<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>geek scrap &#187; microsoft</title>
	<atom:link href="http://geekscrap.com/tags/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://geekscrap.com</link>
	<description>there is at least one way to do it</description>
	<lastBuildDate>Tue, 12 Apr 2011 10:14:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Top 25 vulnerability RSS feeds</title>
		<link>http://geekscrap.com/2010/02/top-25-vulnerability-rss-feeds/</link>
		<comments>http://geekscrap.com/2010/02/top-25-vulnerability-rss-feeds/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 08:00:11 +0000</pubDate>
		<dc:creator>geekscrap</dc:creator>
				<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[checkpoint]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[feed]]></category>
		<category><![CDATA[gentoo]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[opml]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[securityfocus]]></category>
		<category><![CDATA[solaris]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://geekscrap.com/?p=702</guid>
		<description><![CDATA[One way to receive up-to-date reports about vulnerability issues is subscribing to vulnerability RSS feeds: they update on demand, they don&#8217;t rely on your mail subsystem and they don&#8217;t fill up your mailbox. The only drawback is that you could miss alerts if you don&#8217;t sync your feeds for a long time, but if you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p>One way to receive up-to-date reports about vulnerability issues is subscribing to vulnerability RSS feeds: they update <em>on demand</em>, they don&#8217;t rely on your mail subsystem and they don&#8217;t fill up your mailbox. The only drawback is that you could miss alerts if you don&#8217;t sync your feeds for a long time, but if you&#8217;re a IT security manager, you don&#8217;t have a life, so how could it happen anyways? <img src='http://geekscrap.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Here&#8217;s the top feeds you should be subscribed to (<a rel="nofollow" href="http://cve.mitre.org/">CVE</a> tags are reported in brackets):</p>
<ol>
<li><a rel="nofollow" href="http://nvd.nist.gov/download/nvd-rss.xml">NIST Vulnerability Database</a>.</li>
<li><a href="http://www.us-cert.gov/channels/techalerts.rdf">US Cert Technical Security Alerts</a> [CERT].</li>
<li><a href="http://www.securityfocus.com/rss/vulnerabilities.xml">SecurityFocus Vulnerabilities</a> [SF-INCIDENTS].</li>
<li><a rel="nofollow" href="http://osvdb.org/feed/vulnerabilities/latest.rss">Open Source Vulnerability Database</a> [OSVDB].</li>
<li><a rel="nofollow" href="http://www.iss.net/rss.php">IBM Internet Security Systems Threats</a> [ISS].</li>
<li><a rel="nofollow" href="http://www.vupen.com/security-advisories.xml">Vupen Security Advisories</a> [VUPEN].</li>
<li><a rel="nofollow" href="http://secunia.tumblr.com/rss">Secunia Latest Security Advisories</a> (Unofficial) [SECUNIA].</li>
<li><a rel="nofollow" href="http://research.eeye.com/rss/published.rss">eEye Security Advisories</a> [EEYE].</li>
</ol>
<p>The above list is also available as <a href="http://geekscrap.com/wp-content/uploads/2010/02/Security-Advisories.opml">OPML file</a> you can import into your feed reader.</p>
<p><span id="more-702"></span>Furthermore, you should subscribe to Operating Systems product-centric vulnerability feeds to ensure you receive timely information regarding updated packages and suggested workarounds for your infrastructure. Here&#8217;s a comprehensive list, sorted alphabetically:</p>
<ol>
<li><a rel="nofollow" href="http://rss.lists.apple.com/security-announce.rss">Apple Security Announce</a> (Mac OS X, iPhone, etc) [APPLE].</li>
<li>Checkpoint&#8217;s <a href="http://www.checkpoint.com/defense/advisories/public/smartdefense_atomz.xml">SmartDefense Service</a> [CHECKPOINT].</li>
<li><a rel="nofollow" href="http://newsroom.cisco.com/data/syndication/rss2/SecurityAdvisories_20.xml">Cisco&#8217;s Product &amp; Service Security Advisories</a> [CISCO].</li>
<li><a rel="nofollow" href="http://www.debian.org/security/dsa-long">Debian Security Advisories</a> [DEBIAN].</li>
<li><a rel="nofollow" href="https://admin.fedoraproject.org/updates/rss/rss2.0?type=security">Fedora Security Updates</a> [FEDORA].</li>
<li><a rel="nofollow" href="http://www.freebsd.org/security/rss.xml">FreeBSD Security Advisories</a> [FREEBSD].</li>
<li><a rel="nofollow" href="http://www.gentoo.org/rdf/en/glsa-index.rdf">Gentoo Linux Security Advisories</a> (GLSA) [GENTOO].</li>
<li><a rel="nofollow" href="http://www.mandriva.com/rss/feed/security">Mandriva Security Advisories</a> [MANDRIVA].</li>
<li>Microsoft&#8217;s <a rel="nofollow" href="http://www.microsoft.com/technet/security/bulletin/RssFeed.aspx?snscomprehensive">Security Notification Service Comprehensive Edition</a> [MS].</li>
<li><a rel="nofollow" href="http://www.NetBSD.org/support/security/rss-advisories.xml">NetBSD Security Advisories</a> [NETBSD].</li>
<li><a rel="nofollow" href="http://www.openpkg.com/security/advisories/?format=rss">OpenPKG Security Advisories</a> [OPENPKG].</li>
<li><a rel="nofollow" href="http://www.undeadly.org/cgi?action=errata">OpenBSD Errata</a> [OPENBSD].</li>
<li><a rel="nofollow" href="https://rhn.redhat.com/rpc/recent-errata.pxt">Red Hat Security Advisories</a> [REDHAT].</li>
<li><a href="http://dev.slackware.it/rss/slackware-security.xml">Slackware Linux Security Advisories</a> [SLACKWARE].</li>
<li><a rel="nofollow" href="http://search.sun.com/feed/atom/results.jsp?col=main-support-sunalerts&amp;oneof=security&amp;nh=30&amp;rf=1&amp;type=advanced&amp;optstat=true&amp;qt=security&amp;reslang=en&amp;st=1">Solaris SunSolve Alerts</a> [SUNALERT].</li>
<li><a rel="nofollow" href="http://www.novell.com/linux/security/suse_security.xml">SUSE Linux Enterprise Security Advisories</a> (also contains OpenSUSE advisories) [SUSE].</li>
<li><a rel="nofollow" href="http://www.ubuntu.com/usn/rss.xml">Ubuntu Security Notices</a> [UBUNTU].</li>
</ol>
<p>OS security advisory feeds are available as <a href="http://geekscrap.com/wp-content/uploads/2010/02/Security-Advisories1.opml">OPML file</a> as well.</p>
<p>Have I missed anything? Please report if you find some advisory feed I accidentally missed. Also, if you&#8217;re into an Operating System security team and you don&#8217;t offer a security announcement feed, please consider making it available.</p>
]]></content:encoded>
			<wfw:commentRss>http://geekscrap.com/2010/02/top-25-vulnerability-rss-feeds/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Microsoft hotfix tale</title>
		<link>http://geekscrap.com/2010/02/the-microsoft-hotfix-tale/</link>
		<comments>http://geekscrap.com/2010/02/the-microsoft-hotfix-tale/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 08:30:20 +0000</pubDate>
		<dc:creator>geekscrap</dc:creator>
				<category><![CDATA[Rants]]></category>
		<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[q819536]]></category>
		<category><![CDATA[roaming profiles]]></category>
		<category><![CDATA[vbscript]]></category>
		<category><![CDATA[windows 2000]]></category>

		<guid isPermaLink="false">http://geekscrap.com/?p=486</guid>
		<description><![CDATA[A few people on Earth still have a Windows 2000 machine laying around in their lab, mostly schools with severe budget cuts. Some time ago, one of these retro labs had a problem with roaming profiles: apparently Windows 2000 desktop machines refused to sync their profile on logoff. A collegue of mine asked my help [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.w3schools.com/browsers/browsers_os.asp">few people</a> on Earth still have a Windows 2000 machine laying around in their lab, mostly schools with severe budget cuts. Some time ago, one of these retro labs had a problem with <em>roaming profiles</em>: apparently Windows 2000 desktop machines refused to sync their profile on logoff. A collegue of mine asked my help to try and fix the issue, so I started debugging user environment using <a href="http://support.microsoft.com/kb/221833">the classic procedure</a>.</p>
<p>What I found out was that machines were configured to access netlogon share and run a VBScript script upon logon, to set a few things like printing shares and stuff like that. Unluckily, Windows 2000 has a problem with this, because if VBScript instantiates a WMI object and uses it to read registry keys, then WMI object is not released correctly and this locks the registry hive and therefore Windows logoff sync aborts after a long wait.</p>
<p><span id="more-486"></span>The problem is known to Microsoft and a report on the issue is published at KB <a href="http://support.microsoft.com/kb/819536">819536</a>. Now since this lab is located in Italy and and Windows 2000 is localized in italian, Microsoft Knowledge Base site opened in Italian and the page with the bug report mentioned that an hotfix was available but one should call Microsoft support service at no charge to receive it, no link to download the file or anything. So my collegue looked up Microsoft Italia phone number and called up:</p>
<blockquote><p><strong>Sysadmin</strong>: «Hello, I have a problem with a Windows 2000 workstation and I need a hotfix.»<br />
<strong> Microsoft female voice</strong>: «Ok, so I need to open a support case and have someone from the staff call you back.»<br />
<strong> Sysadmin</strong>: «Ok.»<br />
<strong> Microsoft female voice</strong>: «Is your workstation stand-alone or in a domain?»<br />
<strong> Sysadmin</strong>: «Domain.» (it was a samba domain, but better not tell.)<br />
<strong> Microsoft female voice</strong>: «Ok, listen, your machine is NOT in a domain.»<br />
<strong> Sysadmin</strong>: «Uh?»<br />
<strong> Microsoft female voice</strong>: «Look, if I open a enterprise support request for machines in a domain, you have to pay € 299, while if you request a stand-alone support call, it costs you just € 79.»<br />
<strong> Sysadmin</strong>: «Erm&#8230;Your website states that hotfixes are free, aren&#8217;t they?»<br />
<strong> Microsoft female voice</strong>: «Possibly, but just in case you need further help, your fee will be lower.»<br />
<strong> Sysadmin</strong>: «Err&#8230;ok&#8230;nice.» (these Microsoft employees must be really fed up working for the devil himself.)<br />
<strong> Microsoft female voice</strong>: «So, now I need your phone number and your credit card details&#8230;»</p></blockquote>
<p>After one hour we received a call from a guy at their support team. We explained him what we needed and he told us that hotfix was free and we would not pay anything. Then he sent the hotfix over via e-mail. The hotfix worked perfectly and replaced <em>C:\WINDOWS\system32\wbem\stdprov.dll</em> version <em>1.50.1085.104</em> with version <em>1.50.1085.105</em>.</p>
<p>In the hotfix e-mail he also <a href="http://geekscrap.com/wp-content/uploads/2010/02/SRX1118808598ID-Win-2000-pro-_-the-customer-requested_-hotfix-819536.txt">dropped a note</a> saying that Windows 2000 is not supported anymore and therefore hotfixes that are not security-related are not available anymore to customers (he sent the hotfix by mistake). He also said that we would not pay the hotfix he already sent, but that we should consider this information for future requests. In a subsequent phone call from him, he told me that his boss made clear that this is the official position of the company regarding hotfixes for Windows 2000.</p>
<p>Now the crazy thing: when I looked back on Microsoft&#8217;s knowledge base in English (USA), I noticed that on all country versions except Italy, hotfixes for all languages and all Operating Systems are available for download directly at their site at no charge (a download request link is rendered <em>just under the title</em>).</p>
<p>Moral of the story: proprietary software can actually let you down in ways you don&#8217;t imagine, so if you&#8217;re near the end of support cycle, download all the patches and hotfixes you can and make backups.</p>
]]></content:encoded>
			<wfw:commentRss>http://geekscrap.com/2010/02/the-microsoft-hotfix-tale/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows back-to-the-future bug</title>
		<link>http://geekscrap.com/2010/01/windows-back-to-the-future-bug/</link>
		<comments>http://geekscrap.com/2010/01/windows-back-to-the-future-bug/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 00:52:40 +0000</pubDate>
		<dc:creator>geekscrap</dc:creator>
				<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://geekscrap.com/?p=238</guid>
		<description><![CDATA[According to this advisory written by Tavis Ormandy, Windows has been exposed to a vulnerability for over 15 years! Microsoft will only release a patch for supported products, so if you have any Windows 2000 or earlier in your lab, the only way to fix is disabling DOS and WOWEXEC.]]></description>
			<content:encoded><![CDATA[<p>According to <a rel="nofollow" href="http://support.microsoft.com/default.aspx/kb/220159">this advisory</a> written by Tavis Ormandy, Windows has been exposed to a vulnerability for <strong>over 15 years</strong>! Microsoft will only release a patch for supported products, so if you have any Windows 2000 or earlier in your lab, the only way to fix is <a rel="nofollow" href="http://support.microsoft.com/default.aspx/kb/220159">disabling DOS and WOWEXEC</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geekscrap.com/2010/01/windows-back-to-the-future-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security through obscurity</title>
		<link>http://geekscrap.com/2010/01/security-through-obscurity/</link>
		<comments>http://geekscrap.com/2010/01/security-through-obscurity/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 15:29:22 +0000</pubDate>
		<dc:creator>geekscrap</dc:creator>
				<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[closed source]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://geekscrap.com/?p=139</guid>
		<description><![CDATA[If anyone ever, ever, ever dares saying again that open-source-ness is not relevant to security assessment (or worse, that it&#8217;s counter-productive), I will kick them to China. Freedom of choice, yeah right.]]></description>
			<content:encoded><![CDATA[<p>If anyone ever, ever, ever dares saying again that open-source-ness is not relevant to security assessment (or worse, that it&#8217;s counter-productive), I will kick them to China. <a rel="nofollow" href="http://feeds.wired.com/~r/wired/index/~3/Z4VvtBTAjL0/microsoft-zero-day-flaw">Freedom of choice</a>, yeah right.</p>
]]></content:encoded>
			<wfw:commentRss>http://geekscrap.com/2010/01/security-through-obscurity/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
