We’ve got some problems today caused by an install of Symantec Antivirus version 10. On some Windows 2000 systems after installing Symantec Antivirus 10, the SMS client agent would no longer run. Investigation showed that WMI was possibly corrupt. We’re still looking into this problem. Thus far I haven’t found a way to fix it.
Archive for March 2006
Disabling the LanMan Hash
I’m taking another look at whether or not it is worthwhile to disable the LANMAN hash. If you don’t know what that is, this is probably not the article for you.
The LANMAN hash is listed on the SANS/FBI Top 20 list. Microsoft says to disable it you dont need the backward compatibility.
Yet Jesper Johansson pretty much calls doing this security theatre. If someone were to compromise the password database, they aren’t going to be cracking the passwords in his opinion, instead they will be replaying the hash. But sometimes the password is needed such as going after EFS or if the password might be used on other non-windows accounts.
I need to think about this.
Virus Def Update Speed
F-Secure has a little flash video used to illustrate the difference in update speed between F-Secure and several competitors.
Listserv Vulnerability
The ISC reports a vulnerability in Listserv software. NGSSoftware says they will disclose the details of the vulnerability in June. The upgrade is available now.
Here’s the problem are people back on 1.8 effected? What is the vulnerability? If it is in the web site, fine, we dont expose that to the internet. But if the problem accessible via smtp, then there is a problem we need to deal with now.
You see, limited disclosure really doesn’t help when a product is a pain to upgrade like listserv.
Steve Gibson Discovers ARP Cache poisoning
http://www.grc.com/nat/arp.htm
Several years late. Welcome to the party pal.
Parody: Microsoft redesigns the IPod Packaging
I saw this over at Microsoft Monitor. The link to YouTube is dead, but I found it over on video.google.com.
Reportedly this is a self-parody. It was made in house to critique their design process. Either way, I was laughing through it. I just wish the quality of the video was a tough better so I could see the small print.

