Archive | Microsoft

Microsoft patch Tuesday for December

Microsoft issued two new patches and re-issued one other patch on their monthly patch Tuesday. MS05-054 is “Cumulative Security Update for Internet Explorer,” yes, IE, that exploit delivery engine that also displays web pages. Get it patched, and use it only when absolutely necessary! MS05-055 is a very specific patch for Windows 2000 SP4 that patches an exploit which would allow an elevation of privileges. MS05-050, “Vulnerability in DirectShow Could Allow Remote Code Execution” was re-released to for a “revised version” of the security update for users of Windows 2000 SP4, Windows XP SP1 and Windows 2003 – sounds like a patch to the patch.

Get patching!

Microsoft’s Office 12 standards move draws mixed reactions

Microsoft Watch from Mary Jo Foley reports that Pundits Give Microsoft’s Open XML Play Mixed Marks. “While the Massachusetts governor’s office (and attorney Larry Rosen, an open-source specialist) may be upbeat about Microsoft’s decision to push the Office 12 Open XML document format through the ECMA standards process, not everyone is equally bullish about Microsoft’s move.”

I was impressed with the positive tone of Larry Rosen’s review. A fair playing field benefits all, and it looks like Microsoft has taken some good first steps. However, Steven J. Vaughan-Nichols’ column cites several serious concerns. The best point in that article is the last: When the O-12 standard is a legitimate standards-body-approved standard, only then should it be considered as a peer to competing standards at that level. Before that, it’s just another proprietary, encumbered under-documented binary file format.

IE exploit still unpatched six months later

Computerworld News: “Attackers targeting unpatched IE bug, Microsoft warns. Microsoft today warned that attackers could exploit a critical unpatched bug in Internet Explorer, first reported in May, and take over a user’s computer.”

“Microsoft Corp. is warning Internet Explorer users to be careful where they browse because attackers are now targeting a critical unpatched bug in the software. If successful, these attackers could possibly use this bug to seize control of a user’s system, the company said.”

“Be careful?” With clever phishing schemes, unicode obfuscation of URIs, DNS poisoning and adware injection, it’s not possible to “be careful.” Just don’t use IE.

CentraLUG: 5 December: James Fogg on Windows-Linux Interoperability

Please note the change in location: we will be meeting in Little Hall Room 230, a lab with computers. On the NHTI map located at http://www.nhti.edu/welcome/nhtimap.pdf (warning: 1 Mb+ PDF), the building is marked “K”

The monthly meeting of CentraLUG, the Concord/Central New Hampshire chapter of the Greater New Hampshire Linux Users Group, occurs on the first Monday of each month on the New Hampshire Institute Campus starting at 7 PM. Open to the public. Free admission. Tell your friends.

This month’s meeting will feature James Fogg discussing Windows-Linux interoperability. James Fogg is a principal with JDFogg Technology Consulting, where he is a network engineer specializing in delivering IT, Telecommunications and Computer Services, Systems, Sales and Consulting to the Fortune 500.

Many companies now operate mixed environments and managers expect their technical staff to be able to “make it work.” James will provide some ideas on how to do it. He’ll be covering interoperability methods between Microsoft Windows products and Linux/Unix systems. File Sharing, Application Sharing, network Services (DNS, DHCP, NTP, etc.), Mail and Printing. Also included will be the basics of Linux, Unix and Active Directory authentication, authorization and auditing.

I was pleased to learn that in the most recent editions of Microsoft’s Services for Unix, Microsoft is including an NFS client. SFU is a downloadable component for the currently supported versions of Windows and Microsoft has committed to including some of the functionality future OS releases. Interoperability is Good. SFU is one of several things James plans to cover.

Hope to see you there!

Xbox 360 shortages: panic in the streets?

Ken “Caesar” Fisher over at Ars Technica reports “Xbox 360: shortages no joke. Today I ventured out into the wilderness of North Boston to gauge Xbox mania. Initial reports on the ground paint a pretty grim picture for pre-Christmas Xbox shipments.”

There’s two possible explanations. Many, many, many rumor-mongers insist that Microsoft is staging this shortage, coordinating press releases with the stores, to announce a record sell-out on the opening day and start a panic that Junior won’t get his new machine for Christmas. The other is that Microsoft is incapable of planning around all the challenges of shipping a product on time. Which seems more likely?

Microsoft announces Simple Sharing Extensions

Over at Scripting News, Dave Winer posts Sharing at so many levels!.

Microsoft has unveiled a new proposal called SSE, which stands for Simple Sharing Extensions for RSS and OPML. “… “Now, in 2005, almost ten years later, we may be grown-up enough to actually work this way.”

Tigers and their stripes. I’m skeptical, of course. There’s only so many times you can have formats and features embraced, enhanced, extended and extinguished (E^4) before you look at a gift from Microsoft very carefully. On the plus side, though, the spec is released under a Creative Commons license. Interesting.

Microsoft to seek ISO standardization for Office 12 formats

InfoWorld: Top News reports “Update: Microsoft to open Office document format. (InfoWorld) – Microsoftæon Monday said it will offer its Word, Excel, and PowerPoint document formats as open standards, a move that could spark a war with technology rivals over standard document formats.”

Interesting. I wonder if ISO standardization will really change the basic positioning. Will use of Microsoft’s mis-named “Open XML” be free from RAND licensing fees, patent encumberances, or the onerous licensing terms that made it inaccessible from GPL software?

Unpatched IE Javascript exploit published.

InfoWorld: Top News: Hackers publish code for critical IE bug. InfoWorld) – Security experts are warning Internet users to be careful where they click, thanks to a nasty unpatched bug in the way Microsoft Corp.’s Internet Explorer browser handles the JavaScript computer language. The bug is of particular concern because security researchers in the U.K. have now published “proof of concept” code showing how hackers could exploit the problem and possibly take over a Windows system.By Robert_McMillan@idg.com (Robert McMillan).

Just to review: never browse with an untrustworthy browser.

UPDATE: Details at the Internet Storm Center, raising their InfoCon level from green to yellow. ISC is labeling it a zero-day exploit. It’s certainly the potential for one.

Powered by WordPress. Designed by Woo Themes

This work by Ted Roche is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 United States.