<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4635567720205012055</id><updated>2012-01-19T07:12:43.378-07:00</updated><category term='Backups'/><category term='Security'/><title type='text'>GeoApps Security News</title><subtitle type='html'>Working in Computer Consulting for fun and (sometimes) profit.  These are recent security news items everybody who is online should be aware of.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default?start-index=101&amp;max-results=100'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>155</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1976643703324783802</id><published>2011-12-30T08:11:00.001-07:00</published><updated>2011-12-30T08:11:09.019-07:00</updated><title type='text'>Unusual out-of-cycle Microsoft Patch</title><summary type='text'>This one shouldn't affect most people, but system admins would be well advised to take a look at this seriously.  For Microsoft to issue an out-of-cycle patch on a Thursday is very unusual, so there may be some serious side-effects they're not disclosing.  Even if you don't think you're running an ASP.NET server you might be, as many modern services actually run a web server inside your </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1976643703324783802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1976643703324783802' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1976643703324783802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1976643703324783802'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/unusual-out-of-cycle-microsoft-patch.html' title='Unusual out-of-cycle Microsoft Patch'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2565417795878828145</id><published>2011-12-16T16:41:00.001-07:00</published><updated>2011-12-16T16:41:32.318-07:00</updated><title type='text'>Adobe Reader 9.4.7 patch is out</title><summary type='text'>This patch fixes an in-the-wild exploit.  Adobe Reader X has the same vulnerability but in its default configuration has protections which prevent the exploit from working.  If you have AR9, PATCH NOW.  If you have AR X, make sure your settings are configured properly.  Foxit Software has issued a press release claiming their software is not affected by this flaw.Adobe - Security Bulletins: </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2565417795878828145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2565417795878828145' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2565417795878828145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2565417795878828145'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/adobe-reader-947-patch-is-out.html' title='Adobe Reader 9.4.7 patch is out'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2724906322620622159</id><published>2011-12-16T08:36:00.001-07:00</published><updated>2011-12-16T08:36:04.061-07:00</updated><title type='text'>December Windows Update - PATCH NOW!  Also, Java updates are out.</title><summary type='text'>The December Windows Updates were released on Tuesday, and one of them is rated PATCH NOW! by SANS as it is actively being exploited already.  The patches are widely documented both on user-friendly blogs and Microsoft's Technet blog.ISC Diary | December 2011 Microsoft Black Tuesday SummarySecurity Updates for Microsoft Windows, Java — Krebs on SecurityMicrosoft today issued software updates to </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2724906322620622159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2724906322620622159' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2724906322620622159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2724906322620622159'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/december-windows-update-patch-now-also.html' title='December Windows Update - PATCH NOW!  Also, Java updates are out.'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8497661261434415682</id><published>2011-12-09T09:09:00.001-07:00</published><updated>2011-12-09T09:12:52.714-07:00</updated><title type='text'>Download.com IS STILL NOT safe to use</title><summary type='text'>This is a revision of my earlier post titled "Download.com may be safe to use again"They have taken what appears to be corrective steps.  A blog posting by them claims they have removed any toolbar bundles from open-source software and that they have removed the requirement that you have to be a "registered member") in other words "give them your email address") to download files directly without</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8497661261434415682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8497661261434415682' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8497661261434415682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8497661261434415682'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/downloadcom-is-still-not-safe-to-use.html' title='Download.com IS STILL NOT safe to use'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7774554730923311092</id><published>2011-12-08T08:58:00.001-07:00</published><updated>2011-12-08T08:58:49.446-07:00</updated><title type='text'>Update to Foxit Reader 5.1.3</title><summary type='text'>If you use the Foxit Reader instead of Adobe's bloated, insecure PDF reader, you should update.Foxit Reader Unspecified Memory Corruption Vulnerability - Secunia.comDescription: A vulnerability has been reported in Foxit Reader, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to an unspecified error. No further information is currently </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7774554730923311092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7774554730923311092' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7774554730923311092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7774554730923311092'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/update-to-foxit-reader-513.html' title='Update to Foxit Reader 5.1.3'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4386713442837593007</id><published>2011-12-08T06:30:00.005-07:00</published><updated>2011-12-09T09:13:18.307-07:00</updated><title type='text'>Download.com may be safe to use again</title><summary type='text'>revised and reposted on Fri 09 Dec 2011 at 09:10 AM MSTThey have taken what appears to be corrective steps.  A blog posting by them claims they have removed any toolbar bundles from open-source software and that they have removed the requirement that you have to be a "registered member") in other words "give them your email address") to download files directly without using their "download </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4386713442837593007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4386713442837593007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4386713442837593007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4386713442837593007'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/downloadcom-may-be-safe-to-use-again.html' title='Download.com may be safe to use again'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8422606809010037049</id><published>2011-12-07T09:52:00.001-07:00</published><updated>2011-12-07T09:52:46.818-07:00</updated><title type='text'>Avoid Download.com - some downloads include malware toolbars</title><summary type='text'>Apparently the change started this summer.  I usually choose to download from other sources, and since I have scripting disabled when I browse, even when I chose to get software from CNet's site I never saw this.  But other bloggers are reporting this, and it has been confirmed.  DO NOT USE DOWNLOAD.COM to get any downloads until this is corrected.  If you need to know where to get something that</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8422606809010037049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8422606809010037049' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8422606809010037049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8422606809010037049'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/avoid-downloadcom-some-downloads.html' title='Avoid Download.com - some downloads include malware toolbars'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7910671999842304799</id><published>2011-12-07T09:37:00.001-07:00</published><updated>2011-12-07T09:37:56.461-07:00</updated><title type='text'>Be very careful reading PDFs on the web or in email this week.</title><summary type='text'>I've seen a lot of stories about this yesterday and today.  Apparently there is a flaw in Adobe Reader that is being exploited right now.   Adobe is expected to release a patch next week, but for now, I recommend using an alternate PDF reader.  The lightest-weight alternative is Sumatra PDF, which I use, but I also use Foxit Reader.  If you use Foxit Reader, be sure to disable Javascript.The last</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7910671999842304799/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7910671999842304799' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7910671999842304799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7910671999842304799'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/be-very-careful-reading-pdfs-on-web-or.html' title='Be very careful reading PDFs on the web or in email this week.'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5908492124991961073</id><published>2011-12-01T12:46:00.000-07:00</published><updated>2011-12-01T12:46:00.136-07:00</updated><title type='text'>Patch Java NOW if you haven't already</title><summary type='text'>Folks, this looks like a bad one to have out in the wild.  If you don't run Firefox with NoScript, you have Java enabled in your browser, and have not patched, you are at risk regardless of whether you run Windows or OS X.Public Java Exploit Amps Up Threat Level — Krebs on SecurityAn exploit for a recently disclosed Java vulnerability that was previously only available for purchase in the </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5908492124991961073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5908492124991961073' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5908492124991961073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5908492124991961073'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/12/patch-java-now-if-you-haven-already.html' title='Patch Java NOW if you haven&amp;#39;t already'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4102414541970586159</id><published>2011-11-15T15:15:00.001-07:00</published><updated>2011-11-15T15:16:01.460-07:00</updated><title type='text'>Patches galore: Windows Updates, Flash Player, Firefox, iTunes, and Apple updates</title><summary type='text'>Just lost a long post with lots of links, but if you haven't done Windows Updates, or updated Flash Player this month, you need to update both ASAP as there are exploits either in the wild or imminent for both.  Search older posts here for pertinent download links.

If you run Firefox, update to either 8.0 or 3.6.24 as both have security fixes.  Thunderbird is now also at version 8 with security </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4102414541970586159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4102414541970586159' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4102414541970586159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4102414541970586159'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/11/patches-galore-windows-updates-flash.html' title='Patches galore: Windows Updates, Flash Player, Firefox, iTunes, and Apple updates'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7211689393283654798</id><published>2011-11-03T06:42:00.001-07:00</published><updated>2011-11-03T06:42:38.381-07:00</updated><title type='text'>Recent App Updates: Foxit Reader, WinAmp, MS Office 2007 SP3</title><summary type='text'>If you use these apps, you should probably update them.  The Enterprise version of Foxit Reader has not been updated yet, so rolling the update out will be problematic for system admins.  I prefer VLC to WinAmp but many still use WinAmp.Foxit ReaderFoxit Reader 5.1.027 October 2011The free Foxit PDF Reader has been updated to to Version 5.1.0.1021. This version contains new features including </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7211689393283654798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7211689393283654798' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7211689393283654798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7211689393283654798'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/11/recent-app-updates-foxit-reader-winamp.html' title='Recent App Updates: Foxit Reader, WinAmp, MS Office 2007 SP3'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2936480588155201815</id><published>2011-10-28T07:38:00.001-07:00</published><updated>2011-10-28T07:38:45.482-07:00</updated><title type='text'>QuickTime 7.7.1 available</title><summary type='text'>Unpatched QuickTIme is one of the primary ways by which Windows gets infected, so if you use QuickTime instead of my preferred media player VLC, you should patch.  Apple's security bulletin is here:About the security content of QuickTime 7.7.1QuickTime 7.7.1     QuickTime    Available for: Windows 7, Vista, XP SP2 or later    Impact: Viewing a maliciously crafted movie file may lead to an </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2936480588155201815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2936480588155201815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2936480588155201815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2936480588155201815'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/10/quicktime-771-available.html' title='QuickTime 7.7.1 available'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5023380012991436491</id><published>2011-10-20T21:11:00.001-07:00</published><updated>2011-10-20T21:11:35.153-07:00</updated><title type='text'>More info on why you should update Java JRE ASAP</title><summary type='text'>If you have Java installed (XP users check "Add/Remove Programs", Vista/Windows 7 users check "Programs and Features") you either need to uninstall it or update it. Two articles which are 'less user-hostile (most people say "more user-friendly") that the links I posted earlier are here:Critical Java Update Fixes 20 Flaws — Krebs on SecurityOracle Corp. released a critical update to plug at least </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5023380012991436491/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5023380012991436491' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5023380012991436491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5023380012991436491'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/10/more-info-on-why-you-should-update-java.html' title='More info on why you should update Java JRE ASAP'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7218124187154062146</id><published>2011-10-19T22:37:00.001-07:00</published><updated>2011-10-19T22:37:28.618-07:00</updated><title type='text'>Oracle releases BEAST-patched version of Java</title><summary type='text'>System Admins have another patch to roll out.  This one is IMHO not critical high-priority for internal computers which do little on the Internet, but it should be rolled out to your heavier Internet-using computers, especially roaming laptops as they would probably be more susceptible to the MITM attacks that BEAST requires.Oracle updates Java to stop SSL-chewing BEAST • The RegisterFirefox </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7218124187154062146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7218124187154062146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7218124187154062146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7218124187154062146'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/10/oracle-releases-beast-patched-version.html' title='Oracle releases BEAST-patched version of Java'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3921045824539738698</id><published>2011-10-13T07:34:00.001-07:00</published><updated>2011-10-13T07:34:44.502-07:00</updated><title type='text'>iTunes, Windows, iOS, OS X, and Safari all updated this week</title><summary type='text'>It's going to be a busy week for sysadmins.  On Tuesday Microsoft issued the monthly update set and Apple updated iTunes.  Both patch sets fix critical flaws, and I haven't seen any reports of problems so business admins should roll out the patch sets ASAP.  Anyone who is still using IE needs to patch ASAP as all current versions of IE have a vulnerability which allows "drive-by" infection.  See </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3921045824539738698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3921045824539738698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3921045824539738698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3921045824539738698'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/10/itunes-windows-ios-os-x-and-safari-all.html' title='iTunes, Windows, iOS, OS X, and Safari all updated this week'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6664515318201412244</id><published>2011-10-03T09:00:00.002-07:00</published><updated>2011-10-03T09:47:55.672-07:00</updated><title type='text'>99.8% of Commercial Exploits caused by failure to patch</title><summary type='text'>PATCH YOUR SYSTEMS!

According to Danish security company CSIS, most Windows infections by commercial malware are the result of failure to patch a few vulnerable apps:  Java JRE (37%), Adobe Reader/Acrobat (32%), Adobe Flash (16%), Internet Explorer (10%), Windows Help (3%), and Apple Quicktime (2%).  MSIE and Windows Help are patched automatically by Windows Update (which home users should have </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6664515318201412244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6664515318201412244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6664515318201412244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6664515318201412244'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/10/998-of-commercial-exploits-caused-by.html' title='99.8% of Commercial Exploits caused by failure to patch'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6823155026745496162</id><published>2011-09-21T19:05:00.001-07:00</published><updated>2011-09-21T19:05:37.246-07:00</updated><title type='text'>Adobe Flash Player updated again to plug zero-day attacks</title><summary type='text'>Once again the Adobe Flash Player needs to be updated.  As of this writing the MSI installer for the plugin version is NOT available (the ActiveX MSI is), but one hopes it will available soon.  Although the ZDNet story only says "Windows and Mac users", the Adobe Security Bulletin also mentions Linux and Solaris and Android users are vulnerable and need to update.Adobe to rush out Flash Player </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6823155026745496162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6823155026745496162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6823155026745496162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6823155026745496162'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/09/adobe-flash-player-updated-again-to.html' title='Adobe Flash Player updated again to plug zero-day attacks'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8009183714144792268</id><published>2011-09-20T09:34:00.001-07:00</published><updated>2011-09-20T09:34:35.928-07:00</updated><title type='text'>Re-release of Diginotar SSL fix for XP, Windows 2003 Server</title><summary type='text'>If you are still running XP and you apply updates manually, download and re-install KB2616676 manually - re-running Windows Update will NOT apply this patch.  A reboot is required.Microsoft fixes SSL 'kill switch' blooperMicrosoft re-released an update today for Windows XP to correct a snafu that left users vulnerable to potential "man-in-the-middle" attacks for most of last week.Monday's update </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8009183714144792268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8009183714144792268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8009183714144792268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8009183714144792268'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/09/re-release-of-diginotar-ssl-fix-for-xp.html' title='Re-release of Diginotar SSL fix for XP, Windows 2003 Server'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7989747812459292895</id><published>2011-09-14T11:16:00.001-07:00</published><updated>2011-09-14T11:16:18.300-07:00</updated><title type='text'>Adobe AND Microsoft Patch Tuesday - SysAdmins have work this week</title><summary type='text'>If you are a system admin, you are going to have a busy week.  Adobe patched Acrobat and Adobe Reader (versions 8, 9, and 10) and Microsoft patched Microsoft Office 2003 and later -- Office 2000 users are no longer supported and should switch to LibreOffice instead.  If you are still using Adobe Reader 8, please note that support for it ends on November 3, 2011, so it might be time to replace it </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7989747812459292895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7989747812459292895' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7989747812459292895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7989747812459292895'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/09/adobe-and-microsoft-patch-tuesday.html' title='Adobe AND Microsoft Patch Tuesday - SysAdmins have work this week'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5280808706553803706</id><published>2011-09-14T10:52:00.001-07:00</published><updated>2011-09-14T10:52:13.963-07:00</updated><title type='text'>Apple catches up with Microsoft and Mozilla - 3 weeks late</title><summary type='text'>If you are running OS X 10.5 a.k.a. Leopard this won't help you, so see How to: Disable DigiNotar security certificate.Apple strikes stolen SSL certificates from OS XApple had to issue a Mac OS X update because Safari, unlike Chrome and Firefox, relies on the operating system to tell it which certificates have been revoked or banned. The browser then either blocks access to sites that don't have </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5280808706553803706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5280808706553803706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5280808706553803706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5280808706553803706'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/09/apple-catches-up-with-microsoft-and.html' title='Apple catches up with Microsoft and Mozilla - 3 weeks late'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6418862608755520418</id><published>2011-09-06T22:11:00.001-07:00</published><updated>2011-09-06T22:11:15.279-07:00</updated><title type='text'>Emergency Windows and Mozilla updates issued</title><summary type='text'>Dutch certificate authority Diginotar was compromised recently, and as a result Microsoft has issued an out-of-cycle WIndows Update to remove them from the Trusted Certificates list.  If you use Internet Explorer (or Safari on Windows) as your preferred browser you need to apply this ASAP as one of the certificates that was spoofed is for *.google.com.   Firefox and Thunderbird have also been </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6418862608755520418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6418862608755520418' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6418862608755520418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6418862608755520418'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/09/emergency-windows-and-mozilla-updates.html' title='Emergency Windows and Mozilla updates issued'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5383551882089511956</id><published>2011-08-16T22:35:00.001-07:00</published><updated>2011-08-16T22:35:07.655-07:00</updated><title type='text'>Mozilla Security Updates</title><summary type='text'>The Mozilla group has been busy, issuing updates with security fixes to Firefox 3.6, Thunderbird, and Firefox 5 (upgrading it to 6).  I foresee a busy couple of weeks ahead.One comment -- Mozilla is shooting itself in the foot as far as corporate deployment by not providing us with MSI installers that we can script.  Upgrading computers one at a time is very expensive.ISC Diary | Firefox 3.6.20 </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5383551882089511956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5383551882089511956' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5383551882089511956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5383551882089511956'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/08/mozilla-security-updates.html' title='Mozilla Security Updates'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2514944098927352685</id><published>2011-08-10T12:42:00.006-07:00</published><updated>2011-08-10T13:02:13.014-07:00</updated><title type='text'>August Windows Updates critical, require reboot</title><summary type='text'>It has been too long since I posted here.  Microsoft's July update cycle was a small one with only one critical patch affecting Windows Vista/7 users, so I didn't bother blogging about it.  However, the August patch set is much larger -- two critical patches including one for Internet Explorer which Microsoft says is likely to be exploited soon.  The updates for M$ Windows and Microsoft Office </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2514944098927352685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2514944098927352685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2514944098927352685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2514944098927352685'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/08/august-windows-updates-critical-require.html' title='August Windows Updates critical, require reboot'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2494811687933577889</id><published>2011-08-10T09:20:00.001-07:00</published><updated>2011-08-10T09:20:10.383-07:00</updated><title type='text'>Apple QuickTime 7.7</title><summary type='text'>I should have blogged this when it first was announced, but today was the first day that I was able to download QT 7.7 from Apple's manual download site.  Previous to this you had to update your existing QT using Apple Software Update, and that didn't work for network managers.Apple QuickTime flaws haunt Windows users | ZDNetBy Ryan Naraine | August 3, 2011, 7:21pm PDTApple has shipped a </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2494811687933577889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2494811687933577889' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2494811687933577889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2494811687933577889'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/08/apple-quicktime-77.html' title='Apple QuickTime 7.7'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-9023513895722901994</id><published>2011-06-29T09:59:00.001-07:00</published><updated>2011-06-29T09:59:31.133-07:00</updated><title type='text'>Microsoft Office 2010 Service Pack 1 available</title><summary type='text'>Microsoft delivers Office 2010 Service Pack 1 | ZDNetSP1 consists of cumulative and public updates to date for the various point products that are part of Office 2010 and SharePoint 2010. Products that will get fixes and updates include Office 2010 suites, Project 2010, Visio 2010, Office 2010 servers, Office Web Apps, Search Server 2010, SharePoint 2010 Products and FAST Search Server 2010 for </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/9023513895722901994/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=9023513895722901994' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/9023513895722901994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/9023513895722901994'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/microsoft-office-2010-service-pack-1.html' title='Microsoft Office 2010 Service Pack 1 available'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1394382793413094577</id><published>2011-06-29T09:19:00.001-07:00</published><updated>2011-06-29T09:19:26.376-07:00</updated><title type='text'>Mozilla updates Thunderbird and Firefox, Apple Java and OS X Security updates</title><summary type='text'>Mozilla has consolidated their Thunderbird and Firefox websites under mozilla.org and has upgraded both Firefox and Thunderbird to version 5.0.  Apple has issued security updates to OS X and its version of Java.  I'm running Firefox 5 without issues on several systems, although my main system still has 3.6.18 because of the large number of extensions I use there.ISC Diary | Update: Thunderbird </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1394382793413094577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1394382793413094577' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1394382793413094577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1394382793413094577'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/mozilla-updates-thunderbird-and-firefox.html' title='Mozilla updates Thunderbird and Firefox, Apple Java and OS X Security updates'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6496127952888565842</id><published>2011-06-15T09:21:00.002-07:00</published><updated>2011-06-15T09:34:01.118-07:00</updated><title type='text'>Patch City: Microsoft and Adobe have simultaneous huge Patch Tuesdays</title><summary type='text'>System admins will be very busy this week as Microsoft's Patch Tuesday is a big one affecting many products and requiring a reboot, while Adobe rolled out simultaneous patches to Adobe Reader (8.3, 9.4.5, and 10.1.0), Flash Player (10.3.181.26, the second patch in a week), and Shockwave Player (11.6.0.626).  Combine that with last week's must-install patch to Java (6.0.26) and any system admin is</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6496127952888565842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6496127952888565842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6496127952888565842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6496127952888565842'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/patch-city-microsoft-and-adobe-have.html' title='Patch City: Microsoft and Adobe have simultaneous huge Patch Tuesdays'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1132502946584684223</id><published>2011-06-07T16:51:00.001-07:00</published><updated>2011-06-07T16:51:17.823-07:00</updated><title type='text'>Oracle Java 6 update 26 patches 17 security flaws</title><summary type='text'>Another day, another program to patch.ISC Diary | Oracle Releases Java Version 1.6.0.26 http://java.com/en/download/manual.jspOracle Releases Java Version 1.6.0.26 http://java.com/en/download/manual.jspJava Patch Plugs 17 Security Holes — Krebs on SecurityOracle today released an update to its ubiquitous Java software that fixes at least 17 security vulnerabilities in the program.The company is </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1132502946584684223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1132502946584684223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1132502946584684223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1132502946584684223'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/oracle-java-6-update-26-patches-17.html' title='Oracle Java 6 update 26 patches 17 security flaws'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6395448092072228307</id><published>2011-06-06T07:39:00.001-07:00</published><updated>2011-06-06T07:39:00.925-07:00</updated><title type='text'>VLC 1.1.10</title><summary type='text'>A new version of the free multimedia player VLC was released today to fix some security issues.VideoLAN - VLC: Official site - Free multimedia solutions for all OS!VLC 1.1.102011-06-06VideoLAN and the VLC development team present VLC 1.1.10, a minor release of the 1.1 branch.This release, 2 months after 1.1.9, was necessary because some security issues were found, and the VLC development team </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6395448092072228307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6395448092072228307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6395448092072228307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6395448092072228307'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/vlc-1110.html' title='VLC 1.1.10'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8958482920971370097</id><published>2011-06-06T07:27:00.001-07:00</published><updated>2011-06-06T07:27:37.776-07:00</updated><title type='text'>Another Flash Player Patch</title><summary type='text'>On Sunday Adobe released an update to Flash Player to combat a 0-day -- an exploit previously unknown which is "in the wild".  This may also affect Adobe Reader 9 and 10, so watch this space for updates for those programs in the next few days.ISC Diary | Adobe releases Flash Player patch on a Sunday to combat latest 0dayAdobe releases Flash Player patch on a Sunday to combat latest 0dayhttp://</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8958482920971370097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8958482920971370097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8958482920971370097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8958482920971370097'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/06/another-flash-player-patch.html' title='Another Flash Player Patch'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4484949335422007113</id><published>2011-05-13T11:57:00.001-07:00</published><updated>2011-05-13T11:57:56.296-07:00</updated><title type='text'>New version of Adobe Flash Player released</title><summary type='text'>This has much better privacy controls, comes with a new Control Panel applet (in Windows), and includes some security fixes.  Download it and install it soon, the Bad Guys will be sure to take advantage of security holes in the older versions soon.Adobe Flash Player 10.3 released (new Privacy Controls) - Security | DSLReports Forums Adobe Flash Player 10.3.181.14 released May 12, 2011Download </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4484949335422007113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4484949335422007113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4484949335422007113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4484949335422007113'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/05/new-version-of-adobe-flash-player.html' title='New version of Adobe Flash Player released'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-587472592086604669</id><published>2011-05-11T08:04:00.001-07:00</published><updated>2011-05-11T08:04:55.495-07:00</updated><title type='text'>Another reason to abandon debit cards</title><summary type='text'>If you shop at Michael's and have used your debit card there, I recommend you pay close attention to your bank account, or maybe even request a new debit card number by "losing" your debit card.Breach at Michaels Stores Extends Nationwide — Krebs on SecurityEarlier this month, arts &amp; crafts chain Michaels Stores disclosed that crooks had tampered with some point-of-sale devices at store registers</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/587472592086604669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=587472592086604669' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/587472592086604669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/587472592086604669'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/05/another-reason-to-abandon-debit-cards.html' title='Another reason to abandon debit cards'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3453753728372684061</id><published>2011-05-11T08:00:00.001-07:00</published><updated>2011-05-11T08:00:12.783-07:00</updated><title type='text'>A light "Patch Tuesday" from Microsoft this month</title><summary type='text'>Sysadmins deserve a light month every once in a while.  Microsoft's Patch Tuesday this month has only two patches, one of which affects servers on company networks and the other of which affects PowerPoint.  No reboot has been required on any workstation I have patched so far.  SANS rates both patches "Critical", meaning they need to be patched but exploitation is not widespread right </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3453753728372684061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3453753728372684061' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3453753728372684061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3453753728372684061'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/05/light-tuesday-from-microsoft-this-month.html' title='A light &amp;quot;Patch Tuesday&amp;quot; from Microsoft this month'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1448084828520432584</id><published>2011-05-11T07:51:00.001-07:00</published><updated>2011-05-11T07:51:56.466-07:00</updated><title type='text'>Turn off WebGL in new browsers</title><summary type='text'>As is typical of a new standard, after it has been out for a while people start discovering security flaws.  WebGL is no exception.  If you are running Firefox 4, use "about:config: to disable it.US CERT: WebGL Security Risksadded May 10, 2011 at 11:35 amUS-CERT is aware of reports indicating that WebGL contains multiple significant security issues. The impact of these issues includes arbitrary </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1448084828520432584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1448084828520432584' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1448084828520432584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1448084828520432584'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/05/turn-off-webgl-in-new-browsers.html' title='Turn off WebGL in new browsers'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8740636808528171401</id><published>2011-04-29T15:11:00.001-07:00</published><updated>2011-04-29T15:11:39.191-07:00</updated><title type='text'>Mozilla updates Firefox 3.6.17, 4.0.1, and Thunderbird 3.1.10</title><summary type='text'>Security patches included, be sure to update when you can.Mozilla Firefox 3.6.17 Release NotesWhat’s New in Firefox 3.6.17v.3.6.17, released April 28th, 2011Firefox 3.6.17 fixes the following issues found in previous versions of Firefox 3.6:          Fixed several security issues.Fixed several stability issues.                      Please see the            complete list of changes             in</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8740636808528171401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8740636808528171401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8740636808528171401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8740636808528171401'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/mozilla-updates-firefox-3617-401-and.html' title='Mozilla updates Firefox 3.6.17, 4.0.1, and Thunderbird 3.1.10'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5681120147769273820</id><published>2011-04-21T12:26:00.002-07:00</published><updated>2011-04-21T20:37:33.527-07:00</updated><title type='text'>Security updates available for Adobe Reader and Acrobat</title><summary type='text'>I use Foxit Reader or SumatraPDF in preference to Adobe Reader, but most users have Adobe installed.  Update 8:30 PM: added Krebs-on-Security blog reference info at bottom.

Adobe Reader and Acrobat Security Updates
Adobe released important security updates for Adobe Reader X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh OS. The  bulletin is posted here.
[snip]
Affected </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5681120147769273820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5681120147769273820' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5681120147769273820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5681120147769273820'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/security-updates-available-for-adobe.html' title='Security updates available for Adobe Reader and Acrobat'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5199610398068755936</id><published>2011-04-18T21:38:00.001-07:00</published><updated>2011-04-18T21:38:18.554-07:00</updated><title type='text'>Apple releases iTunes 10.2.2, includes security fix</title><summary type='text'>Apple releases iTunes 10.2.2, includes security fixApple releases iTunes 10.2.2, includes security fix. More here: http://support.apple.com/kb/DL1103About the security content of iTunes 10.2.2</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5199610398068755936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5199610398068755936' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5199610398068755936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5199610398068755936'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/apple-releases-itunes-1022-includes.html' title='Apple releases iTunes 10.2.2, includes security fix'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3281846181736992283</id><published>2011-04-18T21:27:00.001-07:00</published><updated>2011-04-18T21:27:12.585-07:00</updated><title type='text'>Adobe Patches Flash Player Again</title><summary type='text'>Don't forget you need different patches for Internet Explorer and Firefox/Opera.Adobe patches latest Flash zero-dayGoogle Chrome users got the the update Thursday        	        	 								        	 	 	 	     By Gregg Keizer, Computerworld  April 15, 2011 04:26 PM ET          	Adobe today patched a critical vulnerability in Flash Player that the company said criminals were already exploiting with</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3281846181736992283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3281846181736992283' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3281846181736992283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3281846181736992283'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/adobe-patches-flash-player-again.html' title='Adobe Patches Flash Player Again'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3370345516010331870</id><published>2011-04-15T20:18:00.001-07:00</published><updated>2011-04-15T20:18:44.826-07:00</updated><title type='text'>Apple issues massive set of patches</title><summary type='text'>If you run any Apple devices (anything running OS X or iOS, such as a Mac computer, iPad, or iPhone), you will want to check your patch status.US-CERT Current Activity: Apple Releases Security Updatesadded April 15, 2011 at 09:40 amApple has released the following security updates:Security Update 2011-002 addresses a vulnerability in the Certificate Trust Policy for Mac OS X v10.5.8, Mac OS X </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3370345516010331870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3370345516010331870' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3370345516010331870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3370345516010331870'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/apple-issues-massive-set-of-patches.html' title='Apple issues massive set of patches'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8988650611664823346</id><published>2011-04-15T20:10:00.002-07:00</published><updated>2011-04-15T20:15:43.202-07:00</updated><title type='text'>Emergency Out-of-cycle Flash Player Patch</title><summary type='text'>Of course it would come out on a Friday.  This is a "PATCH NOW" situation as this vulnerability is being exploited now.
For corporate installation, you may need to wait.  As of 19:03 MST on Fri 15 Apr 2011 the MSI installers are still the old version .  The EXEs are current, for manual installation.
Google has patched Chrome separately, since they have their own version of the Flash player.
Adobe</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8988650611664823346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8988650611664823346' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8988650611664823346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8988650611664823346'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/emergency-out-of-cycle-flash-player.html' title='Emergency Out-of-cycle Flash Player Patch'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3099493904541640739</id><published>2011-04-13T10:10:00.001-07:00</published><updated>2011-04-13T10:10:42.962-07:00</updated><title type='text'>VLC 1.1.9 released - security fixes</title><summary type='text'>VideoLAN has patched their VLC player to fix some security issues.  VideoLAN - NewsVLC 1.1.92011-04-12VideoLAN and the VLC development team present VLC 1.1.9, a minor release of the 1.1 branch.This release, not long after 1.1.8, was necessary because some security issues were found, and the VLC development team cares about security.This release also brings updated translations and a lot of small </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3099493904541640739/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3099493904541640739' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3099493904541640739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3099493904541640739'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/vlc-119-released-security-fixes.html' title='VLC 1.1.9 released - security fixes'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4369180481406929177</id><published>2011-04-13T08:31:00.001-07:00</published><updated>2011-04-13T08:31:40.371-07:00</updated><title type='text'>Record-Breaking Microsoft Black Tuesday</title><summary type='text'>It's the biggest one since last December's record, and it patches more vulnerabilities than that one.   SANS has given several of the patches its highest rating: "PATCH NOW!".  All the systems I have patched are stable, so if you're a home user, go ahead and run Microsoft Update.  Microsoft delivers monster security update for Windows, IEMicrosoft today patched a record 64 vulnerabilities in </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4369180481406929177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4369180481406929177' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4369180481406929177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4369180481406929177'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/record-breaking-microsoft-black-tuesday.html' title='Record-Breaking Microsoft Black Tuesday'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2331376388346838447</id><published>2011-04-11T20:02:00.001-07:00</published><updated>2011-04-11T20:02:08.914-07:00</updated><title type='text'>New Adobe Flash Zero-Day Flaw Being Exploited</title><summary type='text'>Be very careful with any documents (Word documents, Excel spreadsheets) you receive in email.  Do NOT just open them from your email program.  If you think they are legitimate, SAVE them to your hard drive, then submit them to VirusTotal for analysis by over 40 different anti-virus products.New Adobe Flash Zero Day Being Exploited? — Krebs on SecurityAttackers are exploiting a previously unknown </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2331376388346838447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2331376388346838447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2331376388346838447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2331376388346838447'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/04/new-adobe-flash-zero-day-flaw-being.html' title='New Adobe Flash Zero-Day Flaw Being Exploited'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3174189480963379051</id><published>2011-03-25T13:03:00.001-07:00</published><updated>2011-03-25T13:03:56.485-07:00</updated><title type='text'>VideoLAN Releases VLC Media Player 1.1.8</title><summary type='text'>I use VLC in preference to Windows Media player and iTunes/QuickTime.US-CERT: VideoLAN Releases VLC Media Player 1.1.8added March 25, 2011 at 07:43 amVideoLAN has released VLC Media Player 1.1.8 to address two vulnerabilities. These vulnerabilities are due to the improper handling of .AMV and .NSV files. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code.US-CERT</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3174189480963379051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3174189480963379051' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3174189480963379051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3174189480963379051'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/videolan-releases-vlc-media-player-118.html' title='VideoLAN Releases VLC Media Player 1.1.8'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6974870177778308228</id><published>2011-03-24T01:35:00.001-07:00</published><updated>2011-03-24T01:35:04.094-07:00</updated><title type='text'>SSL Certificates compromised, patches needed</title><summary type='text'>Wonderful news: on Wednesday, 23 March: an "out-of-cycle" Windows Update was released.  These are only rolled out when there are active attacks that can be fixed quickly.  Mozilla and Google have also rolled out patches, so if you run Firefox, please update it as well (Chrome auto-updates, while Firefox usually checks once a day).  The ZDNet ZeroDay article below has the "friendliest" write-up </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6974870177778308228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6974870177778308228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6974870177778308228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6974870177778308228'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/ssl-certificates-compromised-patches.html' title='SSL Certificates compromised, patches needed'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5762092074835883143</id><published>2011-03-22T12:39:00.001-07:00</published><updated>2011-03-22T12:39:59.521-07:00</updated><title type='text'>'A' patch day: Apple OS X, Adobe Reader, Adobe Flash Player all patched this week</title><summary type='text'>Apple patches Pwn2Own flaw in massive Mac OS X update | ZDNetBy Ryan Naraine | March 22, 2011, 9:20am PDTApple has shipped another Mac OS X mega-update with fixes for 54 security vulnerabilities, including one that was used to hijack an iPhone 4 device at this year’s CanSecWest Pwn2Own hacker challenge.The Pwn2Own vulnerability, exploited by researchers Charlie Miller (right) and Dion Blazakis, </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5762092074835883143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5762092074835883143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5762092074835883143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5762092074835883143'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/patch-day-apple-os-x-adobe-reader-adobe.html' title='&amp;#39;A&amp;#39; patch day: Apple OS X, Adobe Reader, Adobe Flash Player all patched this week'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5409328350691265653</id><published>2011-03-17T07:31:00.001-07:00</published><updated>2011-03-17T07:31:36.652-07:00</updated><title type='text'>Another Adobe Flash vulnerability being exploited now</title><summary type='text'>I have seen reports of a new flaw in Adobe Flash player in many places on the 'net over the past few days.  Adobe warns of Flash Player zero-day attack | ZDNetMalicious hackers are using rigged Microsoft Excel files to exploit  a zero-day flaw in Adobe’s ubiquitous Flash Player software.A security advisory from Adobe says the “critical” vulnerability affects the latest versions of Adobe Flash </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5409328350691265653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5409328350691265653' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5409328350691265653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5409328350691265653'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/another-adobe-flash-vulnerability-being.html' title='Another Adobe Flash vulnerability being exploited now'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7795652946964612077</id><published>2011-03-09T21:26:00.001-07:00</published><updated>2011-03-09T21:26:04.053-07:00</updated><title type='text'>More on Patch Tuesday ... including iTunes, Flash, and Shockwave updates</title><summary type='text'>A SysAdmin's work is never done.  Brian Krebs has a good write-up on this week's need for patches:Patch Tuesday, Etc. — Krebs on SecurityMicrosoft has issued security updates to fix at least four security holes in its Windows operating system and other software. Not exactly a fat Patch Tuesday from Microsoft, but depending on how agile you are in updating third-party applications like Flash, </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7795652946964612077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7795652946964612077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7795652946964612077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7795652946964612077'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/more-on-patch-tuesday-including-itunes.html' title='More on Patch Tuesday ... including iTunes, Flash, and Shockwave updates'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-307166585439413111</id><published>2011-03-09T11:03:00.001-07:00</published><updated>2011-03-09T11:03:20.037-07:00</updated><title type='text'>Windows and OS X Updates this week</title><summary type='text'>Windows Updates were released on Tuesday.  My XP system didn't require a reboot.  Windows 7 SP1 is out, with reports of some troubles.  Brian Krebs has a story on it: Before You Install Windows 7 Service Pack 1 — Krebs on SecurityApple updated Java a few days ago:Apple updates JavaApple has also released a couple of updates today.  Apparently, they are catching up on some Java updates that Oracle</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/307166585439413111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=307166585439413111' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/307166585439413111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/307166585439413111'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/windows-and-os-x-updates-this-week.html' title='Windows and OS X Updates this week'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7181259438423939199</id><published>2011-03-03T12:51:00.001-07:00</published><updated>2011-03-03T12:51:55.547-07:00</updated><title type='text'>Firefox, Thunderbird, iTunes, Adobe Reader, Adobe Flash Player, Foxit Reader all patched</title><summary type='text'>In addition to Windows Updates this month, system admins have their hands full patching lots of Internet-touching software:Apple plugs 57 major security holes in iTunes | ZDNetIf you use Apple’s iTunes software — whether on Windows or Mac OS X — it’s important that you immediately apply the latest software update.Apple has shipped iTuens [sic] 10.2 as a highly-critical patch to cover a whopping </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7181259438423939199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7181259438423939199' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7181259438423939199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7181259438423939199'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/03/firefox-thunderbird-itunes-adobe-reader.html' title='Firefox, Thunderbird, iTunes, Adobe Reader, Adobe Flash Player, Foxit Reader all patched'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7983583002612512931</id><published>2011-02-15T20:02:00.001-07:00</published><updated>2011-02-15T20:02:40.840-07:00</updated><title type='text'>Critical Windows Updates this month, Adobe Flash and Adobe Reader patches, and now Java 6u24</title><summary type='text'>I thought I was done patching after that incredible Tuesday last week:February 2011 Microsoft Black Tuesday SummaryAdobe - Security Bulletins: APSB11-01 - Security update available for Shockwave PlayerAdobe - Security Bulletins: APSB11-02 - Security update available for Adobe Flash PlayerAdobe - Security Bulletins: APSB11-03 - Security updates available for Adobe Reader and AcrobatAt least they </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7983583002612512931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7983583002612512931' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7983583002612512931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7983583002612512931'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2011/02/critical-windows-updates-this-month.html' title='Critical Windows Updates this month, Adobe Flash and Adobe Reader patches, and now Java 6u24'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5921033163748857679</id><published>2010-12-10T10:29:00.003-07:00</published><updated>2010-12-10T18:34:23.456-07:00</updated><title type='text'>More December Security Patches:  QuickTime, Firefox, and a huge Patch Tuesday coming</title><summary type='text'>The second week in December is starting with a bunch of patching.  So far this week, we have QuickTime, Firefox, and Thunderbird with security updates, and next Tuesday promises to be another record Patch Tuesday with patches for IE among other things.  (Updated Fri 10 Dec 2010  18:31 MST)

Apple QuickTime Patch Fixes 15 Flaws — Krebs on Security
Apple this week issued an update that plugs at </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5921033163748857679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5921033163748857679' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5921033163748857679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5921033163748857679'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/12/more-december-security-patches.html' title='More December Security Patches:  QuickTime, Firefox, and a huge Patch Tuesday coming'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8312954444055497487</id><published>2010-12-10T10:02:00.001-07:00</published><updated>2010-12-10T10:02:07.355-07:00</updated><title type='text'>Security Updates notes for November, 2010</title><summary type='text'>It has been a busy month, and I have not been keeping up with timely posting here.  I will try to keep this a little more current from now on.  We'll start with November's Patch Tuesday and go forward from there.  The final article linked below is definitely something anyone who uses open WiFi hotspots in Starbucks and other places should read.  Also, if you use Flash Player or Adobe Reader, both</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8312954444055497487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8312954444055497487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8312954444055497487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8312954444055497487'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/12/security-updates-notes-for-november.html' title='Security Updates notes for November, 2010'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7912908112393153451</id><published>2010-11-04T09:05:00.001-07:00</published><updated>2010-11-04T09:05:26.580-07:00</updated><title type='text'>Firefox, Thunderbird patched; Adobe Flash patch due today, other stuff</title><summary type='text'>More patching: Firefox has been patched to plug a 0-day flaw that was being exploited "in the wild", and Mozilla Thunderbird has been patched to fix the same bug (which was not exploitable in TBird).  Adobe's Flash Player and Adobe Reader 9 both have a vulnerability that is also currently being exploited; Adobe is supposed to issue a patch for the Flash player today (November 4, 2010) but Reader </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7912908112393153451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7912908112393153451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7912908112393153451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7912908112393153451'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/11/firefox-thunderbird-patched-adobe-flash.html' title='Firefox, Thunderbird patched; Adobe Flash patch due today, other stuff'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4941439091981329860</id><published>2010-11-04T08:17:00.001-07:00</published><updated>2010-11-04T08:17:35.816-07:00</updated><title type='text'>New 0-day flaw in IE 6, 7, and 8 not likely to be fixed</title><summary type='text'>This hit the blogs and tech news sites yesterday.  In one of Microsoft's write-ups, they point out that running as a "Limited User" (an account that doesn't have administrator privileges) is one way to avoid this exploit.  Firefox and Chrome are also not subject to this problem.  The Symantec article has the best technical details.Vulnerability in Internet Explorer Could Allow Remote Code </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4941439091981329860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4941439091981329860' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4941439091981329860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4941439091981329860'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/11/new-0-day-flaw-in-ie-6-7-and-8-not.html' title='New 0-day flaw in IE 6, 7, and 8 not likely to be fixed'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5259305527258852473</id><published>2010-10-21T10:13:00.000-07:00</published><updated>2010-10-21T10:13:00.373-07:00</updated><title type='text'>Firefox, Thunderbird, Chrome, and Real Player patches released</title><summary type='text'>Time for another round of patching, boys and girls.  Mozilla has patched both Firefox and Thunderbird, and Chrome has some more updates (although Chrome automatically updates itself silently).  If you have the Real Player installed, it, too, needs patching.SANS: Firefox 3.6.11 and 3.5.14 released Thunderbird 3.1.4 and 3.0.9 releasedFirefox 3.6.11 and 3.5.14 released, includes security updates (</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5259305527258852473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5259305527258852473' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5259305527258852473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5259305527258852473'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/10/firefox-thunderbird-chrome-and-real.html' title='Firefox, Thunderbird, Chrome, and Real Player patches released'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5864074469179890980</id><published>2010-10-12T21:00:00.001-07:00</published><updated>2010-10-12T21:00:09.760-07:00</updated><title type='text'>More discussion of today's patches</title><summary type='text'>It's looking like there really are some PATCH NOW! patches in today's set of fixes for Microsoft Windows.  Also, Oracle released a major patch for the Java Runtime Engine (JRE), taking it to 6u22.  If you have Java installed, you should patch that as well.  Get your Java patch here: Java Downloads for All Operating Systems.  Here are links to two stories with "user-friendly" discussions of why </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5864074469179890980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5864074469179890980' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5864074469179890980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5864074469179890980'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/10/more-discussion-of-today-patches.html' title='More discussion of today&amp;#39;s patches'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-203494984678504658</id><published>2010-10-12T11:22:00.001-07:00</published><updated>2010-10-12T11:22:06.160-07:00</updated><title type='text'>Biggest PATCH TUESDAY ever -- some rated PATCH NOW</title><summary type='text'>Today was Microsoft's biggest Patch Tuesday in a long time, possible ever.  SANS (first link below) rates several of these PATCH NOW!, their highest rating.  Anyone who runs as administrator on XP should probably patch ASAP.  I'm patching my work systems and home systems now and will report if I have any problems over the next day or so.SANS: October 2010 Microsoft Black Tuesday SummaryMicrosoft </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/203494984678504658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=203494984678504658' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/203494984678504658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/203494984678504658'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/10/biggest-patch-tuesday-ever-some-rated.html' title='Biggest PATCH TUESDAY ever -- some rated PATCH NOW'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6979375994425656552</id><published>2010-10-05T20:56:00.001-07:00</published><updated>2010-10-05T20:56:51.553-07:00</updated><title type='text'>Reader, Acrobat Patches Plug 23 Security Holes</title><summary type='text'>Finally the active 0-day exploit is being patched.  Brian Krebs has the most consumer-friendly write-up on it.Reader, Acrobat Patches Plug 23 Security Holes — Krebs on SecurityA new security update from Adobe plugs at least 23 security holes in its PDF Reader and Acrobat software, including two vulnerabilities that attackers are actively exploiting to break into computers.Adobe is urging Reader </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6979375994425656552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6979375994425656552' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6979375994425656552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6979375994425656552'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/10/reader-acrobat-patches-plug-23-security.html' title='Reader, Acrobat Patches Plug 23 Security Holes'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8753574641508201129</id><published>2010-10-01T08:52:00.001-07:00</published><updated>2010-10-01T08:52:00.945-07:00</updated><title type='text'>XP Users should stop using IE **ASAP**</title><summary type='text'>If you are still running Windows XP, it's really time to stop using Internet Explorer (except for Windows Update) and switch to Firefox or Google Chrome.  There is an active zero-day active that Microsoft has acknowledged in a Security Advisory that affects all XP+IE users without warning when they click a malicious link.  People whose firewall blocks Windows file sharing at the network perimeter</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8753574641508201129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8753574641508201129' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8753574641508201129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8753574641508201129'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/10/xp-users-should-stop-using-ie-asap.html' title='XP Users should stop using IE **ASAP**'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4505614683532932202</id><published>2010-09-21T08:51:00.001-07:00</published><updated>2010-09-21T08:51:45.993-07:00</updated><title type='text'>Adobe patches Flash Player zero-day</title><summary type='text'>The US-CERT article and the ZDNet article linked below both have more information.  I have patched my systems without problems.  If you watch online videos or don't have an adblocker, you should update ASAP as the vulnerability this fixes is being exploited as I type.Adobe released Flash Player 10.1.85.3. Download it at http://www.adobe.com/support/flashplayer/downloads.htmlAdobe released Flash </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4505614683532932202/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4505614683532932202' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4505614683532932202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4505614683532932202'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/adobe-patches-flash-player-zero-day.html' title='Adobe patches Flash Player zero-day'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-774810126657774430</id><published>2010-09-16T09:53:00.001-07:00</published><updated>2010-09-16T09:53:47.535-07:00</updated><title type='text'>Patch Tuesday recap, QuickTime 7.6.8, Firefox 3.6.10</title><summary type='text'>I have already patched all my computers without issue.  These stories all have more technical details and links for those who want to know more.Patch Tuesday recap: Exploits expected for Windows security holes | ZDNetMicrosoft has shipped nine security bulletins with patches for at least 11  documented vulnerabilities in Windows and Microsoft office and is urging customers to pay special </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/774810126657774430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=774810126657774430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/774810126657774430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/774810126657774430'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/patch-tuesday-recap-quicktime-768.html' title='Patch Tuesday recap, QuickTime 7.6.8, Firefox 3.6.10'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2253289510955608238</id><published>2010-09-15T11:11:00.001-07:00</published><updated>2010-09-15T11:11:11.357-07:00</updated><title type='text'>It's Patch Tuesday!  Security Links of the Week</title><summary type='text'>I am going to start accumulating links for weekly posts.  Here's the first set:"Patch Tuesday" includes two CRITICAL patches rated "PATCH NOW" by SANSSANS issued the unusual "PATCH NOW" recommendation for two of this month's "Patch Tuesday" patches.  One is rated "Critical" for Windows XP by Microsoft, and the other affects IIS (Microsoft's web-server software).  If you are running XP on a </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2253289510955608238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2253289510955608238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2253289510955608238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2253289510955608238'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/it-patch-tuesday-security-links-of-week.html' title='It&amp;#39;s Patch Tuesday!  Security Links of the Week'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8843743404180263875</id><published>2010-09-14T09:47:00.001-07:00</published><updated>2010-09-14T09:47:37.152-07:00</updated><title type='text'>Yet Again Another Adobe Vulnerability. Sigh.</title><summary type='text'>I'm seeing reports of this everywhere.  Adobe Flash Player and Adobe Reader 9.3.4 and earlier versions are both subject to 0-day exploits which are "in the wild".  Supposedly the Flash flaw will be fixed in two weeks, the Adobe Reader flaw in four weeks.  That's a long time to go with active exploits.  No word on whether or not this affects other PDF readers.Adobe Flash v10.1.82.76 and earlier </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8843743404180263875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8843743404180263875' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8843743404180263875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8843743404180263875'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/yet-again-another-adobe-vulnerability.html' title='Yet Again Another Adobe Vulnerability. Sigh.'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8865363005964298123</id><published>2010-09-09T09:31:00.001-07:00</published><updated>2010-09-09T09:31:22.482-07:00</updated><title type='text'>Quicktime 0-day drive-by exploit "in the wild"</title><summary type='text'>Unless you absolutely have to have QuickTime (iTunes requires it), you're better off without it.  The VLC media player will play QuickTime media so you don't really need it.Active exploits targeting Apple QuickTime 0-day - SC Magazine USAttackers are now actively exploiting a recently published zero-day vulnerability in Apple QuickTime, security firm Websense disclosed Tuesday.The flaw, details </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8865363005964298123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8865363005964298123' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8865363005964298123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8865363005964298123'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/quicktime-0-day-drive-by-exploit-wild.html' title='Quicktime 0-day drive-by exploit &amp;quot;in the wild&amp;quot;'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8296298103520519050</id><published>2010-09-09T08:43:00.001-07:00</published><updated>2010-09-09T08:43:43.927-07:00</updated><title type='text'>More SysAdmin fun: patch Safari, Chrome, Firefox, Opera, and Thunderbird</title><summary type='text'>If you use Safari, you should patch, although   Windows users who don't use Safari but have had it installed by Apple without knowing they did should just uninstall it.  Google has patched Chrome, Opera has been patched, and Mozilla has patched Firefox and Thunderbird to fix the Windows DLL-loading issue that has been made public recently.  It's going to be a busy week for sysadmins ...Apple </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8296298103520519050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8296298103520519050' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8296298103520519050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8296298103520519050'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/more-sysadmin-fun-patch-safari-chrome.html' title='More SysAdmin fun: patch Safari, Chrome, Firefox, Opera, and Thunderbird'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6036189453962565032</id><published>2010-09-09T08:35:00.001-07:00</published><updated>2010-09-09T08:35:54.790-07:00</updated><title type='text'>iTunes and Chrome both patched</title><summary type='text'>More fun for system administrators: patch your iTunes and Chrome installations.Apple patches 13 iTunes security holes | ZDNetBy Ryan Naraine | September 2, 2010, 8:38am PDTApple has shipped a new version of its iTunes media player to fix 13 security flaws that cold be exploited to launch attacks against Windows machines.The patches in the new iTunes 10 covers vulnerabilities in WebKit, the </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6036189453962565032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6036189453962565032' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6036189453962565032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6036189453962565032'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/itunes-and-chrome-both-patched.html' title='iTunes and Chrome both patched'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3393705523626894848</id><published>2010-09-09T08:30:00.001-07:00</published><updated>2010-09-09T08:30:30.290-07:00</updated><title type='text'>Adobe Reader 0-day PDF exploit in the wild</title><summary type='text'>I've seen multiple reports of this, all referring to Adobe Reader 9.3.4 and Adobe Reader 8.2.4 (the latest versions).   I've seen no mention of whether or not this affects Foxit Reader or other PDF readers.  FWIW on my home machine, where I do most of my "surfing", I use Foxit Reader as my default PDF reader and SumatraPDF when opening PDFs directly from web links.Computer Security Research - </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3393705523626894848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3393705523626894848' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3393705523626894848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3393705523626894848'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/adobe-reader-0-day-pdf-exploit-in-wild.html' title='Adobe Reader 0-day PDF exploit in the wild'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-902582587750407574</id><published>2010-09-01T20:44:00.001-07:00</published><updated>2010-09-01T20:44:33.091-07:00</updated><title type='text'>RealPlayer haunted by 'critical' security holes</title><summary type='text'>If you have Real Player (AOL often installs it), you need to patch it.  The ZDNet article below has the best explanation I have seen.US-CERT Current Activity: RealNetworks Releases Update to Address Vulnerabilities in RealPlayeradded August 31, 2010 at 08:23 amRealNetworks, Inc. has released an update for RealPlayer to address multiple vulnerabilities. These vulnerabilities may allow a remote, </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/902582587750407574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=902582587750407574' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/902582587750407574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/902582587750407574'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/realplayer-haunted-by-security-holes.html' title='RealPlayer haunted by &amp;#39;critical&amp;#39; security holes'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-669748762001502805</id><published>2010-09-01T20:38:00.001-07:00</published><updated>2010-09-01T20:38:16.435-07:00</updated><title type='text'>Microsoft DLL Path vulnerability "in the wild"</title><summary type='text'>This has been getting a lot of play in the trade press over the past week or so.  It's a complicated issue, and there is no simple patch.  The Microsoft "Fixit" isn't just a one-click fix like most of their "Fixits", either.  The Krebs on Security article below has a good but technical discussion of the problem.FWIW I haven't patched any of my personal computers, but I never browse the Internet </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/669748762001502805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=669748762001502805' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/669748762001502805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/669748762001502805'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/09/microsoft-dll-path-vulnerability-wild.html' title='Microsoft DLL Path vulnerability &amp;quot;in the wild&amp;quot;'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2997769649278602</id><published>2010-08-24T23:04:00.001-07:00</published><updated>2010-08-24T23:04:30.986-07:00</updated><title type='text'>Apple Mac OS X and Adobe Shockwave (NOT Flash) Player patches</title><summary type='text'>Apple patches 13 Mac OS X vulnerabilities | ZDNetBy Ryan Naraine | August 24, 2010, 2:19pm PDTApple has shipped a new Mac OS X security update to fix 13 documented vulnerabilities, some serious enough to expose users to remote code execution attacks.The patch includes fixes for security holes in several open-source components, including ClamAV and PHP.Here’s a quick look at the vulnerabilities </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2997769649278602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2997769649278602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2997769649278602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2997769649278602'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/apple-mac-os-x-and-adobe-shockwave-not.html' title='Apple Mac OS X and Adobe Shockwave (NOT Flash) Player patches'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4078899235945696934</id><published>2010-08-20T13:41:00.001-07:00</published><updated>2010-08-20T13:41:25.120-07:00</updated><title type='text'>Sure Happy It's Thursday: Google Chrome, VLC 1.1.3, old Java being exploited</title><summary type='text'>The patch treadmill rolls along.  Google Chrome was patched just recently, and here it is again.  Ditto for VLC.  I was glad to read the Microsoft blog entry as that may explain how some of my out-of-date home users were infected recently.US-CERT Current Activity: Google Releases Chrome 5.0.375.127added August 20, 2010 at 08:47 amGoogle has released Chrome  5.0.375.127 for Windows, Mac, and Linux</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4078899235945696934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4078899235945696934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4078899235945696934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4078899235945696934'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/sure-happy-it-thursday-google-chrome.html' title='Sure Happy It&amp;#39;s Thursday: Google Chrome, VLC 1.1.3, old Java being exploited'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2810863496631229354</id><published>2010-08-19T21:38:00.001-07:00</published><updated>2010-08-19T21:38:58.756-07:00</updated><title type='text'>Adobe Issues Acrobat, Reader Security Patches</title><summary type='text'>Well, Adobe shipped an "emergency" set of patches for Adobe Reader 8.x and 9.x.  If you are updating manually you can get them here: Adobe.com - New downloads.  So far they appear to be working fine on all the systems where I have installed them.Adobe ships critical PDF Reader patch | ZDNetAdobe has shipped a security bulletin with patches for two critical vulnerabilities in its PDF Reader and </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2810863496631229354/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2810863496631229354' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2810863496631229354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2810863496631229354'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/adobe-issues-acrobat-reader-security.html' title='Adobe Issues Acrobat, Reader Security Patches'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6283551971694842446</id><published>2010-08-13T21:45:00.001-07:00</published><updated>2010-08-13T21:45:24.155-07:00</updated><title type='text'>This week's reminder links: Chrome, QuickTime, more</title><summary type='text'>No details are provided on what has been patched.  If you use the Google Chrome browser, it should auto-update.&amp;nbsp.  One of the Chrome alternatives (which don't feed your surfing life to Google), Iron Browser isn't keeping up -- their newest version is dated late June, but ChromePlus was just updated today (13 Aug 2010) and can be downloaded [HERE].US-CERT Current Activity: Google Releases </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6283551971694842446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6283551971694842446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6283551971694842446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6283551971694842446'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/this-week-reminder-links-chrome.html' title='This week&amp;#39;s reminder links: Chrome, QuickTime, more'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3129982425688477435</id><published>2010-08-11T08:50:00.001-07:00</published><updated>2010-08-11T08:50:25.372-07:00</updated><title type='text'>Record Patch Tuesday, and Adobe Flash is updated again</title><summary type='text'>I have applied the Windows Update patches and Flash updates to my systems and I haven't seen any issues, but I don't use Microsoft Office and there are critical patches to Office this month.  According to Brian Krebs, the Office patch is very important: "... a patch that fixes at least four vulnerabilities in Microsoft Office, the most severe of which could lead to users infecting their PCs with </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3129982425688477435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3129982425688477435' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3129982425688477435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3129982425688477435'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/record-patch-tuesday-and-adobe-flash-is.html' title='Record Patch Tuesday, and Adobe Flash is updated again'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4725734899306902931</id><published>2010-08-08T16:47:00.001-07:00</published><updated>2010-08-08T16:47:52.159-07:00</updated><title type='text'>Foxit Fix for “Jailbreak” PDF Flaw — Krebs on Security</title><summary type='text'>Foxit Fix for “Jailbreak” PDF Flaw — Krebs on SecurityOne of the more interesting developments over the past week has been the debut of jailbreakme.com, a Web site that allows Apple customers to jailbreak their devices merely by visiting the site with their iPhone, iPad or iTouch. Researchers soon learned that the page leverages two previously unknown security vulnerabilities in the PDF reader </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4725734899306902931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4725734899306902931' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4725734899306902931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4725734899306902931'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/foxit-fix-for-jailbreak-pdf-flaw-krebs.html' title='Foxit Fix for “Jailbreak” PDF Flaw — Krebs on Security'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-623725866030471256</id><published>2010-08-06T22:34:00.001-07:00</published><updated>2010-08-06T22:34:55.723-07:00</updated><title type='text'>Foxit Releases Foxit Reader 4.1.1.0805</title><summary type='text'>Foxit Software moved a little faster on this than Adobe did ...US-CERT Current Activity: Foxit Releases Foxit Reader 4.1.1.0805added August 6, 2010 at 10:31 am                   Foxit has released Foxit Reader 4.1.1.0805 to address a vulnerability  associated with the improper rendering of PDF documents. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.US-CERT </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/623725866030471256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=623725866030471256' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/623725866030471256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/623725866030471256'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/foxit-releases-foxit-reader-4110805.html' title='Foxit Releases Foxit Reader 4.1.1.0805'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4823301501888770613</id><published>2010-08-05T23:19:00.001-07:00</published><updated>2010-08-05T23:19:40.824-07:00</updated><title type='text'>Another MONDO Patch Tuesday coming ... batten down the hatches.</title><summary type='text'>Looks like SysAdmins are going to be busy little pupplies this coming week.  Not only will we have to patch Adobe Reader, Microsoft has announced another record-tying Patch Tuesday.Microsoft readies record 14 fixes, eight critical - SC Magazine USMicrosoft on Thursday announced that next week it plans to deliver a record 14 patches to resolve 34 vulnerabilities across its product line.The 34 </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4823301501888770613/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4823301501888770613' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4823301501888770613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4823301501888770613'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/another-mondo-patch-tuesday-coming.html' title='Another MONDO Patch Tuesday coming ... batten down the hatches.'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-4330779661651415307</id><published>2010-08-05T23:16:00.001-07:00</published><updated>2010-08-05T23:16:06.107-07:00</updated><title type='text'>Is it time to dump Adobe Reader in favour of an alternate PDF reader?</title><summary type='text'>Patching Adobe products is just getting OLD (not to mention expensive).  FWIW I use both the Foxit Reader and the Sumatra PDF viewer rather than Adobe Reader on Windows.Adobe confirms critical flaw in Reader and Acrobat - SC Magazine USThe vulnerability affects the current version of the software, Adobe Reader 9.3.3, and earlier versions for Windows, Macintosh and UNIX, Adobe said. It also </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/4330779661651415307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=4330779661651415307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4330779661651415307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/4330779661651415307'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/is-it-time-to-dump-adobe-reader-in.html' title='Is it time to dump Adobe Reader in favour of an alternate PDF reader?'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1260518332853739723</id><published>2010-08-03T12:54:00.001-07:00</published><updated>2010-08-03T12:54:59.193-07:00</updated><title type='text'>Patch NOW!  Microsoft Out-of-Band Patch on Monday!</title><summary type='text'>SANS gave this their ultimate "PATCH NOW" rating.  I have patched and only noticed one minor issue with an icon in one user's "Quick Launch" taskbar area on XP Pro.As attacks escalate, Microsoft ships emergency Windows patch | ZDNetMicrosoft has rushed out and emergency patch for all supported versions of Windows to cover a gaping — and under attack — security flaw in the way shortcuts are </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1260518332853739723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1260518332853739723' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1260518332853739723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1260518332853739723'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/08/patch-now-microsoft-out-of-band-patch.html' title='Patch NOW!  Microsoft Out-of-Band Patch on Monday!'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2533038617141723344</id><published>2010-07-30T09:52:00.001-07:00</published><updated>2010-07-30T09:52:27.748-07:00</updated><title type='text'>Friday Quick Links</title><summary type='text'>This was the week for worrying about the Microsoft LNK 0-day exploit (I found at least one laptop with 54 instances of it), browser patches, and a nasty flaw in a banking app for the iPhone:SophosLabs Released Free Tool to Validate Microsoft ShortcutSophosLabs has just released a free tool that provides detection against the  Windows shortcut exploit that we published last week here and here.  </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2533038617141723344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2533038617141723344' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2533038617141723344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2533038617141723344'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/friday-quick-links.html' title='Friday Quick Links'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7098903908524821746</id><published>2010-07-21T10:11:00.002-07:00</published><updated>2010-07-25T07:20:45.604-07:00</updated><title type='text'>Microsoft issues FixIt for LNK vulnerability</title><summary type='text'>Well, I predicted Microsoft would patch this problem, but first they want us to "FixIt" manually.  I ran this FixIt on my main workstation and the main effect is to change some of your "Quick Start" and desktop icons to generic ones:
 becomes 


This mike look like a problem but it is really only a minor inconvenience.  When you hover your mouse over an icon, a tooltip pops up with its name.  And</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7098903908524821746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7098903908524821746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7098903908524821746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7098903908524821746'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/microsoft-issues-fixit-for-lnk.html' title='Microsoft issues FixIt for LNK vulnerability'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_tl4Ma2P2yBw/TExHyV5DuOI/AAAAAAAAAAM/ogcroJHe_E0/s72-c/MicrosoftFixit50486-LNK-before2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3206567034417542149</id><published>2010-07-21T09:57:00.001-07:00</published><updated>2010-07-21T09:57:08.520-07:00</updated><title type='text'>More info on what is patched in Firefox 3.6.7</title><summary type='text'>Good write-up at the Zero Day blog at ZDNet about what has been fixed in Firefox 3.6.7 and why you need to update, especially if you are running as a local administration.Firefox hit by drive-by download security holes | ZDNetMozilla has shipped a mega patch for Firefox to fix a total of 16 security flaws that expose Web surfers to drive-by download, data theft and local bar spoofing attacks.The </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3206567034417542149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3206567034417542149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3206567034417542149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3206567034417542149'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/more-info-on-what-is-patched-in-firefox.html' title='More info on what is patched in Firefox 3.6.7'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2154091299088203832</id><published>2010-07-20T19:04:00.001-07:00</published><updated>2010-07-20T19:04:20.650-07:00</updated><title type='text'>Skimmers Siphoning Credit Card Data at Gas Stations in Arizona, Colorado, Florida</title><summary type='text'>If you buy gas using a DEBIT card, you're particularly at risk since when your debit-card account is compromised, the effects on you are much worse than when a credit-card account is stolen.  The scary thing about these "skimmers" is that they're INTERNAL -- inside the gas pumps -- and can't be seen from the outside.  The Krebs on Security blog has a lot more than the stuff I've excerpted </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2154091299088203832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2154091299088203832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2154091299088203832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2154091299088203832'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/skimmers-siphoning-credit-card-data-at.html' title='Skimmers Siphoning Credit Card Data at Gas Stations in Arizona, Colorado, Florida'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2909423557542244570</id><published>2010-07-20T18:58:00.001-07:00</published><updated>2010-07-20T18:58:24.092-07:00</updated><title type='text'>Firefox 3.6.7 fixes some security issues</title><summary type='text'>Mozilla Firefox 3.6.7 Release Notes        What’s New in Firefox 3.6.7                  Firefox 3.6.7 fixes the following issues found in previous versions of Firefox 3.6:          Fixed several security issues.Fixed several stability issues.                      Please see the            complete list of changes             in this version. You may also be interested in the            Firefox </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2909423557542244570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2909423557542244570' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2909423557542244570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2909423557542244570'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/firefox-367-fixes-some-security-issues.html' title='Firefox 3.6.7 fixes some security issues'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-3721367175605150320</id><published>2010-07-20T11:18:00.001-07:00</published><updated>2010-07-20T11:18:15.830-07:00</updated><title type='text'>iTunes buffer overflow vulnerability (Windows only); Apple Releases iTunes 9.2.1</title><summary type='text'>Here's another patch that needs to be installed on any Windows computer running iTunes.iTunes buffer overflow vulnerabilityApple is reporting new version of iTunes (9.2.1), which address CVE-2010-1777: A buffer overflow exists in the handling of itpc: URLs, which might lead to application termination or arbitrary code execution.More information at http://support.apple.com/kb/HT4263.This affects </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/3721367175605150320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=3721367175605150320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3721367175605150320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/3721367175605150320'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/itunes-buffer-overflow-vulnerability.html' title='iTunes buffer overflow vulnerability (Windows only); Apple Releases iTunes 9.2.1'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-1381286469407122020</id><published>2010-07-20T11:14:00.001-07:00</published><updated>2010-07-20T11:14:13.540-07:00</updated><title type='text'>Serious Microsoft Windows LNK Vulnerability</title><summary type='text'>This one looks very serious to me, and I expect Microsoft will be forced to release an "out-of-band" patch to correct this problem.  Unfortunately both the workarounds proposed by Microsoft in its Security Advisory have significant effects on the usability of Windows PCs -- disabling the use of icons for shortcuts means all your desktop shortcuts and all your "Quick Start" icons will be identical</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/1381286469407122020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=1381286469407122020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1381286469407122020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/1381286469407122020'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/serious-microsoft-windows-lnk.html' title='Serious Microsoft Windows LNK Vulnerability'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6164285807925589255</id><published>2010-07-14T18:12:00.001-07:00</published><updated>2010-07-14T18:12:16.791-07:00</updated><title type='text'>Quick links for Bastille Day, 2010</title><summary type='text'>Two quickies about phone security issues and one surprising report about which company had the most vulnerabilities.Slashdot News Story | Hack AT&amp;T Voicemail With AndroidAn anonymous reader writes "It is shockingly easy to gain access to an AT&amp;T customer's voicemail using caller ID spoofing techniques. What's worse is that AT&amp;T knows about it. On your Android phone, download one of the two caller</summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6164285807925589255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6164285807925589255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6164285807925589255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6164285807925589255'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/quick-links-for-bastille-day-2010.html' title='Quick links for Bastille Day, 2010'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6192955236423222618</id><published>2010-07-14T18:04:00.002-07:00</published><updated>2010-07-14T18:07:18.748-07:00</updated><title type='text'>Microsoft Patch Tuesday: one CRITICAL patch, and the end of support for Windows 2000 and XP SP2</title><summary type='text'>Microsoft's Patch Tuesday for July, 2010, was a small but very important one.   SANS rates patch MS10-042 as "PATCH NOW", their highest rating.  It affects Windows XP and Windows 2003 Server only, not Vista or Windows 7.  This patch fixes a vulnerability which is being actively exploited right now, so if you are still running XP, get patching!  Here are links to and some wording from articles </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6192955236423222618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6192955236423222618' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6192955236423222618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6192955236423222618'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/microsoft-patch-tuesday-one-critical.html' title='Microsoft Patch Tuesday: one CRITICAL patch, and the end of support for Windows 2000 and XP SP2'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-837564101617342916</id><published>2010-07-12T23:01:00.001-07:00</published><updated>2010-07-13T06:50:35.737-07:00</updated><title type='text'>Quick Notes after a driving vacation</title><summary type='text'>Since the last time I posted I have driven 7,000 miles, from Tucson, Arizona, to Mt. Desert Island and Acadia National Park in Maine, and back.  Most of the driving west of the Mississippi and about half the driving east of it was on non-Interstate highways to avoid traffic.  I need a vacation to recover from my vacation.

Of course, the Bad Guys don't take vacations, or if they do, they don't </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/837564101617342916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=837564101617342916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/837564101617342916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/837564101617342916'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/07/quick-notes-after-driving-vacation.html' title='Quick Notes after a driving vacation'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2155373784325949072</id><published>2010-06-23T09:52:00.002-07:00</published><updated>2010-06-24T09:46:35.405-07:00</updated><title type='text'>Mozilla Releases Firefox 3.6.4</title><summary type='text'>It seems to be a little faster than 3.6.3 ... and it includes some better crash protection.  Go get it!

Mozilla Releases Firefox 3.6.4
The Mozilla Foundation has released Firefox 3.6.4 and Firefox 3.5.10 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or conduct </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2155373784325949072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2155373784325949072' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2155373784325949072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2155373784325949072'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/mozilla-releases-firefox-364.html' title='Mozilla Releases Firefox 3.6.4'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6855494854232311169</id><published>2010-06-23T09:49:00.001-07:00</published><updated>2010-06-23T09:49:43.376-07:00</updated><title type='text'>Even legitimate support sites can go bad ....</title><summary type='text'>Just one more reason to browse the Internet using Firefox with NoScript and as a non-administrator.  Use a limited account or use DropMyRights when you browse from machines where you must run as administrator.Lenovo Support Website Loads Malicious IFrame, Infects Visitors With Trojan | CyberInsecure.comThe support site of leading Chinese PC manufacturer Lenovo has been compromised by unknown </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6855494854232311169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6855494854232311169' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6855494854232311169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6855494854232311169'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/even-legitimate-support-sites-can-go.html' title='Even legitimate support sites can go bad ....'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5800734793926201630</id><published>2010-06-17T22:30:00.001-07:00</published><updated>2010-06-17T22:30:11.601-07:00</updated><title type='text'>Apple iTunes 9.2 released</title><summary type='text'>WebKit security flaws haunt Apple's iTunes | ZDNetApple has shipped a critical security patch for its iTunes media player to fix several gaping security holes that expose Windows users to hacker attacks.The vulnerabilities could be exploited to launch remote code execution attacks if a user simply opens an image file or surfs to a rigged Web site. The update applies to Windows 7, Windows Vista </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5800734793926201630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5800734793926201630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5800734793926201630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5800734793926201630'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/apple-itunes-92-released.html' title='Apple iTunes 9.2 released'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-7866397128997847393</id><published>2010-06-16T14:06:00.001-07:00</published><updated>2010-06-16T14:06:38.978-07:00</updated><title type='text'>Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player</title><summary type='text'>Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player - Adobe Product Security Incident Response Team (PSIRT)Earlier today, Apple released security update 2010-004 / Mac OS X v10.6.4. This update includes an earlier version of Adobe Flash Player (version 10.0.45.2) than available from Adobe.com. While the Mac OS X v10.6.4 update does not appear to </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/7866397128997847393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=7866397128997847393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7866397128997847393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/7866397128997847393'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/apple-security-update-2010-004-mac-os-x.html' title='Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-8652445989282261189</id><published>2010-06-16T09:10:00.001-07:00</published><updated>2010-06-16T09:10:23.123-07:00</updated><title type='text'>OS X Patch Tuesday: 28 fixes</title><summary type='text'>Apple releases advisory for Mac OS X - Multiple vulnerabilities discoveredApple released today an advisory for multiple vulnerabilities discovered in Mac OS X. Impacted programs includes CUPS,  Desktop Services, Folder Manager, Help Viewer, iChat, ImageIO, Kerberos, libcurl, Network Autorization, Open Directory, Printer Setup, Printing, Ruby, SMB File Server, Squirrelmail, and Wiki Server. Mac </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/8652445989282261189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=8652445989282261189' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8652445989282261189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/8652445989282261189'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/os-x-patch-tuesday-28-fixes.html' title='OS X Patch Tuesday: 28 fixes'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2139403525454146736</id><published>2010-06-16T09:08:00.001-07:00</published><updated>2010-06-16T09:08:49.893-07:00</updated><title type='text'>Windows XP Help vulnerability now "in the wild"</title><summary type='text'>There are multiple reports of drive-by downloads appearing.  Drive-by downloads are dangerous because you can be infected without taking any action other than browsing to a webpage which carries the infection.  If you are running Windows XP as an administrator, you should probably immediately apply one of the workarounds described on the Microsoft page linked below.Microsoft confirms exploits </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2139403525454146736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2139403525454146736' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2139403525454146736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2139403525454146736'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/windows-xp-help-vulnerability-now-wild.html' title='Windows XP Help vulnerability now &amp;quot;in the wild&amp;quot;'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-6113189078035303707</id><published>2010-06-10T23:12:00.002-07:00</published><updated>2010-06-10T23:19:42.649-07:00</updated><title type='text'>Adobe patches Flash, but Adobe Reader 9 remains unpatched</title><summary type='text'>A nasty hole in Adobe Flash (all platforms: Windows, Mac, Linux) has been patched on the Windows version.  A related hole in Adobe Reader 9 is still unpatched.  I have patched my Adobe Flash players and am in the process of patching Flash on business client computers. For home users, links to the Flash patches can be found here: Adobe - Security Bulletins: APSB10-14 Security update available for </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/6113189078035303707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=6113189078035303707' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6113189078035303707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/6113189078035303707'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/adobe-patches-flash-but-adobe-reader-9.html' title='Adobe patches Flash, but Adobe Reader 9 remains unpatched'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-2951277927678178101</id><published>2010-06-10T22:41:00.002-07:00</published><updated>2010-06-10T23:22:39.606-07:00</updated><title type='text'>Multiple reports of 0-day exploit in Windows XP Help</title><summary type='text'>
Windows Vista, Windows 7, Windows Server 2008/2008 R2 all appear immune.  XP and Server 2003 are vulnerable.  If you run as "Administrator" and use IE, your are particularly at risk.  Those of us who run as non-admin users and use Firefox or Chrome are pretty safe, as far as I can tell at this early time.

Microsoft Security Advisory 2219475
Microsoft has issued a Security Advisory for the </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/2951277927678178101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=2951277927678178101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2951277927678178101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/2951277927678178101'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/multiple-reports-of-0-day-exploit-in.html' title='Multiple reports of 0-day exploit in Windows XP Help'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-38280661470510977</id><published>2010-06-10T09:40:00.001-07:00</published><updated>2010-06-10T09:40:35.211-07:00</updated><title type='text'>Wall Street Journal website infected, served malware</title><summary type='text'>People surfing with ad blockers and script blockers would have been less likely to have been caught by this, which is one more reason I use the Firefox Browser with the Adblock Plus and NoScript add-ons.  Even ChromePlus doesn't block scripts, although you can get an ad-blocker that uses the same lists as the Firefox ad-blocker and also a Flash blocker.Thousands Of High-Ranked Webpages Infected </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/38280661470510977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=38280661470510977' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/38280661470510977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/38280661470510977'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/wall-street-journal-website-infected.html' title='Wall Street Journal website infected, served malware'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4635567720205012055.post-5777116629379466979</id><published>2010-06-08T13:48:00.001-07:00</published><updated>2010-06-08T13:48:57.936-07:00</updated><title type='text'>Microsoft Patch Tuesday: 10 bulletins, many critical, reboot required</title><summary type='text'>Well, this month's set of Microsoft patches have been released, and it's a big set.  Microsoft is urging that system admins roll out several of these ASAP as exploit code is either "in the wild" or easy to develop.Microsoft finally fixes Pwn2Own browser flaw | ZDNetThe Microsoft Patch Tuesday train rolled into town today, dropping off a massive 10 security bulletins with fixes for at least 34 </summary><link rel='replies' type='application/atom+xml' href='http://geoapps.blogspot.com/feeds/5777116629379466979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4635567720205012055&amp;postID=5777116629379466979' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5777116629379466979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4635567720205012055/posts/default/5777116629379466979'/><link rel='alternate' type='text/html' href='http://geoapps.blogspot.com/2010/06/microsoft-patch-tuesday-10-bulletins.html' title='Microsoft Patch Tuesday: 10 bulletins, many critical, reboot required'/><author><name>Angus Scott-Fleming</name><uri>http://www.blogger.com/profile/00881345250007488266</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
