Archive | 2003

CIO Magazine: FrankenPatch — the story of SQL Slammer

Some interesting conclusions that patching doesn’t work. Not convinced that I agree. Patching may not work if the underlying operating system is insecure enough, perhaps. But an interesting read.

CIO: FrankenPatch. “Those looking to cast blame–and there were many–cried a familiar refrain: If everyone had just patched his system in the first place, Slammer wouldn’t have happened. But that’s not true. And therein lies our story. Slammer was unstoppable. Which points to a bigger issue: Patching no longer works.” Link from Tomalak’s Realm

FoxForum Wiki RSS Feeds: 2.0 okay, 1.0 broken

Due to differences in the way the RSS feeds are implemented, the FoxForum Wiki RSS 1.0 feed is broken until the wiki web is able to support Web Services again. Unfortunately, the site suffered a hardware meltdown and is being rebuilt, but it will take a while… Meanwhile, subscribe to the RSS 2.0 feed for up-to-date wiki topics. There’s quite an entertaining mix of information and opinion, one of the best sites on the web for things FoxPro.

Patent Office re-examines early claim for browser-object embedding

O’Reilly Network: PTO Director Orders Re-Exam for ‘906 Patent. “In what could be good news for the Web, the Director of the US Patent and Trademark Office has ordered a re-examination of the ‘906 patent, which was the subject of a patent infringement lawsuit this summer brought by Eolas against Microsoft.” Linked from Tomalak’s Realm

Good news, I think. A patent restriction could be really damaging for many browser manufacturers, and the claim appears to be dubious.

Microsoft Monthly Security Bulletins for November 2003

It’s the first Wednesday of the month, and that means more security bulletins from Microsoft. This month’s come in two emails titled “Microsoft Windows Security Bulletin Summary for November 2003” and “Microsoft Office Security Bulletin Summary for November 2003” and consist of

  • MS03-048 – Cumulative Update for Internet Explorer (824145)
  • MS03-049 – Buffer Overrun in the Workstation Service Could Allow
    Code Execution (828749)

  • MS03-050 – Vulnerabilities in Microsoft Word and Microsoft
    Excel Could Allow Arbitrary Code to run (831527)

  • MS03-051 – Buffer Overrun in Microsoft FrontPage Server
    Extensions Could Allow Code Execution (813360)

All result in “Remote Code Execution” which certainly sounds like a bad thing to me.

You’ll find copies of the bulletins at: http://www.microsoft.com/technet/security/bulletin/winnov03.asp and http://www.microsoft.com/technet/security/bulletin/offnov03.asp.

It’s the 46th week of the year.

Internet Explorer to get pop-up blocker with SP2

News.Com: Internet Explorer to stomp pop-ups. “Darin Linnman, a Microsoft spokesman, said that the company plans to add the pop-up blocking feature to an updated version of Explorer with Service Pack 2 when it’s released in the first half of next year.” Link from Tomalak’s Realm

Now there’s innovation! I wonder if they’ll use the Mozilla model or the Opera model, the two browsers I use instead of IE.

Matrix: Revolutions

Laura and I held off seeing Matrix: Revolutions until the Saturday matinee. I’m glad we had a long car ride home, so I could try to explain some of what I *think* I had figured out. Animatrix supplied a lot of clues that other folks didn’t get. That said, the opinions on Slashdot are all over the place, in the posting “The Matrix: Resolutions” While reading Slashdot, I recommend raising the threshold to 4 or 5 to cut down on the amount of reading.

Powered by WordPress. Designed by Woo Themes

This work by Ted Roche is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 United States.