<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Canadian IT Professionals : Security Bulletins Podcast</title><link>http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx</link><description>Tags: Security Bulletins Podcast</description><dc:language>en-CA</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>“Security Bulletins for the regular IT guy” Podcast – 10/13/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/10/13/security-bulletins-for-the-regular-it-guy-podcast-10-13-2009.aspx</link><pubDate>Tue, 13 Oct 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3286368</guid><dc:creator>Rick Claus</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3286368.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3286368</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3286368</wfw:comment><description>&lt;P&gt;Three guys got together over pints in February 2009 and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought up to them at a User Group meeting they were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were participating in an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;H&lt;/STRONG&gt;ave a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;As always - if you have suggestions on making it better - please pass on your comments. Mail me directly&amp;nbsp; – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE7/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;H4&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode7-10-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Subscribe to the podcast: (so you don't miss an episode)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://feeds.feedburner.com/sbfritg"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://feeds.feedburner.com/sbfritg"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://feeds.feedburner.com/sbfritg"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Bulletins discussed for October 13th, 2009:&lt;/STRONG&gt; &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-050.mspx"&gt;MS09-050 - Critical Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-051.mspx"&gt;MS09-051 - Critical Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-052.mspx"&gt;MS09-052 - Critical Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-053.mspx"&gt;MS09-053 - Important Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-054.mspx"&gt;MS09-054 - Critical Cumulative Security Update for Internet Explorer (974455)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-055.mspx"&gt;MS09-055 - Critical Cumulative Security Update of ActiveX Kill Bits (973525)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-056.mspx"&gt;MS09-056 - Important Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-057.mspx"&gt;MS09-057 - Important Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-058.mspx"&gt;MS09-058 - Important Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-059.mspx"&gt;MS09-059 - Important Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-060.mspx"&gt;MS09-060 - Critical Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx"&gt;MS09-061 - Critical Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx"&gt;MS09-062 - Critical Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Podcast Participants: Pierre Roman and myself.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Additional Technical Show Notes:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Recorded in my backyard on Thanksgiving Weekend in Canada. Clear skies, but darn cold.&amp;nbsp; &lt;/LI&gt;
&lt;LI&gt;Beverage of choice for this edition: leftover Mooshead “Cracked Canoe” ale (&lt;A href="http://www.crackedcanoe.com/"&gt;http://www.crackedcanoe.com/&lt;/A&gt;) from my Thanksgiving festivities. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;PodSafe music from PodSafe Music Network @ &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/"&gt;&lt;STRONG&gt;http://music.podshow.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;. Artist: &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;&lt;STRONG&gt;Derek K Miller&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt;&lt;/P&gt;&lt;!-- AddThis Button BEGIN --&gt;
&lt;SCRIPT type=text/javascript&gt;addthis_pub  = 'CDNDPE';&lt;/SCRIPT&gt;
&lt;A onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout=addthis_close() onclick="return addthis_sendto()" href="http://www.addthis.com/bookmark.php"&gt;&lt;IMG border=0 alt="" src="http://s9.addthis.com/button1-share.gif" width=125 height=16&gt;&lt;/A&gt;
&lt;SCRIPT type=text/javascript src="http://s7.addthis.com/js/152/addthis_widget.js"&gt;&lt;/SCRIPT&gt;
 &lt;!-- AddThis Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3286368" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode7-10-2009.mp3" length="-1" type="application/octet-stream" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 9/8/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/09/08/security-bulletins-for-the-regular-it-guy-podcast-9-8-2009.aspx</link><pubDate>Tue, 08 Sep 2009 19:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3279683</guid><dc:creator>Rick Claus</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3279683.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3279683</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3279683</wfw:comment><description>&lt;P&gt;Three guys got together over pints in February 2009 and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought up to them at a User Group meeting they were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were participating in an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;H&lt;/STRONG&gt;ave a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;As always - if you have suggestions on making it better - please pass on your comments. Mail me directly&amp;nbsp; – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE6/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;H4&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode6-09-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Subscribe to the podcast: (so you don't miss an episode)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Bulletins discussed for September 8th, 2009:&lt;/STRONG&gt; &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-045.mspx"&gt;MS09-045 - Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-046.mspx"&gt;MS09-046 - Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-047.mspx"&gt;MS09-047 - Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-048.mspx"&gt;MS09-048 - Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-049.mspx"&gt;MS09-049 - Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution (970710)&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Podcast Participants: Pierre Roman, Bruce Cowper and myself.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Additional Technical Show Notes:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;The IE8 Block Toolkit that was mentioned during the podcast (in order to block IE8 from downloading on unmanaged machines) can be found &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=21687628-5806-4ba6-9e4e-8e224ec6dd8c&amp;amp;DisplayLang=en"&gt;at this URL&lt;/A&gt;.&amp;nbsp; &lt;/LI&gt;
&lt;LI&gt;Beverages on Pierre’s patio were Alexander Keith’s Red Amber Ale (&lt;A title=http://www.keiths.ca/ href="http://www.keiths.ca/"&gt;http://www.keiths.ca/&lt;/A&gt;)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;PodSafe music from PodSafe Music Network @ &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/"&gt;&lt;STRONG&gt;http://music.podshow.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;. Artist: &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;&lt;STRONG&gt;Derek K Miller&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;BR&gt;&lt;/P&gt;&lt;!-- AddThis Button BEGIN --&gt;
&lt;SCRIPT type=text/javascript&gt;addthis_pub  = 'CDNDPE';&lt;/SCRIPT&gt;
&lt;A onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout=addthis_close() onclick="return addthis_sendto()" href="http://www.addthis.com/bookmark.php"&gt;&lt;IMG border=0 alt="" src="http://s9.addthis.com/button1-share.gif" width=125 height=16&gt;&lt;/A&gt;
&lt;SCRIPT type=text/javascript src="http://s7.addthis.com/js/152/addthis_widget.js"&gt;&lt;/SCRIPT&gt;
 &lt;!-- AddThis Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279683" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode6-09-2009.mp3" length="10533811" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 8/11/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/08/11/security-bulletins-for-the-regular-it-guy-podcast-8-11-2009.aspx</link><pubDate>Tue, 11 Aug 2009 20:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272472</guid><dc:creator>Rick Claus</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3272472.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3272472</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3272472</wfw:comment><description>&lt;P&gt;Three guys got together over pints in February 2009 and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought up to them at a User Group meeting they were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were participating in an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;H&lt;/STRONG&gt;ave a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;As always - if you have suggestions on making it better - please pass on your comments. Mail me directly&amp;nbsp; – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE5/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;H4&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode5-08-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Subscribe to the podcast: (so you don't miss an episode)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Bulletins discussed for August 11th, 2009:&lt;/STRONG&gt; &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-036.mspx"&gt;MS09-036 - Important Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx"&gt;MS09-037 - Critical Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-038.mspx"&gt;MS09-038 - Critical Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx"&gt;MS09-039 - Critical Vulnerabilities in WINS Could Allow Remote Code Execution (969883)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-040.mspx"&gt;MS09-040 - Important Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-041.mspx"&gt;MS09-041 - Important Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-042.mspx"&gt;MS09-042 - Important Vulnerability in Telnet Could Allow Remote Code Execution (960859)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-043.mspx"&gt;MS09-043 - Critical Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-044.mspx"&gt;MS09-044 - Critical Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)&lt;/A&gt;&amp;nbsp; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Podcast Participants: Pierre Roman and myself.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Additional Technical Show Notes:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Pierre and I were in a local pub called &lt;A href="http://www.ottawaplus.ca/ottawa/venues/arrow-and-the-loon"&gt;“The Loon and Arrow”&lt;/A&gt; recording this one – I hope the background noise isn’t too much to handle. For those of you wondering – we were having a pint of Wellington breweries finest &lt;A href="http://www.wellingtonbrewery.ca/?page_id=15"&gt;“County Dark Ale”&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;PodSafe music from PodSafe Music Network @ &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/"&gt;&lt;STRONG&gt;http://music.podshow.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;. Artist: &lt;/STRONG&gt;&lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;&lt;STRONG&gt;Derek K Miller&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;A href="http://social.technet.microsoft.com/bookmarks/en-US/user/Rick%20Claus%20-%20MSFT/" target=_blank&gt;My Shared Bookmarks&lt;/A&gt;&lt;/P&gt;&lt;!-- AddThis Button BEGIN --&gt;
&lt;SCRIPT type=text/javascript&gt;addthis_pub  = 'CDNDPE';&lt;/SCRIPT&gt;
&lt;A onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout=addthis_close() onclick="return addthis_sendto()" href="http://www.addthis.com/bookmark.php"&gt;&lt;IMG border=0 alt="" src="http://s9.addthis.com/button1-share.gif" width=125 height=16&gt;&lt;/A&gt;
&lt;SCRIPT type=text/javascript src="http://s7.addthis.com/js/152/addthis_widget.js"&gt;&lt;/SCRIPT&gt;
 &lt;!-- AddThis Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272472" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode5-08-2009.mp3" length="14113001" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 6/11/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/06/11/security-bulletins-for-the-regular-it-guy-podcast-6-11-2009.aspx</link><pubDate>Thu, 11 Jun 2009 15:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3253350</guid><dc:creator>Rick Claus</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3253350.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3253350</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3253350</wfw:comment><description>&lt;P&gt;Three guys got together over pints in February 2009 and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought up to them at a User Group meeting they were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were participating in an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Well – this is the 4th attempt and it’s 2 days after Patch Tuesday. We’re late. We got caught not being in the same city and got busy like technical professionals do and we ended up here. Sorry about that – we’ll try to not let it happen again. For the 5 of you listening – I’ll buy you a pint next time I’m in town. &lt;/P&gt;
&lt;P&gt;Back to the update - have a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software. There were a bunch of updates this month so we had lots to cover. We still ended up with some nice conversation at the end around lifecycle and patch deployment. &lt;/P&gt;
&lt;P&gt;As always - if you have suggestions on making it better - please pass on your comments. Mail me directly&amp;nbsp; – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE4/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;H4&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode4-06-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Subscribe to the podcast: (so you don't miss an episode)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Bulletins discussed for June 9th, 2009: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;MS09-018 - addresses a vulnerability in Microsoft Windows (KB 971055) – rated Critical&lt;/LI&gt;
&lt;LI&gt;MS09-019 - addresses a vulnerability in Microsoft Internet Explorer (KB 969897) – rated critical&lt;/LI&gt;
&lt;LI&gt;MS09-020 - addresses a vulnerability in Microsoft Internet Information Services (KB 970483) – rated important&lt;/LI&gt;
&lt;LI&gt;MS09-021 - addresses a vulnerability in Microsoft Office (KB 969462) – rated critical&lt;/LI&gt;
&lt;LI&gt;MS09-022 - addresses a vulnerability in Microsoft Windows (KB 961501) – rated Critical&lt;/LI&gt;
&lt;LI&gt;MS09-023 - addresses a vulnerability in Microsoft Windows (KB 963093) – rated Moderate&lt;/LI&gt;
&lt;LI&gt;MS09-024 - addresses a vulnerability in Microsoft Office (KB 957632) – rated critical&lt;/LI&gt;
&lt;LI&gt;MS09-025 - addresses a vulnerability in Microsoft Windows (KB 968537) – rated important&lt;/LI&gt;
&lt;LI&gt;MS09-026 - addresses a vulnerability in Microsoft Windows (KB 970238) – rated important&lt;/LI&gt;
&lt;LI&gt;MS09-027 - addresses a vulnerability in Microsoft Office (KB 969514) – rated Critical&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Podcast Participants: Pierre Roman, Bruce Cowper and myself.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Additional Technical Show Notes:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;From Pierre:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Microsoft Support Lifecycle page:&amp;nbsp; &lt;A href="http://support.microsoft.com/lifecycle"&gt;http://support.microsoft.com/lifecycle&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;List by product families:&amp;nbsp; &lt;A href="http://support.microsoft.com/gp/lifeselect"&gt;http://support.microsoft.com/gp/lifeselect&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here is the official wording of the Security Update policy from Microsoft&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Microsoft will provide security update support for a minimum of 10 years (through the Extended Support phase) for Business and Developer products. The security updates will apply only to the &lt;A href="http://support.microsoft.com/lifecycle/#Service Pack Support"&gt;supported service pack level&lt;/A&gt; for these products.&lt;/P&gt;
&lt;P&gt;Microsoft will provide security update support through the Mainstream Support phase for Consumer, Hardware, Multimedia products. The security updates will apply only to the &lt;A href="http://support.microsoft.com/lifecycle/#Service Pack Support"&gt;supported service pack level&lt;/A&gt; for these products.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both the Mainstream Support and the Extended Support phases require that the product’s &lt;A href="http://support.microsoft.com/lifecycle/#Service Pack Support"&gt;supported service pack level&lt;/A&gt; be installed to continue to receive and install security updates. &lt;/LI&gt;
&lt;LI&gt;Security updates will be available from &lt;A href="http://windowsupdate.microsoft.com/"&gt;Windows Update&lt;/A&gt; during the Mainstream Support phase, and the Extended Support phase (if available). Note that technical limitations in Microsoft Office 2000 require that it remain an exception to this process. Updates will be provided only through the &lt;A href="http://www.microsoft.com/downloads/"&gt;Microsoft Download Center&lt;/A&gt; for the duration of its Support Lifecycle. &lt;/LI&gt;
&lt;LI&gt;Microsoft advises customers to install the latest product releases, security updates, and service packs to remain as secure as possible. Older products, such as Microsoft Windows NT 4.0, may not meet today’s more demanding security requirements. Microsoft may be unable to provide security updates for older products.&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;PodSafe music from PodSafe Music Network @ &lt;A href="http://music.podshow.com/"&gt;http://music.podshow.com/&lt;/A&gt;. Artist: &lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;Derek K Miller&lt;/A&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/P&gt;
&lt;P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;A href="http://social.technet.microsoft.com/bookmarks/en-US/user/Rick%20Claus%20-%20MSFT/" target=_blank&gt;My Shared Bookmarks&lt;/A&gt;&lt;/P&gt;&lt;!-- AddThis Button BEGIN --&gt;
&lt;SCRIPT type=text/javascript&gt;addthis_pub  = 'CDNDPE';&lt;/SCRIPT&gt;
&lt;A onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout=addthis_close() onclick="return addthis_sendto()" href="http://www.addthis.com/bookmark.php"&gt;&lt;IMG border=0 alt="" src="http://s9.addthis.com/button1-share.gif" width=125 height=16&gt;&lt;/A&gt;
&lt;SCRIPT type=text/javascript src="http://s7.addthis.com/js/152/addthis_widget.js"&gt;&lt;/SCRIPT&gt;
 &lt;!-- AddThis Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3253350" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode4-06-2009.mp3" length="30879854" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 05/12/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/05/12/security-bulletins-for-the-regular-it-guy-podcast-05-12-2009.aspx</link><pubDate>Tue, 12 May 2009 21:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3239440</guid><dc:creator>Rick Claus</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3239440.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3239440</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3239440</wfw:comment><description>&lt;P&gt;Three guys got together over pints a while ago and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought to the forefront at a User Group meeting we were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were holding an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 15 minutes OR LESS. this one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Well – here is our 3rd attempt. Have a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software. Since we didn’t get any feedback this time around, we’ve stuck with what we’ve got for a format. If you have suggestions on making it better - please pass on your comments. Mail me directly&amp;nbsp; – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE3/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;H4&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode3-05-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;Subscribe to the podcast: (so you don't miss an episode)&lt;/H4&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Bulletins discussed for May 12th, 2009: MS09-017.&lt;/P&gt;
&lt;P&gt;Podcast Participants: Pierre Roman, Bruce Cowper and myself.&lt;/P&gt;
&lt;H4&gt;Additional Technical Show Notes:&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;From Bruce:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Use the Microsoft Office Isolated Conversion Environment (MOICE) when opening files from unknown or untrusted sources&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The Microsoft Office Isolated Conversion Environment (MOICE) will protect Office 2003 installations by more securely opening Word, Excel, and PowerPoint binary format files.&lt;/P&gt;
&lt;P&gt;To install MOICE, you must have Office 2003 or 2007 Office system installed.&lt;/P&gt;
&lt;P&gt;To install MOICE, you must have the Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats. The compatibility pack is available as a free download from the Microsoft Download Center:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=941b3470-3ae9-4aee-8f43-c6bb74cd1466&amp;amp;displaylang=en"&gt;Download the FileFormatConverters.exe package now&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MOICE requires all updates that are recommended for all Office programs. Visit Microsoft Update to install all recommended updates:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us"&gt;http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;To enable MOICE, change the registered handler for the .ppt, .pot, and .pps file formats. The following table describes the command to enable or to disable MOICE for the .ppt, .pot, and .pps file formats:&lt;/P&gt;
&lt;TABLE border=0 cellSpacing=0 cellPadding=0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width="51%"&gt;
&lt;P&gt;&lt;B&gt;Command to use to enable MOICE to be the registered handler&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width="48%"&gt;
&lt;P&gt;&lt;B&gt;Command to use to disable MOICE as the registered handler&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .PPT=oice.powerpoint.show&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .ppt=PowerPoint.Show.8&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .POT=oice.powerpoint.template&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .pot=PowerPoint.Template.8&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .PPS=oice.powerpoint.slideshow&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top&gt;
&lt;P&gt;ASSOC .pps=PowerPoint.SlideShow.8&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;B&gt;Note&lt;/B&gt; On Windows Vista and Windows Server 2008, the commands above will need to be run from an elevated command prompt.&lt;/P&gt;
&lt;P&gt;For more information on MOICE, see &lt;A href="http://support.microsoft.com/kb/935865"&gt;Microsoft Knowledge Base Article 935865&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Impact of Workaround:&lt;/B&gt; Office 2003 and earlier formatted documents that are converted to the 2007 Microsoft Office System Open XML format by MOICE will not retain macro functionality. Additionally, documents with passwords or that are protected with Digital Rights Management cannot be converted.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use Microsoft Office File Block policy to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The following registry scripts can be used to set the File Block policy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt; Modifying the Registry incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from incorrect modification of the Registry can be solved. Modify the Registry at your own risk.&lt;/P&gt;
&lt;P&gt;For Office 2003&lt;/P&gt;
&lt;P&gt;Windows Registry Editor Version 5.00&lt;/P&gt;
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\PowerPoint\Security\FileOpenBlock]&lt;/P&gt;
&lt;P&gt;"BinaryFiles"=dword:00000001&lt;/P&gt;
&lt;P&gt;Note In order to use 'FileOpenBlock' with Office 2003, all of the latest Office 2003 security updates must be applied.&lt;/P&gt;
&lt;P&gt;Impact of Workaround: Users who have configured the File Block policy and have not configured a special “exempt directory” as discussed in &lt;A href="http://support.microsoft.com/kb/970980"&gt;Microsoft Knowledge Base Article 970980&lt;/A&gt; will be unable to open Office 2003 files or earlier versions in Office 2003 or 2007 Microsoft Office System.&lt;/P&gt;
&lt;P&gt;How to Undo the Workaround:&lt;/P&gt;
&lt;P&gt;For Office 2003&lt;/P&gt;
&lt;P&gt;Windows Registry Editor Version 5.00&lt;/P&gt;
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\PowerPoint\Security\FileOpenBlock]&lt;/P&gt;
&lt;P&gt;"BinaryFiles"=dword:00000000&lt;/P&gt;
&lt;P&gt;Do not open or save Microsoft Office files that you receive from untrusted sources or that you receive unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a specially crafted file.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;BR&gt;From Pierre &lt;BR&gt;&lt;/U&gt;&lt;/STRONG&gt;As it was mentioned in the podcast, here is some information regarding what’s included in the Microsoft Office 2007 Service Pack 2.&lt;/P&gt;
&lt;P&gt;2007 Microsoft Office suite Service Pack 2 (SP2) gives customers the latest updates for the 2007 Office suite. This service pack includes two main categories of fixes: (&lt;A href="http://support.microsoft.com/kb/953195"&gt;http://support.microsoft.com/kb/953195&lt;/A&gt;)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Previously unreleased fixes that were made specifically for this service pack. 
&lt;UL&gt;
&lt;LI&gt;In addition to general product fixes, these fixes include improvements in stability, in performance, and in security. &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;All the public updates, security updates, cumulative updates, and hotfixes that were released through February 2009. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;You can find more information about deploying Office at the &lt;A href="http://blogs.technet.com/odsupport/default.aspx"&gt;Office Deployment Support Team Blog&lt;/A&gt;.&amp;nbsp; Also, Rodney Buike gave a great summary of &lt;A href="http://blogs.technet.com/canitpro/archive/2009/04/28/office-2007-sp2-what-you-need-to-know.aspx"&gt;what you need to know about Office 2007 SP2&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;There are three key changes in Office 2007 with SP2.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;1) Interoperability – Office 2007 SP2 adds support for read, write and save capabilities for the ODF 1.1 file format.&amp;nbsp; There is a great blog post on &lt;A href="http://blogs.msdn.com/dmahugh/archive/2009/04/28/working-with-odf-in-word-2007-sp2.aspx"&gt;Working with ODF in Office 2007 SP2&lt;/A&gt; you should check out, as well as these resources for more specific information on what Word, Excel and PowerPoint support. &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What Word 2007 SP2 supports in the OpenDocument Text (.odt) format: &lt;A href="http://office.microsoft.com/en-us/word/HA102835631033.aspx?pid=CH100626291033"&gt;http://office.microsoft.com/en-us/word/HA102835631033.aspx?pid=CH100626291033&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;What Excel 2007 SP2 supports in the OpenDocument Spreadsheet (.ods) format: &lt;A href="http://office.microsoft.com/en-us/excel/HA102877221033.aspx?pid=CH100648071033"&gt;http://office.microsoft.com/en-us/excel/HA102877221033.aspx?pid=CH100648071033&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;What PowerPoint 2007 SP2 supports in the OpenDocument presentation(.odp) format: &lt;A href="http://office.microsoft.com/en-us/powerpoint/HA102877231033.aspx?pid=CH101956361033"&gt;http://office.microsoft.com/en-us/powerpoint/HA102877231033.aspx?pid=CH101956361033&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;2) Performance – Office 2007 SP2 also adds increased performance and reliability to Office client applications and servers.&amp;nbsp; Outlook 2007 SP2 as an example, includes improved calendaring reliability and performance enhancements which has been a pain for users and administrators.&amp;nbsp; I’ve noticed a significant improvement in performance since I installed SP2.&lt;/P&gt;
&lt;P&gt;3) Converter API – Office 2007 SP2 adds a new API, called the Converter API, which will allow Office developers to include support and conversion options for the ODF 1.1 file format in their Office add-ons and applications.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Slipstreaming a service pack in Office is fairly straight forward. Download the standalone installer (290 MB). The filename is office2007sp2-kb953195-fullfile-en-us.exe in the US.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create two folders one called Extract and Updates for example. (This is really up to you.) &lt;/LI&gt;
&lt;LI&gt;Move the Office 2007 SP2 installer to the Extract folder. And open a command line window (CMD) and use the following command: 
&lt;UL&gt;
&lt;LI&gt;CD C:\Extract office2007sp2-kb953195-fullfile-en-us.exe /extract:C:\Updates &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Agree to the EULA and then close the Installer when completed. &lt;/LI&gt;
&lt;LI&gt;Move the contents of the C:\Updates folder to the Updates folder in your Office 2007 install folder structure. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If you’re using Office 2003 you can find the step by step for Office 2003 for example in the following KB article. &lt;A href="http://support.microsoft.com/kb/555215"&gt;http://support.microsoft.com/kb/555215&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;PodSafe music from PodSafe Music Network @ &lt;A href="http://music.podshow.com/"&gt;http://music.podshow.com/&lt;/A&gt;. Artist: &lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;Derek K Miller&lt;/A&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/P&gt;
&lt;P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;A href="http://social.technet.microsoft.com/bookmarks/en-US/user/Rick%20Claus%20-%20MSFT/" target=_blank&gt;My Shared Bookmarks&lt;/A&gt;&lt;/P&gt;&lt;!-- AddThis Button BEGIN --&gt;
&lt;SCRIPT type=text/javascript&gt;addthis_pub  = 'CDNDPE';&lt;/SCRIPT&gt;
&lt;A onmouseover="return addthis_open(this, '', '[URL]', '[TITLE]')" onmouseout=addthis_close() onclick="return addthis_sendto()" href="http://www.addthis.com/bookmark.php"&gt;&lt;IMG border=0 alt="" src="http://s9.addthis.com/button1-share.gif" width=125 height=16&gt;&lt;/A&gt;
&lt;SCRIPT type=text/javascript src="http://s7.addthis.com/js/152/addthis_widget.js"&gt;&lt;/SCRIPT&gt;
 &lt;!-- AddThis Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3239440" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode3-05-2009.mp3" length="15815141" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 04/14/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/04/14/security-bulletins-for-the-regular-it-guy-podcast-04-14-2009.aspx</link><pubDate>Tue, 14 Apr 2009 21:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226443</guid><dc:creator>Rick Claus</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3226443.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3226443</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3226443</wfw:comment><description>&lt;P&gt;Three guys got together over pints a while ago and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought to the forefront at a User Group meeting we were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were holding an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, Pierre Roman, Bruce Cowper and I decided we would try to help solve the issue of information overload regarding patching and put together a timely podcast to go live each “Patch Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 15 minutes OR LESS. this one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Well – here is our follow up second attempt. Have a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software. We’re still working out the kinks and flow – please let us know what you think and if it has been useful for you. Mail me directly with comments – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE2/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;P&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode2-04-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Subscribe to the podcast: &lt;/STRONG&gt;(so you don't miss an episode)&lt;/P&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Bulletins discussed for April 14th, 2009: MS09-009, MS09-010, MS09-011, MS09-012, MS09-013, MS09-014, MS09-015 and MS09-016.&lt;/P&gt;
&lt;P&gt;Podcast Participants: Pierre Roman (IT Pro Advisor / previously a Senior Technical Account Manager), Bruce Cowper (Chief Security Advisor) and myself.&lt;/P&gt;
&lt;P&gt;PodSafe music from PodSafe Music Network @ &lt;A href="http://music.podshow.com/"&gt;http://music.podshow.com&lt;/A&gt;. Artist: &lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;Derek K Miller&lt;/A&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;A href="http://social.technet.microsoft.com/bookmarks/en-US/user/Rick%20Claus%20-%20MSFT/" target=_blank&gt;My Shared Bookmarks&lt;/A&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3226443" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode2-04-2009.mp3" length="25790950" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item><item><title>“Security Bulletins for the regular IT guy” Podcast – 03/10/2009</title><link>http://blogs.technet.com/canitpro/archive/2009/03/10/security-bulletins-for-the-regular-it-guy-podcast-03-10-2009.aspx</link><pubDate>Tue, 10 Mar 2009 22:21:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3211342</guid><dc:creator>Rick Claus</dc:creator><slash:comments>11</slash:comments><comments>http://blogs.technet.com/canitpro/comments/3211342.aspx</comments><wfw:commentRss>http://blogs.technet.com/canitpro/commentrss.aspx?PostID=3211342</wfw:commentRss><wfw:comment>http://blogs.technet.com/canitpro/rsscomments.aspx?PostID=3211342</wfw:comment><description>&lt;P&gt;Three guys got together over pints a while ago and talked about how one of the issues facing Technical Professionals today is keeping their systems patched and up to date.&amp;nbsp; This issue was brought to the forefront at a User Group meeting we were attending (&lt;A href="http://www.owsug.ca/" target=_blank&gt;Ottawa Windows Server User Group&lt;/A&gt;) where we were holding an “Ask the Microsoft Guy” panel discussion. &lt;/P&gt;
&lt;P&gt;Over pints at &lt;A href="http://ottawa.darcymcgees.com/" target=_blank&gt;D’Arcy McGee’s&lt;/A&gt;, we decided we would try to help solve the issue of information overload and put together a timely podcast to go live each “update Tuesday”.&lt;/P&gt;
&lt;P&gt;Goals:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”. &lt;/LI&gt;
&lt;LI&gt;Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face. &lt;/LI&gt;
&lt;LI&gt;Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion &lt;/LI&gt;
&lt;LI&gt;Keep it top 15 minutes OR LESS. this one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day. &lt;/LI&gt;
&lt;LI&gt;Have fun! &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Well – here is our first attempt. Have a listen directly from the embedded Silverlight player OR subscribe to the specific feed and download it to your iTunes / Zune software. We’re still working out the kinks and flow – please let us know what you think and if it has been useful for you. Mail me directly with comments – &lt;A href="mailto:rick.claus@microsoft.com"&gt;rick.claus@microsoft.com&lt;/A&gt;&lt;/P&gt;&lt;IFRAME style="WIDTH: 500px; HEIGHT: 100px" src="http://silverlight.services.live.com/invoke/58922/SUE1/iframe.html" frameBorder=0 scrolling=no&gt;&lt;/IFRAME&gt;
&lt;P&gt;&lt;STRONG&gt;Direct Download:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=mp3 href="http://media.libsyn.com/media/cdnitmanagers/episode1-03-2009.mp3"&gt;&lt;IMG border=0 alt=mp3 src="http://static.flickr.com/3271/3287072160_72d3db2d98.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Subscribe to the podcast: &lt;/STRONG&gt;(so you don't miss an episode)&lt;/P&gt;
&lt;P&gt;&lt;A title=zunebtn href="zune://subscribe/?Security%20Bulletins%20Podcast%20=http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=zunebtn src="http://static.flickr.com/3539/3286255807_89b4c0383b.jpg"&gt;&lt;/A&gt;&amp;nbsp;&lt;A title=rssbtn href="http://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=rssbtn src="http://static.flickr.com/3489/3287072112_1942c52b51.jpg"&gt;&lt;/A&gt;&lt;A title=itunesbtn href="itpc://blogs.technet.com/canitpro/rss_tag_Security+Bulletins+podcast.xml"&gt;&lt;IMG border=0 alt=itunesbtn src="http://static.flickr.com/3200/3286255751_3d46930296.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; This podcast was produced with the best information available to us at the time of recording. Your primary source for all things Security Bulletin related should always be the &lt;A href="http://blogs.technet.com/msrc" target=_blank&gt;Microsoft Security Response Center blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Bulletins discussed for March 10th, 2009: MS09-006, MS09-007 and MS09-008.&lt;/P&gt;
&lt;P&gt;Podcast Participants: Pierre Roman (IT Pro Advisor / previously a Senior Technical Account Manager), Bruce Cowper (Chief Security Advisor) and myself.&lt;/P&gt;
&lt;P&gt;PodSafe music from PodSafe Music Network @ &lt;A href="http://music.podshow.com/"&gt;http://music.podshow.com&lt;/A&gt;. Artist: &lt;A href="http://music.podshow.com/music/producers/producerLibrary/artistdetails.php?BandHash=0250b0e6c006b4b920ccb81a59066f63"&gt;Derek K Miller&lt;/A&gt;, song - “You’re the Big Sky - rock guitar instrumental” &lt;/P&gt;&lt;IMG alt=Rick src="http://www.canitpro.ca/canitpro/rick-sig.jpg" mce_src="http://www.canitpro.ca/canitpro/rick-sig.jpg"&gt; &lt;BR&gt;&lt;A href="http://blogs.technet.com/canitpro" mce_href="http://blogs.technet.com/canitpro"&gt;IT Pro Team Blog&lt;/A&gt; | &lt;A href="http://blogs.technet.com/cdnitmanagers" mce_href="http://blogs.technet.com/cdnitmanagers"&gt;IT Managers Blog&lt;/A&gt; |&lt;A href="http://twitter.com/rickster_cdn" mce_href="http://twitter.com/rickster_cdn"&gt;Twitter&lt;/A&gt; | &lt;A href="http://www.facebook.com/profile.php?id=620766270" mce_href="http://www.facebook.com/profile.php?id=620766270"&gt;Facebook&lt;/A&gt; | &lt;A href="http://www.linkedin.com/in/rickclaus" mce_href="http://www.linkedin.com/in/rickclaus"&gt;LinkedIn&lt;/A&gt; &lt;BR&gt;&lt;A href="http://social.technet.microsoft.com/bookmarks/en-US/user/Rick%20Claus%20-%20MSFT/" target=_blank&gt;My Shared Bookmarks&lt;/A&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3211342" width="1" height="1"&gt;</description><enclosure url="http://media.libsyn.com/media/cdnitmanagers/episode1-03-2009.mp3" length="15761025" type="audio/mpeg" /><category domain="http://blogs.technet.com/canitpro/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Podcast/default.aspx">Podcast</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Rick+Claus/default.aspx">Rick Claus</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Pierre+Roman/default.aspx">Pierre Roman</category><category domain="http://blogs.technet.com/canitpro/archive/tags/Security+Bulletins+Podcast/default.aspx">Security Bulletins Podcast</category></item></channel></rss>