<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-3204430622523876552</id><updated>2009-09-10T08:55:46.232-05:00</updated><title type='text'>Network Sentry</title><subtitle type='html'>Computer and Network Security Monitoring and Consulting</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.netsentinc.com/blog/atom.xml'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-706191078727562732</id><published>2009-09-08T20:54:00.006-05:00</published><updated>2009-09-08T21:32:35.566-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sockstress'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='ms09-048'/><title type='text'>Microsoft letting Win2k and XP users fend for themselves?</title><content type='html'>Read through the &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS09-048.mspx"&gt;MS09-048&lt;/a&gt; advisory.  See anything out of the ordinary?  Read through it again.  Notice the asterisks?  Looking for a patch for Windows 2000 SP4?  Sorry, "No update available".  Need a patch for Windows XP SP2, SP3 or Windows XP x64 SP2?  You don't need one because it's not vulnerable.  Or is it?  There's an asterisk - "Default configuration not affected".&lt;br /&gt;&lt;br /&gt;In Microsoft's defense, patching Win2k would require the OS to be rearchitected which may introduce stability issues with existing software.  But still - if you ask me, the product is under support and now has three unpatched remote exploits.  Hopefully on tomorrow's call they can clarify the issue.  Maybe it's not as bad as it seems, but as it stands it sounds like Win2k can be DoSed remotely if even a single TCP port is listening - firewalled or not.&lt;br /&gt;&lt;br /&gt;They have no defense for Windows XP.  Most XP systems I've seen have listening ports.  Maybe in the office you are firewalled, but what about road warriors using a hotspot?  Can a malicious person head to his/her local Panera and plant a back door on all the Windows machines?&lt;br /&gt;&lt;br /&gt;The most important aspect of this post is "&lt;span style="font-weight: bold;"&gt;what can I do to protect myself?&lt;/span&gt;"  Well:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;If your platform has a patch, apply it.&lt;/li&gt;&lt;li&gt;If you can afford it, upgrade machines to a platform that is supported.&lt;/li&gt;&lt;li&gt;If you have an unsupported platform, use a host firewall to block inbound connecti0ns.&lt;/li&gt;&lt;li&gt;If you have road warriors, make it a priority to educate them on this issue, how to utilize the firewall when on a public/untrusted network and how to conduct business while out of the office.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Hopefully tommorrow Microsoft will offer more details on this and it won't be as bad as it seems.  I can think of a few ways of protecting devices but again, the dust needs to settle first.  In the meantime, firewall off as many devices as you can and use host firewalls to your advantage.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-706191078727562732?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/706191078727562732/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/09/microsoft-letting-win2k-and-xp-users.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/706191078727562732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/706191078727562732'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/09/microsoft-letting-win2k-and-xp-users.html' title='Microsoft letting Win2k and XP users fend for themselves?'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-6712060671668363304</id><published>2009-08-27T08:14:00.002-05:00</published><updated>2009-08-27T08:28:00.761-05:00</updated><title type='text'>Small Business Information Security Fundamentals</title><content type='html'>Today I read about a new DRAFT document published by NIST (National Institute of Standards and Technology) titled "&lt;a href="http://csrc.nist.gov/publications/drafts/ir-7621/draft-nistir-7621.pdf"&gt;Small Business Information Security: The Fundamentals&lt;/a&gt;".  I must say that this is a great document and if you are a small business, please take a look at it.  It attempts to explain in plain language some of Information Security's best practices.&lt;br /&gt;&lt;br /&gt;If you've read &lt;a href="http://blog.washingtonpost.com/securityfix/"&gt;Brian Krebs' blog&lt;/a&gt; about the increasing occurrence of &lt;a href="http://voices.washingtonpost.com/securityfix/2009/08/businesses_reluctant_to_report.html"&gt;small businesses being targets of money theft&lt;/a&gt; from Eastern European criminals, the stats in the NIST document's overview section really drives home the importance of Infosec for small business.  These businesses are vital to our economy and unfortunately lack the resources of larger businesses who do invest in information security.  If small businesses don't act to protect themselves, their customers or their employees, we're headed down a dangerous path.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-6712060671668363304?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/6712060671668363304/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/08/small-business-information-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/6712060671668363304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/6712060671668363304'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/08/small-business-information-security.html' title='Small Business Information Security Fundamentals'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-3246389009569032368</id><published>2009-08-20T14:59:00.003-05:00</published><updated>2009-08-20T15:10:45.997-05:00</updated><title type='text'>Milw0rm offline again?</title><content type='html'>I haven't been able to get to Milw0rm yesterday or today.  Anyone have a similar experience?  Anyone have any news as to what's up?  I know there was talk about the demise of the site in July, but I thought str0ke decided to keep the site up.  If you have any info, please post a comment.&lt;br /&gt;&lt;br /&gt;Thanks!&lt;br /&gt;&lt;br /&gt;P.S. I did spell it with a zero, not the letter O.  Thanks Blogger ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-3246389009569032368?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/3246389009569032368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/08/milw0rm-offline-again.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3246389009569032368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3246389009569032368'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/08/milw0rm-offline-again.html' title='Milw0rm offline again?'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-3410210067367706596</id><published>2009-08-18T09:32:00.001-05:00</published><updated>2009-08-18T09:35:18.275-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='ms09-039'/><category scheme='http://www.blogger.com/atom/ns#' term='DShield'/><category scheme='http://www.blogger.com/atom/ns#' term='WINS'/><title type='text'>Reports of MS09-039 in the wild</title><content type='html'>We have read in several places about a report of MS09-039 being actively exploited in the wild.  Nothing has been verified, but according to the &lt;a href="http://isc.sans.org/diary.html?storyid=6976"&gt;ISC&lt;/a&gt; and their &lt;a href="http://isc.sans.org/port.html?port=42"&gt;DShield data&lt;/a&gt;, there has been a HUGE increase in port 42 being targeted.  Looking at the graph, port 42 as the destination hovers around 1,000-2,000 targets a day normally.  On the 17th of August, there were nearly 70,000 targets.&lt;br /&gt;&lt;br /&gt;That's a 70x increase.  Just a coincidence?  I don't think so, but unfortunately this is our only fact so far.  Hopefully someone can get a malware sample to add more credibility to the lone report of active exploitation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-3410210067367706596?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/3410210067367706596/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/08/reports-of-ms09-039-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3410210067367706596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3410210067367706596'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/08/reports-of-ms09-039-in-wild.html' title='Reports of MS09-039 in the wild'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-8062791165457658427</id><published>2009-07-21T09:54:00.002-05:00</published><updated>2009-07-21T10:05:14.614-05:00</updated><title type='text'>Nmap 5 released</title><content type='html'>Yes - a little late, I know.  &lt;a href="http://nmap.org/download.html"&gt;Nmap&lt;/a&gt; 5 was released on July 16th.  Some of the &lt;a href="http://nmap.org/5/#5changes"&gt;new cool features&lt;/a&gt; include &lt;a href="http://nmap.org/ncat/"&gt;Ncat &lt;/a&gt;and &lt;a href="http://nmap.org/ndiff/"&gt;Ndiff&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://nmap.org/ncat/"&gt;Ncat &lt;/a&gt;is like Netcat but supposedly better.  I have not tried this so I don't want to comment on it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://nmap.org/ndiff/"&gt;Ndiff &lt;/a&gt;sounds really cool.  You can run nmap scans on 2 different occasions and use ndiff to see the difference.  One immediate application I can think of would be tracking changes to a network over time.  Perhaps run it daily and when a new service appears on a given host, use &lt;a href="http://sourceforge.net/projects/swatch/"&gt;swatch &lt;/a&gt;or some script to alert you.  Really cool new tool if you ask me.  I can't wait to check this one out!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-8062791165457658427?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/8062791165457658427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/nmap-5-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8062791165457658427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8062791165457658427'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/nmap-5-released.html' title='Nmap 5 released'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-8090292415175151119</id><published>2009-07-16T09:42:00.002-05:00</published><updated>2009-07-16T09:47:49.769-05:00</updated><title type='text'>OWC ActiveX exploits starting to increase</title><content type='html'>A few days ago Microsoft released a security advisory (&lt;a href="http://www.microsoft.com/technet/security/advisory/973472.mspx"&gt;973472&lt;/a&gt;) for a vulnerability in Microsoft Office Web Components (OWC).  This is being actively exploited.  Proof of concept code is &lt;a href="http://www.milw0rm.com/exploits/9163"&gt;here &lt;/a&gt;and there is at least one &lt;a href="http://pauldotcom.com/2009/07/metasploit-owc-activex-exploit.html"&gt;Metasploit module for this.&lt;/a&gt;  We'll only be seeing an increase in exploit attempts so until a patch is released, you should start implementing workarounds.&lt;br /&gt;&lt;br /&gt;Some things you can do to protect yourself:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Set killbits {0002E541-0000-0000-C000-000000000046} and {0002E559-0000-0000-C000-000000000046} per the Microsoft advisory.  Thankfully, Microsoft has a slick fix it package &lt;a href="http://go.microsoft.com/?linkid=9672747"&gt;here&lt;/a&gt; from &lt;a href="http://support.microsoft.com/kb/973472"&gt;KB973472.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Block known bad domains such as f1y.in (see &lt;a href="http://isc.sans.org/diary.html?storyid=6811"&gt;SANS ISC post&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;Keep your Antivirus updated!!&lt;/li&gt;&lt;li&gt;Use the Noscript plugin for Firefox&lt;/li&gt;&lt;li&gt;Don't use Internet Explorer until a patch is released&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx"&gt;Microsoft SRD blog has more info.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-8090292415175151119?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/8090292415175151119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/owc-activex-exploits-starting-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8090292415175151119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8090292415175151119'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/owc-activex-exploits-starting-to.html' title='OWC ActiveX exploits starting to increase'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-78497965170653845</id><published>2009-07-15T10:29:00.004-05:00</published><updated>2009-07-15T10:33:57.255-05:00</updated><title type='text'>Oracle's quarterly Critical Patch Update posted today</title><content type='html'>Oracle released their quarterly patches today.  If I have time, I'll post something more detailed.  But for now I'll post a highlight.  There are 30 patches in total (thanks to molecular updates, they can be applied individually), 15 of them are remotely exploitable without authentication.  Only three of those are applicable to the venerable Database product.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html"&gt;Link to the Oracle page.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-78497965170653845?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/78497965170653845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/oracles-quarterly-critical-patch-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/78497965170653845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/78497965170653845'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/oracles-quarterly-critical-patch-update.html' title='Oracle&apos;s quarterly Critical Patch Update posted today'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-8945475344007241923</id><published>2009-07-15T09:20:00.004-05:00</published><updated>2009-07-15T09:41:24.583-05:00</updated><title type='text'>Johhny Long stranded while helping the needy...</title><content type='html'>Johnny Long (of google hacking database fame) and his family are stranded in the middle of Africa while doing charity work because Paypal has 'frozen' his assets.  Can you imagine going to a third world country to help out needy people only to end up being stranded there with hardly any money?  Worse yet is you HAVE money but the people holding it won't give it to you.  This is a good example of false positives and how they are working against Paypal's fraud detection service.&lt;br /&gt;&lt;br /&gt;On a positive note, it looks like the community is starting to band together to help Johhny and his family.  If you or anyone you know has any influence over Paypal...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hackersforcharity.org/259/paypal-shuts-us-down/"&gt;Hackers for charity blog post&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-8945475344007241923?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/8945475344007241923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/johhny-long-stranded-while-helping.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8945475344007241923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/8945475344007241923'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/johhny-long-stranded-while-helping.html' title='Johhny Long stranded while helping the needy...'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-3268285807951691660</id><published>2009-07-14T22:01:00.000-05:00</published><updated>2009-07-14T22:03:15.756-05:00</updated><title type='text'>Martin Roesch is going to be in Chicago?!?!</title><content type='html'>I know it's short notice, but Martin Roesch (of Snort fame) will be in town tomorrow and Thursday - http://www.sourcefire.com/news/webinars/#sem1q09&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-3268285807951691660?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/3268285807951691660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/martin-roesch-is-going-to-be-in-chicago.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3268285807951691660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/3268285807951691660'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/martin-roesch-is-going-to-be-in-chicago.html' title='Martin Roesch is going to be in Chicago?!?!'/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3204430622523876552.post-7879468195548530215</id><published>2009-07-10T14:58:00.000-05:00</published><updated>2009-07-10T15:32:16.691-05:00</updated><title type='text'>Killbits just arent enough in this case :-(</title><content type='html'>Check this out: &lt;a href="http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html"&gt;http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently it's a little more complicated than Microsoft would have us believe.  If the vulnerabilities lie in shared libraries, we're in a world of pain until the libraries are fixed and software compiled using old libraries are recompiled with patched libraries.  At least that's my take...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3204430622523876552-7879468195548530215?l=www.netsentinc.com%2Fblog'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/7879468195548530215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.netsentinc.com/blog/2009/07/killbits-just-arent-enough-in-this-case.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/7879468195548530215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3204430622523876552/posts/default/7879468195548530215'/><link rel='alternate' type='text/html' href='http://www.netsentinc.com/blog/2009/07/killbits-just-arent-enough-in-this-case.html' title='Killbits just arent enough in this case :-('/><author><name>Network Sentry</name><uri>http://www.blogger.com/profile/03518311818338247703</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06328527604198986006'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>