<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Harry Waldron - Microsoft MVP Blog</title><subtitle type="html">Security News and Best Practices for corporate and home users</subtitle><id>http://msmvps.com/blogs/harrywaldron/atom.aspx</id><link rel="alternate" type="text/html" href="http://msmvps.com/blogs/harrywaldron/default.aspx" /><link rel="self" type="application/atom+xml" href="http://msmvps.com/blogs/harrywaldron/atom.aspx" /><generator uri="http://communityserver.org" version="4.0.30619.63">Community Server</generator><updated>2008-06-22T02:50:00Z</updated><entry><title>New DSN Exploits are being developed - Patch your servers now</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/24/new-dsn-exploits-are-being-developed-patch-your-servers-now.aspx" /><id>/blogs/harrywaldron/archive/2008/07/24/new-dsn-exploits-are-being-developed-patch-your-servers-now.aspx</id><published>2008-07-24T08:15:00Z</published><updated>2008-07-24T08:15:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;b&gt;&lt;span style="color:#008000;"&gt;Below are resources for corporate users related to the developments associated with the new DNS vulnerabilities. &lt;/span&gt;&lt;/b&gt;The CERT advisory has an excellent list of vendors and their current status for this issue. It is important to apply applicable security patches for DNS servers as quickly as possible due to active exploit development. &lt;br /&gt;&lt;br /&gt;So far, two versions of exploit code have been developed for this vulnerability. While the first exploit affects DNS caching, security researcher, H.D. Moore has developed &lt;b&gt;&lt;span style="color:#ff0000;"&gt;a more potent second exploit that can replace nameserver entries with the potential to redirect traffice to malicious sites &lt;/span&gt;&lt;/b&gt;(e.g., malware downloading, phishing attacks, etc).&lt;br /&gt;&lt;br /&gt;In some ways, this new security exposure is reminiscent of the Code Red&amp;nbsp;Worm and Blaster attacks during the earlier part of this decade. While security patches were available, many companies did not have the time or insight to patch all of their potential exposures. While there&amp;#39;s time, &lt;b&gt;&lt;span style="color:#008000;"&gt;security administrators should PATCH NOW&lt;/span&gt;&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#800000;"&gt;&lt;b&gt;ARTICLES: Major DNS vulnerability now public&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cwflyris.computerworld.com/t/3374560/1676699/127883/2/"&gt;http://cwflyris.computerworld.com/t/3374560/1676699/127883/2/&lt;/a&gt; &lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=4765"&gt;http://isc.sans.org/diary.html?storyid=4765&lt;/a&gt; &lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447&lt;/a&gt; &lt;br /&gt;&lt;a href="http://cwflyris.computerworld.com/t/3374560/1676699/127883/2/"&gt;http://cwflyris.computerworld.com/t/3374560/1676699/127883/2/&lt;/a&gt; &lt;br /&gt;&lt;a href="http://blog.trendmicro.com/major-dns-cache-poisoning-vulnerability-patch-now/"&gt;http://blog.trendmicro.com/major-dns-cache-poisoning-vulnerability-patch-now/&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.informationweek.com/news/internet/security/showArticle.jhtml?articleID=209401195"&gt;http://www.informationweek.com/news/internet/security/showArticle.jhtml?articleID=209401195&lt;/a&gt; &lt;br /&gt;&lt;a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html"&gt;http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE:&lt;/b&gt; &lt;b&gt;&lt;span style="color:#ff0000;"&gt;&amp;quot;Patch. Today. Now. Yes, stay late.&amp;quot;&lt;/span&gt; &lt;/b&gt;- That&amp;#39;s the word from security researcher Dan Kaminsky, who recently presided over an unprecedented effort to coordinate a fix for a DNS vulnerability across more than 80 software and hardware vendors&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="color:#ff0000;"&gt;Several hackers are almost certainly already developing attack code for the bug,&lt;/span&gt;&lt;/b&gt; and it will most likely crop up within the next few days, said Dave Aitel, chief technology officer at security vendor Immunity Inc. His company will eventually develop sample code for its Canvas security testing software too, a task he expects to take about a day, given the simplicity of the attack. &amp;quot;It&amp;#39;s not that hard,&amp;quot; he said. &amp;quot;You&amp;#39;re not looking at a DNA-cracking effort.&amp;quot; &lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;b&gt;The attack can be used to redirect victims to malicious servers on the Internet by targeting the DNS servers that serve as signposts for all of the Internet&amp;#39;s traffic. &lt;/b&gt;&lt;/span&gt;By tricking an ISP&amp;#39;s servers into accepting bad information, attackers could redirect that company&amp;#39;s customers to malicious Web sites without their knowledge. &lt;br /&gt;&lt;br /&gt;Although a software fix is now available for most users of DNS software, it can take time for these updates to work their way through the testing process and actually get installed on the network. &amp;quot;Most people have not patched yet,&amp;quot; Vixie said. &amp;quot;That&amp;#39;s a gigantic problem for the world.&amp;quot; &lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff0000;"&gt;&lt;b&gt;EXPLOIT DEVELOPMENTS: Second more critical exploit in the wild&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html"&gt;http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE: &lt;span style="color:#ff0000;"&gt;We just added a second exploit which replaces the nameservers of the target domain. &lt;/span&gt;&lt;/b&gt;This is the bug people should actually care about, since it doesn&amp;#39;t matter if anything is already cached. Regarding the cache situation (of the first exploit) -- it&amp;#39;s not possible to do cache overwrites, but &lt;b&gt;&lt;span style="color:#ff0000;"&gt;it is possibe to look up the cache timeout, wait for it, and then replace it. &lt;/span&gt;&lt;/b&gt;With the new exploit module, we just change the DNS server for the entire domain (regardless of what is cached), so it&amp;#39;s much more effective for wide-scale hijacking.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="color:#800000;"&gt;Microsoft DNS Patch should be applied ASAP&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="color:#800000;"&gt;&lt;b&gt;CERT Advisory - Provides a detailed status report by vendor &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.kb.cert.org/vuls/id/800113"&gt;http://www.kb.cert.org/vuls/id/800113&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-size:medium;color:#800000;font-family:Courier New;"&gt;Vendor Status - Date Last Updated (see CERT advisory above for more recent updates) &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="color:#008000;font-family:Courier New;"&gt;3com, Inc. Unknown 10-Jul-2008 &lt;br /&gt;Alcatel-Lucent Unknown 23-Jul-2008 &lt;br /&gt;Apple Computer, Inc. Unknown 5-May-2008 &lt;br /&gt;AT&amp;amp;T Unknown 21-Apr-2008 &lt;br /&gt;Avaya, Inc. Vulnerable 16-Jul-2008 &lt;br /&gt;Avici Systems, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Belkin, Inc. Unknown 13-Jul-2008 &lt;br /&gt;Blue Coat Systems Vulnerable 22-Jul-2008 &lt;br /&gt;BlueCat Networks, Inc. Vulnerable 22-Jul-2008 &lt;br /&gt;Check Point Software Technologies Not Vulnerable 23-Jul-2008 &lt;br /&gt;Cisco Systems, Inc. Vulnerable 10-Jul-2008 &lt;br /&gt;Conectiva Inc. Unknown 5-May-2008 &lt;br /&gt;Cray Inc. Unknown 5-May-2008 &lt;br /&gt;D-Link Systems, Inc. Unknown 2-May-2008 &lt;br /&gt;Data Connection, Ltd. Unknown 21-Apr-2008 &lt;br /&gt;Debian GNU/Linux Vulnerable 9-Jul-2008 &lt;br /&gt;djbdns Not Vulnerable 10-Jul-2008 &lt;br /&gt;dnsmasq Vulnerable 11-Jul-2008 &lt;br /&gt;DragonFly BSD Project Unknown 3-Jul-2008 &lt;br /&gt;EMC Corporation Unknown 21-Apr-2008 &lt;br /&gt;Engarde Secure Linux Unknown 5-May-2008 &lt;br /&gt;Ericsson Unknown 21-Apr-2008 &lt;br /&gt;Extreme Networks Unknown 21-Apr-2008 &lt;br /&gt;F5 Networks, Inc. Vulnerable 14-Jul-2008 &lt;br /&gt;Fedora Project Unknown 5-May-2008 &lt;br /&gt;Force10 Networks, Inc. Not Vulnerable 11-Jul-2008 &lt;br /&gt;Foundry Networks, Inc. Not Vulnerable 10-Jul-2008 &lt;br /&gt;FreeBSD, Inc. Vulnerable 14-Jul-2008 &lt;br /&gt;Fujitsu Vulnerable 18-Jul-2008 &lt;br /&gt;Gentoo Linux Vulnerable 12-Jul-2008 &lt;br /&gt;Gnu ADNS Unknown 5-May-2008 &lt;br /&gt;GNU glibc Unknown 5-May-2008 &lt;br /&gt;Hewlett-Packard Company Vulnerable 16-Jul-2008 &lt;br /&gt;Hitachi Unknown 21-Apr-2008 &lt;br /&gt;Honeywell Unknown 21-Apr-2008 &lt;br /&gt;IBM Corporation Vulnerable 12-Jul-2008 &lt;br /&gt;IBM Corporation (zseries) Unknown 5-May-2008 &lt;br /&gt;IBM eServer Unknown 21-Apr-2008 &lt;br /&gt;Infoblox Vulnerable 21-Jul-2008 &lt;br /&gt;Ingrian Networks, Inc. Unknown 5-May-2008 &lt;br /&gt;Intel Corporation Unknown 21-Apr-2008 &lt;br /&gt;Internet Systems Consortium Vulnerable 14-Jul-2008 &lt;br /&gt;JH Software Not Vulnerable 10-Jul-2008 &lt;br /&gt;Juniper Networks, Inc. Vulnerable 10-Jul-2008 &lt;br /&gt;Linux Kernel Archives Unknown 3-Jun-2008 &lt;br /&gt;Lucent Technologies Unknown 21-Apr-2008 &lt;br /&gt;Luminous Networks Unknown 21-Apr-2008 &lt;br /&gt;Mandriva, Inc. Vulnerable 22-Jul-2008 &lt;br /&gt;MaraDNS Not Vulnerable 10-Jul-2008 &lt;br /&gt;Men &amp;amp; Mice Unknown 5-May-2008 &lt;br /&gt;Metasolv Software, Inc. Unknown 5-May-2008 &lt;br /&gt;Microsoft Corporation Vulnerable 8-Jul-2008 &lt;br /&gt;MontaVista Software, Inc. Unknown 5-May-2008 &lt;br /&gt;Motorola, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Multinet (owned Process Software Corporation) Unknown 21-Apr-2008 &lt;br /&gt;Multitech, Inc. Unknown 21-Apr-2008 &lt;br /&gt;NEC Corporation Not Vulnerable 18-Jul-2008 &lt;br /&gt;NetApp Unknown 3-Jul-2008 &lt;br /&gt;NetBSD Unknown 5-May-2008 &lt;br /&gt;Netgear, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Network Appliance, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Nixu Vulnerable 9-Jul-2008 &lt;br /&gt;NLnet Labs Not Vulnerable 10-Jul-2008 &lt;br /&gt;Nokia Unknown 21-Apr-2008 &lt;br /&gt;Nominum Vulnerable 10-Jul-2008 &lt;br /&gt;Nortel Networks, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Novell, Inc. Vulnerable 14-Jul-2008 &lt;br /&gt;OpenBSD Vulnerable 24-Jul-2008 &lt;br /&gt;OpenDNS Not Vulnerable 10-Jul-2008 &lt;br /&gt;Openwall GNU/*/Linux Vulnerable 17-Jul-2008 &lt;br /&gt;PePLink Not Vulnerable 10-Jul-2008 &lt;br /&gt;Posadis project Unknown 14-Jul-2008 &lt;br /&gt;PowerDNS Not Vulnerable 10-Jul-2008 &lt;br /&gt;QNX, Software Systems, Inc. Unknown 5-May-2008 &lt;br /&gt;Red Hat, Inc. Vulnerable 10-Jul-2008 &lt;br /&gt;Redback Networks, Inc. Unknown 21-Apr-2008 &lt;br /&gt;Secure Computing Network Security Division Vulnerable 17-Jul-2008 &lt;br /&gt;Shadowsupport Unknown 5-May-2008 &lt;br /&gt;Siemens Unknown 8-Jul-2008 &lt;br /&gt;Silicon Graphics, Inc. Unknown 5-May-2008 &lt;br /&gt;Slackware Linux Inc. Vulnerable 12-Jul-2008 &lt;br /&gt;Sony Corporation Unknown 21-Apr-2008 &lt;br /&gt;Sun Microsystems, Inc. Vulnerable 10-Jul-2008 &lt;br /&gt;SUSE Linux Vulnerable 11-Jul-2008 &lt;br /&gt;The SCO Group Unknown 5-May-2008 &lt;br /&gt;Trustix Secure Linux Unknown 5-May-2008 &lt;br /&gt;Turbolinux Unknown 5-May-2008 &lt;br /&gt;Ubuntu Vulnerable 10-Jul-2008 &lt;br /&gt;Wind River Systems, Inc. Vulnerable 9-Jul-2008 &lt;br /&gt;ZyXEL Unknown 21-Apr-2008 &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642009" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Email threat - Avoid free Windows Malicious Software Removal Tool  </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/18/email-threat-avoid-free-windows-malicious-software-removal-tool.aspx" /><id>/blogs/harrywaldron/archive/2008/07/18/email-threat-avoid-free-windows-malicious-software-removal-tool.aspx</id><published>2008-07-18T20:47:00Z</published><updated>2008-07-18T20:47:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-57.gif" alt="Email" /&gt; &lt;em&gt;This new malware threat is well done from an HTML and social engineering perspective.&amp;nbsp; Microsoft automatically includes MSRT with it&amp;#39;s monthly Windows Update process, and never sends tools like this out using email.&amp;nbsp; These messages should be deleted.&lt;/em&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Windows Malicious Software Removal Tool Free Today&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://sunbeltblog.blogspot.com/2008/07/another-fake-ms-spam.html"&gt;http://sunbeltblog.blogspot.com/2008/07/another-fake-ms-spam.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: As we all know, for quite some time now, spam has stopped just being a nuisance, and became a serious potential security threat.&amp;nbsp; It used to be that one wouldn&amp;rsquo;t get too upset if the occasional Viagra email got through a spam filter.&amp;nbsp; That&amp;rsquo;s no longer the case: Spam is a significant vector for malware infection through malicious links and social engineering, and if something gets through a spam filter &amp;mdash; and then makes it past endpoint protection &amp;mdash; one can have all kinds of nasty headaches.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;EXAMPLE OF EMAIL MESSAGE CURRENTLY CIRCULATING&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject: Windows Malicious Software Removal Tool Free Today.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The content in text format.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Click Here! *** Malicious link removed *** &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;About this mailing:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;You are receiving this e-mail because you subscribed to MSN Featured Offers.&lt;br /&gt;Microsoft respects your privacy. If you do not wish to receive this MSN&lt;br /&gt;Featured Offers e-mail, please click the &amp;quot;Unsubscribe&amp;quot; link below. This will&lt;br /&gt;not unsubscribe you from e-mail communications from third-party advertisers&lt;br /&gt;that may appear in MSN Feature Offers. This shall not constitute an offer by&lt;br /&gt;MSN. MSN shall not be responsible or liable for the advertisers&amp;#39; content nor&lt;br /&gt;any of the goods or service advertised. Prices and item availability subject&lt;br /&gt;to change without notice.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;2008 Microsoft | Unsubscribe &amp;lt;&lt;a href="http://www.msn.com"&gt;http://www.msn.com&lt;/a&gt;&amp;gt;&amp;nbsp; | More Newsletters&lt;br /&gt;&amp;lt;&lt;a href="http://www.msn.com"&gt;http://www.msn.com&lt;/a&gt;&amp;gt;&amp;nbsp; | Privacy &amp;lt;&lt;a href="http://www.msn.com"&gt;http://www.msn.com&lt;/a&gt;&amp;gt;&lt;/p&gt;
&lt;p&gt;Microsoft Corporation, One Microsoft Way, Redmond, WA 98052 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641380" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>United Parcel Service - Fake email for package non-delivery </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/16/united-parcel-service-fake-email-for-package-non-delivery.aspx" /><id>/blogs/harrywaldron/archive/2008/07/16/united-parcel-service-fake-email-for-package-non-delivery.aspx</id><published>2008-07-16T14:59:00Z</published><updated>2008-07-16T14:59:00Z</updated><content type="html">&lt;p&gt;&lt;span style="color:#3300ff;"&gt;&lt;span style="color:#000000;"&gt;&lt;img src="http://msmvps.com/emoticons/emotion-57.gif" alt="Email" /&gt; &lt;/span&gt;&lt;em&gt;McAfee and other AV vendors are highlighting this latest social engineering attack.&amp;nbsp; A well disquised email message appears to come from UPS.&amp;nbsp; It claims that a package cannot be delivered unless the fake waybill attachment is selected.&amp;nbsp; &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="color:#3300ff;"&gt;&lt;/span&gt;&lt;/i&gt;&amp;nbsp; &lt;br /&gt;&lt;i&gt;&lt;span style="color:#3300ff;"&gt;Users selecting these attachments will be infected with malicious code from a downloader that originates from a Russian website&lt;/span&gt; &lt;img src="http://www.myitforum.com/forums/image/s10.gif" alt="" /&gt;&lt;/i&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;United Parcel Service - Fake email for package non-delivery&lt;/b&gt;&amp;nbsp; &lt;br /&gt;&lt;a target="_blank" href="http://vil.mcafeesecurity.com/vil/content/v_132901.htm"&gt;&lt;span style="color:#003333;"&gt;http://vil.mcafeesecurity.com/vil/content/v_132901.htm&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;a target="_blank" href="http://wcco.com/techcenter/ups.email.virus.2.771489.html"&gt;&lt;span style="color:#003333;"&gt;http://wcco.com/techcenter/ups.email.virus.2.771489.html&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;a target="_blank" href="http://urbanlegends.about.com/b/2008/07/15/ups-virus-warning.htm"&gt;&lt;span style="color:#003333;"&gt;http://urbanlegends.about.com/b/2008/07/15/ups-virus-warning.htm&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;a target="_blank" href="http://www.startribune.com/local/25464324.html"&gt;&lt;span style="color:#003333;"&gt;http://www.startribune.com/local/25464324.html&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;a target="_blank" href="http://www.ups.com/content/us/en/about/news/service_updates/virus_us.html"&gt;&lt;span style="color:#003333;"&gt;http://www.ups.com/content/us/en/about/news/service_updates/virus_us.html&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE&lt;/b&gt;: &lt;b&gt;&lt;span style="color:#ff0000;"&gt;United Parcel Service is warning of a computer virus circulating under the guise of an e-mail from UPS&lt;/span&gt;&lt;/b&gt;. According to a release from UPS, the virus is attached to an e-mail that warns readers they have a shipment that couldn&amp;#39;t be delivered unless they click on the attachment. The e-mail claims the attachment contains a waybill that will allow the undelivered package to be picked up. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#990000;"&gt;COPY OF EMAIL MESSAGE: (spoofed to appear from UPS)&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;b&gt;&amp;quot;Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient&amp;rsquo;s address is not correct. Please print out the invoice copy attached and collect the package at our office.&amp;nbsp; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&amp;nbsp; &lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;b&gt;Your UPS&amp;quot;&lt;/b&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="color:#3300ff;"&gt;The attached file is an executable which downloads files from the following server: &lt;img src="http://www.myitforum.com/forums/image/s10.gif" alt="" /&gt;&lt;/span&gt;&lt;/i&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#ff0000;"&gt;hxxp: //fixaserver (dot) ru / ldr / [Removed]&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;span class="info"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641101" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Oracle Security Update for July 2008 - 45 updates for all products</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/16/oracle-security-update-for-july-2008-45-updates-for-all-products.aspx" /><id>/blogs/harrywaldron/archive/2008/07/16/oracle-security-update-for-july-2008-45-updates-for-all-products.aspx</id><published>2008-07-16T13:05:00Z</published><updated>2008-07-16T13:05:00Z</updated><content type="html">&lt;p&gt;&lt;em&gt;As applicable for their environment, corporate DBAs and system administrations should download, pilot test, and then install these critical security updates to better protect Oracle based applications.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; The Critical Patch Update for&lt;strong&gt; July 2008&lt;/strong&gt; was released on July 15, 2008. Oracle strongly recommends &lt;strong&gt;applying the patches as soon as possible.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Oracle Security Update for July 2008&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html"&gt;http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641089" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Music Files - New Codec injection attacks add danger for Multi-media files</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/15/music-files-new-codec-injection-attacks-add-danger-for-multi-media-files.aspx" /><id>/blogs/harrywaldron/archive/2008/07/15/music-files-new-codec-injection-attacks-add-danger-for-multi-media-files.aspx</id><published>2008-07-15T20:55:00Z</published><updated>2008-07-15T20:55:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-29.gif" alt="Music" /&gt; &lt;em&gt;Sometimes one bad apple can spoil the entire bunch.&amp;nbsp; A new injection based codec attack has surfaced which can infect all multi-media files on the hard drive.&amp;nbsp; For example, a malicious MP3 file can be downloaded and if the special fake codec routine is accepted, it will inject malicious code into every multi-media file that is processed.&amp;nbsp; Folks should continue to only use trusted sources for music or video.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Infectious Music, Malware-Style&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.trustedsource.org/blog/132/Trojan-infecting-multimedia-files"&gt;http://www.trustedsource.org/blog/132/Trojan-infecting-multimedia-files&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blog.trendmicro.com/infectious-music-malware-style/"&gt;http://blog.trendmicro.com/infectious-music-malware-style/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: A malware that infects multimedia files, modifying them to require the download of a fake codec when played had recently been discovered. It infects widely used multimedia file formats such as MP3, WMA and WMV video files by injecting a malicious code. The said malware is also capable of converting files such as MP2 and MP3 into Windows Media Audio (WMA) format. When a user tries to play an infected file, a pop-up message is displayed, asking the user to &lt;strong&gt;download a certain codec in order to play the file. The downloaded codec is of course, nothing else but malware&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But this malware takes it to a new, and more dangerous level; it manipulates a person&amp;rsquo;s multimedia files and uses it against them&lt;/strong&gt;. People normally keep thousands of multimedia files on their systems, &lt;strong&gt;especially MP3s&lt;/strong&gt;. If each file is infected by the malware then shared through a P2P network, then the user unknowingly turns into a malware host.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640973" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Malicious PDF files - Death of the Internet in 2012</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/15/malicious-pdf-files-death-of-the-internet-in-2012.aspx" /><id>/blogs/harrywaldron/archive/2008/07/15/malicious-pdf-files-death-of-the-internet-in-2012.aspx</id><published>2008-07-15T15:02:00Z</published><updated>2008-07-15T15:02:00Z</updated><content type="html">&lt;p&gt;&lt;em&gt;There are dangerous PDF files being circulated by spammers.&amp;nbsp; The new PDF based attacks typically use Javascript attacks within the document to infect vulnerable systems.&amp;nbsp; Users should always avoid opening any unexpected document or link in email messages.&amp;nbsp; Also, it is important to stay up-to-date on all security updates available from Adobe and other software vendors.&lt;/em&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Malicious PDF files - Death of the Internet in 2012&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://blog.trendmicro.com/death-of-the-internet-foretold/"&gt;http://blog.trendmicro.com/death-of-the-internet-foretold/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The malware involved in this spam run is detected by Trend Micro as T&lt;strong&gt;ROJ_PIDIEF.JT&lt;/strong&gt;, a Trojan that arrives as a PDF file named &lt;strong&gt;DOC.PDF&lt;/strong&gt;. This file promises more information regarding the alleged Internet death.&lt;/p&gt;
&lt;p&gt;PIDIEF Trojans are known &lt;strong&gt;malware droppers or downloaders&lt;/strong&gt;, so once users click on the attached PDF file &amp;mdash; and whether or not they believe the theory &amp;mdash; another malware is already up and running on their systems and doing malicious routines. The death of the Internet is going to be the least of their problems after that &amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Internet Storm Center - PDF Javascript based exploits&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=4726"&gt;http://isc.sans.org/diary.html?storyid=4726&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640910" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Storm Worm - Avoid Tabloid headlines in Spam messages</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/15/storm-worm-avoid-reading-tabloid-spam-messages.aspx" /><id>/blogs/harrywaldron/archive/2008/07/15/storm-worm-avoid-reading-tabloid-spam-messages.aspx</id><published>2008-07-15T11:44:00Z</published><updated>2008-07-15T11:44:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt; &lt;em&gt;The social engineering tactices used by the Storm worm continue to be well engineered.&amp;nbsp; These deceptive messages attempt to trick folks into selecting malicious links that automatically download malware to vulnerable systems.&lt;/em&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Storm Worm - Avoid Tabloid headlines in Spam messages&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://redtape.msnbc.com/2008/07/no-presidential.html"&gt;http://redtape.msnbc.com/2008/07/no-presidential.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; &lt;strong&gt;QUOTE&lt;/strong&gt;: No, spammers haven&amp;rsquo;t hired a bunch of former supermarket tabloid writers. They&amp;rsquo;re just doing what they do best &amp;ndash; exploiting human nature.&lt;/p&gt;
&lt;p&gt;The Storm worm is the Internet&amp;#39;s version of Broadway&amp;rsquo;s &amp;ldquo;Phantom of the Opera&amp;rdquo; -- the longest running hit show around. &lt;strong&gt;Storm first appeared in January 2007&lt;/strong&gt;, teasing users with a headline about deadly storms that hit Europe -- &amp;quot;230 dead as storm batters Europe,&amp;quot; it said, offering a link to a full story. Clickers found themselves infected with the Storm worm. &lt;/p&gt;
&lt;p&gt;Storm was an immediate hit for the hackers, who managed to trick hundreds of thousands of recipients into clicking on the booby-trapped link. That enabled them to build an &lt;strong&gt;enormous network of hijacked computers, called a botnet&lt;/strong&gt;, which they use to send out more spam or commit other Internet crimes.&lt;/p&gt;
&lt;p&gt;There have been &lt;strong&gt;hundreds of Storm variants&lt;/strong&gt; since the first one, sent by a loosely affiliated gang of computer criminals. Some estimates say that &lt;strong&gt;up to 10 million PCs have been infected with Storm at one time or another&lt;/strong&gt;. &lt;/p&gt;
&lt;p&gt;But in April, &lt;strong&gt;Microsoft updated its malicious software removal tool, much to the chagrin of the hackers. About four-fifths of the vast Storm network was cut off,&lt;/strong&gt; said Paul Wood, a security researcher at MessageLabs. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Comprehensive list of dozens of headlines from Message Labs&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.msnbc.msn.com/id/25680334"&gt;http://www.msnbc.msn.com/id/25680334&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640939" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Apple Macintosh computers - Keeping them secure in the corporate environment</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/14/apple-macintosh-computers-keeping-them-secure-in-the-corporate-environment.aspx" /><id>/blogs/harrywaldron/archive/2008/07/14/apple-macintosh-computers-keeping-them-secure-in-the-corporate-environment.aspx</id><published>2008-07-14T14:11:00Z</published><updated>2008-07-14T14:11:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt;&amp;nbsp;In the &lt;a href="http://www.sarbanes-oxley-forum.com/modules.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2469%20"&gt;Sarbanes-Oxley forums&lt;/a&gt;,&amp;nbsp;a&amp;nbsp;good question was asked related to keeping Mac systems protected.&amp;nbsp;Security is more of a &amp;quot;process&amp;quot; rather than being specifically hardware or software related. In other words, you should take the same precautionary protective measure for Apple workstations, just like Windows client PCs. &lt;/p&gt;
&lt;p&gt;For the most part, Apple Mac computers have enjoyed a fairly good track record when it comes to security. There are a fewer in-the-wild threats and the Apple OS X operating system has a Linux-kernel based design, that is fairly secure. &lt;/p&gt;
&lt;p&gt;Still, security is only as strong as it&amp;#39;s weakest link. Thus you want a strong chainlinked fence to keep the fox out of the chicken coop. &lt;/p&gt;
&lt;p&gt;Recommendations: &lt;/p&gt;
&lt;p&gt;1. Keep all operating system, browser, and software products as up-to-date as possible on security patches. &lt;/p&gt;
&lt;p&gt;2. Anti-virus software (anti-spyware might be beneficial also) &lt;/p&gt;
&lt;p&gt;3. Firewall protection is always a must &lt;/p&gt;
&lt;p&gt;4. Authentication to networks (with strong password settings, rotations, and other best practices) &lt;/p&gt;
&lt;p&gt;5. Security policies that include the Mac environment (e.g., discouraging too much personal use, installation of non-business software, etc) &lt;/p&gt;
&lt;p&gt;6. Use of Firefox 3 might be beneficial to look at as a complementary browser to Safari (which has suffered some recent security issues) &lt;/p&gt;
&lt;p&gt;7. Tracking of Apple security exposures and risks as they develop (e.g., monitor Secunia, Internet Storm Center, Apple&amp;#39;s security bulletins, FRSIRT, etc) &lt;/p&gt;
&lt;p&gt;&lt;em&gt;As noted, this list is fairly similar to keeping Windows client PCs secure. These additional&amp;nbsp;links might help: &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;q=corporate+macintosh+security+best+practices"&gt;http://www.google.com/search?hl=en&amp;amp;q=corporate+macintosh+security+best+practices&lt;/a&gt; &lt;br /&gt;&lt;a href="https://security.berkeley.edu/mac.html"&gt;https://security.berkeley.edu/mac.html&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.networkworld.com/news/2007/022707-mac-os-going-corporate.html"&gt;http://www.networkworld.com/news/2007/022707-mac-os-going-corporate.html&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640734" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Microsoft Security Updates - July 2008 includes SQL-Server update </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/14/microsoft-security-updates-july-2008-includes-sql-server-update.aspx" /><id>/blogs/harrywaldron/archive/2008/07/14/microsoft-security-updates-july-2008-includes-sql-server-update.aspx</id><published>2008-07-14T12:43:00Z</published><updated>2008-07-14T12:43:00Z</updated><content type="html">&lt;p&gt;&lt;em&gt;Microsoft have released this month&amp;#39;s patches as part of their usual Patch Tuesday monthly cycle.&amp;nbsp; This months patches are: &lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#006600;"&gt;MS08-037 - Vulnerabilities in DNS Could Allow Spoofing (953230)&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Affects:&lt;/b&gt; Windows 2000, XP (inc x64), Server 2003 (inc x64), Server 2008 (inc x64) &lt;br /&gt;&lt;b&gt;LInk:&lt;/b&gt; &lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx"&gt;&lt;span style="color:#003333;"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#006600;"&gt;MS08-038 - Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582) &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Affects:&lt;/b&gt; Windows Vista and Windows 2008 Server &lt;br /&gt;&lt;b&gt;Link:&lt;/b&gt; &lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx"&gt;&lt;span style="color:#003333;"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#006600;"&gt;MS08-039 - Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747)&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;b&gt;Affects:&lt;/b&gt; Microsoft Exchance Server 2003 &amp;amp; 2007 &lt;br /&gt;&lt;b&gt;Link:&lt;/b&gt; &lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS08-039.mspx"&gt;&lt;span style="color:#003333;"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-039.mspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#006600;"&gt;MS08-040 - Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;b&gt;Affects:&lt;/b&gt; SQL Server 7, 2000, 2005, MSDE 1.0, SQL 2000 Desktop Engine, SQL 2005 Express Edition, Windows 2000, Server 2003 &amp;amp; Server 2008 &lt;br /&gt;&lt;b&gt;Link: &lt;/b&gt;&lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS08-040.mspx"&gt;&lt;span style="color:#003333;"&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-040.mspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Additional Links: &amp;nbsp;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft:&lt;/b&gt; &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx"&gt;&lt;span style="color:#003333;"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;b&gt;MS Blog:&lt;/b&gt; &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2008/07/08/july-2008-bulletin-monthly-release.aspx"&gt;&lt;span style="color:#003333;"&gt;http://blogs.technet.com/msrc/archive/2008/07/08/july-2008-bulletin-monthly-release.aspx&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;b&gt;ISC:&lt;/b&gt; &lt;a target="_blank" href="http://isc.sans.org/diary.html?storyid=4684"&gt;&lt;span style="color:#003333;"&gt;http://isc.sans.org/diary.html?storyid=4684&lt;/span&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;So far, &lt;b&gt;the July updates are working well on my XP SP3 PCs at home and&amp;nbsp;work&lt;/b&gt; ... &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color:#006600;"&gt;IMPORTANT NOTE -- Don&amp;#39;t forget to patch SQL-Server as applicable (after pilot testing your web or client/server based applications)&lt;/span&gt;&lt;/b&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640721" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>IT Project management - Excellent collection of resources</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/09/it-project-management-excellent-collection-of-resources.aspx" /><id>/blogs/harrywaldron/archive/2008/07/09/it-project-management-excellent-collection-of-resources.aspx</id><published>2008-07-09T13:40:00Z</published><updated>2008-07-09T13:40:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;span style="font-style:italic;"&gt;The 100th edition of the ALLPM Today Newsletter shares some excellent resources as the most popular articles for each year are highlighted below: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular allPM Article (for all years) - Communication in the Workplace &lt;br /&gt;By Kate McLeod, PMP&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1910"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1910&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Most popular ALLPM articles for each year:&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2002 Article - Project Management Best Practice #3 -&amp;quot;Strategic Planning for Project Management&amp;quot; &lt;br /&gt;By Dr. Harold Kerzner&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1909"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1909&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2003 Article - Understanding the PRINCE2 Processes - Part One &lt;br /&gt;By David Whelbourn&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1908"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1908&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2004 Article - The True Meaning of Teamwork &lt;br /&gt;By Sloan Campbell MBA, PMP&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1907"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1907&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2005 Article - Acceptance Criteria - Part I &amp;amp; II, &lt;br /&gt;By Eoin Callan (MBA, PMP)&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1906"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1906&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2006 Article - Why Does a Project Need a Project Manager and a Business Analyst &lt;br /&gt;By Barbara Carkenord&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1905"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1905&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Most Popular 2007 Article - The Essence of OPM3&amp;reg; &lt;br /&gt;By Ralf Friedrich&lt;/span&gt; &lt;br /&gt;&lt;a target="_blank" href="http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1904"&gt;http://allpm.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=1904&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639975" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Storm Worm - Avoid July 4th topics offering Fireworks display</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/06/storm-worm-avoid-july-4th-topics-offering-fireworks-display.aspx" /><id>/blogs/harrywaldron/archive/2008/07/06/storm-worm-avoid-july-4th-topics-offering-fireworks-display.aspx</id><published>2008-07-06T12:50:00Z</published><updated>2008-07-06T12:50:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt; As noted in Gary warner&amp;#39;s excellent blog post, please avoid the following email messages in your in-box:&lt;/p&gt;
&lt;p&gt;Storm Worm - Avoid July 4th topics offering Fireworks display&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=4669"&gt;http://isc.sans.org/diary.html?storyid=4669&lt;/a&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2008/07/storm-worm-salutes-our-nation-on-4th.html"&gt;http://garwarner.blogspot.com/2008/07/storm-worm-salutes-our-nation-on-4th.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; &lt;strong&gt;QUOTE:&lt;/strong&gt; The website, which seems to invite visitors to play a fireworks video, actually downloads the Storm malware in the form of an executable called &amp;quot;&lt;strong&gt;fireworks.exe&lt;/strong&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subjects&lt;br /&gt;&lt;/strong&gt;=================&lt;br /&gt;Amazing firework 2008&lt;br /&gt;America the Beautiful&lt;br /&gt;American Independence Day&lt;br /&gt;Bright and joyful Fourth of July&lt;br /&gt;Celebrate Independence&lt;br /&gt;Celebrating Fourth of July&lt;br /&gt;Celebrating the Glory of our Nation&lt;br /&gt;Celebrating the spirit of our Country&lt;br /&gt;Celebrations have already begun&lt;br /&gt;Fabulous Independence Day firework&lt;br /&gt;God bless America&lt;br /&gt;Happy Birthday, America!&lt;br /&gt;Happy Independence Day&lt;br /&gt;Happy Independence Day!!&lt;br /&gt;Independence Day firework broke all records *&lt;br /&gt;Spectacular fireworks show&lt;br /&gt;Stars and Strips forever&lt;br /&gt;The best of 4th of July Salute&lt;br /&gt;Time for Fireworks&lt;br /&gt;Wish your friends a happy Independence Day&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Bodies&lt;/strong&gt;&lt;br /&gt;=================&lt;br /&gt;Amazing Independence Day show&lt;br /&gt;America the Beautiful&lt;br /&gt;Celebrating the Glory of our Nation&lt;br /&gt;God bless America&lt;br /&gt;Sparkling Celebration of Independence Day&lt;br /&gt;Stars and Strips forever&lt;br /&gt;Super 4th!&lt;br /&gt;The best firework you&amp;#39;ve ever seen&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639555" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Internet Explorer 8 Beta 2 - Will focus on security improvements</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/06/internet-explorer-8-beta-2-will-focus-on-security-improvements.aspx" /><id>/blogs/harrywaldron/archive/2008/07/06/internet-explorer-8-beta-2-will-focus-on-security-improvements.aspx</id><published>2008-07-06T12:38:00Z</published><updated>2008-07-06T12:38:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;em&gt;Two recent ZDNet blog posts highlight forthcoming security improvements for the next beta release of IE 8.&amp;nbsp; The release to testers is planned for August.&amp;nbsp; These improvements will make IE8 a worthwhile upgrade when it is released in the future.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Internet Explorer 8 Beta 2 - Will focus on security improvements&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1396"&gt;http://blogs.zdnet.com/security/?p=1396&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/Bott/?p=484"&gt;http://blogs.zdnet.com/Bott/?p=484&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;:&amp;nbsp;When Microsoft&amp;#39;s Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a &lt;strong&gt;full-fledged anti-malware blocker and new protections against some forms of cross-site scripting attacks&lt;/strong&gt;. The existing phishing filter IE 7 has been renamed &lt;strong&gt;SmartScreen Filter and will include blacklist-based blocking of known exploit sites&lt;/strong&gt;.&amp;nbsp; Also new in IE 8 Beta 2 is an &lt;strong&gt;XSS Filter to detect Type-1 (reflection) attacks&lt;/strong&gt; that can lead to cookie theft, keystroke logging, Web site defacement and credentials theft:&lt;/p&gt;
&lt;p&gt;The new beta refresh will also include support for &lt;strong&gt;safer Web 2.0-type mashups, DEP&lt;/strong&gt; (data execution protection) turned on by default in Windows Vista SP 1, &lt;strong&gt;domain highlighting&lt;/strong&gt; to help flag phishing attacks and changes &lt;strong&gt;to the way ActiveX controls are handled.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Below are also an overview of security improvements found in the current beta version:&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Internet Explorer 8 - Two New Security Improvements&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.itsecurity.com/features/ie8-security-features-032408/"&gt;http://www.itsecurity.com/features/ie8-security-features-032408/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;:&amp;nbsp; IE 8&amp;#39;s security environment benefits from the addition of two major enhancements: the Safety Filter tool and the Domain Highlighting feature. Here&amp;#39;s a closer look at both of these new enhancements.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Safety Filter&lt;/strong&gt; -- IE 8 ups the ante with a new Safety Filter that &lt;strong&gt;analyzes the entire URL string&lt;/strong&gt; to search for carefully hidden signs that a Web site may be something other than it claims to be. In Microsoft&amp;#39;s words, the Safety Filter provides &amp;quot;a more granular detection&amp;quot; capability, allowing the browser to protect users from more targeted and sophisticated attacks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Domain Highlighting&lt;/strong&gt; -- IE 8&amp;#39;s other major new security feature is a technology that &lt;strong&gt;highlights the top-level domain in the browser&amp;#39;s address bar.&lt;/strong&gt; This enhancement might not sound like much, but it is designed to provide a hard-to-miss visual clue that will function like a traffic light. The idea is to enable users to quickly confirm that the Web site they are visiting is the site that they intended to visit.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639554" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Citibank ATM breach reveals PIN security problems </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/07/02/citibank-atm-breach-reveals-pin-security-problems.aspx" /><id>/blogs/harrywaldron/archive/2008/07/02/citibank-atm-breach-reveals-pin-security-problems.aspx</id><published>2008-07-02T15:19:00Z</published><updated>2008-07-02T15:19:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt;&amp;nbsp;In most cases, folks are safe to use ATMs for cash withdrawals, although this major&amp;nbsp;security incident reported yesterday is alarming.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Citibank ATM breach reveals PIN security problems &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://news.yahoo.com/s/ap/20080701/ap_on_hi_te/tec_atm_breach"&gt;http://news.yahoo.com/s/ap/20080701/ap_on_hi_te/tec_atm_breach&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SAN JOSE, Calif. - Hackers broke into Citibank&amp;#39;s network of ATMs &lt;strong&gt;inside 7-Eleven stores&lt;/strong&gt; and &lt;strong&gt;stole customers&amp;#39; PIN codes&lt;/strong&gt;, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record. &lt;strong&gt;The scam netted the alleged identity thieves millions of dollars.&lt;/strong&gt; But more importantly for consumers, it indicates criminals were able to access PINs &amp;mdash; the numeric passwords that theoretically are among &lt;strong&gt;the most closely guarded elements of banking&lt;/strong&gt; &lt;strong&gt;transactions &amp;mdash; by attacking the back-end computers responsible for approving the cash withdrawals.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It&amp;#39;s unclear how many Citibank customers were affected by the breach&lt;/strong&gt;, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the U.S., but it doesn&amp;#39;t own or operate any of them.&lt;/p&gt;
&lt;p&gt;That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others. A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn&amp;#39;t been answered publicly. &lt;strong&gt;All that&amp;#39;s known is they broke into the ATM network through a server at a third-party processor&lt;/strong&gt;, which means they probably didn&amp;#39;t have to touch the ATMs at all to pull off the heist.&lt;/p&gt;
&lt;p&gt;They could have gained administrative access to the machines - which means they had carte blanche to grab information - through a flaw in the network or by figuring out those computers&amp;#39; passwords. &lt;strong&gt;Or it&amp;#39;s possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through&lt;/strong&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639117" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Windows Vista - Numerous Security Advantages over XP</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/27/windows-vista-numerous-security-advantages-over-xp.aspx" /><id>/blogs/harrywaldron/archive/2008/06/27/windows-vista-numerous-security-advantages-over-xp.aspx</id><published>2008-06-27T21:26:00Z</published><updated>2008-06-27T21:26:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;em&gt;In searching early this morning, I ran across the link below which&amp;nbsp;highlights numerous security advantages that Vista has over XP.&amp;nbsp; In fact the improved&amp;nbsp;security&amp;nbsp;has&amp;nbsp;caused some&amp;nbsp;incompatibility issues with&amp;nbsp;some applications written for Windows 2000 or XP.&amp;nbsp;&amp;nbsp; Still, if you have a new or relatively new system that&amp;#39;s capable of running Vista and your applications are compatible,&amp;nbsp;you will benefit from the improved security which is part of TWC.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MSDN - Technical&amp;nbsp;document highlights Vista&amp;#39;s&amp;nbsp;security advantages&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/bb188739.aspx" target="_blank"&gt;http://msdn.microsoft.com/en-us/library/bb188739.aspx&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638556" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/27/url-scan-3-0-beta-new-version-helps-detect-sql-injection-attacks.aspx" /><id>/blogs/harrywaldron/archive/2008/06/27/url-scan-3-0-beta-new-version-helps-detect-sql-injection-attacks.aspx</id><published>2008-06-27T12:30:00Z</published><updated>2008-06-27T12:30:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;font color="#800080"&gt;&lt;i&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL injection attacks, that are currently circulating. This security tool can help spot weaknesses that should addressed by the web development tool (e.g., strengthening SQL-Server calls for improved security by using parameterized lists, ADO, stored procedures, and other secure techniques). URL Scan can detect or block many of the generic attacks by searching for special keywords. &lt;/i&gt;&lt;br /&gt;&amp;nbsp;&lt;/font&gt;&lt;br /&gt;&amp;nbsp;&lt;font color="#008000"&gt;U&lt;b&gt;RL Scan 3.0 Beta - New version helps detect SQL Injection Attacks&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&amp;nbsp;&lt;a href="http://blogs.iis.net/wadeh/archive/2008/06/05/urlscan-v3-0-beta-release.aspx"&gt;http://blogs.iis.net/wadeh/archive/2008/06/05/urlscan-v3-0-beta-release.aspx&lt;/a&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;b&gt;&lt;font color="#800080"&gt;QUOTE:&lt;/font&gt;&lt;/b&gt; &lt;b&gt;&lt;font color="#008000"&gt;UrlScan installs as a filter on IIS and looks at incoming requests in real time.&lt;/font&gt;&lt;/b&gt; It can then screen requests based on a set of general request properties. For example, it can block overly long URLs or headers. It can block requests with unexpected HTTP verbs or strings in the URL.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;Today, in 2008, we find ourselves in a similar situation. &lt;b&gt;&lt;font color="#ff0000"&gt;We are seeing a particularly nasty automated SQL Injection attack&lt;/font&gt;&lt;/b&gt; that is targeting our customers. This attack defaces web servers and sends their clients off to malicious servers that attempt to install malware. As before, the vulnerability does not exist in IIS - or any software from Microsoft. In this case, the attack is exploiting vulnerabilities in customer developed applications. And as before, the real fixes will need to come from the myriad developers of those applications. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;b&gt;The new set of features in version 3 are:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;* &lt;font color="#008000"&gt;&lt;b&gt;Support for query string scanning&lt;/b&gt;&lt;/font&gt;, including an option to scan an unescaped version of the query string.&lt;br /&gt;&amp;nbsp;* &lt;b&gt;&lt;font color="#008000"&gt;Change notification for configuration&lt;/font&gt;&lt;/b&gt; (no more restarts for most settings.)&lt;br /&gt;&amp;nbsp;* &lt;b&gt;&lt;font color="#008000"&gt;UrlScan can be installed as a site filter.&lt;/font&gt;&lt;/b&gt; Different sites can have their own copy, with their own configuration.&lt;br /&gt;&amp;nbsp;* &lt;b&gt;&lt;font color="#008000"&gt;Escape sequences can be used in the configuration file to express CRLF&lt;/font&gt;&lt;/b&gt;, a semicolon (normally a comment delimiter) or unprintable characters in rules.&lt;br /&gt;&amp;nbsp;* &lt;font color="#008000"&gt;&lt;b&gt;Custom rules can be created to scan the URL,&lt;/b&gt;&lt;/font&gt; query string, a particular header, all headers or combination of these. The rules can be applied based on the type of file requested.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;We also have plans to update the IIS 7 request filter to add these features. In the interim, UrlScan 3 is fully supported on IIS 7.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;font color="#008000"&gt;&lt;b&gt;IMPORTANT RECOMMENDATION:&lt;/b&gt;&lt;/font&gt; Finally, it cannot be overstated that t&lt;font color="#008000"&gt;&lt;b&gt;hese tools are just an interim measure to buy time to fix the affected applications.&lt;/b&gt;&lt;/font&gt; While they are effective against the current wave of automated attacks, they cannot protect against more directed attacks against a specific server. &lt;b&gt;&lt;font color="#ff0000"&gt;The category of SQL Injection vulnerabilities is so broad that there are no known filter strategies that can block a determined hacker against application vulnerabilities. &lt;/font&gt;&lt;/b&gt;There are many resources available for learning about SQL Injection attacks and prevention strategies. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;b&gt;&lt;font color="#008000"&gt;ADDITIONAL RESOURCES - HOW TO PREVENT SQL-INJECTION ATTACKS&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;a href="http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx"&gt;http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx&lt;/a&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;a href="http://msmvps.com/blogs/harrywaldron/archive/2008/06/15/new-sql-injection-attacks-the-need-to-improve-legacy-web-applications.aspx"&gt;http://msmvps.com/blogs/harrywaldron/archive/2008/06/15/new-sql-injection-attacks-the-need-to-improve-legacy-web-applications.aspx&lt;/a&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;a href="http://msmvps.com/blogs/harrywaldron/archive/2008/06/25/sql-injection-mitigation-tips-for-asp-development.aspx"&gt;http://msmvps.com/blogs/harrywaldron/archive/2008/06/25/sql-injection-mitigation-tips-for-asp-development.aspx&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638363" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>SQL Injection mitigation tips for ASP development </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/25/sql-injection-mitigation-tips-for-asp-development.aspx" /><id>/blogs/harrywaldron/archive/2008/06/25/sql-injection-mitigation-tips-for-asp-development.aspx</id><published>2008-06-25T20:46:00Z</published><updated>2008-06-25T20:46:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;em&gt;Microsoft, the Internet Storm Center, the SQL-Server Worldwide Users Group (SSWUG), and others are actively promoting the dangers associated with automated SQL&amp;nbsp;injection attacks.&amp;nbsp; While SQL Injection concerns have been around for several years, these attacks have growth substantially this year because&amp;nbsp;of automation.&amp;nbsp; There are also numerous vulnerable websites out there, which provide an opportunity for malware&amp;nbsp;attacks.&amp;nbsp; There is a need to fix these sites and&amp;nbsp;promote secure web&amp;nbsp;development.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;font color="#008000"&gt;&lt;b&gt;SQL Injection mitigation tips for ASP development &lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=4610"&gt;http://isc.sans.org/diary.html?storyid=4610&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE: &lt;/b&gt;With the recent SQL injection attacks on ASP pages. A lot of our readers are scrambling to find fixes for their applications. ASP is an older generation Web scripting language would require a bit more work to prevent SQL injection from happening. One of our readers Brian Erman has written a function to filter out the SQL keywords and also escape some the metacharacters in SQL to prevent SQL injection. from happening.&lt;br /&gt;&lt;br /&gt;&lt;font color="#008000"&gt;&lt;b&gt;Brian Erman&amp;#39;s SQL Injection filtering for ASP&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;a href="http://paste-it.net/public/c3cb69a/"&gt;http://paste-it.net/public/c3cb69a/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;To stop SQL injection at the root, we have to understand that SQL injection happens because &lt;font color="#ff0000"&gt;&lt;b&gt;the database cannot effectively distinguish between static portion of the SQL statement and the user input. &lt;/b&gt;&lt;/font&gt;If there is a way we can tell the database - this is static SQL statement and this is user input, SQL injection could be stopped easily.&lt;br /&gt;&lt;br /&gt;In actual fact, such mechanism exists, it is called parameterized query. &lt;b&gt;&lt;font color="#008000"&gt;The user input are passed to the SQL server as an argument (sort of like calling a function in programming language), the SQL server during query execution have a way to identify what part of the statement is static control, and which part is user input.&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Parameterized queries have been widely publicized. In classic ASP, parameterized query is possible if you use ADO command object, an example is here. Parameterized query is available on most other web scripting platforms, now is the time to review all your web app before the automated SQL injection exploitation spreads to other language platforms (PHP, CFM, PL)&lt;br /&gt;&lt;br /&gt;&lt;font color="#008000"&gt;&lt;b&gt;GOOD EXAMPLES OF PARAMETERIZED QUERIES&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;a href="http://aspnet101.com/aspnet101/tutorials.aspx"&gt;http://aspnet101.com/aspnet101/tutorials.aspx&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=6999"&gt;http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=6999&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.inrsolutions.com/blog/details.asp?id=5"&gt;http://www.inrsolutions.com/blog/details.asp?id=5&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637686" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Malware Automation - Trojan2Worm Toolkit </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/25/malware-automation-trojan2worm-toolkit.aspx" /><id>/blogs/harrywaldron/archive/2008/06/25/malware-automation-trojan2worm-toolkit.aspx</id><published>2008-06-25T12:30:00Z</published><updated>2008-06-25T12:30:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-29.gif" alt="Music" /&gt; &lt;font color="#800080"&gt;&lt;i&gt;While Malware authors continue to develop exploits to attack vulnerable systems, they are also creating automated toolsets. The new Trojan2Worm toolkit can take any executable and publish it rapidly as worm based malware that can quickly spread on USB, DVDs, CDs, network shares, and other media. &lt;/i&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Malware Automation - Trojan2Worm Toolkit&lt;/b&gt;&lt;br /&gt;&lt;a href="http://vil.nai.com/vil/content/v_146248.htm"&gt;http://vil.nai.com/vil/content/v_146248.htm&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2008/06/18/trojan_worm_toolkit/"&gt;http://www.theregister.co.uk/2008/06/18/trojan_worm_toolkit/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE&lt;/b&gt;: This Tool-Kit is used by an attacker to &lt;font color="#ff0000"&gt;&lt;b&gt;convert any executable into an autorun worm, which can spread through removable devices, by implementing an “AutoRun.inf” configuration file&lt;/b&gt;&lt;/font&gt;. &amp;quot;Autorun.inf&amp;quot; is a text based configuration file which instructs the Windows operating system to perform some action upon opening a network shared drive, local folder, floppy drive, CD-ROM drive or the insertion of a removable disk drive. &lt;br /&gt;&lt;br /&gt;Trojan2Worm (T2W) toolkit turns any executable file into a worm with auto-spreading capabilities. As such it provides the ability for Trojan infection agents to acquire worm-like spreading abilities.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The tool requires minimal skills to use&lt;/b&gt;, net security firm Panda Security reports. Features include the a&lt;b&gt;&lt;font color="#ff0000"&gt;bility to compress infectious files or mutate their contents, tricks designed to make it easier to smuggle malware past anti-virus scanners.&lt;/font&gt;&lt;/b&gt; It&amp;#39;s also possible to program malware so that it &lt;b&gt;&lt;font color="#ff0000"&gt;disables Task Manager, Windows Registry Editor or even selected browsers.&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637540" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Latest Storm Worm - Uses Fictional Breaking News Alerts</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/23/latest-storm-worm-uses-fictional-breaking-news-alerts.aspx" /><id>/blogs/harrywaldron/archive/2008/06/23/latest-storm-worm-uses-fictional-breaking-news-alerts.aspx</id><published>2008-06-23T00:20:00Z</published><updated>2008-06-23T00:20:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt; &lt;i&gt;The latest storm worm variant sends false news alerts to trick individuals into selecting links and infecting their system. Avoid these messages and use major news sites as a source for alerts. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;font color="#800000"&gt;Storm Worm - Uses Fictional Breaking News Alerts&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/06/20/breaking-news-not/"&gt;http://www.avertlabs.com/research/blog/index.php/2008/06/20/breaking-news-not/&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.f-secure.com/weblog/archives/00001459.html"&gt;http://www.f-secure.com/weblog/archives/00001459.html&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;QUOTE&lt;/b&gt;: Nuwar spammers have moved from jumping on real news of natural disasters and current affairs to &lt;b&gt;&lt;font color="#ff0000"&gt;creating their own fictional events!&lt;/font&gt;&lt;/b&gt; &lt;b&gt;&lt;font color="#ff0000"&gt;This high volume spam campaign is using some wacky subjects to lure people into clicking on the links&lt;/font&gt;&lt;/b&gt;:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; &lt;font color="#800000"&gt;&lt;b&gt;EXAMPLES&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;b&gt;&lt;font color="#ff0000"&gt;Subject: White House hit by lightning, catches fire&lt;br /&gt;Subject: Oprah found sleeping the streets&lt;br /&gt;Subject: Eiffel Tower damaged by massive earthquake&lt;br /&gt;Subject: Donald Trump missing, feared kidnapped&lt;br /&gt;Subject: Lastest! Obama quits presidential race&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This clever &lt;b&gt;&lt;font color="#ff0000"&gt;social engineering technique plays on peoples inquisitiveness in news of natural disasters and celebrities. &lt;/font&gt;&lt;/b&gt;The emails also follow the simple format of some text and a link that looks fairly harmless to the uneducated user. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;font color="#008000"&gt;NEVER click on links in an email unless you are sure of its origin,&lt;/font&gt;&lt;/b&gt; &lt;b&gt;&lt;font color="#008000"&gt;keep your Anti-Virus software up-to-date &lt;/font&gt;&lt;/b&gt;and if you have a website make sure its properly secured so you’re not hosting stuff like this.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636843" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>IT Security - The Essential Guide to Firewalls</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/22/it-security-the-essential-guide-to-firewalls.aspx" /><id>/blogs/harrywaldron/archive/2008/06/22/it-security-the-essential-guide-to-firewalls.aspx</id><published>2008-06-22T11:37:00Z</published><updated>2008-06-22T11:37:00Z</updated><content type="html">&lt;p&gt;&lt;em&gt;The&lt;/em&gt; &lt;a class="" href="http://www.itsecurity.com/"&gt;&lt;strong&gt;IT Security website&lt;/strong&gt;&lt;/a&gt; &lt;em&gt;is an excellent resource for researching corporate security needs and best practices.&amp;nbsp;The articles below describe options and best practices&amp;nbsp;for corporate firewall implementations.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itsecurity.com/features/essential-guide-firewalls-061208/"&gt;http://www.itsecurity.com/features/essential-guide-firewalls-061208/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; &lt;a href="http://www.itsecurity.com/firewalls/"&gt;&lt;strong&gt;Firewalls&lt;/strong&gt;&lt;/a&gt; play a central role in IT security, standing between enterprise networks and the outside world to protect computers, applications and other resources from external attack.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itsecurity.com/features/5-firewall-tests-091107/"&gt;&lt;strong&gt;5 Firewall Tests and Supporting Tools&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itsecurity.com/comparison-guides/firewall-comparison-guide/"&gt;&lt;strong&gt;Firewall Comparison Guide&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itsecurity.com/features/tips-deploying-firewall-012507/"&gt;&lt;strong&gt;3 Tips For Deploying a Firewall&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itsecurity.com/whitepaper/firewall-secure-10-tips/"&gt;&lt;strong&gt;10 Tips to Make Sure Your Firewall is Really Secure&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636662" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Windows Live Writer - New blog publishing application</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2008/06/22/windows-live-writer-new-blog-publishing-application.aspx" /><id>/blogs/harrywaldron/archive/2008/06/22/windows-live-writer-new-blog-publishing-application.aspx</id><published>2008-06-22T01:50:00Z</published><updated>2008-06-22T01:50:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-38.gif" alt="Moon" /&gt; &lt;em&gt;This new desktop publishing application for rich-text blogging, recently became available. It&amp;#39;s free and I plan to learn how to use it in the coming weeks. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Windows Live Writer&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://get.live.com/writer/overview"&gt;http://get.live.com/writer/overview&lt;/a&gt;&lt;br /&gt;&lt;a href="http://get.live.com/writer/features"&gt;http://get.live.com/writer/features&lt;/a&gt;&lt;br /&gt;&lt;a href="http://get.live.com/writer/sysreq"&gt;http://get.live.com/writer/sysreq&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Wikipedia Information&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Windows_Live_Writer"&gt;http://en.wikipedia.org/wiki/Windows_Live_Writer&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Windows Live Writer Blog&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://windowslivewriter.spaces.live.com/"&gt;http://windowslivewriter.spaces.live.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Windows Live Writer is a desktop application that makes it easy to publish rich content to your blog. Key functions include:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;1. Publish to most major blog services&lt;br /&gt;2. Create a compelling blog easily&lt;br /&gt;3. Preview before you post&lt;br /&gt;4. Compose your entries offline&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636604" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry></feed>