Monthly Archive for November, 2006

DDKWizard updated

There is a new version (1.0.2) of DDKWizard available. Go and grab your copy at the DDKWizard website.

What’s new?

Three things have been changed or added:

  • Option to create PREfast configurations as well.
  • The Windows 2003 and Longhorn/Vista DDK are now preselected.
  • There is a new project type “Empty Driver”. This allows you to create a project without creation of all the source files that DDKWizard would normally create. Perfect to create an empty project for incorporation of existing source files.

Enjoy,

// Oliver

Killerspiele gehören verboten …

Wie gut, daß es in Island keine bescheuerten Ordnungsfanatiker gibt, die meinen ein Amoklauf ala Erfurt oder gestern Emsdetten ließe sich durch ein Verbot von Killerspielen verhindern. Vielmehr sollten sich all jene die das fordern mal an die eigene Nase fassen und das bescheuerte Gesellschaftssystem in dem wir leben infrage stellen. Aber die Gesellschaftskritik ([1], [2], [3]), welche der Amokläufer von Emsdetten ja nicht nur aktionistisch sondern offenbar auch lange vorher (in Foren usw.) verbal vorbrachte, die wird gern überhört. Continue reading ‘Killerspiele gehören verboten …’

Marketing for security companies now via Secunia!

<sarcasm>
A great new opportunity for IT security companies which sell products to detect bugs in software automatically (static analysis) – report some vulnerabilities after running your program on a bunch of software applications and feature your own product in the “Provided and/or discovered by” field without ever giving details of the error! The last one is important, never give details! That’s sleek, that’s modern that’s seemingly a new initiative by Secunia to support third party security companies. One of the first to take advantage of this new initiative is GLEG Ltd. from Russia.
</sarcasm>
Continue reading ‘Marketing for security companies now via Secunia!’

Offener Brief an GMX – Betrifft: moderne Browser (nochmal)

Vielen Dank für die Textbausteine, die ich schonmal zugeschickt bekam und auch kommentierte (beachten Sie ruhig das Datum). Schön (oder besser gesagt peinlich), daß der Textbaustein noch nicht angepaßt wurde. Das zeigt doch deutlich wie wichtig Ihnen Topmail-Kunden sind:

http://blog.assarbad.net/20060722/designfragen_gmx/

Wenn ich einen modernen Browser will, ist Internet Explorer 5.5 aus 2000 sicher die letzte Wahl. Netscape 7.2 hat auch schon mehr als 2 Jahre auf dem Buckel, während die Opera-Version welche ich angab keine 6 Monate alt ist. Continue reading ‘Offener Brief an GMX – Betrifft: moderne Browser (nochmal)’

Are you a developer reading my blog?

If you are a developer and have not yet heard of WinDirStat, please check it out first. Then if you like it and can imagine to write a plugin for it, give me some feedback at this blog article. Thanks.

// Oliver

Article: “How Two Hours Can Waste Two Weeks”

Over at Agile Advice, you can find a very nice blog article from the perspective of a development manager. I can tell that much: at my former company the PM (same person as DM in this case) did not take the pressure from us devs, at the current company it seems wo work well. Maybe because of that one major difference … that the CTO is member of the dev team? ;)

I was pointed to the article by a friend who is currently plagued by the flu. Get well soon! :-)

// Oliver

DDKBUILD.CMD updated to version 7.0beta4

OSR is going to update the DDKBUILD.CMD script on their website next week. If you can’t wait, grab your copy at the DDKWizard website.

A bug has been fixed which affected the build for WNET DDK with the two 64bit target processor platforms. Also a glitch on the help screen of the script has been fixed, which was somewhat related to the aforementioned bug.

// Oliver

Shit happens … US nuclear secrets found on USB thumb drives …

Read on http://www.msnbc.msn.com/id/15566388/site/newsweek/

// Oliver

Storm in a teacup or big deal for Novell?

A friend of mine pointed me to the following message (“open letter”) of Novell:
http://www.novell.com/linux/microsoft/openletter.html (the related press release is here). I wonder how this partnership will affect other distros, especially non-commercial. My friend says that it will have a big influence on the other commercial distros and non-commercial ones will be ignored. I am not so sure. What do you think? Leave a comment …

// Oliver

Redpill getting colorless?

Although I had posted this already at the malware research forum and received little feedback, I decided to prepare a brief research paper about this topic and post it here.

The topic is that the Redpill approach by Joanna Rutkowska does not seem to work reliably and the values retrieved in kernel mode inside a virtual machine (VMWare ) differ substantially from the ones retrieved in user mode. While calling SIDT in user mode was the rationale of the whole approach, it would not usually be expected that the results between user mode and kernel mode are different. Also the difference means that the approach is not generally applicable. Last but not least the Redpill approach failed for me on Virtual PC (see the paper).
Continue reading ‘Redpill getting colorless?’

Spammers screwing around with postmaster alias

As required by section 4.5.1 of RFC2821, the RFC detailing the SMTP (Simple Mail Transfer Protocol), the postmaster alias (e.g. postmaster@domain.tld) is required on any system running an SMTP service. So far so good.

Having not gotten spam via my own SMTP, thanks to Greylisting I thought I was safe. But now spammers – scum as they are – resort to the very last method to spam valid addresses. Continue reading ‘Spammers screwing around with postmaster alias’

Got ‘em back, LS :-P …

Backup is always good to have …

Yeah, found the stuff. Here is a screenshot of the article “Bragging Rights” referenced in this article from exactly 3 months back …

Last but not least the two articles – referenced here – about rootkits have been found on my 500 GB backup disk. I could pretend that I found them after only some days, but actually it took only about 10 minutes for the XP search to come up with the results :mrgreen: . Here are the files as an archive. Uncompress the file and watch them with the application that registered to view .mht (web archive) files. Enjoy.

// Oliver