greg hughes - dot net
Note that the contents of this site represent my own thoughts and opinions, not those of anyone else - like my employer - or even my dog for that matter. Besides, the dog would post things that make sense. I don't.
 Tuesday, January 11, 2005
Microsoft today released three security bulletins, two of which are classified as “Critical” severity, and related patches to resolve the issues described in each bulletin:
| Jan 11, 2005 |
Vulnerability in HTML Help Could Allow Code Execution (890175): MS05-001
Affected Software: Windows NT Server 4.0, Windows NT Server 4.0, Enterprise Edition, Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows 98, Windows 98 SE, Windows Me, Internet Explorer 6 |
Windows NT4 Service Pack 6a, Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows XP Service Pack 2, Windows Server 2003 Gold, Windows 98 Gold, Windows 98 SE Gold, Windows 98 SP1, Windows Me Gold, Internet Explorer 6 SP1 |
Critical |
| Jan 11, 2005 |
Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711): MS05-002
Affected Software: Windows NT Server 4.0, Windows NT Server 4.0, Enterprise Edition, Windows NT Server 4.0, Terminal Server Edition, Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition, Windows 98, Windows 98 SE, Windows Me |
Windows NT4 Service Pack 6a, Windows NT4 Terminal Server Service Pack 6, Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows Server 2003 Gold, Windows 98 Gold, Windows 98 SE Gold, Windows 98 SP1, Windows Me Gold |
Critical |
| Jan 11, 2005 |
Vulnerability in the Indexing Service Could Allow Remote Code Execution (871250): MS05-003
Affected Software: Windows 2000 Advanced Server, Windows 2000 Datacenter Server, Windows 2000 Professional, Windows 2000 Server, Windows XP Home Edition, Windows XP Professional, Windows Server 2003 for Small Business Server, Windows Server 2003, Datacenter Edition, Windows Server 2003, Enterprise Edition, Windows Server 2003, Standard Edition, Windows Server 2003, Web Edition |
Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, Windows XP Service Pack 1, Windows Server 2003 Gold |
Important |
I was wide awake at about 4am today, looking around for a fast way to get live syndicated content (need it to always be up-to-date) from a weblog’s RSS feed to the home page of a web site I am maintaining for non-profit organization. Cops on Top has climbers in Africa this week for a memorial mountain climbing expedition to Kilimanjaro, and they are sending electronic communications from the field via email and phone calls. The messages can show up on the weblog in real time, without anyone else’s intervention. So, I wanted to be able to show the latest weblog posts on the org’s home page.
I did a quick Google for what I needed, and came up with a gem of a tool: Feed2JS.
What Feed2JS does is to provide an interface where you can specify the URI to a RSS feed, click a few boxes and buttons on a web page to specify your options, and generate a Javascript output that you can stick straight into your web page, ready to go and immediately syndicating content from the specified feed. In addition, there’s a stylesheet generator on the site that lets you customize the look and feel of the feed as it’s displayed on your web page.
You can even download the original PHP scripts (which are provided under an open source license) and run Feed2JS on your own server, which could speed up the feed-to-web proxy function if you have scalability concerns due to very large volume, or if you want to modify the RSS cache to update more frequently than every 60 minutes. That is the default cache time for feeds being gathered and serviced by the Feed2JS system. At any rate, download your own copy and run it yourself, and you get complete control.
The results are quite good. Sure, the end user has to have jscript/Javascript enabled on the client, but that works for this purpose, so I am happy. Recommended.
Another slightly less-elegant (but quite useful) method using server-side ASP is called RSS in ASP. It works, as well.
 Monday, January 10, 2005
I have been testing development and release builds of dasBlog 1.7 for the past week or so. There are a few of us running it on our live sites to make sure everything’s working as expected and to provide real-world feedback.
This version – spearheaded by developers Omar and Scott and incorporating the work of several others – simply rocks.
There are a large number of performance improvements (it’s a lot faster and uses less resources on the server) and feature additions/enhancements. You can read about all the changes on the dasBlog wiki page for v1.7. Some of my favorites are the ability to post drafts without actually publishing to the live site, RSS 2.0 enclosures, referral spam protection,
One thing that I just added to this site with the latest build is live support for the Movable Type Blacklist, which is another mechanism to kill referral spam before it happens. There’s also the ability to block referrers from being listed by keyword. It’s all pretty cool.
It’ll be done soon, and when it is you’ll want to check it out, regardless of whether you currently use dasBlog.
Here is a point of view I tend to agree with, with regard to business and blogging… It’s not just what you say at work that can get you fired, and companies can employ (or not) based on a number of aspects of a person’s life. If you’re a blogger, these thoughts over at the Blog Your Way weblog are worth reading and taking into account:
Blog Your Way » My thoughts on being fired for blogging
There have been a lot of posts lately about being dooced (fired for blogging). Dooce (Heather) was the first to be fired almost three years ago and thousands have been fired since then. It seems that many more will follow. What was the common denominator in the majority of them? Discretion…and not thinking about the possible reaction to their posts.
From MS MVP Jerry Bryant comes news about the new malicious software combat tools that will launch on Tuesday this week from Microsoft:
Announcement of Upcoming Release of Malicious Software Removal Tools
Starting from January 11th, 2005, Microsoft will provide Windows customers with Malicious Software Removal Tools. New versions of these tools will be available monthly (second Tuesday of every month on the same schedule that Microsoft already delivers other security updates) or more frequently if necessary…
…Microsoft will provide new versions of this tool updated to remove malicious software that is found to be prevalent for that month. The first version of the tool available in January will be able to remove Blaster, Sasser, MyDoom, DoomJuice, Zindos, Berweb (also known as Download.Ject), Gailbot and Nachi viruses / worms.
These removal tools will be made available to customers through the following delivery vehicles:
- As a download through the Microsoft Download Center
- As a critical update through Windows Update and through Auto Update for those customers who have Auto Update turned on
- As an ActiveX control also available at www.microsoft.com/malwareremove
© Copyright 2012 Greg Hughes

This work is licensed under a Creative Commons License.
 | This page was rendered at Thursday, February 09, 2012 3:21:44 AM (Pacific Standard Time, UTC-08:00)
newtelligence dasBlog 2.1.8015.804
|
"Computers used to take up entire buildings, now they just take up our entire lives."
- Unknown
"So how do you know what is the right path to choose to get the result that you desire? And the honest answer is this... You won't. And accepting that greatly eases the anxiety of your life experience."
Syndication [XML] and .net Alerts
For lazy, highly-technical or enlightened people, get this site's content without the use of a web browser. I use FeedDemon for this, but you can choose your own. Subscribe - click the icon for my feed... or sign up for Microsoft Alerts to receive updates through your MSN Messenger, e-mail, or mobile device. Click the orange button thingie to sign up with your Passport account: 
Contact
Drop me an email: Phone: 503-766-2258
Add me to MSN Messenger
Monthly Archive
| November, 2011 (1) |
| October, 2011 (7) |
| July, 2011 (1) |
| May, 2011 (1) |
| April, 2011 (1) |
| January, 2011 (2) |
| December, 2010 (3) |
| November, 2010 (2) |
| October, 2010 (1) |
| September, 2010 (1) |
| July, 2010 (1) |
| June, 2010 (13) |
| May, 2010 (4) |
| April, 2010 (10) |
| February, 2010 (1) |
| January, 2010 (2) |
| December, 2009 (1) |
| November, 2009 (2) |
| September, 2009 (2) |
| August, 2009 (1) |
| July, 2009 (2) |
| June, 2009 (4) |
| May, 2009 (7) |
| April, 2009 (3) |
| March, 2009 (5) |
| February, 2009 (1) |
| January, 2009 (10) |
| December, 2008 (7) |
| November, 2008 (7) |
| October, 2008 (18) |
| September, 2008 (18) |
| August, 2008 (18) |
| July, 2008 (35) |
| June, 2008 (16) |
| May, 2008 (12) |
| April, 2008 (16) |
| March, 2008 (22) |
| February, 2008 (32) |
| January, 2008 (9) |
| December, 2007 (6) |
| November, 2007 (4) |
| October, 2007 (19) |
| September, 2007 (36) |
| August, 2007 (19) |
| July, 2007 (17) |
| June, 2007 (16) |
| May, 2007 (13) |
| April, 2007 (11) |
| March, 2007 (5) |
| February, 2007 (14) |
| January, 2007 (16) |
| December, 2006 (16) |
| November, 2006 (4) |
| October, 2006 (23) |
| September, 2006 (14) |
| August, 2006 (21) |
| July, 2006 (34) |
| June, 2006 (25) |
| May, 2006 (20) |
| April, 2006 (20) |
| March, 2006 (17) |
| February, 2006 (34) |
| January, 2006 (30) |
| December, 2005 (23) |
| November, 2005 (39) |
| October, 2005 (30) |
| September, 2005 (49) |
| August, 2005 (31) |
| July, 2005 (21) |
| June, 2005 (35) |
| May, 2005 (53) |
| April, 2005 (54) |
| March, 2005 (60) |
| February, 2005 (27) |
| January, 2005 (59) |
| December, 2004 (70) |
| November, 2004 (58) |
| October, 2004 (55) |
| September, 2004 (64) |
| August, 2004 (53) |
| July, 2004 (65) |
| June, 2004 (50) |
| May, 2004 (49) |
| April, 2004 (26) |
| March, 2004 (20) |
| February, 2004 (26) |
| January, 2004 (28) |
| December, 2003 (12) |
| October, 2003 (8) |
| September, 2003 (11) |
| August, 2003 (1) |
On this page
Search and Translate this Site
Blog Posting Categories
Navigation Links
Blogroll
Scott Adams' Dilbert Blog
Scott Adams is the creator of Dilbert, and his blog is an incredibly smart, clever and often funny (sometimes very serious) look at the world. Everyone should read this blog. |
Alex Scoble
Alex is a former coworker who blogs about a variety of IT-related topics. |
Brent Strange
Brent is a cool dude and a great QA guy that I used to work with. His blog is, appropriately, focused on QA and testing technology. |
Chris Brooks
Chris was formerly my boss at work and is an avid board gamer and photographer. He always has some new info about top-notch board games you may have never heard of, so if you're into them, you should check out this blog. |
Chris Pirillo
Lockergnome by trade, Chris is always up to something new. If you are not familiar with the Lockergnome newsletters, be sure to check them out, too. |
Matthew Lapworth
Matt's a software developer and friend. He seems to enjoy extreme sports. That's fine as long as he doesn't, like, die or something. |
Milind Pandit
Milind writes about all sorts of interesting stuff. We worked toegther for eight years, and he worked at our employer longer than I, which pretty much makes him old as dirt in company time. :) |
MSFT Security Bulletins [RSS]
RSS feed for all Microsoft security bulletins provides an always-up-to-date list of updates along with complete descriptions of each. |
neopoleon.com
Rory Blyth is one of the funniest and most thought-provoking bloggers I read. And I blame him for everything. Literally. |
Scott Hanselman
Scott's computerzen blog is a popular spot for all things .NET and innovative. I used to work with him, but then he went off to Microsoft. He's one of the smartest guys I know, and arguably the best technical presenter around. |
Sign In
Who Links Here
Total Posts: 1888 This Year: 0 This Month: 0 This Week: 0 Comments: 3458
Android (7) Apple (67) AudioBlogging (42) Aviation (2) Blogging (154) Fireworks (5) Geek Out (130) GnomeDex (20) Google Voice (1) Helping Others (27) Home Servers (5) Humor (144) IT Security (217) Kineflex Artificial Disc Surgery (16) Management (8) Microsoft Office (4) Mobile (139) Movies (31) Mt. St. Helens (13) Office 2003 (52) OneNote (29) Personal Stories (163) Photography (29) Random Stuff (642) RSS Stuff (47) RunAs Radio (28) Safe Computing (38) SharePoint (56) Tablet PC (42) Tech (1035) Things that Suck (69) Windows (6) Windows Media Technology (27)
|