<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Not in code &#187; Security</title>
	<atom:link href="http://notincode.wordpress.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://notincode.wordpress.com</link>
	<description>Software is about people</description>
	<lastBuildDate>Mon, 22 Jun 2009 00:33:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='notincode.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/1bb58d250bfeaaf97c6daf48b9a54b30?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Not in code &#187; Security</title>
		<link>http://notincode.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://notincode.wordpress.com/osd.xml" title="Not in code" />
	<atom:link rel='hub' href='http://notincode.wordpress.com/?pushpress=hub'/>
		<item>
		<title>GDIPlus Scanning Tool from Sans.org</title>
		<link>http://notincode.wordpress.com/2004/09/28/gdiplus-scanning-tool-from-sansorg/</link>
		<comments>http://notincode.wordpress.com/2004/09/28/gdiplus-scanning-tool-from-sansorg/#comments</comments>
		<pubDate>Mon, 27 Sep 2004 23:25:25 +0000</pubDate>
		<dc:creator>hiremaga</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.hiremaga.com/?p=55</guid>
		<description><![CDATA[I recently ranted about the shocking GDIplus.dll JPEG processing vulnerability on this blog. Since then Microsoft released a tool that scans for vulnerable versions of this dll as part of windows update. Unfortunately this tool only results in giving people a false sense of security because it is incomplete. The good people at sans.org have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=43&subd=notincode&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I recently ranted about<a href="http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx"> the shocking GDIplus.dll JPEG processing vulnerability</a> on this blog. Since then Microsoft released a tool that scans for vulnerable versions of this dll as part of <a href="http://windowsupdate.microsoft.com/">windows update</a>. Unfortunately this tool only results in giving people a false sense of security because it is incomplete.</p>
<p>The good people at <a href="http://isc.sans.org/gdiscan.php">sans.org have released their own tool</a> which appears to be much better than Microsoft&#8217;s. I recommend running this tool at least once on your Windows PC and then each time you install any application that *may* install its own copy of the dll (i.e. potentially *any* application that does JPEG processing). Of course it&#8217;s worth making sure that you have installed all vendor updates before you run the tool as they may well fix the vulnerability. Also, please read the sans.org web page carefully before your run their tool as there are some instances where it is &#8220;OK&#8221; if a vulnerable instance of the dll is found on your computer.</p>
<p>Additionally for users of Macromedia&#8217;s MX line of products, they recently released <a href="http://www.macromedia.com/devnet/security/security_zone/mpsb04-07.html">this security bulletin</a> that states that their products are not affected by the vulnerability.</p>
<p>Thanks goes to my ever dependable colleague Rob for showing me the sans.org tool.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/notincode.wordpress.com/43/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/notincode.wordpress.com/43/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/notincode.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/notincode.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/notincode.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/notincode.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/notincode.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/notincode.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/notincode.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/notincode.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/notincode.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/notincode.wordpress.com/43/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=43&subd=notincode&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://notincode.wordpress.com/2004/09/28/gdiplus-scanning-tool-from-sansorg/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cd84e3662c2772ec1f22649b9aa7464a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hiremaga</media:title>
		</media:content>
	</item>
		<item>
		<title>OMIGOD</title>
		<link>http://notincode.wordpress.com/2003/12/09/omigod/</link>
		<comments>http://notincode.wordpress.com/2003/12/09/omigod/#comments</comments>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<dc:creator>hiremaga</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.hiremaga.com/?p=50</guid>
		<description><![CDATA[A quote from the page on microsofts site describing the recent JPEG processing vulnerability in GDI+. Could I still be vulnerable even after I have installed all required security updates? Yes. &#8230;(long list of reasons why)&#8230; Please find me a tall building to jump from&#8230; Will blog some more about this when (and if) I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=37&subd=notincode&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A quote from the page on microsofts site describing the <a href="http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx">recent JPEG processing vulnerability in GDI+.</a></p>
<p><strong>Could I still be vulnerable even after I have installed all required security updates?</strong><br />
Yes. &#8230;(long list of reasons why)&#8230;</p>
<p>Please find me a tall building to jump from&#8230;</p>
<p>Will blog some more about this when (and if) I find an effective way to patch multiple machines + programs without shelling out big $$$</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/notincode.wordpress.com/37/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/notincode.wordpress.com/37/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/notincode.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/notincode.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/notincode.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/notincode.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/notincode.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/notincode.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/notincode.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/notincode.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/notincode.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/notincode.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=37&subd=notincode&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://notincode.wordpress.com/2003/12/09/omigod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cd84e3662c2772ec1f22649b9aa7464a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hiremaga</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Bulletins via RSS</title>
		<link>http://notincode.wordpress.com/2003/12/06/security-bulletins-via-rss/</link>
		<comments>http://notincode.wordpress.com/2003/12/06/security-bulletins-via-rss/#comments</comments>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<dc:creator>hiremaga</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.hiremaga.com/?p=33</guid>
		<description><![CDATA[I discovered the Microsoft Security Bulletins RSS feed today. I&#8217;ve added it to my list of channels in FeedDemon. It makes sense that they would use an RSS feed for their security bulletins, it involves a much lower overhead than individual emails. I guess it&#8217;s not that different from the concept of &#8220;newsgroups&#8221;(hmm, I wonder [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=11&subd=notincode&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I discovered the <a href="http://www.microsoft.com/technet/security/bulletin/secrss.aspx">Microsoft Security Bulletins RSS feed</a> today. I&#8217;ve added it to my list of channels in <a href="http://www.bradsoft.com/feeddemon/index.asp">FeedDemon</a>.</p>
<p>It makes sense that they would use an RSS feed for their security bulletins, it involves a much lower overhead than individual emails. I guess it&#8217;s not that different from the concept of &#8220;newsgroups&#8221;(hmm, I wonder if you can get access to popular newsgroups via RSS?).</p>
<p>Note to self: Look for more security related RSS feeds after my exam next week.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/notincode.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/notincode.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/notincode.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/notincode.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/notincode.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/notincode.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/notincode.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/notincode.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/notincode.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/notincode.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/notincode.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/notincode.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hiremaga.com&blog=2620597&post=11&subd=notincode&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://notincode.wordpress.com/2003/12/06/security-bulletins-via-rss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cd84e3662c2772ec1f22649b9aa7464a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">hiremaga</media:title>
		</media:content>
	</item>
	</channel>
</rss>