Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Out of Band Patches this week

July 27, 2009 By Michael Kavka Leave a Comment

So it seems that a few vulnerabilities have rated out of band patches from Microsoft. One for Visual Studio and one for Internet Explorer. while they are not releasing the details of the patches yet, I”ll bet the IE one is to patch the drive by downloads that have been happening lately.

Read the information here.

I always find it interesting as to what Microsoft considers important enough to do an out of band patch. Last year one was to close up the hole that Cornficker used. Sometimes it seems that they should issue one and they don’t. Maybe someday we will understand the madness to their decisions.

Filed Under: General Tagged With: Internet Explorer, Microsoft, Out of Band, Patches, Security, Visual Studio

Patch Tuesday for July

July 15, 2009 By Michael Kavka Leave a Comment

Yep, that’s right, its that time of month where Microsoft’s servers get slammed. Its patch week.

This month some patches for holes that have Zero Day Exploits out for them already. Included in this is the Active X Video Hole, The Direct X Quicktime Hole, and the Open Type Font hole. The first two I had talked about when they came out, with the Direct X hole being the one that it looked like Microsoft had no serious plans of patching. Nice to be proven wrong.

There is no fix this month for Office Web components, which have recently come under attack. I expect this fix is being worked on and will be out soon. Considering the move to the cloud that people talk about, and that Office Web competes with Google Documents, they do need to secure it.

As always, I do recommend paying attention when you patch as one reader pointed out, you can choose not to install IE8, which still comes down as a critical patch, unless you download it and then stop the install of it, or tell the updater to hide the download of it. Yeah, its a pain, and unfortunately the everyday end user who we tell to make sure they install critical patches will still inadvertently install the sucker, we can at least try to educate them a little and not make the same mistake ourselves.

Filed Under: Computers, Reviews, Security, Software Tagged With: Active X Video, Direct X, Microsoft, Patch Tuesday, Patches, Quicktime, Security

And the pain of Automagical Updates

June 18, 2009 By Michael Kavka 1 Comment

Before I get started let me say this, I believe in patching, and updating systems and software. It is essential to security fo a system.

That being said, there is something to be said about forcing updated software by calling it a high priority update. Yep, I’m talking about IE8 yet again. Don’t get me wrong, I’ve used it, and for general web browsing, it is ok, although a lot of sites still seem broken when using it.Some of it is because of the higher security settings built into IE8 the rest because a lot of sites are not optimized for IE8 yet.

The problem is that it is listed as a high priority update, and if you have a machine set to automatically install critical updates, it gets automatically installed on your machine. This is totally against the statement from Microsoft that IE8 is optional. The non-tech person does not know to check, nor is expected to know how to decline the installation of something like IE8. All of a sudden this is costing my clients money, due to the fact that they have to pay me to remove IE8 and then reinstall IE7 on their machine.

Yeah, its nice for my revenu, but it makes the IT world look bad overall. Clients jsut want things to work, and I can’t blame them on that. I just want things to work also. Microsoft doesn’t seem to care about anything except market share and money, and with more and more viable options coming out, they better start learning that reputation means everything, and properly working software is the way to get more market share and money.

Filed Under: Computers, Rants, Software Tagged With: Automatic Updates, High Priority Updates, IE8, Patches, Patching, Security

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • …
  • 6
  • Next Page »

RSS Taggart Institute Intel Feed

  • From sizzle to drizzle to fizzle: The massive data leak that wasn’t October 12, 2025 Dissent
  • Fake 'Inflation Refund' texts target New Yorkers in new scam October 12, 2025 Lawrence Abrams
  • Aselsan brings in dozens of companies and systems under the Steel Dome umbrella October 12, 2025 Damian Kemp
  • Wireshark 4.4.10 and 4.6.0 Released, (Sun, Oct 12th) October 12, 2025
  • In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. October 11, 2025 Dissent
  • They were victims of a massive data breach in 2009. Interior Health denied it for a decade. October 11, 2025 Dissent
  • Spain dismantles “GXC Team” cybercrime syndicate, arrests leader October 11, 2025 Bill Toulas
  • Mole-Rats Could Hold the Key to Living Longer October 11, 2025 Becky Ferreira
  • Acting US Cyber Command, NSA chief won’t be nominated for the job, sources say October 11, 2025
  • Prosecutors seek 7-year prison term for ‘sophisticated’ PowerSchool hacker October 10, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP