<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Harry Waldron - IT Security</title><link>http://msmvps.com/blogs/harrywaldron/default.aspx</link><description>Security Developments, Software Updates and Best Practices </description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Office 2010 - Data Execution Prevention (DEP) by Default </title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/office-2010-data-execution-prevention-dep-by-default.aspx</link><pubDate>Sun, 07 Feb 2010 16:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1755804</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1755804</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/office-2010-data-execution-prevention-dep-by-default.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt;&amp;nbsp;PC Magazine reports on improved security in Office 2010, where it will integrate DEP protective controls that can prohibit certain malware attacks. This can improve malware protection, when malicious scripts are launched in early attacks and vendors may not have AV signatures available&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Office 2010 - Data Execution Prevention (DEP) by Default &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://blogs.pcmag.com/securitywatch/2010/02/office_2010_opts_in_to_dep_by.php"&gt;http://blogs.pcmag.com/securitywatch/2010/02/office_2010_opts_in_to_dep_by.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Office 2010 - In Depth Article on DEP Protection&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/office2010/archive/2010/02/04/data-excecution-prevention-in-office-2010.aspx"&gt;http://blogs.technet.com/office2010/archive/2010/02/04/data-excecution-prevention-in-office-2010.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Microsoft Office 2010 will, by default, opt in to DEP (Data Execution Prevention), a feature of recent versions of Windows that helps to prevent vulnerability exploits.&amp;nbsp; DEP causes a program to halt when an attempt is made to execute code in an area of memory marked as data. This is a common technique for exploits, including many that have used malicious Office documents over the years. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;WHAT IS Data Execution Prevention (DEP)?&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://support.microsoft.com/default.aspx/kb/875352"&gt;http://support.microsoft.com/default.aspx/kb/875352&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Data Execution Prevention (DEP) is a &lt;strong&gt;set of hardware and software technologies&lt;/strong&gt; that perform &lt;strong&gt;additional checks on memory&lt;/strong&gt; to help &lt;strong&gt;prevent malicious code&lt;/strong&gt; from running on a system. In Microsoft Windows XP, DEP is enforced by hardware and by software.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Office 2010 Beta is available for testing at:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Office 2010 - Home Page&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.microsoft.com/office/2010/en/default.aspx"&gt;http://www.microsoft.com/office/2010/en/default.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1755804" width="1" height="1"&gt;</description></item><item><title>Money Mules - Work at home scams to be prosecuted by FTC</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/money-mules-work-at-home-scams-to-be-prosecuted-by-ftc.aspx</link><pubDate>Sun, 07 Feb 2010 15:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1755783</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1755783</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/money-mules-work-at-home-scams-to-be-prosecuted-by-ftc.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt;&amp;nbsp;The FTC has announced a crack down on fradulent employment at home scams.&lt;/p&gt;
&lt;p&gt;Money Mules - Work at home scams to be prosecuted by FTC&lt;br /&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/02/major-us-crackdown-on-work-at-home.html"&gt;http://sunbeltblog.blogspot.com/2010/02/major-us-crackdown-on-work-at-home.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.krebsonsecurity.com/2010/01/top-10-ways-to-get-fired-as-a-money-mule/"&gt;http://www.krebsonsecurity.com/2010/01/top-10-ways-to-get-fired-as-a-money-mule/&lt;/a&gt;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: The U.S. Federal Trade Commission today announced that next Tuesday they will hold a news conference to make public details of &amp;ldquo;a &lt;strong&gt;law enforcement sweep cracking down on job and work-at-home fraud&lt;/strong&gt; fueled by the economic downturn.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;People who sign on as work-at-home employees from Internet ads (also called &amp;ldquo;&lt;strong&gt;money mules&lt;/strong&gt;&amp;rdquo;) often are&lt;strong&gt; used as conduits for stolen funds&lt;/strong&gt; that are transferred from the bank accounts of victim individuals or companies who have been scammed by phishing or spear-phishing. The money mules set up bank accounts into which stolen funds are transferred. They are instructed to keep a portion of the funds and wire the remainder to the scammers, who are generally outside the U.S.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1755783" width="1" height="1"&gt;</description></item><item><title>Microsoft Patch Tuesday - Huge Security Update on 02/09/2010</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/microsoft-patch-tuesday-huge-security-update-on-02-09-2010.aspx</link><pubDate>Sun, 07 Feb 2010 15:43:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1755779</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1755779</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/02/07/microsoft-patch-tuesday-huge-security-update-on-02-09-2010.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; Please note that Microsoft will be releasing a number of critcal&amp;nbsp; security updates on Patch Tuesday (02/11/10).&amp;nbsp; Please take out to install these important updates and reboot as prompted. This is one of the most important things you can do to protect your PC.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8155"&gt;http://isc.sans.org/diary.html?storyid=8155&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-feb.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-feb.mspx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx"&gt;http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Microsoft announced that they will be releasing a total of &lt;strong&gt;13 bulletins&lt;/strong&gt; next Tuesday. These bulletins will fix &lt;strong&gt;26 difference vulnerabilities&lt;/strong&gt;. The bulletins affect &lt;strong&gt;all versions of Windows.&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1755779" width="1" height="1"&gt;</description></item><item><title>Pushdo Botnet - New DDOS attacks on major web sites</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/02/02/pushdo-botnet-new-ddos-attacks-on-major-web-sites.aspx</link><pubDate>Tue, 02 Feb 2010 18:50:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754926</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754926</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/02/02/pushdo-botnet-new-ddos-attacks-on-major-web-sites.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; Fake SSL connection attacks are being flooded to several prominent websites.&amp;nbsp; DDOS attacks are an attempt to deny or greatly slow down access for legitimate users. Hopefully these attacks and the botnet itself will be shutdown. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pushdo Botnet - New DDOS attacks on major web sites&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/02/pushdocutwailpandex-botnet-attacking.html"&gt;http://sunbeltblog.blogspot.com/2010/02/pushdocutwailpandex-botnet-attacking.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=222600679"&gt;http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=222600679&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20100129"&gt;http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20100129&lt;/a&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8131"&gt;http://isc.sans.org/diary.html?storyid=8131&lt;/a&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8125"&gt;http://isc.sans.org/diary.html?storyid=8125&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt; &lt;strong&gt;MASTER LIST OF WEBSITES BEING ATTACKED&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.shadowserver.org/wiki/uploads/Calendar/pushdo_sites.txt"&gt;http://www.shadowserver.org/wiki/uploads/Calendar/pushdo_sites.txt&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; No one is sure why the Pushdo botnet is running a distributed denial-of-service-like attack against over 300 major web sites including the CIA, Mozilla labs, SANS and Twitter, according to the Shadowserver Foundation. Pushdo is also called Cutwail and Pandex.&lt;/p&gt;
&lt;p&gt;The botnet has been spewing initial SSL connection requests, causing servers to return an SSL negotiation error. The attacks don&amp;rsquo;t appear to be of sufficient intensity to knock any of the target sites off line and possible could be a mechanism to mask the botnet&amp;rsquo;s other traffic. SecureWorks said Pushdo is sending the SSL packets to&lt;strong&gt; port 443&lt;/strong&gt;. The botnet also uses that port for &lt;strong&gt;command-and-control traffic&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Last June, MessageLabs estimated that the Pushdo botnet, believed to be the &lt;strong&gt;world&amp;rsquo;s largest&lt;/strong&gt;, was comprised of &lt;strong&gt;1.5 to 2 million bots&lt;/strong&gt; that pumped out &lt;strong&gt;74 billion spam messages per day&lt;/strong&gt; (51 million per minute.) They said 14 percent of the bots were in Brazil, 14 percent in South Korea and 10 percent in the U.S.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754926" width="1" height="1"&gt;</description></item><item><title>Office 2010 Beta available for testing</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/02/02/office-2010-beta-available-for-testing.aspx</link><pubDate>Tue, 02 Feb 2010 13:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754876</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754876</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/02/02/office-2010-beta-available-for-testing.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; The Office 2010 Professional beta was successfully downloaded and installed on my primary PC at home.&amp;nbsp; Users experienced with Office 2007 should be able to use new version right away.&amp;nbsp;&amp;nbsp;&amp;nbsp;It is available after registering with Microsoft as the following site:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Office 2010 - Home Page&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/office/2010/en/default.aspx"&gt;http://www.microsoft.com/office/2010/en/default.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754876" width="1" height="1"&gt;</description></item><item><title>Facebook - 35% of users checked privacy settings</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/31/facebook-35-of-users-checked-privacy-settings.aspx</link><pubDate>Sun, 31 Jan 2010 16:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754592</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754592</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/31/facebook-35-of-users-checked-privacy-settings.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-47.gif" alt="Person" /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-47.gif" alt="Person" /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-47.gif" alt="Person" /&gt; Recently, Facebook launched a &lt;strong&gt;special security initiative&lt;/strong&gt; encouraging all users to check and improve their PRIVACY settings.&amp;nbsp; While a 35% compliancy is still low, the &lt;strong&gt;industry average is usually 5-10%&lt;/strong&gt;. All Facebook users should periodically check their security settings to ensure personal information is well protected.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Facebook - Only 35% of users have checked privacy settings&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/01/facebook-privacy-settings-35-percent.html"&gt;http://sunbeltblog.blogspot.com/2010/01/facebook-privacy-settings-35-percent.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mediabistro.com/baynewser/privacy/a_third_of_facebook_users_customized_their_privacy_settings_after_the_policy_changes_and_why_facebook_thinks_thats_a_good_thing_150409.asp"&gt;http://www.mediabistro.com/baynewser/privacy/a_third_of_facebook_users_customized_their_privacy_settings_after_the_policy_changes_and_why_facebook_thinks_thats_a_good_thing_150409.asp&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: At a privacy roundtable sponsored by the U.S. Federal Trade Commission in San Francisco, Facebook Director of Public Policy Tim Sparapani said that&lt;strong&gt; 35 percent of the 350 million Facebook users (that&amp;#39;s 122 million!) actually checked their privacy settings when Facebook suggested it in December.&lt;/strong&gt; The BayNewser, a San Francisco media news site, said Sparapani told their reporter that &amp;ldquo;the industry average for users&amp;#39; actively engaging with their settings is actually between 5-10 percent.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;DECEMBER 2009 - FACEBOOK PRIVACY INITIATIVE&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.facebook.com/privacy/explanation.php"&gt;http://www.facebook.com/privacy/explanation.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Sophos&amp;#39;s - Best Practices for Facebook security&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.sophos.com/security/best-practice/facebook/"&gt;http://www.sophos.com/security/best-practice/facebook/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754592" width="1" height="1"&gt;</description></item><item><title>Apple iPad announcement</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/30/apple-ipad-announcement.aspx</link><pubDate>Sat, 30 Jan 2010 13:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754486</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754486</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/30/apple-ipad-announcement.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; While tablet devices are mostly used for specialized purposes, the iPad has state-of-art hardware desgins.&amp;nbsp; It will interesting to follow future security developments, as well as innovative uses in home or office environments.&amp;nbsp; It can plug into a Mac or Windows PC via USB 2.0.&amp;nbsp; For Windows, it requires XP or higher as the Operating System &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Apple iPad - Home Page&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.apple.com/ipad/"&gt;http://www.apple.com/ipad/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.apple.com/ipad/features/"&gt;http://www.apple.com/ipad/features/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.apple.com/ipad/design/"&gt;http://www.apple.com/ipad/design/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.apple.com/ipad/specs/"&gt;http://www.apple.com/ipad/specs/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE: SPECIFICATIONS&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;LCD Display&lt;br /&gt;&lt;/strong&gt;9.7-inch (diagonal) LED-backlit &lt;br /&gt;glossy widescreen Multi-Touch display with IPS technology &lt;br /&gt;1024-by-768-pixel resolution at 132 pixels per inch (ppi) &lt;br /&gt;Fingerprint-resistant oleophobic coating &lt;br /&gt;Support for display of multiple languages and characters simultaneously &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;Capacity&lt;/strong&gt;&lt;br /&gt;16GB, &lt;br /&gt;32GB, &lt;br /&gt;64GB flash drive &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;Processor&lt;br /&gt;&lt;/strong&gt;1GHz Apple A4 custom-designed, &lt;br /&gt;high-performance, &lt;br /&gt;low-power &lt;br /&gt;system-on-a-chip&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;Audio playback&lt;/strong&gt;&lt;br /&gt;Frequency response: 20Hz to 20,000Hz &lt;br /&gt;Audio formats supported: AAC (16 to 320 Kbps)&lt;br /&gt;User-configurable maximum volume limit &lt;br /&gt;TV and video&lt;br /&gt;Support for 1024 by 768 pixels &lt;br /&gt;Dock Connector to VGA Adapter&lt;br /&gt;H.264 video up to 720p, 30 frames per second, &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt;&lt;strong&gt; Wireless and cellular&lt;/strong&gt;&lt;br /&gt;Wi-Fi model&lt;br /&gt;Wi-Fi (802.11a/b/g/n) &lt;br /&gt;Bluetooth 2.1 + EDR technology &lt;br /&gt;Wi-Fi + 3G model&lt;br /&gt;UMTS/HSDPA (850, 1900, 2100 MHz) &lt;br /&gt;GSM/EDGE (850, 900, 1800, 1900 MHz)&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;Input and output&lt;/strong&gt;&lt;br /&gt;Dock connector &lt;br /&gt;3.5-mm stereo headphone jack &lt;br /&gt;Built-in speaker &lt;br /&gt;Microphone &lt;br /&gt;SIM card tray (Wi-Fi + 3G model only) &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; &lt;strong&gt;Environmental &lt;br /&gt;&lt;/strong&gt;Arsenic-free display glass &lt;br /&gt;BFR-free &lt;br /&gt;Mercury-free LCD display &lt;br /&gt;PVC-free &lt;br /&gt;Recyclable aluminum and glass enclosure &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754486" width="1" height="1"&gt;</description></item><item><title>NMAP 5.21 PENTEST tool Release</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/30/nmap-5-21-pentest-tool-release.aspx</link><pubDate>Sat, 30 Jan 2010 13:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754484</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754484</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/30/nmap-5-21-pentest-tool-release.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Some minor issues surfaced with Nmap 5.20 and this release was quickly made to correct these problem areas. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;NMAP 5.21 - HOME PAGE&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://nmap.org/"&gt;http://nmap.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Nmap (&amp;quot;Network Mapper&amp;quot;) is a free and open source (license) utility for network exploration or security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap was named&lt;strong&gt; &amp;ldquo;Security Product of the Year&amp;rdquo;&lt;/strong&gt; by Linux Journal, Info World, LinuxQuestions.Org, and Codetalker Digest. &lt;/p&gt;
&lt;p&gt;New Version offers more than 150 significant improvements, including:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; 30+ new Nmap Scripting Engine scripts&lt;br /&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; enhanced performance and reduced memory consumption&lt;br /&gt;&amp;nbsp;o&amp;nbsp; protocol-specific payloads for more effectie UDP scanning&lt;br /&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; a completely rewritten traceroute engine&lt;br /&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; massive OS and version detection DB updates (10,000+ signatures)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754484" width="1" height="1"&gt;</description></item><item><title>InfoWorld - Security Tests of four major browsers</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/29/infoworld-security-tests-of-four-major-browsers.aspx</link><pubDate>Fri, 29 Jan 2010 16:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754403</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754403</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/29/infoworld-security-tests-of-four-major-browsers.aspx#comments</comments><description>&lt;p&gt;A series of informative articles reflecting security controls in four popular Windows browsers: &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Test Center: How secure is Internet Explorer?&lt;/strong&gt; &lt;br /&gt;[The world&amp;#39;s most popular browser is also the most frequently attacked, but comes with controls and management capabilities other browsers can&amp;#39;t match.]&lt;br /&gt;&lt;a href="http://www.infoworld.com/d/applications/test-center-how-secure-internet-explorer-343"&gt;http://www.infoworld.com/d/applications/test-center-how-secure-internet-explorer-343&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Test Center: How secure is Google Chrome?&lt;/strong&gt;&lt;br /&gt;[Google&amp;#39;s shiny new open source Web browser is a frustrating blend of excellent security model, questionable decisions, and a dearth of critical security controls.]&lt;br /&gt;&lt;a href="http://www.infoworld.com/t/applications/test-center-how-secure-google-chrome-443"&gt;http://www.infoworld.com/t/applications/test-center-how-secure-google-chrome-443&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Test Center: How secure is Firefox?&lt;br /&gt;&lt;/strong&gt;[Mozilla&amp;#39;s popular Web browser is long on user-friendly features and third-party extensions, and short on granular security controls.]&lt;br /&gt;&lt;a href="http://www.infoworld.com/d/security-central/test-center-how-secure-firefox-282"&gt;http://www.infoworld.com/d/security-central/test-center-how-secure-firefox-282&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Test Center: How secure is Opera?&lt;br /&gt;&lt;/strong&gt;[Opera Software&amp;#39;s underrated browser is rich in both features and granular security controls, but misses important Windows protections.]&lt;br /&gt;&lt;a href="http://www.infoworld.com/d/security-central/test-center-how-secure-opera-620"&gt;http://www.infoworld.com/d/security-central/test-center-how-secure-opera-620&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754403" width="1" height="1"&gt;</description></item><item><title>Windows Update - Reboot as soon as possible when prompted  </title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/29/windows-update-reboot-as-soon-as-possible-when-prompted.aspx</link><pubDate>Fri, 29 Jan 2010 14:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754389</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754389</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/29/windows-update-reboot-as-soon-as-possible-when-prompted.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; I see this incident more as a &amp;quot;lessons learned&amp;quot;, than a design flaw that millions of users are suffering with.&amp;nbsp; In the original post the Microsoft Update (MU) icon had been &lt;strong&gt;flashing for a few hours&lt;/strong&gt;.&amp;nbsp; Maybe a reboot could have taken place&lt;strong&gt; while at lunch or when taking a break at work&lt;/strong&gt;. Sometimes corporate group policies are indeed rigid and may not allow flexibilities for MU to just notify or download. Some &amp;quot;lessons learned&amp;quot; include:&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Reboot ASAP&lt;/strong&gt; - so that the&lt;strong&gt; new settings can take place immediately and avoid instability issues&lt;/strong&gt; that rebooting the applied updates would resolve.&amp;nbsp; Still, I&amp;#39;ve been in situations where I&amp;#39;ve had to delay reboots due to time sensitive work I had to accomplish.&amp;nbsp; However, when possible always reboot right away.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;When you see the Microsoft Update shield or prompts to reboot, &lt;strong&gt;SAVE all of your work right away&lt;/strong&gt; to prevent any loss of information.&amp;nbsp; I also start shutting down anything that&amp;#39;s non-essential in preparation for a reboot.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How I got attacked by Windows Update - Tales from the Evil Empire&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://weblogs.asp.net/bleroy/archive/2010/01/22/how-i-got-attacked-by-windows-update.aspx"&gt;http://weblogs.asp.net/bleroy/archive/2010/01/22/how-i-got-attacked-by-windows-update.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; I was writing a wiki page when it happened. The system restart dialog from Windows Update had been blinking helplessly in the task bar for a &lt;strong&gt;few hours&lt;/strong&gt; as I didn&amp;rsquo;t have time for a reboot yet. And then, right in the middle of a sentence, the effing dialog decides that I&amp;rsquo;ve been ignoring it for too long, puts itself in front and gives itself focus.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;You can see what happened then. My fingers were continuing to type, not realizing that the wiki page had gone to the back. Now the thing is, space is a fairly common key to hit when you&amp;rsquo;re writing English. But in dialogs, that&amp;rsquo;s also the key that triggers the default button. Which, in the case of that particular Windows Update dialog, is &amp;ldquo;&lt;strong&gt;Restart&lt;/strong&gt;&amp;rdquo;.&amp;nbsp; So before I realized what was going on,&lt;strong&gt; I was seeing all my windows close, including of course the wiki page I was working on.&lt;/strong&gt; No application should ever be allowed to steal the focus.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754389" width="1" height="1"&gt;</description></item><item><title>Kim Komando - You can't get rid of Internet Explorer</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/28/kim-komando-you-can-t-get-rid-of-internet-explorer.aspx</link><pubDate>Thu, 28 Jan 2010 17:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1754239</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1754239</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/28/kim-komando-you-can-t-get-rid-of-internet-explorer.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; This &amp;quot;tip of the day&amp;quot; provides key reasons why &lt;strong&gt;IE cannot be completely removed from Windows&lt;/strong&gt;.&amp;nbsp; Internet Explorer is more than just a browser, as other alternative browsers may occasionally use&amp;nbsp;IE APIs.&amp;nbsp; As shared in the article,&lt;strong&gt; move to IE8 for better overall security&lt;/strong&gt;, even when other browsers like Firefox, Opera, or Chrome are used exclusively.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kim Komando - You can&amp;#39;t get rid of Internet Explorer&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.komando.com/tips/index.aspx?id=8089"&gt;http://www.komando.com/tips/index.aspx?id=8089&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; There are &lt;strong&gt;good reasons to leave Internet Explorer on your computer.&lt;/strong&gt; And, in fact, you cannot remove it. It is an integral part of Windows. You can remove the icon if you want. But Internet Explorer will always be with you. So, &lt;strong&gt;it&amp;rsquo;s essential that you keep it updated.&lt;/strong&gt; That&amp;rsquo;s actually easy. Just set Windows for the most automatic updates possible. Then, let Microsoft take care of it. Also, be sure you&amp;rsquo;re using Internet Explorer 8. That is the safest version. There is no value in maintaining old versions of Internet Explorer. They simply make you more vulnerable to attacks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1754239" width="1" height="1"&gt;</description></item><item><title>Corporate Policies, Processes and Procedures</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/24/corporate-policies-processes-and-procedures.aspx</link><pubDate>Sun, 24 Jan 2010 14:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753473</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753473</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/24/corporate-policies-processes-and-procedures.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-47.gif" alt="Person" /&gt; The Internet Storm Center shares an excellent awareness on the need for companies to revisit their corporate policies to ensure they are up-to-date, relevant, and easy-to-understand.&amp;nbsp; This is just important, as technological defenses.&amp;nbsp; Both go hand-in-hand to protect the company.&amp;nbsp; Revisiting your security policies is an excellent&amp;nbsp;way to start the new decade.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Users need security rules and boundaries&lt;/strong&gt;, so that acceptable behavior and a reduction of risk occurs in the workplace.&amp;nbsp; Yes, there will some who march to the beat of a different drum and won&amp;#39;t comply.&amp;nbsp; Still, companies need to work with their users to promote the best in privacy, security, and information protection.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve enjoyed authoring these guidelines in the past.&amp;nbsp; Some ideas for success include:&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Design in&lt;strong&gt; positive terms&lt;/strong&gt; (minimize the &amp;quot;Thou shall not&amp;quot; statements, e.g., instead of &amp;quot;do not visit inappropriate sites&amp;quot; state as &amp;quot;users must visit business appropriate sites&amp;quot;).&amp;nbsp; This promotes better best practices and eventual buy-in by the users.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Use &lt;strong&gt;reasonable controls&lt;/strong&gt;&amp;nbsp;rather than absolute restrictions (e.g., avoid saying &amp;quot;absolutely no personal use of IT&amp;nbsp;resources&amp;quot; unless that is the desired policy and will be followed by all.&amp;nbsp; Don&amp;#39;t be too rigid or lenient in the design, so as to allow limited employee freedoms as long as there is a primary business use focus.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Use&lt;strong&gt; simplified language&lt;/strong&gt; to promote understanding by all (avoid legalize, highly technical terms, complex and/or sentence structures, etc)&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Monitor security policies and &lt;strong&gt;enforce them&lt;/strong&gt; (educate first time violators rather than making examples of them) &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Most importantly,&lt;strong&gt; publish them on your corporate Intranet&lt;/strong&gt; where they can be kept up-to-date easily and so they are can be easily accessed by all &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Publish &lt;strong&gt;company wide emails&lt;/strong&gt; when policies change&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&amp;nbsp;Ensure &lt;strong&gt;senior management, HR, and Legal Counsel&lt;/strong&gt; provide input, approve, and back these important guidelines&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Internet Storm Center - The necessary evils: Policies, Processes and Procedures&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8071"&gt;http://isc.sans.org/diary.html?storyid=8071&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: It is one that you can&amp;#39;t afford to overlook.&amp;nbsp; I have found time and time again that &lt;strong&gt;having good policies, processes and procedures keep you out of trouble&lt;/strong&gt; ... What ever the case, having good policies, processes and procedures will only make you and your organization better.&amp;nbsp; So, since its the beginning of a new year, take some time and update your policies and look at your processes and procedures.&amp;nbsp; Have they changed?&amp;nbsp; Do they need updating?&amp;nbsp; Are they even helpful?&amp;nbsp; &lt;strong&gt;Writing something for the sake of saying you have it is a waste of time.&lt;/strong&gt;&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753473" width="1" height="1"&gt;</description></item><item><title>PC Magazine review of AVAST Antivirus 5.0</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/pc-magazine-review-of-avast-antivirus-5-0.aspx</link><pubDate>Sun, 24 Jan 2010 03:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753406</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753406</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/pc-magazine-review-of-avast-antivirus-5-0.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; AVAST is a popular and free AV offering.&amp;nbsp; The latest version has just been reviewed by PC Magazine: &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PC Magazine Review of AVAST Antivirus 5.0&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://blogs.pcmag.com/securitywatch/2010/01/avast_free_antivirus_50.php"&gt;http://blogs.pcmag.com/securitywatch/2010/01/avast_free_antivirus_50.php&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pcmag.com/article2/0,2817,2358288,00.asp"&gt;http://www.pcmag.com/article2/0,2817,2358288,00.asp&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Bottom Line -- The new user interface of avast! free antivirus makes it easier to use, and its new technology eliminates more malware. This tool offers more control over settings and more detail in reporting than some of its free competitors.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pros &lt;/strong&gt;-- Improved user interface. New heuristic anti-malware engine. New code emulator technology. Powerful boot-time scan. Good malware removal. Effective malware blocking.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cons&lt;/strong&gt; -- Full scan and boot scan both take a long time. Some threats still present after supposed removal. Boot scan requires user interaction if threats found.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;strong&gt;ALWIL Software&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.avast.com"&gt;http://www.avast.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Type:&lt;/strong&gt; Personal &lt;br /&gt;&lt;strong&gt;Free:&lt;/strong&gt; Yes &lt;br /&gt;&lt;strong&gt;OS Compatibility:&lt;/strong&gt; Windows Vista, Windows XP, Windows 7 &lt;br /&gt;&lt;strong&gt;Tech Support:&lt;/strong&gt; Online technical support, knowledge base and activity community forum &lt;br /&gt;&lt;strong&gt;Notes:&lt;/strong&gt; Free for non-commercial use &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753406" width="1" height="1"&gt;</description></item><item><title>NMAP 5.20 PENTEST tool Released</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/nmap-5-20-pentest-tool-released.aspx</link><pubDate>Sun, 24 Jan 2010 01:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753394</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753394</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/nmap-5-20-pentest-tool-released.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Nmap is an excellent tool&amp;nbsp;for corporate PENTEST analysis ... New release is now available.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;NMAP 5.20 - HOME PAGE&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://nmap.org/"&gt;http://nmap.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Nmap (&amp;quot;Network Mapper&amp;quot;) is a &lt;strong&gt;free and open source&lt;/strong&gt; (license) utility for &lt;strong&gt;network exploration or security auditing&lt;/strong&gt;. Many systems and network administrators also find it useful for tasks such as &lt;strong&gt;network inventory, managing service upgrade schedules, and monitoring host or service uptime&lt;/strong&gt;. Nmap was named &amp;ldquo;&lt;strong&gt;Security Product of the Year&lt;/strong&gt;&amp;rdquo; by Linux Journal, Info World, LinuxQuestions.Org, and Codetalker Digest. &lt;/p&gt;
&lt;p&gt;New Version offers more than 150 significant improvements, including:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;o &amp;nbsp;&amp;nbsp;30+ new Nmap Scripting Engine scripts&lt;br /&gt;&amp;nbsp;o &amp;nbsp; enhanced performance and reduced memory consumption&lt;br /&gt;&amp;nbsp;o &amp;nbsp;protocol-specific payloads for more effectie UDP scanning&lt;br /&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; a completely rewritten traceroute engine&lt;br /&gt;&amp;nbsp;o&amp;nbsp;&amp;nbsp; massive OS and version detection DB updates (10,000+ signatures)&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753394" width="1" height="1"&gt;</description></item><item><title>SPECIAL FBI WARNING - Best practices to avoid fraudulent scams</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/special-fbi-warning-best-practices-to-avoid-fraudulent-scams.aspx</link><pubDate>Sat, 23 Jan 2010 13:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753300</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753300</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/special-fbi-warning-best-practices-to-avoid-fraudulent-scams.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; This is excellent advice to ensure your donations are received by those who are in need.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;SPECIAL FBI WARNING - Best practices to avoid scam attacks&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.fbi.gov/pressrel/pressrel10/haiti011810.htm"&gt;http://www.fbi.gov/pressrel/pressrel10/haiti011810.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Therefore, before making a donation of any kind, consumers should adhere to certain guidelines, including the following:&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Do not respond to any unsolicited (spam) incoming e-mails, including clicking links contained within those messages. &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Be skeptical of individuals representing themselves as surviving victims or officials asking for donations via e-mail or social networking sites. &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Beware of organizations with copy-cat names similar to but not exactly the same as those of reputable charities.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Rather than following a purported link to a website, verify the legitimacy of non-profit organizations by utilizing various Internet-based resources that may assist in confirming the group&amp;rsquo;s existence and its non-profit status. &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Be cautious of e-mails that claim to show pictures of the disaster areas in attached files, because the files may contain viruses. Only open attachments from known senders.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; To ensure contributions are received and used for intended purposes, make contributions directly to known organizations rather than relying on others to make the donation on your behalf. &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Do not be pressured into making contributions, as reputable charities do not use such tactics.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Do not give your personal or financial information to anyone who solicits contributions. Providing such information may compromise your identity and make you vulnerable to identity theft.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Avoid cash donations if possible. Pay by debit or credit card, or write a check directly to the charity. Do not make checks payable to individuals&lt;/p&gt;
&lt;p&gt;The FBI and the National Center for Disaster Fraud (NCDF) have established a telephone hotline to &lt;strong&gt;report suspected Haitian earthquake relief fraud&lt;/strong&gt;. The number is (866) 720-5721. The phone line is staffed by a live operator 24 hours a day, seven days a week. You can also e-mail information directly to &lt;a href="mailto:disaster@leo.gov"&gt;disaster@leo.gov&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753300" width="1" height="1"&gt;</description></item><item><title>New Haiti Scam - Appears to be spoofed message from our President</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/new-haiti-scam-appears-to-be-spoofed-message-from-our-president.aspx</link><pubDate>Sat, 23 Jan 2010 13:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753298</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753298</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/new-haiti-scam-appears-to-be-spoofed-message-from-our-president.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; AVERT Labs shares additional warnings related to spoofed email and websites regarding the tragedy in Haiti.&amp;nbsp; Please only donate to trusted sources directly, so that we can properly help those in need.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scams Take Advantage of Haiti Relief Efforts&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2010/01/22/scams-take-advantage-of-haiti-relief-efforts/"&gt;http://www.avertlabs.com/research/blog/index.php/2010/01/22/scams-take-advantage-of-haiti-relief-efforts/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Never is the &lt;strong&gt;heartless nature of cybercriminals&lt;/strong&gt; more apparent than in the wake of a tragedy. As relief efforts continue and worldwide aid pours in to help those affected by the earthquake that rocked Haiti on January 12, cybercriminals have not slowed their efforts. &lt;strong&gt;They are eager to get you to donate money that the people of Haiti will never see&lt;/strong&gt;. Spoofing legitimate relief organizations such as the Red Cross is a typical social engineering lure used by the bad guys to take your money. This morning, however, a particular scam caught my eye that I wanted to share with you. Its subject line was &amp;ldquo;&lt;strong&gt;Help for Haiti&lt;/strong&gt;&amp;rdquo; and was sent by &amp;ldquo;&lt;strong&gt;b.obama@whitehouse.gov&lt;/strong&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ADDITIONAL SCAMS&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2010/01/19/investigating-a-possible-charity-scam/"&gt;http://www.avertlabs.com/research/blog/index.php/2010/01/19/investigating-a-possible-charity-scam/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753298" width="1" height="1"&gt;</description></item><item><title>Sunbelt report - Users need to select stronger web passwords </title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/sunbelt-report-users-need-to-select-stronger-web-passwords.aspx</link><pubDate>Sat, 23 Jan 2010 13:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753296</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753296</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/sunbelt-report-users-need-to-select-stronger-web-passwords.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-36.gif" alt="Computer" /&gt; Please ensure web account use strong passwords, and especially for banking and e-commerce sites&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Web users still don&amp;rsquo;t select good passwords&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://www.imperva.com/docs/WP_Consumer_Password_Worst_Practices.pdf"&gt;http://www.imperva.com/docs/WP_Consumer_Password_Worst_Practices.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/01/web-users-still-dont-select-good.html"&gt;http://sunbeltblog.blogspot.com/2010/01/web-users-still-dont-select-good.html&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Key findings:&lt;/p&gt;
&lt;p&gt;&amp;raquo; About 30% of users chose passwords whose length is equal or &lt;strong&gt;below six characters&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;raquo; Moreover, almost 60% of users chose their passwords from a &lt;strong&gt;limited set of alpha-numeric characters&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;raquo; Nearly 50% of users used names, &lt;strong&gt;slang words, dictionary words or trivial passwords&lt;/strong&gt; (consecutive digits, adjacent keyboard keys, and so on). The most common password among Rockyou.com account owners is &amp;ldquo;123456&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Microsoft offers an FREE online facility to check the strength of passwords&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Online Safety -- Check your password &amp;mdash; is it strong? &lt;br /&gt;&lt;/strong&gt;&lt;a href="https://www.microsoft.com/protect/fraud/passwords/checker.aspx"&gt;https://www.microsoft.com/protect/fraud/passwords/checker.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753296" width="1" height="1"&gt;</description></item><item><title>Sunbelt reports 95% of email is spam for users in Europe </title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/sunbelt-reports-95-of-email-is-spam-for-users-in-europe.aspx</link><pubDate>Sat, 23 Jan 2010 12:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753295</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753295</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/sunbelt-reports-95-of-email-is-spam-for-users-in-europe.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-57.gif" alt="Email" /&gt; Despite efforts to shutdown a few spammers recently, these email attacks continue to present challenges to users everywhere.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Report from Europe: 95 percent of email is spam&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/01/report-from-europe-95-percent-of-email.html"&gt;http://sunbeltblog.blogspot.com/2010/01/report-from-europe-95-percent-of-email.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.enisa.europa.eu/media/press-releases/spam-survey-2009-the-fight-against-spam"&gt;http://www.enisa.europa.eu/media/press-releases/spam-survey-2009-the-fight-against-spam&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: The European Network and Information Security Agency (ENISA) has released a report that says &lt;strong&gt;95 percent of all email is now spam&lt;/strong&gt;. The report was based on surveying last year of email traffic by about 100 service providers in 30 countries&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753295" width="1" height="1"&gt;</description></item><item><title>MS10-002 Internet Explorer Security Update</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/ms10-002-internet-explorer-security-update.aspx</link><pubDate>Sat, 23 Jan 2010 12:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753294</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753294</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/ms10-002-internet-explorer-security-update.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Please apply this update expediently to better protect against malicious attacks and &lt;strong&gt;to fix 7 vulnerabilities in Internet Explorer&lt;/strong&gt;.&amp;nbsp; Users with automatic updates set to on, will be notified of this available update immediately (even though it is out-of-band with respect to the normal security updates offered on the 2nd Tuesday of the month, a.k.a., Patch Tuesday)&amp;nbsp;&amp;nbsp; So far, this is working well&amp;nbsp;on&amp;nbsp;IE8 at home and work.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Security Bulletin MS10-002 - Critical&lt;/strong&gt;&lt;br /&gt;Cumulative Security Update for Internet Explorer (978207)&lt;br /&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2010/01/21/bulletin-ms10-002-released.aspx"&gt;http://blogs.technet.com/msrc/archive/2010/01/21/bulletin-ms10-002-released.aspx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a &lt;strong&gt;user views a specially crafted Web page&lt;/strong&gt; using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This security &lt;strong&gt;update is rated Critical for all supported releases of Internet Explorer&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753294" width="1" height="1"&gt;</description></item><item><title>Adobe Flash Shockware security updates</title><link>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/adobe-flash-shockware-security-updates.aspx</link><pubDate>Sat, 23 Jan 2010 12:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1753291</guid><dc:creator>Harry Waldron</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/harrywaldron/rsscomments.aspx?PostID=1753291</wfw:commentRss><comments>http://msmvps.com/blogs/harrywaldron/archive/2010/01/23/adobe-flash-shockware-security-updates.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; Users should install the latest security updates to protect against malicious Shockwave objects circulating in websites. This process is usually invoked automatically and moving to latest version when prompted will better ensure safety when visiting websites.&amp;nbsp; There is also a manual update process as noted in solution information below.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;APSB10-02: Abobe PDF security updates&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html"&gt;http://www.adobe.com/support/security/bulletins/apsb10-03.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Macintosh operating systems. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations to the latest version using the instructions provided below.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution:&lt;/strong&gt; Adobe recommends Shockwave Player users uninstall Shockwave version 11.5.2.602 and earlier on their systems, restart their systems, and install Shockwave version 11.5.6.606, available here: &lt;/p&gt;
&lt;p&gt;&lt;a href="http://get.adobe.com/shockwave/"&gt;http://get.adobe.com/shockwave/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1753291" width="1" height="1"&gt;</description></item></channel></rss>