TWiT.TV — with Leo Laporte & Friends

Podcast navigation

Tip Leo

Poll

Would a tablet fit into your digital lifestyle?:

Buy TWiT Stuff

Click here to see the TWiT SeVs! and/or to see Leo with his SeV

Syndicate

Syndicate content

Episode Guide

NextPrev
234

February 4th, 2010

Security Now 234: Your Questions, Steve's Answers 85

Internet Explorer as a file system, using Live CDs for security, and Steve takes on the iPad...

233

January 27th, 2010

Security Now 233: Let's Design A Computer

Steve explains how computers work by designing one from first principles.

232

January 21st, 2010

Security Now 232: Your Questions, Steve's Answers 84

Steve answers listener questions about live Linux CDs, TrueCrypt RAM encryption, resetting Thomson modem passwords, and more.

231

January 15th, 2010

Security Now 231: Security Omnibus And CES Update

Steve catches up with a mega security update, then gives us some of his favorite (wacky) products from CES.

230

January 6th, 2010

Security Now 230: Your Questions, Steve's Answers 83

This week's questions cover packet flow, hijacking DNS queries, router DNS, Patch Tuesday, and more.

229

January 1st, 2010

Security Now 229: The Rational Rejection of Security Advice

A hard look at the costs and benefits of following all security advice.

228

December 24th, 2009

Security Now 228: Your Questions, Steve's Answers 82

Steve responds to questions covering Skype spam, SSL cracking, unencrypted UAV video feeds, free SSL certificates, and more.

Security Now

Running time: 10:59

Audio

Please install Flash to use the web based podcast player.


AddThis Social Bookmark Button

April 2nd, 2007

Security Now Special Edition: The Animated Cursor Vulnerability

Hosts: Steve Gibson with Leo Laporte A special edition of Security Now to warn and inform listeners of a serious zero-day exploit that affects NT, XP, and Vista - even if fully patched. An interim patch is available from eEye for use until Microsoft provides an official update. (But see below first, since Microsoft is patching out-of-cycle.) At the end of March, exploitation of a previously (publicly) unknown vulnerability in Windows' animated cursor (ANI) processing was detected in the wild. This new vulnerability is now being widely exploited to install Trojan malware into unpatched Windows 2000, XP, Server 2003 and Vista systems. All fully patched Windows systems are currently vulnerable. Microsoft learned of this vulnerability in all versions of Windows more than three months ago, on December 20th, 2006, but did nothing to protect their customers. Proof-of-Concept code has now been publicly released, guaranteeing rapid and widespread adoption of this exploit. Microsoft was forced to publish this acknowledgement of the vulnerability and since they have known of it for many months they have now stated that they will be pushing out an early, out-of-cycle official update to eliminate this vulnerability on Tuesday, April 3rd, 2007. Depending upon your level of concern and/or exposure you could install the eEye patch now, or wait (one day) for Microsoft's official update. But be sure to look for this update on or after Tuesday, April 3rd. For 16kpbs versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Security Now is brought to you by Astaro Internet Security. Bandwidth for Security Now! is provided by AOL Radio

Design by Arktyp - Powered by Drupal