<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>forkb0mb.org - Windows</title>
    <link>http://forkb0mb.org/content/</link>
    <description>Still Watching Bits in a Terabyte World</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.4.1 - http://www.s9y.org/</generator>
    
    

<item>
    <title>TSA Withdraws Subpoenas Against Bloggers</title>
    <link>http://forkb0mb.org/content/index.php?/archives/355-TSA-Withdraws-Subpoenas-Against-Bloggers.html</link>
            <category>Cryptography/Privacy</category>
            <category>Linux</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Unix</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/355-TSA-Withdraws-Subpoenas-Against-Bloggers.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=355</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=355</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.wired.com/threatlevel/2009/12/tsa-withdraws-subpoenas/&quot; title=&quot;http://www.wired.com/threatlevel/2009/12/tsa-withdraws-subpoenas/&quot;&gt;TSA Withdraws Subpoenas Against Bloggers&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
In the wake of public outcry against the Transportation Security Administration for serving civil subpoenas on two bloggers, the government agency has canceled the legal action and apologized for the strong-arm tactics agents used.&lt;br /&gt;
&lt;br /&gt;
Travel writer and photographer Steven Frischling, who was &lt;a href=&quot;http://www.wired.com/threatlevel/2009/12/dhs-threatens-blogger/&quot; title=&quot;http://www.wired.com/threatlevel/2009/12/dhs-threatens-blogger/&quot;&gt;served with a subpoena&lt;/a&gt; by two TSA agents on Tuesday, told &lt;a href=&quot;http://www.wired.com/threatlevel/&quot; title=&quot;http://www.wired.com/threatlevel/&quot;&gt;Threat Level&lt;/a&gt; that he received a phone call Thursday evening from John Drennan, deputy chief counsel for enforcement at TSA, telling him the administration was withdrawing its subpoena.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&quot;Strong-arm tactics;&quot; couldn&#039;t have said it better myself.   I&#039;m glad to hear that, given the publicity, they decided that they didn&#039;t want the negative PR and would do The Right Thing(tm).  If only every case of over-reaching abuse of power could get this level of publicity.  Sadly, people&#039;s privacy rights are trampled nearly every day, it just doesn&#039;t get the press that this case did.&lt;br /&gt;
&lt;br /&gt;
In case you missed it, &lt;a href=&quot;http://slashdot.org/&quot; title=&quot;http://slashdot.org/&quot;&gt;Slashdot&lt;/a&gt; linked to an article on the New York Times regarding the TSA subpoenas entitled &quot;&lt;a href=&quot;http://www.nytimes.com/aponline/2009/12/30/us/politics/AP-US-Airliner-Attack-TSA-Supoenas.html?_r=1&quot; title=&quot;http://www.nytimes.com/aponline/2009/12/30/us/politics/AP-US-Airliner-Attack-TSA-Supoenas.html?_r=1&quot;&gt;TSA Subpoenas Bloggers, Demands Names of Sources&lt;/a&gt;&quot;.  You may want to read it first to familiarize yourself with the issue before reading the article about the TSA withdrawing the subpoenas.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
A second blogger who was also served a subpoena on Tuesday, &lt;a href=&quot;http://www.elliott.org/&quot; title=&quot;http://www.elliott.org/&quot;&gt;Christopher Elliott&lt;/a&gt;, was also told his subpoena was being withdrawn. Elliott had refused to cooperate with the agent who served him the subpoena and had indicated to the TSA that he would be challenging the subpoena in federal court next week.&lt;br /&gt;
&lt;br /&gt;
..&lt;br /&gt;
&lt;br /&gt;
Frischling said the two agents who visited him arrived around 7 p.m. Tuesday, were armed and threatened him with a criminal search warrant if he didn’t provide the name of his source. They also indicated they could get him designated a security risk, which would make it difficult for him to travel and do his job.&lt;br /&gt;
&lt;br /&gt;
&quot;They came to the door and immediately were asking, &#039;Who gave you this document?, Why did you publish the document?&#039; and &#039;I don’t think you know how much trouble you’re in.&#039; It was very much a hardball tactic,&quot; he told Threat Level.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
So much for the First Amendment which includes freedom of the press.  Granted, he was not obligated under any law to turn over the name(s) of his source(s), but they made it clear that if he did not cooperate, they would make his life unnecessarily difficult.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The agents searched through Frischling’s BlackBerry and iPhone and questioned him about a number of phone numbers and messages in the devices.&lt;br /&gt;
&lt;br /&gt;
The agents then tried to image his hard drive, but were unable to do so.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
There goes the Fourth Amendment, as well.  The Fourth Amendment states, and I quote:  &quot;The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, ...&quot;&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I have the utmost respect for those who protect us from would-be attackers; I just feel that they go about it in the wrong way and overstep their boundaries.  The TSA, CIA, NSA, FBI, and ATF have to be right every single time; while an attacker only needs to be right 1 time to be effective.  That certainly makes the job of those who protect us very difficult.&lt;br /&gt;
&lt;br /&gt;
&quot;An ounce of prevention is worth a pound of cure&quot; is most certainly true; but it also doesn&#039;t make sense to use a cannon to kill a mosquito.&lt;br /&gt;
&lt;br /&gt;
If I were to be traveling, I would use the internet to transfer all files to before heading to the airport, and use strong encryption on my hard drive.  That way, I am not entering the airport with any data on my computer, and anything left on the hard drive for the operating system and applications would be inaccessible due to the strong encryption.  Unfortunately, if they cannot access the data easily,  I believe the TSA has the ability (but I don&#039;t think the &lt;em&gt;right&lt;/em&gt;) to confiscate your laptop indefinitely.  If it takes them a thousand years to break your encryption and search your data - only to find nothing of use - you may never get your equipment back. Might I recommend &lt;a href=&quot;http://www.gnupg.org/&quot; title=&quot;http://www.gnupg.org/&quot;&gt;GPG&lt;/a&gt; (for files) and the Linux &lt;a href=&quot;http://en.wikipedia.org/wiki/Cryptoloop&quot; title=&quot;http://en.wikipedia.org/wiki/Cryptoloop&quot;&gt;cryptoloop&lt;/a&gt; driver (for file-systems - I recommend at least AES-256, if not AES-384, AES-512, or Twofish - all of which available in the Linux kernel)?  It appears that &lt;a href=&quot;http://www.freebsd.org/&quot; title=&quot;http://www.freebsd.org/&quot;&gt;FreeBSD&lt;/a&gt; also supports &lt;a href=&quot;http://www.freebsd.org/doc/en/books/handbook/disks-encrypting.html&quot; title=&quot;http://www.freebsd.org/doc/en/books/handbook/disks-encrypting.html&quot;&gt;encrypted partitions&lt;/a&gt;.  A Google search reveals several options for protecting your privacy on Windows; one appears to be a feature built into Windows XP, though I&#039;m not sure I&#039;d trust it to be free of back-doors.  If you&#039;re looking for free, you might look into &lt;a href=&quot;http://www.truecrypt.org/&quot; title=&quot;http://www.truecrypt.org/&quot;&gt;TrueCrypt&lt;/a&gt;.   DISCLAIMER:  I&#039;ve never used TrueCrypt myself, so I cannot comment on it&#039;s features.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 01 Jan 2010 18:04:50 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/355-guid.html</guid>
    
</item>
<item>
    <title>Miscellaneous Microsoft Docs</title>
    <link>http://forkb0mb.org/content/index.php?/archives/322-Miscellaneous-Microsoft-Docs.html</link>
            <category>Operating Systems</category>
            <category>Programming</category>
            <category>Tools</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/322-Miscellaneous-Microsoft-Docs.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=322</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=322</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    /*&lt;br /&gt;
Miscellaneous Microsoft Docs&lt;br /&gt;
&lt;br /&gt;
Occasionally I come across some Microsoft articles that are of use to myself or those I know.  I&#039;ve gathered a list of Windows Server 2K3 and IIS 6.0 commands and tools that will help in automating processes.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/ms957500.aspx&quot;  title=&quot;http://msdn.microsoft.com/en-us/library/ms957500.aspx&quot;&gt;How to Restart IIS&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/d40b56ee-90d4-45e1-9b82-4aaea90eb02e.mspx?mfr=true&quot;  title=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/d40b56ee-90d4-45e1-9b82-4aaea90eb02e.mspx?mfr=true&quot;&gt;Additional Resources for the IIS 6.0 Metabase&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/ms525006.aspx&quot;  title=&quot;http://msdn.microsoft.com/en-us/library/ms525006.aspx&quot;&gt;Command-Line Tools Included in IIS&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/1805162e-6ac5-4a98-9a08-919c4c10827d.mspx?mfr=true&quot;  title=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/1805162e-6ac5-4a98-9a08-919c4c10827d.mspx?mfr=true&quot;&gt;Using Command-Line Administration Scripts&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/95826e7a-bac4-4e1f-bcb6-c52d49c9d7f4.mspx?mfr=true&quot;  title=&quot;http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/95826e7a-bac4-4e1f-bcb6-c52d49c9d7f4.mspx?mfr=true&quot;&gt;Starting and Stopping Services (IIS 6.0)&lt;/a&gt;&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 18 Jun 2008 01:18:06 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/322-guid.html</guid>
    
</item>
<item>
    <title>Wine 1.0 Released</title>
    <link>http://forkb0mb.org/content/index.php?/archives/321-Wine-1.0-Released.html</link>
            <category>MacOS</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Software</category>
            <category>Unix</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/321-Wine-1.0-Released.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=321</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=321</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.osnews.com/story/19871/Wine_1.0_Released&quot;  title=&quot;http://www.osnews.com/story/19871/Wine_1.0_Released&quot;&gt;Wine 1.0 Released&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
It took them 15 years. During those years, the project grew from something that didn&#039;t work, to something that sometimes under special circumstances could maybe perhaps work, to something that sometimes just worked, all the way to something that works in a number of pre-defined cases. You won&#039;t believe it, but &lt;a href=&quot;http://www.winehq.org/&quot;  title=&quot;http://www.winehq.org/&quot;&gt;Wine&lt;/a&gt; 1.0 is here.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I don&#039;t believe it!  I haven&#039;t used Wine in quite some time (when I was unable to get PartyPoker to work through it!), I&#039;m hoping this 1.0 release will stablize a lot of the bugs I&#039;d seen previously.   I mean, how hard is it to emulate a broken OS?  Logic would dictate that you handle X this way, but no, it has to be Windows-compatible, so you take the wrong way.  Their developers must be extreme masochists.&lt;br /&gt;
&lt;br /&gt;
Check out the &lt;a href=&quot;http://appdb.winehq.org/&quot;  title=&quot;http://appdb.winehq.org/&quot;&gt;Application Compatibility List&lt;/a&gt; at &lt;a href=&quot;http://appdb.winehq.org/&quot;  title=&quot;http://appdb.winehq.org/&quot;&gt;AppDB&lt;/a&gt;.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 18 Jun 2008 01:09:54 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/321-guid.html</guid>
    
</item>
<item>
    <title>Microsoft Windows XP Dies June 30, as Planned</title>
    <link>http://forkb0mb.org/content/index.php?/archives/285-Microsoft-Windows-XP-Dies-June-30,-as-Planned.html</link>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Software</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/285-Microsoft-Windows-XP-Dies-June-30,-as-Planned.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=285</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=285</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.eweek.com/c/a/Windows/Microsoft-Windows-XP-Dies-June-30-as-Planned/&quot;  title=&quot;http://www.eweek.com/c/a/Windows/Microsoft-Windows-XP-Dies-June-30-as-Planned/&quot;&gt;Microsoft Windows XP Dies June 30, as Planned&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft will shutter its Windows XP line June 30, as planned, ceasing sales of Windows XP Professional and Windows XP Home to retailers and direct OEMs, Microsoft confirmed to eWEEK April 3.&lt;br /&gt;
&lt;br /&gt;
The statement from Redmond executives ends weeks of speculation that Microsoft would extend the life of the operating system as users turn up their nose at Vista, the operating system meant to supplant XP, and OEMs argue lighter versions of desktops and notebooks don&#039;t have the juice to run Vista.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is a perfect time for someone (Linux, Apple, etc)... &lt;em&gt;anyone&lt;/em&gt;... to really start chipping away at their desktop monopoly.   I don&#039;t care who it is; choose your own OS, but &lt;em&gt;someone&lt;/em&gt; is facing a very lucrative opportunity to snatch up a good chunk of the desktop market.&lt;br /&gt;
&lt;br /&gt;
eWeek is also carrying an opinion piece entitled &quot;&lt;a href=&quot;http://www.eweek.com/c/a/Linux-and-Open-Source/Windows-Is-Caught-Between-Mac-and-Linux/&quot;  title=&quot;http://www.eweek.com/c/a/Linux-and-Open-Source/Windows-Is-Caught-Between-Mac-and-Linux/&quot;&gt;Windows is Caught Between Mac and Linux&lt;/a&gt;&quot;.  Both articles are worth a read.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 04 Apr 2008 01:38:21 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/285-guid.html</guid>
    
</item>
<item>
    <title>EU Fines Microsoft Record $1.35 Billion</title>
    <link>http://forkb0mb.org/content/index.php?/archives/269-EU-Fines-Microsoft-Record-1.35-Billion.html</link>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Technology</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/269-EU-Fines-Microsoft-Record-1.35-Billion.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=269</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=269</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://news.moneycentral.msn.com/provider/providerarticle.aspx?feed=OBR&amp;date=20080227&amp;id=8248346&quot;  title=&quot;http://news.moneycentral.msn.com/provider/providerarticle.aspx?feed=OBR&amp;date=20080227&amp;id=8248346&quot;&gt;EU Fines Microsoft Record $1.35 Billion&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft was fined a record 899 million euros ($1.35 billion) by the European Commission on Wednesday for using high prices to discourage software competition in the latest sanction in their long-running battle.&lt;br /&gt;
&lt;br /&gt;
The executive arm of the European Union said the U.S. software group defied a 2004 order from Brussels to provide the information on reasonable terms.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Nobody actually expected them to provide useful documentation &quot;on reasonable terms.&quot;&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&quot;Microsoft was the first company in 50 years of EU competition policy that the Commission has had to fine for failure to comply with an antitrust decision,&quot; Competition Commissioner Neelie Kroes said in a statement.&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
Kroes took a wait-and-see attitude about Microsoft&#039;s announcement of last week, noting it had promised change on four other occasions without results.&lt;br /&gt;
&lt;br /&gt;
&quot;A press release, such as that issued by Microsoft last week on interoperability principles, does not necessarily equal a change in a business practice,&quot; she said.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
A few other choice quotes from this article.  This kind of news always brings a smile to my face.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 27 Feb 2008 20:30:55 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/269-guid.html</guid>
    
</item>
<item>
    <title>Windows Server 2008 Features Address Linux Challenge</title>
    <link>http://forkb0mb.org/content/index.php?/archives/186-Windows-Server-2008-Features-Address-Linux-Challenge.html</link>
            <category>Linux</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Software</category>
            <category>Unix</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/186-Windows-Server-2008-Features-Address-Linux-Challenge.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=186</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=186</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.eweek.com/article2/0,1895,2132581,00.asp&quot; title=&quot;http://www.eweek.com/article2/0,1895,2132581,00.asp&quot;&gt;Windows Server 2008 Features Address Linux Challenge&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Some of the changes in the upcoming release of Windows Server 2008 are a response to features and performance advantages that have made Linux an attractive option to Microsoft customers.&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
&quot;We also have server core, which doesn&#039;t have the GUI [graphical user interface], so I would say that is a response to the options people had with Linux that they didn&#039;t have with Windows,&quot; he said.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Wow!  Microsoft is finally catching on to the fact that wasting CPU cycles on a GUI is pretty lame.  All of those cycles could be going to servicing requests.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sun, 20 May 2007 15:17:48 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/186-guid.html</guid>
    
</item>
<item>
    <title>Microsoft’s Advisories Giving Clues to Hackers</title>
    <link>http://forkb0mb.org/content/index.php?/archives/141-Microsofts-Advisories-Giving-Clues-to-Hackers.html</link>
            <category>Advisories</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Vulnerabilities</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/141-Microsofts-Advisories-Giving-Clues-to-Hackers.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=141</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=141</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://blogs.zdnet.com/security/?p=167&quot;  title=&quot;http://blogs.zdnet.com/security/?p=167&quot;&gt;Microsoft’s Advisories Giving Clues to Hackers&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The latest zero-day flaw in the Windows DNS Server RPC interface implementation is a perfect example of the tug-o-war within the MSRC (Microsoft Security Response Center) about how much information should be included in the pre-patch advisory.&lt;br /&gt;
&lt;br /&gt;
Using clues in the workarounds section of the advisory, Errata Security researcher David Maynor said he was able to pinpoint the source of the vulnerability without much trouble.&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
In the wake of Maynor&#039;s comments above, I asked the MSRC if there&#039;s a legitimate gripe that about the level of details included in its advisories and was told that it&#039;s a &quot;delicate balancing act&quot; to avoid giving too much clues while ensuring customers have adequate pre-patch protections.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
It really must be a delicate balance.  Usually within 24 hours of a patch being posted, the fix has been reverse-engineered and at least an underground exploit floating around for it.   How many admins do you know that patch all of their servers within 24 hours of a show-stopper like this?   Not many.&lt;br /&gt;
&lt;br /&gt;
This does bring up an interesting point, though.   How much can you give customers to protect themselves without giving the blackhats enough to start circulating exploits?&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Mon, 16 Apr 2007 22:33:07 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/141-guid.html</guid>
    
</item>
<item>
    <title>Notes On Vista Forensics, Part Two</title>
    <link>http://forkb0mb.org/content/index.php?/archives/133-Notes-On-Vista-Forensics,-Part-Two.html</link>
            <category>Operating Systems</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/133-Notes-On-Vista-Forensics,-Part-Two.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=133</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=133</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.securityfocus.com/infocus/1890&quot;  title=&quot;http://www.securityfocus.com/infocus/1890&quot;&gt;Notes On Vista Forensics, Part Two&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
User files and applications:&lt;br /&gt;
&lt;br /&gt;
One of the first things to note about users&#039; data files is that they&#039;re not where they used to be! Instead of the familiar &quot;Documents and Settings&quot; folder we must instead look to a new folder called &quot;Users&quot;. Other folders which typically fall under the scope of an examination have also moved so examiners running scripts which expect certain files or folders to be in specific locations may need to do some editing.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Nothing like a Windows 95-style shakeup.   Move things around, hide things, all makes for an easy transition to the new version!  :)&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
One last point which involves RAM, application usage and a new feature in Vista. As most computer users will know, there often comes a time when our machines slow to a crawl due to too many applications making demands on available memory. The most straightforward solution to this problem (other than running fewer programs at the same time, of course) is to add extra RAM but this can still be a daunting task for those with little technical knowledge. Vista offers a solution to this problem in the shape of ReadyBoost, a new feature which allows attached flash memory devices to be used as extra memory. However, examiners should be aware of two important points. First, although strictly speaking ReadyBoost does provide extra memory the data held on the flash device is actually also present in the host machine&#039;s RAM - the intended benefit of the feature is that it provides faster access to this data for certain types of operations. Second, the data on the device is AES-128 encrypted.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I thought I was the only one that thought it was a neat trick to use thumb drives as swap space!  A $15 1 GB USB flash drive will give you 1 GB of swap space that&#039;s not nearly as fast as real RAM, but in my testing, has shown 5 times the throughput of a SATA drive.   Here&#039;s to hoping Microsoft finally realizes that it is a lot faster to access your &quot;anonymous pages&quot;, or swap, &lt;em&gt;without&lt;/em&gt; going through the filesystem layer (i.e., the pagefile.sys paging file).&lt;br /&gt;
&lt;br /&gt;
First, if it&#039;s being used as swap space, what is the use in having a copy in RAM as well?   Flush it from the RAM and use the flash volume, otherwise, you&#039;re making 2 copies of transient data which is essentially worthless.&lt;br /&gt;
&lt;br /&gt;
Second, if it&#039;s using 128-bit AES encryption, you&#039;re going to double or triple the amount of time it takes to swap in a page.   Now, not only are you swapping, but you&#039;re chewing up a lot of CPU time to {de,en}crypt this data.   Yet another classic example of a decent idea hampered by the implementation.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sun, 15 Apr 2007 23:14:58 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/133-guid.html</guid>
    
</item>
<item>
    <title>Notes On Vista Forensics, Part One</title>
    <link>http://forkb0mb.org/content/index.php?/archives/132-Notes-On-Vista-Forensics,-Part-One.html</link>
            <category>Operating Systems</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/132-Notes-On-Vista-Forensics,-Part-One.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=132</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=132</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.securityfocus.com/infocus/1889&quot;  title=&quot;http://www.securityfocus.com/infocus/1889&quot;&gt;Notes On Vista Forensics, Part One&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&quot;While the fundamental principles of computer forensics remain largely unchallenged, the landscape upon which investigators operate is constantly changing. A combination of new technologies and changing habits of use means that forensic examiners must always strive to keep up to date with the latest developments. One of the most anticipated new product releases this year is the Microsoft operating system Windows Vista. Vista was under development for a long time with Microsoft promising a raft of new features together with major improvements to security.&quot;&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
Forensic professionals should note the following: &lt;br /&gt;
&lt;br /&gt;
&quot;BitLocker Drive Encryption&quot; is available in the &lt;em&gt;Enterprise&lt;/em&gt; and &lt;em&gt;Ultimate&lt;/em&gt; editions.&lt;br /&gt;
&quot;Encrypting File System (EFS)&quot;, &quot;Shadow Copy&quot; and &quot;Complete PC Backup and Restore&quot;&lt;br /&gt;
  are available in the &lt;em&gt;Business&lt;/em&gt;, &lt;em&gt;Enterprise and Ultimate&lt;/em&gt; editions.&lt;br /&gt;
&quot;Scheduled and Network Backup&quot; is available in the &lt;em&gt;Home Premium&lt;/em&gt;, &lt;em&gt;Business&lt;/em&gt;, &lt;em&gt;Enterprise&lt;/em&gt; and &lt;em&gt;Ultimate&lt;/em&gt; editions.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Encrypted filesystems are great if you can handle the overhead of on-the-fly {en,de}cryption.  I imagine the home user chosing to ditch the encryption for a slightly faster computer; anyone remember DoubleSpace for DOS?  The exact same trade-off this time but it&#039;s security instead of capacity.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&quot;What exactly is BitLocker, though? In a nutshell, BitLocker provides AES encryption of all data on a Windows Vista volume (note the term, &quot;volume&quot; rather than &quot;disk,&quot; despite the name) combined with integrity checking of the boot process used to load the OS. The primary purpose of these features is to protect data even if an attacker manages to circumvent the operating system or remove the hardware storage device.&quot;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Basically, this is saying that if you try to install another OS with a multiboot loader, such as Linux, the encryption used one the &quot;volumes&quot; will cause one of two things:  (a) it won&#039;t allow you to install to the master boot record and your install of Linux will not boot, or (b) it will break the integrity of the entire volume and thus Windows will refuse to boot or access the data.    Given Microsoft&#039;s anticompetitive practices, I&#039;m going to say it&#039;s most likely the former.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sun, 15 Apr 2007 22:48:06 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/132-guid.html</guid>
    
</item>
<item>
    <title>Microsoft Windows Help File Unspecified Heap Overflow Vulnerability</title>
    <link>http://forkb0mb.org/content/index.php?/archives/128-Microsoft-Windows-Help-File-Unspecified-Heap-Overflow-Vulnerability.html</link>
            <category>Advisories</category>
            <category>Buffer Overflow</category>
            <category>Exploits</category>
            <category>Operating Systems</category>
            <category>Vulnerabilities</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/128-Microsoft-Windows-Help-File-Unspecified-Heap-Overflow-Vulnerability.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=128</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=128</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.securityfocus.com/bid/23382/info&quot;  title=&quot;http://www.securityfocus.com/bid/23382/info&quot;&gt;Microsoft Windows Help File Unspecified Heap Overflow Vulnerability&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&quot;This vulnerability presents itself when the application handles a specially crafted Windows Help (&#039;.hlp&#039;) file.&lt;br /&gt;
 &lt;br /&gt;
A successful attack may facilitate arbitrary code execution in the context of a vulnerable user who opens a malicious file. Failed exploit attempts will likely result in denial-of-service conditions.&quot;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
It looks like there&#039;s a &lt;a href=&quot;http://www.securityfocus.com/data/vulnerabilities/exploits/23382.hlp&quot;  title=&quot;http://www.securityfocus.com/data/vulnerabilities/exploits/23382.hlp&quot;&gt;proof-of-concept&lt;/a&gt; in the wild for this one, too.  This is a specially crafted .hlp file.   I advise against trying to open it until you know what it does.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sat, 14 Apr 2007 12:47:43 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/128-guid.html</guid>
    
</item>
<item>
    <title>A Reality Check for Vista</title>
    <link>http://forkb0mb.org/content/index.php?/archives/109-A-Reality-Check-for-Vista.html</link>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/109-A-Reality-Check-for-Vista.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=109</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=109</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://money.cnn.com/2006/09/07/technology/Reality_check_Vista.biz2/index.htm?cnn=yes&quot;  title=&quot;http://money.cnn.com/2006/09/07/technology/Reality_check_Vista.biz2/index.htm?cnn=yes&quot;&gt;A Reality Check for Vista&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Judging by the grief that Microsoft is getting over delays in the release of Windows Vista, and the buzz surrounding the price it plans to charge for the next generation operating system, you&#039;d think we were all hankering to get our hands on this hot new piece of software.&lt;br /&gt;
&lt;br /&gt;
Don&#039;t believe the hype: There won&#039;t be lines around the block at midnight when Vista hits store shelves early next year, analysts say.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is not an article from &lt;a href=&quot;http://www.linux.com/&quot;  title=&quot;http://www.linux.com/&quot;&gt;Linux.com&lt;/a&gt; or similar, this is coming from &lt;a href=&quot;http://money.cnn.com/magazines/business2&quot;  title=&quot;http://money.cnn.com/magazines/business2&quot;&gt;Business 2.0&lt;/a&gt;!&lt;br /&gt;
&lt;br /&gt;
I&#039;ll cut to the chase...&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
So here&#039;s a modest proposal: Boycott Vista. Keep your old Windows XP PC around. Don&#039;t buy a new one. That&#039;s the only way we have to let Microsoft know Vista is an overhyped, late, and pointless update to XP - a perfectly fine operating system.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I don&#039;t know about &quot;a perfectly fine operating system&quot;, but it&#039;s certainly better than Windows 98.  I think Microsoft has reached the breaking point of their creative curve.   What can Microsoft produce in Vista that&#039;s so revolutionary that everyone will want to upgrade?  Nothing.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 08 Sep 2006 18:22:21 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/109-guid.html</guid>
    
</item>
<item>
    <title>With Exploits Out, MS Braces for Worm Attack</title>
    <link>http://forkb0mb.org/content/index.php?/archives/91-With-Exploits-Out,-MS-Braces-for-Worm-Attack.html</link>
            <category>Exploits</category>
            <category>Malware</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Vulnerabilities</category>
            <category>Windows</category>
            <category>Worms</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/91-With-Exploits-Out,-MS-Braces-for-Worm-Attack.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=91</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=91</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.eweek.com/article2/0,1895,2002142,00.asp&quot;  title=&quot;http://www.eweek.com/article2/0,1895,2002142,00.asp&quot;&gt;With Exploits Out, MS Braces for Worm Attack&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
A network worm attack exploiting a critical Microsoft Windows vulnerability appears inevitable, security experts warned Aug. 10.&lt;br /&gt;
&lt;br /&gt;
Just days after the Redmond, Wash., software maker issued the MS06-040 bulletin with patches for a &quot;critical&quot; Server Service flaw, Microsoft&#039;s security response unit is bracing for the worst after exploit code that offers a blueprint for attacks began circulating on the Internet.&lt;br /&gt;
&lt;br /&gt;
Even before the release of Microsoft&#039;s patch, the US-CERT (Computer Emergency Readiness Team) warned that the flaw was being used in targeted attacks and that the appearance of public exploits is a sure sign that a worm attack is imminent.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Looks like the next Worm du Jour.  Go figure...&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 11 Aug 2006 19:50:41 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/91-guid.html</guid>
    
</item>
<item>
    <title>Windows PatchGuard 'Hindering Security'</title>
    <link>http://forkb0mb.org/content/index.php?/archives/90-Windows-PatchGuard-Hindering-Security.html</link>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/90-Windows-PatchGuard-Hindering-Security.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=90</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=90</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://news.zdnet.co.uk/0,39020330,39280753,00.htm&quot;  title=&quot;http://news.zdnet.co.uk/0,39020330,39280753,00.htm&quot;&gt;Windows PatchGuard &#039;Hindering Security&#039;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
A protective feature in Windows is locking out the good guys, but letting in a lot of bad guys, according to security software makers.&lt;br /&gt;
&lt;br /&gt;
Microsoft designed PatchGuard to safeguard core parts of Windows, including Vista, against malicious code attacks. But some security companies say that the feature makes it harder for them to protect Windows PCs, as it locks them out of the kernel, the core of the operating system. &lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
Microsoft&#039;s push into the security market has put many defence providers on guard. Symantec, especially, looks wary; it has said it will compete with Microsoft as long as there is a level playing field. Now, for the first time, Symantec is saying that Microsoft is limiting the security choices of consumers — which could be interpreted as anticompetitive behaviour.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Of course it&#039;s anticompetitive behavior.  This is Microsoft.   They&#039;re plain and simple trying to push Symantec and others out of the market.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&quot;PatchGuard will make it harder for third parties, particularly host intrusion-prevention software, to function in Vista,&quot; said Yankee Group analyst Andrew Jaquith. &quot;Third parties have two choices: continue to petition Microsoft to create an approved kernel-hooking interface so products like theirs can work, or use &#039;black hat&#039; techniques to bypass the restrictions.&quot;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Let &#039;em use &quot;black hat&quot; techniques.  It&#039;s about time someone uses them for something useful.  Advertising companies have been using these &quot;black hat techniques&quot; to install spyware/adware via Internet Explorer for ages now.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 11 Aug 2006 19:14:51 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/90-guid.html</guid>
    
</item>
<item>
    <title>Homeland Security: Apply MS06-040 Patch</title>
    <link>http://forkb0mb.org/content/index.php?/archives/87-Homeland-Security-Apply-MS06-040-Patch.html</link>
            <category>Advisories</category>
            <category>Operating Systems</category>
            <category>Vulnerabilities</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/87-Homeland-Security-Apply-MS06-040-Patch.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=87</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=87</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.eweek.com/article2/0,1895,2001412,00.asp&quot;  title=&quot;http://www.eweek.com/article2/0,1895,2001412,00.asp&quot;&gt;Homeland Security: Apply MS06-040 Patch&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Less than 24 hours after Microsoft shipped a dozen bulletins with security fixes for 23 serious software vulnerabilities, the U.S. government&#039;s Department of Homeland Security issued a firm notice to Windows users: immediately apply the patches in the MS06-040 bulletin.&lt;br /&gt;
&lt;br /&gt;
In a somewhat unusual move, the DHS warned that the patches cover a remote code execution vulnerability that could be used in a network worm attack similar to Blaster, Slammer of Sasser.&lt;br /&gt;
&lt;br /&gt;
&quot;Windows users are encouraged to avoid delay in applying this security patch. Attempts to exploit vulnerabilities in operating systems routinely occur within 24 hours of the release of a security patch,&quot; the agency said in an public advisory.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Why is it the same thing over and over again?  If you&#039;re running Windows, you absolutely must enable automatic updates.  There are just far too many patches to try to keep track of them manually.&lt;br /&gt;
&lt;br /&gt;
What puzzles me is what interest the DHS has in protecting the end-user PCs of millions of average people.  Sure, an advisory to all DHS and government employees would be routine, but a public advisory?  They need to find better ways of spending their time.  If they decide to start &quot;reminding&quot; everyone to update their Windows machines every time a new vulnerability is found, they&#039;ll not have the resources left to track the &lt;em&gt;turrrists&lt;/em&gt;.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Thu, 10 Aug 2006 19:43:05 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/87-guid.html</guid>
    
</item>
<item>
    <title>Unpatched Powerpoint Flaw Exploited</title>
    <link>http://forkb0mb.org/content/index.php?/archives/63-Unpatched-Powerpoint-Flaw-Exploited.html</link>
            <category>Advisories</category>
            <category>Operating Systems</category>
            <category>Vulnerabilities</category>
            <category>Windows</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/63-Unpatched-Powerpoint-Flaw-Exploited.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=63</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=63</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2006/07/unpatched_microsoft_powerpoint.html&quot;  title=&quot;http://blog.washingtonpost.com/securityfix/2006/07/unpatched_microsoft_powerpoint.html&quot;&gt;Unpatched Powerpoint Flaw Exploited&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Online criminals are taking advantage of an unpatched security hole in Microsoft&#039;s Office products again. Security experts say they&#039;ve spotted a flaw in the Powerpoint slide-presentation program being exploited in the wild.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This has really been a bad month or so for Microsoft.  First Word, then Excel, now PowerPoint?  It just goes to show that you shouldn&#039;t open attachments from non-trusted sources.   I recommend &lt;a href=&quot;http://www.gnupg.org/&quot;  title=&quot;http://www.gnupg.org/&quot;&gt;GnuPG&lt;/a&gt; for verifying authenticity.&lt;br /&gt;
&lt;br /&gt;
This author of this article apparently doesn&#039;t know much about Microsoft&#039;s security track-record.  It leads you to the conclusion that due to &quot;some of the work Microsoft has done in hardening the security of the Windows operating system&quot; that vulnerability researchers have been forced to &quot;look for lower-hanging fruit in applications that run on top of Windows.&quot;   Searching for bugs in Microsoft software has always been like shooting fish in a barrel.  Nothing has changed, just a few researchers shooting into a different barrel lately.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://isc.sans.org/diary.php?storyid=1484&quot; title=&quot;http://isc.sans.org/diary.php?storyid=1484&quot;&gt;0-day Exploit for Microsoft PowerPoint&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Three (!!!) PoCs for this vulnerability(ies) have just been publicly posted.&lt;br /&gt;
From what we can tell at the moment, they all just crash PowerPoint, but they show where the vulnerabilities are, so a full exploit can be written.&lt;br /&gt;
This is a first step to remote exploitation so we can unfortunately expect to see some malware using this very soon (and we though it will be another quiet weekend).&lt;br /&gt;
&lt;br /&gt;
Again, stress out to users how important it is to be very careful when opening PowerPoint files (and if possible, don&#039;t open them at all until the patch is out). Otherwise you&#039;ll have to rely on your desktop anti-virus product to catch the dropped component, and we all know how (un)reliable this can be.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is an update from the Internet Storm Center&#039;s handler&#039;s diary.   They also link to a &lt;a href=&quot;http://blogs.securiteam.com/?p=508&quot;  title=&quot;http://blogs.securiteam.com/?p=508&quot;&gt;FAQ&lt;/a&gt;.  Thanks to &lt;a href=&quot;http://www.packetstormsecurity.org/&quot;  title=&quot;http://www.packetstormsecurity.org/&quot;&gt;PacketStormSecurity&lt;/a&gt; for linking to PoC&#039;s &lt;a href=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc1.txt&quot;  title=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc1.txt&quot;&gt;1&lt;/a&gt;, &lt;a href=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc2.txt&quot;  title=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc2.txt&quot;&gt;2&lt;/a&gt;, and &lt;a href=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc3.txt&quot;  title=&quot;http://packetstorm.linuxsecurity.com/0607-exploits/mspp-poc3.txt&quot;&gt;3&lt;/a&gt;.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sun, 16 Jul 2006 05:48:34 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/63-guid.html</guid>
    
</item>

</channel>
</rss>