;amp;file=article&amp;amp;sid=[SQL] - here the same as above, send this via POST to&lt;BR&gt;bypass the 'union'-cover&lt;BR&gt;&lt;BR&gt;http://www.example.com/modules.php?name=News&amp;amp;file=comments&amp;amp;Reply&amp;amp;pid=[SQ&lt;BR&gt;L]&lt;BR&gt;&lt;BR&gt;http://www.example.com/modules.php?name=News&amp;amp;file=comments&amp;amp;op=Reply&amp;amp;pid=&lt;BR&gt;[SQL]&lt;BR&gt;&lt;BR&gt;http://www.example.com/modules.php?name=News&amp;amp;file=comments&amp;amp;op=Reply&amp;amp;sid=&lt;BR&gt;[SQL]&lt;BR&gt;&lt;BR&gt;Greets:&lt;BR&gt;==============&lt;BR&gt;CyberDead, atomic, sirius_&lt;BR&gt;Whole secured-pussy.de Team&lt;BR&gt;Zealots :D :D&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Arial color=#000000&gt;Of course I'm not thrilled so I just had to reply:&lt;/FONT&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;The $name variable and others like $sid are expected via $_GET and not&lt;BR&gt;$_POST.&amp;nbsp; The proper start to sanitizing the data here is to ensure that&lt;BR&gt;$name is obtained via $_GET and not injected by $_POST, $_COOKIE, or&lt;BR&gt;anything else.&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;Since you did two things I'm avidly against:&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;1) no vendor contact information&lt;BR&gt;2) no suggested patches&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;I wanted to reply and alert folks who run PHP-Nuke and its forks since&lt;BR&gt;after running a cursory search on some popular PHP-Nuke sites I saw&lt;BR&gt;nothing about this:&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;A href="http://en.wikipedia.org/wiki/Php-nuke"&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;http://en.wikipedia.org/wiki/Php-nuke&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;About the above suggestion.&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;To be specific, find the modules.php file and check for the first instance&lt;BR&gt;of "$name".&amp;nbsp; An example:&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#800080 size=2&gt;if (isset($name)) {&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;Prior to that, simply put in such a line:&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#800080 size=2&gt;$name = $_GET['name'];&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face="Courier New" color=#808080 size=2&gt;You're forcing the $name variable to be set by the HTTP GET request,&lt;BR&gt;rather than inject a value by a cookie or post ($_COOKIE, $_POST&lt;BR&gt;respectively).&lt;BR&gt;&lt;BR&gt;The same applies to the rest of the code for other variables.&lt;/FONT&gt;&lt;BR&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=66352" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author><category term="Advisories" scheme="http://msmvps.com/blogs/castlecops/archive/tags/Advisories/default.aspx" /></entry><entry><title>EULAlyzer 1.0 Released - Analyze License Agreements!</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/09/13/66326.aspx" /><id>/blogs/castlecops/archive/2005/09/13/66326.aspx</id><published>2005-09-13T21:54:00Z</published><updated>2005-09-13T21:54:00Z</updated><content type="html">&lt;DIV id=leftbar&gt;&lt;/DIV&gt;
&lt;DIV id=timage&gt;&lt;A href="http://castlecops.com/article-topic-2.html"&gt;&lt;IMG alt="General News" src="http://castlecops.com/images/topics/eye.gif" border=0&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;FONT class=storycontent&gt;&lt;A href="http://castlecops.com/userinfo-Javacool.html"&gt;Javacool&lt;/A&gt; &lt;A href="http://castlecops.com/a6244-EULAlyzer_1_0_Released_Analyze_License_Agreements.html"&gt;writes&lt;/A&gt; &lt;I&gt;"&lt;B&gt;EULAlyzer 1.0 Released!&lt;/B&gt;&lt;BR&gt;&lt;BR&gt;Analyze license agreements for interesting words and phrases!&lt;BR&gt;&lt;BR&gt;End user license agreements (EULAs) are the bane of most computer users. No one wants to read through pages and pages of boring text, and many people skip reading them altogether. But it can be dangerous not to read license agreements - you might miss important information about software or bundled components, plus you have no idea what you could be agreeing to.&lt;BR&gt;&lt;BR&gt;But now there's a way of making that much easier.&lt;BR&gt;&lt;BR&gt;&lt;B&gt;EULAlyzer - Making it all easy!&lt;/B&gt;&lt;BR&gt;&lt;BR&gt;EULAlyzer can analyze license agreements in seconds, and provide a detailed listing of potentially interesting words and phrases. Discover if the software you're about to install displays pop-up ads, transmits personally identifiable information, uses unique identifiers to track you, or much much more.&lt;BR&gt;&lt;BR&gt;The Benefits:&lt;BR&gt;
&lt;LI&gt;Discover potentially hidden behavior about the software you're going to install&lt;BR&gt;
&lt;LI&gt;Pick up on things you missed when reading license agreements&lt;BR&gt;
&lt;LI&gt;Keep a saved database of the license agreements you view&lt;BR&gt;
&lt;LI&gt;Instant results - super-fast analysis in just a second&lt;BR&gt;&lt;BR&gt;&lt;B&gt;When installing software, never just click past the license agreement. Pop it into EULAlyzer, and EULAlyze it!&lt;/B&gt;&lt;BR&gt;&lt;BR&gt;EULAlyzer Personal is free for personal and educational use.&lt;BR&gt;&lt;BR&gt;&lt;B&gt;More information and download: &lt;A href="http://www.javacoolsoftware.com/eulalyzer.html"&gt;http://www.javacoolsoftware.com/eulalyzer.html&lt;/A&gt;&lt;/B&gt;&lt;BR&gt;&lt;BR&gt;P.S. Want active, automatic protection? Help support the development of this program, and check out &lt;A href="http://www.javacoolsoftware.com/eulalyzerpro.html"&gt;EULAlyzer Pro&lt;/A&gt;!&lt;!--
&lt;rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/"&gt;
&lt;rdf:Description
  rdf:about="http://castlecops.com/articled.html"
  dc:identifier="http://castlecops.com/articled.html"
  dc:title="EULAlyzer 1.0 Released - Analyze License Agreements!"
  trackback:ping="http://castlecops.com/tb/News/d" /&gt;
&lt;/rdf:RDF&gt;
--&gt; "&lt;/I&gt; &lt;/FONT&gt;&lt;/LI&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=66326" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>KPF: End of Life December 31st 2005</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/09/06/65605.aspx" /><id>/blogs/castlecops/archive/2005/09/06/65605.aspx</id><published>2005-09-06T21:39:00Z</published><updated>2005-09-06T21:39:00Z</updated><content type="html">&lt;A href="http://forums.kerio.com/index.php?t=msg&amp;amp;th=7040"&gt;Joshua Thomas&lt;/A&gt; from Kerio has announced that Kerio Personal Firewall will reach end of life. 
&lt;BLOCKQUOTE&gt;&lt;EM&gt;Hello all, &lt;BR&gt;&lt;BR&gt;Kerio Technologies has grown into a significant player in both security and messaging markets. We have achieved many accolades, and we have many satisfied customers all over the world. &lt;BR&gt;&lt;BR&gt;Kerio now employs over one hundred people in our three offices worldwide. We want to continue to deliver products that you enjoy to use. We made a promise to give our customers the best products in their category. And that means implementing some changes in our product strategy. &lt;BR&gt;&lt;BR&gt;During the second half of this year, Kerio will be discontinuing two host-based security products from our portfolio &amp;#8211; Kerio ServerFirewall and Kerio Personal Firewall. &lt;/EM&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;EM&gt;Kerio Personal Firewall will be discontinued as of December 31, 2005. It will not be available for purchase after this date. Subscriptions will not be renewed. Technical support will be provided to all customers with valid subscriptions until the end of 2006. &lt;BR&gt;&lt;BR&gt;Thank you for your support of Kerio. &lt;BR&gt;&lt;BR&gt;Cheers,&lt;BR&gt;Joshua Thomas&lt;/EM&gt;&lt;/BLOCKQUOTE&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=65605" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author></entry><entry><title>Microsoft Security Newsletter - Volume 2, Issue 8</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/08/13/62587.aspx" /><id>/blogs/castlecops/archive/2005/08/13/62587.aspx</id><published>2005-08-13T18:39:00Z</published><updated>2005-08-13T18:39:00Z</updated><content type="html">&lt;P&gt;In &lt;A href="http://www.microsoft.com/technet/security/secnews/newsletter.htm"&gt;this month's&lt;/A&gt; MS security newsletter, I happened to be chosen for MVP of the month:&lt;/P&gt;
&lt;DIV style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; FONT-SIZE: 11px; PADDING-BOTTOM: 1em; LINE-HEIGHT: 140%; PADDING-TOP: 0px; FONT-FAMILY: Verdana, Arial, Helvetica, sans-serif"&gt;
&lt;HR style="COLOR: #cccccc; HEIGHT: 1px"&gt;
&lt;/DIV&gt;&lt;A name=XSLTComponent125123122122122126120120&gt;&lt;/A&gt;
&lt;DIV style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; FONT-WEIGHT: bold; FONT-SIZE: 15px; PADDING-BOTTOM: 12px; PADDING-TOP: 0px; FONT-FAMILY: Verdana, Arial, Helvetica, sans-serif"&gt;MVP Update&lt;/DIV&gt;
&lt;DIV style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; FONT-SIZE: 11px; PADDING-BOTTOM: 1em; LINE-HEIGHT: 140%; PADDING-TOP: 0px; FONT-FAMILY: Verdana, Arial, Helvetica, sans-serif"&gt;
&lt;TABLE cellSpacing=0 cellPadding=0 align=left border=0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;IMG height=100 alt="Paul Laudanski" src="http://www.microsoft.com/technet/images/security/secnews/PaulLaudanski.gif" width=78 border=0&gt; &lt;/TD&gt;
&lt;TD style="WIDTH: 15px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;B&gt;MVP of the Month: Paul Laudanski - Windows Security&lt;/B&gt; &lt;BR&gt;Paul Laudanski, a.k.a. Zhen-Xjell, has been a techno-geek since the 1970s. Laudanski's first genuine computer experience was with the Commodore-64 and a 300 Baud modem running a 24/7 colored ASCII BBS. In the 1980s he became involved in DOS and Windows. During the 1990s he obtained a Bachelor's degree in pure Mathematics and expanded his reach into PCBoard, Centipede, Ygdrasil, Fidonet, Unix, and Linux. These days Laudanski loves to hang out at CastleCops.com (which he founded in 2002), as well as other security-related lists and Web sites. His passions include programming, system hardening, security, and privacy. Paul and his wife (who is also a Microsoft MVP in Windows Security and wrote the MVP Article of the Month below) are proud parents of their first son.&lt;/DIV&gt;
&lt;DIV style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; FONT-SIZE: 11px; PADDING-BOTTOM: 1em; LINE-HEIGHT: 140%; PADDING-TOP: 0px; FONT-FAMILY: Verdana, Arial, Helvetica, sans-serif"&gt;&lt;A href="http://mvp.support.microsoft.com/"&gt;Get more information about the MVP program here&lt;/A&gt;.&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=62587" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author><category term="Dazed" scheme="http://msmvps.com/blogs/castlecops/archive/tags/Dazed/default.aspx" /></entry><entry><title>Microsoft Security Bulletin Summary for August 2005</title><link rel="alternate" type="text/html" href="/blogs/castlecops/archive/2005/08/10/62259.aspx" /><id>/blogs/castlecops/archive/2005/08/10/62259.aspx</id><published>2005-08-10T05:27:00Z</published><updated>2005-08-10T05:27:00Z</updated><content type="html">&lt;DIV id=leftbar&gt;&lt;/DIV&gt;
&lt;DIV id=timage&gt;&lt;A href="http://www.castlecops.com/article-topic-3.html"&gt;&lt;IMG alt=Microsoft src="http://www.castlecops.com/images/topics/msmulti.gif" border=0&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;FONT class=storycontent&gt;MS05-038 - Cumulative Security Update for Internet Explorer (896727) &lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows 2000 Service Pack 4&lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows XP Professional x64 Edition&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 Service Pack 1&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 with SP1 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 x64 Edition &lt;BR&gt;&lt;BR&gt;- Review the FAQ section of bulletin MS05-O38 for information about these operating systems:&lt;BR&gt;- Windows 98&lt;BR&gt;- Windows 98 Second Edition (SE)&lt;BR&gt;- Windows Millennium Edition (ME)&lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;MS05-039 - Vulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588) &lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows 2000 Service Pack 4&lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows XP Professional x64 Edition&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 Service Pack 1&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 with SP1 for Itanium-based Systems&lt;BR&gt;- Windows Server 2003 x64 Edition &lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;MS05-043 - Vulnerability in Print Spooler Service Could Allow Remote Code Execution (896423)&lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows 2000 Service Pack 4&lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;Important Security Bulletins&lt;BR&gt;============================&lt;BR&gt;MS05-040 - Vulnerability in Telephony Service Could Allow Remote Code Execution (893756) &lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows 2000 Service Pack 4&lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows XP Professional x64 Edition&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 Service Pack 1&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 with SP1 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 x64 Edition &lt;BR&gt;&lt;BR&gt;- Review the FAQ section of bulletin MS05-O38 for information about these operating systems:&lt;BR&gt;- Windows 98&lt;BR&gt;- Windows 98 Second Edition (SE)&lt;BR&gt;- Windows Millennium Edition (ME)&lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;Moderate Security Bulletins&lt;BR&gt;===========================&lt;BR&gt;MS05-041 - Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (899591) &lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows XP Professional x64 Edition&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 Service Pack 1&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 with SP1 for Itanium-based Systems&lt;BR&gt;- Windows Server 2003 x64 Edition &lt;BR&gt;&lt;BR&gt;- Impact: Denial of Service&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;MS05-042 - Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587) &lt;BR&gt;&lt;BR&gt;- Affected Software: &lt;BR&gt;- Windows 2000 Service Pack 4&lt;BR&gt;- Windows XP Service Pack 1&lt;BR&gt;- Windows XP Service Pack 2&lt;BR&gt;- Windows XP Professional x64 Edition&lt;BR&gt;- Windows Server 2003&lt;BR&gt;- Windows Server 2003 Service Pack 1&lt;BR&gt;- Windows Server 2003 for Itanium-based Systems &lt;BR&gt;- Windows Server 2003 with SP1 for Itanium-based Systems&lt;BR&gt;- Windows Server 2003 x64 Edition &lt;BR&gt;&lt;BR&gt;- Impact: Remote Code Execution&lt;BR&gt;- Version Number: 1.0 &lt;BR&gt;&lt;BR&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=51160"&gt;Source&lt;/A&gt;&lt;!--
&lt;rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/"&gt;
&lt;rdf:Description
  rdf:about="http://castlecops.com/article.html"
  dc:identifier="http://castlecops.com/article.html"
  dc:title="Microsoft Security Bulletin Summary for August 2005"
  trackback:ping="http://castlecops.com/tb/News/" /&gt;
&lt;/rdf:RDF&gt;
--&gt; &lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=62259" width="1" height="1"&gt;</content><author><name>paul</name><uri>http://msmvps.com/members/paul/default.aspx</uri></author><category term="Advisories" scheme="http://msmvps.com/blogs/castlecops/archive/tags/Advisories/default.aspx" /></entry></feed>