<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:blogChannel="http://backend.userland.com/blogChannelModule" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Stray Thoughts...</title>
    <description>wonderings of  a lost mind....</description>
    <link>http://www.hirantha.net/blog/</link>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>BlogEngine.NET 1.5.0.7</generator>
    <language>en-GB</language>
    <blogChannel:blogRoll>http://www.hirantha.net/blog/opml.axd</blogChannel:blogRoll>
    <blogChannel:blink>http://www.hirantha.net/blog/syndication.axd</blogChannel:blink>
    <dc:creator>Hirantha Hettiarachchi</dc:creator>
    <dc:title>Stray Thoughts...</dc:title>
    <geo:lat>0.000000</geo:lat>
    <geo:long>0.000000</geo:long>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/hirantha" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
      <title>First iPhone worm discovered</title>
      <description>&lt;p&gt;Apple iPhone owners in Australia have &lt;a href="http://forums.whirlpool.net.au/forum-replies.cfm?t=1315624"&gt;reported&lt;/a&gt; that their smart phones have been infected by a worm that has changed their wallpaper to an image of 1980s pop crooner Rick Astley.&lt;/p&gt;  &lt;p&gt;The worm, which &lt;em&gt;could&lt;/em&gt; have spread to other countries although there are no confirmed reports outside Australia, is capable of breaking into jail broken iPhones if their owners have not changed the default password after installing SSH. Once in place, the worm appears to attempt to find other iPhones on the mobile phone network that are similarly vulnerable, and installs itself again&lt;/p&gt;  &lt;p&gt;On each installation, the worm - written by a hacker calling themselves &amp;quot;ikex&amp;quot; - changes the lock background wallpaper to an image of Rick Astley with the message:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;tt&gt;ikee is never going to give you up&lt;/tt&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;What's clear is that if you have jail broken your iPhone or iPod Touch, and installed SSH, then you must always change your root user password to something different than the default, &amp;quot;alpine&amp;quot;. In fact, it would be a good idea if you didn't use a dictionary word at all.&lt;/p&gt;  &lt;p&gt;The worm will not affect users who have not jail broken their iPhones or who have not installed SSH.&lt;/p&gt;  &lt;p&gt;SophosLabs is analyzing the worm's code, which suggests that at least four variants have been written so far. One of the attributes of the latest variant (labeled the &amp;quot;D&amp;quot; version) is that it tries to hide its presence by using a file path suggestive of the Cydia application.&lt;/p&gt;  &lt;p&gt;Presently it appears that the worm does nothing more malicious than spread and change the infected user's lock screen wallpaper. However, that doesn't mean that attacks like this can be considered harmless.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/xUAVtaPLKmA" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/xUAVtaPLKmA/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/11/09/Firt-iPhone-worm-discovered.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=d541bf78-a553-4700-b899-8189c4e64d40</guid>
      <pubDate>Mon, 09 Nov 2009 06:19:46 -0600</pubDate>
      <category>Apple</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=d541bf78-a553-4700-b899-8189c4e64d40</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=d541bf78-a553-4700-b899-8189c4e64d40</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/11/09/Firt-iPhone-worm-discovered.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=d541bf78-a553-4700-b899-8189c4e64d40</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=d541bf78-a553-4700-b899-8189c4e64d40</feedburner:origLink></item>
    <item>
      <title>TLS Man-in-the-middle on renegotiation vulnerability made public</title>
      <description>&lt;p&gt;TLS 1.0+ and SSL 3.0+ (known from among others &amp;quot;https&amp;quot;) is vulnerable to a protocol weakness where a man in the middle attack could be worked in during the renegotiation phase in modern versions of the protocol.&lt;/p&gt;  &lt;p&gt;While the details had been offered in a meeting with the IETF, vendors and the open source implementers of SSL privately, it appears an IETF mailing list came to finding it again. That seems to have prompted the original finders to offer up their finding publicly.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://extendedsubset.com/?p=8"&gt;The original description&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.ietf.org/mail-archive/web/tls/current/msg03948.html"&gt;The summary by the IETF TLS workgroup, and promisses for an amended protocol&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://extendedsubset.com/Renegotiating_TLS.pdf"&gt;Marsh Ray's paper&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://extendedsubset.com/Renegotiating_TLS_pd.pdf"&gt;March Ray's protocol diagrams&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;There does not seem to be much you can do till the protocol is fixed. The main problem seems to be with clients using certificate authentication.&lt;/p&gt;  &lt;p&gt;Exploiting this requires the attacker to be able to intercept the traffic.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/YVZ-mpPVjTc" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/YVZ-mpPVjTc/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/11/06/TLS-Man-in-the-middle-on-renegotiation-vulnerability-made-public.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=1f559e0b-f36d-4e16-a797-2b9a7ed208f7</guid>
      <pubDate>Fri, 06 Nov 2009 07:32:42 -0600</pubDate>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=1f559e0b-f36d-4e16-a797-2b9a7ed208f7</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=1f559e0b-f36d-4e16-a797-2b9a7ed208f7</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/11/06/TLS-Man-in-the-middle-on-renegotiation-vulnerability-made-public.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=1f559e0b-f36d-4e16-a797-2b9a7ed208f7</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=1f559e0b-f36d-4e16-a797-2b9a7ed208f7</feedburner:origLink></item>
    <item>
      <title>RIM fixes random code execution vulnerability</title>
      <description>&lt;p&gt;Affected: BlackBerry Desktop Software version 5.0 and earlier (on all platforms) - IBM Lotus Notes Intellisync&lt;/p&gt;  &lt;p&gt;Fixed in version 5.01&lt;/p&gt;  &lt;p&gt;CVSS score: 9.3&lt;/p&gt;  &lt;p&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0306"&gt;CVE-2009-0306&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;More info: &lt;a href="http://www.blackberry.com/btsc/viewContent.do?externalId=KB19701"&gt;KB19701&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The KB contains a workaround for those not needing the Lotus Notes Intellisync functionality.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/C83CwrXkDds" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/C83CwrXkDds/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/11/06/RIM-fixes-random-code-execution-vulnerability.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=62261340-1bb8-47b7-8ebc-16ebef95212a</guid>
      <pubDate>Fri, 06 Nov 2009 07:28:36 -0600</pubDate>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=62261340-1bb8-47b7-8ebc-16ebef95212a</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=62261340-1bb8-47b7-8ebc-16ebef95212a</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/11/06/RIM-fixes-random-code-execution-vulnerability.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=62261340-1bb8-47b7-8ebc-16ebef95212a</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=62261340-1bb8-47b7-8ebc-16ebef95212a</feedburner:origLink></item>
    <item>
      <title>New VMware Desktop Products Released</title>
      <description>&lt;p&gt;VMware Fusion 3.0 gone from Release Candidate to General Availability, so as&amp;nbsp; VMware Workstation 7.0 and VMware ACE 2.6&lt;/p&gt;
&lt;p&gt;New features&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Nested VMs.&amp;nbsp; This allows you to run ESX with guests inside of workstation&lt;/li&gt;
&lt;li&gt;support for Windows7 (and it's associated new graphics APIs) and Windows Server 2008.&lt;/li&gt;
&lt;li&gt;support for VMs with up to 4 processors and 32GB of memory &lt;/li&gt;
&lt;li&gt;ALSA sound support for Linux &lt;/li&gt;
&lt;li&gt;new "pause" feature, allowing you to pause a VM if you need some temporary processor power for your host or another VM&lt;/li&gt;
&lt;li&gt;a new Virtual Network Editor&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;More Info&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vmware.com/company/news/releases/fusion3-preorder.html" target="_blank"&gt;http://www.vmware.com/company/news/releases/fusion3-preorder.html&lt;/a&gt; &lt;br /&gt;&lt;a href="http://blogs.vmware.com/workstation/2009/10/workstation-7-release-candidate-available.html" target="_blank"&gt;http://blogs.vmware.com/workstation/2009/10/workstation-7-release-candidate-available.html&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/ZrdM6bNRL3c" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/ZrdM6bNRL3c/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/10/28/New-VMware-Desktop-Products-Released.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=57a20fe0-fdc3-480c-a673-48e9db1024bc</guid>
      <pubDate>Wed, 28 Oct 2009 06:21:00 -0600</pubDate>
      <category>VMWare</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=57a20fe0-fdc3-480c-a673-48e9db1024bc</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=57a20fe0-fdc3-480c-a673-48e9db1024bc</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/10/28/New-VMware-Desktop-Products-Released.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=57a20fe0-fdc3-480c-a673-48e9db1024bc</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=57a20fe0-fdc3-480c-a673-48e9db1024bc</feedburner:origLink></item>
    <item>
      <title>Truecrypt 6.3 released</title>
      <description>&lt;p&gt;
from their version history notes:
&lt;/p&gt;
  
&lt;ul&gt;
	   
	&lt;li&gt;Full support for Windows 7. &lt;/li&gt;    
	&lt;li&gt;Full support for Mac OS X 10.6 Snow Leopard. &lt;/li&gt;    
	&lt;li&gt;The ability to configure selected volumes as &amp;#39;system favorite volumes&amp;#39;. &lt;/li&gt; 
&lt;/ul&gt;
  
&lt;p&gt;
TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted volume (data storage device).
&lt;/p&gt;
  
&lt;p&gt;
More information here: &lt;a href="http://www.truecrypt.org/docs/?s=version-history"&gt;http://www.truecrypt.org/docs/?s=version-history&lt;/a&gt;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/Nj3EmRXsGlA" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/Nj3EmRXsGlA/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/10/26/Truecrypt-63-released.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=5800ceef-3825-4af8-aede-18cb9f6d0116</guid>
      <pubDate>Mon, 26 Oct 2009 13:15:00 -0600</pubDate>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=5800ceef-3825-4af8-aede-18cb9f6d0116</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=5800ceef-3825-4af8-aede-18cb9f6d0116</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/10/26/Truecrypt-63-released.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=5800ceef-3825-4af8-aede-18cb9f6d0116</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=5800ceef-3825-4af8-aede-18cb9f6d0116</feedburner:origLink></item>
    <item>
      <title>Oracle Critical Patch Update Advisory - October 2009</title>
      <description>&lt;p&gt;
There are lots of vulnerabilities DBAs must act upon ASAP, although it &amp;quot;only&amp;quot; addresses 38 vulnerabilities...
&lt;/p&gt;
  
&lt;ul&gt;
	   
	&lt;li&gt;&lt;strong&gt;&lt;strong&gt;16&lt;/strong&gt; fixes address flaws in the Oracle database (&lt;strong&gt;six&lt;/strong&gt; can be exploited remotely without user interaction)&lt;/strong&gt; &lt;/li&gt;    
	&lt;li&gt;&lt;strong&gt;&lt;strong&gt;3&lt;/strong&gt; fixes address flaws in the Oracle Application Server (&lt;strong&gt;two&lt;/strong&gt; can be exploited remotely without user interaction)&lt;/strong&gt; &lt;/li&gt;    
	&lt;li&gt;&lt;strong&gt;8&lt;/strong&gt; fixes address flaws in the Oracle Applications Suite (&lt;strong&gt;five&lt;/strong&gt; can be exploited remotely without user interaction) &lt;/li&gt; 
&lt;/ul&gt;
  
&lt;p&gt;
More (advance) information in the pre-release announcement : &lt;a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html" title="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html"&gt;http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html&lt;/a&gt;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/UCsRrRi2MDE" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/UCsRrRi2MDE/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/10/20/Oracle-Critical-Patch-Update-Advisory-October-2009.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=b9fe6fcb-70f5-4612-a30c-6323426db43b</guid>
      <pubDate>Tue, 20 Oct 2009 15:20:00 -0600</pubDate>
      <category>Oracle</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=b9fe6fcb-70f5-4612-a30c-6323426db43b</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=b9fe6fcb-70f5-4612-a30c-6323426db43b</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/10/20/Oracle-Critical-Patch-Update-Advisory-October-2009.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=b9fe6fcb-70f5-4612-a30c-6323426db43b</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=b9fe6fcb-70f5-4612-a30c-6323426db43b</feedburner:origLink></item>
    <item>
      <title>Cisco over-the-air-provisioning skyjacking exploit</title>
      <description>&lt;p&gt;
Cisco issued a security advisory for its&amp;nbsp; 1100 and 1200 Series access lightweight points. The advisory is based on work done by wifi IDS firm AirMagnet. Cisco uses an Over-The-Air-Provisioning (OTAP) protocol that uses multicast data to find a controller. During this initialization phase, a rogue controller could respond and send a bad configuration to the access point, disabling the device.
&lt;/p&gt;
&lt;p&gt;
Cisco provides an advisory here: &lt;a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=18919" target="_blank"&gt;http://tools.cisco.com/security/center/viewAlert.x?alertId=18919&lt;/a&gt; . 
&lt;/p&gt;
&lt;p&gt;
The quick summary: Establish basic configuration options like encryption keys and preferred controller lists before deploying the device.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/xUnRYhBviE4" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/xUnRYhBviE4/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/08/27/Cisco-over-the-air-provisioning-skyjacking-exploit.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=317ad81e-98af-4ee6-988f-a4d65358ebc6</guid>
      <pubDate>Thu, 27 Aug 2009 15:44:00 -0600</pubDate>
      <category>Cisco</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=317ad81e-98af-4ee6-988f-a4d65358ebc6</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=317ad81e-98af-4ee6-988f-a4d65358ebc6</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/08/27/Cisco-over-the-air-provisioning-skyjacking-exploit.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=317ad81e-98af-4ee6-988f-a4d65358ebc6</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=317ad81e-98af-4ee6-988f-a4d65358ebc6</feedburner:origLink></item>
    <item>
      <title>Vulnerability in Pidgin</title>
      <description>&lt;p&gt;
CORE security technologies published a vulnerability in libpurple.&amp;nbsp; Libpurple is the backend frame work to many Instant Messenger clients.
&lt;/p&gt;
  
&lt;p&gt;
Pidgin, Finch, Adium, Meebo, and Gaim among others.&amp;nbsp; Although CORE only specifically mentions GAIM, Libpurple, Pidgin, and Adium specifically, the other libpurple based ones may be vulnerable as well.
&lt;/p&gt;
  
&lt;p&gt;
Versions of Libpurple &amp;lt;= 2.5.8 (Pidgin &amp;lt;=2.5.8 and Adium &amp;lt;=1.3.5) are vulnerable.&amp;nbsp; The vulnerability is an exploit in the function msn_slplink_process_msg() which handles instant messages from the MSN network.&amp;nbsp; 
&lt;/p&gt;
  
&lt;p&gt;
All it takes to exploit this vulnerability is to receive a message from another MSN user.&amp;nbsp; They do not have to be on your buddy list.&amp;nbsp; Unless your buddy list states that you only allow specific users to contact you, it&amp;#39;s the only mitigation step.&amp;nbsp; (Other than patching or logging off of the MSN network.)
&lt;/p&gt;
  
&lt;p&gt;
Solution:
&lt;/p&gt;
  
&lt;p&gt;
Upgrade to a version of your respective IM client that is based off of pidgin.&amp;nbsp; Non vulnerable versions of Libpurple are &amp;gt;=2.5.9.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/esV5uzXSYq4" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/esV5uzXSYq4/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/08/24/Vulnerability-in-Pidgin.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=d1458120-e44b-41c6-8c3f-1746718f20ba</guid>
      <pubDate>Mon, 24 Aug 2009 10:00:00 -0600</pubDate>
      <category>Security</category>
      <category>Instant Messaging</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=d1458120-e44b-41c6-8c3f-1746718f20ba</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=d1458120-e44b-41c6-8c3f-1746718f20ba</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/08/24/Vulnerability-in-Pidgin.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=d1458120-e44b-41c6-8c3f-1746718f20ba</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=d1458120-e44b-41c6-8c3f-1746718f20ba</feedburner:origLink></item>
    <item>
      <title>Updates to VMWare Products</title>
      <description>&lt;p&gt;
VMware has released the following new security advisory, &lt;a href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html"&gt;VMSA-2009-0010&lt;/a&gt;
&lt;/p&gt;
  
&lt;p&gt;
This advisory results in updates to
&lt;/p&gt;
  
&lt;pre&gt;
VMware Workstation
VMware Player
VMware ACE
&lt;/pre&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/SNRxv3BxcAE" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/SNRxv3BxcAE/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/08/24/Updates-to-VMWare-Products.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=5dabf6ec-a4bc-47ee-bfec-aaad4ca5bb73</guid>
      <pubDate>Mon, 24 Aug 2009 09:04:00 -0600</pubDate>
      <category>Security</category>
      <category>VMWare</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=5dabf6ec-a4bc-47ee-bfec-aaad4ca5bb73</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=5dabf6ec-a4bc-47ee-bfec-aaad4ca5bb73</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/08/24/Updates-to-VMWare-Products.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=5dabf6ec-a4bc-47ee-bfec-aaad4ca5bb73</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=5dabf6ec-a4bc-47ee-bfec-aaad4ca5bb73</feedburner:origLink></item>
    <item>
      <title>Thunderbird Version 2.0.0.23 released</title>
      <description>&lt;p&gt;
A new version of Thunderbird, version 2.0.0.23, is available.&amp;nbsp; Thus update fixes &lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-42.html"&gt;MFSA 2009-42&lt;/a&gt; (Compromise of SSL-protected communication). 
&lt;/p&gt;
&lt;p&gt;
If you are a Thunderbird user, it is probably best to apply this update as soon as convenient.
&lt;/p&gt;
&lt;p&gt;
Note that, It appears this update, which affects multiple Mozilla products, has changed the rules for security certificates generated with wildcards. More information is available at the &lt;a href="http://www.fourmilab.ch/fourmilog/archives/2009-08/001175.html"&gt;Fourmilab Blog&lt;/a&gt;.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/NqHPaewIY3w" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/NqHPaewIY3w/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/08/24/Thunderbird-Version-20023-released.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=b231c1f6-f9cc-4fd8-abe7-3ce30c07234d</guid>
      <pubDate>Mon, 24 Aug 2009 09:01:00 -0600</pubDate>
      <category>Mozilla</category>
      <category>Thunderbird</category>
      <category>Open Source</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=b231c1f6-f9cc-4fd8-abe7-3ce30c07234d</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=b231c1f6-f9cc-4fd8-abe7-3ce30c07234d</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/08/24/Thunderbird-Version-20023-released.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=b231c1f6-f9cc-4fd8-abe7-3ce30c07234d</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=b231c1f6-f9cc-4fd8-abe7-3ce30c07234d</feedburner:origLink></item>
    <item>
      <title>Microsoft Windows SDK for Windows 7 and .NET Framework 3.5 SP1</title>
      <description>&lt;p&gt;
The Windows SDK for Windows 7 and .NET Framework 3.5 SP1 provides the documentation, samples, header files, libraries, and tools (including C++ compilers) that you need to develop applications to run on Windows 7 and the .NET Framework 3.5 SP1. To build and run .NET Framework applications, you must have the corresponding version of the .NET Framework installed. This SDK is compatible with Visual Studio&amp;reg; 2008, including Visual Studio Express Editions, which are available free of charge. 
&lt;/p&gt;
&lt;p&gt;
Please see the &lt;a href="http://download.microsoft.com/download/8/8/0/8808A472-6450-4723-9C87-977069714B27/ReleaseNotes_Win7RTMSDK.Htm"&gt;Release Notes&lt;/a&gt; for the full list of supported platforms, compilers, and Visual Studio versions and any late breaking issues. For detailed information about the content in this SDK, including a description of new content, please see the Getting Started section in the documentation.
&lt;/p&gt;
&lt;p&gt;
Download at &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=71deb800-c591-4f97-a900-bea146e4fae1"&gt;Microsoft Download&lt;/a&gt;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/RIA6TwygxX8" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/RIA6TwygxX8/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/08/20/Microsoft-Windows-SDK-for-Windows-7-and-NET-Framework-35-SP1.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=b2973c03-4758-4347-bb96-c24eb021271d</guid>
      <pubDate>Thu, 20 Aug 2009 06:30:00 -0600</pubDate>
      <category>Microsoft</category>
      <category>Software Development</category>
      <category>Windows 7</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=b2973c03-4758-4347-bb96-c24eb021271d</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=b2973c03-4758-4347-bb96-c24eb021271d</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/08/20/Microsoft-Windows-SDK-for-Windows-7-and-NET-Framework-35-SP1.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=b2973c03-4758-4347-bb96-c24eb021271d</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=b2973c03-4758-4347-bb96-c24eb021271d</feedburner:origLink></item>
    <item>
      <title>Firefox 3.5 new exploit</title>
      <description>&lt;p&gt;
The &lt;a href="http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/"&gt;Mozilla security blog&lt;/a&gt; confirms an exploit against an unpatched vulnerability Firefox 3.5 exists and has been made public.
&lt;/p&gt;
&lt;p&gt;
Do note that Heisse tried to confirm the vulnerability and only managed a crash on Vista and can&amp;#39;t seem to make it work on Windows 7 RC1 &lt;br /&gt;
&lt;a href="http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761"&gt;http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The mozilla blog above has a workaround by temporary disabling the &lt;code&gt;javascript.options.jit.content&lt;/code&gt; setting in about:config
&lt;/p&gt;
&lt;p&gt;
Alternatively one could install and use &lt;a href="http://noscript.net/"&gt;NoSCript&lt;/a&gt; to disable all javascript by default.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/iQBn8pMu8Rk" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/iQBn8pMu8Rk/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/07/16/Firefox-35-new-exploit.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=ed28faaa-54f5-4810-b88d-a8e96c7c70dc</guid>
      <pubDate>Thu, 16 Jul 2009 10:26:00 -0600</pubDate>
      <category>Firefox</category>
      <category>Mozilla</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=ed28faaa-54f5-4810-b88d-a8e96c7c70dc</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=ed28faaa-54f5-4810-b88d-a8e96c7c70dc</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/07/16/Firefox-35-new-exploit.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=ed28faaa-54f5-4810-b88d-a8e96c7c70dc</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=ed28faaa-54f5-4810-b88d-a8e96c7c70dc</feedburner:origLink></item>
    <item>
      <title>New VMWare Security Advisory</title>
      <description>&lt;p&gt;
VMWare released a new security advisory about a vulnerability in the krb5 (Kerberos) package. The vulnerability allows a remote attacker to cause a DoS or potentially execute arbitrary code on the ESX server.
&lt;/p&gt;
&lt;p&gt;
&lt;br /&gt;
According to the advisory available at &lt;a href="http://lists.vmware.com/pipermail/security-announce/2009/000059.html"&gt;http://lists.vmware.com/pipermail/security-announce/2009/000059.html&lt;/a&gt; all ESX versions are affected (ESXi is not affected), however, the Kerberos package is not installed by default.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/fYN7fxq75FU" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/fYN7fxq75FU/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/07/02/New-VMWare-Security-Advisory.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=e40ae571-2745-4f0f-b6aa-f331c6a1a923</guid>
      <pubDate>Thu, 02 Jul 2009 08:30:00 -0600</pubDate>
      <category>Security</category>
      <category>Virtualization</category>
      <category>VMWare</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=e40ae571-2745-4f0f-b6aa-f331c6a1a923</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=e40ae571-2745-4f0f-b6aa-f331c6a1a923</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/07/02/New-VMWare-Security-Advisory.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=e40ae571-2745-4f0f-b6aa-f331c6a1a923</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=e40ae571-2745-4f0f-b6aa-f331c6a1a923</feedburner:origLink></item>
    <item>
      <title>Microsoft Security Essentials BETA (Morro)</title>
      <description>&lt;p&gt;
This beta is available only to customers in the United States, Israel (English only), People&amp;#39;s Republic of China (Simplified Chinese only) and Brazil (Brazilian Portuguese only).Please visit the &lt;a href="http://www.microsoft.com/security_essentials/resources.aspx"&gt;more information&lt;/a&gt; page to learn more about system requirements, our End User License Agreement and other important information.
&lt;/p&gt;
  
&lt;p&gt;
To get the beta, just &lt;a href="http://go.microsoft.com/fwlink/?LinkID=153446"&gt;click here&lt;/a&gt; or on the button on the top of this page. This will take you to Microsoft Connect where you&amp;#39;ll answer a few questions and then be able to download the Security Essentials beta.
&lt;/p&gt;
  
&lt;p&gt;
&lt;a href="http://www.microsoft.com/security_essentials/"&gt;http://www.microsoft.com/security_essentials/&lt;/a&gt;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/g4oA0lItG68" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/g4oA0lItG68/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/06/23/Microsoft-Security-Essentials-BETA-(Morro).aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=0f23fc87-ef85-49a9-b464-94e1909e9553</guid>
      <pubDate>Tue, 23 Jun 2009 10:17:00 -0600</pubDate>
      <category>Microsoft</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=0f23fc87-ef85-49a9-b464-94e1909e9553</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=0f23fc87-ef85-49a9-b464-94e1909e9553</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/06/23/Microsoft-Security-Essentials-BETA-(Morro).aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=0f23fc87-ef85-49a9-b464-94e1909e9553</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=0f23fc87-ef85-49a9-b464-94e1909e9553</feedburner:origLink></item>
    <item>
      <title>Web Of Trust &amp;ndash; Browser add-on</title>
      <description>&lt;p&gt;
WOT stands for Web Of Trust, it is a community knowledge based system where information on websites are shared. After installing the add-on, the links from search engines are tagged with extra symbols showing whether the site&amp;#39;s &amp;quot;reputation&amp;quot; level. Very simple to understand, red means potentially bad site and green means good site.
&lt;/p&gt;
&lt;p&gt;
WOT is available for both &lt;a href="http://www.mywot.com/en/download/ff"&gt;Firefox&lt;/a&gt; and &lt;a href="http://www.mywot.com/en/download/ie"&gt;IE&lt;/a&gt; . If you choose to use it, remember to contribute back to the project back by helping to rate sites as you visit them.
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/hirantha/~4/6dy-w8mQiSs" height="1" width="1"/&gt;</description>
      <link>http://feedproxy.google.com/~r/hirantha/~3/6dy-w8mQiSs/post.aspx</link>
      <author>hirantha</author>
      <comments>http://www.hirantha.net/blog/post/2009/06/18/Web-Of-Trust-ndash3b-Browser-add-on.aspx#comment</comments>
      <guid isPermaLink="false">http://www.hirantha.net/blog/post.aspx?id=b73f1beb-f877-4304-80b1-44f916e1fb8c</guid>
      <pubDate>Thu, 18 Jun 2009 14:59:00 -0600</pubDate>
      <category>Firefox</category>
      <category>Internet Explorer</category>
      <category>Security</category>
      <dc:publisher>hirantha</dc:publisher>
      <pingback:server>http://www.hirantha.net/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.hirantha.net/blog/post.aspx?id=b73f1beb-f877-4304-80b1-44f916e1fb8c</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.hirantha.net/blog/trackback.axd?id=b73f1beb-f877-4304-80b1-44f916e1fb8c</trackback:ping>
      <wfw:comment>http://www.hirantha.net/blog/post/2009/06/18/Web-Of-Trust-ndash3b-Browser-add-on.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.hirantha.net/blog/syndication.axd?post=b73f1beb-f877-4304-80b1-44f916e1fb8c</wfw:commentRss>
    <feedburner:origLink>http://www.hirantha.net/blog/post.aspx?id=b73f1beb-f877-4304-80b1-44f916e1fb8c</feedburner:origLink></item>
  </channel>
</rss>
