<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; ray</title>
	<atom:link href="http://www.spamchronicles.com/author/ray/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Computer Security Logs</description>
	<lastBuildDate>Tue, 05 Oct 2010 22:13:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Links of Interest&#8211;October 5, 2010</title>
		<link>http://www.spamchronicles.com/2010/10/05/links-of-interestoctober-5-2010/</link>
		<comments>http://www.spamchronicles.com/2010/10/05/links-of-interestoctober-5-2010/#comments</comments>
		<pubDate>Tue, 05 Oct 2010 22:13:33 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Quick Bits]]></category>
		<category><![CDATA[links]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/2010/10/05/links-of-interestoctober-5-2010/</guid>
		<description><![CDATA[Comcast Rolls Out Constant Guard Bot Detection – Comcast has been piloting a security service where it monitors it’s customers PCs for bot activity and notifies them if any is detected. Comcast seems to be taking a good approach to this. They don’t require you to install any software, instead they look for bot related [...]]]></description>
			<content:encoded><![CDATA[<p><a title="Jump to the COmcast blog entry" href="http://blog.comcast.com/2010/09/security-scene-constant-guard-rolls-out.html">Comcast Rolls Out Constant Guard Bot Detection</a> – Comcast has been piloting a security service where it monitors it’s customers PCs for bot activity and notifies them if any is detected. Comcast seems to be taking a good approach to this. They don’t require you to install any software, instead they look for bot related network traffic from your connection.</p>
<p>The notification will include links for self-help or “professional assistance” which will cost you.</p>
<p><a title="Jump to the website" href="http://safetyandsecuritymessaging.org/">Stop – Think – Connect</a> is a website put together by a coalition led by the Anti-phishing Work Group and National Cyber Security Alliance. The website offers tips and advice related to online security.</p>
<p>Macworld provides a quick article on how to <a title="Jump to the Macworld article" href="http://www.macworld.com/article/154559/2010/10/password_protect_folders.html">encrypt a folder on OS X</a>, no additional software needed.</p>
<p><a title="Jump to the Ars article" href="http://arstechnica.com/web/news/2010/10/opting-out-of-behavioral-ad-tracking-may-get-easier.ars">Ars Technica</a> reports that advertisers have announced a program to allow users to opt-out of behavioral advertising tracking. The program is voluntary on the part of advertisers.</p>
<p><a title="Jump to the Windows Team blog article" href="http://windowsteamblog.com/windows_live/b/windowslive/archive/2010/09/27/hotmail-security-updates-protect-you-from-account-hijackers.aspx">Hotmail</a> has enhanced their security, making it harder to hijack your account.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/29/google-getting-into-malware-detection/" rel="bookmark" class="crp_title">Google Getting Into Malware Detection</a></li><li><a href="http://www.spamchronicles.com/2010/09/28/broken-security-its-the-law-possible-future/" rel="bookmark" class="crp_title">Broken Security: It&#8217;s The Law (possible future)</a></li><li><a href="http://www.spamchronicles.com/2007/05/27/eight-anti-spam-tips/" rel="bookmark" class="crp_title">Eight Anti-Spam Tips</a></li><li><a href="http://www.spamchronicles.com/2006/11/27/spam-project-launched/" rel="bookmark" class="crp_title">Spam Project Launched</a></li><li><a href="http://www.spamchronicles.com/2007/08/08/spam-news-from-around-the-web/" rel="bookmark" class="crp_title">Spam News From Around The Web</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2010/10/05/links-of-interestoctober-5-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Broken Security: It&#8217;s The Law (possible future)</title>
		<link>http://www.spamchronicles.com/2010/09/28/broken-security-its-the-law-possible-future/</link>
		<comments>http://www.spamchronicles.com/2010/09/28/broken-security-its-the-law-possible-future/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 02:56:45 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[legislation]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/?p=157</guid>
		<description><![CDATA[The NY Times (among others) reports on the Obama administration’s desire to force software developers to build backdoors into security software. This seems like a law just begging for unintended consequences.

This doesn’t have to be viewed as an evil attempt to expand power. It’s realistic to view this as a way to keep the same abilities as they have with the old technology. Just like businesses that see their market fad away as technology advances, legislate rather than compete.]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-158" title="KRASH_FistInWall" src="http://www.spamchronicles.com/wp-content/uploads/2010/09/KRASH_FistInWall.png" alt="Graphic comic image of fist crashing through a wall" width="490" height="391" />The NY Times (among others) reports on the Obama administration’s desire to force software developers to build <a title="Jump to the NY TImes article about encryption backdoor" href="http://www.nytimes.com/2010/09/27/us/27wiretap.html">backdoors into security software</a>. This seems like a law just begging for unintended consequences.</p>
<p>This doesn’t have to be viewed as an evil attempt to expand power. It’s realistic to view this as a way to keep the same abilities as they have with the old technology. Just like businesses that see their market fad away as technology advances, legislate rather than compete.</p>
<p>Let’s assume there’s zero abuse and it’s used as described, after getting a legally obtained warrant for legitimate criminal investigations. How long before those backdoors make it out into the world? It can only be a matter of time.</p>
<p>From the article, an event in Greece was mentioned:</p>
<blockquote><p>In 2005, it was discovered that hackers had taken advantage of a legally mandated wiretap function to spy on top officials’ phones, including the prime minister’s.</p></blockquote>
<p>Unfortunately, unlike telephones, modern communication travels the internet, out there for anyone to pull in the bits.</p>
<p>Let’s face it, the bad guys will still have their own backdoor-free encryption but gain access to the legal stuff. That is, those who were already smart enough to use strong encryption today. It’s not like the U.S. has the market on programmers cornered. There’s also those who say the new law wouldn’t force open source development to include the backdoors.</p>
<p>Others have pointed out there’s other ways to get the information, such as sneaking in a key logger. Granted, probably not a effective as having a ready-made door, but a lot fewer problems. With the backdoor they’ll still only catch the stupid criminals, and the smart criminals will have another way to rip off the honest folks.</p>
<p>The world moves forward, legislation is not going to stop it.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/" rel="bookmark" class="crp_title">Microsoft Out of Band Patch for Advisory 2416728</a></li><li><a href="http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/" rel="bookmark" class="crp_title">U.S. AntiSpyware Legislation: Oh-oh</a></li><li><a href="http://www.spamchronicles.com/2007/04/18/annoying-antivirus-software/" rel="bookmark" class="crp_title">Annoying Antivirus Software</a></li><li><a href="http://www.spamchronicles.com/2007/04/29/summary/" rel="bookmark" class="crp_title">Spam Counts and Summary</a></li><li><a href="http://www.spamchronicles.com/2007/05/06/summary-of-week-ending-may-5th/" rel="bookmark" class="crp_title">Summary of Week Ending May 5th</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2010/09/28/broken-security-its-the-law-possible-future/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Out of Band Patch for Advisory 2416728</title>
		<link>http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/</link>
		<comments>http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 02:18:25 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/?p=154</guid>
		<description><![CDATA[Microsoft will be releasing a security patch to address a vulnerability in ASP.NET documented in security advisory 2416728, “Vulnerability in ASP.NET Could Allow Information Disclosure.” The bulletin lists just about every still supported desktop and server OS along with what appears to be every still supported .NET version.]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p><a rel="attachment wp-att-155" href="http://www.spamchronicles.com/?attachment_id=155"></a><img class="aligncenter size-full wp-image-156" title="Security-Patch-Windows-tile" src="http://www.spamchronicles.com/wp-content/uploads/2010/09/Security-Patch-Windows-tile.gif" alt="Category tile for Windows Security Patches" width="475" height="150" />Microsoft will be releasing a security patch to address a vulnerability in ASP.NET documented in <a title="Jump to the Microsoft Security Bulletin" href="http://www.microsoft.com/technet/security/advisory/2416728.mspx">security advisory 2416728</a>, “Vulnerability in ASP.NET Could Allow Information Disclosure.” The bulletin lists just about every still supported desktop and server OS along with what appears to be every still supported .NET version.</p>
<p>Initially the patch will only be available for manual download on Tuesday and will then make it to Windows Update in the next few days.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates and Moving On</title>
		<link>http://www.spamchronicles.com/2007/09/11/updates-and-moving-on/</link>
		<comments>http://www.spamchronicles.com/2007/09/11/updates-and-moving-on/#comments</comments>
		<pubDate>Wed, 12 Sep 2007 02:11:20 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/site-news/updates-and-moving-on/</guid>
		<description><![CDATA[It&#8217;s been a month since the last update to this site. Reality sets in and I realize I don&#8217;t have time to maintain this site and my other site. So I&#8217;ll be adding any new security and spam related content to The OS Quest. No more updates to the Spam Chronicles for awhile. What&#8217;s already [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/deadatdesk.thumbnail.jpg" alt="Dead at Desk" align="left" />It&#8217;s been a month since the last update to this site. Reality sets in and I realize I don&#8217;t have time to maintain this site and my other site. So I&#8217;ll be adding any new security and spam related content to The OS Quest. No more updates to the Spam Chronicles for awhile. What&#8217;s already here will remain.</p>
<p>So head on over to <a href="http://www.theosquest.com" title="Jump to theosquest.com">The OS Quest</a> for future updates.  This week we have:</p>
<p><a href="http://www.theosquest.com/2007/09/11/security-quest-1a-introduction-and-catching-up/" title="Jump to the posting at theosquest.com">Security Quest 1a</a>: Recent Security News and Getting Caught Up</p>
<p><a href="http://www.theosquest.com/2007/09/11/security-quest-1b-microsoft-patch-tuesday/" title="Jump to the Patch Tuesday posting at theosquest.com">Security Quest 1b</a>: Microsoft Patch Tuesday info</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/13/spam-counts-and-misc-news-for-week-ending-may-13th/" rel="bookmark" class="crp_title">Spam Counts and Misc News for Week Ending May 13th</a></li><li><a href="http://www.spamchronicles.com/2007/04/09/comment-and-trackback-spam/" rel="bookmark" class="crp_title">Comment and Trackback Spam</a></li><li><a href="http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/" rel="bookmark" class="crp_title">Microsoft Out of Band Patch for Advisory 2416728</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/" rel="bookmark" class="crp_title">OSX Security Update 2007-007</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/09/11/updates-and-moving-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for August 2007</title>
		<link>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/</link>
		<comments>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 20:26:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-august-2007/</guid>
		<description><![CDATA[Microsoft patch Tuesday for August 2007 brings us 6 critical and 3 important security updates from Microsoft. Microsoft summarizes the patches in their August summary. Every supported desktop version of Windows is affected by one or more patches. Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Microsoft patch Tuesday</strong> for August 2007 brings us <strong>6 critical</strong> and <strong>3 important</strong> security updates from <strong>Microsoft</strong>. Microsoft <a title="Jump to the Microsoft article about the security patches" href="http://www.microsoft.com/technet/security/bulletin/ms07-aug.mspx">summarizes the patches</a> in their August summary. Every supported desktop version of Windows is affected by one or more patches.  Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. Microsoft Office for Mac also needs patching.</p>
<p>Rather than repeating all the patches I&#8217;ll direct you to news.com which has a <a title="Jump to the news.com summary of the Microsoft patches" href="http://news.com.com/8301-10784_3-9759611-7.html?tag=nefd.only">good summary of the patches</a> along with links to the individual bulletins. The patches are available through automatic updates or individual downloads.</p>
<p>Happy patching and good luck.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/" rel="bookmark" class="crp_title">Microsoft Out of Band Patch for Advisory 2416728</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam News From Around The Web</title>
		<link>http://www.spamchronicles.com/2007/08/08/spam-news-from-around-the-web/</link>
		<comments>http://www.spamchronicles.com/2007/08/08/spam-news-from-around-the-web/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 03:12:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/news/spam-news-from-around-the-web/</guid>
		<description><![CDATA[These are some Spam related articles that caught my attention recently. Google Mistakes Own Blog For Spam, Deletes It (via Yahoo News) &#8211; Google thought one of its own blogs was a spam blog so turned it over to someone else. Oops. Google does usually send a notification but they say the bloggers &#8220;overlooked&#8221; it. [...]]]></description>
			<content:encoded><![CDATA[<p>These are some Spam related articles that caught my attention recently.</p>
<p><a title="Jump to the article on Yahoo news" href="http://news.yahoo.com/s/pcworld/20070808/tc_pcworld/135686">Google Mistakes Own Blog For Spam, Deletes It</a> (via Yahoo News) &#8211; Google thought one of its own blogs was a spam blog so turned it over to someone else. Oops. Google does usually send a notification but they say the bloggers &#8220;overlooked&#8221; it.</p>
<p>The Storm Worm has been <a title="Jump to one of the articles. Thos one one at networkworld.com" href="http://www.networkworld.com/news/2007/080207-black-hat-storm-worms-virulence.html">spreading to alarming levels</a> according to several articles around the net. The jist of the article that the botnet (Storm installs bots on it&#8217;s targets) has grown so big there&#8217;s probably plans to change it from use as a spam sender (which is a common use). Some speculate it may be rented out to launch denial of service (Dos) attacks. The story made it to the <a title="Jump to the Slashdot posting" href="http://it.slashdot.org/article.pl?sid=07/08/08/1416243&amp;from=rss">Slashdot</a> from page.</p>
<p>Slashdot also has a posting about a <a title="Jump to the Slashdot posting" href="http://it.slashdot.org/article.pl?sid=07/08/08/127227&amp;from=rss">popup that can&#8217;t be stopped</a>. It circumvents popup blockers, they can be sized to fill the entire screen, and cannot be closed by the user. Oh joy.</p>
<p>Techdirt has the story of a guy who <a title="Jump to the article at Techdirt" href="http://techdirt.com/articles/20070807/005917.shtml">sued a spammer</a> being told to pay the legal fees of the company he sued. The CAN-SPAM act limited who could sue spammers to ISPs. So some people found a loophole (they thought) to become ISPs and they sued. The judge ruled the business was set up for the sole purpose of suing. Part of me is happy he has to pay because he did manipulate things to sue. On the other hand he probably *should* be able to sue but that&#8217;s the fault of our Congress which defined legal spam in the CAN SPAM law and gave spammers legal cover.</p>
<p>Security Fix is reporting about <a title="Jump to the article at the Security Fix blog" href="http://blog.washingtonpost.com/securityfix/2007/08/fake_taxfiling_sites_inflict_t.html">scam tax rebate sites</a>. They&#8217;re popping up even though it&#8217;s not April 15th. October 15th is the deadline for people who filed for an extension. If you get an unsolicited email saying you&#8217;re due a refund but need to supply a credit card number to get it your probably (is there any doubt?) getting scammed. Another scam promotes the site as part of the IRS e-File program. Sometimes they submit the return but the refund goes to them.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/06/summary-of-week-ending-may-5th/" rel="bookmark" class="crp_title">Summary of Week Ending May 5th</a></li><li><a href="http://www.spamchronicles.com/2007/04/15/viruses-spam-and-software-updates/" rel="bookmark" class="crp_title">Viruses, Spam and Software Updates</a></li><li><a href="http://www.spamchronicles.com/2007/05/29/google-getting-into-malware-detection/" rel="bookmark" class="crp_title">Google Getting Into Malware Detection</a></li><li><a href="http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/" rel="bookmark" class="crp_title">U.S. AntiSpyware Legislation: Oh-oh</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/08/08/spam-news-from-around-the-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSX Security Update 2007-007</title>
		<link>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 02:32:39 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/osx-security-update-2007-007/</guid>
		<description><![CDATA[Apple almost made it through the month of July without an operating system security update which would have been a first for the year. But OS X Security Update 2007-007 was released on the last day of the month. Thirteen components are updated. Click the thumbnail to see the component list or visit the Apple [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.png" title="OS X Security Update 2007-007"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.thumbnail.png" alt="OS X Security Update 2007-007" align="left" /></a><b>Apple</b> almost made it through the month of July without an operating system security update which would have been a first for the year. But <b>OS X Security Update 2007-007</b> was released on the last day of the month.</p>
<p>Thirteen components are updated. Click the thumbnail to see the component list or visit the <a href="http://docs.info.apple.com/article.html?artnum=306172" title="Jump to the Apple support page for the update">Apple Support Page</a> for the complete details. Of special note is the Samba vulnerability that Apple has finally patched. Samba is an open source windows file sharing application that is bundled with OS X. A critical vulnerability was found in late may and almost immediately patched by the Samba team. Apple has released several security updates since then but none have included the Samba patch, until now. Samba is off by default but is enabled when turning on Windows sharing in System Preference -&gt; Sharing.</p>
<p>The update is for both Intel and PPC based Macs running OS X 10.3.9 or OS X 10.4.10 including the standard OS and the Server OS. It&#8217;s available through Apple&#8217;s built-in software update service or as a standalone download. A computer restart is needed after applying the patch.</p>
<p>Apple also released <a href="http://www.apple.com/support/downloads/airportextremeupdate2007004.html" title="Jump to the Airport Extreme Update support page">Airport Extreme Update 2007-004</a>. Details are lacking and Apple&#8217;s only comment is:</p>
<blockquote><p>This update is recommended for all Intel-based MacBook, MacBook Pro, and Mac mini computers and improves the reliability of AirPort connections.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Stats Plugin Vulnerability Plugged</title>
		<link>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 20:25:10 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/wordpress-stats-plugin-vulnerability-plugged/</guid>
		<description><![CDATA[I usually don&#8217;t mention WordPress vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched). The WordPress Stats plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 [...]]]></description>
			<content:encoded><![CDATA[<p>I usually don&#8217;t mention <strong>WordPress </strong>vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched).</p>
<p>The <a title="Jump to the Plugin page on wordpress.org" href="http://wordpress.org/extend/plugins/stats/">WordPress Stats</a> plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 and was released July 27th.</p>
<p>I typically turn off (deactivate) plugins before updating them and in this case I had to re-enter the API key when activating the updated plugin.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/" rel="bookmark" class="crp_title">Site Upgraded to WordPress 2.2</a></li><li><a href="http://www.spamchronicles.com/2007/06/24/spam-counts-for-week-ending-june-24-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 24, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Firefox 2.0.0.6 Released</title>
		<link>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 13:04:47 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/mozilla-firefox-2006-released/</guid>
		<description><![CDATA[Mozilla has released a security update to Firefox 2, making it the second update this month. Firefox 2.0.0.6 is available through the built-in auto-update feature or as a standalone download. One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Mozilla</strong> has released a security update to <strong>Firefox 2</strong>, making it the second update this month. <a title="Jump to the Firefox 2.0.0.6 release notes" href="http://en-us.www.mozilla.com/en-US/firefox/2.0.0.6/releasenotes/">Firefox 2.0.0.6</a> is available through the built-in auto-update feature or as a <a title="Jump to the Get Firefox website" href="http://getfirefox.com">standalone download</a>.</p>
<p>One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to the vulnerability that was found when IE 7 passed a malformed URI to Firefox.</p>
<p>The moderate vulnerability is &#8220;Privilege escalation through chrome-loaded about:blank windows&#8221;. This was dependant on add-ons creating about:blank windows.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.5 Released</title>
		<link>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/#comments</comments>
		<pubDate>Wed, 18 Jul 2007 19:19:54 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2005-released/</guid>
		<description><![CDATA[Mozilla has released Firefox 2.0.0.5 which patches eight security vulnerabilities in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities. Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Mozilla</strong> has released <strong><a title="Jump to the Firefox 2.0.0.5 release notes" href="http://www.mozilla.com/en-US/firefox/2.0.0.5/releasenotes/">Firefox 2.0.0.5</a></strong> which patches eight <strong>security vulnerabilities</strong> in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities.</p>
<p>Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating means:</p>
<blockquote><p>Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.</p></blockquote>
<p>Two vulnerabilities were rated as &#8220;high&#8221; which means:</p>
<blockquote><p>Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.</p></blockquote>
<p>The remaining three vulnerabilities where rated as moderate (1) or low(2).</p>
<p>The update will be installed through Firefox&#8217;s auto-update feature. You can force an update check by going to the Help on the menu and selecting &#8220;Check for Updates&#8230;&#8221;. You can also download the full version from the website and run the installation over your current installation. The update is for all languages on all operating systems.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

