Tuesday, December 16, 2008

Firefox: most vulnerable Windows application


A firm Bit9, who listed 12 most vulnerable applications on windows,has taken Firefox on top of the list.

The browser has earned the reputation from Mozilla patching 10 vulnerabilities which could be used to gain control, access, or execute miscellaneous code via buffer overflow, malformed URI links, javascript, documents and third party tools.

The browser is well respected throughout its open source community. Users can download add-ons, themes and many other tweaks that users can be used to adjust, modify and tweak their browser for maximum performance and appearance.

List of the top 12 vulnerable applications:
  1. Mozilla Firefox
  2. Adobe Flash and Adobe Acrobat
  3. EMC VMware Player,Workstation and other products
  4. Sun Java JDK and JRE, Sun Java Runtime Environment (JRE)
  5. Apple QuickTime, Safari and iTunes
  6. Symantec Norton products (all flavors 2006 to 2008)
  7. Trend Micro OfficeScan
  8. Citrix Products
  9. Aurigma Image Uploader, Lycos FileUploader
  10. Skype
  11. Yahoo Assistant
  12. Microsoft Windows Live (MSN) Messenger

ZoneAlarm 8.0.065.0


ZoneAlarm is an easy-to-use firewall that blocks hackers and other unknown threats.
  • Intrusion Blocking systematically identifies hackers and blocks access attempts.
  • Stealth Mode automatically makes your computer invisible to anyone on the Internet.
  • Automatic Program Configuration provides safety and simplicity by automatically configuring programs. Automatically decides whether to allow or deny Internet access to individual programs.
  • Expert Controls give savvy users precise control over security settings.
This free version is for non-commercial use only.

ZoneAlarm

Notepad++ v5.1.2 Released


Released: 12.14.08


Whats New:
1. Fix localization (Japanese/Cyrillic/Hebrew...) display bug under Notepad++ Unicode version.
2. Fix Find in Files search in both Unicode/ANSI files.
3. Make Find in files thread-less to improve the performance and to avoid the crash.
4. Fix crash bug while loading File of User Defined Language.
5. Fix writing a key in registry while preference dialog launches
6. Fix crash in File Dialog if too many languages or extensions were added.
7. Fix memory leak when a file cannot be opened if it consumes too much memory.
8. Fix a vista issue : prevent Notepad++ save files to "virtual store" under vista.
9. Fusion 2 commands "activate main view" and "activate sub view" in "Focus the other view".
10. Fix close all files/app exit cancel bug.
11. Fix default button problem in Find in Files dialog.
12. Fix caret position moving problem after loading a session.
13. Fix bug when pasting to bookmarked lines in Unicode version.

NotePad Forum | Notepad++

Tuesday, November 18, 2008

Bonjour - Zeroconf Service discovery protocol


Hi everyone, sorry i have been too busy since last 2 months in my new job. You know guys when we change job we need to learn lots of new things (Specifically, we IT guys :( ).

Now everyone has this problem that which protocol should be used for local corporate LAN chat.Basically now a days many things are available but i think most popular one is jabber.

You can simple go to jabber.org, get good open source/freeware jabber server and client, and chat on LAN. But this needs your company to install jabber server on local server, and they can see what you are chatting in logs :).

So better you get bonjour from Apple, which is a zero config protol. It will automatically detects all PCs and printers in LAN and show you in you buddy list. You just get it from apple's site and intall you specific OS version. As a client, you can use Pidgin.

Check the image for pidgin configuration of bonjour on you local network.You must install the bonjour library from Apple which is free.

Bonjour | Pidgin

Saturday, September 13, 2008

Privacy/security breach?IPhone Snaps Everything You Do


What is apple upto? I mean... this is totally a privacy breach for any user who just uses a iPhone because he likes it.

wired.com says
While demonstrating how to break the iPhone's passcode lock in a webcast, iPhone hacker and data-forensics expert Jonathan Zdziarski explained that the popular handset snaps a screenshot of your most recent action -- regardless of whether it's sending a text message, e-mailing or browsing a web page -- in order to cache it. This is purely for aesthetic purposes: When an iPhone user taps the Home button, the window of the application you have open shrinks and disappears. In order to create that shrinking effect, the iPhone snaps a screenshot, Zdziarski said.

The phone presumably deletes the image after you close the application. But anyone who understands data is aware that in most cases, deletion does not permanently remove files from a storage device. Therefore, forensics experts have used this security flaw to gather evidence against criminals convicted of rape, murder or drug deals, Zdziarski said.

"There's no way to prevent it," Zdziarski said during the webcast. "I'm kind of divided on it. I hope Apple fixes it because it's a significant privacy leak, but at the same time it's been useful for investigating criminals."

Now what is that means?It means.. to catch such people,everyone is a suspect?And every user who buys an iPhone will have to suffer such things? This is not the right feature if its breaching your security and privacy.I hope wpple will do something in this regard.

iPhone 2.1 firmware

Apple has released new iPhone 2.1 software on its iTunes online service that offers to decrease dropped calls, improve the battery life, improve e-mail reliability, improve text messaging notification, reduce 3rd-party application crashes and reduce the time it takes to sync the device with a computer.

Users have noticed more "bars" on the connection meter and have reported that it was faster performing key tasks. Last month's update from Apple drew some criticism from users that claimed that it did not enhance access to high-speed data networks as Apple had predicted. In this update, Apple also patched 8 security vulnerabilities including the "passcode bug" they fixed last January but failed to include in the July iPhone 2.0 update.

It seems now iPhone will be more of interest if it gives what it claims to provide!What you say?Lets hope this will bring it to what people expect from apple.

Saturday, September 6, 2008

Google : Chrome EULA Update!


We just have discussed the issues about 'chrome is having and Google has done it right!Google has changed their EULA and now its your rights on your content,finally :).

The search engine has been quick to rectify this issue, attributing the whole issue to accidental copy and paste. Under Section 11 of Google's Universal Terms of Service, Google retains a license to transmit or display content through its services, as per US copyright law. However, the section in Chrome was not updated. Mike Yang, Senior Product Counsel at Google, writes:
"[Our] license is limited to providing the service. In Gmail, for example, the terms specifically disclaim our ownership right to Gmail content. So for Google Chrome, only the first sentence of Section 11 should have applied. We're sorry we overlooked this, but we've fixed it now..."
The updated EULA now reads:
"You retain copyright and any other rights you already hold in Content which you submit, post or display on or through, the Services." And, yes, these terms are retroactive."