Re: facebook 'routing flaw'?

2010-01-19 Thread Matthew Leeds
There is a fairly in depth discussion of the issue here: http://arstechnica.com/web/news/2010/01/facebook-att-play-fast-and-loose-with-user-authentication.ars Not a routing issue, more of a proxy issue, and not uncommon in mobile carrier networks. Getting security right in a mobile application

Re: Media Player Classic 6.4.9 MP4 Stack Overflow 0-day

2007-12-12 Thread Matthew Leeds
Just to rehash this for my own clarity, and perhaps that of others, this is not a defect in Media Player Classic so much as a defect in the 3ivx codec. If one were to use a different codec to decode MP4 content this defect would not exist. This is similar to a defect in Adobe Acrobat Reader

Re[2]: Microsoft FTP Client Multiple Bufferoverflow Vulnerability

2007-11-30 Thread Matthew Leeds
Given the past issues with .zip and .rar unpackers, unpacking an archive should be considered a risky activity. In some sense, opening, accessing, playing, or otherwise touching any file from an unknown source could be considered risky. The list of issues with media files, archive files, (or

Re: mac trojan in-the-wild

2007-11-01 Thread Matthew Leeds
Let's see now, user must: 1) Navigate to porn site 2) Download Trojan 3) Either open file or have set 'Open Safe Files...' 4) Must allow install by typing admin password Oh yeah, this will clearly hit Mac users hard, not. I don't see this as a big deal, more as Darwin in action (if you will not

Re[2]: Skype Network Remote DoS Exploit

2007-08-21 Thread Matthew Leeds
I'd consider this uh, untrue. Didn't happen on the last patch Tuesday, nor the one before. What made this month special? Did those millions of Windows users who update all coordinate their activity? Not likely. As to other services that depends on running on consumers computers to provide

Re[2]: Retrieving deleted sms/mms from Nokia phone (Symbian S60)

2007-05-16 Thread Matthew Leeds
In fact this is so well known that many of the charities that accept donated cell phones provide tools for secure deletion of data prior to shipping the phone. http://wirelessrecycling.com/home/data_eraser/ It would be interesting to test the hard reset (factory reset) feature of some current

Map MS Security Bulletins to MS KB numbers

2006-07-22 Thread Matthew Leeds
I'm looking for a resource that maps Microsoft Security Bulletin numbers (such as MS06-033) to Microsoft Knowledge Base numbers (such as KB 917283). I recognize that this may be a one to many mapping since a single SB may point to a set of possible patches depending on OS version or application