<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>C#, VS Deployment and all geek talk : Security</title><link>http://msmvps.com/blogs/vipul/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL UPDATED</title><link>http://msmvps.com/blogs/vipul/archive/2005/08/18/63193.aspx</link><pubDate>Thu, 18 Aug 2005 14:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:63193</guid><dc:creator>Vipul Patel</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/vipul/rsscomments.aspx?PostID=63193</wfw:commentRss><comments>http://msmvps.com/blogs/vipul/archive/2005/08/18/63193.aspx#comments</comments><description>&lt;FONT size=2&gt;
&lt;P&gt;On 17 August 2005 the Microsoft Windows&lt;/P&gt;
&lt;P&gt;Malicious Software Removal Tool has been updated with added detection&lt;/P&gt;
&lt;P&gt;and cleaning capabilities for the following Malicious Software:&lt;/P&gt;
&lt;P&gt;* Zotob.A&lt;/P&gt;
&lt;P&gt;* Zotob.B&lt;/P&gt;
&lt;P&gt;* Zotob.C&lt;/P&gt;
&lt;P&gt;* Zotob.D&lt;/P&gt;
&lt;P&gt;* Zotob.E&lt;/P&gt;
&lt;P&gt;* Bobax.O&lt;/P&gt;
&lt;P&gt;* Esbot.A&lt;/P&gt;
&lt;P&gt;* Rbot.MA&lt;/P&gt;
&lt;P&gt;* Rbot.MB&lt;/P&gt;
&lt;P&gt;* Rbot.MC&lt;/P&gt;
&lt;P&gt;The updated version of the Microsoft Windows Malicious Software Removal&lt;/P&gt;
&lt;P&gt;Tool is available for download from the Download Center at this&lt;/P&gt;
&lt;P&gt;location:&lt;/P&gt;
&lt;P&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4"&gt;&lt;U&gt;&lt;FONT color=#0000ff size=2&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;amp;displaylang=enNOTE"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2&gt;F54-9AB3-75B8EB148356&amp;amp;displaylang=en&lt;/P&gt;
&lt;P&gt;NOTE&lt;/A&gt;: This updated version is currently NOT available on Windows Update,&lt;/P&gt;
&lt;P&gt;Microsoft Update or through Windows Server Update Services.&lt;/P&gt;
&lt;P&gt;More information on the Microsoft Windows Malicious Software Removal&lt;/P&gt;
&lt;P&gt;Tool is available here:&lt;/P&gt;
&lt;P&gt;&lt;/FONT&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=40573"&gt;&lt;U&gt;&lt;FONT color=#0000ff size=2&gt;http://go.microsoft.com/fwlink/?LinkId=40573&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=63193" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/vipul/archive/tags/Security/default.aspx">Security</category></item><item><title>Mydoom.bv (aka Bobax.AF) - An email flavor of MS05-039</title><link>http://msmvps.com/blogs/vipul/archive/2005/08/17/63134.aspx</link><pubDate>Wed, 17 Aug 2005 20:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:63134</guid><dc:creator>Vipul Patel</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/vipul/rsscomments.aspx?PostID=63134</wfw:commentRss><comments>http://msmvps.com/blogs/vipul/archive/2005/08/17/63134.aspx#comments</comments><description>&lt;FONT face=Arial size=2&gt;http://secunia.com/virus_information/20710/&lt;BR&gt;&lt;BR&gt;W32.Bobax.AF@mm is a mass-mailing worm that opens a back door, downloads remote files, and lowers security&lt;BR&gt;settings on the compromised computer. The worm spreads by exploiting the Microsoft Windows Plug and Play&lt;BR&gt;Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039) and by sending a copy of itself to email addresses gathered.&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=63134" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/vipul/archive/tags/Security/default.aspx">Security</category></item><item><title>Zotob Free Removal Tool offered by Symantec</title><link>http://msmvps.com/blogs/vipul/archive/2005/08/17/63131.aspx</link><pubDate>Wed, 17 Aug 2005 20:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:63131</guid><dc:creator>Vipul Patel</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/vipul/rsscomments.aspx?PostID=63131</wfw:commentRss><comments>http://msmvps.com/blogs/vipul/archive/2005/08/17/63131.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;A href="http://www.sarc.com/avcenter/venc/data/w32.zotob.removal.tool.html"&gt;http://www.sarc.com/avcenter/venc/data/w32.zotob.removal.tool.html&lt;/A&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;More about it at &lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FZOTOB%2EA"&gt;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FZOTOB%2EA&lt;/A&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=63131" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/vipul/archive/tags/Developer/default.aspx">Developer</category><category domain="http://msmvps.com/blogs/vipul/archive/tags/Security/default.aspx">Security</category></item><item><title>Random function flaw leads to 'Patient zero' </title><link>http://msmvps.com/blogs/vipul/archive/2005/05/27/49303.aspx</link><pubDate>Fri, 27 May 2005 21:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:49303</guid><dc:creator>Vipul Patel</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/vipul/rsscomments.aspx?PostID=49303</wfw:commentRss><comments>http://msmvps.com/blogs/vipul/archive/2005/05/27/49303.aspx#comments</comments><description>&lt;P&gt;The computer used to kick-start a global worm outbreak in March 2004 has been traced using crucial kinks in its code.&lt;/P&gt;
&lt;P&gt;The worm code involved using a random function to generate the next set of targets. Since Randon function provided by operating systems results in generating the same sequence of random numbers, by reverse tracing, the team of Nicholas Weaver and Vern Paxson from the University of California, Berkeley, and Abhishek Kumar from the Georgia Institute of Technology, painstakingly retraced its steps back to the first computer - or "patient zero" - of the outbreak.&lt;/P&gt;
&lt;P&gt;More details ate avilable at &lt;A href="http://www.newscientist.com/article.ns?id=dn7441&amp;amp;feedId=online-news_rss20"&gt;http://www.newscientist.com/article.ns?id=dn7441&amp;amp;feedId=online-news_rss20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Tip: Dont use the Rand function. Use special classes like CryptGenRandom in Windows : Source: &lt;A href="www.microsoft.com/mspress/books/5957.asp"&gt;Writing Secure code &lt;/A&gt;by &lt;A href="blogs.msdn.com/michael_howard/"&gt;Michael Howard &lt;/A&gt;, &lt;A href="www.microsoft.com/mspress/"&gt;MS Press&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=49303" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/vipul/archive/tags/C_2300_/default.aspx">C#</category><category domain="http://msmvps.com/blogs/vipul/archive/tags/Developer/default.aspx">Developer</category><category domain="http://msmvps.com/blogs/vipul/archive/tags/Security/default.aspx">Security</category></item></channel></rss>