Tag Archives: Security
Phishing and Wardriving
Attacks, Exploits and Patches
Widespread Web Site Attacks Reported Following the reports of high profile web sites like syfy.com and php-nuke.org being compromised, another widespread attack on web servers has been reported. The attacks compromise sites running WordPress and other popular blog software. The attack mechanism is not yet known, but clients should ensure that the latest WordPress version [...]
Password Complexity Trick
I just read http://lifehacker.com/5516188/shift-your-fingers-one-key-to-the-right-for-easy+to+remember-but-awesome-passwords and it makes sense to help create complex passwords. I’ve read One Man’s blog, where John talks about guessing or brute force attacking to hack your password. The introduction of special characters dramatically increases the time it takes for an automated program to try and guess your password. John writes about [...]
April Patches and Updates
1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP Service (MS10-024 CVE-2010-0024) Microsoft Windows SMTP Service and Microsoft Exchange are vulnerable to a denial of service, caused by the improper handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer Protocol component. As SMTP services are often exposed to the [...]
Top Tips for Twenty Ten
Rules of Social Networking Pay attention to what you post and upload. Social networking is public. Consider images, videos, and information you publish You shouldn’t publish your address, date of birth, etc. Use a nick-name that only your friends know. Choose your friends with care. Do not accept friend requests from people you do not [...]
Why Strong Passwords Are Important
Most systems out in the world are secure. Very secure. Thousands of administrators and technical personnel apply patches and configurations to millions of systems throughout the world on a daily basis. In August 2009, someone hacked into Google, but not through a technical vulnerability within the Google infrastructure. A hacker found a personal email account. [...]
New Vulnerabilities and Fixes
MS10-002
Microsoft has released MS10-002 today. The update addresses 7 privately reported and 1 publicly reported vulnerability which is associated with the widely publicized attacks associated with Security Advisory 979352. There are four (4) Uninitialized Memory Corruption Vulnerabilities, two (2) HTML Object Memory Corruption Vulnerabilities, one (1) XSS Filter Script Handling Vulnerability, and one (1) URL [...]
Security Report
Microsoft Announces out of cycle Security Update schedule Microsoft issued their Advanced Notification Service (ANS) notification to inform customers of the impending release of MS10-002 on January 21st, 2010. The update will be cumulative, in advance of the normal February release Cycle, and is intended to protect customers from the known, widely publicized attacks associated [...]
