Showing posts with label Software. Show all posts
Showing posts with label Software. Show all posts

Thursday, October 25, 2007

Microsoft addresses new reports of forced Windows updates and reboots

This seems to be an ongoing story that keeps changing as Microsoft seems to be trying to spin it it, maybe I'm just dense, but what part of no does Microsoft not understand? To make it plain and simple no means no and whatever way Microsoft wants to spin it people still have the right to choose what they want updated or not updated. Microsoft can spin it any way they want, either way they have broken peoples trust, and I think most people will see that. Microsoft spin away, how stupid do you really think people are?

Microsoft has posted a long and complex explanation to its Windows Software Update Services (WSUS) blog, explaining the latest case of why software updates are being pushed to users who believe they've turned automatic updating off. Here's the abridged version of what the Redmondians said.

read more | digg story

Friday, May 11, 2007

CrapWare

I just bought a new computer from HP, I must say I'm not thrilled, Vista is slow and Flashy, yet I don't see much of an improvement over XP SP2 if you have any choice at all stick with that.

The other thing I really hate is all the crapware that's being loaded I have spent hours trying to get rid of it as some of it is in hidden folders or have logfiles missing that one I keep getting when I try to get rid of the yahoo toolbar, needless to say I'm really ticked off with that. When are company's going to figure out that crapware just annoys your customers too death, at the very least make it easy to remove. No one likes something forced on them. All I can say is I'm going to put my money where my mouth is and the next computer I buy will be crapware free if I have to build it myself.

Computer company's take note people don't want Crapware.

Monday, March 05, 2007

WordPress Hacked/Cracked


It seems that the servers for Wordpress a popular program for Blog Publishing was Cracked.


An unknown cracker broke into a server hosting downloads of the popular WordPress blogging software and rigged the file with a remotely exploitable code execution vulnerability.
News of the hack comes directly
from WordPress creator Matt Mullenweg:
"If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately."

Mullenweg described the code planted into the download as "unusual and highly exploitable" and stressed that the 2.1.1 download was the only thing touched during the attack.
"This is the kind of thing you pray never happens, but it did and now we're dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we're declaring the entire version dangerous and have released a new version 2.1.2 that includes minor updates and entirely verified files. We are also taking lots of measures to ensure something like this can't happen again, not the least of which is minutely external verification of the download package so we'll know immediately if something goes wrong for any reason, he added.
He did not say how the attacker was able to breach the server.
Now, WordPress is trying to get the word out to any user who may have downloaded the rigged version 2.1.1.

If your blog is running 2.1.1, please upgrade immediately and do a full overwrite of your old files, especially those in wp-includes. Check out your friends blogs and if any of them are running 2.1.1 drop them a note and, if you can, pitch in and help them with the upgrade.
If you are a web host or network administrator, block access to "theme.php" and "feed.php," and any query string with "ix=" or "iz=" in it.


Thursday, October 12, 2006

Zero Day

Here is an article about even more security flaws in XP. I really don't understand how Microsoft can come out with operating systems that are so prone to problems like this.

Microsoft releases 6 patches for flaws

October 12, 2006 - 12:16PM

Microsoft has released six patches to fix software flaws that carry its highest threat rating, including three for defects that attackers were already trying to exploit.
The company said all six of the critical flaws could allow an attacker to obtain some access to other people's computers.

The software maker also released four other patches to fix vulnerabilities that the company deemed less severe.
Customers can download all the patches for free on Microsoft's security website and also can sign up to have them automatically delivered to their computers. The automatic update system went down for several hours on Tuesday, but the problem was later resolved.
Microsoft said last month that it knew attackers were already trying to take advantage of defects in its Windows operating system, Microsoft Word software and PowerPoint presentation program.

Christopher Budd, a program manager with the Microsoft Security Resource Centre, said that the company had seen limited attacks exploiting the flaws, but were nevertheless recommending that users apply those and other patches immediately.
Such vulnerabilities are rare. In most cases, security experts quietly provide Microsoft evidence of a security flaw, allowing the company to fix the problem in secret and release a patch before attackers can take advantage of it.
But recently, the company has been hit with a number of so-called "zero-day" attacks, in which flaws are targeted before Microsoft is aware of them or can release patches.
Such attacks have prompted some security researchers to release their own interim fixes. Microsoft also has occasionally taken the unusual step of releasing patches outside of its normal monthly fix schedule, so users can be safeguarded more quickly.

Budd said Microsoft isn't seeing any specific pattern to the burst of zero-day attacks. But he said the company is seeing more focus on attackers trying to infiltrate computers through applications - such as Word or PowerPoint - rather than the Windows operating system.
Microsoft software is a constant target of internet attackers, in part because the company's products are so widely used.
Microsoft has yet to release a patch for one other publicly known flaw - one affecting the Internet Explorer browser that is part of its Windows operating system. Budd said the company was seeing very few attacks as a result of the flaw.

AP

Wednesday, September 13, 2006

MicroSoft We Share Your Pain

It's a bit old but still funny, if only they really did feel our pain.




WSYP Project:
"We Share Your Pain"




Now I am all for increasing the connection
between Microsoft's customers and the software product
teams...especially, the individual developer.




So, if you've ever wondered what happens when
you press the Send Error Report button after an application failure,
you need to watch the four minute video!






We Feel Your Pain












FlashVars="fileNumber=0&startStreaming=true&moviePath=http://www.marclirontraining.com/vids/feelpain.flv&movieLength=230&finalRedirectURL=&redirNewWindow=_self&autoplay=1" quality="high" bgcolor="#ffffff" width="330" height="290" name="movieplayer320" align="middle" allowScriptAccess="sameDomain" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />