REFRESH to rotate MAAMAW'S CLICKY NOTES thru this space..... Timely Tips, Best of the Boards & More



You'll find great information in this "Read Only" Archive, but remember..... things change.
Be sure to visit the Current Message Board when you're finished here.

We're very friendly, so don't be shy... just jump right in and post your question.
Scams outnumber legitimate biz ops about a bzillion to one, so it's well worth your time.


| View Thread | Return to Index | Read Prev Msg | Read Next Msg |

FIB - Scams 101 - Ye Olde Archives

Good Catch, Robert -- This One Is Serious

Posted By: Tom Brownsword
Tuesday, 3 January 2006, at 10:20 a.m.

In Response To: Security Issue-WMF (Robert N)

> Greetings Fibers!
> I havent posted anything around here in a long time. But I thought I had
> better post this as I run out the door. There is a serious security hole
> in the windows platform. Its about windows metafiles. I wouldnt begin to
> explain it. If you go to grc.com its steve gibsons site. He is on top of
> it. Fib helped out a few years ago so I decided to pass this on. I didnt
> want to see anybody get slammed-have a productive day

Please take a few minutes to go to http://www.grc.com and click on the link to read about this problem and the two work-arounds. One involves de-registering a DLL -- not complicated -- and installing an official patch, which can be a problem at the moment because the download site is apparently overloaded and isn't responding.

Oh -- regardless of the problems involved in reaching the site, DO NOT DOWNLOAD THE PATCH FROM ANY OTHER LOCATION. I trust Steve Gibson and the Internet Storm Center, but I would not trust too many other sources that provide the patch! I can almost see the smiles on the faces of malicious individuals as they prepare to blast out spam e-mail with "links to alternate download sites" -- or even worse, attachments allegedly containing the patch -- either of which will compromise your machine. So don't trust any source except for the one listed on Steve Gibson's site.

And check out the Internet Storm Center (which is run by SANS, an outstanding security organization -- and one of my daily stops as I surf the Internet), too; their Handler's Diary from January 1 (available at http://isc.sans.org/diary.php?rss&storyid=996) contains a no-B.S. plea to use the workarounds until Microsoft gets around to issuing a patch. And be sure to bookmark the GRC page so that you'll have access to the instructions to re-register the DLL and uninstall the unofficial patch once Microsoft issues an official patch.

So please: stop what you're doing, go to the ISC site and read the post, then go to the GRC site and de-register the DLL and install the patch. Now. And then come back and thank Robert.

Thanks for listening,
Tom Brownsword
Certified Computer Security Professional

Protect and Preserve Your Business

Messages in This Thread

Have you read MAAMAW'S CLICKY NOTES today?
Excuse me... You MISSED them??
At the top o' the page in the blue bars (sheesh!).

| View Thread | Return to Index | Read Prev Msg | Read Next Msg |

FIB - Scams 101 - Ye Olde Archives is maintained with WebBBS 3.11.


You'll find great information in this "Read Only" Archive, but remember..... things change.
Be sure to visit the Current Message Board when you're finished here.

We're very friendly, so don't be shy... just jump right in and post your question.
Scams outnumber legitimate biz ops about a bzillion to one, so it's well worth your time.



NOTICE TO SCUMBEEZLES
(you know who you are... you scream "Foul!" when the truth comes out)
        PLEASE READ THIS LEGAL NOTICE CAREFULLY BEFORE YOU FILE A LAWSUIT OR EVEN WASTE TIME THINKING ABOUT IT.  It has been done before, but never successfully.  In fact, the last dodobird who tried it ended up being ordered to pay more than $77,000 in attorney fees ($65,000+ to my attorneys and $12,000+ to my co-defendant's legal advisor).
        If your attorney is worth his salt, he's going to tell you that the expense of filing a lawsuit you can't win is a whole lot worse than any "damages" resulting from messages posted on this insignificant little chunk of cyberspace.
        NEWS FLASH:  I didn't just climb down off that ol' turnip truck yesterday.  I'm well aware that expressing a negative opinion, relating one's personal experience, and restating provable facts are all legal in this country and do not constitute libel, slander, or defamation -- so you don't want to play games with me, and you sure don't want to start something you aren't prepared to finish.  I don't take threats lightly, and I don't accept bribes (or did you call it a "mutually-beneficial arrangement"?).  I'll turn you in faster than you can yell, "ARREST ME, I'M SCUM!!" 
        Do yourself a favor and turn your legal team loose in greener pastures.

        Although we may, from time to time, monitor or review discussions, postings and the like on the Friends In Business (Scams 101) Message Board, we are under no obligation to do so.  We are not responsible or liable for any claim arising from the content of any such discussions or postings or for any error, defamation, libel, slander, omission, falsehood, obscenity, pornography, profanity, danger, or inaccuracy contained in any information contained within such locations on the Site.
        You are prohibited from posting or transmitting any unlawful, threatening, libelous, defamatory, obscene, scandalous, inflammatory, pornographic, or profane materials or any material that could constitute or encourage conduct that would be considered a criminal offense, give rise to civil liability, or otherwise violate any law.  You are likewise prohibited from posting any false claims against any company or individual.  We will fully cooperate with any law enforcement authorities or court order requesting or directing us to disclose the identity of anyone posting any such information or materials.
        By posting messages and/or content on the Friends In Business (Scams 101) Message Board, you give permission for Lesley Fountain/Friends In Business/Shoestring Success Publications to display, distribute and use the posting and content for publication, advertising, promotion, excerption or example. You grant Lesley Fountain/Friends In Business/Shoestring Success Publications complete, perpetual, but non-exclusive rights to use, archive, reproduce, adapt, modify, distribute, sub-license, repurpose, rework, compile, or offer for sale or resale the messages, postings or content appearing on this site in whole or in part, throughout the world and universe, on a royalty-free basis without remuneration.  If you cannot accept or agree with the terms of service for this website and discussion board, you are advised not to post on this board.
        In closing, I would like to remind you once again that it is still legal, in this great country of ours, to express a PERSONAL OPINION, as long as it is presented as opinion and not as fact.
        And finally, all you scammers out there will do well to remember that TRUTH IS AN ABSOLUTE DEFENSE against charges of libel, defamation, and slander... so if you're operating just a hop, skip, and jump ahead of the law, you might want to think twice before doing anything stupid... (AND SHAME ON YOU!!).