Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Black (Patch) Tuesday…

June 10, 2009 By Michael Kavka Leave a Comment

Ahh yes, the second Tuesday of the month and Microsoft releases patches. This month is a big month for it again with 10 patches, 6 of them marked as critical. So what do we have patched this time?

1) Active Directory. It seems that there are holes in Active Directory’s security that can allow remote code execution. Definitely do some testing on this patch, but try to roll it out as quickly as possible. This does affect 2000, 2003, and XP

2) Print Spooler. A patch that closes up 3 vulnerabilities that could allow remote code execution. Another one that should be rolled out as quickly as possible. I have not heard of code in the wild on this, but you know how quickly people will jump on such a critical system hole.

3) Internet Explorer. Big surprise here as IE seems to get a patch at least every other month. Considering that Microsoft was able to compromise Firefox’s security with a .Net add on for it, the holes in IE need to get patched up as quickly as possible.

4) Word, Excell, Works. I hope you aren’t using Works, but with Word and Excel, test these and then deploy, even though they are marked as critical.

Those are the Critical’s as decided by Microsoft. Interestingly the Direct X vulnerability, which does have code exploiting it in the wild, has no patch whatsoever, and no sign that Microsoft is going to patch that hole anytime soon. Again a concern where Microsoft is concerned, but not surprising considering the amount of resources working on Windows 7, and the amount of reported vulnerabilities Microsoft must receive every month. More information on the Microsoft patches can be found here.

Also, Adobe released a patch to address a number of vulnerabilities that have been found in its Acrobat Reader. Information on that can be found here.

Yep, a busy Patch Tuesday, so go get them, test em, and deploy em. And if you find a problem with any of the patches, or caused by them, let me know.

Filed Under: Computers, Security, Software Tagged With: Active Directory, Active Directory Patch, Adobe Reader, Excel, Microsoft Patches, Patch Tuesday, Patches, Print Spooler, Security, Security Patches, vulnerabilities, Work, Works

Thanks Microsoft

May 15, 2009 By Michael Kavka Leave a Comment

So, in the midst of not writing too much this week, I’ve had a lot of headaches. Headaches that you can avoid.

Headache number one. Always do a daily check of backups. Make sure that everything including SQL databases are being backed up properly. If they aren’t, find a way to remedy that.

Headache number two, SQL 2005. Yes SQL works nicely, but when you have people who insist on using the Eval version past its 120 period, upgrading them to the full version is a pain. One that Microsoft can fix by not forcing an uninstall of the eval and install of the full version. Oh and double check all backups before you do the uninstall.

Headache number three, Windows updates and Symantec Endpoint. I have hit this one a few times this week, where Windows Update goes into a weird connection and install loop for a patch and can’t install it so keeps retrying to the point that Symantec Endpoint 11 things the server is under a DoS attack. Course this eventually led to other issues that required a reboot of the servers in question, so they worked properly again. Well two of them did, the third one led to…

Headache number 4, ease of finding information from Microsoft. Yes, Technet, and Google are nice items, but when one puts in a search about corrupted exchange log E00, you would think that you would get all the info or at least KB articles that offer solutions for it. This is not the case. It took about 100 different search strings along the exact same parameter, with a small change here, small change there to words or order, to finally find the missing step to bring back up a clients exchange information stores.

Yeah, its been a busy week, but at least there are lessons to be learned. The biggest one is that Microsoft is painful.

Filed Under: Computers, Rants, Software Tagged With: Exchange 2003, Exchange 2007, Exchange Backup, Exchange E00 log, Microsoft, Patches, SQL 2005, SQL 2005 Evaluation, SQL Backup, Symantec Endpoint Protection, Windows Update Services

Windows 7 RC Critical Patch

May 11, 2009 By Michael Kavka Leave a Comment

Days after the Windows 7 Release Candidate becomes available, Microsoft has to send out a critical patch. Now it only affects the 32 bit version, and honestly, I think that Microsoft is stupid to make a 32 bit version. All the processors on new machines can support 64 bit, so why not use it.

Anyway, the issue comes in with how ACL lists are handled. You can read more about it here.

Also, on Windows 7 RC patches, in the next week there will be a bunch of fake patches sent out by Microsoft that do nothing. Well, nothing but test the updating system, which is somewhat important. Make sure to use these for testing the system.

Filed Under: Security, Software Tagged With: Microsoft, Patches, RC Testing, Security, Windows 7

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • Next Page »

RSS Taggart Institute Intel Feed

  • From sizzle to drizzle to fizzle: The massive data leak that wasn’t October 12, 2025 Dissent
  • Fake 'Inflation Refund' texts target New Yorkers in new scam October 12, 2025 Lawrence Abrams
  • Aselsan brings in dozens of companies and systems under the Steel Dome umbrella October 12, 2025 Damian Kemp
  • Wireshark 4.4.10 and 4.6.0 Released, (Sun, Oct 12th) October 12, 2025
  • In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. October 11, 2025 Dissent
  • They were victims of a massive data breach in 2009. Interior Health denied it for a decade. October 11, 2025 Dissent
  • Spain dismantles “GXC Team” cybercrime syndicate, arrests leader October 11, 2025 Bill Toulas
  • Mole-Rats Could Hold the Key to Living Longer October 11, 2025 Becky Ferreira
  • Acting US Cyber Command, NSA chief won’t be nominated for the job, sources say October 11, 2025
  • Prosecutors seek 7-year prison term for ‘sophisticated’ PowerSchool hacker October 10, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP