Saturday, July 05, 2003

browser archive

http://browsers.evolt.org/
LIBRARY OF CONGRESS CLASSIFICATION OUTLINE
Listed are the letters and titles of the main classes of the Library of Congress Classification. Click on any class to view an outline of its subclasses.
These links are to PDF files that require the Adobe Acrobat Reader for viewing and printing.
http://lcweb.loc.gov/catdir/cpso/lcco/lcco.html
Windows Server 2003 Administration Tools Pack
The Windows Server 2003 Administration Tools Pack (adminpak.msi) provides server management tools that allow administrators to remotely manage Windows 2000 Servers & Windows Server 2003 family servers. This is the final version (build 3790) of the adminpak.msi file.
http://microsoft.com/downloads/details.aspx?FamilyId=C16AE515-C8F4-47EF-A1E4-A8DCBACFF8E3&displaylang=en

Answers to frequently asked questions about Windows NT, Windows 2000, SQL Server, Exchange Server and Outlook, IIS and more! Brought to you by John Savill and the Windows & .NET Magazine Network.

The downloadable version of the FAQ is no longer available, but the FAQ will be included in the Windows & .NET Magazine article archive CD. It was just getting too big and taking too long to create it anymore!
http://www.ntfaq.com/

Thursday, July 03, 2003

ZoneLabs Won't Fix Hole In Free Firewall
July 1, 2003
By: Mark Hachman

ZoneLabs said it will not fix a vulnerability found in the freeware version of its ZoneAlarm firewall. The company said the vulnerability was a problem found in Windows, not its firewall, and that it would require the hacker equivalent of "brain surgery" to exploit.
Instead, ZoneLabs executives said that the vulnerability could be protected against by using one of its paid products: ZoneAlarm Plus, ZoneAlarm Pro, or its Integrity enterprise system.

According to the posting to the BugTraq mailing list, the vulnerability involves the Windows shell32.dll file, which can invoke the ShellExecute function. When one of the parameters of ShellExecute is set to a Web address, the web browser is prompted to access the web site in question -- and, under most ZoneAlarm configurations, is allowed to freely access web sites without the express permission of the user.

According to the poster, "aceh", that browser could quickly access a malicious web site, funnel a short string of confidential information (such as a username and password) and quickly redirect itself to an innocuous and trusted web site.

Although not stated expressly, the vulnerability appears to first require a Trojan to be loaded onto the user's machine via an email virus or some other means. However, "aceh" concluded that the vulnerability is common to all of the freeware versions of ZoneAlarm. Executives at ZoneLabs, however, said that the free version of ZoneAlarm provides adequate protection.

http://www.securityfocus.com/archive/1/326371

http://www.extremetech.com/print_article/0,3998,a=44172,00.asp

Wednesday, July 02, 2003

National Security Agency Security Recommendation Guides Windows XP Guides Download Page
Security Recommendation Guides
The following files are provided in PDF format. IMPORTANT: Please read our Legal Notice before using these guides.

Guide to Securing Microsoft Windows XP (1,778KB) 141 pages

Windows XP Security Recommendation Guides Zipped Archive

For your convenience the entire set of Windows XP Security Recommendation Guides in this release are also provided in a zipped archive format. A separate utility program is needed to decompress and extract the collection of files from the zipped archive. Programs designed to read ".zip" files are available from popular software download sites on the Internet.
http://www.nsa.gov/snac/winxp/download.htm