MSInfluentials
A new blog site for influential people
Sign in
|
Join
|
Help
Home
Blogs
Media
Jesper's Blog
»
All Tags
»
Security
»
Security Pontification
(
RSS
)
Browse by Tags
Jesper's Blog
Home
Syndication
RSS for Posts
Atom
RSS for Comments
Email Notifications
Go
Recent Posts
Don't fire people until after you wipe their phones
And finally, standard user malware
Please do not e-mail my social security number
Is MS08-067 Wormable?
What They Teach Kids These Days
Tags
Apple
Diving
Least Privilege
Mitigations
National Cyber Security Awareness Month
Privacy
Running Windows
Security
Security Pontification
Software Development
Thinking differently
Troubleshooting
UAC
Windows Security
Windows Server 2008
Windows Vista
View more
Archives
April 2011 (1)
October 2010 (2)
September 2010 (1)
June 2010 (2)
April 2010 (1)
February 2010 (1)
October 2009 (4)
September 2009 (1)
August 2009 (2)
July 2009 (3)
March 2009 (1)
January 2009 (1)
December 2008 (5)
November 2008 (4)
October 2008 (1)
September 2008 (1)
August 2008 (3)
July 2008 (2)
June 2008 (1)
May 2008 (4)
April 2008 (5)
March 2008 (7)
February 2008 (6)
January 2008 (3)
December 2007 (8)
November 2007 (4)
October 2007 (3)
September 2007 (4)
August 2007 (1)
July 2007 (10)
June 2007 (1)
May 2007 (3)
April 2007 (1)
Least Privilege
Thinking differently
Windows Security
Windows Vista
Don't fire people until after you wipe their phones
A very commonly required feature for mobile access to email is remote wipe - the ability to reach out and wipe all corporate data off a mobile device. Exchange ActiveSync supports this feature and has for several versions now. You, as the Exchange or...
Published
Thu, Apr 8 2010 10:31 PM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
,
Windows Security
And finally, standard user malware
Today I finally got wind of my first piece of true standard user malware. MS Antispyware 2008 has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\<something>, and makes...
Published
Tue, Sep 1 2009 1:21 AM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
,
Least Privilege
Please do not e-mail my social security number
Recently I had a very interesting incident. I wrote an article some time in 2008 and the publisher paid me a little bit of money for it. That means the publisher must send a report to the Internal Revenue Service (IRS - the U.S. tax department) reporting...
Published
Tue, Jan 27 2009 11:38 PM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
Is MS08-067 Wormable?
A couple of weeks ago Microsoft released an out-of-band security update in bulletin MS08-067 . Looking at the type of vulnerability and the fact that the issue was already being exploited in the wild at the time, this was a good decision. If you have...
Published
Tue, Nov 4 2008 6:14 AM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
,
Thinking differently
What They Teach Kids These Days
Sweden has always been a little "cutting edge," if you know what I mean. Little did I know, however, just how cutting edge. This picture was snapped in a toy store in Stockholm last week: I probably stood there stunned for a good two minutes...
Published
Mon, Sep 3 2007 3:18 PM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
The Protocol Handler Saga Continues: Say What Secunia?
Sometimes you just have to wonder how far people will go to lend undeserved credibility to opinions. The Protocol Handler Saga is rapidly becoming a religious war. The latest entry is related to a very cool exploit that Billy Rios and Nate McFeters published...
Published
Thu, Jul 26 2007 6:19 PM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
Hey, Mozilla: Quotes Are Not Legal in a URL
When I was a child, I learned a saying that I still find important to keep in mind: Those who are sitting in a glass house shall not throw stones The good folks at Mozilla may want to look up what that really means. Two days ago, Mozilla published Firefox...
Published
Sat, Jul 21 2007 12:25 AM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
,
Windows Security
,
Windows Vista
Blocking the Firefox -> IE 0-day
Thor Larholm, unhelpfully, published details on what he claims is a 0-day exploit for Internet Explorer (IE) yesterday. This exploit is actually for Firefox, but Thor exploited it by making IE launch Firefox. Firefox creates three protocol handlers. A...
Published
Tue, Jul 10 2007 10:55 AM
by
Jesper's Blog
Filed under:
Security
,
Security Pontification
,
Windows Security
All postings are copyright Jesper M. Johansson or Steve Riley, in the year they were made. These postings are provided "AS IS" with no warranties, and confer no rights. All postings are the sole opinions of Jesper M. Johansson or Steve Riley and do not reflect any official opinion of anyone else with whom the poster(s) are affiliated or has been affiliated in the past. Use of included code samples is permitted for non-commercial use, with no warranties of fitness express or implied. All use of any information or code snippets posted in this blog at the user's sole risk. The blog site would like to thank www.ownwebnow.com and www.exchangedefender.com for their support.