|
|
||||||||||||
|
|
2/3/2004
Not really security related, but definatly worth a
read for anyone who designs websites or do any kind of
site management.
HTML Hell Page
1/30/2004
Nice list of the services installed by default in Windows NT4, 2000, and
XP. If you want to optimize and secure your system, but
aren't sure about which services do what, check this
list out.
Disable unnecessary services to improve workstations performance: "NT/W2K/XP supports a large number of services. Unnecessary services take up a lot of cycles. Try disabling the following services to speedup your workstation."
1/29/2004
Lie Detector glasses. Scary, but usefull, tho I'm
undecided how I feel about these.
EE Times - Lie-detector glasses offer peek at future of security: "'We work off the frequency range of voice patterns instead of changes in the body.' The company said that a state police agency in the Midwest found the lie detector 89 percent accurate, compared with 83 percent for a traditional polygraph."
Ok, so this isn't really news, but it's worth a
look. Very funny version of NMAP made by Microsoft.
(Parody).
If Microsoft Had Written Nmap: "What if, in a bizarro, make-believe parallel Universe, Microsoft expanded Office beyond Microsoft Word, Microsoft Excel, and Microsoft Outlook to include. Microsoft Nmap."
1/28/2004
Fairly cheesy, but you could probably get caught
playing this and say it was for research purposes. If
you fraised it properly.
Virus Hunter II - Play for fun and win the discount!: "Kaspersky Labs announces the release of 'Virus Hunter 2', the second version of the popular online game."
Isn't this Karma? If not, at least maybe they'll
stop suing everyone now.
SCO | Investor Relations: "The SCO Group, Inc. (Nasdaq: SCOX), the owner of the UNIX(R) operating system and a leading provider of UNIX-based solutions, today confirmed that it is experiencing a distributed Denial-of-Service (DDOS) attack. SCO announced that it is offering a reward of up to a total of $250,000 for information leading to the arrest and conviction of the individual or individuals responsible for creating the Mydoom virus"
1/27/2004
Running Checkpoint? Make sure you've updated
recently. They aren't secure against this latest worm by
default.
SecurityTracker.com Archives - Check Point FireWall-1/VPN-1 Contains H.323 Processing Vulnerabilities With Unspecified Impact: "It was reported that Check Point FireWall-1 and VPN-1 products are vulnerable to the H.323 security tests "
1/26/2004
Mcafee releases an Antispyware program. And then
charges $40 for it. I've not had a good feeling about
this company since it started filling its site with ads
that greatly resemble spyware ads. Now this happens. I
fear it.
News Center: Network Associates To Launch AntiSpyware Software
1/23/2004
Brief overview of the evils that are pop-ups. If
you don't already use the google toolbar, then shame on
you.
http://toolbar.google.com mcall.com - Invasion of the Pop-Ups: "Microsoft has announced that future versions of the Internet Explorer will include pop-up-blocking software that will be turned on in its default setting."
India is finally taking some measures in
implementing network security. The Indian government has
built a new system in response to increased hacking and
break-ins.
Indian cyber security system unveiled : "IT officials acknowledge that computer security in India is far from satisfactory. Recently, hackers from a neighbouring country hacked sites of the Defence Ministry."
Overview on disabling DCOM can be found here.
Critical Flaw Leaves Windows Users Vulnerable: "RPC/DCOM vulnerability widespread problem" 1/9/2004
SecurityFocus PEN-TEST Infocus: Exploiting Cisco
Routers: Part 1
SecurityFocus PEN-TEST Infocus: Exploiting Cisco Routers: Part 2
New processor technology that should help
eliminate Buffer Overflow Vulnerabilities. How
many Windows Updates will this make unnessicary?
AMD, Intel put antivirus tech into chips | CNET News.com: "'Now in current processors, any programs that go into the memory overflow can be executed,' he said. 'With this, the system only allows read-only in the buffer. It will not execute.' The malicious program is then disposed harmlessly when the PC is turned off, he said. "
Livejournal looks about to get a wakeup
call. Not believing in security is like asking
for a hack. Come on, people.
SecurityFocus HOME News: Defenses lacking at social network sites: "On the initial login page, LiveJournal members send their passwords in the clear. 'We're hoping to change that in the next month,' Fitzpatrick said. 'But site performance is our highest priority, and SSL is a pain.' "
Microsoft is dropping support (even
extended support, so no patches will be issued
unless they really want to) for Internet
Explorer 6 at the same time that Windows XP
Service Pack 2 comes out. This is gonna be the
ugliest thing ever. The hijacks and security
vulnerabilities are going to destroy what
credibility IE has left.
The Windows Clock Is Ticking: "IE 6 for XP: Mainstream support for Internet Explorer 6 on Windows XP Home and XP Professional already ended on December 31, 2001. But the extended support for these two products will terminate around mid-2004, simultaneous with the commercial availability of Windows XP SP2."
Qualys' list of the highest risk
vulnerabilities in the wild. Updated with full
info on the specifid vulnerability.
Qualys, Inc. - Security On-Demand 1/8/2004
Not really big news here. Kazaa is an evil
virus magnet. Extended exposure to Peer to Peer
programs will eventually lead to a virus hitting
your machine. And with the RIAA suing everyone
lately, its not the best time to be pirating music
and software.Almost half of Kazaa downloads 'threaten security' - News & Technology - CNETAsia
NeWT scanner, based on the 'Nix Nessus engine now
available for Windows. Decent ability to see what remote
services are exposed on your systems and how to patch
them. Interface and usage isn't heavy technical,
compared to most port scanners, but has a nice GUI.
Statistics on who got hacked in 2003.
Globes [online] - Worm threatening Linux and Windows on its way 1/7/2004
Great site for Microsoft News and Beta information
Watching Microsoft Like A Hawk - Microsoft News Watch Site
Scots Newsletter beta tests Windows XP Service
Pack 2 and gives details on the security upgrades and
additional features that it will include.
Scot's Newsletter | By Scot Finnie http://www.scotsnewsletter.com/ 1/6/2004
GFI releases a new tool to check for site
vandalism and lost connections.Gfi Releases Freeware Version of Gfi Network Server Monitor / Enables Administrators to Monitor Servers and Check Availability of Http/https Sites for Free 1/2/2004
Curious about Internet Information Services in
2003 Server? In-depth coverage here:Exploring Windows 2003 Security: IIS 6.0
PCWorld.com - Security Worries for 2004 802.11i security standard, WPA, and the
upcoming security standards of wireless networking.
WPA is not yet secure. ZDNet UK - Special Reports - Locking the desktop in the filing cabinet 12/29/2003 Of Dying Viruses and Dangerous Xmas Cards Brief article on the security hazards involved
in using Kazaa and P2P file sharing applications. TechCentral: Story Recap of the biggest news items of 2003. 12/27/2003
Doug Knox's Site of Windows Tips and TricksDoug's Windows 95/98/Me/XP Tweaks and Tips Tom's Hardware giving a review of the latest
CPU's from AMD and Intel for the holiday season. 12/19/2003
Update:If you are overwhelmed by spyware on a regular basis, this might do the trick. I don't recommend it for the normal user, as it will block most everything that you don't remove, but for some it will do nicely. Replace your hosts file with this list to block most advertisers. Using a Hosts File To Make The Internet Not Suck (as much) Proof that Microsoft does indeed have a sense
of humor. Read it even if you don't want to use the
tool. More Microsoft Betas Out the Door Configuring TCP/IP from a CMD Shell. Very nice
walkthrough. Postini - Incidence Of Spam, Viruses, And Fraudulent Email Attacks To Increase Dramatically In 2004 12/17/03 This is obvious. Don't use an evil to stop an
evil. ieXbeta Board -> Win XP SP2 Beta & WU5 Preview Officially Announced 12/18/2003
Windows XP SP2 is in beta now, due in mid
2004. The addition of the Windows Firewall being on
by default is a good idea, but it's going to kill
thousands of LAN connections if it stays in its
current form.Windows XP update moves ahead | CNET News.com 12/17/2003
Trusted Computing and why it is the Internets
downfall.MSNBC - A Net of Control 12/2/2003 323381 - HOW TO: Allow Remote Users to Access Your Network in Windows Server 2003
| |||||||||||