Archive for October 12th, 2007

More on the URI Protocol Handing Flaw (WinXP+IE7)

First we had the Quick time QTL/URI issue, then the Acrobat URI and rumors of more exploits which were all 3rd party problems from the Microsoft perspective. Now things are getting interesting;

Microsoft Flip-Flops On URI Protocol Handing Flaw [SlashDot]
After months of insisting there is nothing to patch, Microsoft has done a complete 180 on the URI protocol handling vulnerability, announcing in a security advisory that a Windows update will be released to revise URI handling code within ShellExecute() to be more strict. The MSRC blog explains the background and offers more details on this issue.

The Microsoft Security Response Center (MSRC)
Additional Details and Background on Security Advisory 943521 [MSRC Blog]
… Our plan is to revise our URI handling code within ShellExecute() to be more strict. While our update will help protect all applications from malformed URI’s, application vendors who handle URI’s can also do stricter validation themselves to prevent malicious URI’s from being passed to ShellExecute(). We have seen several vendors introduce additional validation as a way to protect their customers from this issue. We are also working on a KB article to help third party application authors build this type of validation.

Microsoft Security Advisory (943521)
URL Handling Vulnerability in Windows XP and Windows Server 2003 with Windows Internet Explorer 7 Could Allow Remote Code Execution [MS]
… Microsoft is investigating public reports of a remote code execution vulnerability in supported editions of Windows XP and Windows Server 2003 with Windows Internet Explorer 7 installed. We are not aware of attacks that try to use the reported vulnerability or of customer impact at this time. Microsoft is investigating the public reports.
* This vulnerability does not affect Windows Vista or any supported editions of Windows where Internet Explorer 7 is not installed. …

Radiohead – In Rainbows

Radiohead has released their new album, In Rainbows on their website bypassing the traditional label route. In true Radiohead fashion, this is not a conventional transaction. There are two options;

1.) the DISCBOX meant for die hard fans that comes with the release on vinyl, extra CDs, and artwork for £40.00
2.) Download DRM free MP3s from their site at a price you determine. That’s correct at a price you determine, I paid £5.00

Support a shift to the future, go and download a copy yourself.

What was that smell? That’s the smell of many record company executives collectively having a forced bowel movement!

UPDATE: Looking for ‘In Rainbows’ album art work for your download? tube.hk have the official cover artwork for the front and back covers available for download.


 

October 2007
M T W T F S S
« Sep   Nov »
1234567
891011121314
15161718192021
22232425262728
293031  

Categories

del.icio.us

Flickr Photos

Holiday reading ... with Zombies!

IMG_3953

IMG_3952

IMG_3951

IMG_3950

More Photos

Twittering

Cluster Map