Security

共 234 篇文章。

Fighting against spamming

• Security

It seems that my blog get spammed by various parties. I hereby declare a war against spamming, also for e-mails.

You’re being watched and identified from this point on. Once you spam my blog, I guarantee that your activations are being tracked and analyzed with my knowledge base system and finally I will be able to keep everything from you off my site.

参与评论

不按RFC走?那你必然会遇到麻烦

• Security

RFC也许有时让人觉得过分冗长,但是如果你没有耐心去完全实现它,它就会在不经意间突然咬你一口。

可怜的端木就被咬了……

今天这家伙发了一封邮件给我。

嗯?3.5分?

阅读全文… ( 本文约 273 字,阅读大致需要 1 分钟 )

Solving issue appeared after Windows XP SP2

• Security

Windows XP SP2 is an important update and have introduced many security improvements. However, after installing Windows XP SP2, some graphical identity systems will be rendered to be useless.

The root cause is that these systems makes use of a special MIME type: x-xbitmap, or so called “XBM”.

XBM is originally developed by the X community. Presently it is uncommon on the web. However, banks like China Merchant Bank utilizies this format for authentication.

阅读全文… ( 本文约 130 字,阅读大致需要 1 分钟 )

Seems that Windows XP SP2 CHS has not released after ENU edition released for 13 days

• Security

It seems that Microsoft is still testing/finalizing the Windows XP SP2 release. Up to today’s check, it is not released here. Interestingly, a Korean edition (Korean is another asian language, which is usually listed with Chinese) has been released much more earlier, even before Japanese and Chinese (both Simplified Chinese and Traditional Chinese) editions.

阅读全文… ( 本文约 109 字,阅读大致需要 1 分钟 )

Aha... MD5 is vulnerable

• Security

Researchers have announced preliminary indications of previously unknown vulnerabilities in popular security algorithms that could permit hackers to easily install undetectable back doors into computer code or to counterfeit electronic signatures. French computer scientist Antoine Joux reported on Aug. 12 his discovery of a flaw in the MD5 algorithm, which is often used with digital signatures. The algorithm is known as a hash function, which extrapolates from all input a unique fingerprint; however, if a hacker could produce the same fingerprint with a different input stream, then the resulting hash collision would authenticate software as safe to download and execute even though it contains a back door. MD5 is employed by the open-source Apache Web server product as well as Sun Microsystems’ Solaris Fingerprint Database, and the flaw Joux uncovered means that a hacker can produce one hash collision in a few hours on a standard PC. Meanwhile, four Chinese researchers issued a paper reporting that the SHA-0 Secure Hash Algorithm could be subverted, while Israel Institute of Technology researchers Eli Biham and Rafi Chen revealed at the Crypto 2000 conference on Aug. 17 that they were investigating possible flaws in the SHA-1 algorithm, the only signing algorithm approved for use in the U.S. Digital Signature Standard. SHA-1, which is incorporated into popular programs such as SSL and PGP, is thought to be secure because knowingly producing hash collisions via existing methods is impossible. SHA-1 depends on a computer executing a routine 80 times as it tries to create a unique fingerprint, and Biham declared that he was able to copy the fingerprint for 36 of those 80 executions. If SHA-1 shares similar vulnerabilities with SHA-0, then attempts to falsify a fingerprint would be sped up about 500-fold.

阅读全文… ( 本文约 293 字,阅读大致需要 2 分钟 )

一个没留神,中了3721……

• Security

昨天由于笨球咕噜开发的垃圾产品,不得不放松了Internet Explorer的zone设置,今天上着上着网,突然蹦出一个「您已经成功地安装了3721」。

毋庸讳言,3721是最让我反感的软件,我不知道现在它如何,那不重要——这东西的存在让我觉得不舒服,我不需要什么助手,更不需要文件系统驱动,虽然也许新版本根本不安装驱动,但我还是立即想了所有的办法拆掉了它。

3721似乎比以前更容易卸载了,但我明天将立即检查文件系统中所有的文件。如此如临大敌地对付一个软件,在我看来是很荒谬的事情。

阅读全文… ( 本文约 452 字,阅读大致需要 1 分钟 )