<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MS-DEFCON 2: Eight Security Bulletins are out</title>
	<atom:link href="http://www.askwoody.com/2009/msdefcon-2-security-bulletins/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/</link>
	<description>Woody Leonhard’s no-bull news, tips and help for Windows and Office</description>
	<lastBuildDate>Mon, 06 Sep 2010 19:20:23 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: woody</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-305</link>
		<dc:creator>woody</dc:creator>
		<pubDate>Fri, 17 Apr 2009 00:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-305</guid>
		<description>Yep, I disagree. Susan and I often do.

We address different audiences. Susan is more oriented toward businesses, I&#039;m more concerned about home and home office users.

At some point you&#039;ll need to update Internet Explorer. But for now, as long as you&#039;re using Firefox, I don&#039;t see much exposure at all. SANS Internet Storm Center reports that exploit code is publicly available, but I haven&#039;t heard of any working exploits if you&#039;re using Firefox. MS09-014 says, &quot;The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user connects to an attacker&#039;s server by way of the HTTP protocol.&quot;

The other patch, KB 959246, is for a hole that&#039;s been around a long time - the Safari carpet bomb attack. CVE says, &quot;Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X&quot;

While business users may still be running Internet Explorer - and some brave souls run older versions of Safari - I would be very surprised if any of the readers here fell into either group.</description>
		<content:encoded><![CDATA[<p>Yep, I disagree. Susan and I often do.</p>
<p>We address different audiences. Susan is more oriented toward businesses, I&#8217;m more concerned about home and home office users.</p>
<p>At some point you&#8217;ll need to update Internet Explorer. But for now, as long as you&#8217;re using Firefox, I don&#8217;t see much exposure at all. SANS Internet Storm Center reports that exploit code is publicly available, but I haven&#8217;t heard of any working exploits if you&#8217;re using Firefox. MS09-014 says, &#8220;The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user connects to an attacker&#8217;s server by way of the HTTP protocol.&#8221;</p>
<p>The other patch, KB 959246, is for a hole that&#8217;s been around a long time &#8211; the Safari carpet bomb attack. CVE says, &#8220;Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X&#8221;</p>
<p>While business users may still be running Internet Explorer &#8211; and some brave souls run older versions of Safari &#8211; I would be very surprised if any of the readers here fell into either group.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-301</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Thu, 16 Apr 2009 17:04:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-301</guid>
		<description>I noticed that Susan Bradley in Window&#039;s Secrets suggest that KB 963027 and KB 959426 should be installed immediately, even if you use Firefox.

I presume that you disagree.

Thanks</description>
		<content:encoded><![CDATA[<p>I noticed that Susan Bradley in Window&#8217;s Secrets suggest that KB 963027 and KB 959426 should be installed immediately, even if you use Firefox.</p>
<p>I presume that you disagree.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woody</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-296</link>
		<dc:creator>woody</dc:creator>
		<pubDate>Thu, 16 Apr 2009 03:55:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-296</guid>
		<description>RK -

No problem at all. It&#039;s a jungle out there. 

Most people don&#039;t realize that typing KB followed by the number will take you straight to the Knowledge Base article.

&#039;Course, you may have a bit of trouble understanding the article. I frequently do...</description>
		<content:encoded><![CDATA[<p>RK -</p>
<p>No problem at all. It&#8217;s a jungle out there. </p>
<p>Most people don&#8217;t realize that typing KB followed by the number will take you straight to the Knowledge Base article.</p>
<p>&#8216;Course, you may have a bit of trouble understanding the article. I frequently do&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RK</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-295</link>
		<dc:creator>RK</dc:creator>
		<pubDate>Thu, 16 Apr 2009 02:11:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-295</guid>
		<description>Please excuse me, I am not a techie, I barely know that there is a relationship between KB&#039;s and the MSnn-nnn&#039;s. You have to understand that all I see on the MS update screen are KB&#039;s, so you are my go-to guy to let me know if I can paste them up or not.
I want to thank you for your site and what you do for guys like me.</description>
		<content:encoded><![CDATA[<p>Please excuse me, I am not a techie, I barely know that there is a relationship between KB&#8217;s and the MSnn-nnn&#8217;s. You have to understand that all I see on the MS update screen are KB&#8217;s, so you are my go-to guy to let me know if I can paste them up or not.<br />
I want to thank you for your site and what you do for guys like me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woody</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-292</link>
		<dc:creator>woody</dc:creator>
		<pubDate>Thu, 16 Apr 2009 02:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-292</guid>
		<description>RK -

The KB articles you see are secondary articles for the patches.

KB 923561 is for MS09-010

KB 952004 is for MS09-012

KB 956572 is another Knowledge Base article for MS09-012.

I could try to list all of the KB articles for all of the patches, but you&#039;d see hundreds of numbers. Instead, I&#039;ve listed the KB articles that most people see.

If you&#039;re ever curious about a Knowledge Base article, start Firefox and in the address bar type KB followed by the number, then press Enter. You don&#039;t need to type in an URL. Simply typing, say,

KB 956572

will list the KB article as the first result.

As a side-note... there are already LOTS of identified problems with this month&#039;s patches.</description>
		<content:encoded><![CDATA[<p>RK -</p>
<p>The KB articles you see are secondary articles for the patches.</p>
<p>KB 923561 is for MS09-010</p>
<p>KB 952004 is for MS09-012</p>
<p>KB 956572 is another Knowledge Base article for MS09-012.</p>
<p>I could try to list all of the KB articles for all of the patches, but you&#8217;d see hundreds of numbers. Instead, I&#8217;ve listed the KB articles that most people see.</p>
<p>If you&#8217;re ever curious about a Knowledge Base article, start Firefox and in the address bar type KB followed by the number, then press Enter. You don&#8217;t need to type in an URL. Simply typing, say,</p>
<p>KB 956572</p>
<p>will list the KB article as the first result.</p>
<p>As a side-note&#8230; there are already LOTS of identified problems with this month&#8217;s patches.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RK</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-287</link>
		<dc:creator>RK</dc:creator>
		<pubDate>Wed, 15 Apr 2009 16:56:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-287</guid>
		<description>Why am I always misunderstood. I hoped to get a comment or two about the three patches I can d/l, but were not mentioned in Woody&#039;s item. (I thought I conveyed that I understood I might not have to concern myself about items Woody mentions and items not in the d/l list.)</description>
		<content:encoded><![CDATA[<p>Why am I always misunderstood. I hoped to get a comment or two about the three patches I can d/l, but were not mentioned in Woody&#8217;s item. (I thought I conveyed that I understood I might not have to concern myself about items Woody mentions and items not in the d/l list.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woody</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-285</link>
		<dc:creator>woody</dc:creator>
		<pubDate>Wed, 15 Apr 2009 14:31:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-285</guid>
		<description>If the updates aren&#039;t offered to you, and you&#039;re running a &quot;Genuine&quot; copy of Windows XP, you don&#039;t need to worry about them. There are many, many reasons why you may not need specific patches.</description>
		<content:encoded><![CDATA[<p>If the updates aren&#8217;t offered to you, and you&#8217;re running a &#8220;Genuine&#8221; copy of Windows XP, you don&#8217;t need to worry about them. There are many, many reasons why you may not need specific patches.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RK</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-283</link>
		<dc:creator>RK</dc:creator>
		<pubDate>Wed, 15 Apr 2009 14:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-283</guid>
		<description>Hi - I too show three KB&#039;s not mentioned. Also, you mention four KB&#039;s I do not have in my patch list for downloading: 
My patch items you did not mention: 
KB923561,952004,956572.
Your mentioned items I do not have in my patch group:
KB959454,960477,961759,968557.

I realize I may not need some/any of those in this last group due to what MS programs I have on my PC (Dell using WinXP SP3), I may need your comments on those I have that you did not mention. (I also have two others that you have mentioned in previous items, so I discount those.)</description>
		<content:encoded><![CDATA[<p>Hi &#8211; I too show three KB&#8217;s not mentioned. Also, you mention four KB&#8217;s I do not have in my patch list for downloading:<br />
My patch items you did not mention:<br />
KB923561,952004,956572.<br />
Your mentioned items I do not have in my patch group:<br />
KB959454,960477,961759,968557.</p>
<p>I realize I may not need some/any of those in this last group due to what MS programs I have on my PC (Dell using WinXP SP3), I may need your comments on those I have that you did not mention. (I also have two others that you have mentioned in previous items, so I discount those.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woody</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-282</link>
		<dc:creator>woody</dc:creator>
		<pubDate>Wed, 15 Apr 2009 13:41:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-282</guid>
		<description>Todd -

The first two are alternate KB numbers for MS09-012. I suggest you hold off on them.

The last one is an update for Windows Mail. (!) I have no idea why it was offered to you, unless you suddenly started using Windows Mail. If you did, you should switch over to Windows Live Mail, http://download.live.com/wlmail , which is supported. Windows Mail has been orphaned, pretty much.</description>
		<content:encoded><![CDATA[<p>Todd -</p>
<p>The first two are alternate KB numbers for MS09-012. I suggest you hold off on them.</p>
<p>The last one is an update for Windows Mail. (!) I have no idea why it was offered to you, unless you suddenly started using Windows Mail. If you did, you should switch over to Windows Live Mail, <a href="http://download.live.com/wlmail" rel="nofollow">http://download.live.com/wlmail</a> , which is supported. Windows Mail has been orphaned, pretty much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: todd</title>
		<link>http://www.askwoody.com/2009/msdefcon-2-security-bulletins/comment-page-1/#comment-281</link>
		<dc:creator>todd</dc:creator>
		<pubDate>Wed, 15 Apr 2009 08:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.askwoody.com/?p=2643#comment-281</guid>
		<description>Hi I also got 3 other updates which are kb952004,kb956572,and kb905866 which are not listed could u tell me what these do i have a 64-bit vista system . Thanks 4 any help. Your site is very helpful</description>
		<content:encoded><![CDATA[<p>Hi I also got 3 other updates which are kb952004,kb956572,and kb905866 which are not listed could u tell me what these do i have a 64-bit vista system . Thanks 4 any help. Your site is very helpful</p>
]]></content:encoded>
	</item>
</channel>
</rss>
