Now THIS is some Friday entertainment. While reading through the ChangeLog of the new release of NMap, I found this:
"SCO Corporation of Lindon, Utah (formerly Caldera) has lately taken to an extortion campaign of demanding license fees from Linux users for code that they themselves knowingly distributed under the terms of the GNU GPL. They have also refused to accept the GPL, claiming that some preposterous theory of theirs makes it invalid (and even unconstitutional)! Meanwhile they have distributed GPL-licensed Nmap in (at least) their 'Supplemental Open Source CD'. In response to these blatant violations, and in accordance with section 4 of the GPL, we hereby terminate SCO's rights to redistribute any versions of Nmap in any of their products, including (without limitation) OpenLinux, Skunkware, OpenServer, and UNIXWare. We have also stopped supporting the OpenServer and UNIXWare platforms. "
Nmap 3.50 Press Release
Nice.
February 27, 2004
February 26, 2004
Slipstreaming and Boot CDs
JSI Tip 4253. A quick guide to presinstalling Windows 2000 and Windows XP.
How to create a custom bootable unattended Windows 2000 CD with integrated service pack and automated application installation - (.Doc version) - This is the BEST resource I found for creating my CDs.
Winnt.sif Creator - I do all the work, so you don't have to! - Very nice little free Creator.. even includes reg tweaks. - although you could always use the setupmgr.exe file inside the deploy.cab file on the Windows2000 CD in the \support\tools folder.
Unattended Windows 2003 CD - Reference - A great site for creating an unattended install cd - covers auto installing apps, drivers, tweaks, etc, and contains a great explaination of each option in winnt.sif.
You have a shortcut to explorer.exe but everytime you click it opens in My Documents. To save you time by getting it to open in My Computer instead just open the properties of the explorer.exe shortcut link, and paste explorer.exe /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D} into the target.
February 24, 2004
You come in and a machine is at a black screen telling you the Ntoskrnl.exe is missing or corrupt. Before you panic, take a look at this:
JSI Tip 2745. Windows NT could not start, Ntoskrnl.exe is missing or corrupt?
I dealt with the ntoskrnl.exe issue w/ a laptop just this morning. Basically what you're looking at is a corrupt/missing boot.ini file.
What I ended up doing was taking out the laptop's hdd, attaching it to an laptop hdd to ide adapter, then to a ide to usb adapter. Hooked it up to my workstation, and copied over a copy of the boot.ini file from another like-modeled laptop. Within 20 minutes (including backing up the user's profile and researching the issue) the laptop was back in the user's hands.
February 20, 2004
Freeware Arena Messageboard :: View topic - Yahoo spying on you'hoo: "Yahoo is now using something called 'Web Beacons' to track Yahoo
users around the net and see what you're doing and where you
are going - similar to cookies. Take a look at their updated privacy
statement: http://privacy.yahoo.com/privacy/us/pixels/details.html About half-way down the page, in the section 'Outside the Yahoo!
Network', you'll see a little 'click here' link that will let
you 'opt-out' of their new method of snooping. I strongly recommend
that you do this.
Note: This acts just like cookies.. so you have to do this for each browser and each pc and everytime you empty your cookies.
February 17, 2004
Code attacks Windows vulnerability | CNET News.com - A piece of code that exploits a critical vulnerability that Microsoft issued a patch for only last week has been posted online, raising fears of an imminent MSBlast-style attack.
On Feb. 10, Microsoft released a patch that fixes a networking flaw affecting all Windows XP, NT, 2000 and Windows Server 2003 systems. The company warned people to patch their systems because the vulnerability could be exploited by virus and worm writers.
Four days after the patch was released, a piece of code was published on a French Web site that would let anyone exploit the vulnerability, meaning that unpatched customers could be hit with a worm similar to last summer's MSBlast, also known as Blaster.
*Note:* Everyone needs to patch as soon as possible but be careful; I've heard mixed reviews about this one.. including domain controllers not booting or allowing anyone to log on after the patch has been applied.
February 15, 2004
Internet Storm Center - MS04-007 Exploit released: "A DOS exploit has been made available using the ASN.1 bug (MS04-007). This exploit uses port 445, 139 or 135. While this is just a DOS exploit, more serious exploits may follow soon.
Note: This Exploit appears to work only against Windows 2000 Professional. Dont forget history, it wasnt long after Dcom came out, that we saw universal shellcode for almost all windows platforms."
February 12, 2004
Microsoft probes Windows code leak | CNET News.com: "Microsoft is investigating how a file containing some protected source code to Windows 2000 was posted to several underground sites and chat rooms.
A spokesman said late Thursday that incomplete portions of Windows 2000 and Windows NT were illegally posted to the Internet. "
February 11, 2004
To repair a damaged Personal Folders PST file - Microsoft provides the Inbox Repair Tool for correcting most problems with damaged Personal Folders .pst files. If you do not see the Inbox Repair Tool on the Start menu, under Programs | Accessories | System Tools, use Start | Find or Start | Search (depending on your operating system) to search your system for Scanpst.exe.
Microsoft Security Bulletin MS04-005 - Vulnerability in Virtual PC for Mac could lead to privilege elevation (835150) - Important - This one is pretty out there for the average sysadmin..
Microsoft Security Bulletin MS04-006 - Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352) - Important - if you run WINS (still) you may want to take a peek at this...
Microsoft Security Bulletin MS04-007 - ASN.1 Vulnerability Could Allow Code Execution (828028) - Critical - This one is fun. The vulnerability is caused by an unchecked buffer in the Microsoft ASN.1 Library, which could result in a buffer overflow. An attacker who successfully exploited this buffer overflow vulnerability could execute code with system privileges on an affected system. The attacker could then take any action on the system, including installing programs, viewing data, changing data, deleting data, or creating new accounts with full privileges.
Because ASN.1 is a standard for many applications and devices, there are many potential attack vectors. To successfully exploit this vulnerability, an attacker must force a computer to decode malformed ASN.1 data. For example, when using authentication protocols based on ASN.1 it could be possible to construct a malformed authentication request that could expose this vulnerability.
Server systems are at greater risk than client computers because they are more likely to have a server process running that decodes ASN.1 data.
So basically, this is in *almost* every Windows system (not installed by default on WinNT), there is no workaround, there are a wide numbers of attack vectors (not like you could just block a port), and servers will most likely be hit easier than workstations.
Couple this with the IE update earlier this month (which breaks websites) and it looks like I'll have some overtime on my hands. THANKS MICROSOFT!!!
February 10, 2004
TechRepublic - Templates & Checklists - these are worth a look.
SystemExperts - Windows 2000 security - Hardening Windows 2000 Guide.
February 09, 2004
For those of you who are forced to use this POS...
ISS X-Force Database:realoneplayer-multiple-file-bo(15040): RealOne Player multiple file buffer overflows
February 06, 2004
From W2KNews Newsletter:
A tiny hint, but a source of endless pain for end-users. How to get rid of these cached addresses that keep popping up every time you start typing an email address?
Do a search for a hidden file with the extension *.nk2. That is Outlook's cache. Delete it and you should be fine. Make sure in the search that you are looking for "Hidden Files and Folders".
kbAlertz! - More RSS Feeds - "Receive Free Email Alerts [and RSS feeds] every time Microsoft Publishes NEW Support or Knowledge Base Articles" - Choose your alert for each product. - Nice!