<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>CompHobby! - Security</title>
    <link>http://comphobby.org/</link>
    <description>Occasional ramblings of a somewhat older male tech enthusiast.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 08 Apr 2008 04:49:44 GMT</pubDate>

    <image>
        <url>http://comphobby.org/templates/Modified/img/s9y_banner_small.png</url>
        <title>RSS: CompHobby! - Security - Occasional ramblings of a somewhat older male tech enthusiast.</title>
        <link>http://comphobby.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>A Backup Strategy of Sorts!!</title>
    <link>http://comphobby.org/archives/161-A-Backup-Strategy-of-Sorts!!.html</link>
            <category>PersonalTech</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/161-A-Backup-Strategy-of-Sorts!!.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=161</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=161</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    I&#039;ve actually always had one really. A very haphazard one but a &lt;em&gt;backup strategy&lt;/em&gt; none the less. On most of the PCs I&#039;ve owned until &lt;a href=&quot;http://comphobby.org/archives/157-Mini-Computers-I-Like-Em-The-AOpen-965D.html&quot; title=&quot;the new server&quot;&gt;recently anyway&lt;/a&gt;, always had more than one hard disk installed. The plan was to take valuable files and make duplicate copies on the additional drive. Then I would always make duplicate copies of stuff on different PCs as well, also I always seem to copy files from one OS to another on the same PC if possible. Things I would tend to copy would be pictures, un drm&#039;d musics files, copies of databases, my web and mail servers, install programs, user keys, personal settings, configurations ...etc. Then there were the several USB flash devices I had acquired that I put various files I deemed necessary for one reason or another and they were of course very useful for moving stuff from one machine to another.  The word centralized was not however in my vocabulary as the scattered method had always gotten me through the few emergencies I ever encountered without to much pain.&lt;br /&gt;
&lt;br /&gt;
Recently though the idea of a &lt;em&gt;network attached storage&lt;/em&gt; device had been intriguing me as a means of sort of automating the process and a way of centralizing everything. I at one point considered building &lt;a href=&quot;http://www.mashie.org/casemods/udat1.html&quot; title=&quot;small footprint file server&quot;&gt;such a device&lt;/a&gt; or maybe getting a &lt;a href=&quot;http://www.thecus.com/products_over.php?cid=11&amp;amp;pid=1&quot; title=&quot;N2100&quot;&gt;bring your own disks&lt;/a&gt; type rig. There is certainly no shortage of options in the market right now and it almost seems like if one can visualize what they want they can either find a solution out the box or make it themselves. My criteria were pretty simple I wanted it now so it had to be available locally which is really huge as where I live as shopping choices for hardware are somewhat limited. It also had to be fairly compact because I wanted it hanging off my wireless router, and most importantly it had to be dead simple to to use. I wanted to plug it in, find it on my network, set it up, and start using it period without installing any additional software to access it. It also had to be accessible from Linux as well as Windows. With my criteria in mind I set out to one of the chain computer/home electronics style stores located around here. Very few choices were available but I was expecting that so I settled for &lt;a href=&quot;http://www.buffalotech.com/products/network-storage/linkstation/linkstation-live/&quot; title=&quot;LinkStation Live&quot;&gt;one of these&lt;/a&gt; in the 500GB flavor from Circuit City.&lt;div align=&quot;center&quot;&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://comphobby.org/uploads/ls-live-lg.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/ls-live-lg.jpg&#039;,&#039;Zoom&#039;,&#039;height=515,width=475,top=262,left=410,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot; title=&quot;Buffalo LinkStation Live&quot;&gt;&lt;!-- s9ymdb:36 --&gt;&lt;img width=&quot;207&quot; height=&quot;225&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://comphobby.org/uploads/ls-live-lg.Thumb.jpg&quot; alt=&quot;Buffalo LinkStation Live&quot; /&gt;&lt;/a&gt;&lt;/div&gt;I knew it wasn&#039;t going to be terribly fast but I was pleased to find out that it wasn&#039;t terribly slow either and by that I mean for a home user not doing automated backups, but just backing up user files using the mapped drive interface its speed is tolerable. Now on my server via software I have backup set to happen synchronously  and currently is at about 1 GB of data. Since it is set up synchronously it just runs in the background and keeps up with the task as things change hopefully causing a minimal impact on the servers perfomance.  The initial backup took well over an hour and I used the &lt;a href=&quot;http://www.memeo.com/autobackupstandard.htm&quot; title=&quot;AutoBackUp&quot;&gt;Memeo AutoBackUp&lt;/a&gt; software that came bundled with the &lt;em&gt;LinkStation Live&lt;/em&gt; which  is only a trail version as the registration number they bundled with it did not work (less than honest sh*t imho). It would not copy empty folders and as slow as it seemed to be I wasn&#039;t about to buy it. So I&#039;ve been on a download spree trying almost every free product out there before settling on another &lt;a href=&quot;http://www.techsoftpl.com/backup/index.php&quot; title=&quot;MirrorFolder is a real-time mirroring and synchronization software to backup files from your local computer drive to another local/removable/network drive.&quot;&gt;trialware offering&lt;/a&gt;. The program is called &lt;em&gt;MirrorFolder&lt;/em&gt; and it completed the initial copy in less than 20 minutes which might not sound all that fast but compared to the various programs I gave a shot it is lightening fast and very easy on system resources. It copies everything you tell it to and as far as I can tell does what the program&#039;s writer says it will. To a new user this is not exactly the most intuitive interface but the program&#039;s performance compared to other offerings make the learning curve a worthwhile endeavor. &lt;br /&gt;
&lt;br /&gt;
As far my backup strategy goes I&#039;ll still do all the things I mentioned in the beginning of the post I&#039;ve just expanded a bit to include some new automation tools and hardware. Just for the record the LinkStation Live plays very nicely with Linux (Ubuntu anyway) as my installation had no problems finding and making it usable. Still though the whole experience has been sort of a mixed one for me being somewhat tainted by the bundled Memeo trialware debacle and I found the documentation that came with the product lacking. I mean there is a PDF file on the install CD which I didn&#039;t use and it is also available on the LinkStation Live once one has managed to connect to it. I just prefer a well written quick start guide in paper form at least. After all I did not want to have to install any software to connect it. Luckily I did not have to but I can see where some users might not have any choice as basically the PDF gave that out as the first step.&lt;br /&gt;
&lt;blockquote&gt;Insert the LinkNavigator CD into your computer’s CD-ROM drive.&lt;br /&gt;
On a PC, setup should automatically launch. If it does not, manually launch setup.exe by pressing Start and selecting the Run... option. When the Run dialog opens, type d:\setup.exe (where d is the drive letter of your CD-ROM drive). Press OK to continue.&lt;br /&gt;
&lt;br /&gt;
Installing Software&lt;br /&gt;
If you are installing the software on a Mac, open the CD and click LinkNavigator to begin installation.&lt;/blockquote&gt;Not what I was realy looking for... a minor thing but a thing none the the less.  
    </content:encoded>

    <pubDate>Sun, 09 Mar 2008 12:07:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/161-guid.html</guid>
    
</item>
<item>
    <title>How Well can You Spot A Scam</title>
    <link>http://comphobby.org/archives/154-How-Well-can-You-Spot-A-Scam.html</link>
            <category>PersonalTech</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/154-How-Well-can-You-Spot-A-Scam.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=154</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=154</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    It has been awhile since I&#039;ve posted anything as I have been really busy trying to get things setup where I work. That being said though I always at least skim my compliment of various types of sites and look at what is happening around the web as far as news goes. I ran ran across this &lt;a href=&quot;http://www.siteadvisor.com/quizzes/phishing_0707/&quot;  title=&quot;Can you tell a fake Web site from a real one? Do you always know which e-mails are legitimate?&quot;&gt;McAfee SiteAdvisor Phishing Quiz&lt;/a&gt; . I got nine out ten correct. So I guess that would translate into something like I could spot a fake 90% of the time. Only problem with that though is it only takes one time to really mess up one&#039;s day. Of course this kind of test isn&#039;t an absolute indication of how likely one is to become a scam victim but just an exercise in recognizing what is happening in the wild. Staying safe from scammers  is in my opinion is part &lt;a href=&quot;http://en.wikipedia.org/wiki/Lottery_scam&quot;  title=&quot;A typical lottery scam begins with an unexpected email notification that &#039;You have won!&#039;&quot;&gt;common sense&lt;/a&gt;, coupled with use of &lt;a href=&quot;http://www.cert.org/homeusers/HomeComputerSecurity/&quot;  title=&quot;Your home computer is a popular target for intruders.&quot;&gt;tools and best practices&lt;/a&gt;.   
    </content:encoded>

    <pubDate>Sun, 29 Jul 2007 13:46:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/154-guid.html</guid>
    
</item>
<item>
    <title>Digital Music More Risky Than Porn?</title>
    <link>http://comphobby.org/archives/153-Digital-Music-More-Risky-Than-Porn.html</link>
            <category>News</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/153-Digital-Music-More-Risky-Than-Porn.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=153</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=153</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    Don&#039;t really know about this one as the article doesn&#039;t really define risk very well .&lt;blockquote&gt;McAfee&#039;s SiteAdvisor said that music and technology related websites have a negative impact on computers since they often leave spyware and other malicious codes, which can lead to a massive increase in the amount of spam generated.&lt;br /&gt;
&lt;br /&gt;
The study revealed that browsing porn websites through search engine has a 9 percent risk of infecting PCs with spyware, adware and spam. This figure jumps to 19 percent when searching for digital music. Other sites that can harm computers are those related to electronic gadgets and for background wallpapers.&lt;/blockquote&gt;By define risk I mean is giving up personal info to some pornographer somewhere safer than downloading some  P2P file sharing application and using it to share copyrighted materials. Both practices sound fairly risky to me. Check out the &lt;a href=&quot;http://www.earthtimes.org/articles/show/69209.html&quot;  title=&quot; Porn websites safer than digital music websites&quot;&gt;Earth Times Online Newspaper&lt;/a&gt; for more.  
    </content:encoded>

    <pubDate>Mon, 04 Jun 2007 20:08:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/153-guid.html</guid>
    
</item>
<item>
    <title>License To Use The Internet</title>
    <link>http://comphobby.org/archives/152-License-To-Use-The-Internet.html</link>
            <category>News</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/152-License-To-Use-The-Internet.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=152</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=152</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    We&#039;ve heard this stuff before about how clueless PC users are turning the Internet into some sort of front end for international crime syndicates..... &lt;blockquote&gt; Service providers and everyday users were singled out by panelists and audience members for not taking enough responsibility. Attendees slammed ISPs for not searching for rogue computers on their network or shutting off internet access to compromised PCs reported to them by security companies, charging that ISPs were endangering the internet to avoid support calls from cut off customers.&lt;br /&gt;
&lt;br /&gt;
For their part, users don&#039;t care about security because the rogue zombie software often only uses minimal computing power, making the background spam-spouting code not their problem.&lt;br /&gt;
&lt;br /&gt;
A few audience members argued seriously that computer users should have to take a test to get an internet license, maintain botnet insurance and have their machines inspected for information-super highway worthiness. Others countered that individuals shouldn&#039;t have to know how to secure their own computers -- the machines should simply be more inherently secure. &lt;/blockquote&gt;Personally I don&#039;t think it is going to happen. Users are not going to be licensed, ISPs could generally care less, until of course they get caught with a malware spewing botnet in their network. Even then at most they&#039;ll just block the users in question and get even more clueless users to replace them. As far as systems getting more inherently secure well how long have the major players been working on that one and is it better or worse than say five years ago.  Oh well for the whole article that I pulled the above quote from head over to &lt;a href=&quot;http://www.wired.com/politics/security/news/2007/06/bot_strategy#&quot;  title=&quot;Desperate Botnet Battlers Call for an Internet Driver&#039;s License&quot;&gt;Wired News&lt;/a&gt; and check out the rest.  
    </content:encoded>

    <pubDate>Mon, 04 Jun 2007 19:28:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/152-guid.html</guid>
    
</item>
<item>
    <title>Some Quick Notes</title>
    <link>http://comphobby.org/archives/150-Some-Quick-Notes.html</link>
            <category>AltOS</category>
            <category>News</category>
            <category>PersonalTech</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/150-Some-Quick-Notes.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=150</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=150</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    For Dell &lt;a href=&quot;http://direct2dell.com/one2one/archive/2007/05/01/13147.aspx&quot;  title=&quot;Dell to Offer Ubuntu 7.04&quot;&gt;Ubuntu it is&lt;/a&gt;..&lt;blockquote&gt;In February when Dell launched IdeaStorm as forum for customers to contribute ideas for product offerings, we received overwhelming feedback that customers wanted Linux on desktops and notebooks. As part of an overall effort to update our Linux program, today we are announcing a partnership with Canonical to offer Ubuntu on select consumer desktop and notebook products. &lt;/blockquote&gt;Anyone who reads this site with any regularity might have guessed I am a Ubuntu fan. I really hope Dell can pull this off but realize all experiences with Ubuntu are not &lt;a href=&quot;http://www.extremetech.com/article2/0,1697,2124099,00.asp&quot;  title=&quot;Ubuntu Linux 7.04 Feisty Fawn Review&quot;&gt;always fun&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Saw on another site today there is some really wicked malware that can allegedly &lt;a href=&quot;http://www.vitalsecurity.org/2007/05/how-to-break-pc-in-less-than-10-minutes.html&quot;  title=&quot;How to break a PC in less than 10 minutes&quot;&gt;destroy a PC in than 10 Minutes&lt;/a&gt;.&lt;blockquote&gt;A good 30MB+ of individual files are downloaded onto the PC, and it just kills it. Kills it right in the face. Kills it right in the face with a brick and then comes back with a breeze block to finish the job.&lt;/blockquote&gt;Really sounds nasty I am looking forward to the follow up on that one.&lt;br /&gt;
&lt;br /&gt;
Then lately there is this whole &lt;a href=&quot;http://www.joost.com/&quot;  title=&quot;TV, the way you want it&quot;&gt;Joost&lt;/a&gt;  thing going on. Taking a page from Google and Gmail by making it an invite only thing at first to peak interest these guys have got it going on for the moment. We&#039;ll see how it works out as some &lt;a href=&quot;http://news.zdnet.com/2100-9588_22-6180541.html&quot;  title=&quot;Joost goes one beta better&quot;&gt;big players have jumped in&lt;/a&gt; with them. Still not having seen the service myself it sounds like yet another way for them (whoever them represents) to get advertisements onto my PC. Self directed reruns and commercials sort of like cable only the way I want it instead of the package cable provides. Curious yeah but not that much though.&lt;br /&gt;
&lt;br /&gt;
Of course with Microsoft&#039;s recent release of Vista things are starting to get interesting in the hackasphere. Shall we say &lt;a href=&quot;http://www.tgdaily.com/content/view/31858/108/&quot;  title=&quot; Vista hacks to be demoed at Black Hat conference&quot;&gt;game on&lt;/a&gt;?&lt;blockquote&gt;Las Vegas (NV) - A hacker duo will demonstrate several ways of getting past Windows Vista security in an upcoming Black Hat training class.  Polish security researcher Joanna Rutkowska and Alex Tereshkin will show off new rootkits and ways to defeat Vista’s vaunted BitLocker drive encryption.&lt;/blockquote&gt;An actual class on the subject of defeating a platform&#039;s security features for 3,000 dollars. Not my thing but I do find it interesting. I wonder if people attending a class like that sign &lt;a href=&quot;http://en.wikipedia.org/wiki/Non-disclosure_agreement&quot;  title=&quot;Non-disclosure agreement&quot;&gt;NDA&lt;/a&gt; documents or something similar.&lt;br /&gt;
&lt;br /&gt;
Last off in the incredible greed department there is this whole lets &lt;a href=&quot;http://www.savenetradio.org/&quot;  title=&quot;If the increased rates remain unchanged, the majority of webcasters will go bankrupt and silent on this date.&quot;&gt;screw up internet radio&lt;/a&gt; thing happening as well. One thing is for certain the entertainment industry really doesn&#039;t get their target demographic anymore in fact they are completely clueless about them... a side effect of greed I am sure. Well thats it for this installment.  
    </content:encoded>

    <pubDate>Tue, 01 May 2007 20:46:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/150-guid.html</guid>
    
</item>
<item>
    <title>What Does One Say To A First Time PC Buyer</title>
    <link>http://comphobby.org/archives/141-What-Does-One-Say-To-A-First-Time-PC-Buyer.html</link>
            <category>News</category>
            <category>PersonalTech</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/141-What-Does-One-Say-To-A-First-Time-PC-Buyer.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=141</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=141</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    I guess what I forget is that some people are really just beginning to grasp the whole Internet is really a place concept. Computer security really is important and that real and damaging things can happen as a result of venturing there. I am not a real long time PC user and many lessons I&#039;ve learned, I learned them the hard way. We&#039;ve been PC users at my house since 1996 and have gone from 28.8 dial up Internet access with one shared PC to always on cable connectivity and 5 PCs sharing a connection wireless style. Learned about mal, scum, ad, wares from the file sharing heydays of the post free Napster era. We had a teenager in the house and we all shared the same PC back then. Hell I&#039;ll admit it I have even fallen for the old in order to use this software for free we need to install something else line before. He wasn&#039;t the only one that ever took the bait. I have also been the victim of drive by installs and fought infections all the way to the point of reinstalling my OS more times than I can count. I learned about using antivirus, firewall, and patching my OS from getting viruses and worm infestations. Thing was back in our early days for us the stakes weren&#039;t so high as they are now. Sure things went wrong but they were annoyances more than anything else. I mean for us anyway online banking and bill paying were just getting cranked up around here. Data for about the first 5 years was a disposable commodity in our household. The PC really didn&#039;t have anything that personal to us on its hard drive. Sure it was inconvenient as hell to lose everything and start over but that was all it was really. Times changed rapidly though online banking, 401K management, bill paying, shopping, selling, even some online subscription stuff are pretty common with us now. Then there is the whole 100, 200, even 300+ gigabyte hard drive thing that is so common on PCs now lots of our personal stuff only exists as data. Backup strategies, quality protection products, patched and an up to date OS are musts, not options these days. As homes go we are more connected than some less connected than others, one  thing is for sure though the PC has gone from being a novelty entertainment item to more or less a necessity in our home.&lt;br /&gt;
&lt;br /&gt;
Anyone who knows me knows that I am pretty enthusiastic about PCs. It works out sometimes that people will even ask me for advice when they are about to make a purchase and as strange as it sounds some folks still don&#039;t own a computer. They will says things like we want/need one mostly for the kids really. I try and explain then that it really is in their best interest to become really well acquainted with the device that there are actually are certain risks associated with the use of a computer, especially where &lt;a href=&quot;http://www.securityfocus.com/columnists/408&quot;  title=&quot;MySpace, a place without MyParents&quot;&gt;young people are concerned&lt;/a&gt;. I will even go so far as to tell them that it is not just a one time purchase that actually between Internet and various security product charges there is really like sort of a yearly maintenance fee. I grasp for ways to explain what a &lt;a href=&quot;http://labmice.techtarget.com/security/socialengineering.htm&quot;  title=&quot;Social Engineering&quot;&gt;socially engineered threat&lt;/a&gt; is. The &lt;a href=&quot;http://www.spywareguide.com/&quot;  title=&quot;SpywareGuide is the leading public reference site for spyware and greynet research, details about spyware, adware and greynet applications and their behaviors, all compiled in an extensive updated database.&quot;&gt;evils of ad/spy/malware&lt;/a&gt;, why patching  is important but what could potentially happen &lt;a href=&quot;http://www.websense.com/securitylabs/blog/blog.php?BlogID=82&quot;  title=&quot;VML Candid Camera&quot;&gt;even on a patched system&lt;/a&gt;. Explain if any of this does happen they need to maintain some sort of backup strategy for their personal stuff because even if the machine can be brought back to a workable state the fact is that it was compromised and a reinstall of the OS is probably a good idea as well as changing email addresses, sensitive login information, possibly getting new credit cards ...etc. Explain about alternative browsers&#039; and email clients&#039; possible benefits ...etc. Some get it  some don&#039;t and that has really got me thinking a lot here lately maybe I should be telling them consider using Linux or buying a MAC as sort of a lower their exposure approach as opposed to a beefed up perimeter defense approach. Realistically I don&#039;t see Linux as a good option for a person looking to try out computers for the first time I mean when they can&#039;t just go to CompUSA or wherever and pick up the gadget/printer/card ...etc. and hook it up to their machine and have it working straight away then  disappointment will be their next emotive display. MACs on the other hand seem to have a very broad base of hardware available for them. They look good too. Just wish I had more experience with them. Who knows though maybe &lt;a href=&quot;http://www.microsoft.com/windowsvista/&quot;  title=&quot;Windows Vista &quot;&gt;Vista&lt;/a&gt; along with &lt;a href=&quot;http://www.windowsonecare.com/prodinfo/default.aspx&quot;  title=&quot;Windows Live OneCare&quot;&gt;Windows Live OneCare&lt;/a&gt; will simplify the average users experience and impact PC security in an overall positive way. One thing is for sure now the stakes for the average person are very high where personal security is concerned. Getting people to realize it is a big challenge though.  
    </content:encoded>

    <pubDate>Wed, 06 Dec 2006 07:25:00 -0600</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/141-guid.html</guid>
    
</item>
<item>
    <title>Microsoft Issues Fix For VML Flaw</title>
    <link>http://comphobby.org/archives/138-Microsoft-Issues-Fix-For-VML-Flaw.html</link>
            <category>News</category>
            <category>PersonalTech</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/138-Microsoft-Issues-Fix-For-VML-Flaw.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=138</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=138</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    Microsoft has broken their patch Tuesday cycle and &lt;a href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS06-055.mspx&quot;  title=&quot;Vulnerability in Vector Markup Language Could Allow Remote Code Execution (925486)&quot;&gt;issued a fix&lt;/a&gt; for the VML issue. This is one of those that everyone probably needs to apply immediately lest they visit an evil website and become zombified.  
    </content:encoded>

    <pubDate>Tue, 26 Sep 2006 18:38:12 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/138-guid.html</guid>
    
</item>
<item>
    <title>How Bad Things Happen More Unpatched VML Stuff...</title>
    <link>http://comphobby.org/archives/137-How-Bad-Things-Happen-More-Unpatched-VML-Stuff....html</link>
            <category>News</category>
            <category>PersonalTech</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/137-How-Bad-Things-Happen-More-Unpatched-VML-Stuff....html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=137</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=137</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    From Websense-Blog comes a movie showing how the VML flaw would be exploited by malicious websites....&lt;blockquote&gt;Now that we are seeing VML exploits proliferate the Internet, we thought it would be fun to grab a video capture of what happens when a workstation visits an infected site. We did a similar video when the WMF zero-day was released and our workstation was instantly flooded with Spyware applications and pop-ups galore. It was an impressive sight and obvious that you had just visited an infected site.&lt;br /&gt;
&lt;br /&gt;
So, we fired up our trusty video capture tools and pointed a VMWare workstation at a random site where our miners had recently discovered an iframe containing a VML exploit.&lt;br /&gt;
&lt;br /&gt;
But...what&#039;s this? Nothing happened, or so it seemed.&lt;/blockquote&gt;This one is well explained and very simple to understand everyone should check this one out. The blog entry can be &lt;a href=&quot;http://www.websense.com/securitylabs/blog/blog.php?BlogID=82&quot;  title=&quot;VML exploit in action.&quot;&gt;found here&lt;/a&gt; or if one prefers just go &lt;a href=&quot;http://www.websense.com/securitylabs/images/alerts/vml-movie.wmv&quot;  title=&quot;WMV file of exploit in action.&quot;&gt;straight to the video&lt;/a&gt; as it really drives the potential dangers of the issue home.  
    </content:encoded>

    <pubDate>Sun, 24 Sep 2006 15:15:55 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/137-guid.html</guid>
    
</item>
<item>
    <title>Zeroday Emergency Response Team</title>
    <link>http://comphobby.org/archives/136-Zeroday-Emergency-Response-Team.html</link>
            <category>News</category>
            <category>PersonalTech</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/136-Zeroday-Emergency-Response-Team.html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=136</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=136</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    &lt;a href=&quot;http://isotf.org/zert/&quot;  title=&quot;Zeroday Emergency Response Team (ZERT)&quot;&gt;ZERT&lt;/a&gt; for short has released a &lt;a href=&quot;http://isotf.org/zert/download.htm&quot;  title=&quot;unofficial patch for VML vulnerability&quot;&gt;hot-fix&lt;/a&gt; for the latest &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/925568.mspx&quot;  title=&quot;Vulnerability in Vector Markup Language Could Allow Remote Code Execution&quot;&gt;Internet Explorer Vulnerability&lt;/a&gt;. They also have a &lt;a href=&quot;http://www.isotf.org/zert/testvml.htm&quot;  title=&quot;test for VML vulnerability&quot;&gt;test page&lt;/a&gt; that allows users to test their  browsers and see if they are vulnerable. I tried it with the latest version of IE7 (my secondary browser) and I don&#039;t use Outlook at all so I did not bother with patch so I can&#039;t offer any details as to how easy it is to install or remove. It reported IE7 as not being affected on a XP SPK2 fully patched system. If they stick to their normal  schedule Microsoft will probably address this issue October 10 when they do their monthly patch thing. The exploit is &lt;a href=&quot;http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html&quot;  title=&quot;Seen in the wild: Zero Day exploit being used to infect PCs &quot;&gt;alive in the wild&lt;/a&gt; thus the reason I assume ZERT is offering the patch.  
    </content:encoded>

    <pubDate>Sun, 24 Sep 2006 13:21:40 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/136-guid.html</guid>
    
</item>
<item>
    <title>Security An Ongoing Process... Not An Event...</title>
    <link>http://comphobby.org/archives/129-Security-An-Ongoing-Process...-Not-An-Event....html</link>
            <category>News</category>
            <category>Ramble</category>
            <category>Security</category>
    
    <comments>http://comphobby.org/archives/129-Security-An-Ongoing-Process...-Not-An-Event....html#comments</comments>
    <wfw:comment>http://comphobby.org/wfwcomment.php?cid=129</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://comphobby.org/rss.php?version=2.0&amp;type=comments&amp;cid=129</wfw:commentRss>
    

    <author>nospam@example.com (Dale M)</author>
    <content:encoded>
    Well the patch Tuesday event from Microsoft has come and gone again with  &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms06-aug.mspx&quot;  title=&quot;Microsoft Security Bulletin Summary for August, 2006&quot;&gt;9 critical and 3 important patches&lt;/a&gt;. Anyone who hasn&#039;t done so yet should &lt;a href=&quot;http://windowsupdate.microsoft.com/&quot;  title=&quot;Windows Update&quot;&gt;go get patched&lt;/a&gt;. The Department Of Homeland Security is &lt;a href=&quot;http://www.dhs.gov/dhspublic/display?content=5789&quot;  title=&quot;DHS Recommends Security Patch to Protect Against a Vulnerability Found In Windows Operating Systems &quot;&gt;pitching&lt;/a&gt; one of the patches. Has that ever happened before?&lt;br /&gt;
&lt;br /&gt;
AOL &lt;a href=&quot;http://www.securityfocus.com/brief/274&quot;  title=&quot;AOL apologizes for privacy leak&quot;&gt;goofed recently&lt;/a&gt; giving up 658,000 er cough cough &lt;a href=&quot;http://www.nytimes.com/2006/08/09/technology/09aol.html?ei=5090&amp;amp;en=f6f61949c6da4d38&amp;amp;ex=1312776000&amp;amp;partner=rssuserland&amp;amp;emc=rss&amp;amp;pagewanted=all&quot;  title=&quot;A Face Is Exposed for AOL Searcher No. 4417749&quot;&gt;anonymous users&#039;&lt;/a&gt; search data. Apology is kind of lame but I think that is what the big boys call doing damage control.&lt;br /&gt;
 &lt;br /&gt;
&lt;a href=&quot;http://www.stopbadware.org/&quot;  title=&quot;Regaining Control of Our Computers&quot;&gt;StopBadware.org&lt;/a&gt; and partner Google have announced that...&lt;blockquote&gt;We&#039;re entering a new phase here at StopBadware.org. Google -- which is one of our partners -- is now presenting people with a warning before they visit websites that have been reported to StopBadware.org as sites that distribute badware. &lt;/blockquote&gt;Well I haven&#039;t been able to trip the warning but I guess they are still working out the mechanics of the whole thing. Anyway the warning page is supposed to &lt;a href=&quot;http://www.stopbadware.org/reports/reportdisplay?reportname=themexp&quot;  title=&quot;example badware page&quot;&gt;look something like this&lt;/a&gt;. There is a free Firefox extension or Internet Explorer plugin that I use that does prettty much the same thing called &lt;a href=&quot;http://www.siteadvisor.com/&quot;  title=&quot;McAfee SiteAdvisor&quot;&gt;McAfee Site Advisor&lt;/a&gt;. It also works with Firefox on Linux as well as Windows.&lt;br /&gt;
&lt;br /&gt;
Recently a couple security experts &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2006/08/hijacking_a_macbook_in_60_seco.html&quot;  title=&quot;Hijacking a Macbook in 60 Seconds or Less&quot;&gt;demonstrated&lt;/a&gt; wireless device driver flaws on the often &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2006/08/followup_to_macbook_post.html&quot;  title=&quot;Follow-up to the Macbook Post&quot;&gt;touted as more secure by default&lt;/a&gt; Mac platform.&lt;blockquote&gt;During the course of our interview, it came out that Apple had leaned on Maynor and Ellch pretty hard not to make this an issue about the Mac drivers -- mainly because Apple had not fixed the problem yet. Maynor acknowledged that he used a third-party wireless card in the demo so as not to draw attention to the flaw resident in Macbook drivers. But he also admitted that the same flaws were resident in the default Macbook wireless device drivers, and that those drivers were identically exploitable. And that is what I reported.&lt;/blockquote&gt;I wonder how Linux wireless device drivers stack up against this exploit? My guess would be not much differently.&lt;br /&gt;
&lt;br /&gt;
Last thing for this post I&#039;ll just call the &lt;a href=&quot;http://www.vitalsecurity.org/2006/08/dont-run-aim-screen-name-hacker.html&quot;  title=&quot;Don&#039;t run the AIM Screen Name Hacker&quot;&gt;scum of the week&lt;/a&gt;. It is a sort of interesting malware that employs a little social engineering to get people to install it by encouraging them to do something they ought not be doing anyway.&lt;blockquote&gt;Of course, the program is a complete scam - run it, and you get a fake message telling you that &quot;AOL has fixed the vulnerability&quot;. What they don&#039;t tell you, is that they also dropped a boatload of goodies - well, nasties - in your System32 folder. Those files will rip the top of your PC off and scream at you in a scary, THIS IS BROKE kind of fashion.&lt;/blockquote&gt; If they do install it... Well it does them and they no doubt are turned into spam and ad spewing legions of keystroke logged zombies or something. Keep an eye out and do not download or install &lt;a href=&quot;http://blog.spywareguide.com/2006/08/the_aim_screen_name_hacker_bew.html&quot;  title=&quot;The AIM Screen Name Hacker - Beware or Be Snared!&quot;&gt;The AIM Screen Name Hacker&lt;/a&gt;.  
    </content:encoded>

    <pubDate>Thu, 10 Aug 2006 14:29:00 -0500</pubDate>
    <guid isPermaLink="false">http://comphobby.org/archives/129-guid.html</guid>
    
</item>

</channel>
</rss>