stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


The MS 'friendly' security alert service - just say d'oh







The MS 'friendly' security alert service
- just say d'oh

The MS 'friendly' security alert service
- just say d'oh
03/20/2003 11:55 AM

A




This is a GrokNews Entry: (what is grok?)





Similar Items

The MS 'friendly' security alert service - just say d'oh

Grok Headline matches for The MS 'friendly' security alert service - just say d'oh

MEDIA ALERT: Secure Elements Discusses
IT Security for Higher Education at
EDUCAUSE Security Professionals
Conference


MEDIA ALERT: Secure Elements Discusses
IT Security for Higher Education at
EDUCAUSE Security Professionals
Conference
03/31/2005 03:03 AM
Daniel Bezilla, Secure Elements’ chief technology officer, will explore how educational communities can benefit from implementing an Enterprise Vulnerability Management solution. [PRWEB Mar 31, 2005]

Blacklist Alert Service


Blacklist Alert Service 02/18/2004 10:49 PM

A banker from downunder and a wee to the right just informed me that he can't read my blog because WebSense, used by his bank, is blocking the Docuverse domain.  I know where to go for regular checkup of my credit ratings. Where can I go to find out whether I am on blacklists and how can I get myself off them?  Is there a notification service and correction procedures for blacklists?  If not, I think there is a need for such a service so I'll help in putting one together.


Science.gov Offers Alert Service


Science.gov Offers Alert Service 03/24/2005 01:53 PM
Science.Gov has begun a new e-mail based alert service, which you can access at their home page: http://www.science.gov . If you don't have an account on the Science.gov site, you'll...

'Friendly' Killer Whale Damaging Boats
(AP)


'Friendly' Killer Whale Damaging Boats
(AP)
08/28/2004 11:50 AM
AP - A "playful" killer whale who likes to frolic alongside fishermen has damaged three boats in separate incidents in recent weeks.

'Friendly' Killer Whale Damaging Boats


'Friendly' Killer Whale Damaging Boats 08/29/2004 01:41 AM
Abcnews.go.com - Sat Aug 28, 10:18 pm GMT

D'oh!


D'oh! 04/25/2004 09:54 PM

B rad's not kidding here. Gmail as it stands is hackable. I logged in today and noticed a bunch of read mail I hadn't read and it turned out that my friend got into my account earlier today. That'll teach me to set my password reminder to something I mentioned online ages ago.


Security Alert


Security Alert 09/21/2004 04:41 PM

Mac Security Alert


Mac Security Alert 05/12/2004 09:43 AM
A UK government organization responsible for gathering information on IT security incidents has issued two security advisories regarding recently identified vulnerabilities in Mac OS X. By Macworld UK (via MyAppleMenu)

PHP Security Alert


PHP Security Alert 06/05/2005 11:38 PM
PHP Advanced Transfer Manager Include File Error Lets Remote Users Execute Arbitrary Commands

Best D'oh! of the year so far


Best D'oh! of the year so far 02/01/2005 09:09 PM
Matt Biddulf has an animated screen capture of what del.icio.us would look like embedded in the BBC 3's page. It's an eye-popper all right: So elegant it seems obvious. Brilliant. (Thanks to The Obvious for the link.) [Technorati tag: taxonomy] danah responds to Clay's enthusiasm (which I generally share) for tags. There’s a problematic feature to crowds - they like to homogenize... Folksonomy isn’t asking the questions about the implications of collective action classification. Who benefits? Who becomes marginalized? What priorities bubble up? How does pressure to homogenize affect the schema and the people involved? How are some people hurt...

Kansas Offers Alert Service for
Gubernatorial Press Releases


Kansas Offers Alert Service for
Gubernatorial Press Releases
04/03/2005 04:02 PM
The state of Kansas is offering Govwire, an e-mail service that'll send out alerts when press releases are issued by the office of the Kansas governor. You can get more...

Yet another Windows security alert


Yet another Windows security alert 03/19/2003 10:25 PM
Microsoft has released Security Bulletin MS03-007, which simply says: An identified security vulnerability in Microsoft® Windows® 2000 could allow an attacker to take control of your computer. This issue is most likely to affect computers used as Web servers. You can help protect your computer from this vulnerability by installing this update from Microsoft. If you're using Windows 2000, make sure you install it.

Security Alert: Another IE6
Vulnerability


Security Alert: Another IE6
Vulnerability
11/25/2002 11:55 AM
A new exploit has been found in IE6 that allows a serious security vulnerability. Although this is not directly related to PHP Freaks, I thought I would take a moment to point this out to our readers.

Security Alert: Voluntary XSS


Security Alert: Voluntary XSS 04/09/2004 05:30 PM

This is a personal security alert against a dangerous yet increasingly popular practice which I call Voluntary XSS.  Voluntary XSS involves a website voluntarily embedding script fragments hosted by another, typically very popular, website.  Here is an example:

Voluntary XSS is dangerous because the practice builds a hub-and-spoke (or star) vulnerability network which exposes all the spoke websites to  weaknesses in the hub website.  Since active contents of 'bar.js' from the hub website in the example above is typically injected into every page served by spoke websites, penetration at the hub website allows hackers to change contents of all pages served by spoke websites instantly by replacing the content of 'bar.js' with their own script.

As to how wide spread the use of Voluntary XSS is, Google uses Voluntary XSS to display ads at Google AdSense sites and Technorati uses Voluntary XSS for blog claiming blogs.  I haven't checked Amazon and Yahoo yet, but I intend to soon.

Since this is a personal security alert, allow me to be more blunt than formal security alerts: This is serious shit folks.  By inserting those HTML fragments into your webpages, you are betting that websites hosting those HTML fragments are and will remain impenetrable.Voluntary XSS makes those key websites very attractive to hackers and I seriously doubt any website can withstand constant onslaughts by smart hackers.

My other posts on this topic:

Cross-Site Scripting Network

APWG Threat Advisory Alert on Visual Spoofing


Shark Tank: Well, d'oh!


Shark Tank: Well, d'oh! 08/11/2004 11:06 PM
This contractor pilot fish is a network tech at an Air Force base, and one of his jobs is forwarding and explaining status messages to users. In fact, he even gets to have fun with that part of the job.

D'oh! Petulance strikes


D'oh! Petulance strikes 03/14/2003 07:28 PM
Okay, so the last entry was a bit petulant. A virtual, albeit small, foot stomping snit. I shall, for the...

Security alert at Bute House


Security alert at Bute House 06/12/2004 04:49 AM
A security alert is sparked after a man is seen outside Jack McConnell's official home carrying what looked like a bomb.

Security Alert: PHPNuke Strikes Again


Security Alert: PHPNuke Strikes Again 02/04/2003 08:40 AM

Feds Alert to Web Security Threat


Feds Alert to Web Security Threat 03/21/2003 05:59 AM
The Department of Homeland Security advises Americans to brace themselves for acts of cyberterror. But computer security experts say Internet users probably aren't much more vulnerable than usual. By Joanna Glasner.

Single New Security Alert From Microsoft
For May


Single New Security Alert From Microsoft
For May
05/11/2004 01:44 PM
Windows XP/2003 Help system could execute attack code. In contrast to last month's flood of severe problems, a single "Important" vulnerability in some Windows versions, and re-released of two previous ones.

Community News: PHP Security Alert


Community News: PHP Security Alert 02/13/2004 09:13 AM
In a posting from the fine folks at PHP Magazine:

Gates sparks security alert


Gates sparks security alert 07/30/2004 06:26 AM

Free Sony PSP Alert Notification Service
& Price Watch For Consumers Launches


Free Sony PSP Alert Notification Service
& Price Watch For Consumers Launches
03/14/2005 05:55 PM
PSP4US Offers Help To Consumers Looking To Buy Sony’s Playstation Portable (PSP) Game Console. Sign Up For The PSP4US Alert Service So You Won’t Be Left Without A PSP. [PRWEB Feb 20, 2005]

BA Cancels 2d Flight Amid Security Alert


BA Cancels 2d Flight Amid Security Alert 01/02/2004 02:28 PM
Reuters via Wired News Jan 2 2004 1:08PM ET

Greenspan Sounds Alert on Social
Security (AP)


Greenspan Sounds Alert on Social
Security (AP)
08/28/2004 04:27 AM
AP - For at least the fourth time this year, Federal Reserve Chairman Alan Greenspan has touched the electrified third rail of American politics — Social Security.

Greenspan sounds alert on Social
Security


Greenspan sounds alert on Social
Security
08/29/2004 01:41 AM
Seattletimes.nwsource.com - Sun Aug 29, 02:57 am GMT

Community News: Security Alert from
Netcraft


Community News: Security Alert from
Netcraft
06/14/2004 08:06 AM
A security note issued from Netcraft should be noted this week:

BA Cancels U.S. Flight Amid Security
Alert


BA Cancels U.S. Flight Amid Security
Alert
01/02/2004 07:22 PM
Reuters via Wired News Jan 2 2004 6:44PM ET

Security alert identifies Oracle holes


Security alert identifies Oracle holes 09/03/2004 06:48 AM
Computer Weekly Sep 3 2004 11:14AM GMT

Hoax alert prompts security call


Hoax alert prompts security call 09/05/2004 11:16 AM
Residents of a County Antrim estate call for increased security following a loyalist bomb threat.

Security at on-alert airports can take 5
hours to clear


Security at on-alert airports can take 5
hours to clear
01/08/2004 07:48 PM
Andrew Leonard has an op-ed on Salon today describing the amazingly baroque TSA-inspired "security" procedures in Mexico City last weekend, which created a multiple-day delay for thousands of fliers.
I like to travel. But I'm not looking forward to a future in which I need to get to the airport five hours ahead of departure to be sure I won't miss a flight, one in which I'm patted down from head to toe several times every time I try to board a plane, one in which I am constantly explaining every item in my luggage and every twist in my itinerary to hostile agents. I've had the chance to think about airline security a great deal over the past few days, and I'll tell you this: After being asked by one security guard to drink from a water bottle in my carry-on to prove that it wasn't acid or poison; after being interrogated by a U.S. customs agent who was suspicious at the number of books I had in my luggage; after the long lines, the hand inspections, the X-ray screenings, the near riots by enraged passengers, the uncertainty and the anxiety -- after all that, traveling to a foreign land, or even just across the state of California, doesn't seem quite so exotic or alluring anymore.
Link (Thanks, Kevin!)

Cisco issues wireless Lan security alert


Cisco issues wireless Lan security alert 12/04/2003 09:38 AM
vnunet.com Dec 4 2003 8:48AM ET

BA Cancels Second U.S. Flight Amid
Security Alert


BA Cancels Second U.S. Flight Amid
Security Alert
01/02/2004 02:28 PM
Reuters via Wired News Jan 2 2004 1:08PM ET

Security Alert: Bagle.X Worm Seeding in
Progress


Security Alert: Bagle.X Worm Seeding in
Progress
04/09/2004 03:58 PM
There is an apparent seeding of a new Bagle worm variant, Bagle.X, currently in progress. While this seeding appears to be progressing at a slow rate, previous versions of the Bagle worms have been seeded in a similar manner and have witnessed great success.

Re: [Fwd: Security Alert; possible
buffer overflow in all Mathopd versions]


Re: [Fwd: Security Alert; possible
buffer overflow in all Mathopd versions]
12/08/2003 02:13 PM
Peter Geissler (Dec 07 2003)

Security Alert: New Bagle.X Worm Variant
Detected


Security Alert: New Bagle.X Worm Variant
Detected
04/09/2004 03:58 PM
Bagle.X appears to be progressing slowly, but its seeding rate is consistent with previous Bagle versions that have witnessed great success.

Homeland Security Launches Cyber Alert
System


Homeland Security Launches Cyber Alert
System
01/29/2004 02:48 AM

Windows gamers targeted by Microsoft
security alert


Windows gamers targeted by Microsoft
security alert
06/09/2004 07:42 AM
PC Pro Jun 9 2004 12:23PM GMT

[Fwd: Security Alert; possible buffer
overflow in all Mathopd versions]


[Fwd: Security Alert; possible buffer
overflow in all Mathopd versions]
12/05/2003 01:53 PM
Gregor Lawatscheck (Dec 05 2003)
Grok Description matches for The MS 'friendly' security alert service - just say d'oh
GrokA matches for The MS 'friendly' security alert service - just say d'oh

The MS 'friendly' security alert service - just say d'oh

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Digital Performer 4
available for
pre-order

Darth Maul Will
Visit France In May

Han Shoots First
UK News: Clearance
Keyring

Cisco heads home
with Linksys buy

New ICANN chief open
to change

Yahoo seals Inktomi
deal

Sun reaches out to
JBoss

War Coverage in Your
Aggregator

[ESA-20030320-010]
Several
vulnerabilities in
the OpenSSL toolkit.

[RHSA-2003:088-01]
New kernel 2.2
packages fix
vulnerabilities

Microsoft Security
Bulletin MS03-009:
Flaw In ISA Server
DNS Intrusion
Detection Filter Can
Cause Denial Of
Service (331065)
(fwd)

[Sorcerer-spells]
GLIBC-SORCERER2003-0
3-20

Simple File Manager
.023

white_dune
0.22beta39
(Development)

PowerDNS daemon
2.9.7 (Development)

Cisco to Acquire
Linksys

A Summary of
Pythagorean Theology

The Agonist
You want proof? You
want a reason?

Iraq fires a SCUD?
Rock Library and
Memphis

Download NPR audio
files with Safari

X11 Beta 3 and iMic
problems

Register a MP3
streaming server
with JRendezvous

XJanitor.pl
intelligently runs
required maintenance
tasks

Using an iPod with a
Wallstreet Powerbook

3Com teams up with
Huawei

Only kidding? MS may
ship Longhorn server
after all

Un-american? (09:55
AM)

Chicago Tribune |
Media giant's rally
sponsorship raises
questions

The Sum of All Fears
- What you should
and shouldn't worry
about as we go to
war. By
Robert Wright

After the War
Massive explosion
rocks NASA

The Call to Peace.
wcnt - wav composer
not toilet

SourceForge.net
Spacewar
daixtrose
XExpress
Cygwin GNOME
Context-Aware
Experience Sampling

relaxng
ViewFolderSize v1.03
PictureViewer
v1.0.168

RandomScreen Delux
v3.10.1

Red Hat Strikes
Enterprise Linux
Deal with HP

Leg Lamps Dot Com
New Par and
Module::Scandeps

Elm ME+ Elm 2.4ME+
PL101 (25)

what is grok?