Andrew Berges

Configuration Manager, Security, and other musings from a self-confessed IT geek.

June 2006 - Posts

More URL's to filter...
As per Suzi's blog posting here, and Sunbelt postings here, here, and here:

mswindowssearch(dot)com
trustcleaner(dot)com
813aw0nr01jsxfj374ca(dot)com
adelinatech(dot)com
adsforsite(dot)com
azebar(dot)com
blablablablablablablablabla(dot)com
fandl(dot)net
finditanyway(dot)com
globosoft(dot)info
googlecaches(dot)com
trustclicks(dot)com
trustincash(dot)com
trustincontextual(dot)com
trustinpopups(dot)com
iFramecash(dot)biz
extrememoney(dot)biz
iframemoney(dot)biz
xarwiroozc(dot)biz
xcytxcxqrb(dot)biz
xdnsupulub(dot)biz
xepvdhdnzs(dot)biz
xffsktxdul(dot)biz
xgbgsfmdis(dot)biz
trustinsearch(dot)com
spyfix(dot)biz
yes-yes-yes(dot)com
challengedavinci(dot)com
lynxtrack(dot)com
usa-bibles(dot)com
adwarefinder(dot)com
engagemarketing(dot)com
217.73.64.1-217.73.79.254

Adobe Reader Unspecified Vulnerabilities
http://secunia.com/advisories/20576/

Secunia Advisory: SA20576


TITLE: Adobe Reader Unspecified Vulnerabilities

SECUNIA ADVISORY ID: SA20576

RELEASE DATE: 2006-06-15

VERIFY ADVISORY: http://secunia.com/advisories/20576/

CRITICAL: Moderately critical

WHERE: From remote

IMPACT: Unknown

SOFTWARE: Adobe Reader 7.x

DESCRIPTION: Some vulnerabilities with unknown impacts have been reported in Adobe Reader. The vulnerabilities are caused due to some unspecified errors. The vulnerabilities have been reported in versions prior to 7.0.8.

SOLUTION: Update to the fixed version. Adobe Reader (Windows or Mac OS): Update to version 7.0.8.

REPORTED BY CREDITS: Reported by the vendor.

ORIGINAL ADVISORY: Adobe: http://www.adobe.com/support/techdocs/327817.html
Posted: Jun 15 2006, 12:18 PM by aberges | with no comments
Filed under: , ,
Blog Posting Clients...
Lately, I've been messing around with a lot of the options out there for blog posting clients.  Most recently, I've reinstalled w.bloggar.

I like this program; it's pretty much a universal blog client that supports ALL the major formats as well as making it quite easy to configure your account(s).  Best of all, it's free.  Problem is, I like the idea of a WYSIWYG editor, and this only shows code.

Does anyone know of a client that supports multiple blog accounts that is pretty universal in nature and is freeware or open source?  I'm pretty impressed with BlogJet, but I'm not ready to shell out $40 just for a blog client.
Posted: Jun 14 2006, 07:26 PM by aberges | with 2 comment(s)
Filed under:
For those using McAfee ePO and SMS 2003 OSD with BDD ZTI...
The SMS mailing list presented some questions regarding the updating of ePO agent policies, etc. during an OSD process.

The below commands can be added to your BDD actions menu to allow ePO to "phone home" for the latest policies, as well as update the VirusScan client itself:

ePO Agent - Check Tasks & Send/Receive Properties

"%PROGRAMFILES%\Network Associates\Common Framework\cmdagent.exe" /P

OR

"%PROGRAMFILES%\McAfee\Common Framework\cmdagent.exe" /P (for the 3.5.5 agent used with McAfee HIPS 6.0)

ePO Agent - Enforce Policies

"%PROGRAMFILES%\Network Associates\Common Framework\cmdagent.exe" /E

OR

"%PROGRAMFILES%\McAfee\Common Framework\cmdagent.exe" /E (for the 3.5.5 agent used with McAfee HIPS 6.0)

VirusScan Enterprise Update

"%PROGRAMFILES%\Network Associates\VirusScan\mcupdate.exe" /Update /Quiet
Posted: Jun 14 2006, 04:05 PM by aberges | with no comments
Filed under:
Rogue Antispyware URL's...

As per this post, antispywarebox (dot) com and titanshield(dot)com should be added to any URL blocklist you use in your organization.

I keep a list of these type of URL's for use on our 8e6 R3000 webfiltering applicance - would anyone be interested in comparing lists? I'll gladly share mine!

The Dell De-Crapifier

I've been getting caught up on many of my RSS feeds that I've neglected recently, and found the following application via SunbeltBlog, very handy when you receive a brand-new Dell machine loaded to the hilt with worthless links and applications:

The Dell De-Crapifier

Currently Uninstalls:
  • QuickBooks Trial
  • NetZero Installers
  • Earthlink Setup Files
  • Tiscali Internet Files
  • Wanadoo Europe Installer
  • Corel Photo Album 6
  • McAffee Personal Firewall
  • McAffee SpamKiller
  • McAffee VirusScan Online
  • McAffee Security Center
  • Google Desktop
  • Google Toolbar for Internet Explorer
  • America Online 9.0 US Version
  • America Online 9.0 UK Version
  • Musicmatch Jukebox
  • Musicmatch Music Services
  • Run Registry Keys:
    • "BuildBU" - Part of Dell Alerts which provides customers with an update on latest updates. Can be run manually as needed
    • "DVDLauncher" - Belongs to the Cyberlink PowerCinema video viewing software which allows you to play DVDs on insertation. This program is a non-essential process, and is installed for ease of use.
    • "ISUSPM Startup" and "ISUSScheduler" - InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software. Can be run manually.
    • "msci" - Used for McAffee Security Center
    • "MSKDetectorExe" - Part of McAfee Spamkiller
    • "QBReminderFlash" - QuickBooks
    • "QuickTime Task" - Tray icon that you can use for quick access to the QuickTime application and additional settings. Can be run manually.
    • "RealTray" - Tray icon that you can use for quick access to the Real Player application and additional settings. Can be run manually.
    • "SunJavaUpdateSched" - Updater for the Java Runtime Envronment. Can be run manually
    • "DellSupport" - Agent that offers additional support and update features for your Dell computer or laptop. Can be run manually.

http://www.yorkspace.com/dell-de-crapifier/

Posted: Jun 13 2006, 03:41 PM by aberges | with no comments
Filed under:
More on McAfee...
I suppose this probably has a bit to do with why they're neglecting their current products:

McAfee's 'Falcon' to come in four flavors
Posted: Jun 13 2006, 03:40 PM by aberges | with no comments
Filed under:
Symantec isn't the only security company with complaints...
In this post, Rod discusses the failure of Symantec to address the complaints of the user community and the negative commentary that has been generated as a result.

Being a McAfee ePolicy Orchestrator administrator, I'm not in a position to speak about Symantec's products.  But I can speak about McAfee's offerings...

VirusScan 8.0i has had 11 patches released for it since it was first RTM'd.  The most recent of which, patch 11, caused many clients to stop reporting to servers, locked up Domain Controllers, and generally caused havoc during deployment.  Sadly, this is not a isolated case, and neither has been their response: this patch was released 9/9/2005, and the fix for patch 11 was due for inclusion in patch 12.

9 months later the patch still has not materialized, and documents on the support portal indicate that patch 12 has been abandoned altogether in favor of a new patch 13 build.  Of course, none of this has stopped them from developing a new version of VirusScan...

Another example: recently they overhauled the support portal used for opening cases - this had been the subject of much fanfare from McAfee for many months.  After the new portal goes live, it becomes apparent that:

1.  The portal does not accept the new logins (or our old ones) - for ANYONE, ANYWHERE.
2.  It takes OVER A WEEK to get it fixed so anyone can login.
3.  During this week, since no customer can open cases online, everyone calls the call center instead -- resulting in hours of hold time just to REPORT an issue.
4.  After fixing this, the portal now only works with IE (for a company that supports Unix and Mac, etc - how are they supposed to use this?)

Any other McAfee admins out there with similar thoughts?
Posted: Jun 13 2006, 03:02 PM by aberges | with no comments
Filed under: ,
Treos & Radiation...
Here's something I never thought about: while the "gee-whiz" factor on the Treos is quite impressive, all of this has to come with a cost, right?

Apparently that cost is radiation levels.

'CNET has released a list of the top ten highest-radiation mobile phones in the US. The GSM version of the Palm Treo 650 ranks in the top 10 with a Specific Absorption Rate (SAR) of 1.51 W/kg. The FCC limit for public exposure from cellular telephones is a SAR level of 1.6 watts per kilogram.'

http://www.palminfocenter.com/news/8587/treo-650-ranks-high-on-sar-report/
Posted: Jun 02 2006, 03:29 PM by aberges | with no comments
Filed under: