<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iDunzo.com &#187; Security Patches</title>
	<atom:link href="http://www.idunzo.com/category/security-patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.idunzo.com</link>
	<description>It\'s yet another in a long series of diversions in an attempt to avoid responsibility. - Chris Knight</description>
	<lastBuildDate>Fri, 11 Dec 2009 20:23:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Trusted Web Site? Not So Fast</title>
		<link>http://www.idunzo.com/trusted-web-site-not-so-fast/</link>
		<comments>http://www.idunzo.com/trusted-web-site-not-so-fast/#comments</comments>
		<pubDate>Thu, 24 Jan 2008 17:01:57 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/trusted-web-site-not-so-fast/</guid>
		<description><![CDATA[It&#8217;s not been a great year for Web security, so far. First we learn that Hackersafe isn&#8217;t so hacker safe, after all. Then we find out that hackers have found a way to automatically redirect most home routers to wherever they wish. And now it seems that so-called legitimate Web sites may not be so [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s not been a great year for Web security, so far. First we learn that <a href="http://www.idunzo.com/hacker-safe-geekscom-hacked/" title="Hacker Safe Geeks.com Hacked">Hackersafe isn&#8217;t so hacker safe</a>, after all. Then we find out that hackers have found a way to automatically redirect most home routers to wherever they wish. And now it seems that so-called legitimate Web sites may not be so &#8220;legitimate&#8221; (or at least safe) after all.</p>
<p>It&#8217;s apparently so easy to infect existing Web sites that there&#8217;s decreasing need for criminals to set up shill sites. At least that&#8217;s the takeaway from a recent report published by security vendor <a href="http://www.websense.com/securitylabs/" title="Websense Security Labs">Websense</a>, which attempts to examine security trends for the second half of last year.</p>
<p>In fact, 51% of Web sites infected with malicious code are actually legitimate, but compromised, Web sites. This is actually a stark increase from the 30% or so of infected legitimate sites the company reported for the first half of 2007.</p>
<p>So this means that miscreants &#8212; because the Web site security and development practices of conventional businesses are negligent &#8212; don&#8217;t even have to go through the trouble of developing and <a href="http://www.webhostingsearch.com/">hosting</a> a Web site, or even the bother of deluging everyone with spam designed to lure folks to a Web site trap.</p>
<p>No, all they have to do is find a trusted site that&#8217;s already vulnerable and that, unfortunately, seems all too easy.</p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/trusted-web-site-not-so-fast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Hacker Safe&#8217; Geeks.com Hacked</title>
		<link>http://www.idunzo.com/hacker-safe-geekscom-hacked/</link>
		<comments>http://www.idunzo.com/hacker-safe-geekscom-hacked/#comments</comments>
		<pubDate>Tue, 08 Jan 2008 13:24:49 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/hacker-safe-geekscom-hacked/</guid>
		<description><![CDATA[Geeks.com, a Web site that still displays a banner from McAfee&#8217;s ScanAlert certifying that it is &#8220;Hacker Safe,&#8221; on Friday sent a letter to customers saying that it was hacked last month. &#8220;Genica dba Geeks.com (&#8216;Genica&#8217;) recently discovered on December 5, 2007 that customer information, including Visa credit card information, may have been compromised,&#8221; said [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.geeks.com/" title="Geeks.com - Computer parts, Laptop computers, Desktop computers, Computer hardware">Geeks.com</a>, a Web site that still displays a banner from McAfee&#8217;s ScanAlert certifying that it is &#8220;Hacker Safe,&#8221; on Friday sent a letter to customers saying that it was hacked last month.</p>
<p>&#8220;Genica dba Geeks.com (&#8216;Genica&#8217;) recently discovered on December 5, 2007 that customer information, including Visa credit card information, may have been compromised,&#8221; said a letter <a href="http://consumerist.com/341408/geekscom-website-hacked-customer-data-stolen" title="Identity Theft: Geeks.com Website Hacked, Customer Data Stolen">posted on The Consumerist</a> from Jerry L. Harken, Genica&#8217;s chief of security, to an undisclosed number Geeks.com customers. </p>
<blockquote><p>&#8220;In particular, it is possible that an unauthorized person may be in possession of your name, address, telephone number, e-mail address, credit card number, expiration date, and card verification number. We are still investigating the details of this incident, but it appears that an unauthorized individual may have accessed this information by hacking our e-commerce Web site.&#8221;</p></blockquote>
<p>Geeks.com has reported the incident to federal authorities and Visa, and is encouraging customers to review their credit card statements for unauthorized charges. </p>
<p>The company has set up two help numbers &#8212; 1-888-529-6261 or 1-212-560-5108 for non-<acronym title="United States">US</acronym> customers &#8212; that will be active starting this morning for those with questions about the incident. </p>
<p>It is also providing contact information for the major credit agencies to make it easier to report any identity theft fraud arising from the incident.</p>
<p>Geeks.com describes itself as a direct-to-consumer e-commerce site that specializes in computer-related excess inventory, manufacturer closeouts, and popular and esoteric products for the tech-savvy.</p>
<p><a href="http://www.mcafee.com/us/about/corporate/mcafee_scanalert.html" title="McAfee to Acquire ScanAlert">McAfee acquired ScanAlert</a> in October and describes it as the world&#8217;s leading provider of e-commerce Web site security services. </p>
<p>The Hacker Safe certification, McAfee explains on its Web site, lets &#8220;shoppers of ScanAlert customer sites instantly know that they are a secure Web site and respond by buying more from them.&#8221;</p>
<p>The ScanAlert Web site <a href="https://www.scanalert.com/RatingVerify?ref=www.geeks.com" title="ScanAlert: geek.com">explains</a> that the Hacker Safe certification doesn&#8217;t mean 100% safe. </p>
<p>&#8220;Research indicates sites remotely scanned for known vulnerabilities on a daily basis, such as those earning &#8216;Hacker Safe&#8217; certification, can prevent over 99% of hacker crime,&#8221; the site says. </p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/hacker-safe-geekscom-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows XP Service Pack 3 Looks Like OS Life Extender</title>
		<link>http://www.idunzo.com/windows-xp-service-pack-3-looks-like-os-life-extender/</link>
		<comments>http://www.idunzo.com/windows-xp-service-pack-3-looks-like-os-life-extender/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 18:51:59 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/windows-xp-service-pack-3-looks-like-os-life-extender/</guid>
		<description><![CDATA[Way back in 2004, Microsoft released a little OS upgrade they called Service Pack 2. Windows XP owes much of its current popularity to the changes made in SP2. Although Vista is grabbing all the front page attention with its soon-to-be-released Service Pack 1, XP hangers-on are hopeful that the upcoming Service Pack 3 can [...]]]></description>
			<content:encoded><![CDATA[<p>Way back in 2004, Microsoft released a little <acronym title="Operating System">OS</acronym> upgrade they called Service Pack 2. Windows XP owes much of its current popularity to the changes made in SP2. </p>
<p>Although Vista is grabbing all the front page attention with its soon-to-be-released Service Pack 1, XP hangers-on are hopeful that the upcoming Service Pack 3 can solve the nagging problems of software middle age.</p>
<p>Early results show that SP3 might even provide a performance boost. So Vista may be hip, but XP is getting a hip replacement.</p>
<p>The <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=75ed934c-8423-4386-ad98-36b124a720aa&#038;DisplayLang=en" title="Windows XP Service Pack 3 Release Candidate">XP SP3 Release Candidate</a> is available now, with the final version set to ship in the second quarter of this year. Whatever the actual date, you can bet that Vista SP1 will ship before XP SP3)</p>
<p>XP SP3 adds four new features. Only two seem really significant, one for corporate environments and one for the small-business/consumer side.</p>
<p>For the corporate world, XP SP3 will support the <a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" title="Network Access Protection">Network Access Protection</a> (NAP) feature that is already available in Vista and Windows Server 2008. </p>
<p>It allows <acronym title="Information Technology">IT</acronym> managers to deny a <acronym title="Personal Computer">PC</acronym> access to network resources based on whether they are configured according to company policies. </p>
<p>For example, if a <acronym title="Personal Computer">PC</acronym> does not have the latest antivirus signatures installed, NAP can limit its access so that it can only contact a remediation server that contains up-to-date signatures to be downloaded.</p>
<p>Given the concern that many companies have about security, the NAP feature could have been one that pushed them to upgrade to Vista. Now, they can stay put with XP and still reap the benefits. </p>
<p>It seems so much like the right thing to do that I can hardly believe that Microsoft has done it. Perhaps the goal is to sell more Windows Server 2008 licenses?</p>
<p>Consumers get a Vista feature transplant in XP SP3 with the ability to install without the need to enter a license key during setup. </p>
<p>Within 30 days of installation, the user needs to enter a product key or XP will go in to a reduced-functionality mode similar to Vista.</p>
<p>The final two XP SP3 features seem relatively trivial: additional cryptographic providers, and enabling <a href="http://support.microsoft.com/kb/314825" title="How to Troubleshoot Black Hole Router Issues">black hole router</a> detection by default. </p>
<p>XP already has the ability to detect black hole routers with a single change in the registry, so the feature here just seems to be that the setting will be enabled by default in SP3.</p>
<p>So if these are the only new features and the rest of the changes are patches, why would SP3 be faster? It&#8217;s a bit of a puzzle. </p>
<p>Maybe the tests were anomalous, or perhaps there is a benefit from several non-security-related patches rolled into SP3 that haven&#8217;t been previously released. </p>
<p>Whatever the reason, it actually leaves me looking forward to this mid-life <acronym title="Operating System">OS</acronym> boost.</p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/windows-xp-service-pack-3-looks-like-os-life-extender/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows XP SP3 Release Candidate Now Available</title>
		<link>http://www.idunzo.com/windows-xp-sp3-release-candidate-now-available/</link>
		<comments>http://www.idunzo.com/windows-xp-sp3-release-candidate-now-available/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 20:02:42 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/windows-xp-sp3-release-candidate-now-available/</guid>
		<description><![CDATA[Microsoft has released to the public a near-final version of a major update to its Windows XP operating system. As of early this morning, the &#8216;Release Candidate&#8217; for Windows XP Service Pack 3 was available as a 336 MB download from Microsoft&#8217;s Web site. The software had previously been available only to participants in Microsoft&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img class="left" src="http://www.idunzo.com/images/post-art/microsoft-xp-sp3.jpg" alt="Microsoft XP SP3" />Microsoft has released to the public a near-final version of a major update to its Windows XP operating system.</p>
<p>As of early this morning, the &#8216;Release Candidate&#8217; for Windows XP Service Pack 3 was available as a <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=75ed934c-8423-4386-ad98-36b124a720aa&#038;DisplayLang=en" title="Download Windows XP Service Pack 3 Release Candidate">336 <acronym title="Megabyte">MB</acronym> download</a> from Microsoft&#8217;s Web site. The software had previously been available only to participants in Microsoft&#8217;s official test programs.</p>
<p>Microsoft says it considers the Release Candidate for Windows XP SP3 to be trial software and warns users to download with caution and at their own risk. </p>
<blockquote><p>This pre-release software is provided for testing purposes only. Microsoft does not recommend installing this software on primary or mission critical systems. </p>
<p>Microsoft recommends that you have a backup of your data prior to installing any pre-release software.</p></blockquote>
<p>For the adventurous, however, Windows XP SP3 Release Candidate offers a number of enhancements over the current version of the <acronym title="Operating System">OS</acronym>. It includes all updates issued since Windows XP Service Pack 2 was released in 2004, and some new elements.</p>
<p>Among them: A feature called Network Access Protection that&#8217;s borrowed from the newer Windows Vista operating system. NAP automatically validates a computer&#8217;s &#8220;health,&#8221; ensuring that it&#8217;s free of bugs and viruses, before allowing it access to a network.</p>
<p>Windows XP SP3 also includes improved &#8220;black hole&#8221; router detection &#8212; a feature that automatically detects routers that are silently discarding packets. In XP SP3, the feature is turned on by default, according to Microsoft.</p>
<p>Windows XP SP 3 also steals a page from Vista&#8217;s product activation model, meaning that product keys for each copy of the operating system doesn&#8217;t need to be entered during setup. </p>
<p>The feature should prove popular with corporate <acronym title="Information Technology">IT</acronym> managers, who often need to oversee hundreds, or even thousands, of operating system installations.</p>
<p>Microsoft is in a bit of a Catch-22 with XP. The more it strengthens the <acronym title="Operating System">OS</acronym>, the less reason users have to upgrade to the newer Windows Vista, which by many accounts has failed to catch on with computer users in both the home and office since it debuted in January.</p>
<p>A final version of Windows XP SP3 is expected to ship early 2008. </p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/windows-xp-sp3-release-candidate-now-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Apple Pushes Out First Leopard Updates</title>
		<link>http://www.idunzo.com/apple-pushes-out-first-leopard-updates/</link>
		<comments>http://www.idunzo.com/apple-pushes-out-first-leopard-updates/#comments</comments>
		<pubDate>Mon, 29 Oct 2007 14:19:19 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/apple-pushes-out-first-leopard-updates/</guid>
		<description><![CDATA[Well that didn&#8217;t take long. Apple has already pushed out some Leopard-related upgrades that reportedly fix issues with Keychain passwords, Wi-Fi support, Aperture and Backup. The most significant upgrade, and the only one that applies to all Leopard users, is the Login &#038; Keychain Update 1.0. The update addresses a rather obscure Keychain issue that [...]]]></description>
			<content:encoded><![CDATA[<p>Well that didn&#8217;t take long. <a href="http://www.apple.com/" title="Apple">Apple</a> has already pushed out some Leopard-related upgrades that reportedly fix issues with Keychain passwords, <acronym title="Wireless Fidelity">Wi-Fi</acronym> support, Aperture and Backup.</p>
<p>The most significant upgrade, and the only one that applies to all Leopard users, is the <a href="http://docs.info.apple.com/article.html?artnum=306804" title="About the Login &#038; Keychain Update 1.0">Login &#038; Keychain Update 1.0</a>. </p>
<p>The update addresses a rather obscure Keychain issue that affects accounts originally created in <acronym title="Operating System">OS</acronym> X 10.1, but also includes fixes for those having trouble &#8220;connecting to some 802.11b/g wireless networks.&#8221;</p>
<p>A couple of commenters on our Leopard first look story and other posts I’ve seen around the web reveal that the <acronym title="Wireless Fidelity">Wi-Fi</acronym> troubles have plagued a fair number of users. Hopefully this update will fix the problem.</p>
<p>The other Leopard-related update released today is <a href="http://docs.info.apple.com/article.html?artnum=306387" title="Aperture: Changes in Aperture 1.5.6">Aperture 1.5.6</a> which improves reliability when recovering Aperture libraries from a Vault (Aperture’s backup files) on Leopard, as well as a few other small fixes.</p>
<p>The updates are available through Software Update or directly from the Apple site using the links above.</p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/apple-pushes-out-first-leopard-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.8 Released</title>
		<link>http://www.idunzo.com/firefox-2008-released/</link>
		<comments>http://www.idunzo.com/firefox-2008-released/#comments</comments>
		<pubDate>Fri, 19 Oct 2007 15:42:29 +0000</pubDate>
		<dc:creator>iDunzo</dc:creator>
				<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.idunzo.com/firefox-2008-released/</guid>
		<description><![CDATA[Mozilla released Firefox 2.0.0.8 late last night and it&#8217;s highly recommended that you upgrade your install right away because of a nice list of security fixes. The following security issues were fixed: URIs with invalid %-encoding mishandled by Windows XPCNativeWrapper pollution using Script object Possible file stealing through sftp protocol XUL pages can hide the [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla released <a href="http://www.mozilla.com/" title="Mozilla Firefox 2.0.0.8">Firefox 2.0.0.8</a> late last night and it&#8217;s highly recommended that you upgrade your install right away because of a nice list of security fixes.</p>
<p>The following security issues were fixed:</p>
<ul>
<li>URIs with invalid %-encoding mishandled by Windows</li>
<li>XPCNativeWrapper pollution using Script object</li>
<li>Possible file stealing through sftp protocol</li>
<li><acronym title="XML User Interface Language">XUL</acronym> pages can hide the window titlebar</li>
<li>File input focus stealing vulnerability</li>
<li>Browser digest authentication request splitting</li>
<li>onUnload Tailgating</li>
<li>Crashes with evidence of memory corruption (rv:1.8.1.8)</li>
</ul>
<p>Firefox 2.0.0.8 is also compatible with Mac <acronym title="Operating System">OS</acronym> X 10.5 (Leopard), although there are some <a href="http://www.mozilla.com/en-US/firefox/2.0.0.8/releasenotes/#macosx" title="known Mac issues">known issues</a> affecting some media plugins.</p>]]></content:encoded>
			<wfw:commentRss>http://www.idunzo.com/firefox-2008-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
