Archive for month: August, 2008

Troubleshooting Tips

19 August, 2008 (15:36) | General, tools | By: admin

Found a great article today from Tech Republic, 10+ tips for improving problem determination and resolution. When that phone rings, the clock starts running. The sooner you can resolve the caller’s problem, the better off both of you will be. #1: Remember Occam’s Razor #2: Ask carefully about the “simple” causes #3: Use open-ended questions [...]

WebEx ActiveX buffer overflow

18 August, 2008 (08:00) | General, Security, Software, Web | By: admin

From Cisco’s website A buffer overflow vulnerability exists in an ActiveX control used by the WebEx Meeting Manager. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the user client machine. The WebEx Meeting Manager is a client-side program that is provided by the Cisco WebEx meeting service. The Cisco [...]

Tracking down StormWorm

18 August, 2008 (07:00) | General, Malware, Security, Web | By: admin

This guy knows StormWorm.

Countdown to IPv6

18 August, 2008 (05:00) | General, Software, Web, network | By: admin

From Ars Technica A week ago, we reached the magic number of 2.7 billion IPv4 addresses used. With 3.7 billion possible addresses,¹ this means we now have less than a billion unused IPv4 addresses left. …. In other words, unless something unexpected happens, we’ll be out of IPv4 addresses at some point in the neighborhood [...]

Apple MobileMe Phishing Scam

15 August, 2008 (10:17) | Apple, General, Software, Web | By: admin

From US-CERT US-CERT is aware of public reports of a phishing attack circulating via email messages that appear to be targeting Apple MobileMe users. These messages claim that there is a problem with the user’s billing information and instruct the user to follow a web link to update personal information. Clicking on this link directs [...]

Black Tuesday Overview

13 August, 2008 (04:32) | General, Microsoft, Security, Software | By: admin

Black Tuesday overview courtesy of SANS Internet Storm Center.

Fake IE 7 Update

11 August, 2008 (07:00) | General, Malware, Microsoft, Security, Software, Web | By: admin

According to SANS Internet Storm Center, a new spam campaign is offering fake IE 7 updates. You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the “Unsubscribe” link below. Malware-Test Lab reports clicking the [...]

Proactive Support

9 August, 2008 (22:42) | General, Malware, Security, Software, Web | By: admin

After writing an earlier post about detecting java script exploits, I decided to start googling.  Without overstating the obvious, I found a lot of infected sites.   I cranked up my antivirus settings to obscene and started clicking.  Goolge was blocking many of them and firefox attempted to block another huge chunk. I continued into the [...]

The End of Non-Compete Clauses?

9 August, 2008 (10:59) | General | By: admin

From Ars Technica Noncompete clauses are a reality of the modern labor market as companies seek to keep their employees from using the experience and information they gain in one position from turning into a liability when those employees find jobs elsewhere. California law was a bit of an exception, as it appeared to limit [...]

More SQL Injection attacks

9 August, 2008 (10:34) | General, Malware, Security, Software, Web | By: admin

SANS Internet Storm Center has a great method for detecting a common SQL injection attack on your webservers.  Just google: site:yoursite “script src=http://*/””ngg.js”|”js.js”|”b.js” I have also had luck checking TLDs with site:*.edu “script src=http://*/””ngg.js”|”js.js”|”b.js”