|
Please visit the LangaList Home Page Please note: Older issues may contain information that is now out of date. How To
Subscribe and Unsubscribe is at the end of this
note. Mailing List Trouble? See
http://www.langa.com/help.htm Please recommend the LangaList to a friend! (And maybe win $10,000 !) An easier-to read formatted
HTML version of this newsletter is available The
LangaList 2002-10-21 Please visit our sponsors and help keep the LangaList S.E. free! --- ( Your Clicks On Ad Links Help Keep The LangaList Free! ) ---
--------------( the above is an advertisement )-------------- 1) A Free, Two-Click Solution To "Phone-Home Fields"Unless you've been under a rock lately, you've probably heard of the uproar caused by "hidden fields" inside Microsoft Office documents. The issue affects all versions of Word (both for Windows and the Mac) from 1997 onward, and also affects Excel 2002. Some pundits claimed these fields are a "gaping
security hole" that places literally every
file on your PC at risk. I disagreed about the severity of the problem (
http://www.langa.com/newsletters/2002/2002-10-10.htm#9 ) because only a
minority of users would ever be at risk from these fields, and because there's
an ultra simple, two-click way to avoid the worst of the security issues. To help clear up the confusion--- and to show you exactly how to protect yourself against this kind and all similar kinds of attacks--- I've posted a full-length article at http://www.informationweek.com/story/IWK20021017S0016. There, we'll examine the problem, dissect the two major forms of attack that use hidden fields, and show you how to prevent these attacks from succeeding. Best of all, you can do all this using tools you probably already have at hand, or can easily get for free, even without the Microsoft patch. Don't believe the hype. No one has to lose data to this kind of attack. It's *incredibly* easy to protect yourself. Click on over to http://www.informationweek.com/story/IWK20021017S0016 and see how! Click to email this item to a friend --- ( Your Clicks On Ad Links Help Keep The LangaList Free! ) ---
--------------( the above is an advertisement )-------------- 2) Non-SP1 Patch For XP's Help-System FlawIf you're running XP, I think Service Pack 1 is
worthwhile; it works fine for almost everyone, and improves the OS's security
and operation. But if you've decided NOT to install Service Pack 1 (perhaps
for the reasons we've discussed previously:
Also: If you've NOT installed SP1, be sure to check out http://www.langa.com/newsletters/2002/2002-09-19.htm#1 for info on another stand-alone patch for a separate but similar file-deletion exploit in XP. Click to email this item to a friend 3) Defining "Buffers"Speaking of Microsoft patches, in recently discussing Microsoft's long history of trouble with "unchecked buffers" (see, for example, http://www.langa.com/newsletters/2002/2002-10-17.htm#9 ) I inadvertently left some readers wondering what the jargon meant:
My apologies for not explaining better. In software, a buffer is a kind of internal scratchpad where data can be stored temporarily while it's being worked on, or held for near-term future use. An "unchecked buffer" is one where the software doesn't verify that the buffer is OK to use--- that is, that the buffered data is valid in length, format and content. A malicious hacker can use an unchecked buffer as a kind of unguarded entry point into your software, perhaps using it to stuff hostile code into a program, or simply to bring things to a crashing halt as the buffer overflows with more data than the software was meant to handle. Apparently, Microsoft's quality control people don't have, or don't enforce, effective standards for buffer construction in Microsoft software, and the result has been a stream of literally hundreds of security problems caused by unchecked buffers. (Think I'm exaggerating? See http://www.google.com/search?q=unchecked+buffer+site%3Amicrosoft.com ) If you'd like a more formal definition of "buffer," see http://www.techweb.com/encyclopedia/defineterm?term=buffer&x=24&y=9 Click to email this item to a friend --- ( Your Clicks On Ad Links Help Keep The LangaList Free! ) ---
--------------( the above is an advertisement )-------------- 4) Excellent Suggestion!
Great suggestion, David! With so many fast-replicating worms and viruses out there, it really is smart to make sure your defenses are always completely up to date--- especially after any significant time offline. That means it's well worthwhile to FIRST run your AV update tool, and only THEN start visiting sites and downloading email. Click to email this item to a friend 5) Macy-Jean Turns FiveWe first met Macy-Jean last April ( http://www.langa.com/newsletters/2002/meet_macy_jean.htm ). She's a very young Filipina who was facing a bleak future, but--- thanks to LangaList Plus! Subscribers--- her life has gotten a lot better. She's still too young to be able to write her own notes, but an aid worker in her village recently sent a letter and a new photo on her behalf:
Because those of us with computers and Internet access are vastly better off than most of the world's population, I decided that a portion of the LangaList Plus! subscription fees would be donated to registered/legitimate charities helping the underprivileged around the world. The contribution does not increase the cost of a Plus! subscription in any way; the donation is taken "off the top" of any profits. (This is described in the pages at http://www.langa.com/plus.htm ) Macy-Jean is one of seven kids sponsored on an ongoing basis--- week in, week
out--- by the collective generosity of LangaList Plus! subscribers. Plus!
subscribers also have collectively contributed to emergency earthquake relief
efforts in India and to funds to help the victims of last year's Sept 11th
attacks in the US. (To see all the donations so far, click to
http://www.langa.com/plus2.htm#kids ) If you're not yet a Plus! subscriber check it out: With an inexpensive Plus! subscription (pennies per issue) , you can not only help yourself make the most of your hardware, software and time online--- but you also can help those less fortunate (like Macy-Jean) make the most of their very lives. See http://www.langa.com/plus.htm If you're already a LangaList Plus! subscriber, thank you. I hope you feel good about giving back a little to those less fortunate, and helping to brighten the life of a child in otherwise-desperate circumstances. Click to email this item to a friend 6) $10,000 For Your Trouble?If you think the LangaList is a worthwhile read, just use the following link to recommend the LangaList to a friend. You just may win $10,000(!), your friend just may find a new source of useful information; I just may gain a new subscriber (full details also available via this link): http://www.recommend-it.com/l.z.e?s=143182 Or, win a no-strings $30 Gift Certificate for any item at Amazon.Com---
books, software, hardware, kitchenware, toys... (Full details available via this
link): Either way, thank you, and good luck! Click to email this item to a friend 7) No Simple Answer?
I looked around but came up dry, Tony: If the printer doesn't come with such a program, I think it would be hard to write a good generic one, as it would have to tie into the printer driver to work slickly. But far less elegantly, it's easy to create a quick-and-dirty batch file that sends a line of text such as "Turn me off!" to the printer port (usually LPT1, if the printer is connected directly to the PC). The batch file contents could be as simple as:
If you use Task Scheduler to make the batch file a scheduled task (maybe once every couple hours.), it will try to print at the scheduled time. If the printer is on, it will spring to life and the "Turn me off" message will print out. Your friend then can turn off the printer. If the printer is off, your friend will get an on-screen (error) message stating that is it indeed off. Crude, but it'll work. Anyone know of a more elegant solution? Click to email this item to a friend 8) More Reader Sites!Do you have a home page or website? (It doesn't matter what size.) Please click over to http://www.langa.com/code.htm, and maybe you can join the hundreds and hundreds of LangaList readers who have "Loaded the Code!" (If you've already "Loaded The Code" and are wondering if your site will appear here or on the Langa.Com web site, please see http://www.langa.com/link.txt ) Speaking of which: Here's another eclectic sample of reader sites--- some professional, some very personal: View A Randomly-Chosen Reader Site From Among All Listed Manually Browse All Posted-to-Date Sites Starting At Kindertransport Jordan Racing Team Fever Design By Pandora antenna conspiracy Wimborne Baptist Church (UK) Muzcom Software Irregular Net FLORIDA BASS FISHING Dogs On Holiday Click to email this item to a friend --- ( Your Clicks On Ad Links Help Keep The LangaList Free! ) ---
--------------( the above is an advertisement )-------------- 9) "Cablenut"
Thanks. Craig. The site and software look very good. Of the latter, the site says:
Click to email this item to a friend 10) Just For GrinsAndy Hass sends along these "extreme bumper stickers:"
Click to email this item to a friend --- ( Your Clicks On Ad Links Help Keep The LangaList Free! ) ---
--------------( the above is an advertisement )-------------- 11) Plus! Edition Highlights:
Today's LangaList Plus! Edition contains all ten items above, plus about 30% more content including: free software that works like the commercial versions of Drive Image and Ghost; ways to double the battery life on cordless mice; sources for world-class dictionaries on CDs; and a weird and wonderful site containing various projects that you probably won't want to try on your own, but that are amazing to see--- when someone else is doing it! <g> Complete Plus! Edition info: http://www.langa.com/plus.htm Click to email this item to a friend See you next issue! Best, Please recommend the LangaList to a friend! (And maybe win $10,000!I) An easier-to read formatted HTML version is available in the "Current Issue" section of http://www.langa.com. (The HTML version of each issue normally is available by 9AM EST [UT-5] of the issue date.) All past LangaList issues are also available at the Langa.Com site. UNSUBSCRIBE: From the same email account you
used to sign up with), send an email to This newsletter is SPAM PROOF and requires two levels of subscriber confirmation
before delivery begins: See
http://www.langa.com/info.htm |
|
Please visit the LangaList Home Page |