Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Random Thoughts On Security

November 13, 2009 By Michael Kavka Leave a Comment

Who thinks its funny that the day after Patch Tuesday, Windows 7 and Server 2008 R2 get hit with a zero day exploit that causes them to crash? Its one of those things that the timing seems suspect on. Obviously they knew about the exploit before hand, and had to confirm it before they would allow the world to know about it.

Well if you think about it, waiting till Wednesday, Microsoft basically about itself a full month to get the patch out there. Its a stall tactic. Now considering the flaw does not allow access to data, allow rooting of the OS, or anything worse than a crash, it isn’t as bad as it could be.

The whole thing that people don’t understand about an exploit like this, and say Malware that gets on your system is where the real hole is. The ultimate hole in any OS is the end user. They don’t want to hear that going to their favorite adult site is what is causing them to get infected with malicious software. They patch their system, they only go to sites they trust.

Now I do agree that holes in the OS such as the recently patched kernel flaw can cause a ton of problems. Still once that gets patched, you have less of a chance of a drive by infection. When your users go to unsavory sites, sites that do a ton of redirecting, or just sites that really are not maintained, they cause a much bigger problem.

Then there is the problem of pirated software. The funny thing about pirated software is it usually isn’t the software itself that has the malware in it, its the crack that does. Whether it is a key generator or a small file you change out, that little piece of code is what opens you up. Mind you I’m not saying that file sharing is bad. I’m not bashing bittorrent at all. In fact Bittorrent is very useful for getting legitimate Open Source software, such as Linux ISOs.

I’m also well aware of how expensive software is. The amount of profit Microsoft makes off of Office is insane, and it wouldn’t be pirated nearly as much of the price came down to a more manageable level. The thing is that there is reputable legal free software that can do most of what the expensive software does, without cracks or malicious software hiding inside of a crack. Open Office, Gimp, Linux, VLC, Audacity, and many more Open Source projects are really coming into their own.

The bottom line is no matter what we do, unless we are willing to take the time to properly educate our end users, I don’t care how much you harden your system, something will happen to it. Best to be prepared, and have a slew of tools ready. Oh, and some of the best of those tools, are Open Source and free.

Filed Under: Computers, Rants, Security, Software

Shecky Tweets for 2009-11-12

November 12, 2009 By Michael Kavka Leave a Comment

  • Windows Security Bug Revealed After Microsoft Patch Tuesday – http://shar.es/aypv6 #
  • Rogues FakeVimes and PrivacyCenter added to MSRT. #security #MSRT #
  • Apple updates Safari for security! #Safari #Apple #Security #
  • HP aims for networking cloud with 3Com buy – CNET News: #
  • Seven great (and free!) applications for Windows 7 http://blogs.zdnet.com/hardware/?p=6115 #
  • RT @threatpost: Sourcefire November Vulnerability Report | (Video) #
  • RT @threatpost: Twitter API Being Exploited by Drive By Malware | #
  • From @techradar – 20 essential free apps for your new Windows 7 PC http://techradar.com/648954 #
  • I really hate it when I go to a reputable site and some ad on their page tries to redirect me #WebOfTrust warns me at least so I can stop. #
  • RT @microsoftsubnet: Active Directory Integrated DNS Zones: #
  • RT @DDubie: RT @bcarlsonCIO: Facebook Tips: How to Stay Safe While Using Games and Apps #
  • RT @threatpost: RT @ryanaraine: @dennisf covers a microsoft presentation on security software at OWASP AppSec DC #
  • RT @TechRepublic: Windows kernel-mode vulnerability: Will it be the next Conficker? – http://tinyurl.com/yex3yxy #
  • RT @threatpost: MS Bracing For Malware Attacks From Embedded Fonts | #
  • @ldignan Unfortunately, McAfee should be prepared. That Scareware has been around for a long time and gets new variants every month. in reply to ldignan #

Powered by Twitter Tools

Filed Under: General Tagged With: General Thoughts, Tweets

Shecky Tweets for 2009-11-12

November 12, 2009 By Michael Kavka Leave a Comment

  • Windows Security Bug Revealed After Microsoft Patch Tuesday – http://shar.es/aypv6 #
  • Rogues FakeVimes and PrivacyCenter added to MSRT. #security #MSRT #
  • Apple updates Safari for security! #Safari #Apple #Security #
  • HP aims for networking cloud with 3Com buy – CNET News: #
  • Seven great (and free!) applications for Windows 7 http://blogs.zdnet.com/hardware/?p=6115 #
  • RT @threatpost: Sourcefire November Vulnerability Report | (Video) #
  • RT @threatpost: Twitter API Being Exploited by Drive By Malware | #
  • From @techradar – 20 essential free apps for your new Windows 7 PC http://techradar.com/648954 #
  • I really hate it when I go to a reputable site and some ad on their page tries to redirect me #WebOfTrust warns me at least so I can stop. #
  • RT @microsoftsubnet: Active Directory Integrated DNS Zones: #
  • RT @DDubie: RT @bcarlsonCIO: Facebook Tips: How to Stay Safe While Using Games and Apps #
  • RT @threatpost: RT @ryanaraine: @dennisf covers a microsoft presentation on security software at OWASP AppSec DC #
  • RT @TechRepublic: Windows kernel-mode vulnerability: Will it be the next Conficker? – http://tinyurl.com/yex3yxy #
  • RT @threatpost: MS Bracing For Malware Attacks From Embedded Fonts | #
  • @ldignan Unfortunately, McAfee should be prepared. That Scareware has been around for a long time and gets new variants every month. in reply to ldignan #

Powered by Twitter Tools

Filed Under: General Tagged With: General Thoughts, Tweets

  • « Previous Page
  • 1
  • …
  • 187
  • 188
  • 189
  • 190
  • 191
  • …
  • 248
  • Next Page »

RSS Taggart Institute Intel Feed

  • Are You Protecting Yourself from Deepfakes? Take This Quick Quiz. October 27, 2025 Shanan Winters
  • Losing the Swing States October 27, 2025 Richard Fontaine
  • UN Cybercrime Treaty wins dozens of signatories, to go with its many critics October 27, 2025 Simon Sharwood
  • Uncovering Qilin attack methods exposed through multiple cases October 27, 2025 Takahiro Takeda
  • ISC Stormcast For Monday, October 27th, 2025 https://isc.sans.edu/podcastdetail/9672, (Mon, Oct 27th) October 27, 2025
  • Shaq's new ride gets jaq'ed in haq attaq October 26, 2025 Brandon Vigliarolo
  • The Kavanaugh stop, 50 days later October 26, 2025 Chris Geidner
  • Kaitai Struct WebIDE, (Sun, Oct 26th) October 26, 2025
  • Hackers steal Discord accounts with RedTiger-based infostealer October 26, 2025 Bill Toulas
  • [REVIVE-SA-2025-002] Revive Adserver Vulnerability October 26, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP