Remote Code Execution on MS Word

Posted in Nicht kategorisiert on March 23, 2008 by ibleedyellow

Word is leaking code again…. If you do not use symphonie but the Evil Productivity software you are probably having problems with being the target of hackers…..
If you do own one of the programs below you might be subject of forgery ……
SO USE IBM SYMPHONY… ITS FREE and it comes with your Notes 8 client or as a seperate download

  • Word 2000 Service Pack 3
  • Word 2002 Service Pack 3
  • Word 2003 Service Pack 2 oder 3
  • Word 2007 mit oder ohne Service Pack 1

EVIL Empire is talking of very limited attacks…. yeah sure….

Microsoft is investigating new public reports of very limited, targeted
attacks using a vulnerability in the Microsoft Jet Database Engine that
can be exploited through Microsoft Word.

MS is investigating and take appropriate action (i wonder how much that would be) :-)

Microsoft is investigating the public reports and customer impact. We
are also investigating whether the vulnerability can be exploited
through additional applications. Upon completion of this investigation,
Microsoft will take the appropriate action to help protect our
customers. This may include providing a security update through our
monthly release process or providing an out-of-cycle security update,
depending on customer needs.

And the scenario is sooooooo very seldom an limited… hmmmmm i guess it would be worth some studies on what the definition on limited is…..

In a Web-based attack scenario, an attacker would have to host a Web
site that contains a specially crafted Word file that is used to
attempt to exploit this vulnerability. In addition, compromised Web
sites and Web sites that accept or host user-provided content could
contain specially crafted content that could exploit this
vulnerability. An attacker would have no way to force users to visit
these Web sites. Instead, an attacker would have to persuade users to
visit the Web site, typically by getting them to click a link in an
e-mail message or Instant Messenger message that takes users to the
attacker’s site.

heise online - Word führt fremden Code aus
Microsoft Security Advisory (950627): Vulnerability in Microsoft Jet Database Engine (Jet) Could Allow Remote Code Execution

Technorati Tags: , ,

Software update politics from Apple… hence what could happen

Posted in Nicht kategorisiert on March 22, 2008 by ibleedyellow

Read this article on softwareupdate politics……
I would go one step further…. What if IBM would send you additional software like Sametimeadvance ore any other part of ther bundle and than asking you paying for it :)
that ist hilarious……..
The pricing politics of apple where always very strict and i did love itunes and recently bought me an IPOD. But this lets me think about moving at least with the player software to songbird or any other software that will do. Any good ideas?

ORIGINAL LINK TO Johns BLOG

Apple Software Update

What Apple is doing now with their Apple Software Update on Windows is wrong. It undermines the trust relationship great companies have with their customers, and that’s bad — not just for Apple, but for the security of the whole Web. What they did yesterday was to use their updater for iTunes to also install their Safari Web browser –what follows is some background and analysis.

Keeping software up to date is hard — hard for consumers to understand what patches are for, how to make sure they’re up to date.

It’s also critically, crucially important for the security of end users and for the security of the Web at large that people stay current. If people don’t update software regularly, it is impossible for them to remain safe; good software developers are creating improvements constantly. That’s why Mozilla spends so much time making sure our own Automatic Update Service works, and why we spend so much time agonizing over the user interface for the updates. We look at the data every time we do an update; we obsess about what we call “uptake rates” — the percentage of Firefox users who are on the most current version of the browser a day or a week or a month after release. As a result, Firefox users are incredibly up to date, and adopt very quickly.

There’s an implicit trust relationship between software makers and customers in this regard: as a software maker we promise to do our very best to keep users safe and will provide the quickest updates possible, with absolutely no other agenda. And when the user trusts the software maker, they’ll generally go ahead and install the patch, keeping themselves and everyone else safe.

Anyone who uses iTunes on Windows has Apple Software Update installed on their machines, which does just what I’ve described above: it checks for new patches available for Apple-produced software on your Windows machine, alerts the user to the availability, and allows updates to be installed. That’s great — wonderful, in fact. Makes everyone more likely to have current, patched versions of Apple’s software, and makes everyone safer.

Here’s screen that comes up on Windows XP if you’ve got iTunes installed:


(photo credit CNET)

The problem here is that it lists Safari for getting an update — and has the “Install” box checked by default — even if you haven’t ever installed Safari on your PC.

That’s a problem because of the dynamic I described above — by and large, all software makers are trying to get users to trust us on updates, and so the likely behavior here is for users to just click “Install 2 items,” which means that they’ve now installed a completely new piece of software, quite possibly completely unintentionally. Apple has made it incredibly easy — the default, even — for users to install ride along software that they didn’t ask for, and maybe didn’t want. This is wrong, and borders on malware distribution practices.

It’s wrong because it undermines the trust that we’re all trying to build with users. Because it means that an update isn’t just an update, but is maybe something more. Because it ultimately undermines the safety of users on the web by eroding that relationship. It’s a bad practice and should stop.

[I’ll make 2 points that I want to make very clear: (1) this is not a criticism of Safari as a web browser in any way, and (2) I have no objections to the basic industry practice of using your installed software as a channel for other software. This is specifically a criticism of the way they’re using the updating system. I’d much prefer to be writing about Firefox, but this practice hurts everyone and is important to note.]

Spread the Word Tibetian Life in danger (Tibet and the Big (red) brother)

Posted in Nicht kategorisiert on March 22, 2008 by ibleedyellow

As there are riots going on in Tibeth which is occupied by China… The war is not only being fought on the strid by classic beat them a
up tactics ;-(
The chinese drove it way further and tried to silence the pro Tibet movement by attacking internetservers of democratic movements by the
Dalai Lama
Read more on this F-Secure article Targeted malware attacks against pro-Tibet groups - F-Secure Weblog : News from the Lab

Don’t let Democracie be thrown down. Spread the Word on Tibet

Tibet - Wikipedia, the free encyclopedia

IP Radio Station Ripping

Posted in Nicht kategorisiert on March 22, 2008 by ibleedyellow

document.write(blogsDate.date.localize (120611

while reading “PC Praxis” the other day i stumbled upon ClipInc
a tool to record online radio….. That brings back some nostalgie from
the early days while i spent hours in front of my radio recording all
the chartbreakers on tape……

My question would be:
With all the suing going on with illegal downloads… is ripping radio stations still legal??
If
not….. is getting tought in school still legal or will anyone like
the predesessors of gallilei gallileo or oppenheimer or albert einstein
sue you becaus you did not buy a licens to learn??

hmm i just dont get it…

check out ClipInc here

Bleed Yellow

Posted in Nicht kategorisiert on March 16, 2008 by ibleedyellow

Sundey evening entry…..

ok here is the story…
scott wasn’t able to send me a bleed yellow shirt yet (ok i admit it is due to i did not send him my adress yet and i am not sure he will cover shipping to germany :-)

so i had to get me something else…
ok it is yellow…. not more ti say and it reads “Farbe bekennen” ( confess collour)

Link Collection to important 8.0.1 support docs

Posted in Nicht kategorisiert on March 13, 2008 by ibleedyellow

Open Mic Invitation: Notes 8.0.1 Client Features

Posted in Nicht kategorisiert on March 13, 2008 by ibleedyellow

Having a slight problem.
In my opinnion client installation/migration should be able to be performed no matter what client lays underneeth.
So we where, as we are in the migration phase of about 15 000 users using the 8.0.1 as it came out. After launch of the 8.0.1 german we installed the german over the english client. That caused problems. The client refuses to boot up anymore after upgrade. We had that on multiple machines. With different people performing the update. So no layer 9 problem :-)
So we finaly ended up opening a pmr with ibm. Below is the anonymized answer we got. How helpfull is that??
Anyone knowing any workarround or how to?
Well i know most of you are english tonges so no need for localized installations….
I apreciate any help….

Hello Mr XXX,

My name is Rxxxx Mxxxxx and I am assigned to pmr 6xxxx,xxx,xxx ‘ notes client doesn’t start after update’.

(1) In the pmr description it mentions that the 8.0.1 English was installed first and ten the German 8.01 build was installed over it.

Why was this done. Could the German 8.0.1 Client be installed on its own.

(2) Please use one of the Client machines involved and remove the Client ( all clients ) installation from it.

Use this technote as guidance ;

Lotus Software Knowledge Base Document

Title: How to perform a clean reinstall of a Notes client
Doc #: 1245159
URL: http://www.ibm.com/support/docview.wss?rs=899&uid=swg21245159

(3) Reinstall German Client and see if it launches.

Best regards

Rxxxx Mxxxxxx

This is where the technote goes to
IBM - How to perform a clean reinstall of a Notes client

Open Mic Invitation: Notes 8.0.1 Client Features

Posted in Nicht kategorisiert on March 13, 2008 by ibleedyellow

I got an invitation from IBM :-)
and i think it is some considerable openmic!
so if someone is interested hop on :-)

You are invited to participate in an IBM Open Microphone call with IBM
Development & Support Engineers for the new Notes 8.0.1 Client Features.
There is no charge for participating. The topic and dial information for
this call is:

Title: Notes 8.0.1 Client Features

Date: March 19′th
Time: 10:00 am eastern US time (2 pm GMT)
US & International Dial-in Info =>
http://www.ibm.com/support/docview.wss?uid=swg21297701

Date: March 19′th in the Americas (March 20′th in Asia Pacific)
Time: 9:00 pm eastern US time (1 am GMT, 6 pm US West Coast)
US & International Dial-in Info =>
http://www.ibm.com/support/docview.wss?uid=swg21297701

The IBM Open Mic calls are intended to provide you the opportunity to
interact directly with the IBM Lab developing IBM software products, in
this case the Notes Client team, to have product questions answered. For
details about the Open Mic calls, please see the Lotus Support Open Mic
technical exchange page . If this link is not active, paste this URL into
your browser (http://www.ibm.com/support/docview.wss?&uid=swg27011126).

You can submit your question in advance via the Notes 8 forum using the
Open Mic Invitation for this topic in the “Open Mic” category. We will also
take questions not submitted in advance. Questions should be of general
interest and by their nature help you install, configure, manage or
optimize your environment or processes. Troubleshooting of specific
problems should still be handled by Technical Support, not by Open Mic
calls. For reference, you may wish to review the What’s new in release
8.0.1 of Notes Client, Domino Server, and DWA. (http://www.ibm.com/support/docview.wss?uid=swg21292420). Note: the open mic will focus on new client features.

Link to Open Mic Invitation:
http://www.lotus.com/ldd/nd8forum.nsf/GeneralCategory/00f0347a199e09f2852574090074c4a6?OpenDocument
You will need to provide your name and company affiliation when dialing in.
You will need a touch tone phone to be able to ask questions. The calls
will be recorded and posted to our Support web site as podcasts.

You are receiving this invitation because you are a Lotus Domino customer,
who has contacted us for technical support in the past. If you do not wish
to receive mails like this one from IBM, please reply to this e-mail and
change the Subject field to: unsubscribe <e-mail address>, e.g. unsubscribe
user@company.com. Please be aware that this will also unsubscribe you from
the regular FAQ Response mailings.

Please remember to book your calendar for this call. We look forward to
talking with you!

The IBM Lotus Notes/Domino Support Team

RIM and Traveler

Posted in CEBIT with tags , , on March 7, 2008 by ibleedyellow

RIM and Trevelar

Ok there I walked to my date a the RIM booth.
My first questeion:
How is RIM’s position regarding the Trevelar anouncement?
The Answer:
What is trevelar. Ok one needs to now that mobile windows is no big deal in Germany. My company uses thousands of BlackBerrys and 0 Smartphones runnig Windows mobile. So it was more less a rethorical question. But anyways i was a little astonished on how lax RIM is taking Travelar.

CEBIT travel(er)ing by Deutsche Bundesbahn (sucks)

Posted in CEBIT with tags , , on March 7, 2008 by ibleedyellow

CEBIT travel(er)ing by Deutsche Bundesbahn (sucks)

We ar writing the year 2008 March the 5th. I am underway travveling on hyperspeed by deutsche bahn to the CEBIT 2008 universe….

CEBIT 2008 the world greatest computer fair as you can here it all over the aether….
Steve Balmer, our Chancellor Mrs. Merkel, Volker Weber (VOWE.net) ;-) and many other beeing there..

So am I.

I started my journey at 5:30 AM at home to take a 40 minutes drive to Würzburg train station
Everything arranged by the secretary so nothing could go wrong?
Nothing at all?
You might think that signs leading to a parking are realy ment that you park there??
Hmmmmm ok, i am german and i am bound and used to rules and regulations…..
traffic signs that leed you to certain locations are ment to be followed…..
So i obeyed the rules and i was a good german following the “signs”.
I should not have done that……
Sigh… I went to some service personal at the “Bahnhof” and asked how that reserved parking works…..
well one would expect that everything is arraged they just tell you…. ok go hiere and there….
NO…
I was told i was parking in the wrong “Parkhaus”. Ok i did follow the signs… but i was wrong. Hang on. Something is wrong here :-)
Shouldnt i be following rules and signs cause i am a good german??
Well well…. i got told where i am parking i will have to pay! OK i already did so where is the point paying again. I started aruing, cause this is totaly missleding with the signs. There was no “reserved parking” sign here!
OK….. my temper went down a bit, just to be braught right back to the top :-)
The reserved seats in the train where gone.. just because somebody decided to swap the train.. hm where is the point reserving seats if they are not reserved anymore? and why pay?
So i was sitting in some tight seat, no table no powerplug to get the thinkpad (ohhh  yes i would love to hyve a mac boock pro, if you have a spare one i will give you my mailing adress).
Listening to Keith Urban on my IPOD….
At least the sun was comming up and lightneed up my badly started day a little bit :-)
I will continue on my way back home tonight if and when i am able to load my thinkpad (anyone out there who has a macbook present for me :-)
So bye for now.