<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results matching tag 'Security'</title><link>http://msmvps.com/search/SearchResults.aspx?q=&amp;tag=Security&amp;orTags=0&amp;o=DateDescending</link><description>Search results matching tag 'Security'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>I am a forum spammer! Delete my account immediately!!</title><link>/http://sqlserver-qa.net/blogs/el/archive/2009/10/26/6073.aspx</link><pubDate>Mon, 26 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735488</guid><dc:creator>Anonymous</dc:creator><description>The subject may look confusing that 1 part of it confirms its a forum spammer and another part to delete that account!!! Here is the email text that I have received highlighting valueable advice on security: *********** This email address was created solely to register automatically at thousands of forums for the purposes of spamming forums like yours. Remove my account and any other account registered with my email address, and strongly consider strengthening your forum&amp;#39;s password requirements....(&lt;a href="http://sqlserver-qa.net/blogs/el/archive/2009/10/26/6073.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://sqlserver-qa.net/aggbug.aspx?PostID=6073" width="1" height="1" alt="" /&gt;</description></item><item><title>Some of the .NET patch install suggestions....</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/21/some-of-the-net-patch-install-suggestions.aspx</link><pubDate>Wed, 21 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734173</guid><dc:creator>bradley</dc:creator><description>&lt;p&gt;Some of the .NET patch install suggestions....&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Newsgroups: microsoft.public.windowsupdate&lt;br /&gt;References: &amp;lt;OSBXnxGTKHA.4360@TK2MSFTNGP04.phx.gbl&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;quot;Shawn E. Hale&amp;quot; &lt;br /&gt;&amp;nbsp;news:OSBXnxGTKHA.4360@TK2MSFTNGP04.phx.gbl...&lt;br /&gt;&amp;nbsp; &amp;nbsp;&lt;br /&gt;All other updates released this date installed fine with the &lt;br /&gt;exception of KB953297.&amp;nbsp; Another home computer installed this update&lt;br /&gt;with no problem.&lt;br /&gt;&lt;br /&gt;The only difference I can find is that the computer where the install&lt;br /&gt;failed had .NET Framework 1.1 Hotfix KB928366 installed.&amp;nbsp; The article&lt;br /&gt;(http://support.microsoft.com/kb/953297) states that this recent &lt;br /&gt;update &amp;quot;supersedes&amp;quot; the hotfix.&amp;nbsp; I tried to uninstall the hotfix but &lt;br /&gt;that lead to another problem where it could not find the &amp;quot;netfx.msi&amp;quot;&lt;br /&gt;file to continue.&lt;br /&gt;&lt;br /&gt;So I stopped that hoping to find another answer here.&amp;nbsp; Any thoughts &lt;br /&gt;on what I should do?&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;br /&gt;I had the same problem, all 100pc&amp;#39;s on the network were failing (due, &lt;br /&gt;I think, to previously installed Visual Studio .Net apps, which &lt;br /&gt;updated dot net).&amp;nbsp; It appears that the installer is referencing a &lt;br /&gt;registry key to find the location of the netfx.msi file.&amp;nbsp; When it &lt;br /&gt;fails to find the file it errors out.&lt;br /&gt;&lt;br /&gt;I grabbed the dotnetfx.exe file from&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=a8f5654f-088e-40b2-bbdb-a83353618b38&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=a8f5654f-088e-40b2-bbdb-a83353618b38&amp;amp;displaylang=en&lt;/a&gt; ,&lt;br /&gt;opened it with WinRAR (or use any comprssion program) and extracted &lt;br /&gt;the netfx.msi to our network.&amp;nbsp; I then entered the network location &lt;br /&gt;into the registry key &lt;br /&gt;[HKEY_CLASSES_ROOT\Installer\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\SourceList\Net] &amp;quot;1&amp;quot;=hex(2):&amp;lt;long hex string you will need to change to your netfx.msi location&lt;br /&gt;&lt;br /&gt;Then I re-ran the updates and it installed fine.&lt;br /&gt;&lt;br /&gt;Hope this helps someone,&lt;br /&gt;Box&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Online advertising regaining momentum</title><link>http://msmvps.com/blogs/siljaline/archive/2009/10/21/online-advertising-regaining-momentum.aspx</link><pubDate>Wed, 21 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734030</guid><dc:creator>siljaline</dc:creator><description>&lt;p&gt;After bogging down in the recession, internet advertising is regaining the momentum that has made it the decade&amp;#39;s most disruptive marketing machine.&lt;/p&gt;
&lt;p&gt;The signs of an online revival are emerging even while advertising in print and broadcasts remains in a slump that has triggered mass layoffs, pay cuts and other upheaval.&lt;/p&gt;
&lt;p&gt;Internet advertising was just about the only bright spot in the third-quarter reports of two major U.S. newspaper publishers, Gannett Co. and McClatchy Co.&lt;/p&gt;
&lt;p&gt;Meanwhile, the companies still are dealing with steep declines in print ads &amp;mdash; an imbalance most analysts predict will take years to address.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;More:&lt;/strong&gt; &amp;nbsp;&lt;a href="http://www.cbc.ca/technology/story/2009/10/21/online-advertising-rebound.html"&gt;http://www.cbc.ca/technology/story/2009/10/21/online-advertising-rebound.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Social engineering at it's finest</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/19/social-engineering-at-it-s-finest.aspx</link><pubDate>Mon, 19 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1733599</guid><dc:creator>bradley</dc:creator><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5417.warning.PNG"&gt;&lt;img border="0" src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5417.warning.PNG" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;They are starting to spoof &amp;quot;upgrade&amp;quot; emails very nicely these days.&amp;nbsp; Warn your customers that no upgrades will be emailed to them.&lt;/p&gt;
&lt;p&gt;Inform them of exactly HOW you do updates and how you will not email them links like this.&amp;nbsp; Set in place a process for how you inform folks of needed actions and ensure communication is done in such a manner that they know you are you and spoofs like this can&amp;#39;t happen.&lt;/p&gt;</description></item><item><title>Adobe Patched L&amp;#252;cke in Acrobat Reader 9.1.x</title><link>http://msmvps.com/blogs/wstein/archive/2009/10/16/adobe-patched-l-252-cke-in-acrobat-reader-9-1-x.aspx</link><pubDate>Fri, 16 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732720</guid><dc:creator>Wstein</dc:creator><description>&lt;p&gt;neben dem Microsoft Patchday gab auch Adobe ein &lt;a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank"&gt;Update für den Adobe Reader&lt;/a&gt; heraus. Dieses Update schließt Lücken über die DOS – Angriffe oder verschiedene Buffer overflows ausgeführt werden können. Das Update sollte unbedingt eingespielt werden, der Adobe Reader hat dann die Versionsnummer 9.2.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/wstein.metablogapi/4705.Adobe92_5F00_51FC729A.png"&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="Adobe 92" border="0" alt="Adobe 92" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/wstein.metablogapi/2664.Adobe92_5F00_thumb_5F00_21F22119.png" width="244" height="122" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Viele Grüße&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Walter Steinsdorfer&lt;/p&gt;</description></item><item><title>One of the promised land issues in cloud deployments is that you never have to worry about upgrades.</title><link>http://msmvps.com/blogs/sbsdiva/archive/2009/10/15/one-of-the-promised-land-issues-in-cloud-deployments-is-that-you-never-have-to-worry-about-upgrades.aspx</link><pubDate>Thu, 15 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732498</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;&lt;em&gt;Obligatory cloud paranoia post to justify the Mac Book from &lt;/em&gt;&lt;a href="http://www.vladville.com"&gt;&lt;em&gt;www.vladville.com&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;One of the promised land issues in cloud deployments is that you never have to worry about upgrades.&lt;br /&gt;&lt;br /&gt;The reality is vastly different.&amp;nbsp; Just ask the &lt;a href="http://blog.seattlepi.com/microsoft/archives/182114.asp"&gt;Sidekick folks&lt;/a&gt; about how well upgrades go.&amp;nbsp; And on the Google doc front, just because someone else updates doesn&amp;#39;t mean that the problems go away...&lt;/p&gt;
&lt;p&gt;Bugs hit Google Docs after recent upgrade: &lt;br /&gt;&lt;a href="http://www.computerworld.com/s/article/9139350/Bugs_hit_Google_Docs_after_recent_upgrade"&gt;http://www.computerworld.com/s/article/9139350/Bugs_hit_Google_Docs_after_recent_upgrade&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Bottom line, I don&amp;#39;t care how big or small you are, there are risks in updating.&amp;nbsp; Period.&amp;nbsp; Whether we do it, he does it, they do it, we all deal with the resulting aftermath.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732494" width="1" height="1" alt="" /&gt;</description></item><item><title>A big, big, big sigh</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/15/a-big-big-big-sigh.aspx</link><pubDate>Thu, 15 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732664</guid><dc:creator>bradley</dc:creator><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Jerome Chout : Do not apply KB974571 to LCS/OCS Servers: &lt;br /&gt;&lt;a href="http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx"&gt;http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is one of those patch testing moments that you just shake your head and wonder who was asleep at the wheel here.&amp;nbsp; Just for grins I installed 974571 on my Live Communication Server 2005.&amp;nbsp; The minute you reboot the box, the internal IM dies and refuses to log in, the LCS server service fails to start.&amp;nbsp;&amp;nbsp; When you log into the box and check the event viewer, it&amp;#39;s very obvious that LCS is having a problem.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;There are times that I know that it&amp;#39;s hard to find patch issues.&amp;nbsp; We have a lot of software, we have a corner issues.&amp;nbsp; This one... this is a big fat ooops that implies to me that someone somewhere didn&amp;#39;t do a basic job of testing.&lt;/p&gt;
&lt;p&gt;This is why I have the &amp;quot;canary plan&amp;quot; where I test patches first before installing them.&amp;nbsp; This is why i know patches can be uninstalled.&amp;nbsp; This why we don&amp;#39;t have automatic updates on.&lt;/p&gt;
&lt;p&gt;In my opinion, this one should not have gotten out the door like this.&amp;nbsp; And when one does, it impacts patch trust.&lt;/p&gt;
&lt;p&gt;And for me, that&amp;#39;s a big big sigh.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>A big, big, big sigh</title><link>http://msmvps.com/blogs/sbsdiva/archive/2009/10/15/a-big-big-big-sigh.aspx</link><pubDate>Thu, 15 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732665</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Jerome Chout : Do not apply KB974571 to LCS/OCS Servers: &lt;br /&gt;&lt;a href="http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx"&gt;http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is one of those patch testing moments that you just shake your head and wonder who was asleep at the wheel here.&amp;nbsp; Just for grins I installed 974571 on my Live Communication Server 2005.&amp;nbsp; The minute you reboot the box, the internal IM dies and refuses to log in, the LCS server service fails to start.&amp;nbsp;&amp;nbsp; When you log into the box and check the event viewer, it&amp;#39;s very obvious that LCS is having a problem.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;There are times that I know that it&amp;#39;s hard to find patch issues.&amp;nbsp; We have a lot of software, we have a corner issues.&amp;nbsp; This one... this is a big fat ooops that implies to me that someone somewhere didn&amp;#39;t do a basic job of testing.&lt;/p&gt;
&lt;p&gt;This is why I have the &amp;quot;canary plan&amp;quot; where I test patches first before installing them.&amp;nbsp; This is why i know patches can be uninstalled.&amp;nbsp; This why we don&amp;#39;t have automatic updates on.&lt;/p&gt;
&lt;p&gt;In my opinion, this one should not have gotten out the door like this.&amp;nbsp; And when one does, it impacts patch trust.&lt;/p&gt;
&lt;p&gt;And for me, that&amp;#39;s a big big sigh.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732664" width="1" height="1" alt="" /&gt;</description></item><item><title>Oktober Patchday!</title><link>http://msmvps.com/blogs/wstein/archive/2009/10/14/oktober-patchday.aspx</link><pubDate>Wed, 14 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732300</guid><dc:creator>Wstein</dc:creator><description>&lt;p&gt;es ist wieder soweit, Microsoft hat gestern abend wieder einige Sicherheitsupdates freigegeben. Das aktuelle Security Bulletin findet ihr unter &lt;a title="http://www.microsoft.com/germany/technet/sicherheit/bulletins/ms09-oct.mspx" href="http://www.microsoft.com/germany/technet/sicherheit/bulletins/ms09-oct.mspx"&gt;http://www.microsoft.com/germany/technet/sicherheit/bulletins/ms09-oct.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Es sind einige kritische Updates vorhanden die Remotecodeausführung verhindern, diese sollten unbedingt eingespielt werden. Insbesondere auf den SMB-Patch möchte ich verweisen, hier gibt es ja bereits Beispielcode wie die Lücke ausgenutzt werden kann. Wer diesen Patch nicht sofort einspielen möchte kann auch per Gruppenrichtlinie SMBv2 ausschalten (siehe Screenshot).&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/wstein.metablogapi/3644.SMBv2disable_5F00_55E7D9E6.png"&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;margin-left:0px;border-top:0px;margin-right:0px;border-right:0px;" title="SMBv2 disable" border="0" alt="SMBv2 disable" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/wstein.metablogapi/7444.SMBv2disable_5F00_thumb_5F00_3ACF0AD8.png" width="220" height="244" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Viele Grüße&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Walter Steinsdorfer&lt;/p&gt;</description></item><item><title>Things to read, things to watch</title><link>http://msmvps.com/blogs/sbsdiva/archive/2009/10/14/things-to-read-things-to-watch.aspx</link><pubDate>Wed, 14 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732275</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Things to watch tonight -- &lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv"&gt;http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Things to read tonight -- &lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx"&gt;http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7345"&gt;http://isc.sans.org/diary.html?storyid=7345&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx"&gt;Assessing the risk of the October security bulletins&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx"&gt;MS09-051: A note on the affected platforms&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx"&gt;MS09-050: Exploit timeline for SMB2 RCE vulnerability&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx"&gt;MS09-054: Extra info on the attack surface for the IE security bulletin&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx"&gt;MS09-061: More information about the .NET security bulletin&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx"&gt;Scanti-ly Clad &amp;ndash; Another Rogue Stripped by MSRT&lt;/a&gt; &amp;ndash; Microsoft Malware Protection Center blog &lt;/p&gt;
&lt;p&gt;And I already had to pull this one - &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;974417"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;974417&lt;/a&gt;&amp;nbsp;off the blog site as it was causing the site to resolve very poorly.&amp;nbsp; I&amp;#39;ll be calling into Microsoft support tomorrow (or rather emailing in) but when something worked before, and now it doesn&amp;#39;t, sometimes don&amp;#39;t do a &amp;quot;system rollback&amp;quot;, think about which patch may be the trigger and pull off just that one.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732274" width="1" height="1" alt="" /&gt;</description></item></channel></rss>