Uncategorized

Scot’s Newsletter, his forums and a discussion of XP services

Another newsletter I subscribe to is Scot’s Newsletter. It’s usually pretty long but every so often there’s a real gem in it. The June 17, 2003 issue has a link to one of Scot’s Forums that discusses XP services. The forum postings have some good links to sites that explain what service does what, which services you can shutdown and so on. Here’s a link to the forum:
http://www.scotsnewsletter.com/forums/index.php?act=ST&f=4&t=1271&s=.

Scot’s Newsletter, his forums and a discussion of XP services Read More »

Chris Pirillo and Lockergnome Windows Daily

Since parting company with TechTV, Chris has stepped up promotion promotion of his properties — GnomeTomes, GnomeDex, and his new GnomeForums to name a few — and it gets a little tiresome. Still, a guy’s gotta make a living so I’ll cut him a little slack. Anyway, his Lockergnome Windows Daily still comes up with some useful tidbits. The 6/16/2003 issue tells about Drivers Collection — a site that lets you search for drivers by vendor or product category.

Chris Pirillo and Lockergnome Windows Daily Read More »

BlackICE filter bypass

Another security advisory from Secunia, this time about BlackICE. You can see the advisory at http://www.secunia.com/advisories/9058/. In short, I guess BlackICE is supposed to protect the PC against Cross Site Scripting attacks (the thing that’s been in a lot of the newer advisories of late). It apparently doesn’t check for some small subset of HTTP requests. Their solution isn’t too helpful … it basically comes down to “be careful out there.”

BlackICE filter bypass Read More »

Another IE Cross-site scripting vulnerability …

I dunno, this is listed by Secunia as “moderately critical” but I think the probability of it happening is pretty low if you’re careful about what sites you visit as it first requires the site operator to take you to an error page first and then you must click on a link provided by the malicious site operator.

Secunia has what they call a fix but I consider it a workaround and it requires you to edit the registry. The Secunia advisory is at http://www.secunia.com/advisories/9056/ and gives you a link to the original security notice by GreyMagic which contains a much better explanation than what I gave. Make up your own mind.

Another IE Cross-site scripting vulnerability … Read More »

New Trojan or paranoia in action?

Story’s at http://www.eweek.com/article2/0,3959,1126751,00.asp. Here’s the deal: they say a compromised system listens for packets of size 55,808. Supposedly there’s another system (systems?) out there that are sending TCP SYN packets to random IP addresses at a speed that will allow them to hit 90% of the Internet’s addresses in 24 hours (!! — that’s gotta be FAST! — there’re a LOT of addresses out there). They don’t know what the compromised systems will do or what kind of information they’ll leak so they can’t say what’s up with this new trojan/virus. You gotta admit, though, this is a weird one!

Read the article. Decide for yourself.

New Trojan or paranoia in action? Read More »