ANI vulnerability 3rd party patch available

A 3rd party patch to mitigate exposure to the ANI vulnerability (mouse animated curser) is available free to the public.

I have been testing it this evening and it appears to be effective and safe.

If you run any browser or email client on the Windows 2000, XP, 2003 or Vista platform, you might consider this patch until Microsoft releases their official patch.

The link to the patch is at the very bottom of that page.

FireFox also vulnerable to the ANI exploit

From BugTraq at

"Determina also discovered that under certain circumstances Mozilla Firefox uses the same underlying Windows code for processing ANI files, and can be exploited similarly to Internet Explorer."

Best to be practicing ultra safe web habits until a patch is released. Also (as usual) keep your Spyware shields and AV updated.

ANI vulnerability: Windows Zero Day attack

The last few days saw the discovery of another very serious exploit that takes advantage of a bug in the way Windows XP, Vista and 2003 and Outlook handles animated mouse cursers. A longer list of all vulnerable products is available here. Microsoft has no fix available yet.

As of at least yesterday (and probably longer) researchers have found numerous web sites that are delivering malicious Trojans via this vector. Craig Schmugar at McAfee reports that this includes some fairly popular and supposedly trustworthy sites like the Dolphins Superbowl site, which is compromised and forwards visiters to non-trusted servers.

So far the best advice is to completely turn off email previewing in all versions of Outlook and Outlook Express, to help mitigate infection via spam. Don't open any spam, especially unexpected emails with attachments. And finally don't visit infected websites - which begs the question of how would we know it's infected?

Until a patch is available, be extra careful!

Microsoft's future

I know at least one of the people on my friends list is currently employed by MS. I suspect one or two others may be as well.

If you don't already follow the two bloggers linked below, their most recent articles really seem to nail some of the company's issues, and contain some excellent suggestions to improve things. Assuming of course that's even a remote possibility. (Doubt)

Long reads, but good.

Enjoy . . .

If you have a cat or dog . . .

Thought you might want to know about this:

Turns out that the recalled pet food was contaminated by something called aminopterin, used in China (among other places) as a rat poison. Possibly came from gluten obtained from China, to be used as a thickener for the gravy in recalled wet pet foods.

"The Food and Drug Administration (FDA) reports that the lethal concentration of the chemical is three parts per million (ppm) for rats; the amount found in the contaminated [pet] food samples was 40 ppm. There is speculation that the poison got into the chow because Chinese farmers sprayed their crops, including wheat, with it to protect them from hungry rodents."

Two of my neighbors lost their cats last week during my absence to this poison. I am really grateful that we have fed our cat more healthy fare for her entire life than wet canned pet food.

Also there are reports around the Internet that canned pet food from outside the range of batches and dates specified by the manufacterer are also poisoning pets.

If somehow you did not see the news all last week about the recall, here is the main official page for you with links to the official brands, types and batches involved.


Windows Server 2003 SP2 released today

I lied, one more update today before I go finish packing.

Microsoft quietly released Service Pack 2 for Windows Server 2003 - all editions. Their website calls it a release candidate, but given it's presence on the official update site, I suspect it's the final version.

You can get it via the update site, or if you prefer (as I do) to get it as one download and apply it offline, you can get the entire package here:

Along with a complete rollup of all critical updates released since SP1, it also includes some new features, which depend on whether you are running the standard, R2 or SMS versions.

See the FAQs for more information.

And now I am outta here - see you in two weeks!

Thinking about buying a car from eBay?

One of the more advanced trojans to hit is in the wild now. If you click slideshow attachments in infected emails, it drops a program that sets up a man in the middle attack between you and ebay motors. You send money, the crook gets it, the seller never knows you exist.

"How to avoid being victimized? As always, never click on e-mail attachments from sources you don't trust."

Palm PDA DST Update info

Thanks to for the Palm PDA DST update link at

DST updates for Apple and Linux

A big thank you to for DST info on Apple and Linux systems.

For most Linux distributions, you can find background info and links to update your system for the upcoming Daylight Saving Time changes at For those of you with Gentoo, just an "emerge sys-libs/timezone-data" should do the trick.

Apple users should refer to to find patches or instructions to fix the DST changes manually, depending on your OS version. You will also find links on that page containing special instructions to update your Java and WebObjects environments.

For everyone, Sun has posted DST instructions for Java at In certain cases (but not all) you may wish to remove older versions of Java if you update to the latest and greatest. Directions for that process may be found at

For those just joining in, the original post concerning DST updates for Windows, Windows Mobile, Outlook etc may be found at

Deadline for doing these updates is this coming Saturday, March 10th. If you miss the deadline, don't panic. You can still do the updates at any time, but your calendars and clocks may not show the correct time until you complete the task.


Windows Live One Care is destroying entire local email storage files

It appears that a very serious bug in Microsoft Live One Care Anti Virus is causing much grief among users. If it detects a virus on an incoming email, the next time it does a system scan it may in fact delete the entire PST file for Outlook (all versions) or the entire folder store where that accounts email is cached in Outlook Express. And we are talking hard delete, not recycle bin. The only way to recover all your email is via a file recovery utility that scans the hard drive for deleted files, and that assumes that you have not overwritten the file with cached browser files while searching for a solution . . .

Live One Care has not yet fixed this problem - and in fact it may not get fixed until they go to the beta for version 2.x.

AppScout has a full summary of the problem as well as a work around posted. Look near the bottom of that page to find the workaround.

To add insult to injury, Microsofts Live One Care recently came in dead last in a third party comparison test conducted by AV

(All links open in a new tab or window.)

Edit: It appears that some, but not all, users were able to retrieve their lost PST file from Live One Care's quarantine. Not clear on details on why the difference, your mileage may vary.

Windows Mobile also (finally) gets a DST patch

If you need it, get it . . .


Final countdown to DST change

See my previous article at . . .

Updated to include Windows 2000 Professional and Server.

Programmers personality quiz

Your programmer personality type is:


You're a Doer.

You are very quick at getting tasks done. You believe the outcome is the most
important part of a task and the faster you can reach that outcome the better.
After all, time is money.

You like coding at a Low level.

You're from the old school of programming and believe that you should have an
intimate relationship with the computer. You don't mind juggling registers
around and spending hours getting a 5% performance increase in an algorithm.

You work best in a Solo situation.

The best way to program is by yourself. There's no communication problems, you
know every part of the code allowing you to write the best programs possible.

You are a Conservative programmer.

The less code you write, the less chance there is of it containing a bug. You
write short and to the point code that gets the job done efficiently.

Take the test.

Urgent for WordPress blog users!

WordPress 2.1.1 compromised, upgrade to 2.1.2 ASAP

If any of you administer a blog based on WordPress and you recently upgraded to version 2.1.1 then you should immediately upgrade to 2.1.2 before your site is 0wn3d. Earlier versions of the 2.x release series are safer, although 2.1.x has numerous bug fixes and minor security fixes.

(Links open in a new tab or window.)

"It was determined that a cracker had gained user-level access to one of the servers that powers, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution."

If you are a shared WordPress blog user - you might want to ping your site admin about this today.


RFID questions

I'm researching for a soon to appear article about RFID. One interesting sidebar is about disabling RFID tags in passports or credit cards. Devices for such exist, but I can't find any information about the legalities of such an action. Has anyone spotted some good sources online?

BTW, whatever you do, don't use a microwave to kill embedded RFID tags. Yes - it will destroy the tag - along with the material in which it's installed. It may also damage your microwave.