Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
August, 2008
TechNet Blogs
>
Robert Hensing's Blog
>
August, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
RedHat Package Signing Server - Pwnd
Posted
over 5 years ago
by
rhensing
1
Comments
EDIT : Holy crap: http://rhn.redhat.com/errata/RHSA-2008-0855.html "In connection with the incident, the intruder was able to sign a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and...
Robert Hensing's Blog
The truth about the Dowd / Sotirov Vista memory protection bypass stuff
Posted
over 5 years ago
by
rhensing
0
Comments
Good short interview with Sotirov who clarifies what actually happened at Blackhat for some folks: http://blogs.zdnet.com/Bott/?p=513 He mentions some interesting stuff - like how they worked with us, we gave them feedback, worked with the other vendors...
Robert Hensing's Blog
Happy Patch Tuesday - Random thoughts
Posted
over 5 years ago
by
rhensing
1
Comments
The SnapShot Viewer 0-day that has seen limited exploitation in the wild is now patched - here's an interesting write-up with some things you may not have known about it. Here's the deal - IE Protected Mode, while not a true defendable security boundary...
Robert Hensing's Blog
VMWare Fail Closed Goat Award
Posted
over 5 years ago
by
rhensing
0
Comments
Here's one for the schadenfreude files - VMWare users running ESX 3.5.x Update 2 will be unable to power on their machines today / tomorrow / everafter until a fix is released by VMWare to correct a licensing bug that causes legit copies of the software...
Robert Hensing's Blog
OpenID Fail Open Goat Award
Posted
over 5 years ago
by
rhensing
0
Comments
Really interesting that CRL checks aren't baked into a lot of open source OpenID providers: http://www.links.org/files/openid-advisory.txt Sun has already updated their web site with this disclaimer: Security Issues OpenID is an untrusted...
Robert Hensing's Blog
We're going for an Olympic Silver(light)
Posted
over 5 years ago
by
rhensing
0
Comments
Sort of an interesting story on how it came to be that Microsoft Silverlight was chosen to broadcast the Olympics via the series of interconnecting tubes: http://news.cnet.com/8301-13860_3-10003752-56.html?tag=nefd.lede I'm guessing Silverlight supports...
Page 1 of 1 (6 items)