-
Olliver Sommer , a German Small Business Server MVP, flew home from the Microsoft MVP Summit via O'Hare Airport in Chicago. While there, he spotted this wonderful piece of advice for how to configure your computer to use the airport wireless network. The document is meant well, but lacks a bit in...
-
Today I attended the Microsoft 2008 server wave launch event in Seattle. In the process I learned a number of things: The launch event apparently does not need to coincide with actually launching anything. Server 2008 launched a couple of months ago. Visual Studio 2008 launched in November 2007, and...
-
Change log: Updated on April 8, 2008, with information on Norton Internet Security and Windows Installer 3.1. A number of people are reporting errors when running software update tools. The tools include Windows Update, Windows Defender Updates, Installshield, Adobe Updater, and probably others as well...
-
Last Friday the last of the Windows Server 2008 Security Resource Kit finally went to press! This was a project I had not really planned and so, to complete it in time, I brought in an amazing crew of co-authors. Together, we managed to put together 17 chapters on how to manage security in one of the...
-
The big security news this week is the six vulnerabilities found in various image uploader ActiveX controls. In case you haven't seen the news , there are exploits available publicly for remote vulnerabilities in five different ActiveX controls. US-CERT is offering the, relatively unhelpful, advice...
-
A couple of weeks ago I published a script to list installed updates . Predictably, one of the comments ask for a version that can do that remotely. Here it is. This version can be run a couple of ways. First, you can double-click it. If you do it will prompt you for which computer to list the updates...
-
If you are still on Windows XP SP2 with Internet Explorer (IE) 6, and you install the security update announced in MS07-069 , then you may just have lost your ability to surf much of the web with IE. Apparently that combination causes IE to crash when you go to a web site, according to Microsoft Knowledge...
-
Well, sure it is. According to the Firefox web site, which must of course be untainted by marketing claims since it is Mozilla, " Firefox continues to lead the way in online security". OK, marketing hyperbole aside, I'm a data guy. I care about what the data says. Fortunately, Jeff Jones...
-
When I was a child, I learned a saying that I still find important to keep in mind: Those who are sitting in a glass house shall not throw stones The good folks at Mozilla may want to look up what that really means. Two days ago, Mozilla published Firefox version 2.0.0.5 to fix a security vulnerability...
-
Snake oil , for those that are not familiar with the U.S. English vernacular, is a derogatory term for some product that makes unverifiable or exaggerated claims. True to the tradition, we now find " Vista Firewall Control ," complete with a PC World article that includes not only incorrect...
-
As with Protect Your Windows Network I wrote some tools for the Windows Vista Security book that just came out. However, the Vista book does not come with a CD. Rather, Wiley has made the tools available for download . If you solemnly promise that you will buy the book, you may get the tools from there...
-
Thor Larholm, unhelpfully, published details on what he claims is a 0-day exploit for Internet Explorer (IE) yesterday. This exploit is actually for Firefox, but Thor exploited it by making IE launch Firefox. Firefox creates three protocol handlers. A protocol handler is essentially a mapping from an...
-
All U.S. Government computers are finally required to conform to one of two configurations. White House Memo M-07-11 , further clarified in M-07-18 directs all government agencies to use a single hardening guide. M-07-18 clarifies that it is to be the NIST guide . Overall, this is welcome news. The agencies...
-
In my most recent article in TechNet Magazine I wrote: Unfortunately, icacls.exe can’t show you the owner of an object. There is no way to actually see, from the command line, who the owner of an object is. Furthermore, if you save the ACL for an object, it does not save the owner of the object. As an...
-
TechNet Magazine just published the first of several articles with excerpts from the Windows Vista Security Book . " New ACLs Improve Security in Windows Vista " is what they called the first of two excerpts from the Access Control chapter. The same issue of the magazine also has an interesting...