<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Random Thoughts &#187; Security</title>
	<atom:link href="http://dionaea.com/blog/archives/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://dionaea.com/blog</link>
	<description>My thoughts and whatever about random topics.</description>
	<pubDate>Sun, 24 Aug 2008 22:16:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
	<language>en</language>
			<item>
		<title>IE Security Flaw - Again</title>
		<link>http://dionaea.com/blog/archives/2006/03/27/ie-security-flaw-again/</link>
		<comments>http://dionaea.com/blog/archives/2006/03/27/ie-security-flaw-again/#comments</comments>
		<pubDate>Mon, 27 Mar 2006 17:50:34 +0000</pubDate>
		<dc:creator>Svein Kåre</dc:creator>
		
		<category><![CDATA[Browsers]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dionaea.com/blog/archives/2006/03/27/ie-security-flaw-again/</guid>
		<description><![CDATA[OK, I&#8217;m not going to talk about that security flaw in IE here - I&#8217;ll leave that to others, such as The Register in &#8216;Critical&#8217; IE bug threatens PC users. What I&#8217;ll mention briefly here is the wording I&#8217;ve seen elsewhere, too:
 The other option is to choose an alternative browser, such as Firefox or [...]]]></description>
			<content:encoded><![CDATA[<p>OK, I&#8217;m not going to talk about that security flaw in <acronym title="Internet Explorer">IE</acronym> here - I&#8217;ll leave that to others, such as <a href="http://www.theregister.co.uk/2006/03/27/another_ie_security_flaw/">The Register in &#8216;Critical&#8217; <acronym title="Internet Explorer">IE</acronym> bug threatens PC users</a>. What I&#8217;ll mention briefly here is the wording I&#8217;ve seen elsewhere, too:</p>
<blockquote><p> The other option is to choose an alternative browser, such as Firefox or Opera. However, even these browsers are not as safe from attack as they were once considered.</p>
<p>Firefox has been subject to a number of flaws over the past year, including one that could leave its users more vulnerable to phishing scams. Meanwhile, a report published in September by Symantec rated Internet Explorer as safer than Firefox. The report found some 25 flaws in Mozilla&#8217;s Firefox internet browser, almost double the number it discovered in <acronym title="Internet Explorer">IE</acronym>.
</p></blockquote>
<p>Vulnerabilities in Opera is not mentioned - not here, not elsewhere - and I wonder: Why not? There <strong>are</strong> vulnerabilities to mention, right? Since it&#8217;s mentioned that it&#8217;s not as safe from attacks as once considered, I mean. Wouldn&#8217;t it be natural to mention at least <strong>one</strong>, serious vulnerability, like with Firefox?</p>
<p>Just wondered&#8230;</p>]]></content:encoded>
			<wfw:commentRss>http://dionaea.com/blog/archives/2006/03/27/ie-security-flaw-again/feed/</wfw:commentRss>
		</item>
		<item>
		<title>That Sony rootkit - and its side effects</title>
		<link>http://dionaea.com/blog/archives/2005/11/06/that-sony-rootkit-and-its-side-effects/</link>
		<comments>http://dionaea.com/blog/archives/2005/11/06/that-sony-rootkit-and-its-side-effects/#comments</comments>
		<pubDate>Sun, 06 Nov 2005 00:09:53 +0000</pubDate>
		<dc:creator>Svein Kåre</dc:creator>
		
		<category><![CDATA[Games]]></category>

		<category><![CDATA[In the news]]></category>

		<category><![CDATA[Music/MP3]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dionaea.com/blog/?p=138</guid>
		<description><![CDATA[Not many days have passed since Sony got negative attention for its DRM protection of Copy Protected CDs, to which they were quickly issuing an update to remove it.Or - did they? The update is 3.5 MB, seems to update all the files, and leaves some more files there, according to Ed Felten, who had [...]]]></description>
			<content:encoded><![CDATA[<p>Not many days have passed since <a href="http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/">Sony got negative attention for its DRM protection</a> of Copy Protected CDs, to which they were quickly issuing an <a href="http://dionaea.com/blog/archives/2005/11/03/sony-apologises-not/">update to remove it</a>.Or - did they? The update is 3.5 <acronym title="Megabyte">MB</acronym>, seems to update all the files, and leaves some more files there, <a href="http://www.freedom-to-tinker.com/?p=921">according to Ed Felten</a>, who had looked a bit closer at it:</p>
<blockquote><p>The update is more than 3.5 megabytes in size, and it appears to contain new versions of almost all the files included in the initial installation of the entire DRM system, as well as creating some new files. In short, theyâ€™re not just taking away the rootkit-like function â€” theyâ€™re almost certainly adding things to the system as well. And once again, theyâ€™re not disclosing what theyâ€™re doing.</p>
<p>No doubt theyâ€™ll ask us to just trust them. I wouldnâ€™t. The companies still assert â€” falsely â€” that the original rootkit-like software â€œdoes not compromise securityâ€ and â€œ[t]here should be no concernâ€ about it. So I wouldnâ€™t put much faith in any claim that the new update is harmless. And the companies claim to have developed â€œnew ways of cloaking files on a hard driveâ€. So I wouldnâ€™t derive much comfort from carefully worded assertions that they have removed â€œthe â€¦ component .. that has been discussedâ€.</p></blockquote>
<p>But, there&#8217;s more - related to the rootkit, unrelated to the &#8220;fix&#8221;.</p>
<h4>Use the rootkit to cheat other companies</h4>
<p>Players of World of Warcraft don&#8217;t like the game makers, and the controversial tactics to avoid cheating in the game. (To my limited understanding - I don&#8217;t play it myself.) The program &#8216;Warden&#8217; scans the players&#8217; PCs, to make sure there&#8217;s no processes running tohelp cheating in the game.</p>
<p>Sony to the rescue - their rootkit DRM <a href="http://www.securityfocus.com/brief/34">helps War of Worldcraft hackers to fool the Warden</a>. After all, with the DRM rootkit installed, all that is needed to hide a process is to start the filename with $sys$ - right?</p>]]></content:encoded>
			<wfw:commentRss>http://dionaea.com/blog/archives/2005/11/06/that-sony-rootkit-and-its-side-effects/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Sony apologises - not!</title>
		<link>http://dionaea.com/blog/archives/2005/11/03/sony-apologises-not/</link>
		<comments>http://dionaea.com/blog/archives/2005/11/03/sony-apologises-not/#comments</comments>
		<pubDate>Thu, 03 Nov 2005 14:05:21 +0000</pubDate>
		<dc:creator>Svein Kåre</dc:creator>
		
		<category><![CDATA[In the news]]></category>

		<category><![CDATA[Music/MP3]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dionaea.com/blog/archives/2005/11/03/sony-apologises-not/</guid>
		<description><![CDATA[When it was discovered that Sony took its DRM-implementation too far it was something that didn&#8217;t escape the news. It was discussed all over the place, and didn&#8217;t give Sony high thoughts.
Sony has reacted, and posted a service pack/update that removes the cloaking technology. But does it apologise? No - instead it downplays the problems, [...]]]></description>
			<content:encoded><![CDATA[<p>When it was discovered that <a href="http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/">Sony took its DRM-implementation too far</a> it was something that didn&#8217;t escape the news. It was discussed all over the place, and didn&#8217;t give Sony high thoughts.</p>
<p>Sony has reacted, and posted <a href="http://cp.sonybmg.com/xcp/english/updates.html">a service pack/update</a> that removes the cloaking technology. But does it apologise? No - instead it downplays the problems, saying it wasn&#8217;t malicious and didn&#8217;t compromise security.</p>
<p>Funny. I thought the <a href="http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/">previous article</a> showed how easy security could be compromised&#8230;</p>
<p>Bad move, not to apologise. If Sony doesn&#8217;t regret the actions, what can we expect from the company later?</p>]]></content:encoded>
			<wfw:commentRss>http://dionaea.com/blog/archives/2005/11/03/sony-apologises-not/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Digital Rights Mismanagement: Sony takes it a step too far</title>
		<link>http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/</link>
		<comments>http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/#comments</comments>
		<pubDate>Tue, 01 Nov 2005 20:46:23 +0000</pubDate>
		<dc:creator>Svein Kåre</dc:creator>
		
		<category><![CDATA[In the news]]></category>

		<category><![CDATA[Music/MP3]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/</guid>
		<description><![CDATA[Today I was made aware of an article called Sony, Rootkits and Digital Rights Management Gone Too Far by Mark Russinovich - and it&#8217;s scary news. Mark had bought a Copy Controlled CD made by Sony, and as a result from playing it on his PC, Sony had taken the liberty to install software on [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was made aware of an article called <a href="http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html">Sony, Rootkits and Digital Rights Management Gone Too Far</a> by Mark Russinovich - and it&#8217;s scary news. Mark had bought a Copy Controlled <acronym title="Compact Disk">CD</acronym> made by Sony, and as a result from playing it on his PC, Sony had taken the liberty to install software on his computer - and hidden it.</p>
<p>One thing is to try to limit what can be done with the music on the <acronym title="Compact Disk">CD</acronym>, but trying to hide that you&#8217;ve installed software, and make it very difficult to uninstall, that&#8217;s going too far. Especially as the software in question takes up resources, poses a security risk, and may also be unstable in itself. This sounds too much alike what is commonly known as malware.</p>
<p>Another question that begs to be asked is: Is what Sony has done here legal? Sony may write about this in their EULA, (but it is not certain that they actually <strong>do</strong> this, even after they updated it <strong>after</strong> the fact,) but an EULA can&#8217;t override laws - not everywhere at least - and may even be known <strong>before</strong> the product is bought to be valid.</p>
<p>Maybe it&#8217;s time for consumers to sue?</p>]]></content:encoded>
			<wfw:commentRss>http://dionaea.com/blog/archives/2005/11/01/digital-rights-mismanagement-sony-takes-it-a-step-too-far/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yet another IE spoof</title>
		<link>http://dionaea.com/blog/archives/2005/01/19/yet-another-ie-spoof/</link>
		<comments>http://dionaea.com/blog/archives/2005/01/19/yet-another-ie-spoof/#comments</comments>
		<pubDate>Wed, 19 Jan 2005 19:46:05 +0000</pubDate>
		<dc:creator>Svein Kåre</dc:creator>
		
		<category><![CDATA[Browsers]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dionaea.com/blog/archives/2005/01/19/yet-another-ie-spoof/</guid>
		<description><![CDATA[Netcraft tells about yet another IE spoofing trick:
A number of recent phishing sites blocked by the Netcraft Toolbar community have had a common technique of using JavaScript to create a narrow popup window, which is then placed on top of the Address bar. A fake URL is entered into the popup, using the same default [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://news.netcraft.com/archives/2005/01/16/toolbar_community_reports_internet_explorer_address_bar_spoofing_vulnerabilities_actively_exploited.html">Netcraft</a> tells about yet another <acronym title="Internet Explorer">IE</acronym> spoofing trick:<br />
<blockquote>A number of recent phishing sites blocked by the Netcraft Toolbar community have had a common technique of using JavaScript to create a narrow popup window, which is then placed on top of the Address bar. A fake <acronym title="Uniform Resource Locator">URL</acronym> is entered into the popup, using the same default font as the real address bar. The script continually checks the location of the browser window and moves the popup accordingly, ensuring that it is always placed on top of the Address bar, thus obscuring the real <acronym title="Uniform Resource Locator">URL</acronym> of the phishing site.</p></blockquote>
<p>It might be in its place to remind people that the safest way to avoid trouble with <acronym title="Internet Explorer">IE</acronym>, is to use a different browser. (And while there&#8217;s a lot of talk about Firefox, personally I find <a href="http://www.opera.com" title="Opera is the bestest browser I've used!">Opera</a> a better choice. In my humble opinion, of course.)</p>]]></content:encoded>
			<wfw:commentRss>http://dionaea.com/blog/archives/2005/01/19/yet-another-ie-spoof/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
