RELEASE: Add your Gamer tag to your Blog!
Comments Off on RELEASE: Add your Gamer tag to your Blog!
Posted in Release
RELEASE: VOIP Phone for consumers using Windows Live Messenger Service
Comments Off on RELEASE: VOIP Phone for consumers using Windows Live Messenger Service
Posted in Product
NEWS: 2006… the big year for Microsoft?
Comments Off on NEWS: 2006… the big year for Microsoft?
Posted in Computers and Internet
UPDATE: Official WMF Vulnerability patch coming Jan 10th
Comments Off on UPDATE: Official WMF Vulnerability patch coming Jan 10th
Posted in Product
TOOL: Converting to WMA
Comments Off on TOOL: Converting to WMA
Posted in Tools
COMMENTARY: And you think YOU were ticked about IE’s stale evolution?
RELEASE: USB-based Beverage Cooler
Comments Off on RELEASE: USB-based Beverage Cooler
Posted in Computers and Internet
RELEASE: WMF vulnerability 3rd party patch released
(Note: Microsoft doesn’t recommend that people use this patch)
Ilfak Guilfanov who is being billed as one of the foremost experts in Windows low level technology has released a temporary/interim patch for Windows that’s NOT from Microsoft.
EXE file: http://castlecops.com/article-6436-nested-0-0.html
(MSI file located here: http://handlers.sans.org/tliston/WindowsMetafileFix.html)
Technical details:
"This is a DLL which gets injected to all processes loading user32.dll. It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore."
Once Microsoft releases an official patch, or if the above doesn’t work, you can uninstall it from your Add/Remove Programs menu. It’ll be listed as "Windows WMF Metafile Vulnerability HotFix".
The Internet Storm Center gives this patch its stamp of approval:
——————————————————————————–
We have very carefully scrutinized this patch. It does only what is advertised, it is reversible, and, in our opinion, it is both safe and effective.
The word from Redmond isn’t encouraging. We’ve heard nothing to indicate that we’re going to see anything from Microsoft before January 9th.
The upshot is this: You cannot wait for the official MS patch, you cannot block this one at the border, and you cannot leave your systems unprotected.
Comments Off on RELEASE: WMF vulnerability 3rd party patch released
Posted in Release
COMMENTARY: More reasons why Wiki’s a weak reference tool
Comments Off on COMMENTARY: More reasons why Wiki’s a weak reference tool
Posted in Computers and Internet
RELEASE: A commentary on the WMF Vulnerability
Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution. http://www.microsoft.com/technet/security/advisory/912840.mspx
- SOFTWARE DATA EXECUTION PROTECTION:
There’s a real simple solution – Enable software DEP, a feature of Windows XP Service Pack 2. Here’s a quote from the advisory that no one seems to be reading.
"I have software DEP enabled on my system, does this help mitigate the vulnerability?
Yes. Windows XP Service Pack 2 also includes software-enforced DEP that is designed to reduce exploits of exception handling mechanisms in Windows. By default software-enforced DEP applies to core operating system components and services. This vulnerability can be mitigated by enabling DEP for all programs on your computer.
For additional information about how to “Enable DEP for all programs on your computer”, see the product documentation."To enable or mess around with the DEP settings:
– Go to START->CONTROL PANEL->SYSTEM
– Click ADVANCED tab & press Performance SETTINGS button
– Click DATA EXECUTION PROTECTION tab
Make sure that the "Turn on DEP for essential Windows programs and services only" radio button is clicked. - HARDWARE DATA EXECUTION PROTECTION:
This is an even easier solution. Enable hardware DEP support (also called NX support) on your PC if you have a recent Pentium 4 from Feb 2005 on, or an AMD Athlon chip.
(BTW If you have no idea what this is, check out http://www.updatexp.com/data-execution-prevention.html for a 3rd party explanation of what software and hardware DEP is.) - DISABLE OR UNREGISTER "SHIMGVW.DLL"
A couple of security firms, including Verisign’s iDefense, have published workarounds that appear to mitigate the threat. According to iDefense, Windows users can disable the rendering of WMF files using the following hack:1. Click on the Start button on the taskbar.
2. Click on Run…
3. Type "regsvr32 /u shimgvw.dll" to disable.
4. Click ok when the change dialog appears.iDefense notes that this workaround may interfere with certain thumbnail images loading correctly, though I have used the hack on my machine and haven’t had any problems yet. The company notes that once Microsoft issues a patch, the WMF feature may be enabled again by entering the command "regsvr32 shimgvw.dll" in step three above.
Comments Off on RELEASE: A commentary on the WMF Vulnerability
Posted in Release

Comments Off on COMMENTARY: And you think YOU were ticked about IE’s stale evolution?
Posted in Commentary