風吹くままに

Drift in the wind.

Subscribe to RSS feed

Sticky post

Customizing Your Opera Weblog's Design

, ,

Opera community changed their design.
The following is correspondence between the images of "Change Design" page(click on "My account" > "CHANGE DESIGN of DESIGN") and CSSs.

[NOTE]
Correspondence between the number of the image below and the numbered heading.

Read more...

Sticky post

How To Customize Your Blog, Without The Knowledge Of CSS. (Only OPERA Weblog)

,

Don't use this explanation. Opera community changed their original design.
Even if I take time, I will update this topic.

CSSの知識なしにblogをカスタマイズするためのガイドです。(OPERA Weblog 限定)
[GUIDE-1] How to customize your background color and image on both sides.
両サイドの変更方法。
[GUIDE-2] How to decorate your title of an article.
記事のタイトルの飾りつけ。
[For your information] How To Get RGB Color[/URL]
参考資料、RGBカラーの取得方法。

About Several Updates of Softwares

, , ,

1/ Apple QuickTime
Apple released an update of QuickTime, fixing at least 11 security holes in it for both Mac and Windows.
Windows QuickTime users will need to use the bundled Apple Software Update application.

2/ Symantec Norton
Symantec pluged two critical holes in ActivX control(SYMADATA.DLL).
Following versions are affected:
Norton 360 1.0
Norton AntiVirus Windows 2006 - 2008
Norton Internet Security 2006 - 2008
Norton System Works 2006 - 2008

A corrected version of the ActiveX is available for download.

3/ Avast anti-virus
Avast is anti-virus scanner and is free for home users.
Avast v4.8 adds anti-rootlit and anti-spyware functionarity.
To download its free edition, access HERE.

4/ VLC Media Player
For some time now, there have been several open security holes in VLC Media Player, MPlayer and Xine. VLC was released the latest version(0.8.6f) to plug several security holes.
To download it, access HERE.


About Several Vulnerabilities of Thunderbird

, ,

Mozilla released the latest version(2.0.0.13) which pluged 10 security holes of Firefox.
However, Mozilla has not released the fixed version of Thunderbird(E-Mail cleiant of Mozilla).
It shares five of the vulunerabilityies because Thunderbird shares the browser engine with Firefox. And It could be vulnerable if JavaScript were to be enabled in mail.
Mozilla's David Ascher said that its paches will not be available for several weeks.
And he also said "This is not the default setting, and we strongly discourage users from running JavaScript in mail."

Privilege Escalation via Panda Security Suite

,

A bug in a kernel driver in Panda’s Internet-Security 2008 and Antivirus+Firewall 2008 can be exploited by attackers to escalate their privileges.

See also:
Panda Internet Security/Antivirus+Firewall 2008 cpoint.sys Kernel Driver Memory Corruption Vulnerability, security advisory from Tobias Klein
Vulnerability detected in the Internet protection level control in Panda Internet Security 2008, security advisory and hotfix download from Panda
Vulnerability detected in the Internet protection level control in Panda Antivirus + Firewall 2008,,security advisory and hotfix download from Panda

Spywareblaster Has Been Upgraded To Version 4

, ,

SpywareBlaster 4.0 Download
http://www.javacoolsoftware.com/sbdownload.html

Caution
JavacoolSoftware, the maker of Spywareblaster, recommend you uninstall the previous version before upgrading to the new one.

Thunderbird 2.0.0.12 Is Now Available

,

Mozilla urged users of Thunderbird to update to its new version(2.0.0.12). In its new version, Mozilla fixed five vulnerabilities. One of which is categorized as critical. This vulnerability allow that attackers can inject malicious code by means of special crafted E-Mails.

See also :
http://Fixed in Thunderbird 2.0.0.12
Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability

Steer Clear of Vista Service Pack

,

08 Feb. 2008, George Ou posted the blog following message.

I completed the first two installations of Vista SP1 RTM upgrade last night on to my primary desktop computer and my first Vista laptop meant to be my new work computer. The result is a near death experience with my desktop computer, and then a real death experience with the laptop



18 Feb. 2008, heiseSecurity said that we should not install Vista SP1, based on their test result.

Despite the Service Pack, Vista still doesn't correctly handle backup archives which were generated with its predecessor Windows XP. There is no noticeable improvement to notebook battery life either. When tested one notebook only ran for half as long as when running Windows XP. Eight further notebooks didn't run differently in the c't test. There even were some entirely new issues, for example with virus scanners. Norton Antivirus produces error messages, and Bitdefender Antivirus can't be installed any more at all.



20 Feb. 2008, Microsoft has published a list of programs that may "experience a loss of functionality".

20 Feb. 2008, InfoWorld said :

Update has been pulled from Windows Update, but Microsoft has not yet produced a fix for users whose machines either won't boot or reboot constantly... Responding to reports of endlessly rebooting PCs that flooded support newsgroups last week, Microsoft said on Tuesday it had pulled an update designed to prep Windows Vista for Service Pack 1.



Most of us shouldn’t even think about installing SP1 until things are cleared up.

Opera 9.26 is now available.

,

Opera 9.26 closes three security holes.
The latest version is available for Windows, MacOS, Linux, FreeBSD, and Solaris.

From heiseSecurity

The new release remedies three security vulnerabilities, one of which allows attackers to manipulate file input dialogues. When users enter a file name, attackers can cause certain input to be suppressed. As a result, users might upload a file they were not expecting.

Using a MouseEvent – dispatchEvent, a "click" can be sent to an HTML file input element, allowing user input to be selectively captured. This could allow an attacker to construct an arbitrary file path that is subsequently used to upload a file of the attacker's choosing.

Opera has categorised the problem as only moderately dangerous. Nonetheless, the Norwegians were upset when Mozilla informed them of the flaw just one day before making the news public. The flaw has already been remedied in Firefox and SeaMonkey.

Another flaw can be exploited in cross-site scripting attacks, and a third can be used to execute arbitrary scripts via image properties. For more details, see the Opera change log.

Adobe had pushed out the latest version of Adobe Reader

,

Adobe Reader 8.1.2 is now available.
Adobe had released an update to its Adobe Reader that corrects more than two dozen bugs, including several security holes.
One of security holes is actively being exploited to break into Microsoft Windows computers.
And now, attackers have started to exploit its vulnerabilities.

To update:
http://www.adobe.com/products/acrobat/readstep2.html

For Japanese:
http://www.adobe.com/jp/products/acrobat/readstep2.html
February 2012
S M T W T F S
January 2012March 2012
1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29