<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jesper Johansson's Blog : Security</title><link>http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Passwords are here to stay</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/11/passwords-are-here-to-stay.aspx</link><pubDate>Sun, 11 Oct 2009 05:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1731533</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>At least for the short to medium term. That is the, quite obvious, conclusion drawn in a Newsweek article entitled &amp;quot;Building a Better Password.&amp;quot; The article goes inside the CyLab at Carnegie-Mellon University to understand how passwords may...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/11/passwords-are-here-to-stay.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1731533" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>And finally, standard user malware</title><link>http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx</link><pubDate>Tue, 01 Sep 2009 06:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1719824</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Today I finally got wind of my first piece of true standard user malware. MS Antispyware 2008 has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\&amp;lt;something&amp;gt;, and makes...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1719824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Least+Privilege/default.aspx">Least Privilege</category></item><item><title>Please do not e-mail my social security number</title><link>http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx</link><pubDate>Wed, 28 Jan 2009 05:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1666496</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Recently I had a very interesting incident. I wrote an article some time in 2008 and the publisher paid me a little bit of money for it. That means the publisher must send a report to the Internal Revenue Service (IRS - the U.S. tax department) reporting...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1666496" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Is MS08-067 Wormable?</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/04/is-ms08-067-wormable.aspx</link><pubDate>Tue, 04 Nov 2008 12:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1653027</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>A couple of weeks ago Microsoft released an out-of-band security update in bulletin MS08-067 . Looking at the type of vulnerability and the fact that the issue was already being exploited in the wild at the time, this was a good decision. If you have...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/04/is-ms08-067-wormable.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1653027" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Anatomy of a Hack 2008</title><link>http://msmvps.com/blogs/jesper/archive/2008/08/22/anatomy-of-a-hack-2008.aspx</link><pubDate>Fri, 22 Aug 2008 21:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645559</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>A few years ago I delivered a very popular presentation I called &amp;quot;Anatomy of a Hack.&amp;quot; Well, actually, I called it &amp;quot;How to Get Your Network Hacked in 10 Easy Steps&amp;quot; but the marketing department at my previous employer thought that title...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/08/22/anatomy-of-a-hack-2008.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645559" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Buy the original Olympic Torch from Beijing</title><link>http://msmvps.com/blogs/jesper/archive/2008/08/08/buy-the-original-olympic-torch-from-beijing.aspx</link><pubDate>Sat, 09 Aug 2008 03:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644063</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>&amp;quot;Buy the original Olympic Torch from Beijing&amp;quot; That was one of the fake headlines in the latest &amp;quot;CNN.com Daily Top 10&amp;quot; malware spam I&amp;#39;ve been getting lately. This particular spam is a fake newsfeed which redirects you to one of...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/08/08/buy-the-original-olympic-torch-from-beijing.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644063" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>Phishing for a Tax Refund</title><link>http://msmvps.com/blogs/jesper/archive/2008/05/04/phishing-for-a-tax-refund.aspx</link><pubDate>Mon, 05 May 2008 04:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1613701</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>What&amp;#39;s wrong with this picture? If you answered &amp;quot;why would the IRS use a web server in Korea to ask for information about my tax refund&amp;quot; you are a winner! This is a phishing site preying on people who do not know that all you need to do...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/05/04/phishing-for-a-tax-refund.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1613701" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category></item><item><title>Mitigate the Image Uploader Vulnerabilities</title><link>http://msmvps.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx</link><pubDate>Wed, 06 Feb 2008 19:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1500076</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The big security news this week is the six vulnerabilities found in various image uploader ActiveX controls. In case you haven&amp;#39;t seen the news , there are exploits available publicly for remote vulnerabilities in five different ActiveX controls. US...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1500076" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Mitigations/default.aspx">Mitigations</category></item><item><title>Using Autoplay on Vista To Stop Attacks</title><link>http://msmvps.com/blogs/jesper/archive/2007/12/23/using-autoplay-on-vista-to-stop-attacks.aspx</link><pubDate>Sun, 23 Dec 2007 18:41:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1414520</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The January issue of TechNet Magazine has an article I wrote about how to hack a system using autoplaying USB flash drives. While it is not possible to stop all attacks from USB tokens, Vista does include some interesting protective measures. However...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2007/12/23/using-autoplay-on-vista-to-stop-attacks.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1414520" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Running+Windows/default.aspx">Running Windows</category></item><item><title>Is Firefox More Secure than Internet Explorer?</title><link>http://msmvps.com/blogs/jesper/archive/2007/11/30/is-firefox-more-secure-than-internet-explorer.aspx</link><pubDate>Fri, 30 Nov 2007 20:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1408385</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Well, sure it is. According to the Firefox web site, which must of course be untainted by marketing claims since it is Mozilla, &amp;quot; Firefox continues to lead the way in online security&amp;quot;. OK, marketing hyperbole aside, I&amp;#39;m a data guy. I care...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2007/11/30/is-firefox-more-secure-than-internet-explorer.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1408385" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Software+Development/default.aspx">Software Development</category></item><item><title>What They Teach Kids These Days</title><link>http://msmvps.com/blogs/jesper/archive/2007/09/03/what-they-teach-kids-these-days.aspx</link><pubDate>Mon, 03 Sep 2007 20:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1408395</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Sweden has always been a little &amp;quot;cutting edge,&amp;quot; if you know what I mean. Little did I know, however, just how cutting edge. This picture was snapped in a toy store in Stockholm last week: I probably stood there stunned for a good two minutes...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2007/09/03/what-they-teach-kids-these-days.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1408395" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item></channel></rss>