October, 2008的归档


October
23rd
2008

[紧急]Windows紧急安全更新(KB958644)

业界动态 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

微软爆出特大安全漏洞,会引发大面积远程攻击甚至完全控制,危害程度跟”冲击波”类似,强烈建议各网友下载此补丁.
现已确认存在一个安全问题,通过了身份验证的远程攻击者可能会利用此问题危及基于 Microsoft Windows 的系统的安全并获取对该系统的控制权。

Operating System Maximum Security Impact Aggregate Severity Rating Bulletins Replaced by this Update

Microsoft Windows 2000 Service Pack 4

Remote Code Execution

Critical

MS06-040

Windows XP Service Pack 2

Remote Code Execution

Critical

MS06-040

Windows XP Service Pack 3

Remote Code Execution

Critical

None

Windows XP Professional x64 Edition

Remote Code Execution

Critical

MS06-040

Windows XP Professional x64 Edition Service Pack 2

Remote Code Execution

Critical

None

Windows Server 2003 Service Pack 1

Remote Code Execution

Critical

MS06-040

Windows Server 2003 Service Pack 2

Remote Code Execution

Critical

None

Windows Server 2003 x64 Edition

Remote Code Execution

Critical

MS06-040

Windows Server 2003 x64 Edition Service Pack 2

Remote Code Execution

Critical

None

Windows Server 2003 with SP1 for Itanium-based Systems

Remote Code Execution

Critical

MS06-040

Windows Server 2003 with SP2 for Itanium-based Systems

Remote Code Execution

Critical

None

Windows Vista and Windows Vista Service Pack 1

Remote Code Execution

Important

None

Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1

Remote Code Execution

Important

None

Windows Server 2008 for 32-bit Systems*

Remote Code Execution

Important

None

Windows Server 2008 for x64-based Systems*

Remote Code Execution

Important

None

Windows Server 2008 for Itanium-based Systems

Remote Code Execution

Important

None


October
10th
2008

“不可破解”的加密技术出现

信息安全 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

由于黑客技术的盛行,越来越多的加密技术被广泛采用,但他们都是可以破解的。据BBC报道,在维也纳科学大会上展示出一组完美的加密技术,这种技术被称为量子密码技术,并称是不能破解的,它采用光量子来传递密钥。携带这种加密技术的系统通过光纤通信运行在维也纳的6个位置,据说这种加密技术是由IBM的Charles Bennett 和 蒙特利尔大学的Gilles Brassard 发明的。


October
6th
2008

Security Course Laboratory – Password Security

信息安全 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

This semester, as a TA, I prepared several course laboratories for security courses. This is the first one called Password Security to examine common password-related technologies under both Linux and Windows platforms.

At first, it is to examine the password files on both systems. Then, to run password cracking tools on provided password files in order to familiarize them with this threat. A common saying is that if you are an administrator of a system, you should be the first one to run such tools on your system! (i.e. proactively detect any weak passwords for all your users and disable such accounts). To provide more secure password system, an administrator should know how the password policy works and how to provide such policy on both systems. Finally, it is to examine the password cracking tools on oracle database system.


October
3rd
2008

富士通开发出新款加密软件 纸质文件同样适用

信息安全 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

日本富士通公司最近开发出的一款软件同时可对电子文本和纸质文件加密和解密。目前,计算机内保存的电子文本能轻松加上密码,而传统的纸质文件加密则比较困难。
这款新软件已出现在正在举行的第9届日本高新技术博览会上。工作人员一边用安装有这款软件的计算机演示,一边介绍说,这款名为“DocEncrypt”的软件可以给文件的不同部分设置不同的密码,然后按照浏览者的不同权限,开放特定的加密区域。

经过这款软件加密处理后,电脑屏幕上的文件或者文件的特定部分就会被细小的黑点覆盖起来。除非输入特定的密钥,否则加密的部分无法继续被浏览。

富士通这款加密软件的最大秘密是,经过加密的文件打印出来后,纸质文件上加密的部分也覆盖着密密麻麻的黑点。而且,如果掌握密钥,纸质文件上的加密内容仍然可以神奇般地重新出现。

富士通公司的工作人员说,对电子和纸质文件同时实现加密和解密,这在世界上还是首次。目前富士通正在全球范围内申请专利,估计明年年初这款软件就可以投放市场。


October
3rd
2008

几个实用的XP工具

实用工具 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

Folder Size

Windows资源管理器,默认情况下,不显示文件夹的大小,即使你你选择“详细”的查看的方式。有时候需要对文件夹管理或者查看的时候,你可能就要用到 右键属性来查看了,比较麻烦,又不可能对很多个文件夹大小查看。通过这个工具,可以让你查看到文件夹大小,而不再是繁琐的右键,有助于你管理文件夹。

下载:http://foldersize.sourceforge.net/

QTTabBar

如果您的屏幕堆满Explorer窗口,可以考虑以类似于在Internet Explorer 7 标签来帮助你管理。QTTabBar可以让您实现切换从一个文件夹标签的到另一个窗口,只需要一次点击或按下Ctrl键 。

除了工具栏上的标签,您可以显示或隐藏工具栏以管理自己的标签。

下载:http://qttabbar.wikidot.com/

Direct Folders

在标准的Windows文件打开和文件保存对话框窗口的标题栏右侧放置一个小图标按钮,同时它也能够显示在Windows资源管理器以及浏览文件夹对话框中。该按钮可以显示一些你经常访问的文件夹列表,使得访问更为方便、快捷。

下载: http://www.codesector.com/directfolders.php


October
2nd
2008

How Kerberos Authentication Works

电脑技术 没有评论

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

You may not know it, but your network is probably unsecured right now. Anyone with the right tools could capture, manipulate, and add data between the connections you maintain with the internet. The security cat and mouse game isn’t one sided, however. Network administrators are currently taking advantage of Kerberos to help combat security concerns.

Project Athena

Project Athena was initiated in 1983, when it was decided by the Massachusetts Institute of Technology that security in the TCP/IP model just wasn’t good enough. A total of 8 long years of research passed before Kerberos, named after the three-headed Greek mythological dog known as Cerberus, was officially complete.

The result of MIT’s famous research became widely used as default authentication methods in popular operating systems. If you are running Windows 2000 or later, you are indeed running Kerberos by default. Other operating systems such as the Mac OS X also carry the Kerberos protocol. Kerberos isn’t just limited to operating systems, however, since it is employed by many of Cisco’s routers and switches.