October 2004 - Posts

I bought a copy of Microsoft Voice Comand. It is really cool. I can tell the PPC to ring someone by name, and it does. I can say “Whats my next appointment” and it tells me. It does a few other things, like launch apps, play media, you can find out more on their site.

RSS Sync is a free RSS aggregator and viewer for the PPC. I like it because it is simple and straightforward.

 

Posted by Mark Dormer | with no comments
Great, I found some comment spam on the blog today. They attached to it to a post I had made about comment spam. Nice people.
Posted by Mark Dormer | with no comments

This new tool was released today - 12 Oct 2004

It checks for MS04-028

They support both a SMS and standalone version

For non SMS environments: http://support.microsoft.com/default.aspx?kbid=886988

For SMS: http://support.microsoft.com/kb/885920

Posted by Mark Dormer | with no comments
Filed under:

October Summary
http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx

Critical Bulletins:

MS04-032 - Security Update for microsoft Windows (840987)
http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx

MS04-033 - Vulnerability in microsoft Excel Could Allow Code Execution (886836)
http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx

MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code Execution (873376)
http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx

MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution (885881)
http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx

MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx

MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code Execution (841356)
http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx

MS04-038 - Cumulative Security Update for Internet Explorer (834707)
http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx

Important Bulletins:

MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information Disclosure and Denial of Service (873350)
http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx

MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler Could Lead to a Denial of Service (824151) http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx

MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution (841533)
http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx

Re-Released Bulletins:

MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)
http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx

This represents our regularly scheduled monthly bulletin release (second Tuesday of each month). Please note that microsoft may release bulletins out side of this schedule if we determine the need to do so.

Posted by Mark Dormer | with no comments
Filed under:

I found this page of tools today on the microsoft site. I am finding the Time Zone tool to be quite handy and the calculator is great for conversions.

http://www.microsoft.com/globaldev/outreach/dnloads/downloads.mspx

AppLocale
A utility that allows you to run legacy (code-page based) applications on your Windows XP or Server 2003, without changing the system locale.

European Union (EU) Screensaver
On May 1, 2004, the EU welcomed 10 new member states. See the flags of the new member states as well as those of the orignal 15 EU states.

microsoft Calculator Plus
This application allows you to complete many different types of conversions. It also includes all the mathematical functions offered in microsoft Calculator.

microsoft Keyboard Layout Creator
Want to create your own keyboard layout? Here's the tool from microsoft!

microsoft Time Zone Utility
This utility allows you to easily view the date and time in various locations around the world.

SMS Sender
Send SMS text messages from your PC to your friends' and family's GSM cellular phones.

Valentine's Day Screensaver
This screensaver was released in celebration of Valentine's Day 2004. Express your feelings on the PC of someone you love!

Posted by Mark Dormer | with no comments

microsoft ASP.NET ValidatePath Module has been released.

This is not the final security update.

It is an interim fix that will protect your webserver from all known (by microsoft) canoncalisation vulnerabilities

Posted by Mark Dormer | with no comments
Filed under:

Information is available here and will be updated when the security update is ready.

There is a KB article addressing the issue as well. Programmatically check for canonicalization issues with ASP.NET

Note: This vulnerability affects all versions of ASP.NET

Posted by Mark Dormer | with no comments
Filed under:

I was wondering how many had been released so I fired up Google and ran this search

The result is 522. Does that seem high?

How does it compare to Windows 2000 or XP

Now these results may have duplicates as I see some different language stuff in there, but it is a good indication of the numbers of bugfixes.

Posted by Mark Dormer | with no comments

In an earlier post I mentioned problems with the Time Service on Windows Server 2003

I applied the hotfix mentioned in W32Time frequently logs Event ID 50 and poor time synchronization occurs on Windows Server 2003 and the problem has been fixed.

Out of interest I did a search on Google for all hotfixes associated with the w32tm.exe, there were 224 of them.

Makes you wonder how hard it is to build a time service that works.

Posted by Mark Dormer | with no comments