Details of privilege escalation hole in Windows

Monday, April 21st, 2008

In a security alert last week, Microsoft reported a vulnerability which allows local users and users signed on with access to an Internet Information Server (IIS) or MS SQL server to escalate their privileges. Server operators such as hosting providers who allow user code to be executed, for example on ...

ActiveX module in Microsoft Works opens up security hole

Friday, April 18th, 2008

A demonstration of a security hole in the Microsoft Works Image Server (WkImgSrv.dll) ActiveX module contained in the Microsoft Works office suite has appeared on the Bugtraq mailing list. The demo appears to only cause a system crash. McAfee, however, has already found fully functional exploits which allow attackers to ...

RegToy: All-purpose utility for Windows

Tuesday, April 15th, 2008

It used to be that you would need four or five different programs to optimize your system, clean the registry, rename files, capture screens, etc... That was before RegToy. RegToy is a freeware utility that is basically a collection of utilities. The program sidebar is broken up into three main categories: System, ...

Tracking down Firefox plug-ins

Monday, April 14th, 2008

My last posting was about upgrading the Adobe Flash Player, a Web browser plug-in. Adobe Systems just released a new version that fixes critical bugs in older versions, so everyone should update to the latest version. Adobe's Flash tester page displays the version of the Flash Player being used by your ...

Security and safe browsing for Firefox

Tuesday, March 25th, 2008

You installed Firefox.  How do you make it more secure for daily use?  How do the Mozilla developers ensure that they are doing all the right things?  How do you safely browse the Internet? These are not easy questions to answer, and  some of the answers will be system/OS-dependent. Security functionality in ...

What the DLL is That?

Saturday, March 8th, 2008

When a DLL is identified as the culprit of a system crash, the less troubleshooting-familiar users may have problems determining just what application or driver may be at fault. Google is a great way to find out all sorts of information about errors, but Microsoft has a great resource to ...