Archive for April, 2008

CyTRAP Labs’ tip - Microsoft Windows XP SP3 RC2

Wednesday, April 23rd, 2008

Windows XP Service Pack 3 (SP3) Release Candidate 2 (RC2)

    “Windows XP SP3 is a rollup that includes all previously released updates for Windows XP, including security updates, out-of-band releases, and hotfixes. It contains a small number of new updates, but should not significantly change the Windows XP experience.”

Over 191 hotfixes are included.

Who should download the Windows XP Service Pack 3 (SP3) Release Candidate 2 (RC2)

If you have no problem with Windows XP for now, wait until the public release. If your Windows XP acts weird and you are considering a re-install anyway, this is for you, get the release here:

XP SP3 RC2

You can download this package in German, and/or Japanese besides in English.

Windows XP Service Pack 3 will be offered on Windows Update when Service Pack 3 releases during early summer of 2008 we hope.

If this post was helpful to you, please consider stumbling it or Digg this WinCurity post from CyTRAP Labs.
Also of interest:
CyTRAP Labs quicktip - installing fonts in Windows CyTRAP Labs tip - What is causing missing change/remove program buttons in Windows?
CyTRAP Labs checklist - how to make sure the latest security patch is installed CyTRAP Labs quicktip - Windows Home Server corrupts files


Technorati , , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (385)

Uncategorized | No Comments »

CyTRAP Labs’ choice - free tools - 12 best Twitter tools

Friday, April 18th, 2008

So post-it notes and notebooks is what Twitter is to blogs - a sort of micro-blogging that is becoming ever more popular with users.

Some have argued that all this microblogging is helping us to become less effective

But what are some of the great tools with Twitter?

We list some of our favorites below

Twitter is a great tool to keep track of your friends and associates. However, unless you are careful it can take away too much time from your workday.

To help you save time while taking good advantage of what Twitter can offer you we list a few of the tools we found to work best for us.

These are not listed in particular order and most do not require you to install anything to take advantage of them except in one or two cases an add-on is needed for your Firefox browser, so read on.

1) Update and check on your friends’ Twitter status with Twitter Fox

There are many other tools that help you send out a tweet. I like Twitter Fox because it lets me continue working and just switch over to Firefox to see what my friends are up to or else send an update myself.

This is a nice Firefox add-on.

2) Imports your feeds - matches you up with other touluu users

Based on your feeds and interests, the service will search for other users with interests similar to yours, almost like a dating service, with top matches listed first.

You have the choice of adding people as contacts, or just adding suggested feeds. If you add friends, it also compares you and gives you a match percentage, as well as suggests any of their feeds you might want to read.

3) Twubble

Twubble is a service that recommends new twitter friends to you based on the friends of your friends. It was created by Google software engineer Bob Lee in April 2008

Twubble goes through 30 of your follows who’ve updated most recently, and suggests a maximum of 100 suggestions. It then ranks them

- taking the people you like = follow, AND

- checking who of your favorites (nr. 1) follow the up to 100 suggestions

But it is, of course, a bit inbreeding because it is likely that your favorites will appreciate the same type of tweets you would. Nevertheless, you can find a few important ones that you might have missed otherwise.

PS. limiting things to 100 suggestions prevents time-outs from API calls to Twitter (always an issue) as well as any crash if you happen to be following some heavyeights (e.g., TechCrunch)

4) Use Tweed Scan to track tags or your brand such as Daimler, Mercedes-Benz

This tool searches Twitter’s public timeline for keywords or snippets of text. It helps you:
- find what people are saying about a topic or your brand - Mercedes-Benz

- find what blog posts or webpages people may have linked to in their Twitter posts,

- get a daily digest delivered by Tweet Scan directly to your e-mail in-box (who and what was posted the last 24-hours regarding this name, brand, etc.)

For instance, the above hyperlink shows you all the posts that were tagged with @forrmarketing08 in each tweed, you just type forrmarketing08 in Tweed Scan and voila.

5) Take a drive with summize - find the conversation - meme tool

This is a conversation tracker that is also quite impressive. It allows you to search for keywords user, language, attitude, tag, to and from user and so forth.

In the above URL we used again the forrmarketing08 as the keyword to find the posts that were tagged with this word. As nice as Tweed Scan. Check and compare the two.

6) IPhone works best with Pocket Tweets

While this tool is not as good as Twitter’s new mobile site for reading tweets, it still is the best way to post your tweet to Twitter from an iPhone.

7) Wanting thwirl to be able to be logged into several Twitter accounts at once

This is great if you have several Twitter accounts such as one for work, another for your pals and the third for your family only. The disadvantage is that you have to download
and install Adobe AIR 1.0 (if not already installed) first. Theafter, you can download and install thwirl.

8) TinyURL you need to shorten your URLs - works with Twitter Fox

You can use Tiny URL by going to their site and pasting a link into their web page to get the short URL back. Else, install the the TinyURL bookmarklet with your browser

TinyURL comes with Twitter Fox so you are covered there.

9) Tweedburner helps you track who pays attention to the URLs you tweed

this is great in more ways than one, namely

- it shortens URLS and, most importantly,

- tracks what actually happens with them once you posted them.

This allows you to see how often a link you posted has been clicked on.

Gives you a pretty good picture of what your followers are most interested in at this moment in time.

If this post was helpful to you, please consider stumbling this post from CyTRAP Labs.
CyTRAP Labs tip - 12 best Twitter tools
Twitter - what about privacy and e-discovery?
Twitter - why this technology will cause corporations more than one headache EU-ReguStand trend spotting - Twitter - e-discovery requires managing your risk exposure smartly

.10) Tweetr is the tool to share files with other Twitter users

Tweetr is a mashup of Twitter and file sharing. Drag any file onto Tweetr to automatically upload your file. Tweetr will then provide you with a shortened URL that you can send to your followers via Twitter.Amazing is that it can access a webcam taking pictures to send to Twitter. File size limit is 10 megabytes.

Only disadvantage is that you have to first install Adobe AIR 1.0 to make it work.

11) TweedStats tells you more about your Twitter use

This one crates graphs and shows when you tweet the most and who has sent you the most direct messages.

The above gets you to see my personal Twitter stats.

12) Twitterholic - who has the greatest numbers of followers on Twitter

this one is neat, tells you who is following whom…. many have over 2,000 followers. Nonetheless, a small number are those with more than 10,000 people following their daily tweets, amazing.

Technorati , , , , , , , , , , , , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (383)

Uncategorized | 7 Comments »

CyTRAP Labs’ reminder - 2008-04-17 - security update for Mozilla Firefox and SeakMonkey

Thursday, April 17th, 2008
    The Mozilla Foundation has issued an important security patch for the javascript garbage collector vulnerability for Mozilla Firefox and Seamonkey that fixes 1 critical vulnerabilities (Please click on the link, choose Login as guest - click on this link again and voila free access)

    If you have chosen the option that the program checks regularly with the Mozilla Foundation’s website for updates , the security update should have been downloaded BY NOW automatically or next time you log onto the internet (for more details see below

This vulnerabilitiy exposes you to a vulnerability in the JavaScript engine. This vulnerability is due to memory corruption errors during JavaScript garbage collection.

We rate this risk as follows:

CyTRAP Labs security risk barometer - 4 = critical

low elevated moderate-

ly critical

critical severe
1 2 3 4 5

For more information and explanations about the CyTRAP Labs risk barometer you can visit here:CyTRAP Labs security risk barometer
WHAT CAN YOU DO?

CyTRAP Labs security risk barometer - 4 = critical

operating system affected
affected software

  • Mozilla Firefox - all prior versions to 2.0.0.14, and
  • SeaMonkey - all prior versions to 1.1.9
risk rating given for these vulnerabilities is a 4 (four)
where is the patch? depending upon the program you run:

To download any of these versions you need admin rights on your PC of course

what should one do? The Software Update preference pane is set to automatically check by default if you have the latest version installed.Hence, once you go onto the internet, the latest version should be downloaded automatically.If you were on the Internet on 2008-04-17, the program should have asked you, downloaded and installed the program (requires shutting down program and re-starting it).

If you are not sure, read below we tell you how to check and download manually if need be - quick and easy.

how can I check that I do have the latest version installed click Help > About Firefox or About SeaMonkey from the Help menu

this shows which version runs on your machine or click onHelp > check for updates - if you do not have latest version already installed, Firefox will download it now if you have administrator rights for this PC

not patching the vulnerability could cause what kind of damage to my PC? Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
where can one get more details from the vendor? vendor has issued several security bulletins:MFSA 2008-20 - April 1t, 2008
where can you get more technical information about the vulnerabilities CVE-2008-1380,
release date from vendor 2008-04-16 (Pacific Standard Time)
why is this a reminder and not an alert? security alert or reminder - that’s the question
did CASEScontact.org release an advisory about this earlier? no - neither exploit code was published nor any details before the vendor issued a patch
did CASEScontact.org release a zero-day advisory nothing was necessary (see above) patched zero-day archive

Please make sure that your PC is patched - thank you.

If this post was helpful to you, please consider stumbling it or Digg this WinCurity post from CyTRAP Labs.
Also of interest:
CyTRAP Labs’ reminder - 2008-03-27 - security update for Mozilla Firefox, Mozilla Thunderbird, and SeakMonkey CyTRAP Labs: security reminder - 2008-04-08 - Patch Tuesday - Microsoft
the mission of ComMetrics Benchmarking Firefox 3.0 Beta 4 - did the Test Follow Good or Best Practice?

Technorati , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (382)

Uncategorized | No Comments »

CyTRAP Labs: security reminder - 2008-04-08 - Patch Tuesday - Microsoft

Tuesday, April 8th, 2008

Microsoft has released 8 security bulletins
5 of these bulletings are ranked critical - by Microsoft, which means ‘can result in remote code execution’ 3 are important (this summary focuses on the critical ones only)
If you have Automatic Update activated for your PC, these patches will be downloaded automatically
does your automatic update work properly?If you are not sure if it does, check below, otherwise by mid-day 2008-03-13 the downloads should be on your machine…. remember, installing the downloads might necessitate a reboot.

Just wait until you stop working once you shut down your machine that will suffice to get them installed.

This vulnerabilitiies exposes you to a risk that we rate as follows:

CyTRAP Labs security risk barometer - 4 = critical
low elevated moderately
critical
critical severe
1 2 3 4 5

For more information and explanations about the CyTRAP Labs risk barometer you can visit here:

CyTRAP Labs security risk barometer

what Microsoft Patch Tuesday has in store for us this month
operating system affected
  • Microsoft Office
  • Microsoft Internet Explorer
affected software
  • see above
risk 5 security bulletins rated critical BY Microsoft were released …

the risk rating given for these vulnerabilities by CyTRAP Labs is a 4 (four out of five levels) = CRITICAL - orange

how long did this vulnerability remain unpatched since it was publicly disclosed ==> zero-day alert these vulnerabilities have been known for a while (several months), however, it was not actively exploited.
patch prioritization - client side impact users and administrators are urged to roll out this patch as soon as possible, once it has been verified that it does not break any internal applications.
where is the patch? will be downloaded using Automatic Update, update is detected by the MBSA:

CyTRAP Labs tip - using the Microsoft Baseline Security Analzyer called MBSA

what should one do? If your Automatic Update is functioning properly, you are covered.
CyTRAP Labs tip - how to make sure the latest security patch is installed
how can I check that I do have the latest version installed find out more information how cou can check that this update is installed as well on your PC or server here:
not patching the vulnerability could cause what kind of damage to my PC? could be exploited by attackers to execute arbitrary code on the user’s machine BETTER patch NOW
Once updated, what do you need to do? These updates will require a restart for your PC.
Where can you get the overall summary Microsoft has issued? full version of the Microsoft Security Bulletin Summary for April 2008
where can one get details about each of the patches released on this month’s Microsoft Patch TuesdayWe list the critical ones only - there were 5 important ones as well - Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183) - Microsoft Security Bulletin MS08-018 - CRITICAL
Vulnerabilities in GDI Could Allow Remote Code Execution (948590) MS08-021 - CRITICAL

Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338) Microsoft Security Bulletin MS08-022 - CRITICAL


Security Update of ActiveX Kill Bits (948881) - Microsoft Security Bulletin MS08-023 - CRITICAL

Cumulative Security Update for Internet Explorer (947864) - Microsoft Security Bulletin MS08-024 - CRITICAL

release date from vendor 2008-04-08 - Pacific Standard Time
why is this a reminder and not an alert? security alert or reminder - that’s the question
did CASEScontact.org release an advisory about these vulnerabilities earlier? No we did not issue a zero-day alert
CASEScontact.org release a zero-day advisory NO we did not issue a zero-day advisory see also patched zero-day archive)
Common Vulnerabilities and Exposures (CVE) project has assigned the following numbers to these vulnerabilities that were patched by Microsoft CVE-2008-1083, CVE-2008-1085, CVE-2008-1086, CVE-2008-1087,
CVE-2008-1088,

Please make sure that your PC is patched - thank you.

If this post was helpful to you, please consider stumbling it or Digg this WinCurity post from CyTRAP Labs.
Also of interest:
CyTRAP Labs: security reminder - 2008-02-12 - Patch Tuesday - Microsoft CyTRAP Labs: security reminder - 2008-03-11 - Patch Tuesday - Microsoft
the mission of ComMetrics why benchmark

Technorati , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (381)

Uncategorized | No Comments »

CyTRAP Labs reminder - 2008-04-03 - update Quicktime (iTunes)

Thursday, April 3rd, 2008

Apple has issued an important security patch for Quicktime that fixes several critical vulnerabilities (Please click on the link, choose Login as guest - click on this link again and voila free access)
If you have default Update installed with the program, the latest version should be downloadd automatically next time you log onto the internet (for more details see below)

This vulnerabilitiy exposes you to a risk that we rate as follows:

CyTRAP Labs security risk barometer - 4 = critical
low elevated moderate- ly critical critical severe
1 2 3 4 5

For more information and explanations about the CyTRAP Labs risk barometer you can visit here:

CyTRAP Labs security risk barometer

WHAT CAN YOU DO?

operating system affected
  • Windows XP and Vista,
  • Apple Leopard, Tiger, Panther
affected software
  • Quicktime - all prior versions to 7.3.1
  • iTunes - Quicktime is part of iTunes

Hence, start your Quicktime on your PC go to Help > Update check

risk rating given for these vulnerabilities is a 4 (four)
where is the patch? depending upon the operating system you run:

what should one do? The Software Update preference pane is set to automatically check by default if you have the latest version installed.

Hence, once you go onto the internet, the latest version should be downloaded automatically, if you are not sure, read below we tell you how to check and download manually if need be - quick and easy.

how can I check that I do have the latest version installed click About Quicktime from the Help menu
this shows which version runs on your machine
not patching the vulnerability could cause what kind of damage to my PC? DO NOT OPEN IMAGES, MOVIES, ETC. from untrusted sources 1 could be exploited by remote attackers to disclose sensitive information or take complete control of an affected system.
2 various unspecified errors can be exploited to execute arbitrary code.
3 more nasty things…
where can one get more details from the vendor? vendor Apple has issued a security bulletin
where can you get more technical information about the vulnerabilities CVE-2008-1023, CVE-2008-1022, CVE-2008-1021, CVE-2008-1020,CVE-2008-1019, CVE-2008-1018,
CVE-2008-1017, CVE-2008-1016, CVE-2008-1015, CVE-2008-1014, CVE-2008-1013
release date from vendor 2007-04-03 - Pacific Standard Time
why is this a reminder and not an alert? security alert or reminder - that’s the question
did CASEScontact.org release an advisory about this earlier? NO
did CASEScontact.org release a zero-day advisory No - we did not issue a zero-day advisory see also patched zero-day archive)

60% OF OUR READERS SUBSCRIBE

For better risk management, compliance and protection - become a member of the 60% of our READERS THAT HAVE MADE SURE THEY GET A SUBSCRIPTION

- advisory, zero-day exploits and regulatory intell via alert, newsletter or RSS feed

or just make your choices at CyTRAP Labs subscription portal

Technorati , , , , , , , , , , , , , , , , , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (380)

Uncategorized | No Comments »