<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacybrowser</title>
	<atom:link href="http://hijack-this.co.uk/category/browser/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:31:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Misleading Google adverts</title>
		<link>http://hijack-this.co.uk/2010/06/misleading-google-adverts/</link>
		<comments>http://hijack-this.co.uk/2010/06/misleading-google-adverts/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 13:15:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=298</guid>
		<description><![CDATA[Many of us in the security community are concerned about misleading adverts. This one in particular has started to make waves within the wider Technical support community. It is frequently displayed on blogs &#38; forums offering free technical support and appears designed to fool a user into thinking that they are getting Microsoft Technical Support, [...]]]></description>
			<content:encoded><![CDATA[<p><br />
Many of us in the security community are concerned about misleading adverts. This one in particular has started to make waves within the wider Technical support community. It is frequently displayed on blogs &amp; forums offering free technical support and appears designed to fool a user into thinking that they are getting Microsoft Technical Support, when in fact the link goes to a site that makes you pay for help and assistance  that has absolutely no connection to Microsoft as a company<br />
The advert below is the one in question. Click on it to get a full size image<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers.png"></a></p>
<p style="text-align: center;"><a href="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers.png"><img class="size-medium wp-image-299 aligncenter" title="answers" src="http://hijack-this.co.uk/wp-content/uploads/2010/06/answers-300x36.png" alt="" width="300" height="36" /></a></p>
<p>We all understand that adverts are a necessity in todays world to defray costs in running a website and an occasional rogue or misleading advert will slip through. I use Google adsense here on this blog and hope that all the adverts will be honest and above board. All webmasters, blog owners and Forums admins do need to keep an eye open for such adverts. Google must take a high degree of responsibility and start to police its advertising system more closely and weed out these deliberately misleading adverts.</p>
<p>The Company Justanswer.com who publish the adverts should be ashamed of themselves and I ask all readers to avoid that company and any others that use such underhand tactics to drive vulnerable visitors to their site.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/06/misleading-google-adverts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue:</title>
		<link>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/</link>
		<comments>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 07:18:34 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=291</guid>
		<description><![CDATA[The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue: http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx Hi everyone, On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then [...]]]></description>
			<content:encoded><![CDATA[<p>The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue:</p>
<p><a href="http://" target="_blank">http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx</a></p>
<p>Hi everyone,<br />
On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box. We are not aware of any attacks seeking to exploit this issue at this time and in the current state of our investigation, we have determined that users running Windows 7, Windows Server 2008 R2, Windows Server 2008, and Windows Vista, are not affected by this issue.<span id="more-291"></span></p>
<p>The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system. To help customers better understand unsafe file types, we have published a white paper on the topic which you can find by clicking this link.<br />
Once we have completed our investigation, we will take appropriate action to protect customers. To minimize risk to computer users, Microsoft continues to encourage responsible disclosure. Reporting vulnerabilities directly to vendors without further disclosure helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of – and work to exploit – a vulnerability. Responsible disclosure protects the computer ecosystem and individual computer users from harm.<br />
Anyone believed to have been affected can visit: <a href="http://" target="_blank">http://www.microsoft.com/protect/support/default.mspx</a> and should contact the national law enforcement agency in their country. Those in the United States can contact Customer Service and Support at no charge (for computer security related issues) using the PC Safety hotline at 1-866-727-2338 (PCSAFETY). Customers outside of the United States can visit <a href="http://" target="_blank">http://support.microsoft.com/international</a> to find local support information.<br />
We continue to encourage customers to follow the “Protect Your Computer” guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. Additional information can be found at: <a href="http://" target="_blank">www.microsoft.com/protect</a>.<br />
We will provide more information on this issue as it becomes available.<br />
Thanks,<br />
Jerry Bryant<br />
Sr. Security Communications Manager Lead<br />
*This posting is provided &#8220;AS IS&#8221; with no warranties, and confers no rights.*</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE out of band patch</title>
		<link>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/</link>
		<comments>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 19:10:30 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/</guid>
		<description><![CDATA[This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack. The full [...]]]></description>
			<content:encoded><![CDATA[<p>This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.</p>
<p>The full version of the Microsoft Security Bulletin Advance Notification for this release can be found at  <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a>.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warning IE 0 day exploit</title>
		<link>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/</link>
		<comments>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 09:15:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/</guid>
		<description><![CDATA[http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/ http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/ http://www.microsoft.com/technet/security/advisory/979352.mspx I will  keep you posted when I hear more best advice at this time is make sure antivirus is updated to protect, watch where you surf &#38; consider an alternative browser or set IE protection to high However bear in mind these have all been targeted attacks against specific companies &#38; institutions [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/" target="_blank">http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/</a></p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/</a></p>
<p><a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" target="_blank">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></p>
<p>I will  keep you posted when I hear more</p>
<p>best advice at this time is make sure antivirus is updated to protect, watch where you surf &amp; consider an alternative browser or set IE protection to high</p>
<p>However bear in mind these have all been targeted attacks against specific companies &amp; institutions so less likely to affect the average user, at least until the skiddies get their hands on the exploit</p>
<p>OK if you are still using IE 6 or 7 on any version of windows</p>
<p>use the fixit Microsoft have issued <a href="http://support.microsoft.com/kb/979352" target="_blank">http://support.microsoft.com/kb/979352</a></p>
<p><strong>You do not need this fix if you are using Internet Explorer 8 on Windows XP Service Pack 3 (SP3) or on Windows Vista SP1 or later versions ( including Windows 7 ) . This is because Internet Explorer 8 opts-in to DEP by default on these platforms. </strong></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Issues Critical Updates To Flash, AIR &#8211; Security Watch</title>
		<link>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/</link>
		<comments>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 09:11:25 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=276</guid>
		<description><![CDATA[Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild. Click here to install Flash 10.0.42.34. Click here to install AIR 1.5.3. The expanded security advisory explains that critical [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild.</p>
<p><a href="http://get.adobe.com/flashplayer/" target="_blank">Click here to install Flash 10.0.42.34.</a></p>
<p><a href="http://get.adobe.com/air/" target="_blank">Click here to install AIR 1.5.3.</a></p>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_self">The expanded security advisory</a> explains that critical vulnerabilities could provoke crashes or remote code execution. Adobe Flash Player 10.0.32.18 and earlier versions and Adobe AIR 1.5.2 and earlier versions on all platforms are vulnerable.</p>
<p>7 new vulnerabilities are described cursorily. A patch to an eighth and older vulnerability is also updated. Adobe issues thanks to 6 different researchers for the help they provided with the vulnerabilities.</p>
<p>The advisory also adds that Flash Player version 10.1, which Adobe expects to release in the first half of 2010, will be the last to support PowerPC-based G3 Macs. They are discontinuing support, including security updates, past that version because they are implementing performance enhancements not supported in those processors.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of fake shopping sites</title>
		<link>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/</link>
		<comments>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 10:55:16 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=261</guid>
		<description><![CDATA[With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &#38; credit card details. A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can [...]]]></description>
			<content:encoded><![CDATA[<p><br />
With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &amp; credit card details.</p>
<p>A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can be sure that thousands of people have and the same scam will be applied to just about every well known online shopping site this season.</p>
<p>The email looks quite believable<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email.PNG"><img class="alignnone size-medium wp-image-262" title="littlewoods_email" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email-300x258.PNG" alt="littlewoods_email" width="300" height="258" /></a></p>
<p>The website if you follow the link looks exactly like the real Littlwoods shopping site Account sign in page <strong>EXCEPT</strong> that the real Littlewwoods or ALL reputable shopping sites will have a Padlock icon and the  site address will start with<strong> HTTPS</strong> and the address bar will turn green to show that you are on a secure site</p>
<p>This screenshot shows the fake site and I have blanked out the address for safety reasons<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web.PNG"><img class="alignnone size-medium wp-image-263" title="littlewoods_web" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web-300x231.PNG" alt="littlewoods_web" width="300" height="231" /></a></p>
<p>These show how a genuine site will appear in Internet Explorer 8 on left and Firefox on right. Both show the padlock icon and a green safe address bar. A genuine shopping site will always start <strong>HTTPS</strong> to show a secure site when you are asked to put in any details. The front page of the site might be a normal http:<br />
Unfortunately a lot of well known shopping sites haven&#8217;t yet signed up to the Extended Valuation green bar very secure system yet so watch for the closed padlock and HTTPS in the address bar to show a secure site. In Firefox browser the closed padlock is on the bottom right hand corner of the page, not in the browser address bar </p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE.PNG"><img class="alignnone size-medium wp-image-264" title="littlewoods_IE" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE-300x193.PNG" alt="littlewoods_IE" width="300" height="193" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods.PNG"><img class="alignnone size-medium wp-image-265" title="real_littlewoods" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods-300x232.PNG" alt="real_littlewoods" width="300" height="232" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
By the time  your rss reader get this post here is <strong> 2 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Advisory 977544 vulnerability affecting SMB Protocol</title>
		<link>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/</link>
		<comments>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 10:08:56 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=219</guid>
		<description><![CDATA[Microsoft Security Advisory 977544 Released Today Microsoft released Security Advisory 977544 to provide information, including customer guidance, on a publicly reported Denial-of-Service (DoS) vulnerability affecting Server Messaging Block (SMB) Protocol. This vulnerability, in SMBv1 and SMBv2, affects  Windows 7 and Windows Server 2008 R2. Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and [...]]]></description>
			<content:encoded><![CDATA[<h2>Microsoft Security Advisory 977544 Released</h2>
<p>Today Microsoft released <a href="http://www.microsoft.com/technet/security/advisory/977544.mspx">Security Advisory 977544</a> to provide information, including customer guidance, on a publicly reported Denial-of-Service (DoS) vulnerability affecting Server Messaging Block (SMB) Protocol. This vulnerability, in SMBv1 and SMBv2, affects  Windows 7 and Windows Server 2008 R2. Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and Windows 2000 are not affected.</p>
<p>It needs to be made  clear that this is a DoS vulnerability that is unrelated to Microsoft Security Bulletin <a href="http://go.microsoft.com/fwlink/?LinkId=163970">MS09-050</a> which addressed a remote code execution vulnerability in the SMBv2 protocol. This vulnerability would not allow an attacker to take control or install malware on a user’s system, but could cause the affected system to stop responding until manually restarted.</p>
<p><a href="http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx">http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx</a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sun Java Runtime Environment Multiple Vulnerabilities</title>
		<link>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/</link>
		<comments>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 11:54:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=210</guid>
		<description><![CDATA[Sun Java Runtime Environment Multiple Vulnerabilities Affected: JDK and JRE 6 Update 16 and earlier JDK and JRE 5.0 Update 21 and earlier SDK and JRE 1.4.2_23 and earlier SDK and JRE 1.3.1_26 and earlier Description: Sun&#8217;s implementation of the Java Runtime Environment (JRE) and Java Web Start contains multiple vulnerabilities. A specially crafted Java [...]]]></description>
			<content:encoded><![CDATA[<p>Sun Java Runtime Environment Multiple Vulnerabilities<br />
Affected:<br />
JDK and JRE 6 Update 16 and earlier<br />
JDK and JRE 5.0 Update 21 and earlier<br />
SDK and JRE 1.4.2_23 and earlier<br />
SDK and JRE 1.3.1_26 and earlier</p>
<p>Description: Sun&#8217;s implementation of the Java Runtime Environment (JRE) and Java Web Start contains multiple vulnerabilities. A specially crafted Java application, an audio or image file or an applet could trigger one of these vulnerabilities, with consequences ranging from arbitrary code execution with the privileges of the current user to denials-of-service and security restriction bypass. Note that, depending upon configuration, Java applets embedded in web pages may be opened automatically upon the loading of the page. One of the error is that the update mechanism does not update JRE to the new version when running on non-English Windows versions. There are errors in decoding DER encoded data and the parsing of HTTP headers which might lead to memory exhaustion. There is an authentication bypass vulnerability in JRE while verifying HMAC digests. Multiple buffer overflow and integer overflow vulnerabilities have been reported in JRE while processing specially crafted audio and image files. There is a command execution vulnerability in JRE which could be triggered by a specially crafted web page. There is a flaw in the implementation of security model permissions in the Java Web Start Installer. Some technical details for some of these vulnerabilities are publicly available.</p>
<p>Status: Vendor not confirmed, no updates available. [edit] Updates are available</p>
<p>References:<br />
Zero Day Initiative Advisories<br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-076">http://www.zerodayinitiative.com/advisories/ZDI-09-076</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-077">http://www.zerodayinitiative.com/advisories/ZDI-09-077</a><br />
 <a href="http://www.zerodayinitiative.com/advisories/ZDI-09-078">http://www.zerodayinitiative.com/advisories/ZDI-09-078</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-079">http://www.zerodayinitiative.com/advisories/ZDI-09-079</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-080">http://www.zerodayinitiative.com/advisories/ZDI-09-080</a><br />
Sun Security Advisories<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1</a><br />
Product Home Page<br />
<a href="http://java.sun.com">http://java.sun.com</a><br />
SecurityFocus BID<br />
<a href="http://www.securityfocus.com/bid/36881">http://www.securityfocus.com/bid/36881</a></p>
<p>for this DO NOT rely on check for updates in JAVA control panel BUT go to <a href="http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80">http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80</a></p>
<p>if you have a 64 bit version of windows, you need to install the standard 32 bit version AND the 64 bit version <a href="http://java.com/en/download/manual.jsp">http://java.com/en/download/manual.jsp</a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Shockwave Player Multiple Vulnerabilities</title>
		<link>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/</link>
		<comments>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 08:28:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=204</guid>
		<description><![CDATA[ Affected: Adobe Shockwave Player versions 11.x Description: Adobe Shockwave Player, with over 450 million users, is a multimedia player that allows Adobe Director applications to be published and viewed by a browser that is installed with a Shockwave plug-in.  Multiple vulnerabilities have been reported in Adobe Shockwave Player, which be triggered by a specially crafted [...]]]></description>
			<content:encoded><![CDATA[<p> Affected: Adobe Shockwave Player versions 11.x</p>
<p>Description: Adobe Shockwave Player, with over 450 million users, is a multimedia player that allows Adobe Director applications to be published and viewed by a browser that is installed with a Shockwave plug-in.</p>
<p> Multiple vulnerabilities have been reported in Adobe Shockwave Player, which be triggered by a specially crafted Shockwave content.  There is a error in the way the invalid index is used.  There are also a couple of issues caused by the inappropriate use of the invalid pointer.  And the last issue is a memory corruption error when processing string lengths.</p>
<p> In all the cases successful exploitation might allow an attacker to execute arbitrary code in the context of the logged on user.</p>
<p>There is not enough public information about these vulnerabilities.</p>
<p>Status: Vendor confirmed, updates available.</p>
<p>References:</p>
<p> Adobe Security Bulletin (APSB09-16)  <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">http://www.adobe.com/support/security/bulletins/apsb09-16.html</a></p>
<p>Wikipedia Article on Adobe Shockwave  <a href="http://en.wikipedia.org/wiki/">http://en.wikipedia.org/wiki/</a></p>
<p>Adobe_Shockwave Product Home Page  <a href="http://www.adobe.com/products/shockwaveplayer/">http://www.adobe.com/products/shockwaveplayer/</a></p>
<p> SecurityFocus BID <a href="http://www.securityfocus.com/bid/36905">http://www.securityfocus.com/bid/36905</a></p>
<p><strong>Adobe recommends Shockwave Player users install Shockwave Player version 11.5.2.602 available here: </strong><a href="http://get.adobe.com/shockwave/"><strong>http://get.adobe.com/shockwave/</strong></a><br />
Remember: You need to install shockwave in Every Browser you use separately, if you wish to use it in your browser</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla fixes 16 flaws with Firefox 3.5.4:</title>
		<link>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/</link>
		<comments>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 06:47:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=196</guid>
		<description><![CDATA[http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4 Mozilla fixes 16 flaws with Firefox 3.5.4: http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4  Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4.   The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4">http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4</a></p>
<p>Mozilla fixes 16 flaws with Firefox 3.5.4:</p>
<p><a href="http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4">http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4</a></p>
<p> Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4. </p>
<p> The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a trio of third-party media libraries, and both the JavaScript and browser engines.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
