Pages

Thursday, May 1

ISC Podcast Episode 3

Hey all, we just put out Episode Number 3 for the Internet Storm Center Podcast. Available via iTunes here, and for you non-iTunes users, here.

 Subscribe in a reader

Apple's Safari Market Share on Windows Tripled!

Normally I'd be excited about this, but I am not.  Not really.  Since the way that Apple went about was slightly shady.  I wrote about it here.  And Apple did exactly as I thought they were going to do and trumpet the fact that they now have three times the market share that they used to, but they did it in kind of a shady way.  I called it!

 Subscribe in a reader

What went wrong with the Podcast?

This morning we had a reader write into the Internet Storm Center telling us that the intro music and the outro music was there but there was no vocal track on the podcast.

Turns out what happened was, when I copied and pasted the vocals from the track that I recorded the podcast on into the template I have set up for music and what not, it overwrote the vocal track.  

It's hard to describe, but basically Garageband overwrote itself, so the vocal track ceased to exist.  What a pain.  So, here I am this morning panicking to myself saying 'oh crap I erased the vocal, we'll have to re-record, blah blah'.  

Then I thought about it, I have Time Machine.  I know my laptop backed up to Time Machine after I recorded the podcast right?  So I went to my ~/Music/Garageband folder, and hit the Time machine button, went back in time till yesterday at 7 pm between the time when we got done recording the podcast and I saved it, to when I edited the podcast and put music in it at about 830 pm.  There was the original recording, I clicked restore and Time Machine asked me if I wanted to keep the old one, the new one, or both.  I clicked both.    Then I was able to get the audio from one session to another successfully, then mix it down to mp3.

Worked great.  Thank you Apple.  Thank you Time Machine.  If I didn't have time machine we would have had to re-record the podcast, because of a stupid copy and paste error that I made.  Saved me about 3 hours worth of work.  Awesome.

 Subscribe in a reader

ISC Podcast Episode 3

Hey all, we just put out Episode Number 3 for the Internet Storm Center Podcast. Available via iTunes here, and for you non-iTunes users, here.

 Subscribe in a reader

Monday, April 28

Focus

I've written before about maximizing your core efficiency.  It was a good article, but I thought I could make it better.  It seemed to me that there was something missing.  I had points in the article, but not inspiration.  Not things that kept you going.  Let's see if I can fix any of that.

When I wrote before I talked about focusing on your job.  You were hired to do a job.  Maybe several jobs, but that's what you were hired to do.  All the other stuff is cruft.  If you maximize your efficiency and performance of your job, not only will everything else fall in line, but you will have more time to do whatever else you like to do.

Be calm.  Assess what you need to do.  Let's take a job that I have some experience at.  Since I am an IDS guy by trade, let's look at a typical IDS analyst's job.  What is the analyst there to do?  Pause here when reading this article.  Think for a second.  What is the analyst there to do?  Many of you will think of all the things that you do as an analyst or as a security professional.  You review logs, you review IDS's, you do pro-active scanning, you might even do a little penetration testing.  You probably write some documentation, SOP's, procedural documents, and the like right?  Am I am about right here?  Okay, so that's what you do during the day.  But what is your job?  If I asked you to describe what you do in one sentence or less in as few words as possible, what would you say?

I said this to a room of analysts one time.  We all gathered in a conference room and we sat around the table and I was given the task of organizing these individuals into a team.  I asked this same exact question, and we went around the room.  I heard some descent answers.  One liners.  

I said, "My job is to catch the bad guy."  That's it.  That's my job.

I stood in front of about 200 system administrators one time giving a speech about security, which, even though it should be part of every system administrators job, it's often put on the back burner.  But here I was giving a speech to a packed room.  I made another statement that day, it's a point blank in-your-face statement.  

"The bad-guys are already in your network, right now, as I stand here and speak, they are in your network.  Now what are you going to do about it?"

Think about that for a second.  Am I right?  Some of you will say no, I'm wrong, and go back about your business.  But I am saying it for a reason.  The Bad-Guy IS in your network, right now.  Still think I am wrong?  You aren't paying attention to security.  When I mean you aren't paying attention, I don't mean that you aren't reading the mailing lists and such.  I mean you aren't paying attention.  I am not going to explain to you what I mean about the Bad Guy being in your network, that's for you to figure out.  If you think I am wrong, it's also for you to prove that I am.  At this point you may be thinking that I am being a bit cocky.  No, I am being brash for a point, take the time to think what I mean.  

The Bad-Guy is in your network.  What are you going to do?

Your job as a network security analyst is to catch that bad guy.  What are you going to do?  Let's take it a bit bigger and look at security from a department perspective.  

Let's say you are a security department head for a corporation.  Not big, not small, or huge, or tiny.  It doesn't matter.  The difference between a 100 person startup company and a multi-trillion dollar organization is complexity.  The security of it is no more less or more secure, or no more or less important.  It's just more complex.  

Do not be afraid to roll up your sleeves on day one.  
Be honest with yourself, your employees, and your supervisors.  Don't be afraid to tell them the truth.  Even though the truth may not be what they want to hear.  The person hearing that truth will value you more for it in the end.  I didn't say blunt, or rude.  I said truthful.  You don't have to be an a** to get people to understand you.  You also don't have to tell people the whole truth to your point across.  Get in there and get dirty.  
When I go to a customer's site, on the first day I like to have a meeting with everyone I can.  Management, support staff, analysts, forensics, etc.  Sit them down and clearly state what we are all going to accomplish during this time.  

Don't lump too much into one time period.
Often times I am only on site with a customer for 4 or 5 days.  Sometimes I am onsite with customers for 4 or 5 months.  There is going to be a certain amount of things you can accomplish during this time period, and there are going to be things you won't be able to accomplish sometimes.  Don't stress over it, it's just the way the chips fall.  There is more time available, if it's truly important, I can come back.

Don't beat around the bush.
I kinda already said this up above, but face your challenges.  Putting them aside and procrastinating about projects, no matter how small or large, will only make them get worse.  The small ones will get bigger, the big ones will get monumental.   You've laid out your tasks, now get to it.

Never say anything you aren't sure of, and if you do, make sure the people you are telling that something to knows that you aren't sure.
If you are going to make a statement, make it.  But be right.  Better to not open your mouth and let people think you are an idiot, then to open your mouth and remove all doubt.  If you don't know the answer, and you have to give an answer, give them your best guess, but make sure they know it's your best guess and that you'll get a better answer for them shortly.  Then go get the darn answer.  Don't be afraid to ask for help if you need it.  You don't know everything, no one does.  But collectively a problem that seems like a mountain can shortly become a molehill.

What are you good at?  Make that list, then delegate the rest.
What are you good at?  IDS?  Packets?  Cisco devices?  Windows host based security?  Focus on that, become the absolute best you can be at that specific task.  Delegate the rest until you are the best at #1, then learn your #2's.  If you aren't good at Cisco devices, don't act like you are, find someone that is, hook up with them, learn from them if you can, and move on.  Do what you are good at.

I consider myself to be good at a several things, packet analysis, public speaking, explaining complex things in layman's terms, and teaching others.  I know I am not good at configuring firewalls, can I do it?  Yes, but that's not my core.  I know I am not good at writing documentation, can I do it?  Yes, but that's not my core.  But stick me in front of a large audience of technical people, CEO's, CFO's, and janitors, I can make sure everyone in that room gets my point, and am well understood.  I wasn't born with that, I had to learn it.  When I was first asked to stand in front of people and give speeches, teach, etc.  I sucked at it.  I was horrible.  But I was forced to do it, hundreds of times.   I use the old horse analogy.  If you fall off, get back on.  I wasn't good at teaching or public speaking at first, but I had to do it, so I did it, and I learned.  I didn't take courses at teaching or presenting, but I read books, I watched the masters at work, and I learned.  Now I am pretty confident and pretty good at it.   If you want me to come give a talk at your organization about security, etc.. my contact info is at the top of the blog.  (It says "Contact").  Let's talk.

Now, get a piece of paper (virtual or physical) and draw a line down the middle so that you have two columns.
On the left column, make that "I'm good at this" list.  Then make a separate list of things you wish you were better at on the right.  Take all the time  you need to do this.  Even if you aren't good at making lists. (put it on the right.)

Now look at your left column.  Really?  Are you really good at all those things?  REALLY GOOD?  Any you can concentrate better on?  Anything in there that you wrote down that you probably should have in the right column?  In your column of things I wish I was better at?  Go ahead, erase them and move them over to the right.  

Now how many things do you have on the left?  Probably 5 or 6 things.  Maybe 10.  Your right list should be much longer.  Now, what are your next steps to get better at the things on the right?  Anything you can do easily?  Get to it.

I'll make this a two or three part series.  So expect another post along these lines shortly.


 Subscribe in a reader

Sunday, April 20

Software Update -- Did Apple Do Enough?

As I posted on the ISC --

I've been reading alot of articles recently about Apple's Software Updates. A couple of weeks ago, we talked about this in the ISC podcast, about Safari being automatically checked for installation if you have Apple Software Update installed. Apple Software Update is Apple Inc.'s piece of software that keeps Quicktime, iTunes, and Safari updated on your Windows Machine. It obviously does a lot more on our Apple's.

Now, I am an Apple user, an AVID Apple user. I own no less then 15-20 of their products, and an avid Apple defender. But even I said that Safari being automatically checked and enabled for download and installation on Windows machines was going a step too far. I don't mind if it was there for download, but automatically checked? Meh.

Now, I don't have a Windows machine, so I haven't been able to experience this myself, but apparently Apple issued an update to Software Update last week that moved Safari down to a block called "Optional Downloads", instead of being labeled as an update. Well, it's a great step, but I still am of the opinion that Apple didn't go far enough. Safari is still checked by default!?

What's the big deal? It's just an update, or even an optional download. Well, that's fine except that Safari was checked even on machines that didn't have Safari installed on it. Apple wasn't the forcing the download on people, but it sure wasn't making it obvious that it was an optional download.

So my question is, did Apple go far enough? I don't think they did, I would like to see it unchecked by default as an optional download. I don't mind if Apple offers the Windows users a better browsing experience. ;) But I do mind if they make the browser seem like it's a part of an already existing installation.

The problem wouldn't be so bad, but I know at some point in the near future someone, whether it's Apple or some other agency , will report that Safari as "x" amount of market share, which me, as an Apple guy will say "Yeah! We have "X"!". But will it really be a real metric?

Joel Esler

http://www.joelesler.net


 Subscribe in a reader

Monday, April 14

News on the Podcast


I've received alot of positive feedback on the podcast.  Thanks for listening, apparently we're doing something right, Apple has featured us on the "New and Notable" list on iTunes.  So I am sure we might pick up some subscribers on that.  That's awesome.  I'm glad to see that it's being so well received.

 Subscribe in a reader

For those of you with Twitter

If you don't have twitter, just ignore this post.  Or if you have twitter, and you don't like John C. Dvorak, skip it too.

If you follow anything about John C. Dvorak (famed journalist that writes for alot of publications, most notably PC Magazine -- Recently quoted saying dump Microsoft all together and buy a Mac...  (okay, that was off-topic)) you'd know he doesn't do much of anything that is the new social networking/web 2.0 stuff.

Well, he recently joined twitter, presumably to give Leo Laporte something more to talk about on TWiT.  (Which, yes, I listen to.)  Anyway, if you are a twitter user, and you enjoy Dvorak's rantings as much as I do (hey, it's funny!), add him right here.

 Subscribe in a reader

News on the Podcast


I've received alot of positive feedback on the podcast.  Thanks for listening, apparently we're doing something right, Apple has featured us on the "New and Notable" list on iTunes.  So I am sure we might pick up some subscribers on that.  That's awesome.  I'm glad to see that it's being so well received.

 Subscribe in a reader

For those of you with Twitter

If you don't have twitter, just ignore this post.  Or if you have twitter, and you don't like John C. Dvorak, skip it too.

If you follow anything about John C. Dvorak (famed journalist that writes for alot of publications, most notably PC Magazine -- Recently quoted saying dump Microsoft all together and buy a Mac...  (okay, that was off-topic)) you'd know he doesn't do much of anything that is the new social networking/web 2.0 stuff.

Well, he recently joined twitter, presumably to give Leo Laporte something more to talk about on TWiT.  (Which, yes, I listen to.)  Anyway, if you are a twitter user, and you enjoy Dvorak's rantings as much as I do (hey, it's funny!), add him right here.

 Subscribe in a reader

Wednesday, April 9

iTunes is borked

Someone im'ed me this evening and told me that the new podcast episode was not up on iTunes.  Apparently if you are subscribed you'll get the new one, but it doesn't show up in the iTunes screen right away.  Wierd.  For a direct link to our podcast through our own XML go here.  It'll always be there ;)

 Subscribe in a reader

iTunes is borked

Someone im'ed me this evening and told me that the new podcast episode was not up on iTunes.  Apparently if you are subscribed you'll get the new one, but it doesn't show up in the iTunes screen right away.  Wierd.  For a direct link to our podcast through our own XML go here.  It'll always be there ;)

 Subscribe in a reader

Killbits

I have been getting a ton of hits through Google about people looking for further information on ActiveX KillBits.

Killbits are basically a way to stop IE (or anything based on IE) from calling an ActiveX bit to call another program.  Like, for instance, say you want to stop Yahoo Jukebox (as detailed recently in the most recent MSFT patches) from starting up when someone clicks on a link or something in IE, with the link telling IE to launch the Jukebox.

Well, you can prevent this from taking place by setting a "killbit" in the registry, which will basically prevent a program from being launched from within IE.  Detailed instructions are right here on MSFT's website.  You can do this globally across an enterprise as well by using a GPO for Windows.  I suggest a read of that website for your Killbit needs.

 Subscribe in a reader

Tuesday, April 8

Podcast Episode 2 available tomorrow

Our second podcast at the internet storm center should be available tomorrow, we recorded the second portion of it tonight, and I am sitting here listening to it to make sure it sounds nice and clean, so we should have it up on iTunes tomorrow.  I need to get a pop blocker for my mic, I have a couple red peaks in this record...  Here's the link were you can subscribe.

 Subscribe in a reader

Podcast Episode 2 available tomorrow

Our second podcast at the internet storm center should be available tomorrow, we recorded the second portion of it tonight, and I am sitting here listening to it to make sure it sounds nice and clean, so we should have it up on iTunes tomorrow.  I need to get a pop blocker for my mic, I have a couple red peaks in this record...  Here's the link were you can subscribe.

 Subscribe in a reader

Monday, April 7

GTD in Leopard, with Mail.app and iCal, redux

Remember that blog post I had like three months ago about GTD with Mail.app and Leopard, and iCal, and to-do's etc?  

Well, I found this article over here that basically expands on upon the point, I thought it was excellent, if you are a GTD person, check it out.

 Subscribe in a reader

Thursday, April 3

MSFT Tuesday for April 8, 2008

Looks like 5 critical and 3 important according to this link.  We at the Internet Storm Center will be recording our podcast that night, so we'll be cramming the info for these.  Two podcasts to record in the next few days!  

 Subscribe in a reader

MSFT Tuesday for April 8, 2008

Looks like 5 critical and 3 important according to this link.  We at the Internet Storm Center will be recording our podcast that night, so we'll be cramming the info for these.  Two podcasts to record in the next few days!  

 Subscribe in a reader

Snort releases version 2.8.1

Last night Sourcefire released version 2.8.1 of Snort.

Check out the changelog here.  Download it here.  Feature updates include:

* Support for target-based attribute tables
* Ability to read multiple PCAPs from the command line
* Support for GRE encapsulation for both IPv4 and IPv6
* Support for IP over IP tunneling for both IPv4 and IPv6
* An SSL preprocessor to allow the ability to ignore encrypted traffic
* Update to HTTP Inspect to identify overly long HTTP header fields
* Updates to IPv6 support



 Subscribe in a reader

Quicktime, Frontrow, and iTunes updates

Hey everyone, check out the new updates that Apple put out last night.  Security updates for Quicktime.  Then some other updates (probably compatibility with Quicktime) for Frontrow and iTunes.

I can't find the article right now because Apple's link is broken on their security site, but apparently there are like 11 vulnerabilities that this patches.

UPDATE:  I found it. Apple, fix your site.  kthnkx.

 Subscribe in a reader

Quicktime, Frontrow, and iTunes updates

Hey everyone, check out the new updates that Apple put out last night.  Security updates for Quicktime.  Then some other updates (probably compatibility with Quicktime) for Frontrow and iTunes.

I can't find the article right now because Apple's link is broken on their security site, but apparently there are like 11 vulnerabilities that this patches.

UPDATE:  I found it. Apple, fix your site.  kthnkx.

 Subscribe in a reader

Tuesday, April 1

Apple having an iPhone shortage

Stores across the US are selling out of the 8Gb and 16Gb iPhones according to AppleInsider.  Could this mean that the 3G iPhone is coming soon?  That's certainly what the rumors sound like.  I heard another rumor this morning that said that the manufacturer in Taiwan has received an order from 10 Million 3G iPhones.

Well see soon I guess?

 Subscribe in a reader

Apple having an iPhone shortage

Stores across the US are selling out of the 8Gb and 16Gb iPhones according to AppleInsider.  Could this mean that the 3G iPhone is coming soon?  That's certainly what the rumors sound like.  I heard another rumor this morning that said that the manufacturer in Taiwan has received an order from 10 Million 3G iPhones.

Well see soon I guess?

 Subscribe in a reader

Monday, March 31

Comment becoming a post

Got this as an anonymous comment on my last post:

"anonymous said...
How is it even remotely weak? Considering most virii spreading around these days is done via browser related vulnerabilities, I hardly would consider it "weak".

If it is so easy to discover browser vulnerabilities then how come IE7 held up on the Windows box (until the 3rd day when it was owned by flash)? How come you don't have any browser vulnerabilities credited to your name?

I hate to be "that guy", but the guy that won Pwn2Own walked away with $10k and a new laptop. I doubt he cares too much what bloggers think of him or his vulnerability, especially someone that hasn't done any similar research. Don't bash someone else's work unless you can reproduce it yourself.

Mon Mar 31, 08:55:00 AM"

My response:

Dear person-who-didn't-leave-their-name,

Who says I was bashing work? I still think it's a weak vulnerability.

I'm not saying that the guy that discovered it is stupid, or that the exploit itself is stupid -- props to him for getting 10k and a fat laptop. I'm saying that most of the journalists and bloggers out there are saying things like "Mac owned in 2 minutes". Really? Was it owned in two minutes? Or did the guy merely have the exploit already set up on his webpage before the contest began. Does that make sense? I don't like sensationalist headlines, essentially.

I'm also not saying it's easy for someone to discover the vulnerability, I am sure it took alot of research and fuzzing. I am saying now-a-days, there are alot of browser vulnerabilities. It seems like every week there is at least one. I'm not saying that the research that is done by the people isn't worthwhile, I am just not a fan of browser vulnerabilities, because, as I said.. It's easy to switch browsers.

I do think it was interesting that Windows held up until Flash was introduced. But what kind of metrics are we using here? A machine wasn't able to get exploited in one week? It takes more time than that doesn't it?

All punditry. I guess I just miss the days of remote server side exploits like ws_ftp, IIS, and the like.


Subscribe in a reader

Saturday, March 29

New Calendar phishing


The 419's will stop at nothing to scam you.  Now they are forging legit looking Calendar requests.  (Actually, this was a LEGIT calendar request!)  To get me to meet with them because I had won the death lottery.  Awesome.

Keep an eye out for these!  Classic.

 Subscribe in a reader

Pwn2Own

People have been writing into me asking what I think of the Mac getting owned in the pwn2own contest at CanSecWest.

Truth is, two things.  I don't know about the exploit other than it was Safari related.
And second, browser vulnerabilities suck.  No matter the browser, simply because there are so many exploits for every browser that is out there, and they pop up, then are quickly squashed all the time.  Plus, it's way too easy to just switch browsers now a days.  Many computers are starting to have more than one browser on them now..  not by default, but just by sheer happenstance.

All in all, I am going to say the same thing I said last year when the same thing happened at CanSecWest when a Mac was owned via the browser, then that's all I am going to say about it.

Weak.

 Subscribe in a reader

New Calendar phishing


The 419's will stop at nothing to scam you.  Now they are forging legit looking Calendar requests.  (Actually, this was a LEGIT calendar request!)  To get me to meet with them because I had won the death lottery.  Awesome.

Keep an eye out for these!  Classic.

 Subscribe in a reader

Friday, March 28

Top 30 podcasts in iTunes


Not only did our podcast finally get indexed (correctly) by iTunes yesterday, but today I looked in there, and our podcast is in the top 30!  Now, I know that the algorithm that manages the top "whatever" is done by how many people subscribe all at once and new subscribers and that kind of thing, so naturally, we are going to shoot up at first..  But I thought it was cool.  (No I don't really know how the algorithm works, it's just a hunch, and I know it will be different on other people's computers...

So, thanks.    Subscribe through iTunes here!

Digg it here.




 Subscribe in a reader

Top 30 podcasts in iTunes


Not only did our podcast finally get indexed (correctly) by iTunes yesterday, but today I looked in there, and our podcast is in the top 30!  Now, I know that the algorithm that manages the top "whatever" is done by how many people subscribe all at once and new subscribers and that kind of thing, so naturally, we are going to shoot up at first..  But I thought it was cool.  (No I don't really know how the algorithm works, it's just a hunch, and I know it will be different on other people's computers...

So, thanks.    Subscribe through iTunes here!

Digg it here.




 Subscribe in a reader

Thursday, March 27

A new podcast hits the airwaves

Last night Dr. Johannes and I sat down and recorded the first podcast of the Internet Storm Center.  Episode One.  The audio on my mic at the beginning is a bit low (I wasn't close enough to the mic), and Johannes's mic almost the whole way through was red peaking.  (I had him turned up too loud).  We recorded the whole thing over Skype, and I used Garargeband to master the sound.  It was pretty cool.  I am still learning how to use Garageband, so you might have to bear with me for a couple podcasts still, but I'm getting it.  In total there are about 8 tracks on the podcast, all requiring equalization and mastering, fading in and out, album art... etc.  So, it was kind of interesting.  

You can get the podcast through iTunes here.  (Hit subscribe, it'll download the newest one)  Or for you non-iTunes users, you can get it here.  Right now I only have it available in m4a (aac compression), but we should get the mp3 up very soon.  (I ran out of time last night, screaming baby and all)

On another note...


Paul of PaulDotCom and I were talking this morning about some potential podcast ideas, and we think we have come up with a good idea.  So those of you that are involved in podcasting about security, please start watching your inbox for emails from me/paul/johannes involved an idea we may have.  I know many of you read this blog either directly or through a syndicated feed, so, keep an eye out.

 Subscribe in a reader

A new podcast hits the airwaves

Last night Dr. Johannes and I sat down and recorded the first podcast of the Internet Storm Center.  Episode One.  The audio on my mic at the beginning is a bit low (I wasn't close enough to the mic), and Johannes's mic almost the whole way through was red peaking.  (I had him turned up too loud).  We recorded the whole thing over Skype, and I used Garargeband to master the sound.  It was pretty cool.  I am still learning how to use Garageband, so you might have to bear with me for a couple podcasts still, but I'm getting it.  In total there are about 8 tracks on the podcast, all requiring equalization and mastering, fading in and out, album art... etc.  So, it was kind of interesting.  

You can get the podcast through iTunes here.  (Hit subscribe, it'll download the newest one)  Or for you non-iTunes users, you can get it here.  Right now I only have it available in m4a (aac compression), but we should get the mp3 up very soon.  (I ran out of time last night, screaming baby and all)

On another note...


Paul of PaulDotCom and I were talking this morning about some potential podcast ideas, and we think we have come up with a good idea.  So those of you that are involved in podcasting about security, please start watching your inbox for emails from me/paul/johannes involved an idea we may have.  I know many of you read this blog either directly or through a syndicated feed, so, keep an eye out.

 Subscribe in a reader

Monday, March 24

Happy Birthday OSX!


Seven years old today.  Happy Birthday OSX.  March 24, 2001, Apple Releases OS X (10.0) Code-named Cheetah.  Remember those days?  I was to meet my wife (to be) a week later...  What is now the Apple Store in my local mall used to be a 5-7-9.  My primary operating system at the time was Redhat/XP.  A year later I bought a Mac.

Time flies.  Remember pre-OSX?   Now remember seven years ago... No iPod's?  No iPhones?  No Apple Stores?  

 Subscribe in a reader

Happy Birthday OSX!


Seven years old today.  Happy Birthday OSX.  March 24, 2001, Apple Releases OS X (10.0) Code-named Cheetah.  Remember those days?  I was to meet my wife (to be) a week later...  What is now the Apple Store in my local mall used to be a 5-7-9.  My primary operating system at the time was Redhat/XP.  A year later I bought a Mac.

Time flies.  Remember pre-OSX?   Now remember seven years ago... No iPod's?  No iPhones?  No Apple Stores?  

 Subscribe in a reader

Sunday, March 23

Happy Easter

Just wanted to wish a Happy Easter to everyone.  Take time and spend it with your loved ones.

 Subscribe in a reader

Happy Easter

Just wanted to wish a Happy Easter to everyone.  Take time and spend it with your loved ones.

 Subscribe in a reader

Wednesday, March 19

APPLE-SA-2008-03-19 AirPort Extreme Base Station Firmware 7.3.1

I just posted this over at the ISC as well, but I thought i'd post it here as well in case people don't read both.

Fresh on the heels of yesterday's huge Apple Security Update 2008-0002, today Apple released 2008-03-19 firmware update for the current (and pre-gigabit) Airport Extreme Base Stations.

AirPort Extreme Base Station with 802.11n*
CVE-ID: CVE-2008-1012
Available for: AirPort Extreme Base Station with 802.11n*
Impact: A maliciously crafted AFP request may lead to a denial of
service
Description: An input validation issue exists in the AirPort Extreme
Base Station's handling of AFP requests, which may cause file sharing
to become unresponsive. This update addresses the issue by performing
additional validation of AFP requests. This issue does not affect
Time Capsule or AirPort Express. The fix for this issue is available
in the following separate updates:
- - AirPort Extreme with 802.11n (Fast Ethernet) 7.3.1
- - AirPort Extreme with 802.11n (Gigabit Ethernet) 7.3.1
Credit to Alex deVries for reporting this issue.

More info here. (Although, I think I posted the whole thing above...)

To update to the newest firmware, open Airport Utility that is in your Utilities Folder in Applications. (If you are using a Mac, if you are using it for Windows, well, I don't know where it's at. ;) It should automatically check for the newest update and prompt you. It's a two click download and update.



Subscribe in a reader

APPLE-SA-2008-03-19 AirPort Extreme Base Station Firmware 7.3.1

I just posted this over at the ISC as well, but I thought i'd post it here as well in case people don't read both.

Fresh on the heels of yesterday's huge Apple Security Update 2008-0002, today Apple released 2008-03-19 firmware update for the current (and pre-gigabit) Airport Extreme Base Stations.

AirPort Extreme Base Station with 802.11n*
CVE-ID: CVE-2008-1012
Available for: AirPort Extreme Base Station with 802.11n*
Impact: A maliciously crafted AFP request may lead to a denial of
service
Description: An input validation issue exists in the AirPort Extreme
Base Station's handling of AFP requests, which may cause file sharing
to become unresponsive. This update addresses the issue by performing
additional validation of AFP requests. This issue does not affect
Time Capsule or AirPort Express. The fix for this issue is available
in the following separate updates:
- - AirPort Extreme with 802.11n (Fast Ethernet) 7.3.1
- - AirPort Extreme with 802.11n (Gigabit Ethernet) 7.3.1
Credit to Alex deVries for reporting this issue.

More info here. (Although, I think I posted the whole thing above...)

To update to the newest firmware, open Airport Utility that is in your Utilities Folder in Applications. (If you are using a Mac, if you are using it for Windows, well, I don't know where it's at. ;) It should automatically check for the newest update and prompt you. It's a two click download and update.



Subscribe in a reader

Verizon sets rules for Open Development

I don't want to retype a whole bunch of nonsense, but Verizon has finally published it's specs for Open Development as it promised last month.

Click here for the link.  So this essentially lets anyone develop a phone for Verizon's network, as long as it functions correctly.

 Subscribe in a reader

Verizon sets rules for Open Development

I don't want to retype a whole bunch of nonsense, but Verizon has finally published it's specs for Open Development as it promised last month.

Click here for the link.  So this essentially lets anyone develop a phone for Verizon's network, as long as it functions correctly.

 Subscribe in a reader

Tuesday, March 18

Questions I was Googled for today

In my first installment of "you came to my website because you Googled for something", I take your questions and answer them:

"gdbm invalid argument" -- you were probably trying to install gdbm on osx, where the bin group doesn't exist.  Go here.

"leopard graphics update" -- you were probably wondering what the hell it is.  I don't know.  But here's the post about it.

"the punisher" -- You were probably looking for the movie.  But you came to my site because of a friend of mine whose site is called "The Punisher".

"when was nuclear fusion discovered" -- I have no idea how you wound up at my site.  Here's Wikipedia.  But it appears the answer is "1932".

"make looped ringtones" -- I talked about this on my Garageband post.

"how to airport extreme powerbook"  -- You were probably looking for how to install an airport extreme card into a powerbook.  Uhhh, unless you have a really really old powerbook that comes with a regular airport card (instead of an airport extreme),  you can't put an airport extreme in an older one.   And if you have a newer powerbook, it has an airport extreme built in.

"joel esler" -- Uh, you found me.  Here I am.

"how do i save my iTunes library for reinstating on another machine" -- Okay, here's a good question.  Open up iTunes, then open Preferences.  Then Click on the "Advanced" button.


See the folder location there?  Open up your Finder, browse to your home directory (which it should go to by default), click on music, you will see a folder there called "iTunes".  Copy that folder on to whatever media you have, thumbdrive, through the network directly to the other computer, dvd/cd, whatever...

Now, on your new computer, navigate to the same path, you should have an "iTunes" folder there, with nothing in it.  Delete the folder on the new computer, and replace it with the iTunes folder that you copied from the old computer.  Start iTunes.  iTunes should pick up the folder with all your music in it.  At most, when you play your music, if you have any music that you have bought from the iTunes music store, you will have to authenticate with the iTunes store in order to play your music (big whoop!).

"esler blog"  -- AH!! you found me.

"differences between two operating systems" -- You were probably looking for this post.

That's all for today.  Come back later for more questions answered.

 Subscribe in a reader

Science fiction author Arthur C. Clarke dies aged 90

As if you haven't read it in 90 other publications already,  Arthur C. Clarke died today at the age of 90.  The man who wrote "The Sentinel"  (No, not the movie with Michael Douglas and Keifer Sutherland in it), the book on which "2001:  A Space Odyssey" was based.

R.I.P.

 Subscribe in a reader